On Sun, 2010-09-19 at 11:24 -0400, Marc-André Lévesque wrote:
As for setting selinux to permissive, I didn't bother. I'm sticking to enforcing. I'd rather fix selinux when I'll need a blocked feature than disabling it. For the record, here's the avc:
avc: denied { write } for pid=23972 comm="hp" name=".index" dev=dm-4 ino=1245300 scontext=system_u:system_r:hplip_t:s0-s0:c0.c1023 tcontext=system_u:object_r:snmpd_var_lib_t:s0 tclass=file
It didn't prevent me from printing but I have not tried scanning.
Looks like you can get a lot of AVCs. My guess is it depends on how you installed the printer. The avc above was from a printer installed with hp-setup. But I get a lot more from an old printer entry that I updated its make/model and URI.
MAL