Re: Trying again: why am I getting denials in a directory that has been labeled...

Paul Howarth <[email protected]>
Newsgroups gmane.linux.redhat.fedora.selinux
Message-ID <[email protected]>
On Thu, 14 Jun 2018 14:21:26 -0400
[email protected] wrote:

> Jason L Tibbitts III wrote:
> > Not sure if you realize, but you didn't actually include any
> > information about the denial you are receiving.  It's kind of tough
> > to guess at what it might be.  
> 
> SELinux is preventing Count.cgi from write access on the file...
> Source Context                system_u:system_r:httpd_sys_script_t:s0
> Target Context               
> unconfined_u:object_r:httpd_sys_script_exec_t:s0
> Policy RPM                    selinux-policy-3.13.1-192.el7_5.3.noarch
> Raw Audit Messages
> type=AVC msg=audit(1528998541.365:53668): avc:  denied  { write } for 
> pid= <snip> scontext=system_u:system_r:httpd_sys_script_t:s0
> tcontext=unconfined_u:object_r:httpd_sys_script_exec_t:s0 tclass=file
> 
> Better?

The file you want to write to should probably be
httpd_sys_rw_content_t rather than httpd_sys_script_exec_t.

Paul.
_______________________________________________
selinux mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/[email protected]/message/JHEGQQVA65EHGZGO53ZJZRDRQYCAW2AZ/
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.