Gentoo Archives: gentoo-hardened

From: Grant <emailgrant@×××××.com>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] Grsecurity slows down a web server?
Date: Sat, 24 Jan 2009 16:51:53
Message-Id: 49bf44f10901240851v2f71f26bmc704e95fd0140ad3@mail.gmail.com
In Reply to: Re: [gentoo-hardened] Grsecurity slows down a web server? by pageexec@freemail.hu
1 >> > There is no "nx" in your cpuinfo flags. Therefore, your P4 does not
2 >> > have the hardware NX bit (or XD bit in Intel wording)
3 >>
4 >> I do have SEGMEXEC enabled though. Should it still be noticeably (but
5 >> slightly) slower? If so, I suppose the best thing to do would be to
6 >> upgrade the CPU?
7 >
8 > if both PAGEEXEC and SEGMEXEC are enabled, PaX uses one of them by default,
9 > depending on whether your CPU and kernel config supports the NX bit or not
10 > (yes, you need to enable PAE support in the kernel in order to actually be
11 > able to use the NX bit). in your case the CPU has no NX support so PaX should
12 > have fallen back to SEGMEXEC (pspax could confirm it) and not PAGEEXEC. can
13 > you check what really happened? because if PAGEEXEC was chosen by default on
14 > your CPU, there's a bug somewhere...
15
16 Nope, you guys are absolutely right. It falls back to peMRS whether
17 or not I enable PAGEEXEC since I don't have the nx flag.
18
19 - Grant

Replies

Subject Author
Re: [gentoo-hardened] Grsecurity slows down a web server? pageexec@××××××××.hu