Description of problem: SELinux is preventing /usr/lib/cups/backend/cups-pdf from 'write' accesses on the sock_file system_bus_socket. ***** Plugin catchall (100. confidence) suggests ************************** 若您相信 cups-pdf 應該預設允許在 system_bus_socket sock_file 上作 write 存取。 Then 您應將此回報為錯誤。 您可產生本機模組,以允許這項存取。 Do 立刻允許此存取,請執行: # ausearch -c 'cups-pdf' --raw | audit2allow -M my-cupspdf # semodule -X 300 -i my-cupspdf.pp Additional Information: Source Context system_u:system_r:cups_pdf_t:s0-s0:c0.c1023 Target Context system_u:object_r:system_dbusd_var_run_t:s0 Target Objects system_bus_socket [ sock_file ] Source cups-pdf Source Path /usr/lib/cups/backend/cups-pdf Port <未知> Host (removed) Source RPM Packages cups-pdf-3.0.1-3.fc27.x86_64 Target RPM Packages Policy RPM selinux-policy-3.13.1-283.19.fc27.noarch Selinux Enabled True Policy Type targeted Enforcing Mode Enforcing Host Name (removed) Platform Linux (removed) 4.14.11-300.fc27.x86_64 #1 SMP Wed Jan 3 13:52:28 UTC 2018 x86_64 x86_64 Alert Count 2 First Seen 2018-01-08 00:48:23 CST Last Seen 2018-01-08 00:48:23 CST Local ID fdb8ff69-1011-4dcb-a96f-11f68f89d172 Raw Audit Messages type=AVC msg=audit(1515343703.393:321): avc: denied { write } for pid=4975 comm="cups-pdf" name="system_bus_socket" dev="tmpfs" ino=25698 scontext=system_u:system_r:cups_pdf_t:s0-s0:c0.c1023 tcontext=system_u:object_r:system_dbusd_var_run_t:s0 tclass=sock_file permissive=0 type=SYSCALL msg=audit(1515343703.393:321): arch=x86_64 syscall=connect success=no exit=EACCES a0=6 a1=d5b608 a2=21 a3=7ffc72e4bfa0 items=0 ppid=937 pid=4975 auid=4294967295 uid=0 gid=7 euid=0 suid=0 fsuid=0 egid=7 sgid=7 fsgid=7 tty=(none) ses=4294967295 comm=cups-pdf exe=/usr/lib/cups/backend/cups-pdf subj=system_u:system_r:cups_pdf_t:s0-s0:c0.c1023 key=(null) Hash: cups-pdf,cups_pdf_t,system_dbusd_var_run_t,sock_file,write Version-Release number of selected component: selinux-policy-3.13.1-283.19.fc27.noarch Additional info: component: selinux-policy reporter: libreport-2.9.3 hashmarkername: setroubleshoot kernel: 4.14.11-300.fc27.x86_64 type: libreport
selinux-policy-3.13.1-283.26.fc27 has been submitted as an update to Fedora 27. https://bodhi.fedoraproject.org/updates/FEDORA-2018-a9711c96b2
selinux-policy-3.13.1-283.26.fc27 has been pushed to the Fedora 27 testing repository. If problems still persist, please make note of it in this bug report. See https://fedoraproject.org/wiki/QA:Updates_Testing for instructions on how to install test updates. You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2018-a9711c96b2
selinux-policy-3.13.1-283.26.fc27 has been pushed to the Fedora 27 stable repository. If problems still persist, please make note of it in this bug report.