Displaying 2 results from an estimated 2 matches for "inotifyfs_t".
Did you mean:
inotifyfs
2015 Jan 19
2
CentOS-6.6 Fail2Ban and Postfix Selinux AVCs
...we run postfix on that host and
the sendmail SMTP package is not installed.
type=AVC msg=audit(1421683972.826:4376): avc: denied { read } for
pid=22796 comm="sendmail" path="inotify" dev=inotifyfs ino=1
scontext=system_u:system_r:system_mail_t:s0
tcontext=system_u:object_r:inotifyfs_t:s0 tclass=dir
Was caused by:
Missing type enforcement (TE) allow rule.
You can use audit2allow to generate a loadable module
to allow this access.
SELinux is preventing /usr/sbin/sendmail.postfix from read access on
the directory inotify.
***** Plugin lea...
2015 Jan 19
0
CentOS-6.6 Fail2Ban and Postfix Selinux AVCs
...o_trans };
allow fail2ban_t insmod_exec_t:file { read execute open };
allow fail2ban_t self:capability { net_admin net_raw };
allow fail2ban_t self:rawip_socket { getopt create setopt };
allow fail2ban_t sysctl_kernel_t:dir search;
allow fail2ban_t sysctl_modprobe_t:file read;
allow system_mail_t inotifyfs_t:dir read;
I am not sure whether this issue is the result of something that we
have done or left undone. We have another host configured in much the
same fashion as this one and it does not display these errors. On the
other hand the second host was installed several years ago and has a
number o...