Hardened kernel-2.6.38 and latest qemu-kvm bug

Discuss usability issues, general maintenance, and general support issues for a grsecurity-enabled system.

Hardened kernel-2.6.38 and latest qemu-kvm bug

Postby XVilka » Wed May 11, 2011 9:49 pm

Good day!
I'm have bug, where qemu-kvm (any version, and even from git) doesn't work properly (to be honest, it just doesn't work)
I have two cases:
  • when have enabled PAX UDEREF (CONFIG_GRKERNSEC_HARDENED_SERVER)
  • when have disabled PAX UDEREF (CONFIG_GRKERNSEC_HARDENED_VIRTUALIZATION)

In first case qemu-kvm go to infinite loop and eat 100% of cpu
In second case qemu-kvm just do nothing in infinite loop (~1-2% of cpu)

Linux version 2.6.38-hardened (root@xserver) (gcc version 4.5.2 (Gentoo Hardened 4.5.2 p1.1, pie-0.4.5) )
CPU0: Intel(R) Core(TM) i7 CPU 930 @ 2.80GHz stepping 05

Here is my dmesg http://bugs.gentoo.org/attachment.cgi?id=270061
Here is kernel config of first (CONFIG_GRKERNSEC_HARDENED_CUSTOM) case http://bugs.gentoo.org/attachment.cgi?id=270063
Here is kernel config of second (CONFIG_GRKERNSEC_HARDENED_VIRTUALIZATION) case http://bugs.gentoo.org/attachment.cgi?id=270611
Here is my lspci output http://bugs.gentoo.org/attachment.cgi?id=270065

Here is output from qemu monitor:

Code: Select all
(qemu) info kvm
kvm support: enabled
(qemu) info cpus
* CPU #0: pc=0x000000000010017c (halted) thread_id=4688
(qemu) info pci
  Bus  0, device   0, function 0:
    Host bridge: PCI device 8086:1237
      id ""
  Bus  0, device   1, function 0:
    ISA bridge: PCI device 8086:7000
      id ""
  Bus  0, device   1, function 1:
    IDE controller: PCI device 8086:7010
      BAR4: I/O at 0xc000 [0xc00f].
      id ""
  Bus  0, device   1, function 3:
    Bridge: PCI device 8086:7113
      IRQ 9.
      id ""
  Bus  0, device   2, function 0:
    VGA controller: PCI device 1013:00b8
      BAR0: 32 bit prefetchable memory at 0xf0000000 [0xf1ffffff].
      BAR1: 32 bit memory at 0xf2000000 [0xf2000fff].
      BAR6: 32 bit memory at 0xffffffffffffffff [0x0000fffe].
      id ""
(qemu) info status
VM status: running
(qemu) info roms
fw=genroms/vapic.bin size=0x002400 name="vapic.bin"
addr=00000000fffe0000 size=0x020000 mem=rom name="bios.bin"
(qemu) info registers
EAX=00000000 EBX=00187130 ECX=00187130 EDX=00000000
ESI=00000000 EDI=00000000 EBP=00000000 ESP=0ffcfeac
EIP=0010017c EFL=00000246 [---Z-P-] CPL=0 II=0 A20=1 SMM=0 HLT=1
ES =0028 00000000 ffffffff 00c09300 DPL=0 DS   [-WA]
CS =0020 00000000 ffffffff 00c09b00 DPL=0 CS32 [-RA]
SS =0028 00000000 ffffffff 00c09300 DPL=0 DS   [-WA]
DS =0028 00000000 ffffffff 00c09300 DPL=0 DS   [-WA]
FS =0000 00000000 ffffffff 00000000
GS =0000 00000000 ffffffff 00000000
LDT=0000 00000000 ffffffff 00000000
TR =0008 00000580 00000067 00008b00 DPL=0 TSS32-busy
GDT=     0000ab80 0000002f
IDT=     000030b8 000007ff
CR0=00000013 CR2=00000000 CR3=00000000 CR4=00000000
DR0=0000000000000000 DR1=0000000000000000 DR2=0000000000000000
DR3=0000000000000000
DR6=00000000ffff0ff0 DR7=0000000000000400
EFER=0000000000000000
FCW=037f FSW=0020 [ST=0] FTW=00 MXCSR=00001f80
FPR0=f44d002c60000000 400d FPR1=80847fe700000000 400e
FPR2=fa007fa240000000 400e FPR3=80e88055f0000000 400e
FPR4=ea61009c40000000 400d FPR5=ea62009c40000000 400c
FPR6=bb7fffb9b0000000 400b FPR7=bb83ffb9b0000000 400b
XMM00=00000000000000000000000000000000 XMM01=00000000000000000000000000000000
XMM02=00000000000000000000000000000000 XMM03=00000000000000000000000000000000
XMM04=00000000000000000000000000000000 XMM05=00000000000000000000000000000000
XMM06=00000000000000000000000000000000 XMM07=00000000000000000000000000000000


Additional info in the gentoo bug here http://bugs.gentoo.org/show_bug.cgi?id=363713
XVilka
 
Posts: 2
Joined: Wed Apr 20, 2011 2:07 pm

Re: Hardened kernel-2.6.38 and latest qemu-kvm bug

Postby PaX Team » Thu May 12, 2011 8:24 am

XVilka wrote:Additional info in the gentoo bug here http://bugs.gentoo.org/show_bug.cgi?id=363713
how about answering my question there? ;)
PaX Team
 
Posts: 2310
Joined: Mon Mar 18, 2002 4:35 pm

Re: Hardened kernel-2.6.38 and latest qemu-kvm bug

Postby XVilka » Thu May 12, 2011 7:26 pm

not found 0x10017c line
here is full objdump output http://ompldr.org/vOG82ag/vmlinux_objdump.txt.bz2
XVilka
 
Posts: 2
Joined: Wed Apr 20, 2011 2:07 pm


Return to grsecurity support