Bug 434843 - IMAP server "dovecot" policy fix
Summary: IMAP server "dovecot" policy fix
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Red Hat Enterprise Linux 5
Classification: Red Hat
Component: selinux-policy
Version: 5.0
Hardware: All
OS: Linux
low
low
Target Milestone: rc
: ---
Assignee: Daniel Walsh
QA Contact: Ben Levenson
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2008-02-25 19:56 UTC by Stefan Schulze Frielinghaus
Modified: 2008-05-21 16:07 UTC (History)
2 users (show)

Fixed In Version: RHBA-2008-0465
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2008-05-21 16:07:12 UTC
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)
dovecot file context (532 bytes, patch)
2008-02-25 19:56 UTC, Stefan Schulze Frielinghaus
no flags Details | Diff
dovecot interface changes (726 bytes, patch)
2008-02-25 19:57 UTC, Stefan Schulze Frielinghaus
no flags Details | Diff
init.te patch (561 bytes, patch)
2008-02-25 19:57 UTC, Stefan Schulze Frielinghaus
no flags Details | Diff


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2008:0465 0 normal SHIPPED_LIVE selinux-policy bug fix update 2008-05-20 14:36:31 UTC

Description Stefan Schulze Frielinghaus 2008-02-25 19:56:25 UTC
Description of problem:
The imap server "dovecot" uses a hard link which does not conform with the
SELinux strict/mls policy. The attached patch should solve the problem and was
merged into refpolicy-trunk (today). I'm not sure if the patch will work on the
RedHat policy tree but it is not too big and can be merged easily by hand.

For reference:
http://marc.info/?l=selinux&m=118830456207512&w=2
http://marc.info/?l=selinux&m=120379039220753&w=2

Version-Release number of selected component (if applicable):


How reproducible:


Steps to Reproduce:
1.
2.
3.
  
Actual results:


Expected results:


Additional info:

Comment 1 Stefan Schulze Frielinghaus 2008-02-25 19:56:25 UTC
Created attachment 295832 [details]
dovecot file context

Comment 2 Stefan Schulze Frielinghaus 2008-02-25 19:57:09 UTC
Created attachment 295834 [details]
dovecot interface changes

Comment 3 Stefan Schulze Frielinghaus 2008-02-25 19:57:58 UTC
Created attachment 295835 [details]
init.te patch

Comment 4 Daniel Walsh 2008-02-26 15:35:17 UTC
The FC fix is already in selinux-policy-2.4.6-121.el5

The other fixes might have to wait for U3, since it is currently frozen

Fixed in selinux-policy-2.4.6-124.el5

Comment 5 RHEL Program Management 2008-03-05 22:07:49 UTC
This request was evaluated by Red Hat Product Management for
inclusion, but this component is not scheduled to be updated in
the current Red Hat Enterprise Linux release. If you would like
this request to be reviewed for the next minor release, ask your
support representative to set the next rhel-x.y flag to "?".

Comment 10 Eduard Benes 2008-04-14 13:06:44 UTC
Stefan, you can try the new policy available here:

  http://people.redhat.com/dwalsh/SELinux/RHEL5/noarch/

Comment 12 errata-xmlrpc 2008-05-21 16:07:12 UTC
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.

http://rhn.redhat.com/errata/RHBA-2008-0465.html



Note You need to log in before you can comment on or make changes to this bug.