View Issue Details

IDProjectCategoryView StatusLast Update
0015947CentOS-7selinux-policypublic2019-03-22 19:57
ReporterNigel Aves 
PrioritynormalSeverityminorReproducibilityhave not tried
Status newResolutionopen 
PlatformOSOS Version7
Product Version 
Target VersionFixed in Version 
Summary0015947: SELinux is preventing sendmail from 'read' accesses on the file /var/log/maillog.
DescriptionDescription of problem:
New system build. Was working in with firefox.
SELinux is preventing sendmail from 'read' accesses on the file /var/log/maillog.

***** Plugin catchall (100. confidence) suggests **************************

If you believe that sendmail should be allowed read access on the maillog file by default.
Then you should report this as a bug.
You can generate a local policy module to allow this access.
Do
allow this access for now by executing:
# ausearch -c 'sendmail' --raw | audit2allow -M my-sendmail
# semodule -i my-sendmail.pp

Additional Information:
Source Context system_u:system_r:system_mail_t:s0
Target Context system_u:object_r:var_log_t:s0
Target Objects /var/log/maillog [ file ]
Source sendmail
Source Path sendmail
Port <Unknown>
Host (removed)
Source RPM Packages
Target RPM Packages
Policy RPM selinux-policy-3.13.1-229.el7_6.9.noarch
Selinux Enabled True
Policy Type targeted
Enforcing Mode Permissive
Host Name (removed)
Platform Linux (removed) 5.0.3-1.el7.elrepo.x86_64 #1 SMP
                              Tue Mar 19 09:51:25 EDT 2019 x86_64 x86_64
Alert Count 1
First Seen 2019-03-22 13:56:01 MDT
Last Seen 2019-03-22 13:56:01 MDT
Local ID d474578d-dcd6-4445-982e-86c1023b1323

Raw Audit Messages
type=AVC msg=audit(1553284561.413:1193): avc: denied { read } for pid=26473 comm="sendmail" path="/var/log/maillog" dev="dm-2" ino=33744566 scontext=system_u:system_r:system_mail_t:s0 tcontext=system_u:object_r:var_log_t:s0 tclass=file permissive=1


Hash: sendmail,system_mail_t,var_log_t,file,read

Version-Release number of selected component:
selinux-policy-3.13.1-229.el7_6.9.noarch
Additional Informationreporter: libreport-2.1.11.1
hashmarkername: setroubleshoot
kernel: 5.0.3-1.el7.elrepo.x86_64
reproducible: Not sure how to reproduce the problem
type: libreport
TagsNo tags attached.
abrt_hash05581b8406f7b849baacb3afb41f71f0f579d4b765b7cea443644ba57985828e
URL

Activities

There are no notes attached to this issue.

Issue History

Date Modified Username Field Change
2019-03-22 19:57 Nigel Aves New Issue