GRKERNSEC_IO=y ,Problem Free XFCE Laptop

Discuss usability issues, general maintenance, and general support issues for a grsecurity-enabled system.

GRKERNSEC_IO=y ,Problem Free XFCE Laptop

Postby tdwyer » Thu Nov 21, 2013 8:07 am

Hello,
First I'd like to say, Wow
Just amazing work you guys are doing, very impressive.

So, I configured grsec_lock=1 to be set at boot, but forgot to disable disable_priv_io=0
I didn't notice my mistake until a few days latter. I'm still running with it enabled on my XFCE laptop and am not experiencing any problems. I can't find any errors in the journalctl. Not even that hwclock error.

This is strange. Xorg should not be able to work with it enabled right? Like even in the kernel help section it says that it needs to be disabled for X to run.

Is that problem fix and the doc's are old, or is it not really enabled on my laptop?


Arch Linux
Thinkpad X230
Intel(R) Core(TM) i7-3520M

Running grsec settings
ftp://ftp.myrelay.net/linux/grsec-settings

Kernel config
ftp://ftp.myrelay.net/linux/config.x86_64.3.11.8-1

lspci
Code: Select all
00:00.0 Host bridge: Intel Corporation 3rd Gen Core processor DRAM Controller (rev 09)
00:02.0 VGA compatible controller: Intel Corporation 3rd Gen Core processor Graphics Controller (rev 09)
00:14.0 USB controller: Intel Corporation 7 Series/C210 Series Chipset Family USB xHCI Host Controller (rev 04)
00:16.0 Communication controller: Intel Corporation 7 Series/C210 Series Chipset Family MEI Controller #1 (rev 04)
00:19.0 Ethernet controller: Intel Corporation 82579LM Gigabit Network Connection (rev 04)
00:1a.0 USB controller: Intel Corporation 7 Series/C210 Series Chipset Family USB Enhanced Host Controller #2 (rev 04)
00:1b.0 Audio device: Intel Corporation 7 Series/C210 Series Chipset Family High Definition Audio Controller (rev 04)
00:1c.0 PCI bridge: Intel Corporation 7 Series/C210 Series Chipset Family PCI Express Root Port 1 (rev c4)
00:1c.1 PCI bridge: Intel Corporation 7 Series/C210 Series Chipset Family PCI Express Root Port 2 (rev c4)
00:1c.2 PCI bridge: Intel Corporation 7 Series/C210 Series Chipset Family PCI Express Root Port 3 (rev c4)
00:1d.0 USB controller: Intel Corporation 7 Series/C210 Series Chipset Family USB Enhanced Host Controller #1 (rev 04)
00:1f.0 ISA bridge: Intel Corporation QM77 Express Chipset LPC Controller (rev 04)
00:1f.2 SATA controller: Intel Corporation 7 Series Chipset Family 6-port SATA Controller [AHCI mode] (rev 04)
00:1f.3 SMBus: Intel Corporation 7 Series/C210 Series Chipset Family SMBus Controller (rev 04)
02:00.0 System peripheral: Ricoh Co Ltd PCIe SDXC/MMC Host Controller (rev 07)
03:00.0 Network controller: Intel Corporation Centrino Advanced-N 6205 [Taylor Peak] (rev 34)
tdwyer
 
Posts: 2
Joined: Thu Nov 21, 2013 7:21 am

Re: GRKERNSEC_IO=y ,Problem Free XFCE Laptop

Postby spender » Thu Nov 21, 2013 10:02 am

Hi,

The documentation is correct for some users still and outdated for others. It depends on the userland and video card involved. See these links:
http://www.gossamer-threads.com/lists/g ... ned/267367
http://cgit.freedesktop.org/~ajax/xserv ... aba3a6b442

I'll update the documentation to reflect these changes.

Thanks,
-Brad
spender
 
Posts: 2185
Joined: Wed Feb 20, 2002 8:00 pm

Re: GRKERNSEC_IO=y ,Problem Free XFCE Laptop

Postby tdwyer » Fri Nov 22, 2013 7:47 am

Very cool.

KMS is the preferred standard now anyway, and is default for Intel, Nividia, and ATI open source drivers. I'll edit the grsec Arch Wiki with the new info. This was the only setting that differed between my server and desktop kernels, so now I don't have to build twice or enable sysctl support.
tdwyer
 
Posts: 2
Joined: Thu Nov 21, 2013 7:21 am


Return to grsecurity support

cron