Gentoo Archives: gentoo-hardened

From: Balint Szente <balint@×××××××××.ro>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] nvidia.ko with Grsecurity & PaX kernel
Date: Wed, 11 Sep 2013 20:44:17
Message-Id: 20130911234407.623b277b@inspiro
In Reply to: Re: [gentoo-hardened] nvidia.ko with Grsecurity & PaX kernel by "Amadeusz Sławiński"
1 On Wed, 11 Sep 2013 19:55:13 +0200
2 Amadeusz Sławiński <amade@××××××.net> wrote:
3
4 > [...]
5 > > CONFIG_PAX_KERNEXEC_PLUGIN_METHOD_OR=y
6 > > CONFIG_PAX_KERNEXEC_PLUGIN_METHOD="or"
7 > CONFIG_PAX_KERNEXEC_PLUGIN_METHOD_OR:
8 > This method is incompatible with binary only modules but
9 > has a lower runtime overhead.
10 >
11 > Try using bts
12
13 Yes, of course! Stupid me. This was it... thank you very much.
14
15 Now there is another issue:
16 kernel: grsec: denied RWX mmap of /usr/lib64/opengl/nvidia/lib/libGL.so.325.15
17 on pretty much everything, but it is a known issue:
18 <https://bugs.gentoo.org/show_bug.cgi?id=433121>
19
20 So I disabled CONFIG_PAX_MPROTECT for the moment.

Replies

Subject Author
Re: [gentoo-hardened] nvidia.ko with Grsecurity & PaX kernel Hinnerk van Bruinehsen <h.v.bruinehsen@×××××××××.de>
Re: [gentoo-hardened] nvidia.ko with Grsecurity & PaX kernel Alex Efros <powerman@××××××××.name>