Bug 442191

Summary: selinux errors
Product: [Fedora] Fedora Reporter: Need Real Name <lsof>
Component: hal-cups-utilsAssignee: Tim Waugh <twaugh>
Status: CLOSED CURRENTRELEASE QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: low Docs Contact:
Priority: low    
Version: 9CC: alskn3, ctubbsii, olenb
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: 0.6.16-4.fc9 Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2008-05-17 22:18:19 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Need Real Name 2008-04-12 15:37:43 UTC
These are from permissive mode..

host=box type=AVC msg=audit(1208014311.144:206): avc: denied { getattr } for
pid=10086 comm="python" path="pipe:[43449]" dev=pipefs ino=43449
scontext=system_u:system_r:hplip_t:s0 tcontext=system_u:system_r:hald_t:s0
tclass=fifo_file 

host=box type=SYSCALL msg=audit(1208014311.144:206): arch=40000003 syscall=197
success=yes exit=0 a0=0 a1=bff0e398 a2=6d3ff4 a3=6d483c items=0 ppid=10085
pid=10086 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0
fsgid=0 tty=(none) ses=4294967295 comm="python" exe="/usr/bin/python"
subj=system_u:system_r:hplip_t:s0 key=(null) 

host=box type=AVC msg=audit(1208014311.142:205): avc: denied { ioctl } for
pid=10086 comm="python" path="pipe:[43449]" dev=pipefs ino=43449
scontext=system_u:system_r:hplip_t:s0 tcontext=system_u:system_r:hald_t:s0
tclass=fifo_file

host=box type=SYSCALL msg=audit(1208014311.142:205): arch=40000003 syscall=54
success=no exit=-22 a0=0 a1=5401 a2=bff0e3b8 a3=bff0e3f8 items=0 ppid=10085
pid=10086 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0
fsgid=0 tty=(none) ses=4294967295 comm="python" exe="/usr/bin/python"
subj=system_u:system_r:hplip_t:s0 key=(null) 

host=box type=AVC msg=audit(1208014311.140:204): avc: denied { read } for
pid=10086 comm="hp-makeuri" path="pipe:[43449]" dev=pipefs ino=43449
scontext=system_u:system_r:hplip_t:s0 tcontext=system_u:system_r:hald_t:s0
tclass=fifo_file

host=box type=SYSCALL msg=audit(1208014311.140:204): arch=40000003 syscall=11
success=yes exit=0 a0=a0a9898 a1=a0a8540 a2=a0a9a18 a3=0 items=0 ppid=10085
pid=10086 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0
fsgid=0 tty=(none) ses=4294967295 comm="hp-makeuri" exe="/bin/env"
subj=system_u:system_r:hplip_t:s0 key=(null)

Comment 1 Tim Waugh 2008-04-14 15:38:21 UTC
Please provide more information:

rpm -q hplip
rpm -q hal-cups-utils
rpm -q selinux-policy
Are you able to cause this to happen?  If so, how?

Comment 2 Need Real Name 2008-04-14 16:11:09 UTC
$ rpm -q hplip hal-cups-utils selinux-policy
hplip-2.8.2-2.fc9.i386
hal-cups-utils-0.6.16-3.fc9.i386
selinux-policy-3.3.1-33.fc9.noarch

I don't remember what caused it. I think the "low ink" warning might have
triggered it..

Comment 3 Need Real Name 2008-04-16 20:21:21 UTC
I just printed an e-mail from evolution, and I get this:

host=box type=AVC msg=audit(1208374373.271:180): avc: denied { read } for
pid=9354 comm="hp-makeuri" path="pipe:[32693]" dev=pipefs ino=32693
scontext=system_u:system_r:hplip_t:s0 tcontext=system_u:system_r:hald_t:s0
tclass=fifo_file host=box type=SYSCALL msg=audit(1208374373.271:180):
arch=40000003 syscall=11 success=yes exit=0 a0=890c898 a1=890b540 a2=890ca18
a3=0 items=0 ppid=9353 pid=9354 auid=4294967295 uid=0 gid=0 euid=0 suid=0
fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="hp-makeuri"
exe="/bin/env" subj=system_u:system_r:hplip_t:s0 key=(null) 

Comment 4 Tim Waugh 2008-04-21 14:03:37 UTC
Oh, it's rawhide.  Fixing version.

What does 'ls -Z /usr/libexec/hal_lpadmin' say?

Comment 5 Need Real Name 2008-04-21 16:17:58 UTC
rwxr-xr-x  root root system_u:object_r:cupsd_config_exec_t /usr/libexe/hal_lpadmin


Comment 6 Tim Waugh 2008-05-12 12:26:39 UTC
*** Bug 445780 has been marked as a duplicate of this bug. ***

Comment 7 Tim Waugh 2008-05-12 12:30:47 UTC
Could you please try running the trouble-shooter
(System->Administration->Printing, then select Help->Troubleshoot from the menu
bar) and paste in the diagnostic text you get here?  Thanks.

Comment 8 Tim Waugh 2008-05-12 14:29:57 UTC
*** Bug 446052 has been marked as a duplicate of this bug. ***

Comment 9 Tim Waugh 2008-05-12 14:35:48 UTC
Oh, never mind, problem understood now.

Comment 10 Fedora Update System 2008-05-12 15:15:13 UTC
hal-cups-utils-0.6.16-4.fc9 has been submitted as an update for Fedora 9

Comment 11 Fedora Update System 2008-05-13 15:20:05 UTC
hal-cups-utils-0.6.16-4.fc9 has been pushed to the Fedora 9 testing repository.  If problems still persist, please make note of it in this bug report.
 If you want to test the update, you can install it with 
 su -c 'yum --enablerepo=updates-testing update hal-cups-utils'.  You can provide feedback for this update here: http://admin.fedoraproject.org/updates/F9/FEDORA-2008-3652

Comment 12 Bug Zapper 2008-05-14 09:21:21 UTC
Changing version to '9' as part of upcoming Fedora 9 GA.
More information and reason for this action is here:
http://fedoraproject.org/wiki/BugZappers/HouseKeeping

Comment 13 Tim Waugh 2008-05-16 09:41:42 UTC
Works for me.

Comment 14 Fedora Update System 2008-05-17 22:18:15 UTC
hal-cups-utils-0.6.16-4.fc9 has been pushed to the Fedora 9 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 15 Tim Waugh 2008-05-28 09:46:39 UTC
*** Bug 447433 has been marked as a duplicate of this bug. ***