I should have been more clear here.  I wasn't talking about the
community's experience, but counterarguing with the technical merit of
PaX over ES based on the developer's experience.  The community can
adjust to PaX easily; but the software won't magically adjust to be
better just because the community uses it.

For a counterargument based on the community, I should point out that I
have been using PaX, and have located a lot of the incompatibilities on
x86.  The Hardened Gentoo and Adamantix projects also have been using
PaX.  The Hardened Debian team picked PaX when they started.  GrSecurity
is based around PaX.  YOU may not have experience with it, but you've
got a lot of help if you know where to look.  The community will adjust,
and they'll adjust quickly.


| [1] is a detailed explaination of PaX; [2] has a comparison of
| technologies.  [3] is skeletal and needs more data.  It's notable that
| PaX is from October, 2000, and still actively maintained; while ES and
| W^X both are from May, 2003, and are still actively maintained.  PaX
| therefore has seniority.  The PaX developer, unlike Ingo Molnar, is also
| more of a security guy than a random kernel hack guy; Ingo is good at
| making new preemption schemes and schedulers, and should probably focus
| more on that.

