Gentoo Archives: gentoo-hardened

From: "Javier J. Martínez Cabezón" <tazok.id0@×××××.com>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] Grsecurity slows down a web server?
Date: Fri, 23 Jan 2009 19:18:17
Message-Id: 897813410901231118v41fbd116u5f605c64e0007f56@mail.gmail.com
In Reply to: Re: [gentoo-hardened] Grsecurity slows down a web server? by Grant
1 PaX ignores nx bit in ia32.
2
3 2009/1/23 Grant <emailgrant@×××××.com>:
4 >> Try 'pspax'. If there is no NX bit and you enable both PAGEEXEC and SEGMEXEC
5 >> it should not be using PAGEEXEC.
6 >
7 > What should I be looking for from pspax? I have to admit it does seem
8 > faster now that I've disabled PAGEEXEC.
9 >
10 > - Grant
11 >
12 >
13 >> http://www.bumpin.org/pics/PaX/pax_performance-2.6.24.png
14 >>
15 >> Gordon Malm (gengor)
16 >>
17 >> On Friday, January 23, 2009 10:14:11 Grant wrote:
18 >>> > [snip]
19 >>> >
20 >>> >> menuconfig isn't letting me disable PAGEEXEC. Maybe it's tied to
21 >>> >> grsecurity "Gentoo (server)"? I don't want to disable that. Maybe I
22 >>> >> should live with the slowdown?
23 >>> >
24 >>> > No you should not.
25 >>> >
26 >>> > After selecting server and saving it. You want to then select "Custom"
27 >>> > that will leave all the options enabled from "server". You then scroll
28 >>> > over to the PaX menu and de-select PAGE and select SEGM.
29 >>> >
30 >>> > Easy as pie. Good luck.
31 >>>
32 >>> Alright, thank you. PAGEEXEC and SEGMEXEC are both selected via
33 >>> Gentoo (server) so I disabled PAGEEXEC. Should I submit a bug too?
34 >>>
35 >>> - Grant
36 >
37 >

Replies

Subject Author
Re: [gentoo-hardened] Grsecurity slows down a web server? Gordon Malm <gengor@g.o>