Kernel borks with grsecurity(pax) + 2.6.10

Discuss usability issues, general maintenance, and general support issues for a grsecurity-enabled system.

Kernel borks with grsecurity(pax) + 2.6.10

Postby forsaken » Tue Jan 11, 2005 6:31 pm

Hi,

when I use grsecurity-2.1.0-2.6.10-200501081640 + sec patches with 2.6.10 and enable PAX I'm unable to boot. I've tried with 2 different machines (both x86) and the same problem occurs.

Lilo/Grub loads the kernel and I immediately get a kernel panic preceded by a bunch of numbers in [] and a code about EIP. Sorry since it dies directly I can't give the exact error message.

This happens only when PAX is enabled if I disable PAX but keep the "normal" grsecurity options the kernel boots fine. I tried without "Randomize kernel stack base" but with the same result.

Any thoughts ?

My config:

CONFIG_GRKERNSEC=y
# CONFIG_GRKERNSEC_LOW is not set
# CONFIG_GRKERNSEC_MEDIUM is not set
# CONFIG_GRKERNSEC_HIGH is not set
CONFIG_GRKERNSEC_CUSTOM=y

CONFIG_GRKERNSEC_KMEM=y
# CONFIG_GRKERNSEC_IO is not set
CONFIG_GRKERNSEC_PROC_MEMMAP=y
CONFIG_GRKERNSEC_BRUTE=y
CONFIG_GRKERNSEC_HIDESYM=y

CONFIG_GRKERNSEC_ACL_HIDEKERN=y
CONFIG_GRKERNSEC_ACL_MAXTRIES=3
CONFIG_GRKERNSEC_ACL_TIMEOUT=30

CONFIG_GRKERNSEC_PROC=y
# CONFIG_GRKERNSEC_PROC_USER is not set
CONFIG_GRKERNSEC_PROC_USERGROUP=y
CONFIG_GRKERNSEC_PROC_GID=10
CONFIG_GRKERNSEC_PROC_ADD=y
CONFIG_GRKERNSEC_LINK=y
CONFIG_GRKERNSEC_FIFO=y
CONFIG_GRKERNSEC_CHROOT=y
CONFIG_GRKERNSEC_CHROOT_MOUNT=y
CONFIG_GRKERNSEC_CHROOT_DOUBLE=y
CONFIG_GRKERNSEC_CHROOT_PIVOT=y
CONFIG_GRKERNSEC_CHROOT_CHDIR=y
CONFIG_GRKERNSEC_CHROOT_CHMOD=y
CONFIG_GRKERNSEC_CHROOT_FCHDIR=y
CONFIG_GRKERNSEC_CHROOT_MKNOD=y
CONFIG_GRKERNSEC_CHROOT_SHMAT=y
CONFIG_GRKERNSEC_CHROOT_UNIX=y
CONFIG_GRKERNSEC_CHROOT_FINDTASK=y
CONFIG_GRKERNSEC_CHROOT_NICE=y
CONFIG_GRKERNSEC_CHROOT_SYSCTL=y
CONFIG_GRKERNSEC_CHROOT_CAPS=y

# CONFIG_GRKERNSEC_AUDIT_GROUP is not set
# CONFIG_GRKERNSEC_EXECLOG is not set
CONFIG_GRKERNSEC_RESLOG=y
# CONFIG_GRKERNSEC_CHROOT_EXECLOG is not set
# CONFIG_GRKERNSEC_AUDIT_CHDIR is not set
CONFIG_GRKERNSEC_AUDIT_MOUNT=y
# CONFIG_GRKERNSEC_AUDIT_IPC is not set
CONFIG_GRKERNSEC_SIGNAL=y
# CONFIG_GRKERNSEC_FORKFAIL is not set
# CONFIG_GRKERNSEC_TIME is not set
# CONFIG_GRKERNSEC_PROC_IPADDR is not set
# CONFIG_GRKERNSEC_AUDIT_TEXTREL is not set

CONFIG_GRKERNSEC_EXECVE=y
CONFIG_GRKERNSEC_SHM=y
CONFIG_GRKERNSEC_DMESG=y
CONFIG_GRKERNSEC_RANDPID=y
# CONFIG_GRKERNSEC_TPE is not set

CONFIG_GRKERNSEC_RANDNET=y
CONFIG_GRKERNSEC_RANDISN=y
CONFIG_GRKERNSEC_RANDID=y
CONFIG_GRKERNSEC_RANDSRC=y
CONFIG_GRKERNSEC_RANDRPC=y
# CONFIG_GRKERNSEC_SOCKET is not set

# CONFIG_GRKERNSEC_SYSCTL is not set

CONFIG_GRKERNSEC_FLOODTIME=10
CONFIG_GRKERNSEC_FLOODBURST=4

CONFIG_PAX=y

# CONFIG_PAX_SOFTMODE is not set
CONFIG_PAX_EI_PAX=y
CONFIG_PAX_PT_PAX_FLAGS=y
CONFIG_PAX_NO_ACL_FLAGS=y
# CONFIG_PAX_HAVE_ACL_FLAGS is not set
# CONFIG_PAX_HOOK_ACL_FLAGS is not set

CONFIG_PAX_NOEXEC=y
# CONFIG_PAX_PAGEEXEC is not set
CONFIG_PAX_SEGMEXEC=y
CONFIG_PAX_EMUTRAMP=y
CONFIG_PAX_MPROTECT=y
# CONFIG_PAX_NOELFRELOCS is not set
CONFIG_PAX_KERNEXEC=y

CONFIG_PAX_ASLR=y
CONFIG_PAX_RANDKSTACK=y
CONFIG_PAX_RANDUSTACK=y
CONFIG_PAX_RANDMMAP=y
CONFIG_PAX_RANDEXEC=y
CONFIG_PAX_NOVSYSCALL=y
forsaken
 
Posts: 74
Joined: Tue May 18, 2004 3:04 am

Postby crusader » Tue Jan 11, 2005 6:37 pm

disable this and try again CONFIG_PAX_KERNEXEC
crusader
 
Posts: 17
Joined: Tue Dec 21, 2004 7:25 am

Re: Kernel borks with grsecurity(pax) + 2.6.10

Postby PaX Team » Wed Jan 12, 2005 8:39 am

forsaken wrote:when I use grsecurity-2.1.0-2.6.10-200501081640 + sec patches with 2.6.10 and enable PAX I'm unable to boot. I've tried with 2 different machines (both x86) and the same problem occurs.

Lilo/Grub loads the kernel and I immediately get a kernel panic preceded by a bunch of numbers in [] and a code about EIP. Sorry since it dies directly I can't give the exact error message.
first check the PCI access method in your .config, it should be 'direct'. if it already is, send me your full .config please (or put it on the web).
PaX Team
 
Posts: 2310
Joined: Mon Mar 18, 2002 4:35 pm

Postby forsaken » Wed Jan 12, 2005 12:27 pm

crusader, thx it works now.

PAX Team, It was "any", I will recompile with "direct" and CONFIG_PAX_KERNEXEC turned on and see if it works then.
forsaken
 
Posts: 74
Joined: Tue May 18, 2004 3:04 am

Postby forsaken » Wed Jan 12, 2005 3:41 pm

Enabling "direct" mode made the kernel boot, thx.
forsaken
 
Posts: 74
Joined: Tue May 18, 2004 3:04 am


Return to grsecurity support