在此之后在我的 Ubuntu 19 安装中启动 MariaDB 失败:
nov 02 16:40:51 farnsworth systemd[1]: Starting MariaDB 10.3.17 database server...
nov 02 16:40:51 farnsworth mysqld[5328]: 2019-11-02 16:40:51 0 [Note] /usr/sbin/mysqld (mysqld 10.3.17-MariaDB-1) starting as process 5328 ...
nov 02 16:40:52 farnsworth audit[5328]: AVC apparmor="ALLOWED" operation="sendmsg" info="Failed name lookup - disconnected path" error=-13 profile="/usr/sbin/mysqld" name="run/systemd/notify" pid=5328 comm="mysqld" requested_mask="w" denied_mask="w" fsuid=123 ouid=0
nov 02 16:40:52 farnsworth audit[5328]: AVC apparmor="ALLOWED" operation="sendmsg" info="Failed name lookup - disconnected path" error=-13 profile="/usr/sbin/mysqld" name="run/systemd/notify" pid=5328 comm="mysqld" requested_mask="w" denied_mask="w" fsuid=123 ouid=0
nov 02 16:40:52 farnsworth systemd[1]: mariadb.service: Main process exited, code=exited, status=1/FAILURE
我创建了一个 apparmor 配置文件,我试图让它允许/usr/sbin/mysqld
在以下位置写入权限run/systemd/notify
:
# Last Modified: Fri Nov 1 22:57:29 2019
#include <tunables/global>
# vim:syntax=apparmor
# AppArmor policy for mysqld
# ###AUTHOR###
# Redacted
# ###COPYRIGHT###
# 2019
# ###COMMENT###
# Ubuntu 19/MariaDB
# No template variables specified
/usr/sbin/mysqld flags=(complain) {
#include <abstractions/base>
#include <abstractions/evince>
#include <abstractions/nameservice>
/etc/mysql/conf.d/ r,
/etc/mysql/conf.d/mysql.cnf r,
/etc/mysql/conf.d/mysqldump.cnf r,
/etc/mysql/mariadb.cnf r,
/etc/mysql/mariadb.conf.d/ r,
/etc/mysql/mariadb.conf.d/50-client.cnf r,
/etc/mysql/mariadb.conf.d/50-mysql-clients.cnf r,
/etc/mysql/mariadb.conf.d/50-mysqld_safe.cnf r,
/etc/mysql/mariadb.conf.d/50-server.cnf r,
/run/systemd/notify w,
/usr/sbin/mysqld rk,
/var/lib/mysql/** rw,
/var/log/mysql/** r,
owner /var/lib/mysql/ r,
owner /var/lib/mysql/** rwk,
owner /var/log/mysql/** rw,
}
有趣的是,MariaDB 需要的文件是(绝对路径),而它请求对(没有起始斜线,所以是相对路径)的/run/systemd/notify
写入权限。run/systemd/notify
但是删除斜线会使配置文件失败:
$ sudo apparmor_parser -r /etc/apparmor.d/usr.sbin.mysqld
AppArmor parser error for /etc/apparmor.d/usr.sbin.mysqld in /etc/apparmor.d/usr.sbin.mysqld at line 29: syntax error, unexpected TOK_ID, expecting TOK_MODE
但是,当我将配置文件置于抱怨模式,然后让 apparmor 找出是否需要任何更改时,它没有发现任何问题:
$ sudo aa-complain mysqld
Setting /usr/sbin/mysqld to complain mode.
$ sudo aa-logprof
Reading log entries from /var/log/audit/audit.log.
Updating AppArmor profiles in /etc/apparmor.d.
Complain-mode changes:
有谁知道这个文件的路径设置在哪里?