LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Enterprise Linux Forums > Linux - Enterprise
User Name
Password
Linux - Enterprise This forum is for all items relating to using Linux in the Enterprise.

Notices


Reply
  Search this Thread
Old 07-14-2016, 10:14 PM   #1
Z0sickx
LQ Newbie
 
Registered: Jun 2016
Posts: 17

Rep: Reputation: Disabled
Kernel Panic Resolution


Hello all,

i've been searching for a few hours/troubleshooting 2 servers that went down today both with kernel panic issues so here are the variables. Both servers are Redhat 5

1) today we were hardening the systems mainly just changing file permissions, or changing ownership of files in specific folders. everything took about 4 hours but once we finished everything was working well. fast forward 2 hours later both displayed full on Kernal panics

2) server room its in is very hot....100F server display does not show any hardware failure...but not convinced. (AC broke)

3) i implemented the same hardening changes on 3 systems with the same image but were VM's.

4) the servers that went down are 2 Physical servers


we really want to get into the kernal logs but can't...booting into single user mode /var is empty. Since its in a secure location i can't just bring in a live CD to do a rescue. Any other ideas? Getting those logs would be my most desired want, or any other ideas to fix


this gave me some ideas what to look for hardware wise http://www.makeuseof.com/tag/dont-pa...kernel-panics/

Last edited by Z0sickx; 07-14-2016 at 10:38 PM.
 
Old 07-14-2016, 10:34 PM   #2
syg00
LQ Veteran
 
Registered: Aug 2003
Location: Australia
Distribution: Lots ...
Posts: 21,145

Rep: Reputation: 4124Reputation: 4124Reputation: 4124Reputation: 4124Reputation: 4124Reputation: 4124Reputation: 4124Reputation: 4124Reputation: 4124Reputation: 4124Reputation: 4124
Quote:
Originally Posted by Z0sickx View Post
we really want to get into the kernal logs but can't...booting into single user mode /var is empty.
That probably means you mount /var separately - check /etc/fstab.

What do you mean (exactly) by "single user mode" ?. Does the machine(s) drop into rescue mode on boot, or are you forcing it to boot in single user mode. Be (very) specific.
What distro - again be specific, including release.
 
Old 07-14-2016, 10:38 PM   #3
Z0sickx
LQ Newbie
 
Registered: Jun 2016
Posts: 17

Original Poster
Rep: Reputation: Disabled
Quote:
Originally Posted by syg00 View Post
That probably means you mount /var separately - check /etc/fstab.

What do you mean (exactly) by "single user mode" ?. Does the machine(s) drop into rescue mode on boot, or are you forcing it to boot in single user mode. Be (very) specific.
What distro - again be specific, including release.
Sorry, i'm using Redhat 5, I booted into Single User mode by editing the Kernal file in Grub. init=/bin/bash
 
Old 07-14-2016, 11:25 PM   #4
Z0sickx
LQ Newbie
 
Registered: Jun 2016
Posts: 17

Original Poster
Rep: Reputation: Disabled
so the big question is how do i mount /var in single user mode? i did an initial mount -w -o remount /. can't escalate to root though :/
 
Old 07-15-2016, 04:32 AM   #5
syg00
LQ Veteran
 
Registered: Aug 2003
Location: Australia
Distribution: Lots ...
Posts: 21,145

Rep: Reputation: 4124Reputation: 4124Reputation: 4124Reputation: 4124Reputation: 4124Reputation: 4124Reputation: 4124Reputation: 4124Reputation: 4124Reputation: 4124Reputation: 4124
Why did you do that ?. What is in fstab ?.
Issue a mount command for whatever /var is mounted on. Is it LVM ?. Has a vgchange been issued ?.
We don't have the info you do.

And why did you override init ?. Why do you think the init scripts won't save "yesterdays" logs at boot the same as it always does at boot ?.
 
Old 07-15-2016, 07:44 AM   #6
Z0sickx
LQ Newbie
 
Registered: Jun 2016
Posts: 17

Original Poster
Rep: Reputation: Disabled
Quote:
Originally Posted by syg00 View Post
Why did you do that ?. What is in fstab ?.
Issue a mount command for whatever /var is mounted on. Is it LVM ?. Has a vgchange been issued ?.
We don't have the info you do.

And why did you override init ?. Why do you think the init scripts won't save "yesterdays" logs at boot the same as it always does at boot ?.
the only way i can navigate anything within the system is single user mode. When the system goes through the boot process, everything seems fine and dandy when you get the login on the CLI, after a few seconds the screen goes wack and you see the kernal panic errors with errors such as "cache_fulxarrayx0x74", kme_cace_free, int_check_syscall_exit, drain_arrary, run_workqueue, worker_thread,Child_NP

Is it mount /whatever the path it is in fstab?

how do i get to the init scripts? I'm not fully sure i understand i'm not a redhat admin level by any means and just know how to get around/change settings to make my application work on it
 
Old 07-24-2016, 01:32 PM   #7
Z0sickx
LQ Newbie
 
Registered: Jun 2016
Posts: 17

Original Poster
Rep: Reputation: Disabled
this thread is solved...the issue was Host intrusion Prevention software causing the issue
 
Old 07-25-2016, 08:19 AM   #8
jsdomingo
LQ Newbie
 
Registered: Feb 2016
Posts: 18

Rep: Reputation: Disabled
Quote:
Originally Posted by Z0sickx View Post
this thread is solved...the issue was Host intrusion Prevention software causing the issue
Care to elaborate on what you did?
 
Old 08-05-2016, 05:55 PM   #9
Z0sickx
LQ Newbie
 
Registered: Jun 2016
Posts: 17

Original Poster
Rep: Reputation: Disabled
Quote:
Originally Posted by jsdomingo View Post
Care to elaborate on what you did?
sure

step 1: boot into single user mode
setp 2: mounted the directory i needed to get access to /var
step 3: deleted all HIPS related software
step 4: reboot

and everything was working properly
 
Old 08-08-2016, 07:01 AM   #10
jsdomingo
LQ Newbie
 
Registered: Feb 2016
Posts: 18

Rep: Reputation: Disabled
Quote:
Originally Posted by Z0sickx View Post
sure

step 1: boot into single user mode
setp 2: mounted the directory i needed to get access to /var
step 3: deleted all HIPS related software
step 4: reboot

and everything was working properly
Did you attempt to stop HIPS prior to removing all related software?

Code:
service cma stop
 
Old 08-08-2016, 09:37 AM   #11
ihaveavirus
LQ Newbie
 
Registered: Jul 2016
Distribution: RHEL
Posts: 22

Rep: Reputation: Disabled
Assuming we're talking about McAfee HBSS suit here, CMA is not HIPS. CMA is the service for Policy Auditor. HIPS is a completely separate package and even if you are able to stop HIPS, it will re-start itself if you are in run level 3 or 5. The only sure fire way to stop HIPS is removing the packages associated with it, then rebooting since it has hooks in the kernel.

Moral of the story: get rid of HIPS if you are able to and just use SELinux. Reason being you have more control over the system with SELinux and you can easily troubleshoot any policy violations. If you do continue using HIPS, disable SELinux because if you have both enabled be prepared for an unusable and unstable system.

Last edited by ihaveavirus; 08-08-2016 at 09:39 AM.
 
Old 08-08-2016, 10:44 AM   #12
jsdomingo
LQ Newbie
 
Registered: Feb 2016
Posts: 18

Rep: Reputation: Disabled
Quote:
Originally Posted by ihaveavirus View Post
Assuming we're talking about McAfee HBSS suit here, CMA is not HIPS. CMA is the service for Policy Auditor. HIPS is a completely separate package and even if you are able to stop HIPS, it will re-start itself if you are in run level 3 or 5. The only sure fire way to stop HIPS is removing the packages associated with it, then rebooting since it has hooks in the kernel.

Moral of the story: get rid of HIPS if you are able to and just use SELinux. Reason being you have more control over the system with SELinux and you can easily troubleshoot any policy violations. If you do continue using HIPS, disable SELinux because if you have both enabled be prepared for an unusable and unstable system.
I wish this was possible but I live in a DoD world.
 
Old 08-08-2016, 10:50 AM   #13
ihaveavirus
LQ Newbie
 
Registered: Jul 2016
Distribution: RHEL
Posts: 22

Rep: Reputation: Disabled
Quote:
Originally Posted by jsdomingo View Post
I wish this was possible but I live in a DoD world.
I understand the struggle, but it is something worth exploring. I don't know what command you're at or what part of the DoD you're under, but it would be a fight worth having to get the policies changed. Most of the paper pushers creating these security policies have no concept of the technical difficulties introduced by HIPS.

Last edited by ihaveavirus; 08-08-2016 at 10:53 AM.
 
Old 08-08-2016, 10:56 PM   #14
Z0sickx
LQ Newbie
 
Registered: Jun 2016
Posts: 17

Original Poster
Rep: Reputation: Disabled
Quote:
Originally Posted by jsdomingo View Post
Did you attempt to stop HIPS prior to removing all related software?

Code:
service cma stop
no we just wanted to get that shit off, also there was no point of shutting it off if your just going to uninstall, no remenant would remain afterwards
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Kernel panic giving me panic attack!! alicorn Linux - General 6 05-26-2016 11:40 AM
Determining cause of Linux kernel panic "Kernel panic - not syncing: Fatal exception" gladman002 Linux - Kernel 1 09-07-2015 08:04 PM
Logging a Kernel Panic Event - Problem writing the log in panic situation lucasct Linux - Embedded & Single-board computer 5 09-08-2011 01:44 PM
kernel panic problem resolution prince2242002 Red Hat 3 10-02-2006 01:25 PM
kernel panic (narius panic) narius Linux - Newbie 3 06-20-2002 03:56 PM

LinuxQuestions.org > Forums > Enterprise Linux Forums > Linux - Enterprise

All times are GMT -5. The time now is 04:35 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration