Skip to content

Commit

Permalink
Allow procmail to read mail aliases
Browse files Browse the repository at this point in the history
Fixes:
type=PROCTITLE msg=audit(08/12/2024 10:52:43.901:605) : proctitle=/usr/bin/procmail -a  DEFAULT=/home/bobo/Maildir/ MAILDIR=/home/bobo/Maildir/
type=PATH msg=audit(08/12/2024 10:52:43.901:605) : item=1 name=/lib64/ld-linux-x86-64.so.2 inode=4436472 dev=fd:02 mode=file,755 ouid=root ogid=root rdev=00:00 obj=system_u:object_r:ld_so_t:s0 nametype=NORMAL cap_fp=none cap_fi=none cap_fe=0 cap_fver=0 cap_frootid=0
type=PATH msg=audit(08/12/2024 10:52:43.901:605) : item=0 name=/usr/bin/procmail inode=4915653 dev=fd:02 mode=file,755 ouid=root ogid=mail rdev=00:00 obj=system_u:object_r:procmail_exec_t:s0 nametype=NORMAL cap_fp=none cap_fi=none cap_fe=0 cap_fver=0 cap_frootid=0
type=CWD msg=audit(08/12/2024 10:52:43.901:605) : cwd=/var/spool/postfix
type=EXECVE msg=audit(08/12/2024 10:52:43.901:605) : argc=5 a0=/usr/bin/procmail a1=-a a2= a3=DEFAULT=/home/bobo/Maildir/ a4=MAILDIR=/home/bobo/Maildir/
type=SYSCALL msg=audit(08/12/2024 10:52:43.901:605) : arch=x86_64 syscall=execve success=yes exit=0 a0=0x5639d4f70990 a1=0x5639d4f6f080 a2=0x5639d4f70f10 a3=0x8 items=2 ppid=27104 pid=27106 auid=unset uid=bobo gid=bobo euid=bobo suid=bobo fsuid=bobo egid=bobo sgid=bobo fsgid=bobo tty=(none) ses=unset comm=procmail exe=/usr/bin/procmail subj=system_u:system_r:procmail_t:s0 key=(null)
type=AVC msg=audit(08/12/2024 10:52:43.901:605) : avc:  denied  { read } for  pid=27106 comm=procmail path=/etc/aliases.lmdb dev="vda2" ino=2225144 scontext=system_u:system_r:procmail_t:s0 tcontext=system_u:object_r:etc_aliases_t:s0 tclass=file permissive=0

Resolves: https://issues.redhat.com/browse/RHEL-54014
Signed-off-by: Ondrej Mosnacek <[email protected]>
  • Loading branch information
WOnder93 authored and zpytela committed Dec 11, 2024
1 parent 3dea9b1 commit ce0988e
Showing 1 changed file with 1 addition and 0 deletions.
1 change: 1 addition & 0 deletions policy/modules/contrib/procmail.te
Original file line number Diff line number Diff line change
Expand Up @@ -154,6 +154,7 @@ optional_policy(`

optional_policy(`
mta_read_config(procmail_t)
mta_read_aliases(procmail_t)
mta_mailserver_delivery(procmail_t)
mta_manage_home_rw(procmail_t)
sendmail_domtrans(procmail_t)
Expand Down

0 comments on commit ce0988e

Please sign in to comment.