Bug 1061159
| Summary: | SELinux prevents /usr/libexec/postfix/local from searching in /var/lib/pcp directory | ||
|---|---|---|---|
| Product: | Red Hat Enterprise Linux 7 | Reporter: | Jeff Bastian <jbastian> |
| Component: | selinux-policy | Assignee: | Miroslav Grepl <mgrepl> |
| Status: | CLOSED CURRENTRELEASE | QA Contact: | Milos Malik <mmalik> |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | 7.0 | CC: | jbastian, mmalik |
| Target Milestone: | rc | Keywords: | Reopened |
| Target Release: | --- | ||
| Hardware: | x86_64 | ||
| OS: | Linux | ||
| Whiteboard: | abrt_hash:c8e34f69293e5acf79e2e3d089c10d67353429cbd4a6c3567b28fb53bb5429c4 | ||
| Fixed In Version: | selinux-policy-3.12.1-126.el7 | Doc Type: | Bug Fix |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2014-06-13 09:35:37 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
This happened a couple times last week too (before I set my laptop to sleep for the weekend):
$ sudo ausearch -m avc -c local -o system_u:object_r:pcp_var_lib_t:s0
----
time->Thu Jan 30 00:10:01 2014
type=SYSCALL msg=audit(1391062201.860:14685): arch=c000003e syscall=6 success=no exit=-13 a0=7fee8239a780 a1=7ffff6e29570 a2=7ffff6e29570 a3=7fee7d2f62e0 items=0 ppid=2081 pid=5292 auid=4294967295 uid=0 gid=0 euid=990 suid=0 fsuid=990 egid=988 sgid=0 fsgid=988 tty=(none) ses=4294967295 comm="local" exe="/usr/libexec/postfix/local" subj=system_u:system_r:postfix_local_t:s0 key=(null)
type=AVC msg=audit(1391062201.860:14685): avc: denied { search } for pid=5292 comm="local" name="pcp" dev="dm-0" ino=1463120 scontext=system_u:system_r:postfix_local_t:s0 tcontext=system_u:object_r:pcp_var_lib_t:s0 tclass=dir
----
time->Fri Jan 31 00:10:02 2014
type=SYSCALL msg=audit(1391148602.282:2981): arch=c000003e syscall=6 success=no exit=-13 a0=7fec2edf5780 a1=7fff0deb18a0 a2=7fff0deb18a0 a3=7fec2b63a2e0 items=0 ppid=2175 pid=11328 auid=4294967295 uid=0 gid=0 euid=990 suid=0 fsuid=990 egid=988 sgid=0 fsgid=988 tty=(none) ses=4294967295 comm="local" exe="/usr/libexec/postfix/local" subj=system_u:system_r:postfix_local_t:s0 key=(null)
type=AVC msg=audit(1391148602.282:2981): avc: denied { search } for pid=11328 comm="local" name="pcp" dev="dm-0" ino=1463120 scontext=system_u:system_r:postfix_local_t:s0 tcontext=system_u:object_r:pcp_var_lib_t:s0 tclass=dir
----
time->Tue Feb 4 00:10:02 2014
type=SYSCALL msg=audit(1391494202.001:3291): arch=c000003e syscall=6 success=no exit=-13 a0=7ff43c849780 a1=7fff229fd8f0 a2=7fff229fd8f0 a3=7ff437d3f2e0 items=0 ppid=2124 pid=17790 auid=4294967295 uid=0 gid=0 euid=990 suid=0 fsuid=990 egid=988 sgid=0 fsgid=988 tty=(none) ses=4294967295 comm="local" exe="/usr/libexec/postfix/local" subj=system_u:system_r:postfix_local_t:s0 key=(null)
type=AVC msg=audit(1391494202.001:3291): avc: denied { search } for pid=17790 comm="local" name="pcp" dev="dm-0" ino=1463120 scontext=system_u:system_r:postfix_local_t:s0 tcontext=system_u:object_r:pcp_var_lib_t:s0 tclass=dir
It's very likely that postfix/local searched the /var/lib/pcp directory in the past too, but the SELinux label on that directory has changed (because of updated selinux-policy) from var_lib_t to pcp_var_lib_t and appropriate allow (or dontaudit) rule is missing. The question is whether only "search" is needed. Jeff, any chance to test in permissive? One of my beaker jobs found this AVC accidentally. Going to reschedule the beaker job after making the postfix_local_t domain permissive. It looks like this is being triggered by pcp itself with a cron job from /etc/cron.d/pcp-pmlogger: # daily processing of archive logs 10 0 * * * pcp /usr/libexec/pcp/bin/pmlogger_daily I tried running it manually, but no luck: # setenforce Permissive # su -s /bin/bash -c /usr/libexec/pcp/bin/pmlogger_daily pcp # ausearch -m avc -ts recent <no matches> Apparently something else special happens at 00:10 so I'll check again tomorrow. Argh, so I put my laptop in Permissive mode and then the problem did not happen. 00:10 came and went this morning with no AVCs and I see in the logs that postfix/local did run. I noticed when trying to manually reproduce the problem yesterday that /var/run/pcp was missing for some reason on my system, so I created the directory and set the proper permissions. Maybe I should not have done that... Milos, did you get anything interesting? (On another note, my laptop's hard drive started failing at 03:37 this morning so I may not be able to reproduce this again with this system.) The AVC mentioned in comment#0 is related to /var/lib/pcp directory, which belongs to pcp package. Even if there is no allow rule for that kind of access, I'm unable to reproduce the AVC with selinux-policy-targeted-3.12.1-124.el7. Even if I change system time to 00:09 and restart crond, the cron job does not trigger them. I see the pmlogger_daily record in /var/log/cron file, but no AVCs. This request was resolved in Red Hat Enterprise Linux 7.0. Contact your manager or support representative in case you have further questions about the request. |
Description of problem: I'm not really sure what happened. Postfix ran shortly after midnight (via cron? or just as a daemon?) and tried to search /var/lib/pcp and SELinux blocked it. SELinux is preventing /usr/libexec/postfix/local from 'search' accesses on the directory . ***** Plugin catchall (100. confidence) suggests ************************** If you believe that local should be allowed search access on the directory by default. Then you should report this as a bug. You can generate a local policy module to allow this access. Do allow this access for now by executing: # grep local /var/log/audit/audit.log | audit2allow -M mypol # semodule -i mypol.pp Additional Information: Source Context system_u:system_r:postfix_local_t:s0 Target Context system_u:object_r:pcp_var_lib_t:s0 Target Objects [ dir ] Source local Source Path /usr/libexec/postfix/local Port <Unknown> Host (removed) Source RPM Packages postfix-2.10.1-6.el7.x86_64 Target RPM Packages Policy RPM selinux-policy-3.12.1-122.el7.noarch Selinux Enabled True Policy Type targeted Enforcing Mode Enforcing Host Name (removed) Platform Linux (removed) 3.10.0-81.el7.x86_64 #1 SMP Thu Jan 30 01:57:58 EST 2014 x86_64 x86_64 Alert Count 3 First Seen 2014-01-30 00:10:01 CST Last Seen 2014-02-04 00:10:02 CST Local ID 9172c217-ab3a-4089-a6d6-a0b2cf515598 Raw Audit Messages type=AVC msg=audit(1391494202.1:3291): avc: denied { search } for pid=17790 comm="local" name="pcp" dev="dm-0" ino=1463120 scontext=system_u:system_r:postfix_local_t:s0 tcontext=system_u:object_r:pcp_var_lib_t:s0 tclass=dir type=SYSCALL msg=audit(1391494202.1:3291): arch=x86_64 syscall=lstat success=no exit=EACCES a0=7ff43c849780 a1=7fff229fd8f0 a2=7fff229fd8f0 a3=7ff437d3f2e0 items=0 ppid=2124 pid=17790 auid=4294967295 uid=0 gid=0 euid=990 suid=0 fsuid=990 egid=988 sgid=0 fsgid=988 tty=(none) ses=4294967295 comm=local exe=/usr/libexec/postfix/local subj=system_u:system_r:postfix_local_t:s0 key=(null) Hash: local,postfix_local_t,pcp_var_lib_t,dir,search Additional info: reporter: libreport-2.1.11 hashmarkername: setroubleshoot kernel: 3.10.0-81.el7.x86_64 type: libreport