You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

基于user_r创建自定义motion守护进程角色遇SELinux AVC拒绝问题求助

问题

在Fedora 38 CoreOS系统上,我希望基于user_r角色为自定义motion守护进程创建专属角色,该守护进程在无约束状态下运行正常,现需进一步加固权限。

我找到的SELinux相关资料包括自定义角色创建指南和约束规则文档。切换到user_u角色后,audit.log中出现以下AVC拒绝日志:

type=AVC msg=audit(1686738596.953:155): avc:  denied  { relabelto } for  pid=1054
comm="systemd" name="tmp" dev="tmpfs" ino=302 scontext=user_u:user_r:user_t:s0
tcontext=system_u:object_r:tmp_t:s0 tclass=dir permissive=0

audit2allow给出的提示如下:

#============= user_t ==============

#!!!! This avc is a constraint violation.  You would need to modify the attributes of
either the source or target types to allow this access.
#Constraint rule: 
#   constrain dir { create relabelfrom relabelto } ((u1 == u2 -Fail-)  or (t1 ==
 can_change_object_identity -Fail-) ); Constraint DENIED

#   Possible cause is the source user (user_u) and target user (system_u) are different.
allow user_t tmp_t:dir relabelto;

这是约束规则冲突问题,user_r角色的规则阻止了用户访问/tmp目录,我原本以为user_r可访问/tmp,但实际并非如此。我不想为基于user_r模板的`_back�在我的�/news闭argReenter8的工作目录,从根源避免该操作。

  1. 创建独立的自定义domain类型
    不要直接复用user_t,而是为motion守护进程创建专属的domain类型,继承user_r角色的权限并按需添加规则:
    role custom_motion_r types custom_motion_t;
    role custom_motion_r inherits user_r;
    
    # 添加custom_motion_t访问tmp的必要规则
    allow custom_motion_t tmp_t:dir { read write search add_name remove_name };
    allow custom_motion_t tmp_t:file { read write create unlink };
    
    这样既能继承user_r的安全特性,又能避免因复用user_t带来的跨用户约束冲突。

推荐SELinux学习资料

  • SELinux Project官方指南:涵盖基础概念、policy编写、故障排查的核心内容,是最权威的官方资料。
  • Red Hat SELinux实战文档:针对RHEL/Fedora系列的实用教程,包含大量日常运维和排障案例,适合新手快速上手。
  • 《SELinux by Example》:经典书籍,通过实例讲解SELinux原理与配置,适合系统学习从入门到进阶的知识。
  • Fedora SELinux配置指南:贴合Fedora CoreOS使用场景,包含实用命令和针对性案例。

内容的提问来源于stack exchange,提问作者miller the gorilla

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.18 23:24:55