[bug] full learning mode with 2.1.11-2.6.24

Discuss and suggest new grsecurity features

[bug] full learning mode with 2.1.11-2.6.24

Postby tobij » Wed Jun 11, 2008 9:17 am

Full learning mode seems broken with grsecurity-2.1.11-2.6.24.5-200804211829 and gradm-2.1.11-200804142058 - and the shipped default policy.

Code: Select all
[root@localhost gradm2]# gradm -E -F -L /tmp/learn
Duplicate role :::kernel::: on line 300 of /etc/grsec/policy.
The RBAC system will not be allowed to be enabled until this error is fixed.
[root@localhost gradm2]# uname -a
Linux localhost.localdomain 2.6.24.5-grsec #1 SMP Mon May 19 01:12:56 CEST 2008 i686 i686 i386 GNU/Linux
[root@localhost gradm2]# gradm -v
gradm v2.1.11
Licensed under the GNU General Public License (GPL) version 2 or higher
Copyright 2002,2003,2004  Brad Spengler
[root@localhost gradm2]# md5sum /etc/grsec/policy
71d1fcbb43546a24e421b8ef5992c4ad  /etc/grsec/policy
tobij
 
Posts: 6
Joined: Fri Jan 18, 2008 10:54 am

Re: [bug] full learning mode with 2.1.11-2.6.24

Postby spender » Thu Jun 19, 2008 3:36 pm

IIRC, full learning is enabled by using gradm -F -L <learninglogfile>, no -E is used. I'll fix this particular combination of flags so you get the usage screen when trying to use it.

-Brad
spender
 
Posts: 2185
Joined: Wed Feb 20, 2002 8:00 pm


Return to grsecurity development

cron