I will refrain from using this new version of 3.0 grsec+gradm. But will give it a try when a new version comes out, anyways.
I have to also prepare to invest some energy into connection tracking helper assignments. Dw. -- dr Tóth Attila, Radiológus, 06-20-825-8057 Attila Toth MD, Radiologist, +36-20-825-8057 2013.November 27.(Sze) 20:05 időpontban Anthony G. Basile ezt írta: > On 11/27/2013 01:49 PM, "Tóth Attila" wrote: >> After bumping the kernel and gradm versions, I see these in the log: >> grsec: denied exec of usermode helper binary >> /lib64/rc/sh/cgroup-release-agent.sh located outside of /sbin >> The file is definitely located outside of /sbin. It belongs to openrc. >> What can be the best solution to handle this issue? >> >> Reloading policy knocks out the machine: >> https://forums.grsecurity.net/viewtopic.php?f=3&t=3881 >> > > I should probably have emailed the list to warn people about 3.0. It is > fresh off the assembly line and there are issues. I hit one myself but > didn't report it yet because a new release just came out. > > I will not stabilize a 3.0 anytime soon. Please use a 2.9.1 of the time > being: > > 1) any 2.6.32 > > 2) <= 3.2.52-r6 > > 3) <= 3.11.9 > > Currently the tree has only 2.9.1. The overlay has 3.0. > > Thank you Toth for pushing that report upstream. > > -- > Anthony G. Basile, Ph. D. > Chair of Information Technology > D'Youville College > Buffalo, NY 14201 > (716) 829-8197 > >