Re: [gentoo-hardened] "grsec: denied RWX mprotect" doesn't kill app anymore

2014-11-01 Thread Amadeusz Sławiński
On Sat, 1 Nov 2014 12:08:23 +0200 Alex Efros wrote: > Hi! > > I wonder is something was changed in handling "grsec: denied RWX > mprotect"? Previously when I see this in kernel log it usually result > in killing app (and I've to run `paxctl-ng -m /that/app`), but now it > looks like this doesn't

Re: [gentoo-hardened] SELinux userspace patches in hardened-dev?

2014-08-06 Thread Amadeusz Sławiński
On Tue, 5 Aug 2014 12:47:32 + Sven Vermeulen wrote: > Hi all > > Is it ok if I create a branch in the hardened-dev repo (called > "selinux-userland") which contains the patches for the various SELinux > userland packages we maintain? > > Or would you prefer a different way to centrally mana

Re: [gentoo-hardened] die() required on pax-mark?

2013-10-21 Thread Amadeusz Sławiński
On Sun, 20 Oct 2013 19:39:10 -0400 "Anthony G. Basile" wrote: > On 10/19/2013 08:56 PM, Michael Orlitzky wrote: > > On 10/19/2013 08:29 PM, Anthony G. Basile wrote: > >> > >> Can you check to see if the || die is required only on packages > >> before EAPI = 5? Or is it on all EAPI versions? > >

Re: [gentoo-hardened] nvidia.ko with Grsecurity & PaX kernel

2013-09-11 Thread Amadeusz Sławiński
On Wed, 11 Sep 2013 19:57:03 +0300 Balint Szente wrote: > Hello! > > > I have a Dell Inspiron N5110 laptop with Optimus. I used Xorg with the > Intel driver only until now, but I was thinking to start using the > nVidia card as well, because the HDMI output is connected directly to > the nVidia