The purpose of this ticket is to get a grsecurity kernel to work in Whonix (same as Debian for these purposes here) at all. Having user documentation on how a user could install it. From there we could build up with automation, perhaps installation by default, verifiable (kernel) builds, etc.
Also started a discussion with the mempo developers of deterministic grsecurity kernel deb:
https://github.com/mempo/mempo-kernel/issues/created_by/adrelanos
https://github.com/rickard2/grsecurity-Debian-Installer looks most promising for now. Much simpler than the mempo-kernel.
Licensing is not sorted out yet:
https://github.com/rickard2/grsecurity-Debian-Installer/issues/12
Has some other issues:
https://github.com/rickard2/grsecurity-Debian-Installer/issues/created_by/adrelanos
That script is relatively small and simple. Fixing these issues and/or forking and/or rewriting it depending on how responsive upstream is should be no issue.
TODO:
- Foremost, check if that installer is actually working.