| Summary: | CONFIG_PAX_MPROTECT_COMPAT must be enabled in in hardened "virtualization" profile | ||
|---|---|---|---|
| Product: | Gentoo Linux | Reporter: | Anton Bolshakov <anton.bugs> |
| Component: | Hardened | Assignee: | The Gentoo Linux Hardened Kernel Team (OBSOLETE) <hardened-kernel+disabled> |
| Status: | RESOLVED NEEDINFO | ||
| Severity: | normal | ||
| Priority: | Normal | ||
| Version: | 10.0 | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Package list: | Runtime testing required: | --- | |
|
Description
Anton Bolshakov
2011-05-06 05:27:36 UTC
Hi, IIRC the Virtualization profile is meant mainly to be used with KVM and virtualbox as these are the one we test and support to some extent. Anyway maybe the people on the kernel team can be of more help than I am. Just as additional info, I've got this idea from the forum: http://forums.grsecurity.net/viewtopic.php?f=3&t=2441 and it did the trick. (In reply to comment #2) > Just as additional info, I've got this idea from the forum: > http://forums.grsecurity.net/viewtopic.php?f=3&t=2441 > > and it did the trick. I assume you tested this because I don't run vmware. I switched to virtualbox on hardened. If so, I'll enable PAX_MPROTECT_COMPAT, although I have mixed feelings about it from a security point of view. I've found a workaround for my problem and not very confident with my request any more. I'll reopen it when I have more facts and bug #382793 fixed. |