Bugfixes

This page lists fixes for relevant bugs in all released RSBAC versions from 1.1.0 onwards. If you want to report new bugs or problems, please write to the list and do not forget to mention your kernel and RSBAC version.

Reported oopses and crashes can only be investigated with known function addresses. If these are not shown in the log, we will need your System.map to find them.

The very latest bugfixes might only be available in the subversion repository at svn://rsbac.mprivacy-update.de/rsbac.

Download bugfixes directly

Version 1.2.4

1. JAIL/PAX: suid/sgid files can be created inside jail, RSBAC does not compile without PAX module

Download it (gnupg, md5)

2. General/Kernels 2.4.29-31 and 2.6.10: Missing RSBAC interceptions for sys_sysctl

Download for 2.4 kernels (gnupg, md5)

Download for 2.6 kernels (gnupg , md5)

3. General: Various fixes.

Download for 2.4 kernels (gnupg, md5)

Download for 2.6 kernels (gnupg , md5)

4. General: Memory leak in logging code

Download it (gnupg, md5)

5. General/Kernels 2.4 with bugfix 1.2.4-3: Compile error with gcc 2.95

Download it (gnupg, md5)

6. General: Fix rare dereference oopses in inheritance code.

Download for 2.4 kernels (gnupg, md5)

Download for 2.6 kernels (gnupg , md5)

Download for 2.4 kernels (gnupg, md5)

Download for 2.6 kernels (gnupg , md5)

Version 1.2.3

1. AUTH: In some configs, normal users can switch AUTH module off

Download it (gnupg, md5)

2. General/Kernel 2.6.7: Compile error with GCC 2.95

Download it (gnupg, md5)

3. JAIL: suid/sgid files can be created inside jail

Download it (gnupg, md5)

4. General/Kernels 2.4.26-28/x86_64: Missing RSBAC syscall number.

Download it (gnupg, md5)

5. Admin tools/PAX: attr_set_fd does not accept PaX characters.

Download it (gnupg, md5)

6. General: Various small fixes.

Download it (gnupg, md5)

7. General/Kernels 2.6.6-9: RSBAC initializes from device 00:00

Download it (gnupg, md5)

8. General/Kernels 2.6.7-9: Missing interception for remount

Download it (gnupg, md5)

9. General: More small fixes.

Download it (gnupg, md5)

10. General/Kernels 2.6: Lockups with secure_delete

Download it (gnupg, md5)

11. General/Kernel 2.6.10: PaX and RSBAC PAX module do not compile together

Download it (gnupg, md5)

12. General/Kernels 2.6.6-2.6.10: Hangs with ReiserFS and Posix ACLs

Download it (gnupg, md5)

13. RES: Cannot reset FD resource settings

Download it (gnupg, md5)

14. General/Kernels 2.4.x: Missing RSBAC interception for sys_sysctl

Download it (gnupg, md5)

Version 1.2.2

1. ACL: Network access control uses local template only

2. General/2.4 kernels: Busy Inodes on Umount

3. MAC: Some attributes are unprotected

4. General/SMP Systems: deadlocks on mount or umount possible

5. General: rare oopses in rsbac_get_parent

6. General/Network: wrong remote ports

7. General/Initrd: Cannot umount initial ramdisk

8. AUTH: In some configs, normal users can switch AUTH module off

Version 1.2.1

1. ACL: Possible kernel oopses and hangs when modifying FD or DEV default ACLs

2. General/2.4.19 kernel: process hangs on file truncation with secure_delete

3. JAIL: IPC contact to outside of jail does not work

4. General: Admin tool rsbac_klogd from contrib does not compile

5. General: Booting with Initial Ramdisk (initrd) hangs

Version 1.2.0

If you encounter problems with RSBAC, please make sure that your system is not too old. E.g., your bash version should have a builtin test command for the menues.

1. General: Admin Tool attr_back_fd produces tons of errors EINVALIDMODULE

2. General: Admin Tool Script backup_all_1.1.2 does not run correctly on RC backup

3. General: Workaround for menuconfig bug triggered by CONFIG_RSBAC_NET

4. General: Compilation fails with PM, but without 'Show more options'

5. RC: Admin Tool rc_get_item backup with -p (printall) does not fully backup

6. General: Process signalling is not always intercepted

Version 1.1.2

1. General/2.4.[89] kernels: busy inodes after umount

Version 1.1.1

1. General/ReiserFS: rsbac_check with inode checks fails

2. General/Net support: some programs cannot bind UNIX sockets, e.g. postfix, syslog-ng, mysql

3. General: Rename does not check for overwrite

4. General: 2.4.[0-5] patch removes Linux check for valid signals

Version 1.1.0

1. ACL: Some programs will not run when called as ordinary user

2. ACL: Admin Tool acl_tlist does not backup SCD target ACLs correctly

3. General: rsbacd disabled