Gentoo Archives: gentoo-hardened

From: "Tóth Attila" <atoth@××××××××××.hu>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] New messages in log with hs-3.11.9-r1
Date: Wed, 27 Nov 2013 18:59:20
Message-Id: 8d0ef20241dd46243bf395e8b97986c8.squirrel@atoth.sote.hu
In Reply to: [gentoo-hardened] New messages in log with hs-3.11.9-r1 by "Tóth Attila"
1 I know I can switch to systemd - since Gnome 3.8 (to my great
2 disappointment) forcefully pushes users to move on, but the unit files are
3 still lacking. One mentionable example is iptables. No iptables unit file.
4 I may (or might) have enough time for this by the end of the year.
5
6 BTW: any of you ever operated a machine with bonding using systemd? I've
7 found no documentation regarding the official way to achieve that. I'm
8 curious before I start hacking in my non-professional way.
9
10 Thanks:
11 Dw.
12 --
13 dr Tóth Attila, Radiológus, 06-20-825-8057
14 Attila Toth MD, Radiologist, +36-20-825-8057
15
16 2013.November 27.(Sze) 19:49 időpontban "Tóth Attila" ezt írta:
17 > After bumping the kernel and gradm versions, I see these in the log:
18 > grsec: denied exec of usermode helper binary
19 > /lib64/rc/sh/cgroup-release-agent.sh located outside of /sbin
20 > The file is definitely located outside of /sbin. It belongs to openrc.
21 > What can be the best solution to handle this issue?
22 >
23 > Reloading policy knocks out the machine:
24 > https://forums.grsecurity.net/viewtopic.php?f=3&t=3881
25 > --
26 > dr Tóth Attila, Radiológus, 06-20-825-8057
27 > Attila Toth MD, Radiologist, +36-20-825-8057
28 >
29 >
30 >
31 >
32 >

Replies

Subject Author
Re: [gentoo-hardened] New messages in log with hs-3.11.9-r1 Alexander Tsoy <alexander@××××.me>