undocumented object flag / strange learning behavior

Discuss usability issues, general maintenance, and general support issues for a grsecurity-enabled system.

undocumented object flag / strange learning behavior

Postby TGKx » Sun Feb 23, 2003 4:57 am

Sorry to bother you again, I was running my grsec in learn mode against newest cvs and there is an "s" object flag which i assume is the new 'suppress' functionality.

It seems to be replacing where there would normally be "h" flags on directory objects.

It is getting added to a ton of lines now when it wasnt a before 2 days ago.

/sbin/shutdown o {
/var/run/utmp rws
/var/run/shutdown.pid ws
/var/run s
/usr/share/zoneinfo/US/Central rs
/sbin/init xs
/proc/5911/fd/0 s
/proc/5911 s
/proc/32585/fd/0 s
/proc/32585 s
/proc/18190/fd/0 s
/proc/18190 s
/lib/libnss_compat-2.2.5.so rxs
/lib/libnsl-2.2.5.so rxs
/lib/libc-2.2.5.so rxs
/lib/ld-2.2.5.so xs
/etc/passwd rs
/etc/nsswitch.conf rs
/etc/ld.so.cache rs
/etc s
/dev/pts/1 ws
/dev/pts/0 ws
/sbin/shutdown xs
/ s
-CAP_ALL
+CAP_DAC_OVERRIDE
+CAP_SETUID
connect {
disabled
}
bind {
disabled
}
}

Can I have a little info on what this thing is supposed to do and if its acting properly at this time?

Thanks

-TGK
TGKx
 
Posts: 50
Joined: Wed Feb 19, 2003 4:39 am

Postby spender » Sun Feb 23, 2003 4:16 pm

Sorry about that, I forgot to remove the suppression flag when learning mode is used. It's fixed in current CVS. You'll have to clean out the old learning logs.

-Brad
spender
 
Posts: 2185
Joined: Wed Feb 20, 2002 8:00 pm


Return to grsecurity support