Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

mencoder: page allocation failure: order:1, mode:0x2080024(GFP_ATOMIC|GFP_DMA32) #21

Open
miroR opened this issue Dec 3, 2017 · 6 comments

Comments

@miroR
Copy link

miroR commented Dec 3, 2017

This is complete, with what I was doing, except, the mencoder was recording on composite input to Hauppauge HVR3000, was started earlier:

Dec  3 17:30:04 gdOv kernel: [79226.214967] grsec: (mr:U:/) exec of /usr/local/bin/tzap-cat-g0.sh (tzap-cat-g0.sh RTL RTL ) by /usr/local/bin/tzap-cat-g0.sh[bash:5070] uid/euid:1000/1000 gid/egid:1000/1000, parent /bin/bash[bash:3480] uid/euid:1000/1000 gid/egid:1000/1000
Dec  3 17:30:04 gdOv kernel: [79226.235449] grsec: (mr:U:/bin/ps) exec of /bin/ps (ps aux ) by /bin/ps[tzap-cat-g0.sh:5071] uid/euid:1000/1000 gid/egid:1000/1000, parent /usr/local/bin/tzap-cat-g0.sh[tzap-cat-g0.sh:5070] uid/euid:1000/1000 gid/egid:1000/1000
Dec  3 17:30:04 gdOv kernel: [79226.236698] grsec: (mr:U:/) exec of /bin/grep (grep [t]zap ) by /bin/grep[tzap-cat-g0.sh:5073] uid/euid:1000/1000 gid/egid:1000/1000, parent /usr/local/bin/tzap-cat-g0.sh[tzap-cat-g0.sh:5070] uid/euid:1000/1000 gid/egid:1000/1000
Dec  3 17:30:04 gdOv kernel: [79226.237716] grsec: (mr:U:/) exec of /bin/grep (grep -v tzap-cat ) by /bin/grep[tzap-cat-g0.sh:5072] uid/euid:1000/1000 gid/egid:1000/1000, parent /usr/local/bin/tzap-cat-g0.sh[tzap-cat-g0.sh:5070] uid/euid:1000/1000 gid/egid:1000/1000
Dec  3 17:30:04 gdOv kernel: [79226.237819] grsec: (mr:U:/) exec of /usr/bin/gawk (awk { print $2 } ) by /usr/bin/gawk[tzap-cat-g0.sh:5074] uid/euid:1000/1000 gid/egid:1000/1000, parent /usr/local/bin/tzap-cat-g0.sh[tzap-cat-g0.sh:5070] uid/euid:1000/1000 gid/egid:1000/1000
Dec  3 17:30:04 gdOv kernel: [79226.265146] grsec: (mr:U:/bin/cat) exec of /bin/cat (cat tzap.pid ) by /bin/cat[tzap-cat-g0.sh:5075] uid/euid:1000/1000 gid/egid:1000/1000, parent /usr/local/bin/tzap-cat-g0.sh[tzap-cat-g0.sh:5070] uid/euid:1000/1000 gid/egid:1000/1000
Dec  3 17:30:04 gdOv kernel: [79226.267594] grsec: (mr:U:/) exec of /bin/grep (grep -v tzap-cat ) by /bin/grep[tzap-cat-g0.sh:5077] uid/euid:1000/1000 gid/egid:1000/1000, parent /usr/local/bin/tzap-cat-g0.sh[tzap-cat-g0.sh:5070] uid/euid:1000/1000 gid/egid:1000/1000
Dec  3 17:30:04 gdOv kernel: [79226.267977] grsec: (mr:U:/bin/ps) exec of /bin/ps (ps aux ) by /bin/ps[tzap-cat-g0.sh:5076] uid/euid:1000/1000 gid/egid:1000/1000, parent /usr/local/bin/tzap-cat-g0.sh[tzap-cat-g0.sh:5070] uid/euid:1000/1000 gid/egid:1000/1000
Dec  3 17:30:04 gdOv kernel: [79226.269376] grsec: (mr:U:/) exec of /bin/grep (grep [c]at ) by /bin/grep[tzap-cat-g0.sh:5078] uid/euid:1000/1000 gid/egid:1000/1000, parent /usr/local/bin/tzap-cat-g0.sh[tzap-cat-g0.sh:5070] uid/euid:1000/1000 gid/egid:1000/1000
Dec  3 17:30:04 gdOv kernel: [79226.269950] grsec: (mr:U:/) exec of /usr/bin/gawk (awk { print $2 } ) by /usr/bin/gawk[tzap-cat-g0.sh:5079] uid/euid:1000/1000 gid/egid:1000/1000, parent /usr/local/bin/tzap-cat-g0.sh[tzap-cat-g0.sh:5070] uid/euid:1000/1000 gid/egid:1000/1000
Dec  3 17:30:04 gdOv kernel: [79226.280567] grsec: (mr:U:/bin/cat) exec of /bin/cat (cat cat.pid ) by /bin/cat[tzap-cat-g0.sh:5080] uid/euid:1000/1000 gid/egid:1000/1000, parent /usr/local/bin/tzap-cat-g0.sh[tzap-cat-g0.sh:5070] uid/euid:1000/1000 gid/egid:1000/1000
Dec  3 17:30:04 gdOv kernel: [79226.284784] grsec: (mr:U:/bin/cat) exec of /bin/cat (cat tzap.pid ) by /bin/cat[tzap-cat-g0.sh:5081] uid/euid:1000/1000 gid/egid:1000/1000, parent /usr/local/bin/tzap-cat-g0.sh[tzap-cat-g0.sh:5070] uid/euid:1000/1000 gid/egid:1000/1000
Dec  3 17:30:04 gdOv kernel: [79226.289393] grsec: (mr:U:/bin/cat) exec of /bin/cat (cat tzap.pid ) by /bin/cat[tzap-cat-g0.sh:5082] uid/euid:1000/1000 gid/egid:1000/1000, parent /usr/local/bin/tzap-cat-g0.sh[tzap-cat-g0.sh:5070] uid/euid:1000/1000 gid/egid:1000/1000
Dec  3 17:30:04 gdOv kernel: [79226.291586] grsec: (mr:U:/bin/cat) exec of /bin/cat (cat cat.pid ) by /bin/cat[tzap-cat-g0.sh:5083] uid/euid:1000/1000 gid/egid:1000/1000, parent /usr/local/bin/tzap-cat-g0.sh[tzap-cat-g0.sh:5070] uid/euid:1000/1000 gid/egid:1000/1000
Dec  3 17:30:04 gdOv kernel: [79226.293118] grsec: (mr:U:/bin/cat) exec of /bin/cat (cat cat.pid ) by /bin/cat[tzap-cat-g0.sh:5084] uid/euid:1000/1000 gid/egid:1000/1000, parent /usr/local/bin/tzap-cat-g0.sh[tzap-cat-g0.sh:5070] uid/euid:1000/1000 gid/egid:1000/1000
Dec  3 17:30:04 gdOv kernel: [79226.295453] grsec: (mr:U:/) exec of /usr/bin/tzap (tzap -a0 -f1 -d1 -r RTL ) by /usr/bin/tzap[tzap-cat-g0.sh:5085] uid/euid:1000/1000 gid/egid:1000/1000, parent /usr/local/bin/tzap-cat-g0.sh[tzap-cat-g0.sh:5070] uid/euid:1000/1000 gid/egid:1000/1000
Dec  3 17:30:04 gdOv kernel: [79226.298815] grsec: (mr:U:/) exec of /bin/date (date +H%m%d_%H%M ) by /bin/date[tzap-cat-g0.sh:5086] uid/euid:1000/1000 gid/egid:1000/1000, parent /usr/local/bin/tzap-cat-g0.sh[tzap-cat-g0.sh:5070] uid/euid:1000/1000 gid/egid:1000/1000
Dec  3 17:30:04 gdOv kernel: [79226.301244] grsec: (mr:U:/) exec of /bin/sleep (sleep 3 ) by /bin/sleep[tzap-cat-g0.sh:5088] uid/euid:1000/1000 gid/egid:1000/1000, parent /usr/local/bin/tzap-cat-g0.sh[tzap-cat-g0.sh:5087] uid/euid:1000/1000 gid/egid:1000/1000
Dec  3 17:30:07 gdOv kernel: [79229.304638] grsec: (mr:U:/bin/cat) exec of /bin/cat (cat /dev/dvb/adapter0/dvr1 ) by /bin/cat[tzap-cat-g0.sh:5091] uid/euid:1000/1000 gid/egid:1000/1000, parent /usr/local/bin/tzap-cat-g0.sh[tzap-cat-g0.sh:5087] uid/euid:1000/1000 gid/egid:1000/1000
Dec  3 17:30:24 gdOv kernel: [79245.889599] mencoder: page allocation failure: order:1, mode:0x2080024(GFP_ATOMIC|GFP_DMA32)
Dec  3 17:30:24 gdOv kernel: [79245.889627] CPU: 1 PID: 4991 Comm: mencoder Not tainted 4.9.65-unofficial+grsec171124-23 #1
Dec  3 17:30:24 gdOv kernel: [79245.889639] Hardware name: To Be Filled By O.E.M. To Be Filled By O.E.M./970 Extreme4, BIOS P2.60 11/11/2013
Dec  3 17:30:24 gdOv kernel: [79245.889649]  ffffc9000a3e77f8 ffffffff818211eb 0000000000000020 ce922b3502529753
Dec  3 17:30:24 gdOv kernel: [79245.889665]  ffffffff829de6c0 0000000000000000 ffffc9000a3e7880 ffffffff81244c3d
Dec  3 17:30:24 gdOv kernel: [79245.889679]  0208002400000000 ffffffff829de6c0 ffffc9000a3e7820 ffffffff00000010
Dec  3 17:30:24 gdOv kernel: [79245.889693] Call Trace:
Dec  3 17:30:24 gdOv kernel: [79245.889716]  [<ffffffff818211eb>] dump_stack+0x94/0xf9
Dec  3 17:30:24 gdOv kernel: [79245.889729]  [<ffffffff81244c3d>] warn_alloc+0x1ad/0x1f0
Dec  3 17:30:24 gdOv kernel: [79245.889740]  [<ffffffff81244ff2>] ? __alloc_pages_slowpath+0x2c2/0xff0
Dec  3 17:30:24 gdOv kernel: [79245.889749]  [<ffffffff8124506c>] __alloc_pages_slowpath+0x33c/0xff0
Dec  3 17:30:24 gdOv kernel: [79245.889760]  [<ffffffff81246142>] __alloc_pages_nodemask+0x1c2/0x2c0
Dec  3 17:30:24 gdOv kernel: [79245.889770]  [<ffffffff81096344>] dma_generic_alloc_coherent+0xb4/0x1a0
Dec  3 17:30:24 gdOv kernel: [79245.889780]  [<ffffffff810cf65d>] gart_alloc_coherent+0x6d/0x1a0
Dec  3 17:30:24 gdOv kernel: [79245.889791]  [<ffffffff8205dba5>] cx88_risc_buffer+0x125/0x260
Dec  3 17:30:24 gdOv kernel: [79245.889801]  [<ffffffff82064ebf>] buffer_prepare+0x1ef/0x330
Dec  3 17:30:24 gdOv kernel: [79245.889813]  [<ffffffff82028fef>] __buf_prepare+0x18f/0x230
Dec  3 17:30:24 gdOv kernel: [79245.889822]  [<ffffffff8202afbd>] vb2_core_qbuf+0x1bd/0x300
Dec  3 17:30:24 gdOv kernel: [79245.889833]  [<ffffffff8202f3be>] vb2_qbuf+0x9e/0xe0
Dec  3 17:30:24 gdOv kernel: [79245.889843]  [<ffffffff8202fdfd>] vb2_ioctl_qbuf+0x7d/0xa0
Dec  3 17:30:24 gdOv kernel: [79245.889854]  [<ffffffff820102c0>] v4l_qbuf+0xb0/0xd0
Dec  3 17:30:24 gdOv kernel: [79245.889864]  [<ffffffff82012877>] __video_do_ioctl+0x2c7/0x480
Dec  3 17:30:24 gdOv kernel: [79245.889875]  [<ffffffff82012e0d>] video_usercopy+0x3dd/0x850
Dec  3 17:30:24 gdOv kernel: [79245.889886]  [<ffffffff820125b0>] ? v4l_printk_ioctl+0x100/0x100
Dec  3 17:30:24 gdOv kernel: [79245.889895]  [<ffffffff820132c9>] video_ioctl2+0x49/0x80
Dec  3 17:30:24 gdOv kernel: [79245.889904]  [<ffffffff82006cb9>] v4l2_ioctl+0x149/0x1b0
Dec  3 17:30:24 gdOv kernel: [79245.889915]  [<ffffffff813120d2>] do_vfs_ioctl+0xf2/0xb40
Dec  3 17:30:24 gdOv kernel: [79245.889925]  [<ffffffff81312c76>] rap_sys_ioctl+0x76/0xe0
Dec  3 17:30:24 gdOv kernel: [79245.889936]  [<ffffffff825ad653>] entry_SYSCALL_64_fastpath+0x1e/0xec
Dec  3 17:30:24 gdOv kernel: [79245.889944] Mem-Info:
Dec  3 17:30:24 gdOv kernel: [79245.889962] active_anon:107057 inactive_anon:133576 isolated_anon:0
Dec  3 17:30:24 gdOv kernel: [79245.889962]  active_file:1190633 inactive_file:444549 isolated_file:0
Dec  3 17:30:24 gdOv kernel: [79245.889962]  unevictable:1 dirty:3649 writeback:0 unstable:0
Dec  3 17:30:24 gdOv kernel: [79245.889962]  slab_reclaimable:111180 slab_unreclaimable:8852
Dec  3 17:30:24 gdOv kernel: [79245.889962]  mapped:16800 shmem:2751 pagetables:3735 bounce:0
Dec  3 17:30:24 gdOv kernel: [79245.889962]  free:13082 free_pcp:982 free_cma:0
Dec  3 17:30:24 gdOv kernel: [79245.889991] Node 0 active_anon:428228kB inactive_anon:534304kB active_file:4762532kB inactive_file:1778196kB unevictable:4kB isolated(anon):0kB isolated(file):0kB mapped:67200kB dirty:14596kB writeback:0kB shmem:11004kB writeback_tmp:0kB unstable:0kB pages_scanned:42 all_unreclaimable? no
Dec  3 17:30:24 gdOv kernel: [79245.890000] Node 0 DMA free:12476kB min:20kB low:32kB high:44kB active_anon:0kB inactive_anon:0kB active_file:0kB inactive_file:0kB unevictable:0kB writepending:0kB present:15992kB managed:15908kB mlocked:0kB slab_reclaimable:0kB slab_unreclaimable:0kB kernel_stack:0kB pagetables:0kB bounce:0kB free_pcp:0kB local_pcp:0kB free_cma:0kB
Dec  3 17:30:24 gdOv kernel: [79245.890015] lowmem_reserve[]: 0 3116 7851 7851
Dec  3 17:30:24 gdOv kernel: [79245.890027] Node 0 DMA32 free:28876kB min:4496kB low:7684kB high:10872kB active_anon:133692kB inactive_anon:17936kB active_file:2132392kB inactive_file:699484kB unevictable:4kB writepending:14556kB present:3364976kB managed:3263712kB mlocked:4kB slab_reclaimable:233116kB slab_unreclaimable:7008kB kernel_stack:208kB pagetables:2456kB bounce:0kB free_pcp:2424kB local_pcp:684kB free_cma:0kB
Dec  3 17:30:24 gdOv kernel: [79245.890043] lowmem_reserve[]: 0 0 4735 4735
Dec  3 17:30:24 gdOv kernel: [79245.890054] Node 0 Normal free:10976kB min:6832kB low:11680kB high:16528kB active_anon:294536kB inactive_anon:516368kB active_file:2630140kB inactive_file:1078712kB unevictable:0kB writepending:40kB present:4980732kB managed:4849116kB mlocked:0kB slab_reclaimable:211604kB slab_unreclaimable:28400kB kernel_stack:4256kB pagetables:12484kB bounce:0kB free_pcp:1504kB local_pcp:212kB free_cma:0kB
Dec  3 17:30:24 gdOv kernel: [79245.890068] lowmem_reserve[]: 0 0 0 0
Dec  3 17:30:24 gdOv kernel: [79245.890079] Node 0 DMA: 1*4kB (U) 0*8kB 0*16kB 0*32kB 1*64kB (H) 1*128kB (H) 0*256kB 0*512kB 0*1024kB 2*2048kB (UM) 2*4096kB (M) = 12484kB
Dec  3 17:30:24 gdOv kernel: [79245.890205] Node 0 DMA32: 7211*4kB (UME) 4*8kB (E) 0*16kB 0*32kB 0*64kB 0*128kB 0*256kB 0*512kB 0*1024kB 0*2048kB 0*4096kB = 28876kB
Dec  3 17:30:24 gdOv kernel: [79245.890240] Node 0 Normal: 2612*4kB (UEH) 40*8kB (H) 9*16kB (H) 2*32kB (H) 0*64kB 0*128kB 0*256kB 0*512kB 0*1024kB 0*2048kB 0*4096kB = 10976kB
Dec  3 17:30:24 gdOv kernel: [79245.890283] Node 0 hugepages_total=0 hugepages_free=0 hugepages_surp=0 hugepages_size=2048kB
Dec  3 17:30:24 gdOv kernel: [79245.890286] 1637951 total pagecache pages
Dec  3 17:30:24 gdOv kernel: [79245.890293] 1 pages in swap cache
Dec  3 17:30:24 gdOv kernel: [79245.890299] Swap cache stats: add 489, delete 488, find 0/0
Dec  3 17:30:24 gdOv kernel: [79245.890304] Free swap  = 8995992kB
Dec  3 17:30:24 gdOv kernel: [79245.890309] Total swap = 8997948kB
Dec  3 17:30:24 gdOv kernel: [79245.890314] 2090425 pages RAM
Dec  3 17:30:24 gdOv kernel: [79245.890319] 0 pages HighMem/MovableOnly
Dec  3 17:30:24 gdOv kernel: [79245.890330] 58241 pages reserved
Dec  3 17:30:24 gdOv kernel: [79245.890346] PAX: please report this to [email protected]
Dec  3 17:30:24 gdOv kernel: [79245.890357] BUG: unable to handle kernel NULL pointer dereference at 0000000000000004
Dec  3 17:30:24 gdOv kernel: [79245.896818] IP: [<ffffffff82064ba3>] buffer_queue+0x43/0x170
Dec  3 17:30:24 gdOv kernel: [79245.903396] PGD 1ee3ba000 
Dec  3 17:30:24 gdOv kernel: [79245.903449] 
Dec  3 17:30:24 gdOv kernel: [79245.909987] Oops: 0002 [#1] SMP
Dec  3 17:30:24 gdOv kernel: [79245.916571] CPU: 1 PID: 4991 Comm: mencoder Not tainted 4.9.65-unofficial+grsec171124-23 #1
Dec  3 17:30:24 gdOv kernel: [79245.923372] Hardware name: To Be Filled By O.E.M. To Be Filled By O.E.M./970 Extreme4, BIOS P2.60 11/11/2013
Dec  3 17:30:24 gdOv kernel: [79245.930246] task: ffff880086ace400 task.stack: ffffc9000a3e4000
Dec  3 17:30:24 gdOv kernel: [79245.932687] grsec: (root:U:/usr/sbin/rsyslogd) denied access to hidden file /run/utmp by /usr/sbin/rsyslogd[rs:main Q:Reg:2031] uid/euid:0/0 gid/egid:0/0, parent /sbin/init[init:1] uid/euid:0/0 gid/egid:0/0
Dec  3 17:30:24 gdOv kernel: [79245.932766] grsec: (root:U:/usr/sbin/rsyslogd) denied access to hidden file /run/utmp by /usr/sbin/rsyslogd[rs:main Q:Reg:2031] uid/euid:0/0 gid/egid:0/0, parent /sbin/init[init:1] uid/euid:0/0 gid/egid:0/0
Dec  3 17:30:24 gdOv kernel: [79245.965938] RIP: 0010:[<ffffffff82064ba3>]  [<ffffffff82064ba3>] buffer_queue+0x43/0x170
Dec  3 17:30:24 gdOv kernel: [79245.973433] RSP: 0018:ffffc9000a3e7b60  EFLAGS: 00010286
Dec  3 17:30:24 gdOv kernel: [79245.980876] RAX: ffff880224764000 RBX: ffff880162a4f000 RCX: 0000000000000000
Dec  3 17:30:24 gdOv kernel: [79245.988373] RDX: 0000000000000008 RSI: 0000000000000000 RDI: ffff880162a4f000
Dec  3 17:30:24 gdOv kernel: [79245.995859] RBP: ffffc9000a3e7b78 R08: 0000000000000005 R09: 0000000000000000
Dec  3 17:30:24 gdOv kernel: [79246.003396] R10: ffff88022fff9dd0 R11: 0000000000011612 R12: ffff880224721000
Dec  3 17:30:24 gdOv kernel: [79246.010948] R13: 8000000000000000 R14: ffff880162a4f000 R15: ffff880224764010
Dec  3 17:30:24 gdOv kernel: [79246.018333] FS:  00000356ac402700(0000) GS:ffff88022fc80000(0000) knlGS:0000000000000000
Dec  3 17:30:24 gdOv kernel: [79246.025582] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
Dec  3 17:30:24 gdOv kernel: [79246.032662] CR2: 0000000000000004 CR3: 0000000002c22000 CR4: 00000000000006f0
Dec  3 17:30:24 gdOv kernel: [79246.039603] Stack:
Dec  3 17:30:24 gdOv kernel: [79246.046321]  0000000000000001 ffff880162a4f048 8000000000000000 ffffc9000a3e7ba8
Dec  3 17:30:24 gdOv kernel: [79246.053023]  ffffffff820279d2 ffff880224764b80 ffff880162a4f000 ffffc9000a3e7d38
Dec  3 17:30:24 gdOv kernel: [79246.059542]  ffffffff82853e00 ffffc9000a3e7bd0 ffffffff8202b034 ffff880224764b80
Dec  3 17:30:24 gdOv kernel: [79246.065893] Call Trace:
Dec  3 17:30:24 gdOv kernel: [79246.072023]  [<ffffffff820279d2>] __enqueue_in_driver+0xd2/0x110
Dec  3 17:30:24 gdOv kernel: [79246.078051]  [<ffffffff8202b034>] vb2_core_qbuf+0x234/0x300
Dec  3 17:30:24 gdOv kernel: [79246.084022]  [<ffffffff8202f3be>] vb2_qbuf+0x9e/0xe0
Dec  3 17:30:24 gdOv kernel: [79246.089812]  [<ffffffff8202fdfd>] vb2_ioctl_qbuf+0x7d/0xa0
Dec  3 17:30:24 gdOv kernel: [79246.095394]  [<ffffffff820102c0>] v4l_qbuf+0xb0/0xd0
Dec  3 17:30:24 gdOv kernel: [79246.100927]  [<ffffffff82012877>] __video_do_ioctl+0x2c7/0x480
Dec  3 17:30:24 gdOv kernel: [79246.106534]  [<ffffffff82012e0d>] video_usercopy+0x3dd/0x850
Dec  3 17:30:24 gdOv kernel: [79246.112126]  [<ffffffff820125b0>] ? v4l_printk_ioctl+0x100/0x100
Dec  3 17:30:24 gdOv kernel: [79246.117729]  [<ffffffff820132c9>] video_ioctl2+0x49/0x80
Dec  3 17:30:24 gdOv kernel: [79246.123325]  [<ffffffff82006cb9>] v4l2_ioctl+0x149/0x1b0
Dec  3 17:30:24 gdOv kernel: [79246.128780]  [<ffffffff813120d2>] do_vfs_ioctl+0xf2/0xb40
Dec  3 17:30:24 gdOv kernel: [79246.134120]  [<ffffffff81312c76>] rap_sys_ioctl+0x76/0xe0
Dec  3 17:30:24 gdOv kernel: [79246.139345]  [<ffffffff825ad653>] entry_SYSCALL_64_fastpath+0x1e/0xec
Dec  3 17:30:24 gdOv kernel: [79246.144561] Code: 10 07 6e 9d db ff ff ff ff cc cc cc cc cc cc cc cc 48 8b 03 8b b3 18 02 00 00 48 8b 8b 08 02 00 00 48 8b 40 48 8d 56 08 4c 8b 20 <89> 51 04 48 8b 93 10 02 00 00 c7 02 00 00 01 70 8b b3 18 02 00 
Dec  3 17:30:24 gdOv kernel: [79246.155952] RIP  [<ffffffff82064ba3>] buffer_queue+0x43/0x170
Dec  3 17:30:24 gdOv kernel: [79246.161437]  RSP <ffffc9000a3e7b60>
Dec  3 17:30:24 gdOv kernel: [79246.166856] CR2: 0000000000000004
Dec  3 17:30:24 gdOv kernel: [79246.196544] ---[ end trace fbbe04dc53961045 ]---
Dec  3 17:30:24 gdOv kernel: [79246.196553] grsec: banning user with uid 1000 until system restart for suspicious kernel crash
Dec  3 17:30:24 gdOv kernel: [79246.333477] grsec: (root:U:/bin/bash) special role admin (id 8) exited by /bin/bash[bash:3670] uid/euid:0/0 gid/egid:0/0, parent /usr/bin/sudo[sudo:3669] uid/euid:0/0 gid/egid:0/0
Dec  3 17:30:24 gdOv kernel: [79246.493856] grsec: (root:U:/sbin/init) denied access to hidden file /sbin/getty by /sbin/init[init:5093] uid/euid:0/0 gid/egid:0/0, parent /sbin/init[init:1] uid/euid:0/0 gid/egid:0/0
Dec  3 17:30:24 gdOv kernel: [79246.523903] grsec: (root:U:/sbin/agetty) exec of /sbin/agetty (/sbin/getty 38400 tty6 ) by /sbin/agetty[init:5094] uid/euid:0/0 gid/egid:0/0, parent /sbin/init[init:1] uid/euid:0/0 gid/egid:0/0

@miroR
Copy link
Author

miroR commented Dec 3, 2017

I trying to call attention to this issue to mencoder devs:
Mencoder involved in system crashes? WAS: DVD rip (to avi) using mencoder

@theLOICofFRANCE
Copy link

If you are sure you know the cause, disable "GRKERNSEC_KERN_LOCKOUT" to see what happens next.

@miroR
Copy link
Author

miroR commented Dec 14, 2017

First, a note: in the meantime, after my last post, I have had no more crashes. The following is the first one after this (unusually for these weeks here) long quiet time.

Dec 14 18:15:06 gdOv kernel: [88965.348822] grsec: (root:U:/bin/chown) exec of /bin/chown (chown tcpdump:tcpdump dump_171214_1815_gdO.pcap ) by /bin/chown[bash:27915] uid/euid:0/0 gid/egid:0/0, parent /usr/bin/sudo[sudo:27914] uid/euid:0/0 gid/egid:0/0
Dec 14 18:15:06 gdOv kernel: [88965.351630] grsec: (mr:U:/) exec of /bin/sleep (sleep 1.5 ) by /bin/sleep[uncenz-1st:27917] uid/euid:1000/1000 gid/egid:1000/1000, parent /usr/local/bin/uncenz-1st[uncenz-1st:27743] uid/euid:1000/1000 gid/egid:1000/1000
Dec 14 18:15:06 gdOv kernel: [88965.352224] grsec: (mr:U:/usr/bin/sudo) exec of /usr/bin/sudo (sudo -s tcpdump -i any -Z tcpdump -U -v -w dump_171214_1815_gdO.pcap ) by /usr/bin/sudo[uncenz-1st:27916] uid/euid:1000/1000 gid/egid:1000/1000, parent /usr/local/bin/uncenz-1st[uncenz-1st:27743] uid/euid:1000/1000 gid/egid:1000/1000
Dec 14 18:15:06 gdOv kernel: [88965.361604] grsec: (root:U:/bin/bash) exec of /bin/bash (/bin/bash -c tcpdump -i any -Z tcpdump -U -v -w dump_171214_1815_gdO\.pcap ) by /bin/bash[sudo:27918] uid/euid:0/0 gid/egid:0/0, parent /usr/bin/sudo[sudo:27916] uid/euid:0/0 gid/egid:0/0
Dec 14 18:15:06 gdOv kernel: [88965.363726] grsec: (root:U:/usr/sbin/tcpdump) exec of /usr/sbin/tcpdump (tcpdump -i any -Z tcpdump -U -v -w dump_171214_1815_gdO.pcap ) by /usr/sbin/tcpdump[bash:27918] uid/euid:0/0 gid/egid:0/0, parent /usr/bin/sudo[sudo:27916] uid/euid:0/0 gid/egid:0/0
Dec 14 18:15:08 gdOv kernel: [88966.787309] sky2 0000:06:00.0 eth1: Link is up at 100 Mbps, full duplex, flow control both
Dec 14 18:15:08 gdOv kernel: [88966.853687] grsec: (mr:U:/bin/cat) exec of /bin/cat (cat .uncenz-ts ) by /bin/cat[uncenz-1st:27931] uid/euid:1000/1000 gid/egid:1000/1000, parent /usr/local/bin/uncenz-1st[uncenz-1st:27929] uid/euid:1000/1000 gid/egid:1000/1000
Dec 14 18:15:08 gdOv kernel: [88966.854610] grsec: (mr:U:/) exec of /bin/sleep (sleep 1.5 ) by /bin/sleep[uncenz-1st:27930] uid/euid:1000/1000 gid/egid:1000/1000, parent /usr/local/bin/uncenz-1st[uncenz-1st:27743] uid/euid:1000/1000 gid/egid:1000/1000
Dec 14 18:15:08 gdOv kernel: [88966.855594] grsec: (mr:U:/usr/bin/ffmpeg) exec of /usr/bin/ffmpeg (ffmpeg -f x11grab -nostdin -loglevel quiet -s 1366x768 -r 10 -i :0.0 -c:v libx264 -preset ultrafast -threads 0 Screen_171214_181) by /usr/bin/ffmpeg[uncenz-1st:27929] uid/euid:1000/1000 gid/egid:1000/1000, parent /usr/local/bin/uncenz-1st[uncenz-1st:27743] uid/euid:1000/1000 gid/egid:1000/1000
Dec 14 18:15:09 gdOv kernel: [88967.720759] mencoder: page allocation failure: order:1, mode:0x2080024(GFP_ATOMIC|GFP_DMA32)
Dec 14 18:15:09 gdOv kernel: [88967.720775] CPU: 1 PID: 23251 Comm: mencoder Not tainted 4.9.68-unofficial+grsec171212-04 #1
Dec 14 18:15:09 gdOv kernel: [88967.720781] Hardware name: To Be Filled By O.E.M. To Be Filled By O.E.M./970 Extreme4, BIOS P2.60 11/11/2013
Dec 14 18:15:09 gdOv kernel: [88967.720784]  ffffc9000986f790 ffffffff81802176 ffffffff829df9a8 0000000000000000
Dec 14 18:15:09 gdOv kernel: [88967.720788]  ffffc9000986f818 ffffffff8123bd9d 0208002400000001 ffffffff829df9a8
Dec 14 18:15:09 gdOv kernel: [88967.720790]  ffffc9000986f7b8 0000000000000010 ffffc9000986f828 ffffc9000986f7d8
Dec 14 18:15:09 gdOv kernel: [88967.720793] Call Trace:
Dec 14 18:15:09 gdOv kernel: [88967.720803]  [<ffffffff81802176>] dump_stack+0x81/0xcb
Dec 14 18:15:09 gdOv kernel: [88967.720807]  [<ffffffff8123bd9d>] warn_alloc+0x1ad/0x1f0
Dec 14 18:15:09 gdOv kernel: [88967.720810]  [<ffffffff8123c18b>] ? __alloc_pages_slowpath+0x2fb/0x1060
Dec 14 18:15:09 gdOv kernel: [88967.720812]  [<ffffffff8123c1f4>] __alloc_pages_slowpath+0x364/0x1060
Dec 14 18:15:09 gdOv kernel: [88967.720814]  [<ffffffff8123d2fd>] __alloc_pages_nodemask+0x1bd/0x2c0
Dec 14 18:15:09 gdOv kernel: [88967.720817]  [<ffffffff81092e44>] dma_generic_alloc_coherent+0x114/0x190
Dec 14 18:15:09 gdOv kernel: [88967.720821]  [<ffffffff810cbb6d>] gart_alloc_coherent+0x6d/0x1a0
Dec 14 18:15:09 gdOv kernel: [88967.720824]  [<ffffffff8202c47c>] cx88_risc_buffer+0x12c/0x290
Dec 14 18:15:09 gdOv kernel: [88967.720827]  [<ffffffff8203371d>] buffer_prepare+0x1cd/0x2f0
Dec 14 18:15:09 gdOv kernel: [88967.720831]  [<ffffffff81ff7e07>] __buf_prepare+0x197/0x250
Dec 14 18:15:09 gdOv kernel: [88967.720834]  [<ffffffff81ff9c60>] vb2_core_qbuf+0xa0/0x300
Dec 14 18:15:09 gdOv kernel: [88967.720837]  [<ffffffff81ffe12e>] vb2_qbuf+0x9e/0xe0
Dec 14 18:15:09 gdOv kernel: [88967.720839]  [<ffffffff81ffeb69>] vb2_ioctl_qbuf+0x69/0xa0
Dec 14 18:15:09 gdOv kernel: [88967.720843]  [<ffffffff81fdb939>] v4l_qbuf+0x89/0xd0
Dec 14 18:15:09 gdOv kernel: [88967.720846]  [<ffffffff81fe196e>] __video_do_ioctl+0x1fe/0x4a0
Dec 14 18:15:09 gdOv kernel: [88967.720848]  [<ffffffff81fe1e8b>] video_usercopy+0x27b/0x820
Dec 14 18:15:09 gdOv kernel: [88967.720850]  [<ffffffff81fe1770>] ? v4l_printk_ioctl+0x100/0x100
Dec 14 18:15:09 gdOv kernel: [88967.720852]  [<ffffffff81fe2479>] video_ioctl2+0x49/0x80
Dec 14 18:15:09 gdOv kernel: [88967.720854]  [<ffffffff81fd5f36>] v4l2_ioctl+0xe6/0x1c0
Dec 14 18:15:09 gdOv kernel: [88967.720858]  [<ffffffff81305b7f>] do_vfs_ioctl+0xef/0xb40
Dec 14 18:15:09 gdOv kernel: [88967.720861]  [<ffffffff81306726>] rap_sys_ioctl+0x76/0xe0
Dec 14 18:15:09 gdOv kernel: [88967.720864]  [<ffffffff82567113>] entry_SYSCALL_64_fastpath+0x1e/0xec
Dec 14 18:15:09 gdOv kernel: [88967.720866] Mem-Info:
Dec 14 18:15:09 gdOv kernel: [88967.720872] active_anon:321300 inactive_anon:102570 isolated_anon:0
Dec 14 18:15:09 gdOv kernel: [88967.720872]  active_file:1782791 inactive_file:561806 isolated_file:0
Dec 14 18:15:09 gdOv kernel: [88967.720872]  unevictable:0 dirty:6756 writeback:0 unstable:0
Dec 14 18:15:09 gdOv kernel: [88967.720872]  slab_reclaimable:235130 slab_unreclaimable:11759
Dec 14 18:15:09 gdOv kernel: [88967.720872]  mapped:65746 shmem:4085 pagetables:5509 bounce:0
Dec 14 18:15:09 gdOv kernel: [88967.720872]  free:19343 free_pcp:1025 free_cma:0
Dec 14 18:15:09 gdOv kernel: [88967.720880] Node 0 active_anon:1285200kB inactive_anon:410280kB active_file:7131164kB inactive_file:2247224kB unevictable:0kB isolated(anon):0kB isolated(file):0kB mapped:262984kB dirty:27024kB writeback:0kB shmem:16340kB writeback_tmp:0kB unstable:0kB pages_scanned:0 all_unreclaimable? no
Dec 14 18:15:09 gdOv kernel: [88967.720882] Node 0 DMA free:12476kB min:16kB low:28kB high:40kB active_anon:0kB inactive_anon:0kB active_file:0kB inactive_file:0kB unevictable:0kB writepending:0kB present:15992kB managed:15908kB mlocked:0kB slab_reclaimable:0kB slab_unreclaimable:0kB kernel_stack:0kB pagetables:0kB bounce:0kB free_pcp:0kB local_pcp:0kB free_cma:0kB
Dec 14 18:15:09 gdOv kernel: [88967.720887] lowmem_reserve[]: 0 3116 11883 11883
Dec 14 18:15:09 gdOv kernel: [88967.720890] Node 0 DMA32 free:45812kB min:3652kB low:6840kB high:10028kB active_anon:108756kB inactive_anon:48176kB active_file:2149576kB inactive_file:619124kB unevictable:0kB writepending:24808kB present:3364976kB managed:3263712kB mlocked:0kB slab_reclaimable:276128kB slab_unreclaimable:6748kB kernel_stack:416kB pagetables:1660kB bounce:0kB free_pcp:2908kB local_pcp:688kB free_cma:0kB
Dec 14 18:15:09 gdOv kernel: [88967.720893] lowmem_reserve[]: 0 0 8767 8767
Dec 14 18:15:09 gdOv kernel: [88967.720896] Node 0 Normal free:19084kB min:10284kB low:19260kB high:28236kB active_anon:1176260kB inactive_anon:362076kB active_file:4981588kB inactive_file:1628100kB unevictable:0kB writepending:2216kB present:9175036kB managed:8977884kB mlocked:0kB slab_reclaimable:664392kB slab_unreclaimable:40288kB kernel_stack:6016kB pagetables:20376kB bounce:0kB free_pcp:1192kB local_pcp:328kB free_cma:0kB
Dec 14 18:15:09 gdOv kernel: [88967.720900] lowmem_reserve[]: 0 0 0 0
Dec 14 18:15:09 gdOv kernel: [88967.720902] Node 0 DMA: 1*4kB (H) 0*8kB 0*16kB 0*32kB 1*64kB (H) 1*128kB (H) 0*256kB 0*512kB 0*1024kB 2*2048kB (UM) 2*4096kB (M) = 12484kB
Dec 14 18:15:09 gdOv kernel: [88967.720910] Node 0 DMA32: 11391*4kB (UE) 0*8kB 0*16kB 0*32kB 0*64kB 0*128kB 0*256kB 0*512kB 0*1024kB 0*2048kB 0*4096kB = 45564kB
Dec 14 18:15:09 gdOv kernel: [88967.720917] Node 0 Normal: 4625*4kB (UEH) 27*8kB (H) 13*16kB (H) 5*32kB (H) 0*64kB 0*128kB 0*256kB 0*512kB 0*1024kB 0*2048kB 0*4096kB = 19084kB
Dec 14 18:15:09 gdOv kernel: [88967.720926] Node 0 hugepages_total=0 hugepages_free=0 hugepages_surp=0 hugepages_size=2048kB
Dec 14 18:15:09 gdOv kernel: [88967.720926] 2348711 total pagecache pages
Dec 14 18:15:09 gdOv kernel: [88967.720929] 0 pages in swap cache
Dec 14 18:15:09 gdOv kernel: [88967.720930] Swap cache stats: add 0, delete 0, find 0/0
Dec 14 18:15:09 gdOv kernel: [88967.720931] Free swap  = 8997948kB
Dec 14 18:15:09 gdOv kernel: [88967.720932] Total swap = 8997948kB
Dec 14 18:15:09 gdOv kernel: [88967.720933] 3139001 pages RAM
Dec 14 18:15:09 gdOv kernel: [88967.720935] 0 pages HighMem/MovableOnly
Dec 14 18:15:09 gdOv kernel: [88967.720936] 74625 pages reserved
Dec 14 18:15:09 gdOv kernel: [88967.720940] PAX: please report this to [email protected]
Dec 14 18:15:09 gdOv kernel: [88967.720944] BUG: unable to handle kernel NULL pointer dereference at 0000000000000004
Dec 14 18:15:09 gdOv kernel: [88967.724212] IP: [<ffffffff8203399a>] buffer_queue+0x4a/0x170
Dec 14 18:15:09 gdOv kernel: [88967.725878] PGD 151fde000 
Dec 14 18:15:09 gdOv kernel: [88967.725893] 
Dec 14 18:15:09 gdOv kernel: [88967.727540] Oops: 0002 [#1] SMP
Dec 14 18:15:09 gdOv kernel: [88967.729120] CPU: 1 PID: 23251 Comm: mencoder Not tainted 4.9.68-unofficial+grsec171212-04 #1
Dec 14 18:15:09 gdOv kernel: [88967.730702] Hardware name: To Be Filled By O.E.M. To Be Filled By O.E.M./970 Extreme4, BIOS P2.60 11/11/2013
Dec 14 18:15:09 gdOv kernel: [88967.732309] task: ffff8802c303abc0 task.stack: ffffc9000986c000
Dec 14 18:15:09 gdOv kernel: [88967.733936] RIP: 0010:[<ffffffff8203399a>]  [<ffffffff8203399a>] buffer_queue+0x4a/0x170
Dec 14 18:15:09 gdOv kernel: [88967.735558] RSP: 0018:ffffc9000986fb00  EFLAGS: 00010286
Dec 14 18:15:09 gdOv kernel: [88967.737171] RAX: ffff88031f4b0000 RBX: ffff8802c1022800 RCX: 0000000000000000
Dec 14 18:15:09 gdOv kernel: [88967.738795] RDX: 0000000000000008 RSI: 0000000000000000 RDI: ffff8802c10229e8
Dec 14 18:15:09 gdOv kernel: [88967.740442] RBP: ffffc9000986fb18 R08: 0000000000013164 R09: 0000000000000000
Dec 14 18:15:09 gdOv kernel: [88967.742052] R10: 000000000000000b R11: 0000000000ffff0a R12: ffff88031f46c000
Dec 14 18:15:09 gdOv kernel: [88967.743651] R13: 8000000000000000 R14: ffffc9000986fcc8 R15: 00000000c058560f
Dec 14 18:15:09 gdOv kernel: [88967.745240] FS:  000003a955931700(0000) GS:ffff88032fc80000(0000) knlGS:0000000000000000
Dec 14 18:15:09 gdOv kernel: [88967.746867] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
Dec 14 18:15:09 gdOv kernel: [88967.748419] CR2: 0000000000000004 CR3: 0000000002c20000 CR4: 00000000000006f0
Dec 14 18:15:09 gdOv kernel: [88967.749952] Stack:
Dec 14 18:15:09 gdOv kernel: [88967.751455]  0000000000000001 ffff8802c1022800 8000000000000000 ffffc9000986fb40
Dec 14 18:15:09 gdOv kernel: [88967.752961]  ffffffff81ff6839 ffff88031f4b0b80 ffff8802c1022800 ffffc9000986fcc8
Dec 14 18:15:09 gdOv kernel: [88967.754440]  ffffc9000986fb68 ffffffff81ff9db2 ffff88031f4b0b80 ffffc9000986fcc8
Dec 14 18:15:09 gdOv kernel: [88967.755931] Call Trace:
Dec 14 18:15:09 gdOv kernel: [88967.757358]  [<ffffffff81ff6839>] __enqueue_in_driver+0xd9/0x110
Dec 14 18:15:09 gdOv kernel: [88967.758799]  [<ffffffff81ff9db2>] vb2_core_qbuf+0x1f2/0x300
Dec 14 18:15:09 gdOv kernel: [88967.760241]  [<ffffffff81ffe12e>] vb2_qbuf+0x9e/0xe0
Dec 14 18:15:09 gdOv kernel: [88967.761657]  [<ffffffff81ffeb69>] vb2_ioctl_qbuf+0x69/0xa0
Dec 14 18:15:09 gdOv kernel: [88967.763052]  [<ffffffff81fdb939>] v4l_qbuf+0x89/0xd0
Dec 14 18:15:09 gdOv kernel: [88967.764451]  [<ffffffff81fe196e>] __video_do_ioctl+0x1fe/0x4a0
Dec 14 18:15:09 gdOv kernel: [88967.765868]  [<ffffffff81fe1e8b>] video_usercopy+0x27b/0x820
Dec 14 18:15:09 gdOv kernel: [88967.767292]  [<ffffffff81fe1770>] ? v4l_printk_ioctl+0x100/0x100
Dec 14 18:15:09 gdOv kernel: [88967.768734]  [<ffffffff81fe2479>] video_ioctl2+0x49/0x80
Dec 14 18:15:09 gdOv kernel: [88967.770209]  [<ffffffff81fd5f36>] v4l2_ioctl+0xe6/0x1c0
Dec 14 18:15:09 gdOv kernel: [88967.771658]  [<ffffffff81305b7f>] do_vfs_ioctl+0xef/0xb40
Dec 14 18:15:09 gdOv kernel: [88967.773106]  [<ffffffff81306726>] rap_sys_ioctl+0x76/0xe0
Dec 14 18:15:09 gdOv kernel: [88967.774544]  [<ffffffff82567113>] entry_SYSCALL_64_fastpath+0x1e/0xec
Dec 14 18:15:09 gdOv kernel: [88967.775961] Code: ff ff cc cc cc cc cc cc cc cc 48 8b 03 8b b3 18 02 00 00 48 8d bb e8 01 00 00 48 8b 8b 08 02 00 00 48 8b 40 48 8d 56 08 4c 8b 20 <89> 51 04 48 8b 93 10 02 00 00 c7 02 00 00 01 70 8b b3 18 02 00 
Dec 14 18:15:09 gdOv kernel: [88967.778884] RIP  [<ffffffff8203399a>] buffer_queue+0x4a/0x170
Dec 14 18:15:09 gdOv kernel: [88967.780282]  RSP <ffffc9000986fb00>
Dec 14 18:15:09 gdOv kernel: [88967.781661] CR2: 0000000000000004
Dec 14 18:15:09 gdOv kernel: [88967.790900] ---[ end trace 489d7da926a45019 ]---
Dec 14 18:15:09 gdOv kernel: [88967.790903] grsec: banning user with uid 1000 until system restart for suspicious kernel crash
Dec 14 18:15:09 gdOv kernel: [88967.803691] grsec: (root:U:/usr/sbin/rsyslogd) denied access to hidden file /run/utmp by /usr/sbin/rsyslogd[rs:main Q:Reg:2397] uid/euid:0/0 gid/egid:0/0, parent /sbin/init[init:1] uid/euid:0/0 gid/egid:0/0
Dec 14 18:15:09 gdOv kernel: [88967.803759] grsec: (root:U:/usr/sbin/rsyslogd) denied access to hidden file /run/utmp by /usr/sbin/rsyslogd[rs:main Q:Reg:2397] uid/euid:0/0 gid/egid:0/0, parent /sbin/init[init:1] uid/euid:0/0 gid/egid:0/0
Dec 14 18:15:09 gdOv kernel: [88967.931156] grsec: (root:U:/bin/bash) special role admin (id 14) exited by /bin/bash[bash:4383] uid/euid:0/0 gid/egid:0/0, parent /usr/bin/sudo[sudo:4382] uid/euid:0/0 gid/egid:0/0
Dec 14 18:15:09 gdOv kernel: [88968.067460] grsec: (root:U:/sbin/agetty) exec of /sbin/agetty (/sbin/getty 38400 tty6 ) by /sbin/agetty[init:27944] uid/euid:0/0 gid/egid:0/0, parent /sbin/init[init:1] uid/euid:0/0 gid/egid:0/0
Dec 14 18:15:15 gdOv kernel: [88973.687989] mrfw_dropIN=eth1 OUT= MAC=00:30:4f:47:37:17:2c:95:7f:14:4e:c6:08:00 SRC=192.168.1.1 DST=192.168.1.2 LEN=576 TOS=0x00 PREC=0x00 TTL=64 ID=0 PROTO=UDP SPT=67 DPT=68 LEN=556 
Dec 14 18:15:15 gdOv kernel: [88973.689363] grsec: (root:U:/sbin/dhclient-script) exec of /sbin/dhclient-script (/sbin/dhclient-script ) by /sbin/dhclient-script[dhclient:27946] uid/euid:0/0 gid/egid:0/0, parent /sbin/dhclient[dhclient:6073] uid/euid:0/0 gid/egid:0/0
Dec 14 18:15:15 gdOv kernel: [88973.693174] grsec: (root:U:/bin/run-parts) exec of /bin/run-parts (run-parts --list /etc/dhcp/dhclient-enter-hooks.d ) by /bin/run-parts[dhclient-script:27947] uid/euid:0/0 gid/egid:0/0, parent /sbin/dhclient-script[dhclient-script:27946] uid/euid:0/0 gid/egid:0/0
Dec 14 18:15:15 gdOv kernel: [88973.697380] grsec: (root:U:/bin/readlink) exec of /bin/readlink (readlink -f /etc/resolv.conf ) by /bin/readlink[dhclient-script:27948] uid/euid:0/0 gid/egid:0/0, parent /sbin/dhclient-script[dhclient-script:27946] uid/euid:0/0 gid/egid:0/0
Dec 14 18:15:15 gdOv kernel: [88973.702685] grsec: (root:U:/bin/rm) exec of /bin/rm (rm -f /etc/resolv.conf.dhclient-new.27946 ) by /bin/rm[dhclient-script:27949] uid/euid:0/0 gid/egid:0/0, parent /sbin/dhclient-script[dhclient-script:27946] uid/euid:0/0 gid/egid:0/0
Dec 14 18:15:15 gdOv kernel: [88973.704240] grsec: (root:U:/bin/chown) exec of /bin/chown (chown --reference=/etc/resolv.conf /etc/resolv.conf.dhclient-new.27946 ) by /bin/chown[dhclient-script:27950] uid/euid:0/0 gid/egid:0/0, parent /sbin/dhclient-script[dhclient-script:27946] uid/euid:0/0 gid/egid:0/0
Dec 14 18:15:15 gdOv kernel: [88973.708375] grsec: (root:U:/bin/chmod) exec of /bin/chmod (chmod --reference=/etc/resolv.conf /etc/resolv.conf.dhclient-new.27946 ) by /bin/chmod[dhclient-script:27951] uid/euid:0/0 gid/egid:0/0, parent /sbin/dhclient-script[dhclient-script:27946] uid/euid:0/0 gid/egid:0/0
Dec 14 18:15:15 gdOv kernel: [88973.711010] grsec: (root:U:/bin/mv) exec of /bin/mv (mv -f /etc/resolv.conf.dhclient-new.27946 /etc/resolv.conf ) by /bin/mv[dhclient-script:27952] uid/euid:0/0 gid/egid:0/0, parent /sbin/dhclient-script[dhclient-script:27946] uid/euid:0/0 gid/egid:0/0

@miroR
Copy link
Author

miroR commented Dec 14, 2017

HacKurx wrote:

If you are sure you know the cause, disable "GRKERNSEC_KERN_LOCKOUT" to see what happens next.

Long time no read from you! 👍
I will try and follow your advice.
But no, I'm not sure about the cause... Far from. I'm the least knowledgeable in these discussions --not that many people participate... Guess why? Maybe because everybody understands it all completely... Or the other way round?
And the crash above --so similar to the previous one(s) in this issue, happened as I was writing to Getmail ML about these crashes having a (possibly) related hard to diagnose issue there:
Getmail and Maildrop tricked into delivering truncated emails
( but in my next email there, sent 2 hr ago, yet to appear )

@miroR
Copy link
Author

miroR commented Dec 18, 2017

HacKurx wrote:

If you are sure you know the cause, disable "GRKERNSEC_KERN_LOCKOUT" to see what happens next.
But that's on all the time in both my all-modules-any-sytem kernel that I post on:
https://croatiafidelis.hr/gnu/deb/linux-deb-grsec-current/
as well as the only-my-hardware no-modules kernel that I use after I test the first one.

  +------------------ Active kernel exploit response -------------------+
  | CONFIG_GRKERNSEC_KERN_LOCKOUT:                                      |  
  |                                                                     |  
  | If you say Y here, when a PaX alert is triggered due to suspicious  |  
  | activity in the kernel (from KERNEXEC/UDEREF/USERCOPY)              |  
  | or an OOPS occurs due to bad memory accesses, instead of just       |  
  | terminating the offending process (and potentially allowing         |  
  | a subsequent exploit from the same user), we will take one of two   |  
  | actions:                                                            |  
  |  If the user was root, we will panic the system                     |  
  |  If the user was non-root, we will log the attempt, terminate       |  
  |  all processes owned by the user, then prevent them from creating   |  
  |  any new processes until the system is restarted                    |  
  | This deters repeated kernel exploitation/bruteforcing attempts      |  
  | and is useful for later forensics.                                  |  
  |                                                                     |  
  | Symbol: GRKERNSEC_KERN_LOCKOUT [=y]                                 |  
  | Type  : boolean                                                     |  
  | Prompt: Active kernel exploit response                              |  
  |   Location:                                                         |  
  |     -> Security options                                             |  
  |       -> Grsecurity                                                 |  
  |         -> Grsecurity (GRKERNSEC [=y])                              |  
  |           -> Customize Configuration                                |  
  |             -> Memory Protections                                   |  
  |   Defined at grsecurity/Kconfig:263                                 |  
  |   Depends on: GRKERNSEC [=y] && (X86 [=y] || ARM || PPC || SPARC)   |  
  |                                                                     |
  +--------------------------------------------------------------(100%)-+  
  |                              < Exit >                               |  
  +---------------------------------------------------------------------+

Notice the:

  | CONFIG_GRKERNSEC_KERN_LOCKOUT:                                      |  

Hmmmh...

@minipli
Copy link
Owner

minipli commented Dec 28, 2017

That's an upstream kernel bug in the cx88 kernel module; probably others, too. The memory allocation in cx88_risc_buffer() fails but gets ignored by returning 0 from buffer_prepare() in any case. Later on, in buffer_queue(), that failed memory allocation triggers the above panic by dereferencing the NULL pointer in buf->risc.cpu.

Please report this bug upstream. Not our bug ;)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants