I will refrain from using this new version of 3.0 grsec+gradm.
But will give it a try when a new version comes out, anyways.

I have to also prepare to invest some energy into connection tracking
helper assignments.

Dw.
-- 
dr Tóth Attila, Radiológus, 06-20-825-8057
Attila Toth MD, Radiologist, +36-20-825-8057

2013.November 27.(Sze) 20:05 időpontban Anthony G. Basile ezt írta:
> On 11/27/2013 01:49 PM, "Tóth Attila" wrote:
>> After bumping the kernel and gradm versions, I see these in the log:
>> grsec: denied exec of usermode helper binary
>> /lib64/rc/sh/cgroup-release-agent.sh located outside of /sbin
>> The file is definitely located outside of /sbin. It belongs to openrc.
>> What can be the best solution to handle this issue?
>>
>> Reloading policy knocks out the machine:
>> https://forums.grsecurity.net/viewtopic.php?f=3&t=3881
>>
>
> I should probably have emailed the list to warn people about 3.0.  It is
> fresh off the assembly line and there are issues.  I hit one myself but
> didn't report it yet because a new release just came out.
>
> I will not stabilize a 3.0 anytime soon.  Please use a 2.9.1 of the time
> being:
>
> 1) any 2.6.32
>
> 2) <= 3.2.52-r6
>
> 3) <= 3.11.9
>
> Currently the tree has only 2.9.1.  The overlay has 3.0.
>
> Thank you Toth for pushing that report upstream.
>
> --
> Anthony G. Basile, Ph. D.
> Chair of Information Technology
> D'Youville College
> Buffalo, NY 14201
> (716) 829-8197
>
>



Reply via email to