Bug 827568 - selinux is preventing dovecot-imap from accessing Maildir
selinux is preventing dovecot-imap from accessing Maildir
Status: CLOSED ERRATA
Product: Fedora
Classification: Fedora
Component: selinux-policy (Show other bugs)
17
x86_64 Linux
unspecified Severity medium
: ---
: ---
Assigned To: Miroslav Grepl
Fedora Extras Quality Assurance
:
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2012-06-01 15:05 EDT by Roger Noble
Modified: 2012-06-16 20:01 EDT (History)
3 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2012-06-16 20:01:11 EDT
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)
selinux dovecot imap alert details (2.36 KB, text/plain)
2012-06-01 15:05 EDT, Roger Noble
no flags Details
selinux dovecot imap alert details (14.59 KB, text/plain)
2012-06-12 08:00 EDT, Roger Noble
no flags Details

  None (edit)
Description Roger Noble 2012-06-01 15:05:16 EDT
Created attachment 588563 [details]
selinux dovecot imap alert details

Description of problem:

selinux is preventing dovecot-imap from accessing Maildir.


Version-Release number of selected component (if applicable):

3.10.0-125


How reproducible:

Always.


Steps to Reproduce:
1. Start dovecot imap
2. Wait
3.
  
Actual results:

selinux security alerts


Expected results:

No alerts


Additional info:

selinux is preventing various accesses: getattr, open, etc etc

I've changed to permissive mode to allow it all to work.

Attached are some example details.
Comment 1 Miroslav Grepl 2012-06-04 09:48:19 EDT
Fixed in selinux-policy-3.10.0-129.fc17
Comment 2 Roger Noble 2012-06-04 11:45:19 EDT
Thanks.
Comment 3 Fedora Update System 2012-06-11 16:58:33 EDT
selinux-policy-3.10.0-130.fc17 has been submitted as an update for Fedora 17.
https://admin.fedoraproject.org/updates/selinux-policy-3.10.0-130.fc17
Comment 4 Roger Noble 2012-06-11 18:18:26 EDT
3.10.0-130 is OK as it goes, but I am now getting selinux failures for dovecot-imap on dovecot-uidlist.lock (unlink, add_name, remove_name, create), dovecot.index.log (write), and dovecot-uidlist.tmp (rename). Attempting to install a policy for these gives the error:

libsepol.print_missing_requirements: dovecot's global requirements were not met: type/attribute dovecot_t (No such file or directory).
Comment 5 Miroslav Grepl 2012-06-12 07:47:19 EDT
Could you add AVC msgs?
Comment 6 Roger Noble 2012-06-12 08:00:52 EDT
Created attachment 591175 [details]
selinux dovecot imap alert details

Attached as requested.
Comment 7 Daniel Walsh 2012-06-12 21:07:17 EDT
9e1b6760c12b739877b0a6ca70eb77290132a66c should fix this.
Comment 8 Miroslav Grepl 2012-06-15 07:50:11 EDT
Fixed in selinux-policy-3.10.0-131.fc17
Comment 9 Fedora Update System 2012-06-15 19:56:20 EDT
Package selinux-policy-3.10.0-130.fc17:
* should fix your issue,
* was pushed to the Fedora 17 testing repository,
* should be available at your local mirror within two days.
Update it with:
# su -c 'yum update --enablerepo=updates-testing selinux-policy-3.10.0-130.fc17'
as soon as you are able to.
Please go to the following url:
https://admin.fedoraproject.org/updates/FEDORA-2012-9520/selinux-policy-3.10.0-130.fc17
then log in and leave karma (feedback).
Comment 10 Fedora Update System 2012-06-16 20:01:11 EDT
selinux-policy-3.10.0-130.fc17 has been pushed to the Fedora 17 stable repository.  If problems still persist, please make note of it in this bug report.

Note You need to log in before you can comment on or make changes to this bug.