View Issue Details

IDProjectCategoryView StatusLast Update
0016084CentOS-7selinux-policypublic2019-05-20 15:07
PrioritynormalSeverityminorReproducibilityhave not tried
Status newResolutionopen 
PlatformOSOS Version7
Product Version 
Target VersionFixed in Version 
Summary0016084: SELinux is preventing sendmail from 'getattr' accesses on the archivo /proc/sys/net/ipv6/conf/all/disable_ipv6.
DescriptionDescription of problem:
No permite acceso a enviar mail
SELinux is preventing sendmail from 'getattr' accesses on the archivo /proc/sys/net/ipv6/conf/all/disable_ipv6.

***** Plugin catchall (100. confidence) suggests **************************

Si cree que de manera predeterminada se debería permitir a sendmail el acceso getattr sobre disable_ipv6 file.
Then debería reportar esto como un error.
Puede generar un módulo de política local para permitir este acceso.
permita el acceso temporalmente ejecutando:
# ausearch -c 'sendmail' --raw | audit2allow -M mi-sendmail
# semodule -i mi-sendmail.pp

Additional Information:
Source Context system_u:system_r:system_mail_t:s0
Target Context system_u:object_r:sysctl_net_t:s0
Target Objects /proc/sys/net/ipv6/conf/all/disable_ipv6 [ file ]
Source sendmail
Source Path sendmail
Port <Unknown>
Host (removed)
Source RPM Packages
Target RPM Packages
Policy RPM selinux-policy-3.13.1-229.el7_6.12.noarch
Selinux Enabled True
Policy Type targeted
Enforcing Mode Permissive
Host Name (removed)
Platform Linux (removed) 3.10.0-957.12.1.el7.x86_64 #1 SMP
                              Mon Apr 29 14:59:59 UTC 2019 x86_64 x86_64
Alert Count 10
First Seen 2019-05-14 17:18:35 CEST
Last Seen 2019-05-14 17:27:37 CEST
Local ID b8097160-8d55-4832-a323-6b84d94b4195

Raw Audit Messages
type=AVC msg=audit(1557847657.777:1179): avc: denied { getattr } for pid=19792 comm="sendmail" path="/proc/sys/net/ipv6/conf/all/disable_ipv6" dev="proc" ino=205144 scontext=system_u:system_r:system_mail_t:s0 tcontext=system_u:object_r:sysctl_net_t:s0 tclass=file permissive=1

Hash: sendmail,system_mail_t,sysctl_net_t,file,getattr

Version-Release number of selected component:
Additional Informationreporter: libreport-
hashmarkername: setroubleshoot
kernel: 3.10.0-957.12.1.el7.x86_64
reproducible: Not sure how to reproduce the problem
type: libreport
TagsNo tags attached.

Issue History

Date Modified Username Field Change
2019-05-14 15:30 GoodWolf8 New Issue
2019-05-20 15:07 BlueH2O Note Added: 0034485