This service will be undergoing maintenance at 00:00 UTC, 2016-08-01. It is expected to last about 1 hours
Bug 120369 - pam_console takes all permissions back on USB mouse [un]plug.
pam_console takes all permissions back on USB mouse [un]plug.
Status: CLOSED WORKSFORME
Product: Fedora
Classification: Fedora
Component: pam (Show other bugs)
rawhide
All Linux
medium Severity high
: ---
: ---
Assigned To: Tomas Mraz
: SELinux
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2004-04-07 23:15 EDT by Aleksey Nogin
Modified: 2007-11-30 17:10 EST (History)
1 user (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2004-10-19 10:02:42 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:


Attachments (Terms of Use)

  None (edit)
Description Aleksey Nogin 2004-04-07 23:15:56 EDT
If I plug or unplug a USB mouse, pam_console changes the ownership on
all devices, setting it back to root.

audit(1081394226.403:0): avc:  denied  { use } for  pid=12026
exe=/sbin/pam_console_apply path=/dev/null dev=hda2 ino=2683571
scontext=system_u:system_r:pam_console_t
tcontext=system_u:system_r:hotplug_t tclass=fd
audit(1081394226.403:0): avc:  denied  { use } for  pid=12026
exe=/sbin/pam_console_apply path=/dev/null dev=hda2 ino=2683571
scontext=system_u:system_r:pam_console_t
tcontext=system_u:system_r:hotplug_t tclass=fd
audit(1081394226.403:0): avc:  denied  { use } for  pid=12026
exe=/sbin/pam_console_apply path=/dev/null dev=hda2 ino=2683571
scontext=system_u:system_r:pam_console_t
tcontext=system_u:system_r:hotplug_t tclass=fd
audit(1081394226.624:0): avc:  denied  { read } for  pid=12026
exe=/sbin/pam_console_apply name=console.lock dev=hda2 ino=179980
scontext=system_u:system_r:pam_console_t
tcontext=system_u:object_r:xdm_var_run_t tclass=file
audit(1081394227.191:0): avc:  denied  { use } for  pid=12028
exe=/sbin/pam_console_apply path=/dev/null dev=hda2 ino=2683571
scontext=system_u:system_r:pam_console_t
tcontext=system_u:system_r:hotplug_t tclass=fd
audit(1081394227.191:0): avc:  denied  { use } for  pid=12028
exe=/sbin/pam_console_apply path=/dev/null dev=hda2 ino=2683571
scontext=system_u:system_r:pam_console_t
tcontext=system_u:system_r:hotplug_t tclass=fd
audit(1081394227.191:0): avc:  denied  { use } for  pid=12028
exe=/sbin/pam_console_apply path=/dev/null dev=hda2 ino=2683571
scontext=system_u:system_r:pam_console_t
tcontext=system_u:system_r:hotplug_t tclass=fd
audit(1081394227.193:0): avc:  denied  { read } for  pid=12028
exe=/sbin/pam_console_apply name=console.lock dev=hda2 ino=179980
scontext=system_u:system_r:pam_console_t
tcontext=system_u:object_r:xdm_var_run_t tclass=file

P.S. This is somewhat related, but different from 119309. What's
interseting is that even for those devices for which pam_console fails
to give permissions on kdm login (see bug 119309), after I change the
ownership manually and then [un]plug the USB mouse, it has no trouble
taking the permissions back...
Comment 1 Aleksey Nogin 2004-04-21 02:50:43 EDT
This was working OK for a while now.

Note You need to log in before you can comment on or make changes to this bug.