Bug 120369 - pam_console takes all permissions back on USB mouse [un]plug.
Summary: pam_console takes all permissions back on USB mouse [un]plug.
Status: CLOSED WORKSFORME
Alias: None
Product: Fedora
Classification: Fedora
Component: pam (Show other bugs)
(Show other bugs)
Version: rawhide
Hardware: All Linux
medium
high
Target Milestone: ---
Assignee: Tomas Mraz
QA Contact:
URL:
Whiteboard:
Keywords: SELinux
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2004-04-08 03:15 UTC by Aleksey Nogin
Modified: 2007-11-30 22:10 UTC (History)
1 user (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2004-10-19 14:02:42 UTC
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

Description Aleksey Nogin 2004-04-08 03:15:56 UTC
If I plug or unplug a USB mouse, pam_console changes the ownership on
all devices, setting it back to root.

audit(1081394226.403:0): avc:  denied  { use } for  pid=12026
exe=/sbin/pam_console_apply path=/dev/null dev=hda2 ino=2683571
scontext=system_u:system_r:pam_console_t
tcontext=system_u:system_r:hotplug_t tclass=fd
audit(1081394226.403:0): avc:  denied  { use } for  pid=12026
exe=/sbin/pam_console_apply path=/dev/null dev=hda2 ino=2683571
scontext=system_u:system_r:pam_console_t
tcontext=system_u:system_r:hotplug_t tclass=fd
audit(1081394226.403:0): avc:  denied  { use } for  pid=12026
exe=/sbin/pam_console_apply path=/dev/null dev=hda2 ino=2683571
scontext=system_u:system_r:pam_console_t
tcontext=system_u:system_r:hotplug_t tclass=fd
audit(1081394226.624:0): avc:  denied  { read } for  pid=12026
exe=/sbin/pam_console_apply name=console.lock dev=hda2 ino=179980
scontext=system_u:system_r:pam_console_t
tcontext=system_u:object_r:xdm_var_run_t tclass=file
audit(1081394227.191:0): avc:  denied  { use } for  pid=12028
exe=/sbin/pam_console_apply path=/dev/null dev=hda2 ino=2683571
scontext=system_u:system_r:pam_console_t
tcontext=system_u:system_r:hotplug_t tclass=fd
audit(1081394227.191:0): avc:  denied  { use } for  pid=12028
exe=/sbin/pam_console_apply path=/dev/null dev=hda2 ino=2683571
scontext=system_u:system_r:pam_console_t
tcontext=system_u:system_r:hotplug_t tclass=fd
audit(1081394227.191:0): avc:  denied  { use } for  pid=12028
exe=/sbin/pam_console_apply path=/dev/null dev=hda2 ino=2683571
scontext=system_u:system_r:pam_console_t
tcontext=system_u:system_r:hotplug_t tclass=fd
audit(1081394227.193:0): avc:  denied  { read } for  pid=12028
exe=/sbin/pam_console_apply name=console.lock dev=hda2 ino=179980
scontext=system_u:system_r:pam_console_t
tcontext=system_u:object_r:xdm_var_run_t tclass=file

P.S. This is somewhat related, but different from 119309. What's
interseting is that even for those devices for which pam_console fails
to give permissions on kdm login (see bug 119309), after I change the
ownership manually and then [un]plug the USB mouse, it has no trouble
taking the permissions back...

Comment 1 Aleksey Nogin 2004-04-21 06:50:43 UTC
This was working OK for a while now.


Note You need to log in before you can comment on or make changes to this bug.