Note: This bug is displayed in read-only format because the product is no longer active in Red Hat Bugzilla.
RHEL Engineering is moving the tracking of its product development work on RHEL 6 through RHEL 9 to Red Hat Jira (issues.redhat.com). If you're a Red Hat customer, please continue to file support cases via the Red Hat customer portal. If you're not, please head to the "RHEL project" in Red Hat Jira and file new tickets here. Individual Bugzilla bugs in the statuses "NEW", "ASSIGNED", and "POST" are being migrated throughout September 2023. Bugs of Red Hat partners with an assigned Engineering Partner Manager (EPM) are migrated in late September as per pre-agreed dates. Bugs against components "kernel", "kernel-rt", and "kpatch" are only migrated if still in "NEW" or "ASSIGNED". If you cannot log in to RH Jira, please consult article #7032570. That failing, please send an e-mail to the RH Jira admins at rh-issues@redhat.com to troubleshoot your issue as a user management inquiry. The email creates a ServiceNow ticket with Red Hat. Individual Bugzilla bugs that are migrated will be moved to status "CLOSED", resolution "MIGRATED", and set with "MigratedToJIRA" in "Keywords". The link to the successor Jira issue will be found under "Links", have a little "two-footprint" icon next to it, and direct you to the "RHEL project" in Red Hat Jira (issue links are of type "https://issues.redhat.com/browse/RHEL-XXXX", where "X" is a digit). This same link will be available in a blue banner at the top of the page informing you that that bug has been migrated.

Bug 1061159

Summary: SELinux prevents /usr/libexec/postfix/local from searching in /var/lib/pcp directory
Product: Red Hat Enterprise Linux 7 Reporter: Jeff Bastian <jbastian>
Component: selinux-policyAssignee: Miroslav Grepl <mgrepl>
Status: CLOSED CURRENTRELEASE QA Contact: Milos Malik <mmalik>
Severity: medium Docs Contact:
Priority: medium    
Version: 7.0CC: jbastian, mmalik
Target Milestone: rcKeywords: Reopened
Target Release: ---   
Hardware: x86_64   
OS: Linux   
Whiteboard: abrt_hash:c8e34f69293e5acf79e2e3d089c10d67353429cbd4a6c3567b28fb53bb5429c4
Fixed In Version: selinux-policy-3.12.1-126.el7 Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2014-06-13 09:35:37 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Jeff Bastian 2014-02-04 13:08:07 UTC
Description of problem:
I'm not really sure what happened.  Postfix ran shortly after midnight (via cron? or just as a daemon?) and tried to search /var/lib/pcp and SELinux blocked it.
SELinux is preventing /usr/libexec/postfix/local from 'search' accesses on the directory .

*****  Plugin catchall (100. confidence) suggests   **************************

If you believe that local should be allowed search access on the  directory by default.
Then you should report this as a bug.
You can generate a local policy module to allow this access.
Do
allow this access for now by executing:
# grep local /var/log/audit/audit.log | audit2allow -M mypol
# semodule -i mypol.pp

Additional Information:
Source Context                system_u:system_r:postfix_local_t:s0
Target Context                system_u:object_r:pcp_var_lib_t:s0
Target Objects                 [ dir ]
Source                        local
Source Path                   /usr/libexec/postfix/local
Port                          <Unknown>
Host                          (removed)
Source RPM Packages           postfix-2.10.1-6.el7.x86_64
Target RPM Packages           
Policy RPM                    selinux-policy-3.12.1-122.el7.noarch
Selinux Enabled               True
Policy Type                   targeted
Enforcing Mode                Enforcing
Host Name                     (removed)
Platform                      Linux (removed) 3.10.0-81.el7.x86_64 #1 SMP Thu
                              Jan 30 01:57:58 EST 2014 x86_64 x86_64
Alert Count                   3
First Seen                    2014-01-30 00:10:01 CST
Last Seen                     2014-02-04 00:10:02 CST
Local ID                      9172c217-ab3a-4089-a6d6-a0b2cf515598

Raw Audit Messages
type=AVC msg=audit(1391494202.1:3291): avc:  denied  { search } for  pid=17790 comm="local" name="pcp" dev="dm-0" ino=1463120 scontext=system_u:system_r:postfix_local_t:s0 tcontext=system_u:object_r:pcp_var_lib_t:s0 tclass=dir


type=SYSCALL msg=audit(1391494202.1:3291): arch=x86_64 syscall=lstat success=no exit=EACCES a0=7ff43c849780 a1=7fff229fd8f0 a2=7fff229fd8f0 a3=7ff437d3f2e0 items=0 ppid=2124 pid=17790 auid=4294967295 uid=0 gid=0 euid=990 suid=0 fsuid=990 egid=988 sgid=0 fsgid=988 tty=(none) ses=4294967295 comm=local exe=/usr/libexec/postfix/local subj=system_u:system_r:postfix_local_t:s0 key=(null)

Hash: local,postfix_local_t,pcp_var_lib_t,dir,search

Additional info:
reporter:       libreport-2.1.11
hashmarkername: setroubleshoot
kernel:         3.10.0-81.el7.x86_64
type:           libreport

Comment 1 Jeff Bastian 2014-02-04 13:12:24 UTC
This happened a couple times last week too (before I set my laptop to sleep for the weekend):

$ sudo ausearch -m avc -c local -o system_u:object_r:pcp_var_lib_t:s0
----
time->Thu Jan 30 00:10:01 2014
type=SYSCALL msg=audit(1391062201.860:14685): arch=c000003e syscall=6 success=no exit=-13 a0=7fee8239a780 a1=7ffff6e29570 a2=7ffff6e29570 a3=7fee7d2f62e0 items=0 ppid=2081 pid=5292 auid=4294967295 uid=0 gid=0 euid=990 suid=0 fsuid=990 egid=988 sgid=0 fsgid=988 tty=(none) ses=4294967295 comm="local" exe="/usr/libexec/postfix/local" subj=system_u:system_r:postfix_local_t:s0 key=(null)
type=AVC msg=audit(1391062201.860:14685): avc:  denied  { search } for  pid=5292 comm="local" name="pcp" dev="dm-0" ino=1463120 scontext=system_u:system_r:postfix_local_t:s0 tcontext=system_u:object_r:pcp_var_lib_t:s0 tclass=dir
----
time->Fri Jan 31 00:10:02 2014
type=SYSCALL msg=audit(1391148602.282:2981): arch=c000003e syscall=6 success=no exit=-13 a0=7fec2edf5780 a1=7fff0deb18a0 a2=7fff0deb18a0 a3=7fec2b63a2e0 items=0 ppid=2175 pid=11328 auid=4294967295 uid=0 gid=0 euid=990 suid=0 fsuid=990 egid=988 sgid=0 fsgid=988 tty=(none) ses=4294967295 comm="local" exe="/usr/libexec/postfix/local" subj=system_u:system_r:postfix_local_t:s0 key=(null)
type=AVC msg=audit(1391148602.282:2981): avc:  denied  { search } for  pid=11328 comm="local" name="pcp" dev="dm-0" ino=1463120 scontext=system_u:system_r:postfix_local_t:s0 tcontext=system_u:object_r:pcp_var_lib_t:s0 tclass=dir
----
time->Tue Feb  4 00:10:02 2014
type=SYSCALL msg=audit(1391494202.001:3291): arch=c000003e syscall=6 success=no exit=-13 a0=7ff43c849780 a1=7fff229fd8f0 a2=7fff229fd8f0 a3=7ff437d3f2e0 items=0 ppid=2124 pid=17790 auid=4294967295 uid=0 gid=0 euid=990 suid=0 fsuid=990 egid=988 sgid=0 fsgid=988 tty=(none) ses=4294967295 comm="local" exe="/usr/libexec/postfix/local" subj=system_u:system_r:postfix_local_t:s0 key=(null)
type=AVC msg=audit(1391494202.001:3291): avc:  denied  { search } for  pid=17790 comm="local" name="pcp" dev="dm-0" ino=1463120 scontext=system_u:system_r:postfix_local_t:s0 tcontext=system_u:object_r:pcp_var_lib_t:s0 tclass=dir

Comment 2 Milos Malik 2014-02-04 13:21:13 UTC
It's very likely that postfix/local searched the /var/lib/pcp directory in the past too, but the SELinux label on that directory has changed (because of updated selinux-policy) from var_lib_t to pcp_var_lib_t and appropriate allow (or dontaudit) rule is missing.

Comment 3 Miroslav Grepl 2014-02-05 08:52:49 UTC
The question is whether only "search" is needed.

Jeff,
any chance to test in permissive?

Comment 4 Milos Malik 2014-02-05 10:40:47 UTC
One of my beaker jobs found this AVC accidentally. Going to reschedule the beaker job after making the postfix_local_t domain permissive.

Comment 5 Jeff Bastian 2014-02-05 15:41:06 UTC
It looks like this is being triggered by pcp itself with a cron job from /etc/cron.d/pcp-pmlogger:

# daily processing of archive logs
10     0  *  *  *  pcp  /usr/libexec/pcp/bin/pmlogger_daily


I tried running it manually, but no luck:

# setenforce Permissive
# su -s /bin/bash -c /usr/libexec/pcp/bin/pmlogger_daily pcp
# ausearch -m avc -ts recent
<no matches>


Apparently something else special happens at 00:10 so I'll check again tomorrow.

Comment 6 Jeff Bastian 2014-02-06 15:14:28 UTC
Argh, so I put my laptop in Permissive mode and then the problem did not happen.  00:10 came and went this morning with no AVCs and I see in the logs that postfix/local did run.

I noticed when trying to manually reproduce the problem yesterday that /var/run/pcp was missing for some reason on my system, so I created the directory and set the proper permissions.  Maybe I should not have done that...

Milos, did you get anything interesting?


(On another note, my laptop's hard drive started failing at 03:37 this morning so I may not be able to reproduce this again with this system.)

Comment 7 Milos Malik 2014-02-06 16:21:15 UTC
The AVC mentioned in comment#0 is related to /var/lib/pcp directory, which belongs to pcp package.

Even if there is no allow rule for that kind of access, I'm unable to reproduce the AVC with selinux-policy-targeted-3.12.1-124.el7. Even if I change system time to 00:09 and restart crond, the cron job does not trigger them. I see the pmlogger_daily record in /var/log/cron file, but no AVCs.

Comment 14 Ludek Smid 2014-06-13 09:35:37 UTC
This request was resolved in Red Hat Enterprise Linux 7.0.

Contact your manager or support representative in case you have further questions about the request.