Re: Issues with the include/contrib/courier.if policy

Sam Varshavchik <[email protected]>
Newsgroups gmane.linux.redhat.fedora.selinux
Message-ID <[email protected]>
Lukas Vrabec writes:

>
> Can please run following commands before you reproduce the scenario again:
>
> # chcon -t courier_exec_t /usr/lib/courier/sbin/couriertcpd
> # dnf install selinux-policy-devel -y
> $ cat httpd_courier.te
> policy_module(httpd_courier, 1.0)
> gen_require(`
>     type httpd_sys_script_t;
>     type courier_spool_t;
>     type system_mail_t;
> ')
>
> stream_connect_pattern(httpd_sys_script_t, courier_spool_t,
> courier_spool_t, system_mail_t)
>
> # make -f /usr/share/selinux/devel/Makefile httpd_courier.pp
> # semodule -i httpd_courier.pp
>
> ### reproduce the scenario
>
> And attach output of:
> # ausearch -m AVC -ts today

The above was done:

[root@jack ~]# semodule --list | grep courier
courier
httpd_courier
[root@jack ~]# ls -alZ /usr/lib/courier/sbin/couriertcpd
-r-xr-xr-x. 1 daemon daemon system_u:object_r:courier_exec_t:s0 142456 May  
10 01:14 /usr/lib/courier/sbin/couriertcpd

The server daemons were restarted.

Both the webmail socket connection was blocked, as well as signals to  
courierlogger. The first two AVCs is the webmail connection:

----
time->Mon May 11 20:00:38 2020
type=AVC msg=audit(1589241638.443:3693): avc:  denied  { connectto } for  pid=1629725 comm="webmail" path="/var/spool/courier/sqwebmail.sock" scontext=system_u:system_r:httpd_sys_script_t:s0 tcontext=system_u:system_r:unconfined_service_t:s0 tclass=unix_stream_socket permissive=0
----
time->Mon May 11 20:00:54 2020
type=AVC msg=audit(1589241654.975:3701): avc:  denied  { connectto } for  pid=1629864 comm="webmail" path="/var/spool/courier/sqwebmail.sock" scontext=system_u:system_r:httpd_sys_script_t:s0 tcontext=system_u:system_r:unconfined_service_t:s0 tclass=unix_stream_socket permissive=0

The socket and the cgi-bin binary are labeled thusly:

[root@jack ~]# ls -alZ /var/spool/courier/sqwebmail.sock
srwxrwxrwx. 1 root root system_u:object_r:courier_spool_t:s0 0 May 11 20:01  
/var/spool/courier/sqwebmail.sock
[root@jack ~]# ls -alZ /var/www/cgi-bin/webmail
-r-xr-xr-x. 1 root bin system_u:object_r:httpd_sys_script_exec_t:s0 31464  
May 10 01:14 /var/www/cgi-bin/webmail

The remaining AVCs are for the signal issue:

----
time->Mon May 11 20:02:13 2020
type=AVC msg=audit(1589241733.799:3740): avc:  denied  { signal } for  pid=1630215 comm="courierlogger" scontext=unconfined_u:unconfined_r:system_mail_t:s0-s0:c0.c1023 tcontext=system_u:system_r:unconfined_service_t:s0 tclass=process permissive=0
----
time->Mon May 11 20:02:23 2020
type=AVC msg=audit(1589241743.799:3743): avc:  denied  { sigkill } for  pid=1630215 comm="courierlogger" scontext=unconfined_u:unconfined_r:system_mail_t:s0-s0:c0.c1023 tcontext=system_u:system_r:unconfined_service_t:s0 tclass=process permissive=0
----
time->Mon May 11 20:02:33 2020
type=AVC msg=audit(1589241753.800:3744): avc:  denied  { sigkill } for  pid=1630215 comm="courierlogger" scontext=unconfined_u:unconfined_r:system_mail_t:s0-s0:c0.c1023 tcontext=system_u:system_r:unconfined_service_t:s0 tclass=process permissive=0
----
time->Mon May 11 20:02:43 2020
type=AVC msg=audit(1589241763.800:3751): avc:  denied  { sigkill } for  pid=1630215 comm="courierlogger" scontext=unconfined_u:unconfined_r:system_mail_t:s0-s0:c0.c1023 tcontext=system_u:system_r:unconfined_service_t:s0 tclass=process permissive=1
----
time->Mon May 11 20:02:43 2020
type=AVC msg=audit(1589241763.807:3752): avc:  denied  { signal } for  pid=1630256 comm="courierlogger" scontext=unconfined_u:unconfined_r:system_mail_t:s0-s0:c0.c1023 tcontext=system_u:system_r:unconfined_service_t:s0 tclass=process permissive=1

Noting that the running processes are unconfined, even though the binary is  
labeled:

# ps -efZ | grep courierlogger
system_u:system_r:unconfined_service_t:s0 root 1630457 1  0 20:10 ?         
00:00:00 /usr/sbin/courierlogger - ... every one of them
root@jack ~]# ls -alZ /usr/sbin/courierlogger
-rwxr-xr-x. 1 daemon daemon system_u:object_r:courier_exec_t:s0 25296 May  9  
23:19 /usr/sbin/courierlogger

_______________________________________________
selinux mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/[email protected]
signature.asc (application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAABCAAdFiEEMWrVnbBKLOeG9ifkazpiviedvyUFAl6561EACgkQazpivied
vyUoGhAAjTcWZu70fKICiHspHb3/kn390sFjYVm08fVGb/YrFewa2Xe69rRz5zHJ
mWF7hCYE6T+tWPpyEWp0EGD1V3VHoJ2Ze0TN99+qrrepw4ZiF0MEgjjbW6Jlt/5c
nk/2Yj8jSVe/Eo5SXnZayEGDgLgmiMLOxEVqPl7LLUtEgR92d8TPYWdkIZZkQEWm
xmsf6J9g/0NRfKGVkGxCeUufVMSoR4NzbzYlWgHoxCfBUdpNujPJ7JyZIFSLpJxg
T6a5qSeTWCrehTOsAIvBYYzpnnLl2wHWGUnWadkeUwz5DhVFxy5cceaH0ZAQW/pn
IiB9g8rhfmxusp1EUKrKc1J0N6feqaWHXt0d8ri+84CsHIiley3OJ5meMscVOdD+
j1BNimg9xsMToSl03/73UnrkpLONcXppcZI/LDSSfDTLH6dk+XTNtKNpRicbzeJQ
eWfyf+UP2vCGCNKWhXAj25JVMAY1oRj3g41sqcLOdm1mqxJ0w2ZVv2pJx00gHl9I
hDT6I5dKji4i6lg7Cfjfpe2OptNwe+Lj9/BGB5lXE/hLwUypBXuJwtkkp0nFtj8t
IvjlDoU3wiURLr4BPlvwlJARjJm1TnY7re5dBT1pYH0jXWh2NpPelLlBfZJ/Rvsp
M2M6q9ntNmDebZl56H2j2XZAYAykTb7T24w0GGKcj4imls6WSj0=
=x07S
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.