2.6.14 is out

Discuss and suggest new grsecurity features

2.6.14 is out

Postby Dodger » Fri Oct 28, 2005 4:28 am

Hi,

can anyone provide a working patch for 2.6.14 for testing ?

:-))

Time for another stable grsec release ?

Thx for your good work
Dodger
 
Posts: 29
Joined: Tue May 17, 2005 5:59 am

Postby Hal9000 » Fri Oct 28, 2005 6:53 am

i think kernel 2.6.15 will be released before grsec on 2.6.14 will be stable :) just look at what happened to the 2.6.13 patch ;)
so i guess the most realistic target is getting the stable patch for 2.6.13.4, afaik 2.6.14 doesnt fix any major security issues...
Hal9000
 
Posts: 78
Joined: Wed Jun 16, 2004 2:40 am

stable

Postby Dodger » Fri Oct 28, 2005 8:03 am

2.6.14 is released as latest stable kernel.

im trusting this so far.

the last known good grsec release is for 2.6.11.12 and i think 2.6.14 is some good steps ahead ...

btw im also available for cvs testing, but latest spender patch is from 19-10-2005 ..... and it isnt working on 2.6.14

;-)
Dodger
 
Posts: 29
Joined: Tue May 17, 2005 5:59 am

Postby bb » Sat Oct 29, 2005 3:34 pm

There is grsec patch for 2.6.14 in ~spender dir:
http://grsecurity.org/~spender/grsecuri ... 1211.patch
bb
 
Posts: 1
Joined: Sat Oct 29, 2005 3:33 pm

Postby bani » Sun Oct 30, 2005 3:48 am

anyone tested it yet?
bani
 
Posts: 15
Joined: Sun Aug 28, 2005 10:56 pm

Postby forsaken » Sun Oct 30, 2005 6:49 am

Yeah, I'm using it now. Works well for me.
forsaken
 
Posts: 74
Joined: Tue May 18, 2004 3:04 am

Spender?

Postby Blueroot » Sun Oct 30, 2005 4:25 pm

Hi spender,

can you tell us if a new stable grsecurity is planed?

Thanks Blueroot
Blueroot
 
Posts: 3
Joined: Sat Aug 27, 2005 6:50 pm

Postby Wolfi » Mon Oct 31, 2005 5:52 am

In my kernel hangs kernel on this new patch while starting (signal 11 in log).
Previous (2.6.13.2) works well. Nothing changed in kernel config or in grsecurity config in my case. So I'll wait for stable.
Last edited by Wolfi on Tue Nov 01, 2005 2:06 am, edited 1 time in total.
Wolfi
 
Posts: 5
Joined: Sat Oct 29, 2005 3:38 pm

Postby mscnln » Mon Oct 31, 2005 5:23 pm

Interesting, 2.6.13.4 would freeze on boot for me, but 2.6.14 has been working without any issues.
mscnln
 
Posts: 1
Joined: Mon Oct 31, 2005 5:18 pm

Gaim

Postby tuxq » Thu Nov 03, 2005 3:57 am

This is rather odd, Gaim isn't able to find the protocol plugin while using 2.6.14 with grsecurity-2.1.7-2.6.14-200510291211.patch ...Any ideas?

Oh, and no errors in syslog, messages or secure

Update: Went back to 2.6.13.1 w/ GRSec patch, no problems with gaim.
Weird [bug]?

Has PAX changed anything since the 2.6.13.1 GRSec patch?
tuxq
 
Posts: 34
Joined: Sun Mar 06, 2005 5:59 am

Re: Gaim

Postby PaX Team » Thu Nov 03, 2005 12:51 pm

tuxq wrote:This is rather odd, Gaim isn't able to find the protocol plugin while using 2.6.14 with grsecurity-2.1.7-2.6.14-200510291211.patch ...Any ideas?
can you produce strace -f outputs please (both for the working and non-working kernels)? they will probably be big, so better put them on a website, or maybe email them to me directly (especially if it contains some sensitive info, check it first).
PaX Team
 
Posts: 2310
Joined: Mon Mar 18, 2002 4:35 pm

Postby tuxq » Thu Nov 03, 2005 1:29 pm

Sure. Give me a few minutes.

Update: Sent to your e-mail, PaX
tuxq
 
Posts: 34
Joined: Sun Mar 06, 2005 5:59 am

Postby Ron » Thu Nov 03, 2005 7:30 pm

I tried this patch with a working 2.6.14 kernel, it hangs, I didnt enable much I wanted to see how well it would work. pax is unchecked, very little under grsecurity is enabled...

Last couple lines:
CFS: Mounted root (ext3 filesystem) readonly.
Freeing unsused kernel memory: 340k freed

and thats it.. doesnt get to the init
Ron
 
Posts: 4
Joined: Thu Nov 03, 2005 3:11 pm

Postby PaX Team » Thu Nov 03, 2005 8:00 pm

tuxq wrote:Sure. Give me a few minutes.

Update: Sent to your e-mail, PaX
are you sure you sent it to the right address? it didn't make it here yet...
PaX Team
 
Posts: 2310
Joined: Mon Mar 18, 2002 4:35 pm

Postby PaX Team » Thu Nov 03, 2005 8:02 pm

Ron wrote:Last couple lines:
CFS: Mounted root (ext3 filesystem) readonly.
Freeing unsused kernel memory: 340k freed

and thats it.. doesnt get to the init
yes, i know of this one and am working on it.
PaX Team
 
Posts: 2310
Joined: Mon Mar 18, 2002 4:35 pm

Next

Return to grsecurity development