cups avcs....

Daniel J Walsh dwalsh at redhat.com
Tue Apr 12 02:31:05 UTC 2005


Tom London wrote:

>Running targeted/enforcing, latest rawhide.
>
>Just noticed the following in the log:
>
>Apr 11 17:40:22 localhost kernel: audit(1113266422.034:0): avc: 
>denied  { search } for  pid=2553 exe=/usr/sbin/cupsd name=dbus
>dev=dm-0 ino=2142154 scontext=user_u:system_r:cupsd_t
>tcontext=system_u:object_r:system_dbusd_var_run_t tclass=dir
>Apr 11 17:40:22 localhost kernel: audit(1113266422.291:0): avc: 
>denied  { search } for  pid=2553 exe=/usr/sbin/cupsd name=dbus
>dev=dm-0 ino=2142154 scontext=user_u:system_r:cupsd_t
>tcontext=system_u:object_r:system_dbusd_var_run_t tclass=dir
>Apr 11 17:40:22 localhost kernel: audit(1113266422.295:0): avc: 
>denied  { search } for  pid=2553 exe=/usr/sbin/cupsd name=dbus
>dev=dm-0 ino=2142154 scontext=user_u:system_r:cupsd_t
>tcontext=system_u:object_r:system_dbusd_var_run_t tclass=dir
>Apr 11 17:40:22 localhost kernel: audit(1113266422.709:0): avc: 
>denied  { search } for  pid=2561 exe=/usr/lib/cups/backend/hal
>name=dbus dev=dm-0 ino=2142154 scontext=user_u:system_r:cupsd_t
>tcontext=system_u:object_r:system_dbusd_var_run_t tclass=dir
>
>or
>allow cupsd_t system_dbusd_var_run_t:dir search;
>
>Did something change?
>
>tom
>  
>
This is strange I look at my policy sources

allow { cupsd_t } { var_run_t system_dbusd_var_run_t }:dir search;

Are you running the latest policy?

Dan

-- 





More information about the fedora-selinux-list mailing list