SELinux问题:root用户无法删除文件,自定义类型触发AVC拒绝
问题:Rocky Linux 9上Pi-hole SELinux策略导致无法删除/etc/pihole下的临时文件
问题现象
执行删除临时文件命令时提示权限拒绝:
[root@pihole03 ~]# rm /etc/pihole/sed* rm: remove regular file '/etc/pihole/sedGcMe6O'? y rm: cannot remove '/etc/pihole/sedGcMe6O': Permission denied rm: remove regular file '/etc/pihole/sedkOdgd5'? y rm: cannot remove '/etc/pihole/sedkOdgd5': Permission denied rm: remove regular file '/etc/pihole/sedTetiRf'? y rm: cannot remove '/etc/pihole/sedTetiRf': Permission denied
查看文件属性,发现/etc/pihole目录的SELinux类型为pihole_t,而临时文件类型为pihole_etc_t:
drwxrwxr-x. 3 pihole pihole system_u:object_r:pihole_t:s0 4096 May 31 08:19 . [...] -rw-r--r--. 1 root root system_u:object_r:pihole_etc_t:s0 398 May 30 20:40 sedGcMe6O -rw-------. 1 root root system_u:object_r:pihole_etc_t:s0 399 May 30 21:47 sedkOdgd5 -rw-r--r--. 1 root root system_u:object_r:pihole_etc_t:s0 399 May 30 21:49 sedTetiRf [...]
对应的AVC拒绝日志:
type=AVC msg=audit(1685513107.410:217): avc: denied { remove_name } for pid=17665 comm="rm" name="sedGcMe6O" dev="dm-0" ino=482814 scontext=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 tcontext=system_u:object_r:pihole_t:s0 tclass=dir permissive=0 type=AVC msg=audit(1685513108.270:218): avc: denied { remove_name } for pid=17665 comm="rm" name="sedkOdgd5" dev="dm-0" ino=469130 scontext=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 tcontext=system_u:object_r:pihole_t:s0 tclass=dir permissive=0 type=AVC msg=audit(1685513108.793:219): avc: denied { remove_name } for pid=17665 comm="rm" name="sedTetiRf" dev="dm-0" ino=480817 scontext=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 tcontext=system_u:object_r:pihole_t:s0 tclass=dir permissive=0
问题根源分析
直接添加allow unconfined_t pihole_t:dir remove_name;并非合理方案,核心问题在于进程类型与文件类型混淆:
pihole_t是Pi-hole进程的SELinux域(进程类型),不应该被应用到/etc/pihole目录上;/etc/pihole目录及文件应使用定义的pihole_etc_t类型,但实际目录被错误设置为pihole_t;- 策略中对
pihole_etc_t的类型定义不规范,未使用/etc配置目录对应的标准宏,导致默认权限缺失。
解决方案
1. 修正文件上下文规则与目录类型
确保/etc/pihole目录及子内容正确应用pihole_etc_t类型:
- 检查文件上下文规则,明确匹配目录和子内容:
/etc/pihole gen_context(system_u:object_r:pihole_etc_t,s0) /etc/pihole/.* gen_context(system_u:object_r:pihole_etc_t,s0) - 重新应用文件上下文:
若仍无效,先手动修正目录类型再恢复:restorecon -Rv /etc/piholechcon -t pihole_etc_t /etc/pihole restorecon -Rv /etc/pihole
2. 调整SELinux策略中pihole_etc_t的定义
将pihole_etc_t从普通文件类型改为/etc配置目录专用的config_file类型,继承标准权限:
# 替换原有的 files_type(pihole_etc_t) files_config_file(pihole_etc_t)
3. 修正unconfined_t的权限规则
将原针对pihole_t目录的权限规则,改为针对正确的pihole_etc_t:
# 替换原有的 allow unconfined_t pihole_t:dir { add_name write }; allow unconfined_t pihole_etc_t:dir { add_name remove_name write };
SELinux策略优化建议
- 优先使用标准宏:尽量使用SELinux提供的宏(如
files_config_file、manage_file_perms)替代手动罗列权限,减少冗余并遵循默认安全规范; - 区分进程类型与文件类型:严格避免将进程域(如
pihole_t)应用到文件/目录上,避免权限混乱; - 收紧进程权限:检查
pihole_t的权限规则,移除不必要的权限(如shell_exec_t的执行权限,若Pi-hole updater无需直接调用shell可调整); - 利用audit2allow辅助排查:通过
audit2allow -a生成建议规则,但需仔细审核避免过度授权; - 拆分策略模块:将不同组件(如HTTPD交互、Pi-hole进程权限)的规则拆分,提升策略可读性与维护性。
内容的提问来源于stack exchange,提问作者derdeagle
相关产品推荐
相关产品推荐

