You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

已设置ACL且禁用SELinux,vector用户仍无法访问/var/log/httpd目录

解决vector用户无法访问Apache日志目录的问题

问题描述

vector用户无法进入/var/log/httpd/目录,执行cat /var/log/httpd/myapp.co.uk/logfile.log时提示权限拒绝,操作报错如下:

[vector@Server01 root]$ cd /var/
[vector@Server01 var]$ cd /var/log/
[vector@Server01 log]$ cd /var/log/httpd/
bash: cd: /var/log/httpd/: Permission denied

环境信息:

  • Apache版本:Server version: Apache/2.4.37 (rocky)
  • Linux发行版:Rocky 8(CentOS/Redhat)
  • SELinux状态:已禁用(执行getenforce返回Disabled)

各目录ACL权限信息:

[root@Server01~]# getfacl /var/
# file: var/
# owner: root
# group: root
user::rwx
group::r-x
other::r-x

[root@Server01~]# getfacl  /var/log/
# file: var/log/
# owner: root
# group: root
user::rwx
user:vector:r--
group::r-x
mask::r-x
other::r-x
default:user::rwx
default:user:vector:r--
default:group::r-x
default:mask::r-x
default:other::r-x

[root@Server01~]# getfacl  /var/log/httpd/
# file: var/log/httpd/
# owner: root
# group: root
user::rwx
user:vector:r--
group::---
mask::r--
other::---
default:user::rwx
default:user:vector:r--
default:group::---
default:mask::r--
default:other::---

[root@Server01~]# getfacl  /var/log/httpd/myapp.co.uk/
# file: var/log/httpd/myapp.co.uk/
# owner: root
# group: root
user::rwx
user:vector:r--
group::r-x
mask::r-x
other::r-x

问题原因

Linux系统中,进入目录需要执行权限(x)。当前/var/log/httpd/目录给vector用户的ACL仅为r--(只读无执行),导致无法遍历该目录,进而无法访问其中的日志文件。

解决步骤

  1. 给vector用户添加/var/log/httpd/目录的读+执行权限:
setfacl -m u:vector:rx /var/log/httpd/
  1. 验证权限是否生效:
getfacl /var/log/httpd/

确认输出中user:vector:r-x存在即可。
3. 测试访问:切换到vector用户,执行以下命令验证:

cd /var/log/httpd/
cat myapp.co.uk/logfile.log

内容的提问来源于stack exchange,提问作者Confounder

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.23 13:07:32