Bug 544263 - SELinux is preventing the foomatic-rip from using potentially mislabeled files (HP-LaserJet-1018.ppd).
Summary: SELinux is preventing the foomatic-rip from using potentially mislabeled file...
Keywords:
Status: CLOSED DUPLICATE of bug 538428
Alias: None
Product: Fedora
Classification: Fedora
Component: selinux-policy
Version: 12
Hardware: i386
OS: Linux
low
medium
Target Milestone: ---
Assignee: Daniel Walsh
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard: setroubleshoot_trace_hash:96d724037e6...
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2009-12-04 12:34 UTC by popmar
Modified: 2009-12-04 13:05 UTC (History)
2 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2009-12-04 13:05:04 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description popmar 2009-12-04 12:34:43 UTC
Sommario:

SELinux is preventing the foomatic-rip from using potentially mislabeled files
(HP-LaserJet-1018.ppd).

Descrizione dettagliata:

SELinux has denied foomatic-rip access to potentially mislabeled file(s)
(HP-LaserJet-1018.ppd). This means that SELinux will not allow foomatic-rip to
use these files. It is common for users to edit files in their home directory or
tmp directories and then move (mv) them to system directories. The problem is
that the files end up with the wrong file context which confined applications
are not allowed to access.

Abilitazione accesso in corso:

If you want foomatic-rip to access this files, you need to relabel them using
restorecon -v 'HP-LaserJet-1018.ppd'. You might want to relabel the entire
directory using restorecon -R -v ''.

Informazioni aggiuntive:

Contesto della sorgente       unconfined_u:system_r:cupsd_t:s0-s0:c0.c1023
Contesto target               system_u:object_r:tmp_t:s0
Oggetti target                HP-LaserJet-1018.ppd [ file ]
Sorgente                      bannertops
Percorso della sorgente       /usr/lib/cups/filter/bannertops
Porta                         <Sconosciuto>
Host                          (removed)
Sorgente Pacchetti RPM        foomatic-4.0.0-2.fc11
Pacchetti RPM target          
RPM della policy              selinux-policy-3.6.12-53.fc11
Selinux abilitato             True
Tipo di policy                targeted
Modalità Enforcing           Enforcing
Nome plugin                   home_tmp_bad_labels
Host Name                     (removed)
Piattaforma                   Linux (removed)
                              2.6.29.5-191.fc11.i686.PAE #1 SMP Tue Jun 16
                              23:19:53 EDT 2009 i686 i686
Conteggio avvisi              3
Primo visto                   dom 28 giu 2009 12:06:27 CEST
Ultimo visto                  dom 28 giu 2009 12:06:27 CEST
ID locale                     1dc086ec-611a-43d5-a2f3-365e7532537f
Numeri di linea               

Messaggi Raw Audit            

node=(removed) type=AVC msg=audit(1246183587.170:42): avc:  denied  { read } for  pid=3531 comm="foomatic-rip" name="HP-LaserJet-1018.ppd" dev=dm-0 ino=122531 scontext=unconfined_u:system_r:cupsd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:tmp_t:s0 tclass=file

node=(removed) type=SYSCALL msg=audit(1246183587.170:42): arch=40000003 syscall=5 success=no exit=-13 a0=902f990 a1=0 a2=1b6 a3=0 items=0 ppid=3525 pid=3531 auid=500 uid=4 gid=7 euid=4 suid=4 fsuid=4 egid=7 sgid=7 fsgid=7 tty=(none) ses=1 comm="foomatic-rip" exe="/usr/bin/foomatic-rip" subj=unconfined_u:system_r:cupsd_t:s0-s0:c0.c1023 key=(null)



Hash String generated from  selinux-policy-3.6.12-53.fc11,home_tmp_bad_labels,bannertops,cupsd_t,tmp_t,file,read
audit2allow suggests:

#============= cupsd_t ==============
allow cupsd_t tmp_t:file read;

Comment 1 Miroslav Grepl 2009-12-04 13:05:04 UTC

*** This bug has been marked as a duplicate of bug 538428 ***


Note You need to log in before you can comment on or make changes to this bug.