You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

RHEL系统Docker部署Mailcow的SELinux权限问题求助

解决RHEL系统Docker部署Mailcow的SELinux权限问题

问题现象

  • RHEL系统中Docker部署Mailcow后出现空白屏,SELinux阻止php-fpm进程读取/web/inc/init_db.inc.php文件

审计日志

type=AVC msg=audit(1676319004.771:1087): avc: denied { read } for pid=14555 comm="php-fpm" name="init_db.inc.php" dev="dm-0" ino=135058961 scontext=system_u:system_r:container_t:s0:c706,c972 tcontext=system_u:object_r:container_file_t:s0:c89,c575 tclass=file permissive=0
type=SYSCALL msg=audit(1676319004.771:1087): arch=c000003e syscall=2 success=no exit=-13 a0=7fffc4e15850 a1=8000 a2=0 a3=0 items=1 ppid=6637 pid=14555 auid=4294967295 uid=82 gid=82 euid=82 suid=82 fsuid=82 egid=82 sgid=82 fsgid=82 tty=(none) ses=4294967295 comm="php-fpm" exe="/usr/local/sbin/php-fpm" subj=system_u:system_r:container_t:s0:c706,c972 key=(null)
type=CWD msg=audit(1676319004.771:1087): cwd="/web"
type=PATH msg=audit(1676319004.771:1087): item=0 name="/web/inc/init_db.inc.php" inode=135058961 dev=fd:00 mode=0100666 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:container_file_t:s0:c89,c575 nametype=NORMAL cap_fp=0 cap_fi=0 cap_fe=0 cap_fver=0 cap_frootid=0

尝试的解决命令及错误

执行以下命令时出现编译失败:

ausearch -c 'php' --raw | audit2allow -M my-php semodule -X 300 -i my-php.pp

错误输出:

compilation failed:
my-php.te:15:ERROR 'syntax error' at token 'mlsconstrain' on line 15:
#       mlsconstrain file { ioctl read lock execute execute_no_trans } ((h1 dom h2 -Fail-)  or (t1 != mcs_constrained_type -Fail-) ); Constraint DENIED
mlsconstrain file { write setattr append unlink link rename } ((h1 dom h2 -Fail-)  or (t1 != mcs_constrained_type -Fail-) ); Constraint DENIED
/usr/bin/checkmodule:  error(s) encountered while parsing configuration
[root@rhel ~]# semodule -X 300 -i my-php.pp
libsemanage.map_compressed_file: Unable to open my-php.pp
 (No such file or directory).
libsemanage.semanage_direct_install_file: Unable to read file my-php.pp
 (No such file or directory).
semodule:  Failed on my-php.pp!

解决方法

方法1:生成正确的自定义SELinux模块(永久解决)

问题出在audit2allow抓取了全局的mlsconstrain规则,这些规则不能被自定义模块修改,需要过滤后重新生成:

  1. 精准提取相关的AVC拒绝日志:
ausearch -m avc -ts recent | grep -A 2 -B 2 "init_db.inc.php" --raw | audit2allow -M my-mailcow-php
  1. 编辑生成的my-mailcow-php.te文件,删除所有包含mlsconstrain的行(这些是系统级约束,无需包含在自定义模块中)
  2. 重新编译并加载模块:
checkmodule -M -m -o my-mailcow-php.mod my-mailcow-php.te
semodule_package -o my-mailcow-php.pp -m my-mailcow-php.mod
semodule -i my-mailcow-php.pp

方法2:临时调整文件SELinux上下文(快速验证)

如果需要快速验证是否为SELinux导致的问题,可以修改挂载目录的SELinux上下文:

# 替换为你的Mailcow web目录实际路径
chcon -Rt container_file_t /opt/mailcow-dockerized/data/web/inc/

方法3:Docker运行时指定SELinux安全选项

在启动Mailcow容器时,添加SELinux标签选项,确保容器进程能访问挂载文件:

  • 单容器启动:
docker run --security-opt label=type:container_file_t [其他Mailcow容器参数]
  • docker-compose部署:在对应的php-fpm服务中添加配置:
services:
  php-fpm-mailcow:
    ...
    security_opt:
      - label=type:container_file_t

内容的提问来源于stack exchange,提问作者ArchMatt

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.31 16:00:59