I need to run
mplex -f 8 -o /dev/stdout
In logs I see
- Code: Select all
Apr 9 02:00:56 voron [167380.903664] grsec: From 92.49.242.4: (voron:U:/) denied open of /dev/stdout for writing by /usr/bin/mplex[mplex:24847] uid/euid:1000/1000 gid/egid:100/100, parent /home/voron/camcorder/remux2[remux2:24834] uid/euid:1000/1000 gid/egid:100/100
I'm trying to enable rw to /dev/stdin and /dev/stdout in subject /, but I got an error
- Code: Select all
gradm -E -L /var/gradm.log
Error on line 105 of /etc/grsec/policy. Grsecurity does not support fine-grained policy on devpts mounts.
Please change your more fine-grained object to a /dev/pts object. This will in addition produce a better policy that will not break as unnecessarily.
The RBAC system will not load until this error is fixed.
- Code: Select all
head -105 /etc/grsec/policy|tail -1
/dev/stdin rw
- Code: Select all
role voron u
subject / {
/ s
/lib rx
/lib/grub h
/lib/iptables h
/lib/modules h
/lib/nut h
/lib/rcscripts h
/lib/security h
/lib/udev h
/var hs
/root hs
/sbin hs
/bin rxs
/dev
/dev/null rw
/dev/zero r
/dev/snd rw
/dev/urandom r
/dev/pts rw
/dev/stdin rw
/dev/stdout rw
/dev/tty rw
/dev/grsec hs
/dev/mem hs
/dev/kmem hs
/dev/port hs
/dev/log hs
/etc r
/etc/grsec hs
/etc/ssh hs
/etc/shadow hs
/etc/shadow- hs
/etc/gshadow hs
/etc/gshadow- hs
/etc/ppp/chap-secrets hs
/etc/ppp/pap-secrets hs
/etc/samba/smbpasswd hs
/media
/media/fotik rwcd
/proc r
/proc/kcore hs
/proc/bus hs
/proc/sys hs
/tmp rwcdl
/var/tmp rwcdl
/usr
/usr/kde rx
/usr/libexec rxs
/usr/qt/3 rxs
/usr/bin rxs
/usr/lib rxs
/usr/local
/usr/opt rx
/usr/share rxs
/var/cache/fontconfig r
/usr/src hs
/usr/d1 hs
/usr/d2 hs
/sys hs
/boot hs
/home s
#voron specefic
/home/voron rwcdlx
/home/* hs
/usr/data rwcdl
# /usr/1data rwcdl
-CAP_ALL
bind disabled
#DNS
connect 0.0.0.0/0:53 dgram udp
#cups
connect 127.0.0.1/32:631 stream tcp
}
- Code: Select all
Apr 9 02:34:43 voron [169405.502889] grsec: From 92.49.242.4: (voron:U:/) denied open of /proc/25985/fd/1 for writing by /usr/bin/mplex[mplex:25985] uid/euid:1000/1000 gid/egid:100/100, parent /home/voron/camcorder/remux2[remux2:25972] uid/euid:1000/1000 gid/egid:100/100