Gentoo Archives: gentoo-hardened

From: Matthew Summers <msummers42@×××××.com>
To: gentoo-hardened@l.g.o
Subject: [gentoo-hardened] grsec: denied RWX mprotect AND execution attempt ksplashqml plasmashell kwin_x11 kscreenlocker_greet
Date: Sun, 26 Mar 2017 01:45:59
Message-Id: CADhbkg=4Z6w3fmeZ2me1unf_GvJ81eNBomVf9SkXHQ4ja5x43w@mail.gmail.com
1 Hello,
2
3 I am experiencing task terminated & segfaults with KDE Plasma 5.8.6
4 following the recent stable upgrade from 5.8.5.
5
6 I am curious is anyone on this list is using Plasma 5.8.6 with
7 hardened-sources successfully.
8
9 Previously, Plasma functioned very well. I've used it every day for quite
10 awhile. Now, I must disable PAX mprotect to use this desktop environment
11 for the following binaries:
12 /usr/bin/plasmashell
13 /usr/bin/ksmserver
14 /usr/bin/ksplashqml
15 /usr/lib64/libexec/kscreenlocker_greet
16 /usr/lib64/libexec/ksmserver-logout-greeter
17
18 Even after that, kscreenlock_greet segfaults when I lock my session. So
19 this is basically unusable for daily work.
20
21 The system is running sys-kernel/hardened-sources-4.8.17-r2 on the hardened
22 amd64 no-multilib profile. I cobbled together sufficient USE from the
23 plasma profile to produce what was a very nice, minimal desktop environment
24 (-jit of course). I use a stable toolchain.
25
26 Other desktop environments work just fine, at least Awesome and Openbox.
27 Various KDE apps work fine too, like Konsole, Dolphin, and Gwenview.
28
29 Anyone have any pointers as to what USE or new options might be causing
30 this? Should I simply upgrade to plasma 5.9.4?
31
32 Thanks a ton!
33 Matt
34
35 --
36 M. Summers
37 aka quantumsummers
38
39 "...there are no rules here -- we're trying to accomplish something."
40 - Thomas A. Edison