Gentoo Archives: gentoo-hardened

From: "Tóth Attila" <atoth@××××××××××.hu>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] New messages in log with hs-3.11.9-r1
Date: Sat, 14 Dec 2013 02:34:25
Message-Id: 3d0adccf0e454f345b5635fc556ef37d.squirrel@atoth.sote.hu
In Reply to: Re: [gentoo-hardened] New messages in log with hs-3.11.9-r1 by "Anthony G. Basile"
1 Just to let you know:
2 I've retested gradm-3.0 using hardened-sources-3.12.4 and the system seems
3 to behave.
4 Reloading policy no longer renders the machine unresponsive.
5 Log messages related to user mode helper binary have also gone.
6
7 Regards: Dw.
8 --
9 dr Tóth Attila, Radiológus, 06-20-825-8057
10 Attila Toth MD, Radiologist, +36-20-825-8057
11
12 2013.November 27.(Sze) 20:05 időpontban Anthony G. Basile ezt írta:
13 > On 11/27/2013 01:49 PM, "Tóth Attila" wrote:
14 >> After bumping the kernel and gradm versions, I see these in the log:
15 >> grsec: denied exec of usermode helper binary
16 >> /lib64/rc/sh/cgroup-release-agent.sh located outside of /sbin
17 >> The file is definitely located outside of /sbin. It belongs to openrc.
18 >> What can be the best solution to handle this issue?
19 >>
20 >> Reloading policy knocks out the machine:
21 >> https://forums.grsecurity.net/viewtopic.php?f=3&t=3881
22 >>
23 >
24 > I should probably have emailed the list to warn people about 3.0. It is
25 > fresh off the assembly line and there are issues. I hit one myself but
26 > didn't report it yet because a new release just came out.
27 >
28 > I will not stabilize a 3.0 anytime soon. Please use a 2.9.1 of the time
29 > being:
30 >
31 > 1) any 2.6.32
32 >
33 > 2) <= 3.2.52-r6
34 >
35 > 3) <= 3.11.9
36 >
37 > Currently the tree has only 2.9.1. The overlay has 3.0.
38 >
39 > Thank you Toth for pushing that report upstream.
40 >
41 > --
42 > Anthony G. Basile, Ph. D.
43 > Chair of Information Technology
44 > D'Youville College
45 > Buffalo, NY 14201
46 > (716) 829-8197
47 >
48 >