Note: This is a beta release of Red Hat Bugzilla 5.0. The data contained within is a snapshot of the live data so any changes you make will not be reflected in the production Bugzilla. Also email is disabled so feel free to test any aspect of the site that you want. File any problems you find or give feedback here.
Bug 160743 - libgnomeprint shouldn't use the top level /tmp directory
Summary: libgnomeprint shouldn't use the top level /tmp directory
Alias: None
Product: Fedora
Classification: Fedora
Component: libgnomeprint
Version: rawhide
Hardware: i386
OS: Linux
Target Milestone: ---
Assignee: Matthias Clasen
QA Contact:
Whiteboard: bzcl34nup
Depends On:
TreeView+ depends on / blocked
Reported: 2005-06-17 00:33 UTC by Ivan Gyurdiev
Modified: 2008-04-04 21:07 UTC (History)
2 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Last Closed: 2008-04-04 21:07:22 UTC

Attachments (Terms of Use)

Description Ivan Gyurdiev 2005-06-17 00:33:12 UTC
From Bugzilla Helper:
User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.7.8) Gecko/20050524 Fedora/1.0.4-4 Firefox/1.0.4

Description of problem:
libgnomeprint uses the top level /tmp directory to exchange print information.
I am not sure of the exact process of how this happens, but it creates
problems for SELinux strict policy. I know libgnomecups also makes use
of this directory.

The problem is that we are trying to restrict content flow for certain
untrusted applications, such as evolution, for example. We want to control
whether evolution can read content, or write content, and we also
mark content written by evolution as untrusted, and potentially dangerous
(to protect from hostile content from the web).

To accomplish this, we have designated top level /tmp as a "content" location,
and SELinux automatically transitions applications to a particular type
upon creating files there. 

However, the intent is to regulate whether "content" is saved or loaded
by the application - not internal data. Because SElinux has limited
capabilities, we are not able to distinguish which is which, without
adding SELinux code to the application and/or libgnomeprint, which
we want to avoid if possible.

I suggest that libgnomeprint and libgnomecups be changed
to not save print data to the top level tmp directory.
Instead, they should use a private subdirectory, which we
can label for that purpose. I think it is good design practice
to separate internal program data from user-visible content
when possible - this will make SElinux' job a lot easier.

Ivan Gyurdiev @ Red Hat
SELinux Intern

Version-Release number of selected component (if applicable):

How reproducible:
Didn't try

Additional info:

Comment 1 Bug Zapper 2008-04-03 16:12:40 UTC
Based on the date this bug was created, it appears to have been reported
against rawhide during the development of a Fedora release that is no
longer maintained. In order to refocus our efforts as a project we are
flagging all of the open bugs for releases which are no longer
maintained. If this bug remains in NEEDINFO thirty (30) days from now,
we will automatically close it.

If you can reproduce this bug in a maintained Fedora version (7, 8, or
rawhide), please change this bug to the respective version and change
the status to ASSIGNED. (If you're unable to change the bug's version
or status, add a comment to the bug and someone will change it for you.)

Thanks for your help, and we apologize again that we haven't handled
these issues to this point.

The process we're following is outlined here:

We will be following the process here: to ensure this
doesn't happen again.

Note You need to log in before you can comment on or make changes to this bug.