Issues with the include/contrib/courier.if policy

Sam Varshavchik <[email protected]>
Newsgroups gmane.linux.redhat.fedora.selinux
Message-ID <[email protected]>
Fedora's selinux package has a contributed policy for Courier,  
include/contrib/courier.if, which has two issues (that I found so far) with  
my upstream rpm packages. My rpm packages have worked this way for a long  
time, probably 15+ years, or so, this is not a recent change. The only thing  
that changed is that I'm actually tried to run in enforcing mode late last  
year, and ran into this. I'm picking this issue up now, for one last college  
try to figure out the fix.

I couldn't figure out how courier.if works; so last time after doing some  
random reading, I was able to come up with a band-aid for the first issue.  
The rpm package installs a binary in /var/www/cgi-bin that talks to the  
running webmail daemon over an AF_Unix socket. selinux's policy was labeling  
the /var/www/cgi-bin binary, and blocking its socket connection. The band- 
aid was this additional local policy:

policy_module(courier_webmail, 1.0)

require {
	type httpd_sys_script_t;
	type courier_spool_t;
};

allow httpd_sys_script_t courier_spool_t:dir search_dir_perms;
allow httpd_sys_script_t courier_spool_t:sock_file manage_sock_file_perms;

That seemed innocent enough. But I revisited the entire package this week,  
and found two more issues.

The first one is an additional AVC that was now blocking the same webmail  
binary:

type=AVC msg=audit(1589086763.118:1319): avc:  denied  { connectto } for   
pid=674413 comm="webmail" path="/var/spool/courier/sqwebmail.sock"  
scontext=system_u:system_r:httpd_sys_script_t:s0  
tcontext=system_u:system_r:unconfined_service_t:s0 tclass=unix_stream_socket  
permissive=0

This was new, I could not figure out why the target context was unconfined,  
because:

[root@jack ~]# ls -alZ /var/spool/courier/sqwebmail.sock
srwxrwxrwx. 1 root root system_u:object_r:courier_spool_t:s0 0 May 10 01:15  
/var/spool/courier/sqwebmail.sock

As a band-aid on top of the first band-aid, I added

allow httpd_sys_script_t unconfined_service_t:unix_stream_socket connectto;

to the local policy, to get it working. But this doesn't seem ideal.

The second issue was that an individual uninstall of one of the rpm- 
subpackages was hanging. selinux was blocking a signal sent by binary that  
%preun runs. The signal is sent to the running process:

type=AVC msg=audit(1589082060.526:1156): avc:  denied  { signal } for   
pid=672912 comm="courierlogger"  
scontext=unconfined_u:unconfined_r:system_mail_t:s0-s0:c0.c1023  
tcontext=system_u:system_r:unconfined_service_t:s0 tclass=process  
permissive=0

and

type=AVC msg=audit(1589082160.527:1172): avc:  denied  { sigkill } for   
pid=672912 comm="courierlogger"  
scontext=unconfined_u:unconfined_r:system_mail_t:s0-s0:c0.c1023  
tcontext=system_u:system_r:unconfined_service_t:s0 tclass=process  
permissive=0

The main rpm package's systemd unit runs a startup script that inventories  
which subpackages are installed, and starts each one's service. Manually  
uninstalling an rpm subpackage executes a %preun that stops just its own  
service, and this part is getting blocked. The binary that sends the signal  
appears to be labeled by the contributed Fedora policy:

rwxr-xr-x. 1 daemon daemon system_u:object_r:courier_exec_t:s0 25296 May  9  
23:19 /usr/sbin/courierlogger

The binary is trying to send a signal to one of these processes:

system_u:system_r:unconfined_service_t:s0 root 780748 780747  0 01:15 ?     
00:00:00 /usr/lib/courier/sbin/couriertcpd [parameters]

r-xr-xr-x. 1 daemon daemon system_u:object_r:bin_t:s0 142456 May 10 01:14  
/usr/lib/courier/sbin/couriertcpd

I could avoid this by systemctl stop in %preun and systemctl start in 
%postun, I suppose. Startup and shutdown, which sends the same signal via  
the same binary, seems to work when the main rpm package runs systemctl  
stop. But doing it this way stops and restarts everything when a single  
subpackage gets removed, this is not ideal.

_______________________________________________
selinux mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/[email protected]
signature.asc (application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAABCAAdFiEEMWrVnbBKLOeG9ifkazpiviedvyUFAl63/6gACgkQazpivied
vyW/cA//Z8Ep5hlHpnArJvKW8nJtZtX8wtpB9HITv5BhQOAyAeFbFef7qfrKlz5N
Rui/iXULGGq9yfn61XkN31L8vRItpUSYxTtqhD50bqY6dpBr7vplhvinXS1HM0Nc
i3mUui2yU3vNFXeNXU0z95PQnybREUSQ7ZixuM16talUlj1/i+61grnqM0F/4icp
QENjR/sXzZmfOrQEzUl+daQRygY6ry2JdIvHJG0vUqjajKO96U6UlMiKobRnFzCg
KP2MloD9/kgBV7sltOx4KCFvud3yBGp9i1k6LS9/g5L1sUjrYDyqoKgN4Sf/98eB
9Gt36vIfjdhhyx7eQqs8OUAYEug7zsskQMEXKGD7Jb/vHUqzi7sBl/PiUpbn6H+B
jprLk/EPiKqzHzNZoEjDVFbQe3l/5SQrxoAYk/ydPZo4fTJMGhdRQT4CWEUcnRup
36LrRbfeh6EzY6HkhtOdKiO5Vs4aB+71KnEu4Bq91DoJCd9NL3OH/iHgLIECV8qN
oy6s/T8k4793tUed0MLkgwL/NQLLWleuF44IbJniZC9WycCnl/IC+jmQXim7lQOH
/ZYTxKYIRNVJPhkua9sKw8YDyBgpilXQiCDjTEuJRS7p7MJ986GGsM56hl4jL3Df
kUBR4cty31NtDy+P3q8MCyv24KPDSfTWXLmD5SjUkZ41/Shj2V0=
=bce6
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.