Gentoo Archives: gentoo-hardened

From: "Tóth Attila" <atoth@××××××××××.hu>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] grsec warnings and segfaults during emerging world
Date: Tue, 23 Apr 2013 17:51:16
Message-Id: 7805ecf2b13696d240de20c664ef2900.squirrel@atoth.sote.hu
In Reply to: [gentoo-hardened] grsec warnings and segfaults during emerging world by SZENTE Balint
1 What marking does grub-probe looses during install?
2 What marking python needs?
3
4 I have to admit: I keep the good old chpax init.d and conf.d file, but
5 modified it to make it up-to-date...
6 --
7 dr Tóth Attila, Radiológus, 06-20-825-8057
8 Attila Toth MD, Radiologist, +36-20-825-8057
9
10 2013.Április 23.(K) 09:03 időpontban SZENTE Balint ezt írta:
11 > Hello!
12 >
13 >
14 > After several years of "regular" Gentoo I decided to move to Hardened
15 > Gentoo using grsecurity & PaX.
16 >
17 > I tried initially the XT marking, but I switched back to PT marking
18 > because of bug #465000.
19 >
20 > Everything seems fine and seems to work, but I noticed some weird logs
21 > in the kernel log when I did yesterday an "emerge -e @world".
22 >
23 > I observed that for several packages in the configure step grsec is
24 > reporting resource overstep denials. But what really concerns me the 2
25 > segfaults: readline and gcc. Please see attached kern.log file. What
26 > confuses me is that both packages build fine beside these errors.
27 >
28 > Is this "normal" for grsec hardened kernels? Should I just ignore those
29 > grsec messages and segfaults? I would really appreciate some hints about
30 > these.
31 >
32 > I attached also my kernel options related to security.
33 >
34 > Regards,
35 > Balint Szente
36 >

Replies

Subject Author
Re: [gentoo-hardened] grsec warnings and segfaults during emerging world SZENTE Balint <balint@×××××××××.ro>