Bug#863060: linux-image-4.9.0-2-grsec-amd64: grsec prevents sddm and KDE from starting

2017-05-21 Thread Yves-Alexis Perez
On Sun, 2017-05-21 at 09:44 +0700, Hieu Van wrote:
> Recently I installed grsec kernel for my PC which is running Debian 9 with
> KDE Plasma as the main desktop environment. It would have been good if sddm
> had started so I can login to KDE but grsec seems to be preventing sddm from
> starting up (some kind of "denied priority change" and "untrusted exec").
> Every time the boot process finishes, I'm greeted with a totally blank
> screen. Attempted to run "startx" and what I got is just the KDE mouse
> cursor and nothing else. Trying to run "sddm" would throw a "...resource
> overstep" error. I'm just a noob, please help me :(

Hi,

this is not a support channel and there's plenty of help here and there about
these, just google a bit with the error log.
> 
> Update : Just used "paxctl -m" to disable some sort of protection on
> /usr/bin/plasmashell as well as sddm and nothing came up to my expectation.

First, you can set kernel.grsecurity.chroot_execlog to 0 in
/etc/sysctl.d/grsec.conf so logs are a bit less noisy. Then paste the relevant
log lines here so I can take a look.

Regards,
-- 
Yves-Alexis

signature.asc
Description: This is a digitally signed message part


Bug#863060: linux-image-4.9.0-2-grsec-amd64: grsec prevents sddm and KDE from starting

2017-05-20 Thread Hieu Van
Package: src:linux-grsec
Version: 4.9.18-1+grsec201703261106+1
Severity: important

Dear Maintainer,

Recently I installed grsec kernel for my PC which is running Debian 9 with KDE 
Plasma as the main desktop environment. It would have been good if sddm had 
started so I can login to KDE but grsec seems to be preventing sddm from 
starting up (some kind of "denied priority change" and "untrusted exec"). Every 
time the boot process finishes, I'm greeted with a totally blank screen. 
Attempted to run "startx" and what I got is just the KDE mouse cursor and 
nothing else. Trying to run "sddm" would throw a "...resource overstep" error. 
I'm just a noob, please help me :(

Update : Just used "paxctl -m" to disable some sort of protection on 
/usr/bin/plasmashell as well as sddm and nothing came up to my expectation.

-- Package-specific info:
** Version:
Linux version 4.9.0-2-grsec-amd64 (cor...@debian.org) (gcc version 6.3.0 
20170321 (Debian 6.3.0-11) ) #1 SMP Debian 4.9.18-1+grsec201703261106+1 
(2017-03-30)

** Command line:
BOOT_IMAGE=/boot/vmlinuz-4.9.0-2-grsec-amd64 
root=UUID=4b1b36ee-7398-4827-8b82-eac1cc3b363e ro quiet

** Not tainted

** Kernel log:

** Model information
[  610.728031] grsec: exec of /bin/dash (/bin/sh -c apt-cache pkgnames ) by 
/bin/dash[reportbug:1354] uid/euid:0/0 gid/egid:0/0, parent 
/usr/bin/reportbug[reportbug:1350] uid/euid:0/0 gid/egid:0/0
[  610.729688] grsec: exec of /usr/bin/apt-cache (apt-cache pkgnames ) by 
/usr/bin/apt-cache[sh:1355] uid/euid:0/0 gid/egid:0/0, parent 
/bin/dash[sh:1354] uid/euid:0/0 gid/egid:0/0
[  610.735207] grsec: exec of /usr/bin/dpkg (/usr/bin/dpkg 
--print-foreign-architectures ) by /usr/bin/dpkg[apt-cache:1356] uid/euid:0/0 
gid/egid:0/0, parent /usr/bin/apt-cache[apt-cache:1355] uid/euid:0/0 
gid/egid:0/0
[  610.775686] grsec: exec of /usr/bin/dpkg (/usr/bin/dpkg 
--print-foreign-architectures ) by /usr/bin/dpkg[apt-cache:1357] uid/euid:0/0 
gid/egid:0/0, parent /usr/bin/apt-cache[apt-cache:1355] uid/euid:0/0 
gid/egid:0/0
[  622.479920] grsec: exec of /bin/dash (/bin/sh -c COLUMNS=79 dpkg --status 
linux-image-4.9.0-2-grsec-amd64 2>/dev/null ) by /bin/dash[reportbug:1358] 
uid/euid:0/0 gid/egid:0/0, parent /usr/bin/reportbug[reportbug:1350] 
uid/euid:0/0 gid/egid:0/0
[  622.481836] grsec: exec of /usr/bin/dpkg (dpkg --status 
linux-image-4.9.0-2-grsec-amd64 ) by /usr/bin/dpkg[sh:1359] uid/euid:0/0 
gid/egid:0/0, parent /bin/dash[sh:1358] uid/euid:0/0 gid/egid:0/0
[  622.483434] grsec: exec of /usr/bin/dpkg-query (dpkg-query --status -- 
linux-image-4.9.0-2-grsec-amd64 ) by /usr/bin/dpkg-query[dpkg:1359] 
uid/euid:0/0 gid/egid:0/0, parent /bin/dash[sh:1358] uid/euid:0/0 gid/egid:0/0
[  622.527054] grsec: exec of /bin/dash (/bin/sh -c /usr/bin/debsums 
--ignore-permissions -s linux-image-4.9.0-2-grsec-amd64 ) by 
/bin/dash[reportbug:1360] uid/euid:0/0 gid/egid:0/0, parent 
/usr/bin/reportbug[reportbug:1350] uid/euid:0/0 gid/egid:0/0
[  622.528799] grsec: exec of /usr/bin/debsums (/usr/bin/debsums 
--ignore-permissions -s linux-image-4.9.0-2-grsec-amd64 ) by 
/usr/bin/debsums[sh:1361] uid/euid:0/0 gid/egid:0/0, parent /bin/dash[sh:1360] 
uid/euid:0/0 gid/egid:0/0
[  622.619641] grsec: exec of /usr/bin/dpkg (/usr/bin/dpkg --print-architecture 
) by /usr/bin/dpkg[debsums:1362] uid/euid:0/0 gid/egid:0/0, parent 
/usr/bin/debsums[debsums:1361] uid/euid:0/0 gid/egid:0/0
[  622.622504] grsec: exec of /usr/bin/dpkg-query (dpkg-query 
--admindir=/var/lib/dpkg --showformat=${Package}  ${PackageSpec}  
${binary:Package}  ${Version}  ${Status}  ${Conffil) by 
/usr/bin/dpkg-query[debsums:1363] uid/euid:0/0 gid/egid:0/0, parent 
/usr/bin/debsums[debsums:1361] uid/euid:0/0 gid/egid:0/0
[  622.705971] grsec: exec of /bin/dash (sh -c LC_ALL=C dpkg-divert --list 
--admindir /var/lib/dpkg ) by /bin/dash[debsums:1364] uid/euid:0/0 
gid/egid:0/0, parent /usr/bin/debsums[debsums:1361] uid/euid:0/0 gid/egid:0/0
[  622.708344] grsec: exec of /usr/bin/dpkg-divert (dpkg-divert --list 
--admindir /var/lib/dpkg ) by /usr/bin/dpkg-divert[sh:1365] uid/euid:0/0 
gid/egid:0/0, parent /bin/dash[sh:1364] uid/euid:0/0 gid/egid:0/0
[  623.730034] grsec: exec of /bin/dash (/bin/sh -c COLUMNS=79 dpkg 
--print-architecture 2>/dev/null ) by /bin/dash[reportbug:1366] uid/euid:0/0 
gid/egid:0/0, parent /usr/bin/reportbug[reportbug:1350] uid/euid:0/0 
gid/egid:0/0
[  623.731755] grsec: exec of /usr/bin/dpkg (dpkg --print-architecture ) by 
/usr/bin/dpkg[sh:1367] uid/euid:0/0 gid/egid:0/0, parent /bin/dash[sh:1366] 
uid/euid:0/0 gid/egid:0/0
[  623.738400] grsec: exec of /bin/dash (/bin/sh -c COLUMNS=79 dpkg 
--print-architecture 2>/dev/null ) by /bin/dash[reportbug:1368] uid/euid:0/0 
gid/egid:0/0, parent /usr/bin/reportbug[reportbug:1350] uid/euid:0/0 
gid/egid:0/0
[  623.740267] grsec: exec of /usr/bin/dpkg (dpkg --print-architecture ) by 
/usr/bin/dpkg[sh:1369] uid/euid:0/0 gid/egid:0/0, parent /bin/dash[sh:1368] 
uid/euid:0/0 gid/egid:0/0
[  626.126653] grsec: exec of /bin/dash