{"id":242,"date":"2013-11-15T11:42:19","date_gmt":"2013-11-15T02:42:19","guid":{"rendered":"http:\/\/darkgray.homelinux.com\/modules\/xpress\/?p=242"},"modified":"2013-11-15T11:42:19","modified_gmt":"2013-11-15T02:42:19","slug":"selinux%e3%81%ae%e3%83%9d%e3%83%aa%e3%82%b7%e3%83%bc%e3%82%92%e4%bf%ae%e6%ad%a3%e3%81%99%e3%82%8b%e3%80%82","status":"publish","type":"post","link":"https:\/\/darkgray.homelinux.com\/blog\/?p=242","title":{"rendered":"SELinux\u306e\u30dd\u30ea\u30b7\u30fc\u3092\u4fee\u6b63\u3059\u308b\u3002"},"content":{"rendered":"<p><a href=\"http:\/\/darkgray.homelinux.com\/modules\/xpress\/?p=235\" target=\"_blank\" rel=\"noopener noreferrer\">\u524d\u56de\u306e\u8a18\u4e8b<\/a>\u3067quota\u306e\u521d\u671f\u5316\u306b\u5931\u6557\u3057\u305f\u3002\u305d\u3053\u3067quota\u3068Selinux\u306e\u7d61\u3093\u3060\u8a18\u4e8b\u3092\u691c\u7d22\u3057\u3066\u8abf\u3079\u3066\u307f\u305f\u3002<\/p>\n<p>\u305d\u306e\u7d50\u679c\u3000\u3053\u308c\u3068\u8a00\u3063\u305f\u89e3\u6c7a\u7b56\u306f\u898b\u3064\u304b\u3089\u306a\u304b\u3063\u305f\u3002\u3000\u65e5\u672c\u8a9e\u306e\u30da\u30fc\u30b8\u306b\u81f3\u3063\u3066\u306f\u3000\u300cSelinux\u3092\u5916\u3057\u3066\u3057\u307e\u3048\u300d\u3068\u8a00\u3046\u8a18\u4e8b\u3057\u304b\u898b\u3064\u304b\u3089\u306a\u304b\u3063\u305f\u3002\u3053\u308c\u306f\u3082\u3046\u30dd\u30ea\u30b7\u30fc\u3092\u4fee\u6b63\u3059\u308b\u3057\u304b\u306d\u30fc\u3079\u3063\u3066\u4e8b\u3067\u3000Selinux\u306e\u30dd\u30ea\u30b7\u30fc\u3092\u30b4\u30cb\u30e7\u30b4\u30cb\u30e7\u3057\u3066\u307f\u308b\u3002<br \/>\n<!--more--><\/p>\n<p>\u53c2\u8003URL:\u3000<a href=\"http:\/\/fdays.blogspot.jp\/2010\/03\/selinux.html\" target=\"_blank\" rel=\"noopener noreferrer\">http:\/\/fdays.blogspot.jp\/2010\/03\/selinux.html<\/a><\/p>\n<p><span style=\"color: #ff6600;\" data-mce-mark=\"1\">\u6ce8\u610f\uff1a<\/span>\u3000\u4e0b\u8a18\u306e\u65b9\u6cd5\u3067Selinux\u306e\u30dd\u30ea\u30b7\u30fc\u3092\u66f8\u304d\u63db\u3048\u308b\u306e\u306f\u3000\u6700\u7d42\u624b\u6bb5\u3067\u3042\u3063\u3066\u3000\u4f55\u3067\u3082\u304b\u3093\u3067\u3082\u3053\u306e\u65b9\u6cd5\u3092\u53d6\u308b\u3079\u304d\u3067\u306f\u306a\u3044\u3068\u601d\u3046\u3002\u3000\u4eca\u56de\u306fquota\u3068Selinux\u306e\u95a2\u4fc2\u3067\u8a2d\u5b9a\u3059\u308b\u65b9\u6cd5\u304c\u898b\u3064\u304b\u3089\u306a\u304b\u3063\u305f\u306e\u3067\u3000\u6700\u7d42\u624b\u6bb5\u3092\u3068\u3063\u305f\u3002\u3000Selinux\u306e\u305d\u306e\u4ed6\u306e\u8a2d\u5b9a\u65b9\u6cd5\u3092\u77e5\u308a\u305f\u3044\u4eba\u306f\u3000\u4e0a\u306e\u53c2\u8003\u30ea\u30f3\u30af\u3092\u8fbf\u3063\u3066\u8abf\u3079\u3066\u307b\u3057\u3044\u3002<\/p>\n<p><strong>\u30a8\u30e9\u30fc\u306e\u30ed\u30b0\u3092\u53d6\u308b\u3002<\/strong><br \/>\n[bash]<br \/>\n# setenforce 0\u3000      !Selinux\u3092\u4e00\u6642\u7684\u306b\u30b9\u30c8\u30c3\u30d7\u3057\u3066\u30a8\u30e9\u30fc\u30ed\u30b0\u3092\u53ce\u96c6<br \/>\n# quotacheck -avugm   !\u30a8\u30e9\u30fc\u306e\u767a\u751f\u3057\u3066\u308b\u30b3\u30de\u30f3\u30c9\u3092\u5b9f\u884c<br \/>\n# setenforce 1        !Selinux\u3092\u6709\u52b9\u306b\u3059\u308b<br \/>\n# ausearch -m avc     !\u30a8\u30e9\u30fc\u30ed\u30b0\u3092\u8868\u793a\u3059\u308b<br \/>\n[\/bash]<\/p>\n<p><strong>\u30a8\u30e9\u30fc\u30ed\u30b0\u306f\u3053\u3093\u306a\u611f\u3058<\/strong><br \/>\n[bash]<br \/>\n&#8212;-<br \/>\ntime-&gt;Fri Nov 15 09:22:48 2013<br \/>\ntype=SYSCALL \u30fb\u30fb\u30fb\u30bb\u30ad\u30e5\u30ea\u30c6\u30a4\u4e0a\u306e\u7406\u7531\u306b\u3088\u308a\u4ee5\u5f8c\u7701\u7565<br \/>\ntype=AVC \u3000\u30fb\u30fb\u30fb\u30fb\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u4e0a\u306e\u7406\u7531\u306b\u3088\u308a\u4ee5\u5f8c\u7701\u7565<br \/>\n&#8212;-<br \/>\n[\/bash]<br \/>\n\u30de\u30a4\u30ca\u30b9\u3067\u5404\u30a8\u30e9\u30fc\u306e\u9805\u76ee\u304c\u533a\u5207\u3089\u308c\u3066\u308b\u3002\u5404\u9805\u306e\u884c\u982d\u306e\u6642\u9593\u3067\u3000\u4eca\u56de\u306e\u30a8\u30e9\u30fc\u304b\u4ee5\u524d\u306e\u30a8\u30e9\u30fc\u304b\u5224\u65ad\u3057\u3066\u3000\u4eca\u56de\u306e\u30a8\u30e9\u30fc\u306e\u9805\u3060\u3051\u5225\u30d5\u30a1\u30a4\u30eb\u306b\u3057\u3066\u4fdd\u5b58\u3059\u308b\u3002<\/p>\n<p><strong>\u30a8\u30e9\u30fc\u30ed\u30b0\u304b\u3089\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u30dd\u30ea\u30b7\u30fc\u3092\u66f4\u65b0\u3059\u308b\u3002<\/strong><br \/>\n[bash]<br \/>\n# audit2allow -M local -i &lt;\u629c\u304d\u51fa\u3057\u305f\u30ed\u30b0&gt;<br \/>\n# semodule -i local.pp<br \/>\n[\/bash]<br \/>\n\u30dd\u30ea\u30b7\u30fc\u306e\u66f4\u65b0\u304c\u51fa\u6765\u305f\u3089\u30a8\u30e9\u30fc\u306e\u767a\u751f\u3057\u305f\u30b3\u30de\u30f3\u30c9\u3092\u5b9f\u884c\u3057\u3066\u8a66\u3057\u3066\u307f\u308b\u3002\u3000\u30a8\u30e9\u30fc\u304c\u307e\u3060\u51fa\u308b\u3088\u3046\u3060\u3063\u305f\u3089\u3000\u3053\u306e\u30da\u30fc\u30b8\u306e\u632f\u308a\u51fa\u3057\u306b\u623b\u3063\u3066\u3000\u30a8\u30e9\u30fc\u306e\u30ed\u30b0\u53d6\u308a\u304b\u3089\u30dd\u30ea\u30b7\u30fc\u306e\u66f4\u65b0\u3092\u7e70\u308a\u8fd4\u3059\u3002\u3000\u4f5c\u696d\u9014\u4e2d\u3067\u51fa\u6765\u305f\u30d5\u30a1\u30a4\u30eb\uff08\u4eca\u56de\u306e\u5834\u5408\u3000\/home\/aquota*\uff09\u306f\u3000Selinux\u306e\u8a2d\u5b9a\u304c\u4e2d\u9014\u534a\u7aef\u306a\u306e\u3067\u3000\u30c6\u30b9\u30c8\uff0f\u8a2d\u5b9a\u3092\u7e70\u308a\u8fd4\u3059\u5834\u5408\u306f\u3000\u305d\u306e\u90fd\u5ea6\u6d88\u3057\u3066\u30c6\u30b9\u30c8\u3059\u308b\u3088\u3046\u306b\u3001\u6b8b\u3057\u3066\u308b\u3068\u3044\u3089\u3093\u30a8\u30e9\u30fc\u304c\u51fa\u3066\u8ff7\u3046\u3088\u3002<\/p>\n<p><strong>\u3067\u3000\u3053\u3093\u306a\u611f\u3058\u306b\u306a\u3063\u305f\u3002<\/strong><br \/>\n[bash]<br \/>\n# quotacheck -avugm<br \/>\nquotacheck: Scanning \/dev\/mapper\/vg_psyche-Lv_home [\/home] done<br \/>\nquotacheck: Cannot stat old user quota file: \u305d\u306e\u3088\u3046\u306a\u30d5\u30a1\u30a4\u30eb\u3084\u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u306f\u3042\u308a\u307e\u305b\u3093<br \/>\nquotacheck: Cannot stat old group quota file: \u305d\u306e\u3088\u3046\u306a\u30d5\u30a1\u30a4\u30eb\u3084\u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u306f\u3042\u308a\u307e\u305b\u3093<br \/>\nquotacheck: Cannot stat old user quota file: \u305d\u306e\u3088\u3046\u306a\u30d5\u30a1\u30a4\u30eb\u3084\u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u306f\u3042\u308a\u307e\u305b\u3093<br \/>\nquotacheck: Cannot stat old group quota file: \u305d\u306e\u3088\u3046\u306a\u30d5\u30a1\u30a4\u30eb\u3084\u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u306f\u3042\u308a\u307e\u305b\u3093<br \/>\nquotacheck: Checked 18870 directories and 317891 files<br \/>\nquotacheck: Old file not found.<br \/>\nquotacheck: Old file not found.<br \/>\n[\/bash]<br \/>\n\u7d50\u5c40\u306e\u6240\u3000quota\u306b\u95a2\u3057\u3066Selinux\u306e\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u5ea6\u304c\u4f4e\u304f\u306a\u3063\u3066\u3057\u307e\u3046\u3068\u8a00\u3046\u3053\u3068\u306a\u306e\u3060\u304c\u30fb\u30fb\u30fb\u3000\u52d5\u304b\u306a\u3044\u3068\u3057\u3087\u3046\u304c\u306a\u3044\u306e\u3067\u3000\u3053\u308c\u3067\u826f\u3057\u3068\u3059\u308b\u3002<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u524d\u56de\u306e\u8a18\u4e8b\u3067quota\u306e\u521d\u671f\u5316\u306b\u5931\u6557\u3057\u305f\u3002\u305d\u3053\u3067quota\u3068Selinux\u306e\u7d61\u3093\u3060\u8a18\u4e8b\u3092\u691c\u7d22\u3057\u3066\u8abf\u3079\u3066\u307f\u305f\u3002 \u305d\u306e\u7d50\u679c\u3000\u3053\u308c\u3068\u8a00\u3063\u305f\u89e3\u6c7a\u7b56\u306f\u898b\u3064\u304b\u3089\u306a\u304b\u3063\u305f\u3002\u3000\u65e5\u672c\u8a9e\u306e\u30da\u30fc\u30b8\u306b\u81f3\u3063\u3066\u306f\u3000\u300cSelinux\u3092\u5916\u3057\u3066\u3057\u307e\u3048\u300d\u3068 &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/darkgray.homelinux.com\/blog\/?p=242\" class=\"more-link\"><span class=\"screen-reader-text\">&#8220;SELinux\u306e\u30dd\u30ea\u30b7\u30fc\u3092\u4fee\u6b63\u3059\u308b\u3002&#8221; \u306e<\/span>\u7d9a\u304d\u3092\u8aad\u3080<\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_bbp_topic_count":0,"_bbp_reply_count":0,"_bbp_total_topic_count":0,"_bbp_total_reply_count":0,"_bbp_voice_count":0,"_bbp_anonymous_reply_count":0,"_bbp_topic_count_hidden":0,"_bbp_reply_count_hidden":0,"_bbp_forum_subforum_count":0,"footnotes":""},"categories":[5,20,21],"tags":[56],"class_list":["post-242","post","type-post","status-publish","format-standard","hentry","category-darkgray-server","category-quota","category-selinux","tag-selinux"],"_links":{"self":[{"href":"https:\/\/darkgray.homelinux.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/242","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/darkgray.homelinux.com\/blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/darkgray.homelinux.com\/blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/darkgray.homelinux.com\/blog\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/darkgray.homelinux.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=242"}],"version-history":[{"count":0,"href":"https:\/\/darkgray.homelinux.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/242\/revisions"}],"wp:attachment":[{"href":"https:\/\/darkgray.homelinux.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=242"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/darkgray.homelinux.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=242"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/darkgray.homelinux.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=242"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}