Gentoo Archives: gentoo-hardened

From: "Tóth Attila" <atoth@××××××××××.hu>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] bonding module auto-loading
Date: Sat, 21 May 2011 13:18:41
Message-Id: c871866224297427f150eb67eed88e4a.squirrel@atoth.sote.hu
In Reply to: Re: [gentoo-hardened] bonding module auto-loading by Ed W
1 2011.Május 21.(Szo) 14:36 időpontban Ed W ezt írta:
2 >> I want the round-robin, what's bothering me is the miimon
3 >> which I can't change from 0 which means no mii mon which is not good.
4 >
5 > # cat /sys/class/net/bond0/bonding/miimon
6 > 100
7 > # cat /sys/class/net/bond0/bonding/mode
8 > 802.3ad 4
9 >
10 > # cat /sys/class/net/bond1/bonding/mode
11 > balance-rr 0
12 > # cat /sys/class/net/bond1/bonding/miimon
13 > 100
14 >
15 > Not sure what values are sensible though?
16 >
17 > Good luck
18 >
19 > Ed W
20
21 Previously I could proprely configure compiled-in bonding (for ages). Now
22 I can only configure it by passing module parameters.
23
24 I don't know if it's openrc or my kernel, which is 2.6.38-hardened-r4. The
25 kernel is definetly newer than yours. I don't know if the module-lockdown
26 method provided by grsecurity influences tuning compiled-in components or
27 not...
28
29 What do you get if you try to echo something into a bonding/mode file? It
30 might be possible, that openrc executes the command earlier now than
31 before.
32
33 I can live with bonding compiled in as a module, but the behavior has been
34 changed somehow. And I still don't know how I can fix the error message
35 supplied by grsec - apart from the workaround.
36
37 Regards,
38 Dw.
39 --
40 dr Tóth Attila, Radiológus, 06-20-825-8057
41 Attila Toth MD, Radiologist, +36-20-825-8057