Fedora Account System
Red Hat Associate
Red Hat Customer
Summary: SELinux is preventing sendmail (sendmail_t) "read" to ./hosts.deny (dosfs_t). Detailed Description: SELinux denied access requested by sendmail. It is not expected that this access is required by sendmail and this access may signal an intrusion attempt. It is also possible that the specific version or configuration of the application is causing it to require additional access. Allowing Access: Sometimes labeling problems can cause SELinux denials. You could try to restore the default system file context for ./hosts.deny, restorecon -v './hosts.deny' If this does not work, there is currently no automatic way to allow this access. Instead, you can generate a local policy module to allow this access - see FAQ (http://fedora.redhat.com/docs/selinux-faq-fc5/#id2961385) Or you can disable SELinux protection altogether. Disabling SELinux protection is not recommended. Please file a bug report (http://bugzilla.redhat.com/bugzilla/enter_bug.cgi) against this package. Additional Information: Source Context system_u:system_r:sendmail_t:s0 Target Context system_u:object_r:dosfs_t:s0 Target Objects ./hosts.deny [ file ] Source sendmail Source Path /usr/sbin/sendmail.sendmail Port <Unknown> Host (removed) Source RPM Packages sendmail-8.14.2-4.fc9 Target RPM Packages Policy RPM selinux-policy-3.3.1-84.fc9 Selinux Enabled True Policy Type targeted Enforcing Mode Enforcing Plugin Name catchall_file Host Name (removed) Platform Linux (removed) 2.6.25.14-108.fc9.x86_64 #1 SMP Mon Aug 4 13:46:35 EDT 2008 x86_64 x86_64 Alert Count 1 First Seen Fri 05 Sep 2008 09:15:01 BST Last Seen Fri 05 Sep 2008 09:15:01 BST Local ID 20c7fb43-09c1-4cc0-94e9-15a5f27f91a3 Line Numbers Raw Audit Messages node=(removed) type=AVC msg=audit(1220602501.422:28): avc: denied { read } for pid=8502 comm="sendmail" name="hosts.deny" dev=dm-0 ino=818251 scontext=system_u:system_r:sendmail_t:s0 tcontext=system_u:object_r:dosfs_t:s0 tclass=file node=(removed) type=SYSCALL msg=audit(1220602501.422:28): arch=c000003e syscall=2 success=no exit=-13 a0=affbc9 a1=0 a2=1b6 a3=7f2e764227a0 items=0 ppid=3018 pid=8502 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=51 sgid=51 fsgid=51 tty=(none) ses=4294967295 comm="sendmail" exe="/usr/sbin/sendmail.sendmail" subj=system_u:system_r:sendmail_t:s0 key=(null) Hash String generated from selinux-policy-3.3.1-84.fc9,catchall_file,sendmail,sendmail_t,dosfs_t,file,read audit2allow suggests: #============= sendmail_t ============== allow sendmail_t dosfs_t:file read;
*** This bug has been marked as a duplicate of bug 538428 ***