Big Problem: attempted resource overstep by requesting...

Discuss usability issues, general maintenance, and general support issues for a grsecurity-enabled system.

Big Problem: attempted resource overstep by requesting...

Postby vendor_id » Thu Dec 30, 2004 6:36 am

Hi,

since 2 weeks i get problems with grsec.
The Server freezes when grsec have an ressource error.
The harddisks are 4 weeks old (including the 3ware raid).
The RBAC-system is offline.

Code: Select all
Dec 29 19:35:18 server3 kernel: grsec: From 205.206.231.26: attempted resource overstep by requesting 4096 for RLIMIT_CORE against limit 0 by /usr/local/pd-admin2/bin/clamscan[clamscan:12316] uid/euid:1015/1015 gid/egid:1005/1005, parent /usr/local/pd-admin2/bin/perl5.8.4[perl5.8.4:12313] uid/euid:1015/1015 gid/egid:1005/1005
Dec 29 20:59:51 server3 kernel: grsec: From 84.128.254.224: attempted resource overstep by requesting 4096 for RLIMIT_CORE against limit 0 by /usr/local/pd-admin2/bin/clamscan[clamscan:15059] uid/euid:1015/1015 gid/egid:1005/1005, parent /usr/local/pd-admin2/bin/perl5.8.4[perl5.8.4:15056] uid/euid:1015/1015 gid/egid:1005/1005
Dec 30 02:21:01 server3 kernel: grsec: attempted resource overstep by requesting 4096 for RLIMIT_CORE against limit 0 by /opt/pdadmin/bin/quota.pl[quota.pl:24819] uid/euid:0/0 gid/egid:0/0, parent /bin/bash[sh:24818] uid/euid:0/0 gid/egid:0/0
Dec 30 02:21:02 server3 kernel: grsec: attempted resource overstep by requesting 4096 for RLIMIT_CORE against limit 0 by /usr/lib/cgi-bin/awstats.pl[awstats.pl:24816] uid/euid:0/0 gid/egid:0/0, parent /opt/pdadmin/bin/stats_awstats.sh[stats_awstats.s:24813] uid/euid:0/0 gid/egid:0/0
Dec 30 02:21:05 server3 kernel: grsec: attempted resource overstep by requesting 4096 for RLIMIT_CORE against limit 0 by /usr/lib/cgi-bin/awstats.pl[awstats.pl:24821] uid/euid:0/0 gid/egid:0/0, parent /opt/pdadmin/bin/stats_awstats.sh[stats_awstats.s:24813] uid/euid:0/0 gid/egid:0/0
Dec 30 02:21:05 server3 kernel: grsec: attempted resource overstep by requesting 4096 for RLIMIT_CORE against limit 0 by /usr/lib/cgi-bin/awstats.pl[awstats.pl:24822] uid/euid:0/0 gid/egid:0/0, parent /opt/pdadmin/bin/stats_awstats.sh[stats_awstats.s:24813] uid/euid:0/0 gid/egid:0/0
Dec 30 02:21:08 server3 kernel: grsec: attempted resource overstep by requesting 4096 for RLIMIT_CORE against limit 0 by /usr/lib/cgi-bin/awstats.pl[awstats.pl:24824] uid/euid:0/0 gid/egid:0/0, parent /opt/pdadmin/bin/stats_awstats.sh[stats_awstats.s:24813] uid/euid:0/0 gid/egid:0/0
Dec 30 02:21:09 server3 kernel: grsec: more alerts, logging disabled for 10 seconds
Dec 30 02:21:23 server3 kernel: grsec: attempted resource overstep by requesting 4096 for RLIMIT_CORE against limit 0 by /usr/lib/cgi-bin/awstats.pl[awstats.pl:24837] uid/euid:0/0 gid/egid:0/0, parent /opt/pdadmin/bin/stats_awstats.sh[stats_awstats.s:24813] uid/euid:0/0 gid/egid:0/0
Dec 30 02:21:23 server3 kernel: EXT3-fs error (device sd(8,7)): ext3_free_blocks: Freeing blocks not in datazone - block = 2415919104, count = 1
Dec 30 02:21:23 server3 kernel: attempt to access beyond end of device
Dec 30 02:21:23 server3 kernel: 08:07: rw=0, want=1073741828, limit=125033863
Dec 30 02:21:23 server3 kernel: EXT3-fs error (device sd(8,7)): ext3_free_branches: Read failure, inode=15597646, block=268435456
Dec 30 02:21:23 server3 kernel: EXT3-fs error (device sd(8,7)): ext3_free_blocks: Freeing blocks not in datazone - block = 2147483648, count = 1
Dec 30 02:21:23 server3 kernel: EXT3-fs error (device sd(8,7)): ext3_free_blocks: Freeing blocks not in datazone - block = 268435456, count = 1
Dec 30 02:21:23 server3 kernel: EXT3-fs error (device sd(8,7)): ext3_free_blocks: Freeing blocks not in datazone - block = 419430400, count = 1
Dec 30 02:21:23 server3 kernel: EXT3-fs error (device sd(8,7)): ext3_free_blocks: Freeing blocks not in datazone - block = 2164260864, count = 1
Dec 30 02:21:23 server3 kernel: EXT3-fs error (device sd(8,7)): ext3_free_blocks: Freeing blocks not in datazone - block = 402653184, count = 1
Dec 30 02:21:23 server3 kernel: attempt to access beyond end of device
Dec 30 02:21:23 server3 kernel: 08:07: rw=0, want=1248077828, limit=125033863
Dec 30 02:21:23 server3 kernel: EXT3-fs error (device sd(8,7)): ext3_free_branches: Read failure, inode=15597654, block=-224851456
Dec 30 02:21:23 server3 kernel: attempt to access beyond end of device
Dec 30 02:21:23 server3 kernel: 08:07: rw=0, want=134217732, limit=125033863
Dec 30 02:21:23 server3 kernel: EXT3-fs error (device sd(8,7)): ext3_free_branches: Read failure, inode=15597654, block=33554432
Dec 30 02:21:23 server3 kernel: attempt to access beyond end of device
Dec 30 02:21:23 server3 kernel: 08:07: rw=0, want=1625616132, limit=125033863
Dec 30 02:21:23 server3 kernel: EXT3-fs error (device sd(8,7)): ext3_free_branches: Read failure, inode=15597654, block=-1741079616
Dec 30 02:21:23 server3 kernel: attempt to access beyond end of device
Dec 30 02:21:23 server3 kernel: 08:07: rw=0, want=0, limit=125033863


I have 3 other times, where grsec gets an ressource error and the system goes down (hard disk errors, memory errors [swapd zombie]...)
What configs do you need to help me?
vendor_id
 
Posts: 4
Joined: Sun Dec 26, 2004 10:52 am

Postby spender » Thu Dec 30, 2004 12:38 pm

It looks like you have filesystem/harddrive problems that are unrelated to grsec. You should run smartd and check the status of your drives.

-Brad
spender
 
Posts: 2185
Joined: Wed Feb 20, 2002 8:00 pm

Postby vendor_id » Thu Dec 30, 2004 7:51 pm

Hi,

i have a swaperror too.
Every error comes in the same time with a grsec error.
How can i solve the problem with the ressource overstep?
I don't want wo deactivate grsec.

Code: Select all
Dec 24 11:45:02 server02 kernel: grsec: From 172.176.34.190: attempted resource overstep by requesting 1383878656 for RLIMIT_STACK against limit 2093056 by /usr/bin/python2.3[python:7423] uid/euid:1053/1053 gid/egid:1053/1053, parent /bin/bash[sh:7376] uid/euid:1053/1053 gid/egid:1053/1053
Dec 24 11:45:02 server02 kernel: Unable to handle kernel paging request at virtual address 6d83bb57
Dec 24 11:45:02 server02 kernel:  printing eip:
Dec 24 11:45:02 server02 kernel: 6d83bb57
Dec 24 11:45:02 server02 kernel: *pde = 00000000
Dec 24 11:45:02 server02 kernel: Oops: 0000
Dec 24 11:45:02 server02 kernel: CPU:    0
Dec 24 11:45:02 server02 kernel: EIP:    0010:[<6d83bb57>]    Not tainted
Dec 24 11:45:02 server02 kernel: EFLAGS: 00010202
Dec 24 11:45:02 server02 kernel: eax: d0105a60   ebx: c11e9da0   ecx: c11e9dbc   edx: 6d83bb57
Dec 24 11:45:02 server02 kernel: esi: 000001d2   edi: c01039f8   ebp: 00004ee3   esp: d2bf1df0
Dec 24 11:45:02 server02 kernel: ds: 0018   es: 0018   ss: 0018
Dec 24 11:45:02 server02 kernel: Process python (pid: 7423, stackpage=d2bf1000)
Dec 24 11:45:02 server02 kernel: Stack: c01e72f1 c11e9da0 000001d2 00000000 c11e9da0 c01dc813 c11e9da0 000001d2
Dec 24 11:45:02 server02 kernel:        00000c7e 000001d2 00000019 00000020 000001d2 c01039f8 c01039f8 c01dca5d
Dec 24 11:45:02 server02 kernel:        d2bf1e50 000001d2 0000003c 00000020 c01dcae2 d2bf1e50 d63f3180 00000000
Dec 24 11:45:02 server02 kernel: Call Trace:    [<c01e72f1>] [<c01dc813>] [<c01dca5d>] [<c01dcae2>] [<c01dd672>]
Dec 24 11:45:02 server02 kernel:   [<c01dd988>] [<c01d4e89>] [<c0215280>] [<c01d554d>] [<c01d57d1>] [<c01d5dc0>]
Dec 24 11:45:02 server02 kernel:   [<c01d5dc0>] [<c01d5f57>] [<c01d5dc0>] [<c02dedb4>] [<c01e4d03>] [<c01b31a3>]
Dec 24 11:45:02 server02 kernel:
Dec 24 11:45:02 server02 kernel: Code:  Bad EIP value.
Dec 24 11:45:02 server02 kernel:  <1>Unable to handle kernel paging request at virtual address 6d83bb57
Dec 24 11:45:02 server02 kernel:  printing eip:
Dec 24 11:45:02 server02 kernel: 6d83bb57
Dec 24 11:45:02 server02 kernel: *pde = 00000000
Dec 24 11:45:02 server02 kernel: Oops: 0000
Dec 24 11:45:02 server02 kernel: CPU:    0
Dec 24 11:45:02 server02 kernel: EIP:    0010:[<6d83bb57>]    Not tainted
Dec 24 11:45:02 server02 kernel: EFLAGS: 00010202
Dec 24 11:45:02 server02 kernel: eax: d0105a60   ebx: c1260900   ecx: c126091c   edx: 6d83bb57
Dec 24 11:45:02 server02 kernel: esi: 000001f0   edi: c01039f8   ebp: 00004eed   esp: c4d9de98
Dec 24 11:45:02 server02 kernel: ds: 0018   es: 0018   ss: 0018
Dec 24 11:45:02 server02 kernel: Process pdns_server (pid: 917, stackpage=c4d9d000)
Dec 24 11:45:02 server02 kernel: Stack: c01e72f1 c1260900 000001f0 00000000 c1260900 c01dc813 c1260900 000001f0
Dec 24 11:45:02 server02 kernel:        000009c4 000001f0 00000019 00000019 000001f0 c01039f8 c01039f8 c01dca5d
Dec 24 11:45:02 server02 kernel:        c4d9def8 000001f0 0000003c 00000020 c01dcae2 c4d9def8 c4d9df0c 00000000
Dec 24 11:45:02 server02 kernel: Call Trace:    [<c01e72f1>] [<c01dc813>] [<c01dca5d>] [<c01dcae2>] [<c01dd672>]
Dec 24 11:45:02 server02 kernel:   [<c01dd988>] [<c01ddaac>] [<c01f58c0>] [<c01b31a3>]
Dec 24 11:45:02 server02 kernel:
Dec 24 11:45:02 server02 kernel: Code:  Bad EIP value.
Dec 24 11:45:02 server02 kernel:  general protection fault: 72f0
Dec 24 11:45:02 server02 kernel: CPU:    0
Dec 24 11:45:02 server02 kernel: EIP:    0010:[<bfffad32>]    Not tainted
Dec 24 11:45:02 server02 kernel: EFLAGS: 00010217
Dec 24 11:45:02 server02 kernel: eax: d010590a   ebx: c1260930   ecx: c126094c   edx: 6d830757
Dec 24 11:45:02 server02 kernel: esi: 000001d2   edi: c01039f8   ebp: 00004eec   esp: cc267d24
Dec 24 11:45:02 server02 kernel: ds: 0018   es: 0018   ss: 0018
Dec 24 11:45:02 server02 kernel: Process sh (pid: 7376, stackpage=cc267000)
Dec 24 11:45:02 server02 kernel: Stack: c01e72f1 c1260930 000001d2 00000000 c1260930 c01dc813 c1260930 000001d2
Dec 24 11:45:02 server02 kernel:        00000c80 000001d2 00000020 00000020 000001d2 c01039f8 c01039f8 c01dca5d
Dec 24 11:45:02 server02 kernel:        cc267d84 000001d2 0000003c 00000020 c01dcae2 cc267d84 0c369f8c 00000000
Dec 24 11:45:02 server02 kernel: Call Trace:    [<c01e72f1>] [<c01dc813>] [<c01dca5d>] [<c01dcae2>] [<c01dd672>]
Dec 24 11:45:02 server02 kernel:   [<c01dd988>] [<c01d4e00>] [<c01dd002>] [<c01de14c>] [<c01d20e1>] [<c01d21e8>]
Dec 24 11:45:02 server02 kernel:   [<c01d25f0>] [<c01bf298>] [<c01dbf04>] [<c01d1d48>] [<c01dd87b>] [<c01d2636>]
Dec 24 11:45:02 server02 kernel:   [<c039994f>] [<c01bf298>] [<c01bf070>] [<c01b32b4>] [<c01c640d>] [<c01c6555>]
Dec 24 11:45:02 server02 kernel:   [<c01b31a3>]
Dec 24 11:45:02 server02 kernel:
Dec 24 11:45:02 server02 kernel: Code:  Bad EIP value.
Dec 24 15:48:38 server02 kernel:  <7>hw tcp v4 csum failed
Dec 24 22:06:01 server02 kernel: Unable to handle kernel NULL pointer dereference at virtual address 00000028
Dec 24 22:06:02 server02 kernel:  printing eip:
Dec 24 22:06:02 server02 kernel: c01faf58
Dec 24 22:06:02 server02 kernel: *pde = 00000000
Dec 24 22:06:02 server02 kernel: Oops: 0000
Dec 24 22:06:02 server02 kernel: CPU:    0
Dec 24 22:06:02 server02 kernel: EIP:    0010:[<c01faf58>]    Not tainted
Dec 24 22:06:02 server02 kernel: EFLAGS: 00010213
Dec 24 22:06:02 server02 kernel: eax: 00000000   ebx: 00000000   ecx: 0000000f   edx: dff80000
Dec 24 22:06:02 server02 kernel: esi: 00000000   edi: dffbb298   ebp: 0030a7bd   esp: d27f7e98
Dec 24 22:06:02 server02 kernel: ds: 0018   es: 0018   ss: 0018
Dec 24 22:06:02 server02 kernel: Process find (pid: 19667, stackpage=d27f7000)
Dec 24 22:06:02 server02 kernel: Stack: 00000000 d6044e00 c1659800 00007fff dffbb298 0030a7bd c1659800 c01fb354
Dec 24 22:06:02 server02 kernel:        c1659800 0030a7bd dffbb298 00000000 00000000 0030a7bd cf357600 c1659800
Dec 24 22:06:02 server02 kernel:        cf357600 c0218ad9 c1659800 0030a7bd 00000000 00000000 c9baf044 fffffff4
Dec 24 22:06:02 server02 kernel: Call Trace:    [<c01fb354>] [<c0218ad9>] [<c01ef3dd>] [<c01efc31>] [<c01f0029>]
Dec 24 22:06:02 server02 kernel:   [<c01f02d9>] [<c01ec5df>] [<c01b31a3>]
Dec 24 22:06:02 server02 kernel:
Dec 24 22:06:02 server02 kernel: Code: 39 6b 28 89 de 75 f1 8b 44 24 20 39 83 a0 00 00 00 75 e5 8b
Dec 24 22:09:34 server02 kernel:  <6>Adding Swap: 979924k swap-space (priority -2)


It looks like an problem with my Tyan onboard networkcard and my raid?!?
The raid components are 1 month old (3ware and the 2 sata disks).
Last edited by vendor_id on Fri Dec 31, 2004 8:24 pm, edited 1 time in total.
vendor_id
 
Posts: 4
Joined: Sun Dec 26, 2004 10:52 am

Postby spender » Thu Dec 30, 2004 11:36 pm

can you run that oops through ksymoops so i can see what functions are involved?

-Brad
spender
 
Posts: 2185
Joined: Wed Feb 20, 2002 8:00 pm

Postby vendor_id » Fri Dec 31, 2004 7:54 pm

Here...
Code: Select all
Warning (expand_objects): object /lib/modules/2.4.27-1-386/kernel/fs/ext3/ext3.o for module ext3 has changed since load
Warning (expand_objects): object /lib/modules/2.4.27-1-386/kernel/fs/jbd/jbd.o for module jbd has changed since load
Warning (expand_objects): object /lib/modules/2.4.27-1-386/kernel/drivers/scsi/sd_mod.o for module sd_mod has changed since load
Warning (expand_objects): object /lib/modules/2.4.27-1-386/kernel/drivers/scsi/sg.o for module sg has changed since load
Warning (expand_objects): object /lib/modules/2.4.27-1-386/kernel/drivers/scsi/3w-xxxx.o for module 3w-xxxx has changed since load
Warning (expand_objects): object /lib/modules/2.4.27-1-386/kernel/drivers/scsi/scsi_mod.o for module scsi_mod has changed since load
Warning (expand_objects): object /lib/modules/2.4.27-1-386/kernel/net/unix/unix.o for module unix has changed since load
Dec 28 22:03:35 server02 kernel: e100: eth0: e100_wait_exec_simple: failed
Dec 30 02:21:23 server02 kernel: kernel BUG at transaction.c:1257!
Dec 30 02:21:23 server02 kernel: invalid operand: 0000
Dec 30 02:21:23 server02 kernel: CPU:    0
Dec 30 02:21:23 server02 kernel: EIP:    0010:[<c01bc095>]    Not tainted
Using defaults from ksymoops -t elf32-i386 -a i386
Dec 30 02:21:23 server02 kernel: EFLAGS: 00010286
Dec 30 02:21:23 server02 kernel: eax: 00000058   ebx: d4a8b200   ecx: d490a000   edx: c4b37f54
Dec 30 02:21:23 server02 kernel: esi: db507b70   edi: c162b8f4   ebp: c162b880   esp: d490bb6c
Dec 30 02:21:23 server02 kernel: ds: 0018   es: 0018   ss: 0018
Dec 30 02:21:23 server02 kernel: Process cp (pid: 24839, stackpage=d490b000)
Dec 30 02:21:23 server02 kernel: Stack: c030aa20 c0307eec c0307cbc 000004e9 c0307efb c3a33b80 d4a8b200 dc79a900
Dec 30 02:21:23 server02 kernel:        db078180 00000000 c01b06b0 db078180 d4a8b200 d50a8a00 0000008d 00000000
Dec 30 02:21:23 server02 kernel:        db078180 d50a8a00 db078180 dc79a900 00010000 d3eb5518 db078180 dc79a900
Dec 30 02:21:23 server02 kernel: Call Trace:    [<c01b06b0>] [<c01b2bb0>] [<c01bb6b3>] [<c01b2cf5>] [<c015c6d4>]
Dec 30 02:21:23 server02 kernel:   [<c01feb4e>] [<c01b3058>] [<c0182901>] [<c01b2eb4>] [<c01828a0>] [<c01b2eb4>]
Dec 30 02:21:23 server02 kernel:   [<c0182901>] [<c01b2eb4>] [<c01c07b7>] [<c01b07ec>] [<c01b33e2>] [<c01bb6b3>]
Dec 30 02:21:23 server02 kernel:   [<c016f9e7>] [<c01b3060>] [<c016c8ae>] [<c0197a2d>] [<c01b4010>] [<c0197c33>]
Dec 30 02:21:23 server02 kernel:   [<c017e9f4>] [<c018c547>] [<c017fd6e>] [<c0180143>] [<c0150213>]
Dec 30 02:21:23 server02 kernel: Code: 0f 0b e9 04 bc 7c 30 c0 e9 51 ff ff ff c7 04 24 20 aa 30 c0


>>EIP; c01bc095 <ethtool_set_pauseparam+2/6f>   <=====

>>ebx; d4a8b200 <_end+147b5320/2053f180>
>>ecx; d490a000 <_end+14634120/2053f180>
>>edx; c4b37f54 <_end+4862074/2053f180>
>>esi; db507b70 <_end+1b231c90/2053f180>
>>edi; c162b8f4 <_end+1355a14/2053f180>
>>ebp; c162b880 <_end+13559a0/2053f180>
>>esp; d490bb6c <_end+14635c8c/2053f180>

Trace; c01b06b0 <FPU_store_single+192/44d>
Trace; c01b2bb0 <FPU_shrxs+40/47>
Trace; c01bb6b3 <ethtool_set_settings+2e/6f>
Trace; c01b2cf5 <sqrt_stage_2_done+a/54>
Trace; c015c6d4 <ramfs_get_inode+14/ca>
Trace; c01feb4e <pvc_bind+7f/10e>
Trace; c01b3058 <L_accum_loop+14/4c>
Trace; c0182901 <reset_buffer_flags+5f/63>
Trace; c01b2eb4 <LFirst_div_done+6/3d>
Trace; c01828a0 <check_unthrottle+28/2a>
Trace; c01b2eb4 <LFirst_div_done+6/3d>
Trace; c0182901 <reset_buffer_flags+5f/63>
Trace; c01b2eb4 <LFirst_div_done+6/3d>
Trace; c01c07b7 <nf_reinject+24/147>
Trace; c01b07ec <FPU_store_single+2ce/44d>
Trace; c01b33e2 <sockfs_statfs+16/1b>
Trace; c01bb6b3 <ethtool_set_settings+2e/6f>
Trace; c016f9e7 <acpi_hw_get_gpe_status+5c/79>
Trace; c01b3060 <L_accum_loop+1c/4c>
Trace; c016c8ae <acpi_ex_acquire_mutex+58/ef>
Trace; c0197a2d <handle_scancode+190/2b2>
Trace; c01b4010 <sys_bind+48/69>
Trace; c0197c33 <enter+0/36>
Trace; c017e9f4 <get_date_field+20/59>
Trace; c018c547 <lf+30/57>
Trace; c017fd6e <tty_set_ldisc+17/282>
Trace; c0180143 <do_tty_hangup+2e/191>
Trace; c0150213 <disk_name+e3/1ae>

Code;  c01bc095 <ethtool_set_pauseparam+2/6f>
00000000 <_EIP>:
Code;  c01bc095 <ethtool_set_pauseparam+2/6f>   <=====
   0:   0f 0b                     ud2a      <=====
Code;  c01bc097 <ethtool_set_pauseparam+4/6f>
   2:   e9 04 bc 7c 30            jmp    307cbc0b <_EIP+0x307cbc0b>
Code;  c01bc09c <ethtool_set_pauseparam+9/6f>
   7:   c0 e9 51                  shr    $0x51,%cl
Code;  c01bc09f <ethtool_set_pauseparam+c/6f>
   a:   ff                        (bad)
Code;  c01bc0a0 <ethtool_set_pauseparam+d/6f>
   b:   ff                        (bad)
Code;  c01bc0a1 <ethtool_set_pauseparam+e/6f>
   c:   ff c7                     inc    %edi
Code;  c01bc0a3 <ethtool_set_pauseparam+10/6f>
   e:   04 24                     add    $0x24,%al
Code;  c01bc0a5 <ethtool_set_pauseparam+12/6f>
  10:   20 aa 30 c0 00 00         and    %ch,0xc030(%edx)

Dec 30 11:08:59 server02 kernel: cpu: 0, clocks: 1329492, slice: 664746
Dec 30 11:08:59 server02 kernel: e100: selftest OK.
Dec 30 11:08:59 server02 kernel: e100: eth0: Intel(R) PRO/100 Network Connection
Dec 30 11:08:59 server02 kernel: e100: eth0 NIC Link is Up 100 Mbps Full duplex
Dec 31 03:25:45 server02 kernel: e100: selftest OK.
Dec 31 03:25:45 server02 kernel: e100: eth0: Intel(R) PRO/100 Network Connection
Dec 31 03:25:45 server02 kernel: e1000: eth1: e1000_probe: Intel(R) PRO/1000 Network Connection
Dec 31 03:25:45 server02 kernel: e100: eth0 NIC Link is Up 100 Mbps Full duplex
Dec 31 06:25:32 server02 kernel: Unable to handle kernel paging request at virtual address 52818dd8
Dec 31 06:25:32 server02 kernel: c0142abe
Dec 31 06:25:32 server02 kernel: *pde = 00000000
Dec 31 06:25:32 server02 kernel: Oops: 0000
Dec 31 06:25:32 server02 kernel: CPU:    0
Dec 31 06:25:32 server02 kernel: EIP:    0010:[find_inode+26/92]    Not tainted
Dec 31 06:25:32 server02 kernel: EFLAGS: 00010a83
Dec 31 06:25:32 server02 kernel: eax: 00232ebc   ebx: 00000000   ecx: 0000000f   edx: c15c0000
Dec 31 06:25:32 server02 kernel: esi: 52818db0   edi: 00000000   ebp: c15f8970   esp: cf625ec0
Dec 31 06:25:32 server02 kernel: ds: 0018   es: 0018   ss: 0018
Dec 31 06:25:32 server02 kernel: Process find (pid: 7077, stackpage=cf625000)
Dec 31 06:25:32 server02 kernel: Stack: 00232ebc c15f8970 00232ebc df626400 c0142df3 df626400 00232ebc c15f8970
Dec 31 06:25:32 server02 kernel:        00000000 00000000 00232ebc df626400 cae19b30 cae194a0 e0859f2c df626400
Dec 31 06:25:32 server02 kernel:        00232ebc 00000000 00000000 cae15158 cae19b30 fffffff4 cae16210 c013965f
Dec 31 06:25:32 server02 kernel: Call Trace:    [iget4_locked+63/191] [hw_random:__insmod_hw_random_O/lib/modules/2.4.27-1-386/kernel/driver+-1179860/96] [real_lookup+77/176] [link_path_walk+1284/1791] [getname+94/150]
Dec 31 06:25:32 server02 kernel: Code: 39 46 28 89 f3 75 ed 8b 44 24 14 39 86 a0 00 00 00 75 e1 85


>>edx; c15c0000 <_end+12ea120/2053f180>
>>ebp; c15f8970 <_end+1322a90/2053f180>
>>esp; cf625ec0 <_end+f34ffe0/2053f180>

Code;  c01bc095 <ethtool_set_pauseparam+2/6f>
00000000 <_EIP>:
Code;  c01bc095 <ethtool_set_pauseparam+2/6f>
   0:   39 46 28                  cmp    %eax,0x28(%esi)
Code;  c01bc098 <ethtool_set_pauseparam+5/6f>
   3:   89 f3                     mov    %esi,%ebx
Code;  c01bc09a <ethtool_set_pauseparam+7/6f>
   5:   75 ed                     jne    fffffff4 <_EIP+0xfffffff4>
Code;  c01bc09c <ethtool_set_pauseparam+9/6f>
   7:   8b 44 24 14               mov    0x14(%esp),%eax
Code;  c01bc0a0 <ethtool_set_pauseparam+d/6f>
   b:   39 86 a0 00 00 00         cmp    %eax,0xa0(%esi)
Code;  c01bc0a6 <ethtool_set_pauseparam+13/6f>
  11:   75 e1                     jne    fffffff4 <_EIP+0xfffffff4>
Code;  c01bc0a8 <ethtool_set_pauseparam+15/6f>
  13:   85 00                     test   %eax,(%eax)

Dec 31 15:52:25 server02 kernel: Unable to handle kernel paging request at virtual address 20cb6470
Dec 31 15:52:25 server02 kernel: 40a2117a
Dec 31 15:52:25 server02 kernel: *pde = 00000000
Dec 31 15:52:25 server02 kernel: Oops: 0002
Dec 31 15:52:25 server02 kernel: CPU:    0
Dec 31 15:52:25 server02 kernel: EIP:    0010:[<40a2117a>]    Not tainted
Dec 31 15:52:25 server02 kernel: EFLAGS: 00010212
Dec 31 15:52:25 server02 kernel: eax: 20cb6470   ebx: cafe7a80   ecx: cafe7a90   edx: cafe7a90
Dec 31 15:52:25 server02 kernel: esi: 40a22440   edi: c6626400   ebp: 00000e26   esp: c15bdf20
Dec 31 15:52:25 server02 kernel: ds: 0018   es: 0018   ss: 0018
Dec 31 15:52:25 server02 kernel: Process kswapd (pid: 4, stackpage=c15bd000)
Dec 31 15:52:25 server02 kernel: Stack: c0142f09 cafe7a80 cafe60c8 cafe60b0 cafe7a80 c0140ead cafe7a80 00000000
Dec 31 15:52:25 server02 kernel:        c13a70cc 0000000d 000001d0 c0141157 000011ef c012ab9b 00000006 000001d0
Dec 31 15:52:25 server02 kernel:        ffffffff 0000362c c023ffd8 00000020 000001d0 c023ffd8 00000020 c012add7
Dec 31 15:52:25 server02 kernel: Call Trace:    [iput+63/532] [prune_dcache+213/295] [shrink_dcache_memory+27/45] [shrink_cache+571/789] [shrink_caches+46/55]
Dec 31 15:52:25 server02 kernel: Code:  Bad EIP value.


>>EIP; 40a2117a Before first symbol   <=====

>>ebx; cafe7a80 <_end+ad11ba0/2053f180>
>>ecx; cafe7a90 <_end+ad11bb0/2053f180>
>>edx; cafe7a90 <_end+ad11bb0/2053f180>
>>edi; c6626400 <_end+6350520/2053f180>
>>esp; c15bdf20 <_end+12e8040/2053f180>

Dec 31 15:53:41 server02 kernel:  <1>Unable to handle kernel paging request at virtual address e778af03
Dec 31 15:53:41 server02 kernel: c0142efd
Dec 31 15:53:41 server02 kernel: *pde = 00000000
Dec 31 15:53:41 server02 kernel: Oops: 0000
Dec 31 15:53:41 server02 kernel: CPU:    0
Dec 31 15:53:41 server02 kernel: EIP:    0010:[iput+51/532]    Not tainted
Dec 31 15:53:41 server02 kernel: EFLAGS: 00010286
Dec 31 15:53:41 server02 kernel: eax: e778aeeb   ebx: cafe7c50   ecx: cafe7c60   edx: cafe7c60
Dec 31 15:53:41 server02 kernel: esi: 00000000   edi: ce626400   ebp: 00001158   esp: c7d8de08
Dec 31 15:53:41 server02 kernel: ds: 0018   es: 0018   ss: 0018
Dec 31 15:53:41 server02 kernel: Process python (pid: 19493, stackpage=c7d8d000)
Dec 31 15:53:41 server02 kernel: Stack: cafe6138 cafe6120 cafe7c50 c0140ead cafe7c50 00000000 c142ac28 0000000c
Dec 31 15:53:41 server02 kernel:        000001d2 c0141157 00001158 c012ab9b 00000006 000001d2 ffffffff 00003dc6
Dec 31 15:53:41 server02 kernel:        c023ffd8 00000020 000001d2 c023ffd8 00000020 c012add7 c7d8de78 000001d2
Dec 31 15:53:41 server02 kernel: Call Trace:    [prune_dcache+213/295] [shrink_dcache_memory+27/45] [shrink_cache+571/789] [shrink_caches+46/55] [try_to_free_pages_zone+67/193]
Dec 31 15:53:41 server02 kernel: Code: 83 78 18 00 89 c6 74 05 53 ff 50 18 58 ff 4b 2c 0f 94 c0 84


>>ebx; cafe7c50 <_end+ad11d70/2053f180>
>>ecx; cafe7c60 <_end+ad11d80/2053f180>
>>edx; cafe7c60 <_end+ad11d80/2053f180>
>>edi; ce626400 <_end+e350520/2053f180>
>>esp; c7d8de08 <_end+7ab7f28/2053f180>

Code;  40a2117a Before first symbol
00000000 <_EIP>:
Code;  40a2117a Before first symbol
   0:   83 78 18 00               cmpl   $0x0,0x18(%eax)
Code;  40a2117e Before first symbol
   4:   89 c6                     mov    %eax,%esi
Code;  40a21180 Before first symbol
   6:   74 05                     je     d <_EIP+0xd>
Code;  40a21182 Before first symbol
   8:   53                        push   %ebx
Code;  40a21183 Before first symbol
   9:   ff 50 18                  call   *0x18(%eax)
Code;  40a21186 Before first symbol
   c:   58                        pop    %eax
Code;  40a21187 Before first symbol
   d:   ff 4b 2c                  decl   0x2c(%ebx)
Code;  40a2118a Before first symbol
  10:   0f 94 c0                  sete   %al
Code;  40a2118d Before first symbol
  13:   84 00                     test   %al,(%eax)

Jan  1 01:05:09 server02 kernel: Unable to handle kernel NULL pointer dereference at virtual address 00000028
Jan  1 01:05:09 server02 kernel: c0142abe
Jan  1 01:05:09 server02 kernel: *pde = 00000000
Jan  1 01:05:09 server02 kernel: Oops: 0000
Jan  1 01:05:09 server02 kernel: CPU:    0
Jan  1 01:05:09 server02 kernel: EIP:    0010:[find_inode+26/92]    Not tainted
Jan  1 01:05:09 server02 kernel: EFLAGS: 00010207
Jan  1 01:05:09 server02 kernel: eax: 0023aebb   ebx: 00000000   ecx: 0000000f   edx: c15c0000
Jan  1 01:05:09 server02 kernel: esi: 00000000   edi: 00000000   ebp: c15f8970   esp: c5957ec0
Jan  1 01:05:09 server02 kernel: ds: 0018   es: 0018   ss: 0018
Jan  1 01:05:09 server02 kernel: Process find (pid: 30875, stackpage=c5957000)
Jan  1 01:05:09 server02 kernel: Stack: 0023aebb c15f8970 0023aebb df626400 c0142df3 df626400 0023aebb c15f8970
Jan  1 01:05:09 server02 kernel:        00000000 00000000 0023aebb df626400 d44e3190 d467af20 e0859f2c df626400
Jan  1 01:05:09 server02 kernel:        0023aebb 00000000 00000000 d60646d0 d44e3190 fffffff4 cb5db260 c013965f
Jan  1 01:05:09 server02 kernel: Call Trace:    [iget4_locked+63/191] [hw_random:__insmod_hw_random_O/lib/modules/2.4.27-1-386/kernel/driver+-1179860/96] [real_lookup+77/176] [link_path_walk+1284/1791] [getname+94/150]
Jan  1 01:05:09 server02 kernel: Code: 39 46 28 89 f3 75 ed 8b 44 24 14 39 86 a0 00 00 00 75 e1 85


>>edx; c15c0000 <_end+12ea120/2053f180>
>>ebp; c15f8970 <_end+1322a90/2053f180>
>>esp; c5957ec0 <_end+5681fe0/2053f180>

Code;  40a2117a Before first symbol
00000000 <_EIP>:
Code;  40a2117a Before first symbol
   0:   39 46 28                  cmp    %eax,0x28(%esi)
Code;  40a2117d Before first symbol
   3:   89 f3                     mov    %esi,%ebx
Code;  40a2117f Before first symbol
   5:   75 ed                     jne    fffffff4 <_EIP+0xfffffff4>
Code;  40a21181 Before first symbol
   7:   8b 44 24 14               mov    0x14(%esp),%eax
Code;  40a21185 Before first symbol
   b:   39 86 a0 00 00 00         cmp    %eax,0xa0(%esi)
Code;  40a2118b Before first symbol
  11:   75 e1                     jne    fffffff4 <_EIP+0xfffffff4>
Code;  40a2118d Before first symbol
  13:   85 00                     test   %eax,(%eax)

Jan  1 01:06:49 server02 kernel:  <1>Unable to handle kernel paging request at virtual address 80000000
Jan  1 01:06:49 server02 kernel: e085bf90
Jan  1 01:06:49 server02 kernel: *pde = 00000000
Jan  1 01:06:49 server02 kernel: Oops: 0002
Jan  1 01:06:49 server02 kernel: CPU:    0
Jan  1 01:06:49 server02 kernel: EIP:    0010:[hw_random:__insmod_hw_random_O/lib/modules/2.4.27-1-386/kernel/driver+-1171568/96]    Not tainted
Jan  1 01:06:49 server02 kernel: EFLAGS: 00010286
Jan  1 01:06:49 server02 kernel: eax: e0863960   ebx: cafe78b0   ecx: 00000007   edx: 80000000
Jan  1 01:06:49 server02 kernel: esi: cafe78b0   edi: c4095e4c   ebp: 00000db6   esp: c4095e18
Jan  1 01:06:49 server02 kernel: ds: 0018   es: 0018   ss: 0018
Jan  1 01:06:49 server02 kernel: Process clamscan (pid: 30941, stackpage=c4095000)
Jan  1 01:06:49 server02 kernel: Stack: cafe78b0 c0142799 cafe78b0 cafe78b8 c014281e cafe78b0 cf5fcb48 cf5fcb40
Jan  1 01:06:49 server02 kernel:        d082d148 00000000 c0142a5f c4095e4c 00001941 cafe76e8 cb36e228 00000000
Jan  1 01:06:49 server02 kernel:        c13b9dec 00000008 000001d2 c0142a92 00001941 c012aba7 00000006 000001d2
Jan  1 01:06:49 server02 kernel: Call Trace:    [clear_inode+131/188] [dispose_list+76/140] [prune_icache+166/190] [shrink_icache_memory+27/45] [shrink_cache+583/789]
Jan  1 01:06:49 server02 kernel: Code: ff 0a 0f 94 c0 84 c0 74 07 52 e8 bf dd 8c df 58 c7 83 90 01


>>eax; e0863960 <[ext3]ext3_sops+0/50>
>>ebx; cafe78b0 <_end+ad119d0/2053f180>
>>esi; cafe78b0 <_end+ad119d0/2053f180>
>>edi; c4095e4c <_end+3dbff6c/2053f180>
>>esp; c4095e18 <_end+3dbff38/2053f180>

Code;  40a2117a Before first symbol
00000000 <_EIP>:
Code;  40a2117a Before first symbol
   0:   ff 0a                     decl   (%edx)
Code;  40a2117c Before first symbol
   2:   0f 94 c0                  sete   %al
Code;  40a2117f Before first symbol
   5:   84 c0                     test   %al,%al
Code;  40a21181 Before first symbol
   7:   74 07                     je     10 <_EIP+0x10>
Code;  40a21183 Before first symbol
   9:   52                        push   %edx
Code;  40a21184 Before first symbol
   a:   e8 bf dd 8c df            call   df8cddce <_EIP+0xdf8cddce>
Code;  40a21189 Before first symbol
   f:   58                        pop    %eax
Code;  40a2118a Before first symbol
  10:   c7 83 90 01 00 00 00      movl   $0x0,0x190(%ebx)
Code;  40a21191 Before first symbol
  17:   00 00 00


8 warnings issued.  Results may not be reliable.


It doesn't seems to be an problem with grsec, but i'll be pleases when you can help me.
:)


ED: some error with the new 2.6.10:

net/built-in.o(.text+0x61d94): In function `match':
: undefined reference to `tcp_v4_lookup_listener'
make: *** [vmlinux] Fehler 1
vendor_id
 
Posts: 4
Joined: Sun Dec 26, 2004 10:52 am


Return to grsecurity support