Portál AbcLinuxu, 8. května 2025 04:02
Řešení dotazu:
# sesearch -A -s syslogd_t -t httpd_log_t -c file -p write Found 1 semantic av rules: allow syslogd_t logfile : file { ioctl read write create getattr setattr lock append unlink link rename open } ; # seinfo -x -alogfile | grep httpd httpd_log_t # sesearch -A -s httpd_t -t httpd_log_t -c file -p read Found 1 semantic av rules: allow httpd_t httpd_log_t : file { ioctl read create getattr setattr lock append open } ;v rhel-7 na to je dokonce utilita:
# sepolicy communicate -s syslogd_t -t httpd_t -c file nagios_log_t security_t cluster_var_lib_t cluster_var_run_t mirrormanager_log_t httpd_log_t dirsrv_var_log_t pki_ra_log_t root_t cluster_conf_t krb5_host_rcache_t keystone_log_t pki_tps_log_t jetty_log_t
Tiskni
Sdílej:
ISSN 1214-1267, (c) 1999-2007 Stickfish s.r.o.