SELinux下clamd与php/apache共享日志文件权限问题求助
Great question—this is a super common SELinux permission conflict when two different services need access to the same file, and it’s tricky because each service expects a specific security context. Let’s walk through the best solutions, since setting SELinux to permissive isn’t an option for you.
1. Custom SELinux Policy Module (Recommended)
This is the most secure and sustainable fix, as it creates a targeted rule that lets both clamd and apache/php access the log file without breaking existing security boundaries.
Follow these steps:
- First, restore the log file to its default SELinux context (undo your earlier type change):
restorecon -v /var/log/clamav/clamd.log - Next, capture the SELinux denial logs that occur when
apache/phptries to access the file. You can useaudit2allowto automatically generate a policy template:# Capture recent AVC denials related to clamd.log ausearch -m avc -ts recent | grep clamd.log > clamd_httpd_denials.log # Generate a policy module from the denials audit2allow -i clamd_httpd_denials.log -M clamd_httpd_log - Load the generated policy module to apply the rules:
semodule -i clamd_httpd_log.pp
This module will explicitly grant apache/php the necessary permissions to read (and write, if needed) the var_log_t-labeled clamd.log file, while leaving clamd’s ability to write to the log intact.
2. Using SELinux Multi-Category Security (MCS)
If you prefer a quicker (but slightly less targeted) approach, you can add a custom security category to the log file and grant both services access to that category:
- Assign a unique category to the log file (we’ll use
c100as an example):chcon -t var_log_t -l s0:c100 /var/log/clamav/clamd.log - Update the file context rules to make this change persistent across reboots:
semanage fcontext -a -t var_log_t -l s0:c100 "/var/log/clamav/clamd.log" restorecon -v /var/log/clamav/clamd.log - Grant both
clamd_tandhttpd_tdomains access to thec100category:semanage category -a c100 semanage domain -m -s s0 -r s0-s0:c0.c100 clamd_t semanage domain -m -s s0 -r s0-s0:c0.c100 httpd_t
This lets both services interact with files labeled with the c100 category, including your log file.
3. "Ignore" the File (Not Recommended)
SELinux doesn’t have a built-in "ignore this file" option, but you can label the file with the unlabeled_t type, which effectively bypasses SELinux controls for it. This is not secure and should only be used as a last resort:
chcon -u unconfined_u -r object_r -t unlabeled_t /var/log/clamav/clamd.log
To make this persistent:
semanage fcontext -a -t unlabeled_t "/var/log/clamav/clamd.log" restorecon -v /var/log/clamav/clamd.log
Quick Check: Existing Boolean Settings
Before diving into custom policies, you can check if there’s a pre-existing SELinux boolean that might solve your issue. Run this command to see relevant booleans for Apache log access:
getsebool -a | grep httpd | grep log
For example, httpd_can_read_syslog might allow Apache to read system logs, but it won’t grant write access if that’s what you need.
内容的提问来源于stack exchange,提问作者Saragan

