I just would like to try the hardened gentoo profile and patch my kernel with PaX, if it's possible. (yes, I have a lots of time)
Unfortunately, when I tried it being guided by the official hardened gentoo documents my trial system crashed after the first reboot.
(it said a serious recursive error had been successfully fixed but reboot was needed... I've restarted my Sabayon a few times but the result still the same. At last, I re-installed it)
Or in the case of that it's impossible for some reason, is there another way to make my system so bullet proof as the way PaX kernel patching promise?
Oh, yes . And I still have an important question yet: is it true that Linus was forced to develop SELinux to (well, how can I say...) quite enough "NSA-compatible" ?
