RHEL系统Docker部署Mailcow的SELinux权限问题求助
解决RHEL系统Docker部署Mailcow的SELinux权限问题
问题现象
- RHEL系统中Docker部署Mailcow后出现空白屏,SELinux阻止
php-fpm进程读取/web/inc/init_db.inc.php文件
审计日志
type=AVC msg=audit(1676319004.771:1087): avc: denied { read } for pid=14555 comm="php-fpm" name="init_db.inc.php" dev="dm-0" ino=135058961 scontext=system_u:system_r:container_t:s0:c706,c972 tcontext=system_u:object_r:container_file_t:s0:c89,c575 tclass=file permissive=0 type=SYSCALL msg=audit(1676319004.771:1087): arch=c000003e syscall=2 success=no exit=-13 a0=7fffc4e15850 a1=8000 a2=0 a3=0 items=1 ppid=6637 pid=14555 auid=4294967295 uid=82 gid=82 euid=82 suid=82 fsuid=82 egid=82 sgid=82 fsgid=82 tty=(none) ses=4294967295 comm="php-fpm" exe="/usr/local/sbin/php-fpm" subj=system_u:system_r:container_t:s0:c706,c972 key=(null) type=CWD msg=audit(1676319004.771:1087): cwd="/web" type=PATH msg=audit(1676319004.771:1087): item=0 name="/web/inc/init_db.inc.php" inode=135058961 dev=fd:00 mode=0100666 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:container_file_t:s0:c89,c575 nametype=NORMAL cap_fp=0 cap_fi=0 cap_fe=0 cap_fver=0 cap_frootid=0
尝试的解决命令及错误
执行以下命令时出现编译失败:
ausearch -c 'php' --raw | audit2allow -M my-php semodule -X 300 -i my-php.pp
错误输出:
compilation failed: my-php.te:15:ERROR 'syntax error' at token 'mlsconstrain' on line 15: # mlsconstrain file { ioctl read lock execute execute_no_trans } ((h1 dom h2 -Fail-) or (t1 != mcs_constrained_type -Fail-) ); Constraint DENIED mlsconstrain file { write setattr append unlink link rename } ((h1 dom h2 -Fail-) or (t1 != mcs_constrained_type -Fail-) ); Constraint DENIED /usr/bin/checkmodule: error(s) encountered while parsing configuration [root@rhel ~]# semodule -X 300 -i my-php.pp libsemanage.map_compressed_file: Unable to open my-php.pp (No such file or directory). libsemanage.semanage_direct_install_file: Unable to read file my-php.pp (No such file or directory). semodule: Failed on my-php.pp!
解决方法
方法1:生成正确的自定义SELinux模块(永久解决)
问题出在audit2allow抓取了全局的mlsconstrain规则,这些规则不能被自定义模块修改,需要过滤后重新生成:
- 精准提取相关的AVC拒绝日志:
ausearch -m avc -ts recent | grep -A 2 -B 2 "init_db.inc.php" --raw | audit2allow -M my-mailcow-php
- 编辑生成的
my-mailcow-php.te文件,删除所有包含mlsconstrain的行(这些是系统级约束,无需包含在自定义模块中) - 重新编译并加载模块:
checkmodule -M -m -o my-mailcow-php.mod my-mailcow-php.te semodule_package -o my-mailcow-php.pp -m my-mailcow-php.mod semodule -i my-mailcow-php.pp
方法2:临时调整文件SELinux上下文(快速验证)
如果需要快速验证是否为SELinux导致的问题,可以修改挂载目录的SELinux上下文:
# 替换为你的Mailcow web目录实际路径 chcon -Rt container_file_t /opt/mailcow-dockerized/data/web/inc/
方法3:Docker运行时指定SELinux安全选项
在启动Mailcow容器时,添加SELinux标签选项,确保容器进程能访问挂载文件:
- 单容器启动:
docker run --security-opt label=type:container_file_t [其他Mailcow容器参数]
- docker-compose部署:在对应的php-fpm服务中添加配置:
services: php-fpm-mailcow: ... security_opt: - label=type:container_file_t
内容的提问来源于stack exchange,提问作者ArchMatt
相关产品推荐
相关产品推荐

