logo       

Choosing A Webhost:
A web hosting service is a type of Internet hosting service that allows individuals and organizations to provide their own website accessible via the World Wide Web. Web hosts are companies that provide space on a server they own for use by their clients as well as providing Internet connectivity, typically in a data center. Web hosts can also provide data center space and connectivity to the Internet for servers they do not own to be located in their data center, called colocation. more...

Re: hald - r/w access to /dev/usb/lp0?: msg#00148

Subject: Re: hald - r/w access to /dev/usb/lp0?
Understand and agree about read access, but  the AVC 
shows it wanting write access as well.

Your patch allows read/getattr/ioctl. but not write. I can certainly
imagine a dialog protocol that would require both read and write,
but I'm not certain if this is in fact used here.

What do you think?
   tom


On Sun, 26 Sep 2004 05:34:51 +1000, Russell Coker <russell@xxxxxxxxxxxx> wrote:
> On Sun, 26 Sep 2004 04:27, Tom London <selinux@xxxxxxxxx> wrote:
> > When haldaemon starts, and typically just after the text 'login:'
> > appears but before the graphical stuff takes over, I get:
> >
> > Sep 25 10:28:57 fedora kernel: audit(1096133337.944:0): avc:  denied
> > { read write } for  pid=3187 exe=/usr/sbin/hald name=lp0 dev=tmpfs
> > ino=5073 scontext=system_u:system_r:hald_t
> > tcontext=system_u:object_r:printer_device_t tclass=chr_file
> >
> > referring to /dev/usb/lp0.
> >
> > Does hald need read/write access to the printer_device?
> 
> Does hald need it right now?  Probably, but I'm not sure.
> 
> Will it need such access in the future to perform the tasks that it is
> designed for?  Definitely!  There is a lot of variation among printer
> hardware and hald is the correct program to inform you of what type of
> printer you have just connected.  I've attached a patch to add the access.
> 
> --
> http://www.coker.com.au/selinux/   My NSA Security Enhanced Linux packages
> http://www.coker.com.au/bonnie++/  Bonnie++ hard drive benchmark
> http://www.coker.com.au/postal/    Postal SMTP/POP benchmark
> http://www.coker.com.au/~russell/  My home page
> 
> 
> 
> 



-- 
Tom London


<Prev in Thread] Current Thread [Next in Thread>
Google Custom Search

Recently Viewed:
qnx.openqnx.dev...    gcc.libstdc++.c...    solaris.opensol...    information-ret...    misc.misterhous...    web.catalyst.ge...    apache.webservi...    redhat.release....    hardware.lirc/2...    kernel.autofs/2...    technology.sust...    linux.vdr/2003-...    editors.lyx.gen...    org.user-groups...    netbsd.devel.pk...    xdg.devel/2004-...    version-control...    jakarta.slide.d...    debian.packages...    creativecommons...    ports.ppc.embed...    bug-tracking.bu...   
Home | blog view | USPTO Patent Archive | advertise | OSDir is an inevitable website. super tiny logo

Free Magazines

Cisco News
Receive a free quarterly e-newsletter with exclusive articles on how Cisco IT uses its own products and solutions to enable the business.
subscribe

Systems Management News, the newspaper for IT systems administration and data center managers! Each issue of Systems Management News is chock-full of news and analysis to help you understand what's happening in your field.
subscribe

The Enterprise Newsweekly eWeek is the essential technology information source for builders of e-business.
subscribe

Oracle Magazine Oracle Magazine contains technology strategy articles, sample code, tips, Oracle and partner news, how to articles for developers and DBAs, and more. Oracle (NASDAQ: ORCL) is the world's largest enterprise software company.
subscribe

Total Telecom Total Telecom is "The Economist of the communications industry".
subscribe

Navigation