Bug 2367736

Summary: selinux blocks sending an failure report
Product: [Fedora] Fedora EPEL Reporter: Frank Büttner <bugzilla>
Component: opendmarcAssignee: Kevin Fenzi <kevin>
Status: NEW --- QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: unspecified Docs Contact:
Priority: unspecified    
Version: epel9CC: abo, kevin, mikel
Target Milestone: ---   
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Frank Büttner 2025-05-21 07:29:09 UTC
Description of problem:
When opendmarc needs sending an an failure report, it fails because of selinux


Version-Release number of selected component (if applicable):
opendmarc-1.4.2-29.el9.x86_64


How reproducible:
Receive an mail where the SPF check fails

Actual results:
The report are not send.


Expected results:
That the report is send.


Additional info:
Journal log:
opendmarc[281744]: 4DD79810FDDB: SPF(mailfrom): <DOMAIN> fail
opendmarc[440956]: sendmail: fatal: open /etc/postfix/main.cf: Permission denied
postfix/sendmail[440956]: fatal: open /etc/postfix/main.cf: Permission denied
opendmarc[281744]: 4DD79810FDDB: pclose() exited with status 75
Audit log:
ausearch -m avc  -p 440956
----
time->Tue May 20 10:00:15 2025
type=PROCTITLE msg=audit(1747728015.416:27163): proctitle=2F7573722F7362696E2F73656E646D61696C002D74002D6F6471
type=SYSCALL msg=audit(1747728015.416:27163): arch=c000003e syscall=257 success=no exit=-13 a0=ffffff9c a1=555f548ddad0 a2=0 a3=0 items=0 ppid=281744 pid=440956 auid=4294967295 uid=981 gid=980 euid=981 suid=981 fsuid=981 egid=980 sgid=980 fsgid=980 tty=(none) ses=4294967295 comm="sendmail" exe="/usr/sbin/sendmail.postfix" subj=system_u:system_r:dkim_milter_t:s0 key=(null)
type=AVC msg=audit(1747728015.416:27163): avc:  denied  { search } for  pid=440956 comm="sendmail" name="postfix" dev="dm-0" ino=134779488 scontext=system_u:system_r:dkim_milter_t:s0 tcontext=system_u:object_r:postfix_etc_t:s0 tclass=dir permissive=0