Bug 523408
Summary: | SELinux is preventing spamd (spamd_t) "read" to identity (spamd_var_lib_t). | ||
---|---|---|---|
Product: | [Fedora] Fedora | Reporter: | Carlos Miguel Sousa Almeida <cmsa> |
Component: | selinux-policy | Assignee: | Miroslav Grepl <mgrepl> |
Status: | CLOSED ERRATA | QA Contact: | Fedora Extras Quality Assurance <extras-qa> |
Severity: | urgent | Docs Contact: | |
Priority: | low | ||
Version: | 10 | CC: | dwalsh, jkubin, mgrepl |
Target Milestone: | --- | ||
Target Release: | --- | ||
Hardware: | i686 | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | 3.5.13-72.fc10 | Doc Type: | Bug Fix |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2009-10-14 01:34:58 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: |
Description
Carlos Miguel Sousa Almeida
2009-09-15 11:47:28 UTC
I have never seen this before, but I see no reason to block it. Miroslav, add manage_lnk_files_pattern(spamd_t, spamd_var_lib_t, spamd_var_lib_t) To F10 and F11 Added to selinux-policy-3.6.12-83.fc11.noarch Fixed in selinux-policy-3.5.13-72.fc10 selinux-policy-3.5.13-72.fc10 has been submitted as an update for Fedora 10. http://admin.fedoraproject.org/updates/selinux-policy-3.5.13-72.fc10 selinux-policy-3.5.13-72.fc10 has been pushed to the Fedora 10 testing repository. If problems still persist, please make note of it in this bug report. If you want to test the update, you can install it with su -c 'yum --enablerepo=updates-testing update selinux-policy'. You can provide feedback for this update here: http://admin.fedoraproject.org/updates/F10/FEDORA-2009-9808 I run yum --enablerepo=updates-testing update selinux-policy, so i have one installed. I still get: SELinux is preventing imapd (cyrus_t) "search" to ./mail (etc_mail_t). node=colegioinfanta.homelinux.com type=AVC msg=audit(1254310632.472:315): avc: denied { search } for pid=6740 comm="imapd" name="mail" dev=dm-0 ino=1958705 scontext=system_u:system_r:cyrus_t:s0 tcontext=system_u:object_r:etc_mail_t:s0 tclass=dir node=colegioinfanta.homelinux.com type=SYSCALL msg=audit(1254310632.472:315): arch=40000003 syscall=5 success=no exit=-13 a0=11f5f38 a1=8000 a2=1b6 a3=0 items=0 ppid=3042 pid=6740 auid=4294967295 uid=76 gid=12 euid=76 suid=76 fsuid=76 egid=12 sgid=12 fsgid=12 tty=(none) ses=4294967295 comm="imapd" exe="/usr/lib/cyrus-imapd/imapd" subj=system_u:system_r:cyrus_t:s0 key=(null) And: SELinux is preventing spamd (spamd_t) "read" to identity (spamd_var_lib_t). node=colegioinfanta.homelinux.com type=AVC msg=audit(1254310636.411:316): avc: denied { read } for pid=6765 comm="spamd" name="identity" dev=dm-0 ino=4169986 scontext=unconfined_u:system_r:spamd_t:s0 tcontext=system_u:object_r:spamd_var_lib_t:s0 tclass=lnk_file node=colegioinfanta.homelinux.com type=SYSCALL msg=audit(1254310636.411:316): arch=40000003 syscall=85 success=yes exit=19 a0=a554474 a1=bff2a4b8 a2=fff a3=98d850c items=0 ppid=1 pid=6765 auid=50000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=12 comm="spamd" exe="/usr/bin/perl" subj=unconfined_u:system_r:spamd_t:s0 key=(null) Ohh! and I did a startup with relabeling active. So selinux did a relabeling of entire file system. You also need to update selinux-policy-targeted package. Execute yum --enablerepo=updates-testing update selinux-policy-targeted selinux-policy-3.5.13-72.fc10 has been pushed to the Fedora 10 stable repository. If problems still persist, please make note of it in this bug report. |