Gentoo Archives: gentoo-hardened

From: Alexander Tsoy <alexander@××××.me>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] "grsec: denied RWX mprotect" doesn't kill app anymore
Date: Sat, 01 Nov 2014 22:04:38
Message-Id: 20141102010430.5d1062fc@home.puleglot
In Reply to: Re: [gentoo-hardened] "grsec: denied RWX mprotect" doesn't kill app anymore by "Amadeusz Sławiński"
1 В Sat, 1 Nov 2014 11:21:51 +0100
2 Amadeusz Sławiński <amade@××××××.net> пишет:
3
4 > On Sat, 1 Nov 2014 12:08:23 +0200
5 > Alex Efros <powerman@××××××××.name> wrote:
6 >
7 > > Hi!
8 > >
9 > > I wonder is something was changed in handling "grsec: denied RWX
10 > > mprotect"? Previously when I see this in kernel log it usually
11 > > result in killing app (and I've to run `paxctl-ng -m /that/app`),
12 > > but now it looks like this doesn't happens anymore. For example:
13 > >
14 >
15 > https://bugs.freedesktop.org/show_bug.cgi?id=73473
16 >
17 > OpenGL apps fallback to software rendering if they can't mmap
18 > executable memory.
19
20 Alex uses nvidia blob, so fdo bug is unrelated here:
21
22 > > # eselect opengl list
23 > > Available OpenGL implementations:
24 > > [1] nvidia *
25 > > [2] xorg-x11
26
27 --
28 Alexander Tsoy