Bug 1291033
Summary: | SELinux is preventing hp from 'write' accesses on the directory /var/lib/net-snmp/mib_indexes. | ||
---|---|---|---|
Product: | [Fedora] Fedora | Reporter: | Matthew Saltzman <mjs> |
Component: | selinux-policy | Assignee: | Lukas Vrabec <lvrabec> |
Status: | CLOSED ERRATA | QA Contact: | Fedora Extras Quality Assurance <extras-qa> |
Severity: | high | Docs Contact: | |
Priority: | medium | ||
Version: | 23 | CC: | bztdlinux, dominick.grift, dwalsh, erm67, garrett.mitchener, laurent.rineau__fedora, luya, lvrabec, mgrepl, obliterator666, pb, plautrba, redhat-bugzilla, req1348, rpm, sanjay.ankur, v |
Target Milestone: | --- | ||
Target Release: | --- | ||
Hardware: | x86_64 | ||
OS: | Unspecified | ||
Whiteboard: | abrt_hash:eaacbb77d6e05b06952481485c7608b9b6ee1a5effdba3eecab2c3d01a562e94; | ||
Fixed In Version: | selinux-policy-3.13.1-158.8.fc23 selinux-policy-3.13.1-158.9.fc23 | Doc Type: | Bug Fix |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2016-03-05 06:22:34 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: |
Description
Matthew Saltzman
2015-12-13 01:24:57 UTC
Description of problem: When printing to a HP Printer. Version-Release number of selected component: selinux-policy-3.13.1-155.fc23.noarch Additional info: reporter: libreport-2.6.3 hashmarkername: setroubleshoot kernel: 4.2.6-301.fc23.x86_64 type: libreport Description of problem: Popped up on desktop session. Version-Release number of selected component: selinux-policy-3.13.1-157.fc23.noarch Additional info: reporter: libreport-2.6.3 hashmarkername: setroubleshoot kernel: 4.2.7-300.fc23.x86_64 type: libreport I'm seeing this too with: Source RPM Packages hplip-3.15.11-3.fc23.x86_64 Target RPM Packages net-snmp-libs-5.7.3-7.fc23.x86_64 Policy RPM selinux-policy-3.13.1-157.fc23.noarch when printing to a HP 8600 Plus printer. Raw Audit Messages type=AVC msg=audit(1451161908.916:625): avc: denied { write } for pid=6061 comm="hp" name="mib_indexes" dev="dm-1" ino=786500 scontext=system_u:system_r:cupsd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:snmpd_var_lib_t:s0 tclass=dir permissive=0 type=SYSCALL msg=audit(1451161908.916:625): arch=x86_64 syscall=open success=no exit=EACCES a0=7ffeebac8760 a1=241 a2=1b6 a3=240 items=0 ppid=2553 pid=6061 auid=4294967295 uid=0 gid=7 euid=0 suid=0 fsuid=0 egid=7 sgid=7 fsgid=7 tty=(none) ses=4294967295 comm=hp exe=/usr/lib/cups/backend/hp subj=system_u:system_r:cupsd_t:s0-s0:c0.c1023 key=(null) Description of problem: I tried printing to a hplip printer. Additional info: reporter: libreport-2.6.3 hashmarkername: setroubleshoot kernel: 4.2.8-300.fc23.x86_64 type: libreport Description of problem: Probably trying to print to an HP printer I suppose Version-Release number of selected component: selinux-policy-3.13.1-158.fc23.noarch Additional info: reporter: libreport-2.6.3 hashmarkername: setroubleshoot kernel: 4.2.8-300.fc23.x86_64 type: libreport Description of problem: It appears when printing something on a hp envy4500 Version-Release number of selected component: selinux-policy-3.13.1-158.fc23.noarch Additional info: reporter: libreport-2.6.3 hashmarkername: setroubleshoot kernel: 4.2.8-300.fc23.x86_64 type: libreport Hit by the same issue # grep hp /var/log/audit/audit.log | audit2allow #============= cupsd_t ============== allow cupsd_t snmpd_var_lib_t:dir write; hplip-3.15.11-4.fc23.x86_64 net-snmp-libs-5.7.3-7.fc23.x86_64 selinux-policy-3.13.1-158.2.fc23.noarch Printer is also a HP network printer Workaround according to SE troubleshooting UI: # grep hp /var/log/audit/audit.log | audit2allow -M mypol # semodule -i mypol.pp Description of problem: I just printed something! My scenario was the following: in "Firefox", with "Amazon", list of commands, I clicked on "print bill". Okular (from KDE 5) opened, and I clicked on "print", in the menu. The document was printed, but SELinux Alert popped at the same time. Version-Release number of selected component: selinux-policy-3.13.1-158.2.fc23.noarch Additional info: reporter: libreport-2.6.3 hashmarkername: setroubleshoot kernel: 4.3.4-300.fc23.x86_64 type: libreport (In reply to Laurent Rineau from comment #9) > Description of problem: > I just printed something! > > My scenario was the following: > in "Firefox", with "Amazon", list of commands, I clicked on "print bill". > Okular (from KDE 5) opened, and I clicked on "print", in the menu. The > document was printed, but SELinux Alert popped at the same time. > > Version-Release number of selected component: > selinux-policy-3.13.1-158.2.fc23.noarch > > Additional info: > reporter: libreport-2.6.3 > hashmarkername: setroubleshoot > kernel: 4.3.4-300.fc23.x86_64 > type: libreport Also an HP printer. After allowing "write" it also wants "add_name", let see what coming next... allow cupsd_t snmpd_var_lib_t:dir write; allow cupsd_t snmpd_var_lib_t:dir add_name; Description of problem: I installed an HP wireless printer using hp-setup. Now I keep getting SE alerts about it. Version-Release number of selected component: selinux-policy-3.13.1-158.4.fc23.noarch Additional info: reporter: libreport-2.6.4 hashmarkername: setroubleshoot kernel: 4.3.5-300.fc23.x86_64 type: libreport After applying following policy extension, no longer an alert occurs: allow cupsd_t snmpd_var_lib_t:dir { add_name write }; allow cupsd_t snmpd_var_lib_t:file { create write }; commit d94643659af9fc5a1673a32aa24395d10d0243bc Author: Lukas Vrabec <lvrabec> Date: Wed Feb 24 14:14:29 2016 +0100 Allow hplip driver to write to its MIB index files stored in the /var/lib/net-snmp/mib_indexes. Resolves: rhbz#1291033 Description of problem: Printing to a HP printer from Evince Version-Release number of selected component: selinux-policy-3.13.1-158.6.fc23.noarch Additional info: reporter: libreport-2.6.4 hashmarkername: setroubleshoot kernel: 4.3.5-300.fc23.x86_64 type: libreport Description of problem: I was printing a series of documents on my networked HP printer Version-Release number of selected component: selinux-policy-3.13.1-158.7.fc23.noarch Additional info: reporter: libreport-2.6.4 hashmarkername: setroubleshoot kernel: 4.4.2-301.fc23.x86_64 type: libreport selinux-policy-3.13.1-158.9.fc23 has been submitted as an update to Fedora 23. https://bodhi.fedoraproject.org/updates/FEDORA-2016-ffbae3a870 selinux-policy-3.13.1-158.9.fc23 has been pushed to the Fedora 23 testing repository. If problems still persist, please make note of it in this bug report. See https://fedoraproject.org/wiki/QA:Updates_Testing for instructions on how to install test updates. You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2016-ffbae3a870 selinux-policy-3.13.1-158.9.fc23 has been pushed to the Fedora 23 stable repository. If problems still persist, please make note of it in this bug report. |