No matter what I try to do now with gradm, it gets stuck
Those stucked gradm processes can't be killed.
Every once in a while following appears in kern.log:
- Code: Select all
Dec 2 10:24:54 xxxx kernel: Unable to handle kernel paging request at virtual address 69afac52
Dec 2 10:24:54 xxxx kernel: printing eip:
Dec 2 10:24:54 xxxx kernel: c02c03b2
Dec 2 10:24:54 xxxx kernel: *pde = 00000000
Dec 2 10:24:54 xxxx kernel: Oops: 0000
Dec 2 10:24:54 xxxx kernel: CPU: 0
Dec 2 10:24:54 xxxx kernel: EIP: 0010:[<c02c03b2>] Not tainted
Dec 2 10:24:54 xxxx kernel: EFLAGS: 00010206
Dec 2 10:24:54 xxxx kernel: eax: 69afa1ca ebx: 00000000 ecx: db6a4d80 edx: 000002a4
Dec 2 10:24:54 xxxx kernel: esi: c014e524 edi: c014e51c ebp: c014e510 esp: cf17be4c
Dec 2 10:24:54 xxxx kernel: ds: 0018 es: 0018 ss: 0018
Dec 2 10:24:54 xxxx kernel: Process gradm (pid: 26391, stackpage=cf17b000)
Dec 2 10:24:54 xxxx kernel: Stack: c02b7737 cf17a000 080cbee8 cf17bf54 cf17be84 c02ba8b7 c0102c78 00000002
Dec 2 10:24:54 xxxx kernel: d3183840 00000001 c0110f80 db6a4da0 00000000 000000d0 080cbef0 00000010
Dec 2 10:24:54 xxxx kernel: 0000001a 000000f8 00000000 00000000 00000000 00000000 00000000 00000000
Dec 2 10:24:54 xxxx kernel: Call Trace: [<c02b7737>] [<c02ba8b7>] [<c01a9bad>] [<c01a9c00>] [<c01c5c07>]
Dec 2 10:24:54 xxxx kernel: [<c01941a3>]
Dec 2 10:24:54 xxxx kernel:
Dec 2 10:24:54 xxxx kernel: Code: 8b 44 90 f8 85 c0 74 09 50 e8 88 c9 ef ff 83 c4 04 ff 0d 40
My acl was:
- Code: Select all
/ {
/
# /opt rx
/home rx
/mnt r
/dev
/dev/random r
/dev/urandom r
# /dev/input rw
# /dev/psaux rw
/dev/tty? rw
/dev/null rw
/dev/pts rw
/dev/ptmx rw
/dev/tty rw
# /dev/dsp rw
# /dev/mixer rw
/dev/console rw
/dev/mem h
/dev/kmem h
/dev/port h
/dev/zero rw
/bin rx
/sbin rx
/lib rx
/usr rx
/etc rx
# /etc/postfix r
/etc/init.d h
/etc/shadow- h
/etc/shadow h
/proc rwx
/proc/sys r
/proc/kcore h
/root r
/tmp rw
/var rx
/var/cache rw
/var/spool rw
# /var/spool/postfix/lib rx
/var/run rw
/var/tmp rw
/var/log
/boot r
/etc/grsec h
-CAP_ALL
}
And I used following versions:
gradm-1.9.13
grsecurity-1.9.13-2.4.23
linux-2.4.23
I'm not using any other kernel patches than grsec.
any ideas?