You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Rocky Linux下sudo执行nginx -t遭遇SELinux权限拒绝问题求助

Rocky Linux下sudo执行nginx -t遭遇SELinux权限拒绝问题求助

各位大佬好,我正在部署Rocky Linux,结果执行nginx配置检查的时候碰到权限问题了,具体情况如下:

我执行了这条命令:

sudo nginx -t

得到的错误输出是:

nginx: the configuration file /etc/nginx/nginx.conf syntax is ok
nginx: [emerg] bind() to 0.0.0.0:80 failed (13: Permission denied)
nginx: configuration file /etc/nginx/nginx.conf test failed

然后我查了自己用户和sudo后的SELinux上下文信息:
普通用户下执行id -Z的结果:

staff_u:staff_r:staff_t:s0-s0:c0.c1023

执行sudo -s后再查id -Z的结果是正常的:

staff_u:sysadm_r:sysadm_t:s0-s0:c0.c1023

我的sudoer规则配置是这样的:

USERNAME ALL=(ALL) ROLE=sysadm_r TYPE=sysadm_t NOPASSWD: ALL

我是按照管理员受限配置的步骤来做的,但还是出问题了。

一开始没找到日志,我关掉了dontaudit规则后,用这条命令查了审计日志:

ausearch -m AVC,USER_AVC,SELINUX_ERR,USER_SELINUX_ERR -ts recent

得到的日志内容如下:

time->Fri Oct  6 17:02:35 2023

type=PROCTITLE msg=audit(1696611755.583:1149): proctitle=7375646F006E67696E78002D74

type=PATH msg=audit(1696611755.583:1149): item=0 name="/lib64/ld-linux-x86-64.so.2" inode=8668 dev=fd:02 mode=0100755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:ld_so_t:s0 nametype=NORMAL cap_fp=0 cap_fi=0 cap_fe=0 cap_fver=0 cap_frootid=0

type=CWD msg=audit(1696611755.583:1149): cwd="/home/USERNAME"

type=EXECVE msg=audit(1696611755.583:1149): argc=3 a0="sudo" a1="nginx" a2="-t"

type=SYSCALL msg=audit(1696611755.583:1149): arch=c000003e syscall=59 success=yes exit=0 a0=56233d0695a0 a1=56233d1800a0 a2=56233cffae40 a3=8 items=1 ppid=6128 pid=11286 auid=1000 uid=1000 gid=1000 euid=0 suid=0 fsuid=0 egid=1000 sgid=1000 fsgid=1000 tty=pts0 ses=3 comm="sudo" exe="/usr/bin/sudo" subj=staff_u:staff_r:staff_sudo_t:s0-s0:c0.c1023 key=(null)

type=AVC msg=audit(1696611755.583:1149): avc:  denied  { siginh } for  pid=11286 comm="sudo" scontext=staff_u:staff_r:staff_t:s0-s0:c0.c1023 tcontext=staff_u:staff_r:staff_sudo_t:s0-s0:c0.c1023 tclass=process permissive=0

type=AVC msg=audit(1696611755.583:1149): avc:  denied  { rlimitinh } for  pid=11286 comm="sudo" scontext=staff_u:staff_r:staff_t:s0-s0:c0.c1023 tcontext=staff_u:staff_r:staff_sudo_t:s0-s0:c0.c1023 tclass=process permissive=0

type=AVC msg=audit(1696611755.583:1149): avc:  denied  { noatsecure } for  pid=11286 comm="bash" scontext=staff_u:staff_r:staff_t:s0-s0:c0.c1023 tcontext=staff_u:staff_r:staff_sudo_t:s0-s0:c0.c1023 tclass=process permissive=0

我发现问题所在了:执行sudo nginx -t的时候,进程的SELinux上下文还是staff_u:staff_r:staff_t:s0-s0:c0.c1023,而不是预期的staff_u:sysadm_r:sysadm_t:s0-s0:c0.c1023。

我对SELinux这块不太熟,有没有大佬能帮忙看看怎么解决?

另外补充一下audit2allow -a的输出结果:

#============= chkpwd_t ==============

allow chkpwd_t user_devpts_t:chr_file { read write };

#============= init_t ==============

allow init_t unconfined_service_t:process siginh;

#============= staff_sudo_t ==============

allow staff_sudo_t chkpwd_t:process { noatsecure rlimitinh siginh };

allow staff_sudo_t self:capability net_admin;

allow staff_sudo_t shadow_t:file read;

allow staff_sudo_t sysadm_t:process { noatsecure rlimitinh siginh };

#============= staff_t ==============

allow staff_t staff_sudo_t:process { noatsecure rlimitinh siginh };

#============= sysadm_t ==============

allow sysadm_t http_port_t:tcp_socket name_bind;

还有nginx配置目录的SELinux上下文信息:
执行sudo ls -Z /etc/nginx的结果:

system_u:object_r:httpd_config_t:s0 conf.d
system_u:object_r:httpd_config_t:s0 fastcgi_params
system_u:object_r:httpd_config_t:s0 mime.types
system_u:object_r:httpd_config_t:s0 modules
system_u:object_r:httpd_config_t:s0 nginx.conf
system_u:object_r:httpd_config_t:s0 scgi_params
system_u:object_r:httpd_config_t:s0 uwsgi_params

执行sudo ls -Z /etc/nginx/conf.d的结果:

system_u:object_r:httpd_config_t:s0 default.conf

备注:内容来源于stack exchange,提问作者Blue Nomad

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.21 11:49:37