Bug 427809 - SELinux is preventing /usr/bin/procmail (procmail_t) "read" to pipe (crond_t).
SELinux is preventing /usr/bin/procmail (procmail_t) "read" to pipe (crond_t).
Product: Fedora
Classification: Fedora
Component: selinux-policy-targeted (Show other bugs)
All Linux
low Severity low
: ---
: ---
Assigned To: Daniel Walsh
Ben Levenson
Depends On:
  Show dependency treegraph
Reported: 2008-01-07 12:24 EST by Dave Jones
Modified: 2015-01-04 17:30 EST (History)
1 user (show)

See Also:
Fixed In Version: Current
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 2008-03-05 17:17:20 EST
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

  None (edit)
Description Dave Jones 2008-01-07 12:24:53 EST
avc: denied { read } for comm=procmail dev=pipefs egid=500 euid=500
exe=/usr/bin/procmail exit=0 fsgid=500 fsuid=500 gid=500 items=0
path=pipe:[265116] pid=4367 scontext=system_u:system_r:procmail_t:s0-s0:c0.c1023
sgid=500 subj=system_u:system_r:procmail_t:s0-s0:c0.c1023 suid=500
tclass=fifo_file tcontext=system_u:system_r:crond_t:s0-s0:c0.c1023 tty=(none)

I suspect this is why I stopped getting mail from crond.
Comment 1 Dave Jones 2008-01-07 12:25:30 EST
this is selinux-policy-3.0.8-73.fc8, and using exim as an MTA instead of sendmail.
Comment 2 Daniel Walsh 2008-01-08 11:06:52 EST
You can allow this for now by executing 

# audit2allow -M mypol -i /var/log/audit/audit.log 
# semodule -i mypol.pp

Fixed in selinux-policy-3.0.8-74.fc8
Comment 3 Daniel Walsh 2008-03-05 17:17:20 EST
Bugs have been in modified for over one month.  Closing as fixed in current
release please reopen if the problem still persists.

Note You need to log in before you can comment on or make changes to this bug.