问答文章1 问答文章501 问答文章1001 问答文章1501 问答文章2001 问答文章2501 问答文章3001 问答文章3501 问答文章4001 问答文章4501 问答文章5001 问答文章5501 问答文章6001 问答文章6501 问答文章7001 问答文章7501 问答文章8001 问答文章8501 问答文章9001 问答文章9501


发布网友 发布时间:2022-04-25 13:14



懂视网 时间:2022-04-12 14:18

When you create the linux file node, such as “dev/nfccard0”, you must add the selinux policy for it, or the application can not get the permit to access. this is an example for the system_server to accecc the dev/nfccard0 file node. we c

When you create the linux file node, such as “dev/nfccard0”, you must add the selinux policy for it, or the application can not get the permit to access.

this is an example for the system_server to accecc the dev/nfccard0 file node.

we can do the following three things to mak the system work smoothly.

1 define the file type

in the file.te add the below line

type nfccard_device,dev_type

2 define the file context

in the file_context.te add the below line

/dev/nfccard0 u:object_r:nfccard_devicd:s0

3 allow the system_server to access it.

Allow system_server nfccard_device:chr_file rw_file_perms


Allow system_server nfccard_device:chr_file {read write open getattr ioctl}

there are many file type , {socket, binder, property,etc}, we must do carefully to avoid influence the system.

热心网友 时间:2022-04-12 11:26

  shell> getenforce

  shell> sestatus
SELinux status: enabled
SELinuxfs mount: /selinux
Current mode: enforcing
Mode from config file: enforcing
Policy version: 24
Policy from config file: targeted

  shell> cat /root/test.html
hello, world.

  shell> cp /root/test.html /var/www/html

  shell> curl http://localhost/test.html
hello, world.

  shell> mv /root/test.html /var/www/html

  shell> curl http://localhost/test.html
<title>403 Forbidden</title>
<p>You don't have permission to access /test.html
on this server.</p>

  shell> audit2why < /var/log/audit/audit.log

  shell> yum install setroubleshoot

  shell> sealert -a /var/log/audit/audit.log

SELinux is preventing /usr/sbin/httpd "getattr" access to

Detailed Description:

SELinux denied access requested by httpd. /var/www/html/test.html may be a
mislabeled. /var/www/html/test.html default SELinux type is httpd_sys_content_t,
but its current type is admin_home_t. Changing this file back to the default
type, may fix your problem.

File contexts can be assigned to a file in the following ways.

* Files created in a directory receive the file context of the parent
directory by default.
* The SELinux policy might override the default label inherited from the
parent directory by specifying a process running in context A which creates
a file in a directory labeled B will instead create the file with label C.
An example of this would be the dhcp client running with the dhclient_t type
and creating a file in the directory /etc. This file would normally receive
the etc_t type e to parental inheritance but instead the file is labeled
with the net_conf_t type because the SELinux policy specifies this.
* Users can change the file context on a file using tools such as chcon, or

This file could have been mislabeled either by user error, or if an normally
confined application was run under the wrong domain.

However, this might also indicate a bug in SELinux because the file should not
have been labeled with this type.

If you believe this is a bug, please file a bug report against this package.

Allowing Access:

You can restore the default system context to this file by executing the
restorecon command. restorecon '/var/www/html/test.html', if this file is a
directory, you can recursively restore using restorecon -R

Fix Command:

/sbin/restorecon '/var/www/html/test.html'

  shell> ls -Z /path

  注:关于SELinux和Apache的详细介绍,可以参考『man httpd_selinux』。

热心网友 时间:2022-04-12 12:44


热心网友 时间:2022-04-12 14:19

上面有个小错,应该是echo "0" > /selinux/enforce (少了>)selinux如果有开很容易造成ifind问题,参看下面系统日志Aug 2 20:52:06 cc-lnx-imglib setroubleshoot: SELinux is preventing /opt/simpana/iDataAgent/ifind "execstack" access to . For complete SELinux messages. run sealert -l 4a0b3993-b18f-4c72-9e1d-4f5d8175ad41Jul 31 00:30:09 cc-lnx-imglib setroubleshoot: SELinux is preventing /bin/hostname access to a leaked /tmp/.gxsetup/cvpkglo g.pipe.26262 file descriptor. For complete SELinux messages. run sealert -l e675a6a6-efc9-461f-b794-784c0fd2d308

热心网友 时间:2022-04-12 16:10

别一种查看SElinux方法:# sestatusSELinux status: disabled
哪种颜色款式的拉丁舞服装好看 初学拉丁舞穿裤还是裙 有时 有时 有时造句 诺基亚n73手机地图2008年新版的在哪可以下? 我用n73上网,怎么样可以下载地图包 NOKIA N73手机地图问题 脖子里面长了个硬疙瘩 开始有点硬。 不发红。 现在中间有点红, 变软了。 周边有点硬 手相真的能看出一个人的命运吗 双色球蓝球明晚开什么 索道是什么呢 Ext.getCmp(&#39;cardIn&#39;).disable(&#39;true&#39;); 有效 Ext.getCmp(&#39;cardIn... 为什么我的DELL电脑重装后开机出现警报声,说找不到驱动,但按F1,又能... phalcon是有个bug的? 如何提高电脑开机速度~~ 求助Easyui datagrid 的默认选中问题 【简单】改一句代码就行 easyui datagrid 怎样默认为全选数据 谁帮我翻译一下这段英文?电脑方面的 jquery如何获取整个页面文本框属性为disabled的id ,并用循环遍历出内容... WebDriver到底怎么用 写一个HTML页面,实现以下功能 如何在javascript中让一个链接变成灰色,不可点击? 如何启动cookie(转)How to Enable Cookies 开机后屏幕显示“alert! Cover was prviously removed”,什么意思... 2018年江苏省盐城市、南京市高考英语二模试卷 含解析 全国高考二卷是哪些省市专考的? 2018年高考英语分不分乙、甲、丙卷 直播伴侣可以推流到视频号嘛 2018年高考试题及答案(全国2卷、全国二卷)(英语)(高清) 索道 什么意思 谁能用简单文字 详细解释 谢谢你 谁给 个easyui里面datagrid的例子,用json加载 的例子 如何让外观专利无效 什么是索道?为什么爬山时有人走索道??? dell 服务器开机报错 外观专利无效的条件 索道和缆车的区别是什么?? 如何调出OneThink的ueditor编辑器 索道和缆车的区别是什么? 什么情况下外观专利无效 jquery easyui怎么动态改treegrid表上的toolbar的按钮的样式和文字... 太白山索道是什么? 如何申请专利专利宣告专利无效 什么是索道运输,有什么技术要求? 无效外观专利需要什么证据 缆车与索道有什么区别? 怎样认定外观设计专利的无效 “华山西峰索道”的简介是什么? 怎么申请对方专利无效 八大处索道是什么?滑道是什么?都多少钱?学生能打折吗?