Couple of devices gone walk-about

Per Bjornsson perbj at stanford.edu
Thu Aug 26 16:44:04 UTC 2004


On Thu, 2004-08-26 at 07:53, Alexandre Strube wrote:
> That's odd... I have three or four machines whose cd recorders are no
> longer working with fedora2. 

Are you sure about that? It might just be that you updated to kernel
2.6.8 (the 2.6.8-1.521 update RPM) which does SCSI command filtering
unless the user has the capability CAP_SYS_RAWIO. This was put in in
order to prevent ordinary users who happen to have direct access - even
read access - to a drive, e.g. a CD drive, from doing dangerous things
like uploading new firmware. It was tossed in rather shortly before the
release of the 2.6.8 kernel and it has been discovered that the command
list that was allowed was not long enough to e.g. allow CD burning.
Check LKML, work is going on to figure out how to do this sanely.

Try burning a CD as root. If that works, it's in all likelihood the
command filtering that has bitten you. The only quick solution I know of
is to roll back to an earlier kernel version or patch out the filtering
in a custom kernel (both of which of course expose the security hole
that this was supposed to fix).

Cheers,
Per

-- 
Per Bjornsson <perbj at stanford.edu>
Ph.D. Candidate, Department of Applied Physics, Stanford University





More information about the fedora-test-list mailing list