Gentoo Archives: gentoo-hardened

From: "Anthony G. Basile" <basile@××××××××××××××.edu>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] PaX kills Tor due to overflow
Date: Tue, 21 Aug 2012 21:03:34
Message-Id: 5033F318.4010009@opensource.dyc.edu
1 On 08/20/2012 01:59 PM, Pavel Labushev wrote:
2 > On Mon, 20 Aug 2012 16:16:27 +0100
3 > Karl-Johan Karlsson<creideiki+gentoo-hardened@××××××××××.se> wrote:
4 >
5 >> My Tor node gets killed once every day or two with the following message in
6 >> dmesg:
7 >>
8 >> PAX: size overflow detected in function tcp_recvmsg net/ipv4/tcp.c:1696
9 >
10 > That's a size_overflow false positive. Try some of the recent grsec
11 > patches, it might be fixed there. Or disable PAX_SIZE_OVERFLOW and
12 > rebuild your kernel.
13
14 That sounds about right. I'm not hitting this with tor-ramdisk, a tiny
15 ramdisk image for running tor relays, built with latest tor + busybox +
16 hardened kernel. I have PAX_SIZE_OVERFLOW off. I didn't even try
17 turning it on since its still very experimental.
18
19
20 --
21 Anthony G. Basile, Ph. D.
22 Chair of Information Technology
23 D'Youville College
24 Buffalo, NY 14201
25 (716) 829-8197

Replies

Subject Author
Re: [gentoo-hardened] PaX kills Tor due to overflow Maxim Kammerer <mk@×××.su>