基于user_r创建自定义motion守护进程角色遇SELinux AVC拒绝问题求助
问题
在Fedora 38 CoreOS系统上,我希望基于user_r角色为自定义motion守护进程创建专属角色,该守护进程在无约束状态下运行正常,现需进一步加固权限。
我找到的SELinux相关资料包括自定义角色创建指南和约束规则文档。切换到user_u角色后,audit.log中出现以下AVC拒绝日志:
type=AVC msg=audit(1686738596.953:155): avc: denied { relabelto } for pid=1054 comm="systemd" name="tmp" dev="tmpfs" ino=302 scontext=user_u:user_r:user_t:s0 tcontext=system_u:object_r:tmp_t:s0 tclass=dir permissive=0
audit2allow给出的提示如下:
#============= user_t ============== #!!!! This avc is a constraint violation. You would need to modify the attributes of either the source or target types to allow this access. #Constraint rule: # constrain dir { create relabelfrom relabelto } ((u1 == u2 -Fail-) or (t1 == can_change_object_identity -Fail-) ); Constraint DENIED # Possible cause is the source user (user_u) and target user (system_u) are different. allow user_t tmp_t:dir relabelto;
这是约束规则冲突问题,user_r角色的规则阻止了用户访问/tmp目录,我原本以为user_r可访问/tmp,但实际并非如此。我不想为基于user_r模板的`_back�在我的�/news闭argReenter8的工作目录,从根源避免该操作。
- 创建独立的自定义domain类型
不要直接复用user_t,而是为motion守护进程创建专属的domain类型,继承user_r角色的权限并按需添加规则:
这样既能继承role custom_motion_r types custom_motion_t; role custom_motion_r inherits user_r; # 添加custom_motion_t访问tmp的必要规则 allow custom_motion_t tmp_t:dir { read write search add_name remove_name }; allow custom_motion_t tmp_t:file { read write create unlink };user_r的安全特性,又能避免因复用user_t带来的跨用户约束冲突。
推荐SELinux学习资料
- SELinux Project官方指南:涵盖基础概念、policy编写、故障排查的核心内容,是最权威的官方资料。
- Red Hat SELinux实战文档:针对RHEL/Fedora系列的实用教程,包含大量日常运维和排障案例,适合新手快速上手。
- 《SELinux by Example》:经典书籍,通过实例讲解SELinux原理与配置,适合系统学习从入门到进阶的知识。
- Fedora SELinux配置指南:贴合Fedora CoreOS使用场景,包含实用命令和针对性案例。
内容的提问来源于stack exchange,提问作者miller the gorilla
相关产品推荐
相关产品推荐

