Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 575340 - app-crypt/letsencrypt 0.4.0-run-time segfault on gentoo hardened
Summary: app-crypt/letsencrypt 0.4.0-run-time segfault on gentoo hardened
Status: RESOLVED INVALID
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: Current packages (show other bugs)
Hardware: AMD64 Linux
: Normal normal (vote)
Assignee: Manuel Rüger (RETIRED)
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2016-02-21 23:44 UTC by Vitaliy
Modified: 2016-03-02 01:57 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments
emerge --info (emerge.info,5.27 KB, text/plain)
2016-02-21 23:44 UTC, Vitaliy
Details

Note You need to log in before you can comment on or make changes to this bug.
Description Vitaliy 2016-02-21 23:44:39 UTC
Created attachment 426158 [details]
emerge --info

Even simple cmd "letsencrypt --help" leads to Segmentation fault.

On non-hardened system all works fine.

grsec.log entry:

Feb 22 04:27:56 localhost kernel: [1267249.382734] grsec: From 10.0.0.2: denied RWX mmap of <anonymous mapping> by /usr/lib64/python-exec/python2.7/letsencrypt[letsencrypt:15950] uid/euid:0/0 gid/egid:0/0, parent /bin/bash[bash:15430] uid/euid:0/0 gid/egid:0/0

Feb 22 04:27:56 localhost kernel: [1267249.382751] grsec: From 10.0.0.2: Segmentation fault occurred at            (nil) in /usr/lib64/python-exec/python2.7/letsencrypt[letsencrypt:15950] uid/euid:0/0 gid/egid:0/0, parent /bin/bash[bash:15430] uid/euid:0/0 gid/egid:0/0

Feb 22 04:27:56 localhost kernel: [1267249.382763] grsec: From 10.0.0.2: denied resource overstep by requesting 4096 for RLIMIT_CORE against limit 0 for /usr/lib64/python-exec/python2.7/letsencrypt[letsencrypt:15950] uid/euid:0/0 gid/egid:0/0, parent /bin/bash[bash:15430] uid/euid:0/0 gid/egid:0/0
Comment 1 Magnus Granberg gentoo-dev 2016-02-23 15:40:24 UTC
Check that you have emutramp enable in the kernel.
Comment 2 Vitaliy 2016-03-02 01:57:49 UTC
(In reply to Magnus Granberg from comment #1)
> Check that you have emutramp enable in the kernel.

Thx! it works now.

p.s. i've used tipical config Automatic - Host - KVM - Security