SELinux is preventing cups hp backend from starting.

Jim Hayward jimhayward at earthlink.net
Sat Sep 22 18:50:00 UTC 2007


Hi All,

The last problem I reported is fixed now. But SELinux is now preventing
the hp backend from starting. selinux-policy-targeted-3.0.8-8.fc8

I see this in the cups error log...

E [22/Sep/2007:11:20:05 -0700] Unable to
execute /usr/lib/cups/backend/hp: Permission denied
E [22/Sep/2007:11:20:05 -0700] [Job 15] Unable to start backend "hp" -
Permission denied.

And I see this avc messages..

SELinux is preventing /usr/sbin/cupsd (cupsd_t) "getattr"
to /usr/lib/cups/backend/hp (hplip_exec_t).

avc: denied { getattr } for comm=cupsd dev=sda2 egid=0 euid=0
exe=/usr/sbin/cupsd exit=0 fsgid=0 fsuid=0 gid=0 items=0
path=/usr/lib/cups/backend/hp pid=3454
scontext=system_u:system_r:cupsd_t:s0-s0:c0.c1023 sgid=0
subj=system_u:system_r:cupsd_t:s0-s0:c0.c1023 suid=0 tclass=file
tcontext=system_u:object_r:hplip_exec_t:s0 tty=(none) uid=0

SELinux is preventing /usr/sbin/cupsd (cupsd_t) "execute" to hp
(hplip_exec_t).

avc: denied { execute } for comm=cupsd dev=sda2 egid=0 euid=0
exe=/usr/sbin/cupsd exit=0 fsgid=0 fsuid=0 gid=0 items=0 name=hp
pid=3454 scontext=system_u:system_r:cupsd_t:s0-s0:c0.c1023 sgid=0
subj=system_u:system_r:cupsd_t:s0-s0:c0.c1023 suid=0 tclass=file
tcontext=system_u:object_r:hplip_exec_t:s0 tty=(none) uid=0 

SELinux is preventing /usr/lib/cups/backend/hp (cupsd_t)
"execute_no_trans" to /usr/lib/cups/backend/hp (hplip_exec_t).

avc: denied { execute_no_trans } for comm=hp dev=sda2 egid=7 euid=4
exe=/usr/lib/cups/backend/hp exit=0 fsgid=7 fsuid=4 gid=7 items=0
path=/usr/lib/cups/backend/hp pid=3459
scontext=system_u:system_r:cupsd_t:s0-s0:c0.c1023 sgid=7
subj=system_u:system_r:cupsd_t:s0-s0:c0.c1023 suid=4 tclass=file
tcontext=system_u:object_r:hplip_exec_t:s0 tty=(none) uid=4 

and these might be related...

SELinux is preventing python (cupsd_config_t) "read write" to 001
(usb_device_t).

avc: denied { read, write } for comm=python dev=tmpfs name=001 pid=2695
scontext=system_u:system_r:cupsd_config_t:s0 tclass=chr_file
tcontext=system_u:object_r:usb_device_t:s0 

SELinux is preventing python (cupsd_config_t) "read" to 001
(usb_device_t)

avc: denied { read } for comm=python dev=tmpfs name=001 pid=2695
scontext=system_u:system_r:cupsd_config_t:s0 tclass=chr_file
tcontext=system_u:object_r:usb_device_t:s0 

SELinux is preventing python (cupsd_config_t) "read write" to 002
(usb_device_t).

avc: denied { read, write } for comm=python dev=tmpfs name=002 pid=2695
scontext=system_u:system_r:cupsd_config_t:s0 tclass=chr_file
tcontext=system_u:object_r:usb_device_t:s0 

SELinux is preventing python (cupsd_config_t) "read" to 002
(usb_device_t).

avc: denied { read } for comm=python dev=tmpfs egid=0 euid=0
exe=/usr/bin/python exit=-13 fsgid=0 fsuid=0 gid=0 items=0 name=002
pid=2695 scontext=system_u:system_r:cupsd_config_t:s0 sgid=0
subj=system_u:system_r:cupsd_config_t:s0 suid=0 tclass=chr_file
tcontext=system_u:object_r:usb_device_t:s0 tty=(none) uid=0 

SELinux is preventing python (cupsd_config_t) "read write" to 003
(usb_device_t)

avc: denied { read, write } for comm=python dev=tmpfs name=003 pid=2695
scontext=system_u:system_r:cupsd_config_t:s0 tclass=chr_file
tcontext=system_u:object_r:usb_device_t:s0


Regards,
	Jim H
-- 
Jim Hayward <jimhayward at earthlink.net>
GPG Key available at: http://keyserver.noreply.org
gpg --recv-keys --keyserver keyserver.noreply.org 0x85A92DCC
GPG Fingerprint: 1AA9 AEC9 BFDF FF7A E4F8 90C7 4947 3A41 85A9 2DCC 
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 189 bytes
Desc: This is a digitally signed message part
URL: <http://listman.redhat.com/archives/fedora-test-list/attachments/20070922/86a9c1f1/attachment.sig>


More information about the fedora-test-list mailing list