You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

SELinux下clamd与php/apache共享日志文件权限问题求助

Great question—this is a super common SELinux permission conflict when two different services need access to the same file, and it’s tricky because each service expects a specific security context. Let’s walk through the best solutions, since setting SELinux to permissive isn’t an option for you.

This is the most secure and sustainable fix, as it creates a targeted rule that lets both clamd and apache/php access the log file without breaking existing security boundaries.

Follow these steps:

  • First, restore the log file to its default SELinux context (undo your earlier type change):
    restorecon -v /var/log/clamav/clamd.log
    
  • Next, capture the SELinux denial logs that occur when apache/php tries to access the file. You can use audit2allow to automatically generate a policy template:
    # Capture recent AVC denials related to clamd.log
    ausearch -m avc -ts recent | grep clamd.log > clamd_httpd_denials.log
    # Generate a policy module from the denials
    audit2allow -i clamd_httpd_denials.log -M clamd_httpd_log
    
  • Load the generated policy module to apply the rules:
    semodule -i clamd_httpd_log.pp
    

This module will explicitly grant apache/php the necessary permissions to read (and write, if needed) the var_log_t-labeled clamd.log file, while leaving clamd’s ability to write to the log intact.

2. Using SELinux Multi-Category Security (MCS)

If you prefer a quicker (but slightly less targeted) approach, you can add a custom security category to the log file and grant both services access to that category:

  • Assign a unique category to the log file (we’ll use c100 as an example):
    chcon -t var_log_t -l s0:c100 /var/log/clamav/clamd.log
    
  • Update the file context rules to make this change persistent across reboots:
    semanage fcontext -a -t var_log_t -l s0:c100 "/var/log/clamav/clamd.log"
    restorecon -v /var/log/clamav/clamd.log
    
  • Grant both clamd_t and httpd_t domains access to the c100 category:
    semanage category -a c100
    semanage domain -m -s s0 -r s0-s0:c0.c100 clamd_t
    semanage domain -m -s s0 -r s0-s0:c0.c100 httpd_t
    

This lets both services interact with files labeled with the c100 category, including your log file.

SELinux doesn’t have a built-in "ignore this file" option, but you can label the file with the unlabeled_t type, which effectively bypasses SELinux controls for it. This is not secure and should only be used as a last resort:

chcon -u unconfined_u -r object_r -t unlabeled_t /var/log/clamav/clamd.log

To make this persistent:

semanage fcontext -a -t unlabeled_t "/var/log/clamav/clamd.log"
restorecon -v /var/log/clamav/clamd.log

Quick Check: Existing Boolean Settings

Before diving into custom policies, you can check if there’s a pre-existing SELinux boolean that might solve your issue. Run this command to see relevant booleans for Apache log access:

getsebool -a | grep httpd | grep log

For example, httpd_can_read_syslog might allow Apache to read system logs, but it won’t grant write access if that’s what you need.

内容的提问来源于stack exchange,提问作者Saragan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.27 10:02:42