Advice needed on SELinux policy

nick4soup_at_yahoo.com.au
Date: 05/30/05


Date: 30 May 2005 01:48:44 -0700

Hi,

The basic problem I have is that I cannot run a PHP script that
connects to a MySQL database, when I browse the URL. I have figured
out that this is because of SELinux, refer pertinent log message below.

    /var/log/messages:
      May 23 05:54:22 jervois kernel: audit(1116791662.840:0): avc:
denied { write } for pid=1755 exe=/usr/sbin/httpd name=mysql.sock
dev=dm-0 ino=262316 scontext=user_u:system_r:httpd_t
tcontext=user_u:object_r:var_lib_t tclass=sock_file

I'm running the targeted policy, version 18 in enforcing mode. Is
there a simple change that I can make to the policy so I can get it
working?

In the policy, I notice a httpd_php_t type (and several related ones)
... is this meant to have something to do with it?

Nick Bishop
-----
email replies ignored.
-----
BIBO = Bug In, Bug Out
-oOo-



Relevant Pages

  • Rework [Was: Static vs. Dynamic typing...]
    ... restore which bits, lead to bug hunts. ... the sweep of your changes to those that can honestly fit in your mind. ... your policy makes teamwork impossible. ... taking more than a few days, and had a zero bug count thru the entire ...
    (comp.object)
  • Rework [Was: Static vs. Dynamic typing...]
    ... restore which bits, lead to bug hunts. ... the sweep of your changes to those that can honestly fit in your mind. ... your policy makes teamwork impossible. ... taking more than a few days, and had a zero bug count thru the entire ...
    (comp.programming)
  • Re: dhclient in 6.0
    ... ...it's worth considering the way it standardizes ... DHCP is worthwhile, learning to do ARP also lets us pick up on Bernard ... I'm not really interested in arguing with either you or ISC's policy, ... Because of the placement of the buffer which might be overflowed, it is unlikely this bug will result in serious consequences, however the possibility of a remotely triggered server crash cannot be ruled out. ...
    (freebsd-stable)
  • Re: Do you use SELinux
    ... If it works then don't report a bug unless it returns. ... In those cases where something does need a rule change, ... SELinux policy makers? ... (ftp can be run in two ways anonymous ftp or access to users home dirs. ...
    (Fedora)
  • Re: Interesting Password Behaviour
    ... Honestly, it has been quite a while since I played with policy on a 2K domain, it could be that there was a bug in that on 2K or it wasn't supported, I don't recall. ... have expected that Win2000 DCs also wouldnt store a hashed passsword.. ... Based on my testing all the Win2000 DCs are setting passwords that the ...
    (microsoft.public.win2000.active_directory)