<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="https://forum.alpinelinux.org"  xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
 <title>Alpine Linux forums - PaX &amp; grsecurity</title>
 <link>https://forum.alpinelinux.org/taxonomy/term/5</link>
 <description></description>
 <language>en</language>
<item>
 <title>Future of GRSecurity in Alpine?</title>
 <link>https://forum.alpinelinux.org/forum/pax-grsecurity/future-grsecurity-alpine</link>
 <description>&lt;div class=&quot;field field-name-taxonomy-forums field-type-taxonomy-term-reference field-label-above&quot;&gt;&lt;div class=&quot;field-label&quot;&gt;Forums:&amp;nbsp;&lt;/div&gt;&lt;div class=&quot;field-items&quot;&gt;&lt;div class=&quot;field-item even&quot;&gt;&lt;a href=&quot;/forums/pax-grsecurity&quot;&gt;PaX &amp;amp; grsecurity&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;field field-name-body field-type-text-with-summary field-label-hidden&quot;&gt;&lt;div class=&quot;field-items&quot;&gt;&lt;div class=&quot;field-item even&quot;&gt;&lt;p&gt;With the end of public grsecurity patches (&lt;a href=&quot;https://grsecurity.net/passing_the_baton_faq.php&quot; rel=&quot;nofollow&quot;&gt;https://grsecurity.net/passing_the_baton_faq.php&lt;/a&gt;) what is the future looking like for grsec/pax in Alpine?  I had a search but couldn&#039;t find anything definite - some mention of a fork maybe?  Is Alpine&#039;s grsec implementation already a fork?&lt;/p&gt;

&lt;p&gt;I&#039;d love to know more about this, any helpful link or info greatly appreciated.&lt;/p&gt;

&lt;p&gt;Thanks.&lt;/p&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
 <pubDate>Thu, 18 May 2017 04:46:24 +0000</pubDate>
 <dc:creator>dnx</dc:creator>
 <guid isPermaLink="false">19046 at https://forum.alpinelinux.org</guid>
 <comments>https://forum.alpinelinux.org/forum/pax-grsecurity/future-grsecurity-alpine#comments</comments>
</item>
<item>
 <title>Unprivileged LXC and grsecurity kernel</title>
 <link>https://forum.alpinelinux.org/forum/pax-grsecurity/unprivileged-lxc-and-grsecurity-kernel</link>
 <description>&lt;div class=&quot;field field-name-taxonomy-forums field-type-taxonomy-term-reference field-label-above&quot;&gt;&lt;div class=&quot;field-label&quot;&gt;Forums:&amp;nbsp;&lt;/div&gt;&lt;div class=&quot;field-items&quot;&gt;&lt;div class=&quot;field-item even&quot;&gt;&lt;a href=&quot;/forums/pax-grsecurity&quot;&gt;PaX &amp;amp; grsecurity&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;field field-name-body field-type-text-with-summary field-label-hidden&quot;&gt;&lt;div class=&quot;field-items&quot;&gt;&lt;div class=&quot;field-item even&quot;&gt;&lt;p&gt;Hello. Excuse me, please, but it seems that there is some kind of incompatibility between grsec kernel variants and the use of unprivileged LXC containers... Or maybe I do something wrong.&lt;br /&gt;&lt;!--break--&gt;&lt;br /&gt;
I try to create such container with command&lt;br /&gt;
&lt;div class=&quot;geshifilter&quot;&gt;&lt;pre class=&quot;text geshifilter-text&quot; style=&quot;font-family:monospace;&quot;&gt;# lxc-create -B btrfs -f /etc/lxc/default.conf -n alpine_1 -t download -- -d alpine -r 3.4 -a i386&lt;/pre&gt;&lt;/div&gt;&lt;br /&gt;
&lt;span class=&quot;geshifilter&quot;&gt;&lt;code class=&quot;text geshifilter-text&quot;&gt;/etc/lxc/default.conf&lt;/code&gt;&lt;/span&gt; I have created and changed to something like:&lt;br /&gt;
&lt;div class=&quot;geshifilter&quot;&gt;&lt;pre class=&quot;text geshifilter-text&quot; style=&quot;font-family:monospace;&quot;&gt;# Alpine fix from /etc/lxc/lxc.conf
lxc.cgroup.use = @kernel
...
# Mapping
lxc.id_map = u 0 100000 65536
lxc.id_map = g 0 100000 65536&lt;/pre&gt;&lt;/div&gt;&lt;br /&gt;
The root user has a subuid and subgid range.&lt;br /&gt;
But I receive an error:&lt;br /&gt;
&lt;div class=&quot;geshifilter&quot;&gt;&lt;pre class=&quot;text geshifilter-text&quot; style=&quot;font-family:monospace;&quot;&gt;newuidmap: Target process 2106 is owned by a different user: uid:0 pw_uid:0 st_uid:0, gid:0 pw_gid:0 st_gid:30
error mapping child
setgid: Invalid argument
lxc-create: lxccontainer.c: create_run_template: 1290 container creation template for ... failed
lxc-create: tools/lxc_create.c: main: 318 Error creating container&lt;/pre&gt;&lt;/div&gt;&lt;/p&gt;

&lt;p&gt;Maybe, this &lt;a href=&quot;https://github.com/lxc/lxc/issues/296#issuecomment-234708658&quot; class=&quot;bb-url&quot; rel=&quot;nofollow&quot;&gt;github issue&lt;/a&gt; is related to the problem...&lt;br /&gt;
It works with vanilla kernel on Alpine Linux, also it works on Arch Linux with grsec kernel from their repo (their version is built without &lt;span class=&quot;geshifilter&quot;&gt;&lt;code class=&quot;text geshifilter-text&quot;&gt;GRKERNSEC_SYSFS_RESTRICT&lt;/code&gt;&lt;/span&gt;)&lt;br /&gt;
I just hope - is there some workaround without kernel rebuild? Sorry.&lt;/p&gt;

&lt;p&gt;Alpine Linux v3.5, kernel: &lt;span class=&quot;geshifilter&quot;&gt;&lt;code class=&quot;text geshifilter-text&quot;&gt;4.4.52-0-virtgrsec&lt;/code&gt;&lt;/span&gt;&lt;br /&gt;
Thanks.&lt;/p&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
 <pubDate>Sat, 04 Mar 2017 08:57:36 +0000</pubDate>
 <dc:creator>fludardes</dc:creator>
 <guid isPermaLink="false">18961 at https://forum.alpinelinux.org</guid>
 <comments>https://forum.alpinelinux.org/forum/pax-grsecurity/unprivileged-lxc-and-grsecurity-kernel#comments</comments>
</item>
<item>
 <title>[SOLVED] i3status doesn&#039;t work because of sysfs restrictions</title>
 <link>https://forum.alpinelinux.org/forum/pax-grsecurity/solved-i3status-doesnt-work-because-sysfs-restrictions</link>
 <description>&lt;div class=&quot;field field-name-taxonomy-forums field-type-taxonomy-term-reference field-label-above&quot;&gt;&lt;div class=&quot;field-label&quot;&gt;Forums:&amp;nbsp;&lt;/div&gt;&lt;div class=&quot;field-items&quot;&gt;&lt;div class=&quot;field-item even&quot;&gt;&lt;a href=&quot;/forums/pax-grsecurity&quot;&gt;PaX &amp;amp; grsecurity&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;field field-name-body field-type-text-with-summary field-label-hidden&quot;&gt;&lt;div class=&quot;field-items&quot;&gt;&lt;div class=&quot;field-item even&quot;&gt;&lt;p&gt;Some modules in i3status config (battery, cpu_temperature) want to access files in /sys/. However, due to GRKERNSEC_SYSFS_RESTRICT they can&#039;t do that.&lt;br /&gt;
Is there a way to make i3status work without ditching linux-grsec for linux-vanilla, or setting SUID bit for i3status, or recompiling the kernel?&lt;/p&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
 <pubDate>Sat, 03 Sep 2016 06:18:14 +0000</pubDate>
 <dc:creator>imv</dc:creator>
 <guid isPermaLink="false">18826 at https://forum.alpinelinux.org</guid>
 <comments>https://forum.alpinelinux.org/forum/pax-grsecurity/solved-i3status-doesnt-work-because-sysfs-restrictions#comments</comments>
</item>
<item>
 <title>grsec administration on Alpine</title>
 <link>https://forum.alpinelinux.org/forum/pax-grsecurity/grsec-administration-alpine</link>
 <description>&lt;div class=&quot;field field-name-taxonomy-forums field-type-taxonomy-term-reference field-label-above&quot;&gt;&lt;div class=&quot;field-label&quot;&gt;Forums:&amp;nbsp;&lt;/div&gt;&lt;div class=&quot;field-items&quot;&gt;&lt;div class=&quot;field-item even&quot;&gt;&lt;a href=&quot;/forums/pax-grsecurity&quot;&gt;PaX &amp;amp; grsecurity&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;field field-name-body field-type-text-with-summary field-label-hidden&quot;&gt;&lt;div class=&quot;field-items&quot;&gt;&lt;div class=&quot;field-item even&quot;&gt;&lt;p&gt;While i&#039;ve managed to patch a debian system with grsec+pax and get it to work well i&#039;m lost with Alpine.&lt;/p&gt;

&lt;p&gt;dmesg shows frequent notifications such as &lt;/p&gt;

&lt;p&gt;grsec: denied resource overstep by requesting 4096 for RLIMIT_CORE against limit 0 /usr/.....&lt;/p&gt;

&lt;p&gt;I&#039;ve searched the wiki but could not find much, please provide a resource or other to continue.&lt;/p&gt;

&lt;p&gt;&lt;/p&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
 <pubDate>Sat, 30 Jan 2016 16:46:23 +0000</pubDate>
 <dc:creator>commandline.be</dc:creator>
 <guid isPermaLink="false">18683 at https://forum.alpinelinux.org</guid>
 <comments>https://forum.alpinelinux.org/forum/pax-grsecurity/grsec-administration-alpine#comments</comments>
</item>
<item>
 <title>Running strace</title>
 <link>https://forum.alpinelinux.org/forum/pax-grsecurity/running-strace</link>
 <description>&lt;div class=&quot;field field-name-taxonomy-forums field-type-taxonomy-term-reference field-label-above&quot;&gt;&lt;div class=&quot;field-label&quot;&gt;Forums:&amp;nbsp;&lt;/div&gt;&lt;div class=&quot;field-items&quot;&gt;&lt;div class=&quot;field-item even&quot;&gt;&lt;a href=&quot;/forums/pax-grsecurity&quot;&gt;PaX &amp;amp; grsecurity&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;field field-name-body field-type-text-with-summary field-label-hidden&quot;&gt;&lt;div class=&quot;field-items&quot;&gt;&lt;div class=&quot;field-item even&quot;&gt;&lt;p&gt;I&#039;ve been having a few problems with a tool I use Consul, receiving a bunch of signals which I don&#039;t think it should be. I tried to use strace to debug this and listen in on the signals it is actually receiving but I haven&#039;t been able to.&lt;/p&gt;

&lt;p&gt;I keep getting the following error from my strace command:&lt;/p&gt;

&lt;p&gt;&lt;div class=&quot;geshifilter&quot;&gt;&lt;pre class=&quot;text geshifilter-text&quot; style=&quot;font-family:monospace;&quot;&gt;strace: test_ptrace_setoptions_for_all: PTRACE_TRACEME doesn&#039;t work: Permission denied
strace: test_ptrace_setoptions_for_all: unexpected exit status 1&lt;/pre&gt;&lt;/div&gt;&lt;/p&gt;

&lt;p&gt;I tried to add the following into /etc/sysctl.d/01-alpine.conf, but it hasn&#039;t changed anything:&lt;/p&gt;

&lt;p&gt;&lt;div class=&quot;geshifilter&quot;&gt;&lt;pre class=&quot;text geshifilter-text&quot; style=&quot;font-family:monospace;&quot;&gt;kernel.grsecurity.harden_ptrace = 0
kernel.grsecurity.ptrace_readexec = 0&lt;/pre&gt;&lt;/div&gt;&lt;/p&gt;

&lt;p&gt;Is there anything else I can do to get strace running on Alpine Linux?&lt;/p&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
 <pubDate>Tue, 01 Dec 2015 03:26:35 +0000</pubDate>
 <dc:creator>smebberson</dc:creator>
 <guid isPermaLink="false">18647 at https://forum.alpinelinux.org</guid>
 <comments>https://forum.alpinelinux.org/forum/pax-grsecurity/running-strace#comments</comments>
</item>
<item>
 <title>grsec-Patches only for sponsors</title>
 <link>https://forum.alpinelinux.org/forum/pax-grsecurity/grsec-patches-only-sponsors</link>
 <description>&lt;div class=&quot;field field-name-taxonomy-forums field-type-taxonomy-term-reference field-label-above&quot;&gt;&lt;div class=&quot;field-label&quot;&gt;Forums:&amp;nbsp;&lt;/div&gt;&lt;div class=&quot;field-items&quot;&gt;&lt;div class=&quot;field-item even&quot;&gt;&lt;a href=&quot;/forums/pax-grsecurity&quot;&gt;PaX &amp;amp; grsecurity&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;field field-name-body field-type-text-with-summary field-label-hidden&quot;&gt;&lt;div class=&quot;field-items&quot;&gt;&lt;div class=&quot;field-item even&quot;&gt;&lt;p&gt;Hi,&lt;/p&gt;

&lt;p&gt;I was introduced to alpine last weekend by a friend. Now &lt;a href=&quot;https://grsecurity.net/announce.php&quot; class=&quot;bb-url&quot; rel=&quot;nofollow&quot;&gt;grsecurity announced&lt;/a&gt;, that patches will be available only to sponsors. &lt;br /&gt;
Will this in any way affect this project?&lt;/p&gt;

&lt;p&gt;Lemming&lt;/p&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
 <pubDate>Thu, 27 Aug 2015 07:44:54 +0000</pubDate>
 <dc:creator>Lemming</dc:creator>
 <guid isPermaLink="false">18588 at https://forum.alpinelinux.org</guid>
 <comments>https://forum.alpinelinux.org/forum/pax-grsecurity/grsec-patches-only-sponsors#comments</comments>
</item>
<item>
 <title>Hardened Kernel Goals</title>
 <link>https://forum.alpinelinux.org/forum/pax-grsecurity/hardened-kernel-goals</link>
 <description>&lt;div class=&quot;field field-name-taxonomy-forums field-type-taxonomy-term-reference field-label-above&quot;&gt;&lt;div class=&quot;field-label&quot;&gt;Forums:&amp;nbsp;&lt;/div&gt;&lt;div class=&quot;field-items&quot;&gt;&lt;div class=&quot;field-item even&quot;&gt;&lt;a href=&quot;/forums/pax-grsecurity&quot;&gt;PaX &amp;amp; grsecurity&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;field field-name-body field-type-text-with-summary field-label-hidden&quot;&gt;&lt;div class=&quot;field-items&quot;&gt;&lt;div class=&quot;field-item even&quot;&gt;&lt;p&gt;I have been doing some custom kernel compilation base on the default Alpine kernel. I added a decent amount of extra security mechanisms for the kernel such as chroot hardening and trusted path of execution (TPE). How locked down should the default kernel be for Alpine Linux? Should we have an extra version of Alpine the &quot;paranoid&quot; version? What are the core goals of Alpine and how do they affect the choices made for PaX &amp;amp; grsecurity?&lt;/p&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
 <pubDate>Sun, 02 Nov 2014 19:55:44 +0000</pubDate>
 <dc:creator>systmkor</dc:creator>
 <guid isPermaLink="false">18041 at https://forum.alpinelinux.org</guid>
 <comments>https://forum.alpinelinux.org/forum/pax-grsecurity/hardened-kernel-goals#comments</comments>
</item>
</channel>
</rss>
