grsec: denied resource overstep - RLIMIT_STACK

FreeBSD, Gentoo, openSUSE, CentOS, Ubuntu, Debian
as-n
Posts: 196
Joined: 2002-12-19 17:42

grsec: denied resource overstep - RLIMIT_STACK

Post by as-n » 2005-07-04 07:55

Hallo,

mein grsecurity Kernel bringt mir seit zwei Tagen immer wieder folgende Meldung:

Code: Select all

Jul 3 04:02:02 linux kernel: grsec: From 66.249.68.142: denied resource overstep by requesting 8392704 for RLIMIT_STACK against limit 8388608 for /usr/sbin/httpd2-prefork[httpd2-prefork:17976] uid/euid:30/30 gid/egid:8/8, parent /usr/sbin/httpd2-prefork[httpd2-prefork:14596] uid/euid:0/0 gid/egid:0/0
Jul 3 04:02:02 linux kernel: grsec: From 66.249.68.142: signal 11 sent to /usr/sbin/httpd2-prefork[httpd2-prefork:17976] uid/euid:30/30 gid/egid:8/8, parent /usr/sbin/httpd2-prefork[httpd2-prefork:14596] uid/euid:0/0 gid/egid:0/0
Jul 3 04:02:02 linux kernel: grsec: From 66.249.68.142: denied resource overstep by requesting 8392704 for RLIMIT_STACK against limit 8388608 for /usr/sbin/httpd2-prefork[httpd2-prefork:17976] uid/euid:30/30 gid/egid:8/8, parent /usr/sbin/httpd2-prefork[httpd2-prefork:14596] uid/euid:0/0 gid/egid:0/0......
66.249.68.142 ist der googlebot.

Seltsam ist nur, dass ich gar kein Limit gesetzt habe:

Code: Select all

linux:# ulimit -a
core file size        (blocks, -c) 0
data seg size         (kbytes, -d) unlimited
file size             (blocks, -f) unlimited
max locked memory     (kbytes, -l) unlimited
max memory size       (kbytes, -m) unlimited
open files                    (-n) 1024
pipe size          (512 bytes, -p) 8
stack size            (kbytes, -s) unlimited
cpu time             (seconds, -t) unlimited
max user processes            (-u) 4095
virtual memory        (kbytes, -v) unlimited

Wo könnte das limit denn noch herkommen?

Ciao
AS-N

as-n
Posts: 196
Joined: 2002-12-19 17:42

Re: grsec: denied resource overstep - RLIMIT_STACK

Post by as-n » 2005-07-05 08:24

Also irgend wie lief jetzt mein Kernel Amok, grsec hat plötzlich gar nichts mehr erlaubt.
Ich ahbe jetzt erstmal wieder einen Standardkernel drin, aber woran kann das denn liegen, der Kernel lief ja schon 2-3Wochen ohne Probleme.

Ciao
AS-N