You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

SELinux问题:root用户无法删除文件,自定义类型触发AVC拒绝

问题:Rocky Linux 9上Pi-hole SELinux策略导致无法删除/etc/pihole下的临时文件

问题现象

执行删除临时文件命令时提示权限拒绝:

[root@pihole03 ~]# rm /etc/pihole/sed*
rm: remove regular file '/etc/pihole/sedGcMe6O'? y
rm: cannot remove '/etc/pihole/sedGcMe6O': Permission denied
rm: remove regular file '/etc/pihole/sedkOdgd5'? y
rm: cannot remove '/etc/pihole/sedkOdgd5': Permission denied
rm: remove regular file '/etc/pihole/sedTetiRf'? y
rm: cannot remove '/etc/pihole/sedTetiRf': Permission denied

查看文件属性,发现/etc/pihole目录的SELinux类型为pihole_t,而临时文件类型为pihole_etc_t:

drwxrwxr-x.   3 pihole pihole system_u:object_r:pihole_t:s0              4096 May 31 08:19 .
[...]
-rw-r--r--.   1 root   root   system_u:object_r:pihole_etc_t:s0           398 May 30 20:40 sedGcMe6O
-rw-------.   1 root   root   system_u:object_r:pihole_etc_t:s0           399 May 30 21:47 sedkOdgd5
-rw-r--r--.   1 root   root   system_u:object_r:pihole_etc_t:s0           399 May 30 21:49 sedTetiRf
[...]

对应的AVC拒绝日志:

type=AVC msg=audit(1685513107.410:217): avc:  denied  { remove_name } for  pid=17665 comm="rm" name="sedGcMe6O" dev="dm-0" ino=482814 scontext=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 tcontext=system_u:object_r:pihole_t:s0 tclass=dir permissive=0
type=AVC msg=audit(1685513108.270:218): avc:  denied  { remove_name } for  pid=17665 comm="rm" name="sedkOdgd5" dev="dm-0" ino=469130 scontext=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 tcontext=system_u:object_r:pihole_t:s0 tclass=dir permissive=0
type=AVC msg=audit(1685513108.793:219): avc:  denied  { remove_name } for  pid=17665 comm="rm" name="sedTetiRf" dev="dm-0" ino=480817 scontext=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 tcontext=system_u:object_r:pihole_t:s0 tclass=dir permissive=0

问题根源分析

直接添加allow unconfined_t pihole_t:dir remove_name;并非合理方案,核心问题在于进程类型与文件类型混淆:

  • pihole_t是Pi-hole进程的SELinux域(进程类型),不应该被应用到/etc/pihole目录上;
  • /etc/pihole目录及文件应使用定义的pihole_etc_t类型,但实际目录被错误设置为pihole_t;
  • 策略中对pihole_etc_t的类型定义不规范,未使用/etc配置目录对应的标准宏,导致默认权限缺失。

解决方案

1. 修正文件上下文规则与目录类型

确保/etc/pihole目录及子内容正确应用pihole_etc_t类型:

  • 检查文件上下文规则,明确匹配目录和子内容:
    /etc/pihole	gen_context(system_u:object_r:pihole_etc_t,s0)
    /etc/pihole/.*	gen_context(system_u:object_r:pihole_etc_t,s0)
    
  • 重新应用文件上下文:
    restorecon -Rv /etc/pihole
    
    若仍无效,先手动修正目录类型再恢复:
    chcon -t pihole_etc_t /etc/pihole
    restorecon -Rv /etc/pihole
    

2. 调整SELinux策略中pihole_etc_t的定义

将pihole_etc_t从普通文件类型改为/etc配置目录专用的config_file类型,继承标准权限:

# 替换原有的 files_type(pihole_etc_t)
files_config_file(pihole_etc_t)

3. 修正unconfined_t的权限规则

将原针对pihole_t目录的权限规则,改为针对正确的pihole_etc_t:

# 替换原有的 allow unconfined_t pihole_t:dir { add_name write };
allow unconfined_t pihole_etc_t:dir { add_name remove_name write };

SELinux策略优化建议

  • 优先使用标准宏:尽量使用SELinux提供的宏(如files_config_file、manage_file_perms)替代手动罗列权限,减少冗余并遵循默认安全规范;
  • 区分进程类型与文件类型:严格避免将进程域(如pihole_t)应用到文件/目录上,避免权限混乱;
  • 收紧进程权限:检查pihole_t的权限规则,移除不必要的权限(如shell_exec_t的执行权限,若Pi-hole updater无需直接调用shell可调整);
  • 利用audit2allow辅助排查:通过audit2allow -a生成建议规则,但需仔细审核避免过度授权;
  • 拆分策略模块:将不同组件(如HTTPD交互、Pi-hole进程权限)的规则拆分,提升策略可读性与维护性。

内容的提问来源于stack exchange,提问作者derdeagle

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.20 15:32:36