Bug 215781 - SELinux prevents postfix from working with cyrus
Summary: SELinux prevents postfix from working with cyrus
Keywords:
Status: CLOSED CURRENTRELEASE
Alias: None
Product: Fedora
Classification: Fedora
Component: selinux-policy-targeted
Version: 6
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Daniel Walsh
QA Contact: Ben Levenson
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2006-11-15 18:32 UTC by Aurelien Bompard
Modified: 2007-11-30 22:11 UTC (History)
0 users

Fixed In Version: Current
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2007-08-22 14:14:04 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Aurelien Bompard 2006-11-15 18:32:05 UTC
Description of problem:
SELinux blocks postfix from delivering messages to cyrus using the lmtp
protocol. I'm having these messages in the audit.log :

type=AVC msg=audit(1163615289.186:35044): avc:  denied  { search } for  pid=738
comm="lmtp" name="lib" dev=sda2 ino=843650
scontext=user_u:system_r:postfix_smtp_t:s0
tcontext=system_u:object_r:var_lib_t:s0 tclass=dir
type=SYSCALL msg=audit(1163615289.186:35044): arch=40000003 syscall=102
success=no exit=-13 a0=3 a1=bf8e4650 a2=82fff4 a3=833780 items=0 ppid=32529
pid=738 auid=500 uid=89 gid=89 euid=89 suid=89 fsuid=89 egid=89 sgid=89 fsgid=89
tty=(none) comm="lmtp" exe="/usr/libexec/postfix/lmtp"
subj=user_u:system_r:postfix_smtp_t:s0 key=(null)

Version-Release number of selected component (if applicable):
selinux-policy-targeted-2.4.3-2.fc6

How reproducible:
Always

Additional info:
I did a fixfiles relabel and restarted postfix and cyrus-imapd to make sure. I
still have the problem.
The distribution is an FC5 yum-upgraded to FC6, but the "fixfiles relabel"
should have taken care of labeling problems

Comment 1 Daniel Walsh 2006-11-28 21:09:08 UTC
Fixed in selinux-policy-2.4.5-3.fc6

Comment 2 Daniel Walsh 2007-08-22 14:14:04 UTC
Fixed in current release


Note You need to log in before you can comment on or make changes to this bug.