Gentoo Archives: gentoo-hardened

From: Ned Ludd <solar@g.o>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] SELinux problem -> avc: denied {execmem}
Date: Mon, 22 May 2006 22:44:34
Message-Id: 1148337641.6851.26.camel@localhost
In Reply to: Re: [gentoo-hardened] SELinux problem -> avc: denied {execmem} by pageexec@freemail.hu
1 On Mon, 2006-05-22 at 21:43 +0200, pageexec@××××××××.hu wrote:
2 > On 22 May 2006 at 19:32, Jan Meier wrote:
3 > > > do you have a new gentoo setup there or did you migrate an old install?
4 > > The gentoo installation is two month old, I migrated to SELinux.
5 > > It is a PPC, could this be a problem?
6 >
7 > i'm wondering if it's the ppc .plt issue that PaX runs against as well
8 > (it's rwx and runtime generated -> not good). a year ago or so Red Hat
9 > people added secureplt support to binutils/ld, (hardened) gentoo should
10 > probably take a look.
11 >
12 > http://gcc.gnu.org/ml/gcc-patches/2005-05/msg01134.html
13 > http://sources.redhat.com/ml/binutils/2005-05/msg00391.html
14
15 Last we spoke about this I thought you said it was reverted.
16
17 Btw. I'm running a ppc box with pretty great success with most of the
18 supported PaX features enabled. (only bugs thus far have been with SPP
19 and a few pkgs (glibc/busybox/gcc) but I'm sure that wont shock you :)
20
21 Linux luna 2.6.14-hardened #1 Tue Nov 15 21:55:38 UTC 2005 ppc
22 7447/7457, altivec supported GNU/Linux
23
24 128bb000-128c1000 r-xp 00000000 03:03 1703959 /bin/cat
25 128cb000-128cc000 r--p 00010000 03:03 1703959 /bin/cat
26 128cc000-128cd000 rw-p 00011000 03:03 1703959 /bin/cat
27 128cd000-128fb000 rw-p 128cd000 00:00 0 [heap]
28 32cc6000-32cde000 r-xp 00000000 03:03 205825 /lib/ld-2.3.5.so
29 32cde000-32cdf000 rw-p 32cde000 00:00 0
30 32ce6000-32ce7000 r--p 00020000 03:03 205825 /lib/ld-2.3.5.so
31 32ce7000-32ce8000 rw-p 00021000 03:03 205825 /lib/ld-2.3.5.so
32 32ce8000-32ce9000 rw-p 32ce8000 00:00 0
33 32cea000-32cee000 r-xp 00000000 03:03 205787 /lib/libaudit.so
34 32cee000-32cfa000 ---p 00004000 03:03 205787 /lib/libaudit.so
35 32cfa000-32cfb000 r--p 00010000 03:03 205787 /lib/libaudit.so
36 32cfb000-32cfc000 rw-p 00011000 03:03 205787 /lib/libaudit.so
37 32d06000-32e29000 r-xp 00000000 03:03 205828 /lib/libc-2.3.5.so
38 32e29000-32e36000 ---p 00123000 03:03 205828 /lib/libc-2.3.5.so
39 32e36000-32e38000 r--p 00130000 03:03 205828 /lib/libc-2.3.5.so
40 32e38000-32e3c000 rw-p 00132000 03:03 205828 /lib/libc-2.3.5.so
41 32e3c000-32e3e000 rw-p 32e3c000 00:00 0
42 32e3e000-32e40000 r-xp 00000000 03:03 205830 /lib/libdl-2.3.5.so
43 32e40000-32e4e000 ---p 00002000 03:03 205830 /lib/libdl-2.3.5.so
44 32e4e000-32e4f000 r--p 00010000 03:03 205830 /lib/libdl-2.3.5.so
45 32e4f000-32e50000 rw-p 00011000 03:03 205830 /lib/libdl-2.3.5.so
46 7904f000-79065000 rw-p 7904f000 00:00 0 [stack]
47
48
49 --
50 Ned Ludd <solar@g.o>
51 Gentoo Linux
52
53 --
54 gentoo-hardened@g.o mailing list