In an ideal world, I'd like a modern kernel with the grsec/pax patches and ksplice. This should keep the Torouter kernel in good shape. In a realistic world, I think we'd be lucky to simply get a regularly updated kernel that includes the grsec/pax patches.
What do you want to see in the kernel?
To upload designs, you'll need to enable LFS and have an admin enable hashed storage. More information
Child items ...
Show closed items
Linked items 0
Link issues together to show that they're related.
Learn more.
It seems like our hardware may be fixed enough such that we do not need kernel module loading at all. If we enable everything we need, we can simply remove modules entirely. If we want the device to be a bit more extendable, we'll have to open up module loading and vet specific devices. Otherwise we ship a kitchen sink...
If I wanted to go with the most stripped down kernel possible, I'd suggest a static kernel (no module loading) without /dev/mem, with grsec in high security mode, and with support only for the devices we absolutely need.
On the flip side from a stock kernel but a fairly extensible one, I'd take the kernel sources from the DreamPlug website, configure with /proc/config.gz, and then patch with grsec configured for high security mode.
If this project were to be revived, this discussion would have to take place again around the targeted hardware platform, and so closing this ticket as no longer relevant. See also #20747 (closed).
Trac: Status: new to closed Sponsor: N/AtoN/A Parent: N/Ato#20747 (closed) Severity: N/Ato Normal Reviewer: N/AtoN/A Resolution: N/Ato wontfix