Description of problem: Version-Release number of selected component (if applicable): unknown component How reproducible: selinux with strict policy will let neither sendmail nor procmail access /root directory Steps to Reproduce: 1. Install fc7 dvd with sendmail/procmail support enabled 2. boot system 3 login as nonroot 4. After a short while, setroubleshooter display pops up. Actual results: Logged messages: avc: denied { search } for comm="procmail" dev=dm-0 egid=0 euid=0 exe="/usr/bin/procmail" exit=-13 fsgid=0 fsuid=0 gid=0 items=0 name="root" pid=4125 scontext=system_u:system_r:procmail_t:s0 sgid=0 subj=system_u:system_r:procmail_t:s0 suid=0 tclass=dir tcontext=system_u:object_r:default_t:s0 tty=(none) uid=0 avc: denied { getattr } for comm="sendmail" dev=dm-0 egid=51 euid=51 exe="/usr/sbin/sendmail.sendmail" exit=-13 fsgid=51 fsuid=51 gid=51 items=0 name="root" path="/root" pid=3846 scontext=system_u:system_r:system_mail_t:s0 sgid=51 subj=system_u:system_r:system_mail_t:s0 suid=51 tclass=dir tcontext=system_u:object_r:default_t:s0 tty=(none) uid=51 The help message by setroubleshoot is also problematic -- the primary solution requires a reboot, while the secondary solution is not offered: If you want a confined domain to use these files you will probably need to relabel the file/directory with chcon. In some cases it is just easier to relabel the system, to relabel execute: "touch /.autorelabel; reboot" Expected results: No setroubleshoot display with default system. Additional info:
uid 51 is smmsp.
Your root directory is mislabeled. restorecon -R -v /root
But I didn't label my root directory. Hence, this step should be done by F7 during install. I therefore respectfully submit that this is still a bug. I will apply the fix you have mentioned (which, as you may note from my initial description, was not suggested by setroubleshoot).
But I didn't label my root directory. Hence, this step should be done by F7 during install. I therefore respectfully submit that this is still a bug. If you agree with me, please reopen this as a bug. I will apply the fix you have mentioned (which, as you may note from my initial description, was not suggested by setroubleshoot).