LINUXOR.SK ... open source notes ...

Email - dovecot-local-1.1.te (SELinux module)

category: solutionz · date: 2019-12-31 · updated: 2026-10-02 · author: LALA

Email Solution · Config document · referenced from Virtual machines and OS build

A local SELinux type-enforcement module for Dovecot. It lets Dovecot create and write mailboxes in a directory that carries the default label, and lets the authentication process create a symbolic link in its temporary directory.

ItemValue
Path on the server/etc/selinux/dovecot-local-1.1.te
Shown hereDC2-A-VCMSX001
Also onDC2-B-VCMSX001 and DC2-A-VCMSX002, identical
Compiled withcheckmodule -M -m, then semodule_package; the install notes show the commands for version 1.0 only
Loaded withsemodule -i
SELinux modeenforcing, targeted policy

The file

c
module dovecot-local-1.1 1.1;

require {
        type dovecot_t;
        type default_t;
        type nfs_t;
        type dovecot_auth_t;
        type dovecot_auth_tmp_t;
        class dir { add_name create remove_name write };
        class file { append create getattr lock open read unlink write };
        class lnk_file create;
}

#============= dovecot_t ==============

#!!!! This avc is allowed in the current policy
allow dovecot_t default_t:dir { add_name create remove_name write };
allow dovecot_t default_t:file unlink;

#!!!! This avc is allowed in the current policy
allow dovecot_t default_t:file { append create getattr lock open read write };

#!!!! This avc is allowed in the current policy
allow dovecot_t nfs_t:dir write;

#============= dovecot_auth_t ==============
allow dovecot_auth_t dovecot_auth_tmp_t:lnk_file create;

The lines beginning with #!!!! were written by audit2allow, not by me: it adds them when a rule it is asked to generate is already allowed by the loaded policy, here by version 1.0 of this same module.

Differences between versions

WhereModule lineWhat is different
Install notes of all three servers, design documentsmodule dovecot-local 1.0; in /etc/selinux/dovecot-local.teOnly the dovecot_t rules; no dovecot_auth_t, no lnk_file class
Archived configuration, all three serversmodule dovecot-local-1.1 1.1; in /etc/selinux/dovecot-local-1.1.teAdds allow dovecot_auth_t dovecot_auth_tmp_t:lnk_file create;

The Source material does not say when or why version 1.1 was made, and it holds no commands for building it.

Checked against RHEL 10.2

As builtToday
.te compiled with checkmodule -M -m, packaged with semodule_package, loaded with semodule -iStill works; checkpolicy and policycoreutils are shipped. The Red Hat SELinux guide for RHEL 10 no longer shows checkmodule: it shows audit2allow -M <name> followed by semodule -X 300 -i <name>.pp, and local modules written as .cil files that semodule -i loads directly
A local module with its own rulesRed Hat states that custom modules with own rules are outside the support scope

The type names used in the module (dovecot_auth_tmp_t among them) were not checked against the current policy.

← solutionz