Gentoo Archives: gentoo-hardened

From: "Anthony G. Basile" <blueness@g.o>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] Changes to the predefined grsec profiles: GRKERNSEC_HARDENED_{SERVER,WORKSTATION,VIRTUALIZATION}
Date: Mon, 02 Jan 2012 18:41:53
Message-Id: 4F01F9F1.7040802@gentoo.org
In Reply to: Re: [gentoo-hardened] Changes to the predefined grsec profiles: GRKERNSEC_HARDENED_{SERVER,WORKSTATION,VIRTUALIZATION} by pageexec@freemail.hu
1 On 01/02/2012 06:14 AM, pageexec@××××××××.hu wrote:
2 > On 2 Jan 2012 at 10:56, Hinnerk van Bruinehsen wrote:
3 >
4 >> - - with PAX_RANDKSTACK enabled I'm not able to sucessfully compile
5 >> glibc-2.14.1-r2 and glibc-2.14.1-r1 (gcc-4.6.2). I get an oops
6 >> (because auf the kernelstack - I think).
7 >
8 > that's interesting, i'd need the oops message (enable kernel symbols in
9 > your config) and your vmlinux (not bzImage) file. you could also try to
10 > apply PaX alone just to be sure it's not a grsec porting issue.
11 >
12
13 Hinnerk, thanks for the report and don't worry, I'm not stabilizing
14 these chagnes anytime soon.
15
16 The sysfs bug doesn't surprise me. Can you either open or bug or just
17 report here exactly what programs break and which work. The problem is
18 the way these programs were written and I'd rather patch them than relax
19 the sysfs restrictions, if possible. Otherwise I'll relax this on the
20 WORKSTATION profile.
21
22 The randkstack <-> glibc is of concern. If you can open a bug for it
23 (or at least pass on your kernel config) I'll try to reproduce and help
24 to get pageexec the details he needs.
25
26
27 --
28 Anthony G. Basile, Ph.D.
29 Gentoo Linux Developer [Hardened]
30 E-Mail : blueness@g.o
31 GnuPG FP : 8040 5A4D 8709 21B1 1A88 33CE 979C AF40 D045 5535
32 GnuPG ID : D0455535

Replies