Comment 6 for bug 420015

Revision history for this message
Till Kamppeter (till-kamppeter) wrote :

In addition to removing the kernel module, the CUPS "usb" backend needs full access to the /dev/bus/usb/*/* files to get fully functional. The settings in /etc/apparmor.d/usr.sbin.cupsd need to get adapted.

Currently, I get audit messages like that in /var/log/syslog:

Aug 28 13:49:51 till-laptop kernel: [330386.770396] type=1502 audit(1251460191.621:2380): operation="open" pid=3873 parent=3871 profile="/usr/sbin/cupsd" requested_mask="::r" denied_mask="::r" fsuid=7 ouid=0 name="/dev/bus/usb/"
Aug 28 13:49:51 till-laptop kernel: [330386.770437] type=1502 audit(1251460191.621:2381): operation="file_perm" pid=3873 parent=3871 profile="/usr/sbin/cupsd" requested_mask="::r" denied_mask="::r" fsuid=7 ouid=0 name="/dev/bus/usb/"
Aug 28 13:49:51 till-laptop kernel: [330386.770489] type=1502 audit(1251460191.621:2382): operation="open" pid=3873 parent=3871 profile="/usr/sbin/cupsd" requested_mask="::r" denied_mask="::r" fsuid=7 ouid=0 name="/dev/bus/usb/"
Aug 28 13:49:51 till-laptop kernel: [330386.770510] type=1502 audit(1251460191.621:2383): operation="file_perm" pid=3873 parent=3871 profile="/usr/sbin/cupsd" requested_mask="::r" denied_mask="::r" fsuid=7 ouid=0 name="/dev/bus/usb/"
Aug 28 13:49:51 till-laptop kernel: [330386.770567] type=1502 audit(1251460191.621:2384): operation="file_perm" pid=3873 parent=3871 profile="/usr/sbin/cupsd" requested_mask="::r" denied_mask="::r" fsuid=7 ouid=0 name="/dev/bus/usb/"