[gentoo-hardened] Can't get fully functional (kde) desktop with SELinux

2012-08-21 Thread f.p.barile@gmail.com2
Hello to all the list. I need your help to understand what's wrong here. I tried to convert my laptop to a selinux profile (targeted) several times following the documentation step by step. Now, the last time I tried, I'm using 2.20120725-r3 policies from the hardened-dev overlay, but I found the s

Re: [gentoo-hardened] Can't get fully functional (kde) desktop with SELinux

2012-08-21 Thread Sven Vermeulen
On Tue, Aug 21, 2012 at 09:14:39AM +0200, f.p.barile@gmail.com2 wrote: > Hello to all the list. I need your help to understand what's wrong here. > I tried to convert my laptop to a selinux profile (targeted) several > times following the documentation step by step. Hi F.P. First of all, thanks

Re: [gentoo-hardened] PaX kills Tor due to overflow

2012-08-21 Thread Anthony G. Basile
On 08/20/2012 01:59 PM, Pavel Labushev wrote: On Mon, 20 Aug 2012 16:16:27 +0100 Karl-Johan Karlsson wrote: My Tor node gets killed once every day or two with the following message in dmesg: PAX: size overflow detected in function tcp_recvmsg net/ipv4/tcp.c:1696 That's a size_overflow f

Re: [gentoo-hardened] PaX kills Tor due to overflow

2012-08-21 Thread Maxim Kammerer
On Tue, Aug 21, 2012 at 11:44 PM, Anthony G. Basile wrote: > That sounds about right. I'm not hitting this with tor-ramdisk, a tiny > ramdisk image for running tor relays, built with latest tor + busybox + > hardened kernel. I have PAX_SIZE_OVERFLOW off. I didn't even try turning > it on since

Re: [gentoo-hardened] PaX kills Tor due to overflow

2012-08-21 Thread PaX Team
On 22 Aug 2012 at 1:37, Maxim Kammerer wrote: > On Tue, Aug 21, 2012 at 11:44 PM, Anthony G. Basile > wrote: > > That sounds about right. I'm not hitting this with tor-ramdisk, a tiny > > ramdisk image for running tor relays, built with latest tor + busybox + > > hardened kernel. I have PAX_SIZ

Re: [gentoo-hardened] PaX kills Tor due to overflow

2012-08-21 Thread Maxim Kammerer
On Wed, Aug 22, 2012 at 2:19 AM, PaX Team wrote: > did your thorough search include the grsec mailing list archives? if > you google '"size_overflow" pax' then it's like the first hit there ;). Yes! :) I did read that post, and what I (probably wrongly) gathered from it was that the plugin was de