Community Packages

Please read this before reporting a bug:
https://wiki.archlinux.org/title/Bug_reporting_guidelines

Do NOT report bugs when a package is just outdated, or it is in the AUR. Use the 'flag out of date' link on the package page, or the Mailing List.

REPEAT: Do NOT report bugs for outdated packages!
Tasklist

FS#51646 - [paxd] grsec: denied RWX mmap by /usr/bin/gnome-terminal

Attached to Project: Community Packages
Opened by Faris (f4r1s) - Wednesday, 02 November 2016, 15:22 GMT
Last edited by Jonathan Roemer (pid1) - Wednesday, 02 November 2016, 16:37 GMT
Task Type Bug Report
Category Packages
Status Closed
Assigned To No-one
Architecture All
Severity Low
Priority Normal
Reported Version
Due in Version Undecided
Due Date Undecided
Percent Complete 100%
Votes 0
Private No

Details

Description:

The /etc/paxd.conf file no entry for the gnome-terminal. Upon launching the application the RWX mmap error gets logged to the journal.

The line /usr/bin/gnome-terminal needs to be added in the cinnamon/gnome/gtk section of the config file.
To get the application to function correctly I also had to disable the RANDMMAP feature.

/etc/paxd.conf
...
# cinnamon/gnome/gtk (mostly caused by gjs and webkitgtk)
+ emr /usr/bin/gnome-terminal
...

Additional info:
Kernel: Linux <HOST> 4.7.10.201610262029-1-grsec #1 SMP PREEMPT Thu Oct 27 19:37:55 EDT 2016 x86_64 GNU/Linux
paxd package version: local/paxd 32-1
gnome-terminal version: local/gnome-terminal 3.22.0+4+g87e36d3-1 (gnome)

Steps to reproduce:
1. Clean installation Arch Linux with GNOME desktop environment
2. Enable grsec and paxd on the system.
3. Launch the gnome-terminal application.
This task depends upon

Closed by  Jonathan Roemer (pid1)
Wednesday, 02 November 2016, 16:37 GMT
Reason for closing:  None

Loading...