[gentoo-hardened] NFS server on SELinux

2010-07-16 Thread Karl-Johan Karlsson
me open } ; allow nfsd_t user_home_t : fifo_file { ioctl read write create getattr setattr lock append unlink link rename open } ; Is there a way to get the kernel nfsd thread to run as nfsd_t instead of kernel_t? -- Karl-Johan Karlsson

[gentoo-hardened] PaX kills Tor due to overflow

2012-08-20 Thread Karl-Johan Karlsson
Is there a way to figure out where Tor goes wrong and provokes this error? No core dump is produced, and not even running Tor under GDB helps - execution ends with: Program terminated with signal SIGKILL, Killed. The program no longer exists. -- Karl-Johan Karlsson signature.asc

Re: [gentoo-hardened] PaX kills Tor due to overflow

2012-08-20 Thread Karl-Johan Karlsson
Hardware (EPT/RVI Processor Support) ---> Virtualization Software (KVM) ---> Required Priorities (Security) ---> I'm not sure when these crashes started, but I've seen them at least since net-misc/tor-0.2.3.19_rc. I'm now on net-misc/tor-0.2.3.20_rc.

[gentoo-hardened] XATTR_PAX, paxmark.sh, elog, icedtea, and maybe more

2014-12-13 Thread Karl-Johan Karlsson
nce PAX_XATTR_PAX_FLAGS is set. Which brings us to problem number three: why aren't xattrs working in $PORTAGE_TMPDIR on ext3 when they are in /bin on ext4? Problems one and two are clearly bugs, one in sys-apps/elfix and two in sys- apps/elfix or the documentation. Should I file them in Bugz

Re: [gentoo-hardened] XATTR_PAX, paxmark.sh, elog, icedtea, and maybe more

2014-12-14 Thread Karl-Johan Karlsson
PT_PAX: -em-- XATTR_PAX : -em-- ./dev-java/icedtea-7.2.5.3/work/icedtea-2.5.3/openjdk.build-boot/j2sdk- image/jre/bin/java: PT_PAX: -em-- XATTR_PAX : -em-- ./dev-java/icedtea-7.2.5.3/work/icedtea-2.5.3/openjdk.build/bin/java: PT_PAX: -em-- XATTR_PAX :

Re: [gentoo-hardened] XATTR_PAX, paxmark.sh, elog, icedtea, and maybe more

2014-12-18 Thread Karl-Johan Karlsson
On Thu 18 Dec 2014 19.58.11 Anthony G. Basile wrote: > On 12/13/14 18:52, Karl-Johan Karlsson wrote: > > So it works on ext4, but not ext3, even though both have the ext_attr flag > > on disk. Any difference in kernel support? > > Because on ext3 you need to add user_xattr

Re: [gentoo-hardened] XATTR_PAX, paxmark.sh, elog, icedtea, and maybe more

2014-12-19 Thread Karl-Johan Karlsson
On Fri 19 Dec 2014 18.00.16 James Taylor wrote: > On 2014/12/19 17:08, Karl-Johan Karlsson wrote: > > Unfortunately, the machine is in production, and since it works without > > that option when using the ext4 code to read ext3, I would prefer to > > leave it alone for

Re: [gentoo-hardened] XATTR_PAX, paxmark.sh, elog, icedtea, and maybe more

2014-12-21 Thread Karl-Johan Karlsson
t everyone standardise? On my preferred options, naturally :) -- Karl-Johan Karlsson signature.asc Description: This is a digitally signed message part.