Bug 160292

Summary: avc denied cups-lpd
Product: [Fedora] Fedora Reporter: Iain Arnell <iarnell>
Component: selinux-policy-targetedAssignee: Daniel Walsh <dwalsh>
Status: CLOSED CURRENTRELEASE QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: 4CC: arequipeno, rcoker, twaugh, zing
Target Milestone: ---   
Target Release: ---   
Hardware: i386   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2005-06-27 11:17:33 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Iain Arnell 2005-06-14 07:48:38 UTC
From Bugzilla Helper:
User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.7.8) Gecko/20050524 Fedora/1.0.4-4 Firefox/1.0.4

Description of problem:
cups-lpd is not working.

audit.log shows:

type=SYSCALL msg=audit(1118734940.160:1361988): arch=40000003 syscall=11 success=yes exit=0 a0=948b438 a1=9486690 a2=9486f08 a3=bf912b34 items=2 pid=3199 auid=4294967295 uid=4 gid=7 euid=4 suid=4 fsuid=4 egid=7 sgid=7 fsgid=7 comm="cups-lpd" exe="/usr/lib/cups/daemon/cups-lpd"
type=AVC msg=audit(1118734940.160:1361988): avc:  denied  { read write } for  pid=3199 comm="cups-lpd" name=[16136] dev=sockfs ino=16136 scontext=system_u:system_r:cupsd_t tcontext=system_u:system_r:inetd_t tclass=tcp_socket
type=AVC msg=audit(1118734940.160:1361988): avc:  denied  { read write } for  pid=3199 comm="cups-lpd" name=[16136] dev=sockfs ino=16136 scontext=system_u:system_r:cupsd_t tcontext=system_u:system_r:inetd_t tclass=tcp_socket
type=AVC msg=audit(1118734940.160:1361988): avc:  denied  { read write } for  pid=3199 comm="cups-lpd" name=[16136] dev=sockfs ino=16136 scontext=system_u:system_r:cupsd_t tcontext=system_u:system_r:inetd_t tclass=tcp_socket

Version-Release number of selected component (if applicable):
selinux-policy-targeted-1.23.16-6

How reproducible:
Always

Steps to Reproduce:
1. Installed cups-lpd-1.1.23-15 (and xinetd-2.3.13-6)
2. configured a printer, shared it and enabled lpd (using system-config-printer)
3. rebooted
4. tail /var/log/audit.log

Additional info:

Comment 2 Daniel Walsh 2005-06-26 11:38:45 UTC
fixed in selinux-policy-targeted-1.23.18-12

Comment 3 Iain Arnell 2005-06-27 06:10:46 UTC
Confirming - selinux-policy-targeted-1.23.18-12 solves the problem.