Closed psivesely closed 7 years ago
In paxrat.conf you currently have two entries for /usr/sbin/grub-probe. Firstly, this should be both caught by paxrat -t paxrat.conf, and logged as an error when applied at runtime.
paxrat.conf
/usr/sbin/grub-probe
paxrat -t paxrat.conf
Since you have PAX_EMUTRAMP=y set in your latest kernel conffig, I believe you'll want to go with just the E flag (see https://en.wikibooks.org/wiki/Grsecurity/Application-specific_Settings#Grub).
PAX_EMUTRAMP=y
E
The other weird thing I noticed is that the flags that actually result from applying this config are me instead of mE as one might expect.
me
mE
Resolved via 121745eee6bccf2359ee0da6272553e92865eec2.
In
paxrat.conf
you currently have two entries for/usr/sbin/grub-probe
. Firstly, this should be both caught bypaxrat -t paxrat.conf
, and logged as an error when applied at runtime.Since you have
PAX_EMUTRAMP=y
set in your latest kernel conffig, I believe you'll want to go with just theE
flag (see https://en.wikibooks.org/wiki/Grsecurity/Application-specific_Settings#Grub).The other weird thing I noticed is that the flags that actually result from applying this config are
me
instead ofmE
as one might expect.