Deleted (file)

Discuss usability issues, general maintenance, and general support issues for a grsecurity-enabled system.

Deleted (file)

Postby ralphy » Fri Jul 13, 2007 9:23 pm

Somebody mind telling me how to fix this?

This occurred primarily after a gentoo update (I forgot which one). Restarted using gradm but that was to no avail. Any possible way to fix this other than a reboot?

Code: Select all
Jul 14 02:48:28 HOSTNAME grsec: (default:D:/) denied access to hidden file /dev/md0 by /var/tmp/portage/sys-fs/mdadm-2.6.2/image/sbin (deleted)/mdadm[mdadm:2066] uid/euid:0/0 gid/egid:0/0, parent /sbin/init[init:1] uid/euid:0/0 gid/egid:0/0
Jul 14 02:48:28 HOSTNAME grsec: (default:D:/) denied access to hidden file /dev by /var/tmp/portage/sys-fs/mdadm-2.6.2/image/sbin (deleted)/mdadm[mdadm:2066] uid/euid:0/0 gid/egid:0/0, parent /sbin/init[init:1] uid/euid:0/0 gid/egid:0/0
ralphy
 
Posts: 52
Joined: Wed Jan 11, 2006 12:51 pm

Postby zakalwe » Sat Jul 14, 2007 8:35 am

I think this happens when the file is still in use but overwritten. Restart whatever service got updated and that should fix it I think.
zakalwe
 
Posts: 22
Joined: Mon Jul 10, 2006 9:40 am

Postby ralphy » Sat Jul 14, 2007 4:38 pm

Such a simple solution, don't know why I hadn't thought of it, heh. Many thanks for the help :)
ralphy
 
Posts: 52
Joined: Wed Jan 11, 2006 12:51 pm

Postby spender » Wed Jul 18, 2007 7:31 pm

What version of grsecurity are you using, and on what kernel? You shouldn't have "(deleted)" appearing in any of your pathnames.

-Brad
spender
 
Posts: 2185
Joined: Wed Feb 20, 2002 8:00 pm

Postby zakalwe » Thu Jul 19, 2007 2:35 pm

I've seen these messages after upgrading a running service. It happens with 2.6.21.6-grsec, and I'm pretty sure it has been like that for a while. I never thought anything of it, because the service needs restarted anyway. :)
zakalwe
 
Posts: 22
Joined: Mon Jul 10, 2006 9:40 am

Postby ralphy » Sat Jul 21, 2007 3:39 pm

It's linux-2.4.34, grsec 2.1.10

mdadm had just been upgraded. After following the advice of the previous poster, the error had disappeared.
ralphy
 
Posts: 52
Joined: Wed Jan 11, 2006 12:51 pm

Postby spender » Wed Aug 01, 2007 8:04 pm

This will be fixed in grsecurity 2.1.11. A patch for 2.4.35 already exists in ~spender and 2.6.22 will follow soon. The problem manifests itself only when the parent directory of a removed file is also removed.

-Brad
spender
 
Posts: 2185
Joined: Wed Feb 20, 2002 8:00 pm

Postby ralphy » Wed Aug 01, 2007 10:21 pm

Ah. Thanks spender.
ralphy
 
Posts: 52
Joined: Wed Jan 11, 2006 12:51 pm


Return to grsecurity support