1 |
>> >> My website seems a bit slower since I enabled grsecurity on that |
2 |
>> >> system. Is that typical? Is it most likely due to MPROTECT, or |
3 |
>> >> something else? |
4 |
>> > |
5 |
>> > can you quantify this slowdown? and what grsec/pax features did you enable? |
6 |
>> |
7 |
>> I enabled the grsecurity "Gentoo (server)" profile in the hardened |
8 |
>> kernel. |
9 |
> |
10 |
> ok, is PAGEEXEC enabled (and SEGMEXEC isn't) and is your cpu some P4 variant |
11 |
> without NX support? that's about the only situation where you should see an |
12 |
> observable slowdown, otherwise i doubt you can percieve a few % without |
13 |
> actual measurements. so if neither is your case, it's definitely worth an |
14 |
> investigation. |
15 |
|
16 |
Very close. PAGEEXEC is enabled, but so is SEGMEXEC. My CPU is a |
17 |
P4-2.8, and I'm not sure about NX support but these are the flags: |
18 |
|
19 |
fpu vme de pse tsc msr pae mce cx8 apic mtrr pge mca cmov pat pse36 |
20 |
clflush dts acpi mmx fxsr sse sse2 ss ht tm pbe constant_tsc pebs bts |
21 |
pni monitor ds_cpl cid xtpr |
22 |
|
23 |
- Grant |