denied executable mmap

Discuss usability issues, general maintenance, and general support issues for a grsecurity-enabled system.

denied executable mmap

Postby vpolyakov » Thu Jan 23, 2003 9:12 am

Me again! :lol:
hopefully the last time i have to bug you people with my petty problems.. im sure i annoyed all of you already

but anyway

Jan 23 07:15:42 dev-null kernel: grsec: denied executable mmap of /dev/zero by (wolf.x86:2123) UID(1002) EUID(1002), parent (wolfmp:2122) UID(1002) EUID(1002)

with the ACL for wolf.x86:

/usr/local/games/wolfenstein/wolf.x86 oOX {
/usr/local/games/wolfenstein/main r
/usr/local/games/wolfenstein
/usr/lib/libGLcore.so.1.0.4191 rx
/usr/X11R6/lib/libXext.so.6.4 rx
/usr/X11R6/lib/libX11.so.6.2 rx
/tmp/.X11-unix/X0 rw
/lib/ld-2.2.5.so x
/home/vpolyakov/.wolf/main r
/home/vpolyakov/.wolf w
/home/vpolyakov/.Xauthority r
/home/vpolyakov
/etc/passwd r
/etc/nsswitch.conf r
/etc/ld.so.cache r
/ r
/opt rx
/home rxw
/mnt rw
/dev
/dev/urandom r
/dev/random r
/dev/zero rw
/dev/input rw
/dev/psaux rw
/dev/nvidiactl rw
/dev/nvidia1 rw
/dev/null rw
/dev/tty0 rw
/dev/tty1 rw
/dev/tty2 rw
/dev/tty3 rw
/dev/tty4 rw
/dev/tty5 rw
/dev/tty6 rw
/dev/tty7 rw
/dev/tty8 rw
/dev/console rw
/dev/tty rw
/dev/pts rw
/dev/ptmx rw
/dev/dsp rw
/dev/mixer rw
/dev/ippp0 rw
/dev/ippp1 rw
/dev/ippp2 rw
/dev/ippp3 rw
/dev/ippp4 rw
/dev/ippp5 rw
/dev/ippp6 rw
/dev/ippp7 rw
/dev/initctl rw
/dev/fd0 r
/dev/cdrom r
/dev/mem h
/dev/kmem h
/dev/port h
/bin rx
/sbin rx
/lib rx
/usr/lib/libGL.so.1 rx
/usr/lib/libGL.so.1.0.4191 rx
/usr rx
/etc rx
/proc rxw
/proc/kcore h
/proc/sys r
/root r
/tmp rw
/var rxw
/var/tmp rw
/var/log r
/boot r
/etc/grsec h
/usr/local/games/wolfenstein/wolf.x86 x
+CAP_ALL
-CAP_LINUX_IMMUTABLE
-CAP_NET_RAW
-CAP_SYS_MODULE
-CAP_SYS_RAWIO
-CAP_MKNOD
}

1.9.9.-rc3
with the latest devel gradm

Thanks!
vpolyakov
 
Posts: 7
Joined: Tue Jan 21, 2003 12:36 pm

Postby spender » Thu Jan 23, 2003 10:08 am

all you have to do is give rwx to /dev/zero. The ACL system won't complain since you have "O" in the subject mode.

-Brad
spender
 
Posts: 2185
Joined: Wed Feb 20, 2002 8:00 pm


Return to grsecurity support

cron