You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Fedora下配置Samba共享磁盘驱动器遇SELinux权限问题,已设置fcontext仍报错的排查求助

Fedora下配置Samba共享磁盘驱动器遇SELinux权限问题,已设置fcontext仍报错的排查求助

各位好,我现在在Fedora系统上配置Samba,想把本地磁盘驱动器共享给虚拟机使用。目前只要执行sudo setenforce 0临时关闭SELinux,共享就能正常工作,显然问题出在SELinux的权限配置上。

我已经设置了这些SELinux文件上下文规则:

sudo semanage fcontext -l | grep samba

对应的输出结果是:

/home/hanuman(/.*)?                                all files          system_u:object_r:samba_share_t:s0 
/run/media/hanuman(/.*)?                           all files          system_u:object_r:samba_share_t:s0 

但共享还是无法正常运行,我查看SELinux审计日志时发现了这条报错:

type=AVC msg=audit(1718035536.971:480): avc:  denied  { getattr } for  pid=7754 comm="smbd[192.168.1." path=2F72756E2F6D656469612F68616E756D616E2F53746F726167652D6E7466732F4D6F73742042656175746966756C204368696E65736520536F6E6720596F752077696C6C20457665722048656172203230313020323031352E6D7033 dev="sda1" ino=228609 scontext=system_u:system_r:smbd_t:s0 tcontext=system_u:object_r:fusefs_t:s0 tclass=file permissive=0

我注意到日志里Samba进程的安全上下文是smbd_t,而被访问文件的上下文是fusefs_t,并不是我之前设置的samba_share_t。想请教下这两者的区别是什么?我到底哪里配置遗漏了,才会导致权限被拒绝呢?


备注:内容来源于stack exchange,提问作者Etienne Charland

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.16 12:12:57