echo foo
foo
/etc/init.d/apache2 start
/etc/init.d/apache2: line 23: 7392 Killed $APACHE2
${APACHE2_OPTS} -t > /dev/null 2>&1
* Apache2 has detected a syntax error in your configuration files:
/etc/init.d/apache2: line 23: 7394 Killed ${APACHE2}
${APACHE2_OPTS} -t
dmesg | tail
grsec: From ***.***.***.***: exec of /usr/bin/printenv (printenv PATH
) by /sbin/runscript.sh[runscript.sh:7391] uid/euid:0/0 gid/egid:0/0,
parent /sbin/runscript.sh[runscript.sh:7390] uid/euid:0/0 gid/egid:0/0
grsec: From ***.***.***.***: exec of /bin/env (env -i
PATH=/bin:/sbin:/usr/bin:/usr/sbin:/usr/local/sbin:/sbin:/bin:/usr/sbin:/usr/bin
/usr/sbin/apache2 -D PHP5 -D USERDIR -D ) by
/sbin/runscript.sh[runscript.sh:7392] uid/euid:0/0 gid/egid:0/0,
parent /sbin/runscript.sh[runscript.sh:7390] uid/euid:0/0 gid/egid:0/0
grsec: From ***.***.***.***: exec of /usr/sbin/apache2
(/usr/sbin/apache2 -D PHP5 -D USERDIR -D SSL -d /usr/lib/apache2 -f
/etc/apache2/httpd.conf -t ) by /bin/env[env:7392] uid/euid:0/0
gid/egid:0/0, parent /sbin/runscript.sh[runscript.sh:7390]
uid/euid:0/0 gid/egid:0/0
grsec: From ***.***.***.***: exec of /usr/bin/logger (/usr/bin/logger
-p daemon.err -t rc-scripts -- Apache2 has detected a syntax error in
your configuration files: ) by /sbin/runscript.sh[runscript.sh:7393]
uid/euid:0/0 gid/egid:0/0, parent
/sbin/runscript.sh[runscript.sh:7390] uid/euid:0/0 gid/egid:0/0
grsec: From ***.***.***.***: exec of /bin/env (env -i
PATH=/bin:/sbin:/usr/bin:/usr/sbin:/usr/local/sbin:/sbin:/bin:/usr/sbin:/usr/bin
/usr/sbin/apache2 -D PHP5 -D USERDIR -D ) by
/sbin/runscript.sh[runscript.sh:7394] uid/euid:0/0 gid/egid:0/0,
parent /sbin/runscript.sh[runscript.sh:7390] uid/euid:0/0 gid/egid:0/0
grsec: From ***.***.***.***: exec of /usr/sbin/apache2
(/usr/sbin/apache2 -D PHP5 -D USERDIR -D SSL -d /usr/lib/apache2 -f
/etc/apache2/httpd.conf -t ) by /bin/env[env:7394] uid/euid:0/0
gid/egid:0/0, parent /sbin/runscript.sh[runscript.sh:7390]
uid/euid:0/0 gid/egid:0/0
grsec: From ***.***.***.***: exec of /bin/rm (rm -Rf
/var/lib/init.d/daemons/apache2 /var/lib/init.d/starting/apache2
/var/lib/init.d/started/apache2 /var/lib/init.d/inactive) by
/sbin/runscript.sh[runscript.sh:7395] uid/euid:0/0 gid/egid:0/0,
parent /sbin/runscript.sh[runscript.sh:7349] uid/euid:0/0 gid/egid:0/0
grsec: From ***.***.***.***: exec of /bin/tail (tail ) by
/bin/bash[bash:7397] uid/euid:0/0 gid/egid:0/0, parent
/bin/bash[bash:6900] uid/euid:0/0 gid/egid:0/0
grsec: From ***.***.***.***: exec of /bin/dmesg (dmesg ) by
/bin/bash[bash:7396] uid/euid:0/0 gid/egid:0/0, parent
/bin/bash[bash:6900] uid/euid:0/0 gid/egid:0/0
echo foo
foo
paxctl -PemRXs
/etc/init.d/apache2 start
* Starting apache2 ...
[ ok ]
dmesg | tail
grsec: From ***.***.***.***: exec of /usr/bin/printenv (printenv PATH
) by /sbin/runscript.sh[runscript.sh:7475] uid/euid:0/0 gid/egid:0/0,
parent /sbin/runscript.sh[runscript.sh:7474] uid/euid:0/0 gid/egid:0/0
grsec: From ***.***.***.***: exec of /bin/env (env -i
PATH=/bin:/sbin:/usr/bin:/usr/sbin:/usr/local/sbin:/sbin:/bin:/usr/sbin:/usr/bin
/usr/sbin/apache2 -D PHP5 -D USERDIR -D ) by
/sbin/runscript.sh[runscript.sh:7476] uid/euid:0/0 gid/egid:0/0,
parent /sbin/runscript.sh[runscript.sh:7474] uid/euid:0/0 gid/egid:0/0
grsec: From ***.***.***.***: exec of /usr/sbin/apache2
(/usr/sbin/apache2 -D PHP5 -D USERDIR -D SSL -d /usr/lib/apache2 -f
/etc/apache2/httpd.conf -t ) by /bin/env[env:7476] uid/euid:0/0
gid/egid:0/0, parent /sbin/runscript.sh[runscript.sh:7474]
uid/euid:0/0 gid/egid:0/0
grsec: From ***.***.***.***: exec of /bin/env (env -i
PATH=/bin:/sbin:/usr/bin:/usr/sbin:/usr/local/sbin:/sbin:/bin:/usr/sbin:/usr/bin
/usr/sbin/apache2 -D PHP5 -D USERDIR -D ) by
/sbin/runscript.sh[runscript.sh:7477] uid/euid:0/0 gid/egid:0/0,
parent /sbin/runscript.sh[runscript.sh:7474] uid/euid:0/0 gid/egid:0/0
grsec: From ***.***.***.***: exec of /usr/sbin/apache2
(/usr/sbin/apache2 -D PHP5 -D USERDIR -D SSL -d /usr/lib/apache2 -f
/etc/apache2/httpd.conf -k start ) by /bin/env[env:7477] uid/euid:0/0
gid/egid:0/0, parent /sbin/runscript.sh[runscript.sh:7474]
uid/euid:0/0 gid/egid:0/0
grsec: From ***.***.***.***: exec of /bin/ln (ln -snf
/etc/init.d/apache2 /var/lib/init.d/started/apache2 ) by
/sbin/runscript.sh[runscript.sh:7479] uid/euid:0/0 gid/egid:0/0,
parent /sbin/runscript.sh[runscript.sh:7433] uid/euid:0/0 gid/egid:0/0
grsec: From ***.***.***.***: exec of /bin/rm (rm -f
/var/lib/init.d/starting/apache2 /var/lib/init.d/inactive/apache2
/var/lib/init.d/wasinactive/apache2 /var/lib/init.d/stop) by
/sbin/runscript.sh[runscript.sh:7481] uid/euid:0/0 gid/egid:0/0,
parent /sbin/runscript.sh[runscript.sh:7433] uid/euid:0/0 gid/egid:0/0
grsec: From ***.***.***.***: exec of /bin/tail (tail ) by
/bin/bash[bash:7539] uid/euid:0/0 gid/egid:0/0, parent
/bin/bash[bash:6900] uid/euid:0/0 gid/egid:0/0
grsec: From ***.***.***.***: exec of /bin/dmesg (dmesg ) by
/bin/bash[bash:7538] uid/euid:0/0 gid/egid:0/0, parent
/bin/bash[bash:6900] uid/euid:0/0 gid/egid:0/0
On 8/24/07, [EMAIL PROTECTED] <[EMAIL PROTECTED]> wrote:
> On 24 Aug 2007 at 1:32, Matt Poletiek wrote:
>
> > So did hardened-gentoo become more strict or did apache become more relaxed?
>
> i think neither, it's probably an issue with the vma mirroring
> code that i rewrote for 2.6.22 (to reduce its performance impact,
> now it's basically not measurable on kernel compilation, and even
> on fork/exec syscall microbenchmarks it's around 12% only).
>
> --
> [EMAIL PROTECTED] mailing list
>
>
--
Matthew Poletiek
www.chill-fu.net
--
[EMAIL PROTECTED] mailing list