All of lore.kernel.org
 help / color / mirror / Atom feed
* I am add a custom rule, know how 2 do te file, what about fc file, please help
@ 2006-03-26  1:38 Rongdong Lu
  2006-03-27 14:56 ` Serge E. Hallyn
                   ` (2 more replies)
  0 siblings, 3 replies; 5+ messages in thread
From: Rongdong Lu @ 2006-03-26  1:38 UTC (permalink / raw)
  To: SELinux

Hi, List,

Selinux has been driving me real crazy for the last serveral weeks, now 
finally I'am getting some clue.

Here's a problem i am having now. I have a centos4 server, with selinux 
turned on, I can't use php to send out mail. I am using 
selinux-policy-targeted-1.17.30-2.126. I am trying to add a custom rule the 
first time.

here is the error messge in messages log:

Mar 25 20:19:14 example kernel: audit(1143335954.882:36): avc:  denied  { 
execute } for  pid=10036 comm="sh" name="sendmail" dev=sda5 ino=1228853 
scontext=root:system_r:httpd_sys_script_t tcontext=system_u:object_r:var_t 
tclass=file
Mar 25 20:19:14 example kernel: audit(1143335954.882:37): avc:  denied  { 
getattr } for  pid=10036 comm="sh" name="sendmail" dev=sda5 ino=1228853 
scontext=root:system_r:httpd_sys_script_t tcontext=system_u:object_r:var_t 
tclass=file

I know I can use audit2allow to get the rule to add in to a te file, but 
what do I add to the fc file? I couldn't find which is the command trys to 
access sendmail, a process with that pid one didn't exist after the error 
message is generated.

any advice is appeciated, thanks in advance, guys

Ron

_________________________________________________________________
Is your PC infected? Get a FREE online computer virus scan from McAfee® 
Security. http://clinic.mcafee.com/clinic/ibuy/campaign.asp?cid=3963


--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2006-03-28 12:15 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2006-03-26  1:38 I am add a custom rule, know how 2 do te file, what about fc file, please help Rongdong Lu
2006-03-27 14:56 ` Serge E. Hallyn
2006-03-28 12:15   ` I am add a custom rule, know how 2 do te file, what about fc file, please he Rongdong Lu
2006-03-27 18:51 ` I am add a custom rule, know how 2 do te file, what about fc file, please help Daniel J Walsh
2006-03-27 19:09 ` Stephen Smalley

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.