Bug 1310297
Summary: | SELinux is preventing /usr/sbin/lighttpd from 'create' accesses on the sock_file mirdesign.sock-0. | ||||||
---|---|---|---|---|---|---|---|
Product: | [Fedora] Fedora | Reporter: | Guillaume Poirier-Morency <guillaumepoiriermorency> | ||||
Component: | lighttpd | Assignee: | Gwyn Ciesla <gwync> | ||||
Status: | CLOSED RAWHIDE | QA Contact: | Fedora Extras Quality Assurance <extras-qa> | ||||
Severity: | unspecified | Docs Contact: | |||||
Priority: | unspecified | ||||||
Version: | 23 | CC: | dominick.grift, dwalsh, gwync, lvrabec, mgrepl, plautrba | ||||
Target Milestone: | --- | ||||||
Target Release: | --- | ||||||
Hardware: | x86_64 | ||||||
OS: | Unspecified | ||||||
Whiteboard: | abrt_hash:abde6c036fc7778dc0b1e796f983de9f0948e9e2bdf38a74f8cefca3091313a4;VARIANT_ID=workstation; | ||||||
Fixed In Version: | Doc Type: | Bug Fix | |||||
Doc Text: | Story Points: | --- | |||||
Clone Of: | Environment: | ||||||
Last Closed: | 2016-06-28 18:00:46 UTC | Type: | --- | ||||
Regression: | --- | Mount Type: | --- | ||||
Documentation: | --- | CRM: | |||||
Verified Versions: | Category: | --- | |||||
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||
Cloudforms Team: | --- | Target Upstream Version: | |||||
Embargoed: | |||||||
Attachments: |
|
Description
Guillaume Poirier-Morency
2016-02-20 05:46:39 UTC
No reason to block this, although sock files should really go under /run rather then in /var/lib. In the default configuration, sockets end-up in home_dir + "/sockets" rather that state_dir + "/sockets". SELinux seems fine for sockets in /var/run/lighttpd/sockets. Right so we should fix lighttpd to put its sockets into /run by default. Created attachment 1129597 [details]
Patch for lighttpd.conf
That's the best thing to do! Hi, As Dan wrote, this is more lighttpd issue then SELinux policy issue. Could you move sockets into /run by default? Thank you!. Just a rectification, sockets should end-up in '/run/lighttpd/sockets' and I would advise to move 'lighttpd.pid' in '/run/lighttpd' for more consistency. |