Running strict/enforcing, w/USB printer. Reconnecting printer (after pulling the plug) yields the following: Sep 25 18:46:47 fedora kernel: audit(1096163207.182:0): avc: denied { search } for pid=7592 exe=/usr/sbin/hal_lpadmin name=cups dev=hda2 ino=4474131 scontext=system_u:system_r:hald_t tcontext=system_u:object_r:cupsd_etc_t tclass=dir Sep 25 18:46:48 fedora kernel: audit(1096163208.050:0): avc: denied { read } for pid=7593 exe=/usr/bin/python name=printconf_tui.py dev=hda2 ino=4309021 scontext=system_u:system_r:hald_t tcontext=system_u:object_r:printconf_t tclass=file Sep 25 18:46:48 fedora kernel: audit(1096163208.050:0): avc: denied { getattr } for pid=7593 exe=/usr/bin/python path=/usr/share/printconf/util/printconf_tui.py dev=hda2 ino=4309021 scontext=system_u:system_r:hald_t tcontext=system_u:object_r:printconf_t tclass=file Sep 25 18:46:49 fedora kernel: audit(1096163209.538:0): avc: denied { read } for pid=7595 exe=/usr/bin/perl name=urandom dev=tmpfs ino=965 scontext=system_u:system_r:hald_t tcontext=system_u:object_r:urandom_device_t tclass=chr_file Attached patch to cups.te adds allow rules for these. Please correct/edit/etc. tom -- Tom London
Attachment:
diff-cups
Description: Binary data