> as you can read in this new bug report that I submitted:
> 
> GNU debugger employed via Postfix crashed PaX hardened kernel
> https://bugs.gentoo.org/show_bug.cgi?id=541104
> 
> also:
> 
> GNU debugger checking for PaX and refusing to work with it
> https://forums.gentoo.org/viewtopic-t-1011162.html
> 
> and:
> 
> PAX terminating task on /usr/bin/gdb
> http://forums.grsecurity.net/viewtopic.php?f=3&t=4137
> 
> In short, from:
> 
> https://541104.bugs.gentoo.org/attachment.cgi?id=397334
> 
> Feb 23 08:43:51 gbn kernel: [30489.762828] grsec: bruteforce prevention
> initiated for the next 30 minutes or until service restarted, stalling
> each fork 30 seconds.  Please investigate the crash report for
> /usr/bin/gdb[gdb:14515] uid/euid:0/0 gid/egid:0/0, parent
> /usr/bin/gdb[gdb:14507] uid/euid:0/0 gid/egid:0/0
> 
> 
> but, if Postfix is configured correctly, mail is still sent... but the
> scare is ugly...
> 
> Surely, the gdb on such kernel does no work at all, other than the scare
> on the poor user.
> 
> I think it would be a good thing to post a line that reflects this
> issue, and warns Grsec-hardened users of it, in the:
> 
> http://www.postfix.org/DEBUG_README.html

I fear this is not a Postfix issue. You always will have trouble with gdb 
debugging under Gentoo hardening. And the kernel did not crash as you reported. 
It simply put a line in the message buffer informing you about issues ;-)

As I had similar problems with other software under Gentoo, I did a trick:

I also installed gentoo-sources and if I really want to do debugging, I reboot 
into the gentoo-sources kernel.

Even if setting things with paxctl, it will be mostly impossible to get things 
working. I had enormous problems to debug OpenDKIM that way, until I switched 
to another kernel while debugging.

Christian
--
Bachelor of Science Informatik
Erlenwiese 14, 36304 Alsfeld
T: +49 6631 78823400, F: +49 6631 78823409, M: +49 171 9905345
USt-IdNr.: DE225643613, http://www.roessner-network-solutions.com

Attachment: signature.asc
Description: Message signed with OpenPGP using GPGMail

Reply via email to