Description of problem: type=AVC msg=audit(11/18/2017 17:50:22.190:182) : avc: denied { read } for pid=1330 comm=newaliases name=dynamicmaps.cf.d dev="dm-0" ino=2099156 scontext=system_u:system_r:sendmail_t:s0 tcontext=system_u:object_r:postfix_etc_t:s0 tclass=dir permissive=0 Was caused by: Missing type enforcement (TE) allow rule. You can use audit2allow to generate a loadable module to allow this access. Caused when starting postfix (which updates the alias.db file): aliasesdb[7045]: newaliases: warning: /etc/postfix/dynamicmaps.cf.d: directory open failed: Permission denied Adding the following policy allowed access: allow sendmail_t postfix_etc_t:dir read; Version-Release number of selected component (if applicable): selinux-policy-3.13.1-283.14.fc27.noarch postfix-3.2.4-1.fc27.x86_64
selinux-policy-3.13.1-283.17.fc27 has been submitted as an update to Fedora 27. https://bodhi.fedoraproject.org/updates/FEDORA-2017-d05b1a2ab9
*** Bug 1516523 has been marked as a duplicate of this bug. ***
selinux-policy-3.13.1-283.17.fc27 has been pushed to the Fedora 27 testing repository. If problems still persist, please make note of it in this bug report. See https://fedoraproject.org/wiki/QA:Updates_Testing for instructions on how to install test updates. You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2017-d05b1a2ab9
Appears fixed in latest build, adding karma!
selinux-policy-3.13.1-283.17.fc27 has been pushed to the Fedora 27 stable repository. If problems still persist, please make note of it in this bug report.