Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 490366 - sys-apps/systemd - Check that CONFIG_GRKERNSEC_PROC is disabled when running hardened, or at least warn about it.
Summary: sys-apps/systemd - Check that CONFIG_GRKERNSEC_PROC is disabled when running ...
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: [OLD] Core system (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo systemd Team
URL: https://bugs.freedesktop.org/show_bug...
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2013-11-04 11:32 UTC by Tom Wijsman (TomWij) (RETIRED)
Modified: 2013-11-04 12:32 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Tom Wijsman (TomWij) (RETIRED) gentoo-dev 2013-11-04 11:32:43 UTC
In the following thread

http://forums.gentoo.org/viewtopic-t-974630.html

an user had problems with permissions that disallowed the user from configuring NetworkManager, he found the following thread after a while

https://bugs.freedesktop.org/show_bug.cgi?id=65575

which shows that this is due to CONFIG_GRKERNSEC_PROC so please consider to check or warn for this, users are experiencing trouble when they don't know about it.

Thank you very much in advance.
Comment 1 Michał Górny archtester Gentoo Infrastructure gentoo-dev Security 2013-11-04 11:59:04 UTC
Sure. Is it the most accurate and only option that needs to be disabled for hardened?
Comment 2 Agostino Sarubbo gentoo-dev 2013-11-04 12:08:44 UTC
(In reply to Tom Wijsman (TomWij) from comment #0)
> In the following thread
> 
> http://forums.gentoo.org/viewtopic-t-974630.html
> 
> an user had problems with permissions that disallowed the user from
> configuring NetworkManager, he found the following thread after a while
> 
> https://bugs.freedesktop.org/show_bug.cgi?id=65575
> 
> which shows that this is due to CONFIG_GRKERNSEC_PROC so please consider to
> check or warn for this, users are experiencing trouble when they don't know
> about it.
> 
> Thank you very much in advance.

sounds like a dupe of 472098



(In reply to Michał Górny from comment #1)
> Sure. Is it the most accurate and only option that needs to be disabled for
> hardened?

yes
Comment 3 Michał Górny archtester Gentoo Infrastructure gentoo-dev Security 2013-11-04 12:32:34 UTC
/var/cvsroot/gentoo-x86/sys-apps/systemd/systemd-204-r1.ebuild,v  <--  systemd-204-r1.ebuild
new revision: 1.9; previous revision: 1.8
/var/cvsroot/gentoo-x86/sys-apps/systemd/systemd-208-r2.ebuild,v  <--  systemd-208-r2.ebuild
new revision: 1.4; previous revision: 1.3
/var/cvsroot/gentoo-x86/sys-apps/systemd/systemd-9999.ebuild,v  <--  systemd-9999.ebuild
new revision: 1.71; previous revision: 1.70

Added.