Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 313699 - teamspeak-server-bin-3.0.0_beta20: could not be started because grsec denies untrusted exec
Summary: teamspeak-server-bin-3.0.0_beta20: could not be started because grsec denies ...
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: Hardened (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: The Gentoo Linux Hardened Team
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2010-04-07 16:36 UTC by Timo Eissler
Modified: 2012-12-20 09:34 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Timo Eissler 2010-04-07 16:36:42 UTC
The ts3server-bin could not be started as teamspeak3 because grsec policy denies the untrusted execution.



Reproducible: Always

Steps to Reproduce:
1. emerge teamspeak-server-bin
2. change /etc/init.d/teamspeak3-server as described here (Gentoo Bugzilla Bug 303621)
3. /etc/init.d/teamspeak3-server start
4. look at dmesg or /var/log/kern.log

Actual Results:  
Apr  7 18:20:14 echo517 kernel: grsec: From <ip>: denied untrusted exec of /opt/teamspeak3-server/ts3server-bin by /sbin/st
art-stop-daemon[start-stop-daem:3999] uid/euid:108/108 gid/egid:1019/1019, parent /sbin/init[init:1] uid/euid:0/0 gid/egid:0/0

Expected Results:  
ts3server-bin start without an error

Portage 2.1.7.17 (hardened/linux/x86/10.0, gcc-4.3.4, glibc-2.10.1-r1, 2.6.27-hardened-r8_20090301-1 i686)
=================================================================
System uname: Linux-2.6.27-hardened-r8_20090301-1-i686-Dual-Core_AMD_Opteron-tm-_Processor_1212_HE-with-gentoo-1.12.13
Timestamp of tree: Wed, 07 Apr 2010 01:15:01 +0000
ccache version 2.4 [disabled]
app-shells/bash:     4.0_p37
dev-java/java-config: 2.1.10
dev-lang/python:     2.5.4-r3, 2.6.4-r1
dev-python/pycrypto: 2.1.0_beta1
dev-util/ccache:     2.4-r7
sys-apps/baselayout: 1.12.13
sys-apps/sandbox:    1.6-r2
sys-devel/autoconf:  2.63-r1
sys-devel/automake:  1.9.6-r2, 1.10.3, 1.11.1
sys-devel/binutils:  2.18-r3
sys-devel/gcc:       3.4.6-r2, 4.3.4
sys-devel/gcc-config: 1.4.1
sys-devel/libtool:   2.2.6b
virtual/os-headers:  2.6.30-r1
ACCEPT_KEYWORDS="x86"
ACCEPT_LICENSE="* -@EULA dlj-1.1"
CBUILD="i686-pc-linux-gnu"
CFLAGS="-mtune=i686 -O2 -pipe -fforce-addr"
CHOST="i686-pc-linux-gnu"
CONFIG_PROTECT="/etc /opt/openfire/resources/security/ /var/bind"
CONFIG_PROTECT_MASK="/etc/ca-certificates.conf /etc/env.d /etc/env.d/java/ /etc/fonts/fonts.conf /etc/gconf /etc/php/apache2-php5/ext-active/ /etc/php/cgi-php5/ext-active/ /etc/php/cli-php5/ext-active/ /etc/revdep-rebuild /etc/sandbox.d /etc/terminfo /etc/udev/rules.d"
CXXFLAGS="-mtune=i686 -O2 -pipe -fforce-addr"
DISTDIR="/usr/portage/distfiles"
FEATURES="assume-digests distlocks fixpackages news parallel-fetch protect-owned sandbox sfperms strict unmerge-logs unmerge-orphans userfetch"
GENTOO_MIRRORS="http://mirrors.sec.informatik.tu-darmstadt.de/gentoo/ ftp://ftp-stud.fht-esslingen.de/pub/Mirrors/gentoo/ "
LANG="de_DE.UTF-8"
LC_ALL="de_DE.UTF-8"
LDFLAGS="-Wl,-O1"
MAKEOPTS="-j3"
PKGDIR="/usr/portage/packages"
PORTAGE_CONFIGROOT="/"
PORTAGE_RSYNC_OPTS="--recursive --links --safe-links --perms --times --compress --force --whole-file --delete --stats --timeout=180 --exclude=/distfiles --exclude=/local --exclude=/packages"
PORTAGE_TMPDIR="/var/tmp"
PORTDIR="/usr/portage"
SYNC="rsync://rsync.europe.gentoo.org/gentoo-portage"
USE="3dnow 3dnowext acl apache2 berkdb bzip2 cli cracklib crypt cups cxx dri fam gd gdbm gpm hardened iconv imap ipv6 logrotate maildir mmx modules mudflap mysql ncurses nls nptl nptlonly openmp pam pcre perl pic posix pppd python readline reflection session spl sse sse2 ssl sysfs tcpd tiff unicode urandom userlocales vhosts x86 xml xorg zlib" ALSA_CARDS="ali5451 als4000 atiixp atiixp-modem bt87x ca0106 cmipci emu10k1         emu10k1x ens1370 ens1371 es1938 es1968 fm801 hda-intel intel8x0 intel8x0m       maestro3 trident usb-audio via82xx via82xx-modem ymfpci" ALSA_PCM_PLUGINS="adpcm alaw asym copy dmix dshare dsnoop empty extplug file hooks iec958 ioplug ladspa lfloat linear meter mmap_emul mulaw multi null plug rate route share shm softvol" APACHE2_MODULES="actions alias auth_basic auth_digest authn_anon authn_dbd authn_dbm authn_default authn_file authz_dbm authz_default authz_groupfile authz_host authz_owner authz_user autoindex cache dav dav_fs dav_lock dbd deflate dir disk_cache env expires ext_filter file_cache filter headers ident imagemap include info log_config logio mem_cache mime mime_magic negotiation proxy proxy_ajp proxy_balancer proxy_connect proxy_http rewrite setenvif so speling status unique_id userdir usertrack vhost_alias" ELIBC="glibc" INPUT_DEVICES="keyboard mouse evdev" KERNEL="linux" LCD_DEVICES="bayrad cfontz cfontz633 glk hd44780 lb216 lcdm001 mtxorb ncurses text" RUBY_TARGETS="ruby18" USERLAND="GNU" VIDEO_CARDS="apm ark chips cirrus cyrix dummy fbdev glint i128 i740 intel  mach64 mga neomagic nsc nv r128 radeon rendition s3 s3virge savage        siliconmotion sis sisusb tdfx tga trident tseng v4l vesa via vmware     voodoo" 
Unset:  CPPFLAGS, CTARGET, EMERGE_DEFAULT_OPTS, FFLAGS, INSTALL_MASK, LINGUAS, PORTAGE_COMPRESS, PORTAGE_COMPRESS_FLAGS, PORTAGE_RSYNC_EXTRA_OPTS, PORTDIR_OVERLAY
Comment 1 Benjamin Börngen-Schmidt 2011-01-06 12:07:32 UTC
when patching the init script with my attached patch from #346059 the server starts up fine on my hardened system.
I think this bug can be closed.

-benjamin
Comment 2 Pacho Ramos gentoo-dev 2012-11-18 10:16:36 UTC
Still valid with teamspeak-server-bin-3.0.6.1?
Comment 3 Timo Eissler 2012-12-20 09:34:36 UTC
No this problem is fixed with teamspeak-server-bin-3.0.6.1.

With this version it runs without any manual intervention on my hardened system.