Gentoo Archives: gentoo-hardened

From: Kevin Chadwick <ma1l1ists@××××××××.uk>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] The last browser (opera) to work with grsec by default may be succombing (ptrace).
Date: Mon, 12 Dec 2011 18:53:46
Message-Id: 20111212185417.b8c987c2.ma1l1ists@yahoo.co.uk
In Reply to: Re: [gentoo-hardened] The last browser (opera) to work with grsec by default may be succombing (ptrace). by Alex Efros
1 On Mon, 12 Dec 2011 02:05:04 +0200
2 Alex Efros <powerman@××××××××.name> wrote:
3
4 > Hi!
5 >
6 > I've just updated to opera-11.60.1185 and firefox-bin-8.0.
7 > Opera work just fine,
8
9 Interesting and thanks, I have the same build but as I should have
10 stated earlier just a GrSec+Pax kernel on arch linux and 11.52 works
11 fine but 11.60 fails with ptrace denied by grsec. Do you have the
12 following line set to y in your kernel config?
13
14 "CONFIG_GRKERNSEC_HARDEN_PTRACE=y"
15
16 > but firefox fail to start (hangs using 100% CPU)
17 > because paxmarking -m isn't enough. To fix firefox paxmarking -r needed too:
18 > paxctl -r /opt/firefox/firefox
19 >
20 > I'm using only GrSec+PaX, so there are may be also SELinux/RBAC related issues.
21
22 Yeah it's been like that for a while. I think gentoo-hardened
23 automatically sets those pax flags. See this link.
24
25 "http://hardenedgentoo.blogspot.com/2011/06/firefox-5-with-mprotect-onof-course.html"
26
27 --
28 Kc

Replies