reconnecting USB p rinter

Tom London selinux at gmail.com
Sun Sep 26 02:01:25 UTC 2004


Running strict/enforcing, w/USB printer.

Reconnecting printer (after pulling the plug) yields the following:

Sep 25 18:46:47 fedora kernel: audit(1096163207.182:0): avc:  denied 
{ search } for  pid=7592 exe=/usr/sbin/hal_lpadmin name=cups dev=hda2
ino=4474131 scontext=system_u:system_r:hald_t
tcontext=system_u:object_r:cupsd_etc_t tclass=dir
Sep 25 18:46:48 fedora kernel: audit(1096163208.050:0): avc:  denied 
{ read } for  pid=7593 exe=/usr/bin/python name=printconf_tui.py
dev=hda2 ino=4309021 scontext=system_u:system_r:hald_t
tcontext=system_u:object_r:printconf_t tclass=file
Sep 25 18:46:48 fedora kernel: audit(1096163208.050:0): avc:  denied 
{ getattr } for  pid=7593 exe=/usr/bin/python
path=/usr/share/printconf/util/printconf_tui.py dev=hda2 ino=4309021
scontext=system_u:system_r:hald_t
tcontext=system_u:object_r:printconf_t tclass=file
Sep 25 18:46:49 fedora kernel: audit(1096163209.538:0): avc:  denied 
{ read } for  pid=7595 exe=/usr/bin/perl name=urandom dev=tmpfs
ino=965 scontext=system_u:system_r:hald_t
tcontext=system_u:object_r:urandom_device_t tclass=chr_file

Attached patch to cups.te adds allow rules for these.

Please correct/edit/etc.
   tom

-- 
Tom London
-------------- next part --------------
A non-text attachment was scrubbed...
Name: diff-cups
Type: application/octet-stream
Size: 367 bytes
Desc: not available
Url : http://lists.fedoraproject.org/pipermail/selinux/attachments/20040925/994835e8/attachment.obj 


More information about the selinux mailing list