Gentoo Archives: gentoo-hardened

From: pageexec@××××××××.hu
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] Grsecurity slows down a web server?
Date: Sat, 24 Jan 2009 16:45:58
Message-Id: 497B459F.21727.1AE408@pageexec.freemail.hu
In Reply to: Re: [gentoo-hardened] Grsecurity slows down a web server? by Grant
1 On 23 Jan 2009 at 9:16, Grant wrote:
2
3 > > There is no "nx" in your cpuinfo flags. Therefore, your P4 does not
4 > > have the hardware NX bit (or XD bit in Intel wording)
5 >
6 > I do have SEGMEXEC enabled though. Should it still be noticeably (but
7 > slightly) slower? If so, I suppose the best thing to do would be to
8 > upgrade the CPU?
9
10 if both PAGEEXEC and SEGMEXEC are enabled, PaX uses one of them by default,
11 depending on whether your CPU and kernel config supports the NX bit or not
12 (yes, you need to enable PAE support in the kernel in order to actually be
13 able to use the NX bit). in your case the CPU has no NX support so PaX should
14 have fallen back to SEGMEXEC (pspax could confirm it) and not PAGEEXEC. can
15 you check what really happened? because if PAGEEXEC was chosen by default on
16 your CPU, there's a bug somewhere...

Replies

Subject Author
Re: [gentoo-hardened] Grsecurity slows down a web server? Grant <emailgrant@×××××.com>