|
From: roy b. <roy...@ya...> - 2009-05-27 22:46:28
|
Hi, I just wondered, as no-one has replied, if I am the one one with this issue? Many Thanks Roy. PS Hope sending a reply to my own mail is acceptable :-) --- On Thu, 14/5/09, roy barnard <roy...@ya...> wrote: > From: roy barnard <roy...@ya...> > Subject: [Devil-linux-develop] DL-1.4RC1-2009-05-12 Grub Installation on USB mounted Flash Card issue and workaround > To: dev...@li... > Date: Thursday, 14 May, 2009, 6:06 PM > > Hi, > > I have been having grub installation issues with the 1.3.7 > and 1.4 Release streams. I have just reproduced the > same issue with 1.4RC1-2009-05-12. > > What I have established is that the 'install-on-usb' script > when used to install to a Flash Card accessed via a /dev/sda > (or as applicable), the script calls grub using a shell > script variable: > > > grub_shell=$TMPDIR/iso-mnt/sbin/grub > > This gives (dependant on DL release) one of two types of > error either grub crashes or the grub fails to install > properbly complaining about a device mapping and/or LVM > issue. > > The system being used to install DL onto the flash Card > is: > > CentOS release 4.4 (Final) > With Kernal 2.6.9-42.0.8 #1 SMP i686 i386 > IDE HardDisk (Non-SCSI system) installed without LVM > configured. > > My workaround for this issue is to change the > 'install-on-usb' line from the above to the following: > grub_shell=/sbin/grub > > I believe that this means that the Grub being installed is > the one from CentOS NOT the Grub shipped as part of DL. > > I appreciate that this is not a good long term fix but it > is allowing me to roll out 20 Internal OpenVPN Firewalls > using Devil Linux 1.4RC1 :-) > > I am willing to do any testing you might need in providing > a better solution, but I am happy with my current > <strikeout>fudge</strikeout> workaround shown > here. > > I would be interested if anyone else has found similar > issues and any better fixes for this grub issue. > > Thanks for all the good work > > Roy Barnard > > > > > > ------------------------------------------------------------------------------ > The NEW KODAK i700 Series Scanners deliver under ANY > circumstances! Your > production scanning environment may not be a perfect world > - but thanks to > Kodak, there's a perfect scanner to get the job done! With > the NEW KODAK i700 > Series Scanner you'll get full speed at 300 dpi even with > all image > processing features enabled. http://p.sf.net/sfu/kodak-com > _______________________________________________ > Devil-linux-develop mailing list > Dev...@li... > https://lists.sourceforge.net/lists/listinfo/devil-linux-develop > |
|
From: Serge L. <fi...@in...> - 2009-05-27 23:25:37
|
Hi Roy, you are not the one who faced the problem. I'm afraid anyone have the same problem. The root source of it is grsecurity. I'd suggest using syslinux loader in case of grsec enabled version of DL and any loader (grub,syslinux) for DL builds without grsec. Thank you for the feedback, Serge roy barnard wrote: > Hi, > > I just wondered, as no-one has replied, if I am the one one with this issue? > > Many Thanks > Roy. > > PS Hope sending a reply to my own mail is acceptable :-) > > > --- On Thu, 14/5/09, roy barnard <roy...@ya...> wrote: > >> From: roy barnard <roy...@ya...> >> Subject: [Devil-linux-develop] DL-1.4RC1-2009-05-12 Grub Installation on USB mounted Flash Card issue and workaround >> To: dev...@li... >> Date: Thursday, 14 May, 2009, 6:06 PM >> >> Hi, >> >> I have been having grub installation issues with the 1.3.7 >> and 1.4 Release streams. I have just reproduced the >> same issue with 1.4RC1-2009-05-12. >> >> What I have established is that the 'install-on-usb' script >> when used to install to a Flash Card accessed via a /dev/sda >> (or as applicable), the script calls grub using a shell >> script variable: >> >> >> grub_shell=$TMPDIR/iso-mnt/sbin/grub >> >> This gives (dependant on DL release) one of two types of >> error either grub crashes or the grub fails to install >> properbly complaining about a device mapping and/or LVM >> issue. >> >> The system being used to install DL onto the flash Card >> is: >> >> CentOS release 4.4 (Final) >> With Kernal 2.6.9-42.0.8 #1 SMP i686 i386 >> IDE HardDisk (Non-SCSI system) installed without LVM >> configured. >> >> My workaround for this issue is to change the >> 'install-on-usb' line from the above to the following: >> grub_shell=/sbin/grub >> >> I believe that this means that the Grub being installed is >> the one from CentOS NOT the Grub shipped as part of DL. >> >> I appreciate that this is not a good long term fix but it >> is allowing me to roll out 20 Internal OpenVPN Firewalls >> using Devil Linux 1.4RC1 :-) >> >> I am willing to do any testing you might need in providing >> a better solution, but I am happy with my current >> <strikeout>fudge</strikeout> workaround shown >> here. >> >> I would be interested if anyone else has found similar >> issues and any better fixes for this grub issue. >> >> Thanks for all the good work >> >> Roy Barnard |
|
From: Serge L. <fi...@in...> - 2009-05-28 21:48:12
|
Hi Roy, Thanks for attracting our attention to the problem. Hopefully it will be fixed in RC2. I did some test and it looks solvable. Sincerely, Serge roy barnard wrote: > Hi, > > I just wondered, as no-one has replied, if I am the one one with this issue? > > Many Thanks > Roy. > > PS Hope sending a reply to my own mail is acceptable :-) > |
|
From: Serge L. <fi...@in...> - 2009-05-28 22:04:29
|
Heiko, To fix the problem we should modify ELF section of grub binary. It can be done either by paxctl or shpax utility. I see script for chpax in the repository but it's enabled for 2.4 kernel only. I've checked PaX homepage and paxctl seems to be a new replacement of shpax. So, I suggest using paxctl and remove shpax's script. I need your advice because my grsec experience is zero. Serge roy barnard wrote: > Hi, > > I just wondered, as no-one has replied, if I am the one one with this issue? > > Many Thanks > Roy. > > PS Hope sending a reply to my own mail is acceptable :-) > > > --- On Thu, 14/5/09, roy barnard <roy...@ya...> wrote: > >> From: roy barnard <roy...@ya...> >> Subject: [Devil-linux-develop] DL-1.4RC1-2009-05-12 Grub Installation on USB mounted Flash Card issue and workaround >> To: dev...@li... >> Date: Thursday, 14 May, 2009, 6:06 PM >> >> Hi, >> >> I have been having grub installation issues with the 1.3.7 >> and 1.4 Release streams. I have just reproduced the >> same issue with 1.4RC1-2009-05-12. >> >> What I have established is that the 'install-on-usb' script >> when used to install to a Flash Card accessed via a /dev/sda >> (or as applicable), the script calls grub using a shell >> script variable: >> >> >> grub_shell=$TMPDIR/iso-mnt/sbin/grub >> >> This gives (dependant on DL release) one of two types of >> error either grub crashes or the grub fails to install >> properbly complaining about a device mapping and/or LVM >> issue. >> >> The system being used to install DL onto the flash Card >> is: >> >> CentOS release 4.4 (Final) >> With Kernal 2.6.9-42.0.8 #1 SMP i686 i386 >> IDE HardDisk (Non-SCSI system) installed without LVM >> configured. >> >> My workaround for this issue is to change the >> 'install-on-usb' line from the above to the following: >> grub_shell=/sbin/grub >> >> I believe that this means that the Grub being installed is >> the one from CentOS NOT the Grub shipped as part of DL. >> >> I appreciate that this is not a good long term fix but it >> is allowing me to roll out 20 Internal OpenVPN Firewalls >> using Devil Linux 1.4RC1 :-) >> >> I am willing to do any testing you might need in providing >> a better solution, but I am happy with my current >> <strikeout>fudge</strikeout> workaround shown >> here. >> >> I would be interested if anyone else has found similar >> issues and any better fixes for this grub issue. >> >> Thanks for all the good work >> >> Roy Barnard >> >> >> >> >> >> ------------------------------------------------------------------------------ >> The NEW KODAK i700 Series Scanners deliver under ANY >> circumstances! Your >> production scanning environment may not be a perfect world >> - but thanks to >> Kodak, there's a perfect scanner to get the job done! With >> the NEW KODAK i700 >> Series Scanner you'll get full speed at 300 dpi even with >> all image >> processing features enabled. http://p.sf.net/sfu/kodak-com >> _______________________________________________ >> Devil-linux-develop mailing list >> Dev...@li... >> https://lists.sourceforge.net/lists/listinfo/devil-linux-develop >> > > > > > ------------------------------------------------------------------------------ > Register Now for Creativity and Technology (CaT), June 3rd, NYC. CaT > is a gathering of tech-side developers & brand creativity professionals. Meet > the minds behind Google Creative Lab, Visual Complexity, Processing, & > iPhoneDevCamp as they present alongside digital heavyweights like Barbarian > Group, R/GA, & Big Spaceship. http://p.sf.net/sfu/creativitycat-com > _______________________________________________ > Devil-linux-develop mailing list > Dev...@li... > https://lists.sourceforge.net/lists/listinfo/devil-linux-develop > |
|
From: Heiko Z. <he...@zu...> - 2009-05-29 11:56:14
|
Quoting Serge Leschinsky <fi...@in...>: > Heiko, > > To fix the problem we should modify ELF section of grub binary. It > can be done > either by paxctl or shpax utility. I see script for chpax in the > repository but > it's enabled for 2.4 kernel only. I've checked PaX homepage and > paxctl seems to > be a new replacement of shpax. So, I suggest using paxctl and remove shpax's > script. > I need your advice because my grsec experience is zero. Would the 'scanelf' utility help any? We got that included already. Other then that I'd just go by what you saw on the grsecurity website. It's a very long time ago since I played with those utilities. -- Regards Heiko Zuerker http://www.devil-linux.org ---------------------------------------------------------------- This message was sent using IMP, the Internet Messaging Program. |
|
From: Serge L. <fi...@in...> - 2009-05-29 18:50:31
|
Heiko Zuerker wrote: >> it's enabled for 2.4 kernel only. I've checked PaX homepage and >> paxctl seems to >> be a new replacement of shpax. So, I suggest using paxctl and remove shpax's >> script. >> I need your advice because my grsec experience is zero. > > Would the 'scanelf' utility help any? We got that included already. > Other then that I'd just go by what you saw on the grsecurity website. > It's a very long time ago since I played with those utilities. I guess - no. I've read 'scanelf' man page and not found the way how to change necessary flags. Well, 'paxctl' utility has been added to the build system and I've added 'correction code' to grub build script. Let's wait for a feedback :-) Serge |