Bug 886036

Summary: AVC produced during installation: comm="sendmail" path="/var/lib/nocpulse/.forward" dev=... ino=... scontext=system_u:system_r:sendmail_t:s0 tcontext=system_u:object_r:var_lib_t:s0 tclass=file
Product: Red Hat Satellite 5 Reporter: Jan Hutař <jhutar>
Component: MonitoringAssignee: Milan Zázrivec <mzazrivec>
Status: CLOSED DEFERRED QA Contact: Red Hat Satellite QA List <satqe-list>
Severity: low Docs Contact:
Priority: low    
Version: 550CC: cperry
Target Milestone: ---   
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2015-05-29 20:11:55 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 462714    

Description Jan Hutař 2012-12-11 11:36:12 UTC
Description of problem:
AVC message appears from time to time when installing Satellite 5.4.1 about sendmail reaching "/var/lib/nocpulse/.forward" file.


Version-Release number of selected component (if applicable):
nocpulse-common-2.1.19-4.el6sat.noarch
libselinux-2.0.94-5.3.el6.x86_64
spacewalk-selinux-1.2.1-5.el6sat.noarch
selinux-policy-targeted-3.7.19-155.el6_3.8.noarch
spacewalk-monitoring-selinux-1.1.1-3.el6sat.noarch
selinux-policy-3.7.19-155.el6_3.8.noarch


How reproducible:
it is very rare


Steps to Reproduce:
1. Install Satellite 5.4.1 with embedded DB


Actual results:
time->Mon Dec 10 15:45:02 2012
type=SYSCALL msg=audit(1355172302.712:108): arch=c000003e syscall=4 success=no exit=-13 a0=7fff782f8150 a1=7fff782f9210 a2=7fff782f9210 a3=8 items=0 ppid=4940 pid=4941 auid=4294967295 uid=0 gid=497 euid=497 suid=497 fsuid=497 egid=497 sgid=497 fsgid=497 tty=(none) ses=4294967295 comm="sendmail" exe="/usr/sbin/sendmail.sendmail" subj=system_u:system_r:sendmail_t:s0 key=(null)
type=AVC msg=audit(1355172302.712:108): avc:  denied  { getattr } for  pid=4941 comm="sendmail" path="/var/lib/nocpulse/.forward" dev=dm-0 ino=788563 scontext=system_u:system_r:sendmail_t:s0 tcontext=system_u:object_r:var_lib_t:s0 tclass=file


Expected results:
No AVCs reported


Additional info:
I know this might be a candidate to NOTABUG as it is rare and without exact reproducer.