Gentoo Archives: gentoo-hardened

From: mRyOuNg <mryoung@×××××××××.net>
To: gentoo-hardened@l.g.o
Subject: [gentoo-hardened] Tips for VMware Workstation with Hardened Profile ?
Date: Sun, 22 Apr 2012 00:02:15
Message-Id: 4F9341BF.7010004@soundbomb.net
1 Hi,
2
3 I've just build vmware-workstation on a hardened box with 3.0.4 hardened
4 kernel ...
5 I emerged the vmware product with server flag, to be able to remotely
6 connect to it ...
7 vmware init script start, and load modules into kernel perfectly ... but,
8
9 When i try to start the vmware-workstation-server init script, i get the
10 following grsec log:
11
12 Apr 22 01:00:23 kernel: grsec: From denied access of range 0 -> 100000
13 in /dev/mem by
14 /opt/vmware/lib/vmware/bin/vmware-hostd[vmware-hostd:11737] uid/euid:0/0
15 gid/egid:0/0, parent /sbin/init[init:1] uid/euid:0/0 gid/egid:0/0
16 Apr 22 01:02:21 kernel: grsec: From : Abort occurred at
17 0000000000002ed3 in
18 /opt/vmware/lib/vmware/bin/vmware-vim-cmd[vmware-vim-cmd:11987]
19 uid/euid:0/0 gid/egid:0/0, parent
20 /opt/vmware/lib/vmware/bin/vmware-vim-cmd[vmware-vim-cmd:11886]
21 uid/euid:0/0 gid/egid:0/0
22 Apr 22 01:02:21 kernel: grsec: From denied resource overstep by
23 requesting 4096 for RLIMIT_CORE against limit 0 for
24 /opt/vmware/lib/vmware/bin/vmware-vim-cmd[vmware-vim-cmd:11987]
25 uid/euid:0/0 gid/egid:0/0, parent
26 /opt/vmware/lib/vmware/bin/vmware-vim-cmd[vmware-vim-cmd:11886]
27 uid/euid:0/0 gid/egid:0/0
28
29 After some googling (without any success), I decided to post here to get
30 some advices from people already running this product with the same
31 configuration (I'm not sure paxctl will change anything here)...
32
33 Anyone around can help ?
34
35 Thanks in advance for your answer.
36
37 Cya
38
39 --
40 . mRyOuNg :: [ SoundBomB ] .
41 mail: mryoung@×××××××××.net
42 web : mryoung.soundbomb.net