the infamous java + grsecurity issue

Discuss usability issues, general maintenance, and general support issues for a grsecurity-enabled system.

the infamous java + grsecurity issue

Postby warchild » Tue Aug 02, 2005 6:32 pm

I've read countless posts on this forum and many sites on the web regarding grsecurity and java.

I believe I found old posts from people running older versions of the Linux kernel, jre/sdk and gresecurity that actually got java running without it getting a SIG11 fairly often.

I've done the suggested chpax commands and even gone as far as 'chpax -pemrxs' all the binaries. Still, every so often I get a SIG11 sent to java.

Things *seem* to be working fine, so that makes me think that the majority of this java application is working fine. But the fact that I get fairly regular logs indicating the SIG11 bothers me and makes me think that something deep dark and ugly is going on.

I'm on debian stable, custom built kernel version 2.4.31 with MEDIUM grsecurity turned on, and j2sdk1.4.2_07.

If anyone has gotten a similarly new configuration with Linux, grsecurity and java working, please let me know what you are running and how you got it working without the frequent SIG11s.

Thanks!
warchild
 
Posts: 1
Joined: Tue Aug 02, 2005 6:25 pm

java and grsecurity

Postby marcolinuz » Wed Aug 31, 2005 4:41 am

Hello,

I had your same configuration in my production server and I had your same problems.

Before today the server works good even if i got frequently and randomly SIGNAL 11 messages.

But today my server has crashed!!!!!!!

I make an integrity test on it, and it tells me that NOTHING was changed on my system.
The last messages on console (and on kern.log) was the java related SIGNAL 11 sent from grsec to the java processes.

After a reboot the server goes on and now it works fine like before the crash, but the messages still continue to trash my kern.log.

I have the insane idea that this isn't only a boring warning message but a real and critial problem.. :O(

Bye.
marcolinuz
 
Posts: 6
Joined: Wed Aug 31, 2005 4:06 am


Return to grsecurity support

cron