Re: [gentoo-hardened] GrSecurity: slow learning mode & incomplete policy

2014-09-29 Thread Michel Arboi
On Thu, Sep 18, 2014 at 12:31 AM, Anthony G. Basile wrote: > 2) The cpu problems seems like a genuine bug. One of the commands finished: # time gradm -F -L /tmp/learning.logs -O /etc/grsec/policy4 ... Beginning full learning object reduction for subject /...done. Beginning full learning object r

Re: [gentoo-hardened] GrSecurity: slow learning mode & incomplete policy

2014-09-20 Thread PaX Team
On 20 Sep 2014 at 13:20, Michel Arboi wrote: > On Fri, Sep 19, 2014 at 9:09 PM, PaX Team wrote: > > did you email spender with your problem and logs? > > No. What's his e-mail? i put him on cc in my previous mail, you could have just hit 'reply all'...

Re: [gentoo-hardened] GrSecurity: slow learning mode & incomplete policy

2014-09-20 Thread Michel Arboi
On Fri, Sep 19, 2014 at 9:09 PM, PaX Team wrote: > did you email spender with your problem and logs? No. What's his e-mail?

Re: [gentoo-hardened] GrSecurity: slow learning mode & incomplete policy

2014-09-19 Thread PaX Team
On 18 Sep 2014 at 15:28, Michel Arboi wrote: > > 2) The cpu problems seems like a genuine bug. > > Still running by the way. > 21170 pts/2RL+ 7004:37 gradm -L /tmp/learning.logs -O /tmp/policy > 31255 pts/1RL+ 18605:09 gradm -F -L /tmp/learning.logs -O > /etc/grsec/policy4 > (I tried b

Re: [gentoo-hardened] GrSecurity: slow learning mode & incomplete policy

2014-09-18 Thread Michel Arboi
On Thu, Sep 18, 2014 at 12:31 AM, Anthony G. Basile wrote: > I don't see any, to be honest. 1) are you sure fetchnews ran at least once > during the learning? Yes. # grep fetchnews learning.logs | grep -v /backup | wc -l 132 # grep /etc/cron.daily/fetchnews learning.logs | grep -v /backup | wc

Re: [gentoo-hardened] GrSecurity: slow learning mode & incomplete policy

2014-09-17 Thread Anthony G. Basile
On 09/14/14 08:28, Michel Arboi wrote: I have some troubles with GrSecurity learning mode and did not find any answer in https://en.wikibooks.org/wiki/Grsecurity/The_Administration_Utility#Learning_Mode Their ML appears to be dead, or restricted to announces now. 1) I let "gradm -F -L ..." run