What the heck is going on? I'm getting the same sort of thing from crond where it has access to the file but is erroring saying it cant read the hidden file. It appears some sort of corruption of the table may be going on.
This acl was working fine 36 hours ago, but now its flipping a shitbrick =(
Current version is CVS of both gradm and grsec.
gradm -T /usr/bin/procmail /etc/passwd
Allowed access for /etc/passwd from /usr/bin/procmail:
Read: yes
Write: no
Append: no
Execute: no
Hidden: no
Inherit ACL on exec: no
Read-only ptrace: no
Audit reads: no
Audit writes: no
Audit execs: no
Audit appends: no
Audit finds: no
Audit inherits: no
Apr 18 09:55:25 src@soup grsec: From 161.114.1.207: denied access to hidden file /etc/passwd by (procmail:26499) UID(0) EUID(0), parent (sendmail:9556) UID(0) EUID(0)
/usr/bin/procmail o {
/var/spool/mail rw
/usr/share/zoneinfo/US/Central r
/lib rx
/lib/ld-2.2.5.so x
/etc/passwd r
/etc/nsswitch.conf r
/etc/ld.so.cache r
/etc/group r
/dev/null rw
/dev
/dev/log rw
/usr/bin/procmail x
/usr/local/bin/spamassassin rx
/home rw
/root rw
/bin/bash rx
/ h
-CAP_ALL
+CAP_CHOWN
+CAP_SETGID
+CAP_SETUID
+CAP_SYS_NICE
connect {
127.0.0.1:512 dgram udp
}
bind {
disabled
}
}
/usr/sbin/sendmail o {
/var/tmp
/var/spool/mqueue rw
/var/spool
/var/spool/clientmqueue rw
/var/run/sendmail.pid w
/var/run
/var
/usr/share/zoneinfo/US/Central r
/usr/bin/procmail x
/usr/bin
/usr
/root
/proc/loadavg r
/proc/cpuinfo r
/lib rx
/lib/ld-2.2.5.so x
/home
/etc/mail rw
/etc r
/dev/null rw
/dev/log rw
/usr/sbin/sendmail x
/
-CAP_ALL
+CAP_SETGID
+CAP_SETUID
+CAP_NET_BIND_SERVICE
}