Bug 557913 - SELinux is preventing /usr/bin/pdftops "setattr" access on /var/cache/fontconfig.
Summary: SELinux is preventing /usr/bin/pdftops "setattr" access on /var/cache/fontcon...
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Fedora
Classification: Fedora
Component: selinux-policy
Version: 12
Hardware: i386
OS: Linux
low
medium
Target Milestone: ---
Assignee: Miroslav Grepl
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard: setroubleshoot_trace_hash:465c30feca7...
: 558147 558446 559632 559691 560489 (view as bug list)
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2010-01-22 19:34 UTC by Wojciech Domalewski
Modified: 2010-02-09 18:28 UTC (History)
13 users (show)

Fixed In Version: 3.6.32-78.fc12
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2010-02-02 01:22:36 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Wojciech Domalewski 2010-01-22 19:34:26 UTC
Podsumowanie:

SELinux is preventing /usr/bin/pdftops "setattr" access on
/var/cache/fontconfig.

Szczegółowy opis:

SELinux denied access requested by pdftops. It is not expected that this access
is required by pdftops and this access may signal an intrusion attempt. It is
also possible that the specific version or configuration of the application is
causing it to require additional access.

Zezwalanie na dostęp:

You can generate a local policy module to allow this access - see FAQ
(http://fedora.redhat.com/docs/selinux-faq-fc5/#id2961385) Please file a bug
report.

Dodatkowe informacje:

Kontekst źródłowy          system_u:system_r:cupsd_t:s0-s0:c0.c1023
Kontekst docelowy             system_u:object_r:fonts_cache_t:s0
Obiekty docelowe              /var/cache/fontconfig [ dir ]
Źródło                     pdftops
Ścieżka źródłowa         /usr/bin/pdftops
Port                          <Nieznane>
Komputer                      (removed)
Źródłowe pakiety RPM       poppler-utils-0.12.2-1.fc12
Docelowe pakiety RPM          fontconfig-2.8.0-1.fc12
Pakiet RPM polityki           selinux-policy-3.6.32-69.fc12
SELinux jest włączony       True
Typ polityki                  targeted
Tryb wymuszania               Enforcing
Nazwa wtyczki                 catchall
Nazwa komputera               (removed)
Platforma                     Linux (removed)
                              2.6.31.5-127.fc12.i686 #1 SMP Sat Nov 7 21:41:45
                              EST 2009 i686 athlon
Liczba alarmów               1
Po raz pierwszy               pią, 22 sty 2010, 09:48:35
Po raz ostatni                pią, 22 sty 2010, 09:48:35
Lokalny identyfikator         6998e2c1-a8de-4d78-b823-5e1fbf4135d2
Liczba wierszy                

Surowe komunikaty audytu      

node=(removed) type=AVC msg=audit(1264150115.190:37): avc:  denied  { setattr } for  pid=19178 comm="pdftops" name="fontconfig" dev=dm-0 ino=15770 scontext=system_u:system_r:cupsd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:fonts_cache_t:s0 tclass=dir

node=(removed) type=SYSCALL msg=audit(1264150115.190:37): arch=40000003 syscall=15 success=no exit=-13 a0=a018490 a1=1ed a2=4811a8 a3=a018490 items=0 ppid=19176 pid=19178 auid=4294967295 uid=4 gid=7 euid=4 suid=4 fsuid=4 egid=7 sgid=7 fsgid=7 tty=(none) ses=4294967295 comm="pdftops" exe="/usr/bin/pdftops" subj=system_u:system_r:cupsd_t:s0-s0:c0.c1023 key=(null)



Hash String generated from  selinux-policy-3.6.32-69.fc12,catchall,pdftops,cupsd_t,fonts_cache_t,dir,setattr
audit2allow suggests:

#============= cupsd_t ==============
allow cupsd_t fonts_cache_t:dir setattr;

Comment 1 Daniel Walsh 2010-01-25 15:54:48 UTC
*** Bug 558147 has been marked as a duplicate of this bug. ***

Comment 2 Daniel Walsh 2010-01-25 15:56:41 UTC
Miroslav, rawhide has

miscfiles_setattr_fonts_cache_dirs(cupsd_t)

Comment 3 Miroslav Grepl 2010-01-25 16:36:46 UTC
Fixed in selinux-policy-3.6.32-77.fc12

Comment 4 Miroslav Grepl 2010-01-26 13:23:49 UTC
*** Bug 558446 has been marked as a duplicate of this bug. ***

Comment 5 Fedora Update System 2010-01-28 09:23:03 UTC
selinux-policy-3.6.32-78.fc12 has been submitted as an update for Fedora 12.
http://admin.fedoraproject.org/updates/selinux-policy-3.6.32-78.fc12

Comment 6 Miroslav Grepl 2010-01-28 16:38:11 UTC
*** Bug 559632 has been marked as a duplicate of this bug. ***

Comment 7 Daniel Walsh 2010-01-28 18:51:10 UTC
*** Bug 559691 has been marked as a duplicate of this bug. ***

Comment 8 Fedora Update System 2010-01-29 03:28:19 UTC
selinux-policy-3.6.32-78.fc12 has been pushed to the Fedora 12 testing repository.  If problems still persist, please make note of it in this bug report.
 If you want to test the update, you can install it with 
 su -c 'yum --enablerepo=updates-testing update selinux-policy'.  You can provide feedback for this update here: http://admin.fedoraproject.org/updates/F12/FEDORA-2010-1207

Comment 9 Miroslav Grepl 2010-02-01 15:38:45 UTC
*** Bug 560489 has been marked as a duplicate of this bug. ***

Comment 10 Fedora Update System 2010-02-02 01:20:24 UTC
selinux-policy-3.6.32-78.fc12 has been pushed to the Fedora 12 stable repository.  If problems still persist, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.