Gentoo Archives: gentoo-hardened

From: Michel Arboi <michel.arboi@×××××.com>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] GrSecurity: slow learning mode & incomplete policy
Date: Thu, 18 Sep 2014 13:28:33
Message-Id: CAJPBRYMm=XBQu7YE5+uQUJ62NHehA4yopC8RLBt0W+XZO-KUKw@mail.gmail.com
In Reply to: Re: [gentoo-hardened] GrSecurity: slow learning mode & incomplete policy by "Anthony G. Basile"
1 On Thu, Sep 18, 2014 at 12:31 AM, Anthony G. Basile
2 <basile@××××××××××××××.edu> wrote:
3 > I don't see any, to be honest. 1) are you sure fetchnews ran at least once
4 > during the learning?
5
6 Yes.
7 # grep fetchnews learning.logs | grep -v /backup | wc -l
8 132
9 # grep /etc/cron.daily/fetchnews learning.logs | grep -v /backup | wc -l
10 42
11 #
12
13 > 2) The cpu problems seems like a genuine bug.
14
15 Still running by the way.
16 21170 pts/2 RL+ 7004:37 gradm -L /tmp/learning.logs -O /tmp/policy
17 31255 pts/1 RL+ 18605:09 gradm -F -L /tmp/learning.logs -O
18 /etc/grsec/policy4
19 (I tried both commands, just in case)
20
21 The processor is not very fast (AMD Athlon II X4 610e) but this is really long.

Replies

Subject Author
Re: [gentoo-hardened] GrSecurity: slow learning mode & incomplete policy PaX Team <pageexec@××××××××.hu>