On 11/27/2013 01:49 PM, "Tóth Attila" wrote:
After bumping the kernel and gradm versions, I see these in the log:
grsec: denied exec of usermode helper binary
/lib64/rc/sh/cgroup-release-agent.sh located outside of /sbin
The file is definitely located outside of /sbin. It belongs to openrc.
What can be the best solution to handle this issue?
Reloading policy knocks out the machine:
https://forums.grsecurity.net/viewtopic.php?f=3&t=3881
I should probably have emailed the list to warn people about 3.0. It is
fresh off the assembly line and there are issues. I hit one myself but
didn't report it yet because a new release just came out.
I will not stabilize a 3.0 anytime soon. Please use a 2.9.1 of the time
being:
1) any 2.6.32
2) <= 3.2.52-r6
3) <= 3.11.9
Currently the tree has only 2.9.1. The overlay has 3.0.
Thank you Toth for pushing that report upstream.
--
Anthony G. Basile, Ph. D.
Chair of Information Technology
D'Youville College
Buffalo, NY 14201
(716) 829-8197