Page 1 of 1

grsec + 2.4.28 + SMP = break :(

PostPosted: Thu Dec 09, 2004 2:43 am
by SG
Hi

I have a problem with grsec on SMP servers. Servers without SMP (P3) working fine. But servers with SMP (single P4 HT, dual P4 HT) hanging after some times from start. I not have any information from logs and console. With old kernels (2.4.18-26) all working fine.

PostPosted: Sat Jan 22, 2005 4:27 am
by SG
I got grsecurity-2.0-2.4.26.patch (last stable on SMP patch) and rewrote it for 2.4.28 kernel. My servers don`t freeze with it patch. But freeze with 2.24.28 kernel and grsecurity-2.0.2-2.4.28.patch/grsecurity-2.1.0-2.4.28-200501051112.patch also as .27 kernel and grsecurity-2.0.1-2.4.27.patch

PostPosted: Sat Jan 22, 2005 3:35 pm
by Sleight of Mind
my SMP box is currently running on 2.4.29 + grsec + some other patches and does not have any problems.

PostPosted: Mon Jan 24, 2005 6:29 am
by SG
May be me use grsec different way?

I using virtual system in jail (chroot) with full isolation jail from parent and other jails.

I using HyperThreading of P4.

PostPosted: Fri Feb 11, 2005 4:51 am
by l0ud
Hello all,

Just wondering if anything else came of this discussion? I am having some problems with a SMP kernel myself. Its a dual 2.4 Xeon machine, 1GB RAM, with a 3ware IDE raid card (4 drives -- two raid 1 arrays).

A 2.4.27 and 2.4.28 SMP kernel with grsec will randomly hardlock. Sometime 4-5 times in a day, sometimes once every 2 months. No OOPS, no panic, nothing in the logs.

A 2.4.29 SMP kernel with grsec seems not to hardlock, but to simply reboot every so often. Again nothing worth anything in the logs.

Taking Grsec out of the kernel seems to make the issue go away. I have run all the hardware diagnostics from Intel as well as Memtest86, all came up clean. This has happen to me on two SMP machines -- both the same hardware setup.

I can post kernel CONFIG or other requested information if needed. Let me know if there is any other info that may help. These machines are production machines, so I am not sure how much debugging I can do however.

Thanks!