Ū•xÜŖœ( ė) 1 VH gŸ h |p (í ™$tžI3~}Ŋü,ē/į.bFŠĻÁŨh‹F SŌ!P&"Nw"NÆ"G#]]#Oģ#k $Rw$qĘ$f<%VŖ%Vú%SQ&jĨ&B'TS'^¨'Á(tÉ(?>)Z~)YŲ)Ž3*XÂ,-,.?/ U0 _1 m2zy3šô3šŽ4†I5įĐ53¸6eė6_R7e˛7f88œ8¸]9Ã:ƒÚ:\^<bģ<\=+{=c§=7 ><C>:€>ģ>Ë>4Û>?,+?X??t?0´?1å?]@2u@K¨@2ô@]'Ac…AéA,ųA&Bd9BNžBíB_C]eCEÃC- D7D4PD!…D'§D$ĪD ôD_ERuEOČE9F:RFF‹ĢF7GBRGA•G^×Gs6H–ĒHĄAIųãJĨŨLuƒOšųOŧŗPŅpQBR%ÂT\čXŅEZ~[–]1§^ÁŲ_Ŗ›bŨ?e@j[^m ēo‰Įu›QzÆí}ô~}x€ö€w€œø€¤•Ä:‚¤˙‚¤ƒÂž„Á…ˆC†ƒĖ†ÛP‡š,ˆ†ĮˆÎN‰åŠÜŒāŒŅ`Đ2Ž ÷•L–fS˜iēšZ$bŸ\âĄ-?¤{mĨéĻ4¨$7Š€\ĢüŨĢųÚŦōÔ­úĮŽO¯°—-ąŞ Ô´\Ūˇb;¸\ž¸+û¸z'šŸĸšSBēŦ–ēFCģPŠģbÛģ<>ŧu{ŧCņŧ•5Ŋ^ËŊ_*ž—Šžc"ŋ†ŋa$Ā$†ĀCĢÁīÂZ˙ÂZÃümÃíjÄ:XœŞÆÁģĮc}ČUáȊ7ÉcÂÉP&Ę}wĘbõĘÄX˧ˤÅ˘j͙ÎbÎņĪqōĪ—dЖüĐΓŅ0bŌŽ“ĶVS_ZIN9:jx6.@gBY]F>JEvs4T5 KlfHhQ'cWk0i^ *[1oPUrMRpXe") t<=$; qC 73a(,A2m+&w\-8dbu!D#LO%nG`/? dac_override and dac_read_search capabilities usually indicates that the root process does not have access to a file based on the permission flags. This usually mean you have some file with the wrong ownership/permissions on it. SELinux denied access requested by $SOURCE. It is not expected that this access is required by $SOURCE and this access may signal an intrusion attempt. It is also possible that the specific version or configuration of the application is causing it to require additional access. Attempt restorecon -v '$TARGET_PATH' or chcon -t SIMILAR_TYPE '$TARGET_PATH' Changing the "$BOOLEAN" boolean to true will allow this access: "setsebool -P $BOOLEAN=1" Changing the "$BOOLEAN" boolean to true will allow this access: "setsebool -P $BOOLEAN=1." Changing the "allow_ftpd_use_nfs" boolean to true will allow this access: "setsebool -P allow_ftpd_use_nfs=1." Changing the file_context to mnt_t will allow mount to mount the file system: "chcon -t mnt_t '$TARGET_PATH'." You must also change the default file context files on the system in order to preserve them even on a full relabel. "semanage fcontext -a -t mnt_t '$FIX_TARGET_PATH'" If httpd scripts should be allowed to write to public directories you need to turn on the $BOOLEAN boolean and change the file context of the public directory to public_content_rw_t. Read the httpd_selinux man page for further information: "setsebool -P $BOOLEAN=1; chcon -t public_content_rw_t " You must also change the default file context labeling files on the system in order to preserve public directory labeling even on a full relabel. "semanage fcontext -a -t public_content_rw_t " If you want $SOURCE to continue, you must turn on the $BOOLEAN boolean. Note: This boolean will affect all applications on the system. If you want httpd to send mail you need to turn on the $BOOLEAN boolean: "setsebool -P $BOOLEAN=1" If you want to allow $SOURCE to bind to port $PORT_NUMBER, you can execute # semanage port -a -t PORT_TYPE -p %s $PORT_NUMBER where PORT_TYPE is one of the following: %s. If this system is running as an NIS Client, turning on the allow_ypbind boolean may fix the problem. setsebool -P allow_ypbind=1. If you want to allow $SOURCE to connect to $PORT_NUMBER, you can execute # sandbox -X -t sandbox_net_t $SOURCE If you want to allow $SOURCE to connect to $PORT_NUMBER, you can execute # semanage port -a -t PORT_TYPE -p %s $PORT_NUMBER where PORT_TYPE is one of the following: %s. If you want to change the file context of $TARGET_PATH so that the automounter can execute it you can execute "chcon -t bin_t $TARGET_PATH". If you want this to survive a relabel, you need to permanently change the file context: execute "semanage fcontext -a -t bin_t '$FIX_TARGET_PATH'". SELinux denied access requested by $SOURCE. It is not expected that this access is required by $SOURCE and this access may signal an intrusion attempt. It is also possible that the specific version or configuration of the application is causing it to require additional access. SELinux denied access requested by the $SOURCE command. It looks like this is either a leaked descriptor or $SOURCE output was redirected to a file it is not allowed to access. Leaks usually can be ignored since SELinux is just closing the leak and reporting the error. The application does not use the descriptor, so it will run properly. If this is a redirection, you will not get output in the $TARGET_PATH. You should generate a bugzilla on selinux-policy, and it will get routed to the appropriate package. You can safely ignore this avc. SELinux denied access to $TARGET_PATH requested by $SOURCE. $TARGET_PATH has a context used for sharing by a different program. If you would like to share $TARGET_PATH from $SOURCE also, you need to change its file context to public_content_t. If you did not intend to allow this access, this could signal an intrusion attempt. SELinux denied cvs access to $TARGET_PATH. If this is a CVS repository it needs to have a file context label of cvs_data_t. If you did not intend to use $TARGET_PATH as a CVS repository it could indicate either a bug or it could signal an intrusion attempt. SELinux denied xen access to $TARGET_PATH. If this is a XEN image, it has to have a file context label of xen_image_t. The system is setup to label image files in directory /var/lib/xen/images correctly. We recommend that you copy your image file to /var/lib/xen/images. If you really want to have your xen image files in the current directory, you can relabel $TARGET_PATH to be xen_image_t using chcon. You also need to execute semanage fcontext -a -t xen_image_t '$FIX_TARGET_PATH' to add this new path to the system defaults. If you did not intend to use $TARGET_PATH as a xen image it could indicate either a bug or an intrusion attempt. SELinux has denied the $SOURCE access to potentially mislabeled files $TARGET_PATH. This means that SELinux will not allow httpd to use these files. If httpd should be allowed this access to these files you should change the file context to one of the following types, %s. Many third party apps install html files in directories that SELinux policy cannot predict. These directories have to be labeled with a file context which httpd can access. SELinux has denied the $SOURCE_PATH from executing potentially mislabeled files $TARGET_PATH. Automounter can be setup to execute configuration files. If $TARGET_PATH is an automount executable configuration file it needs to have a file label of bin_t. If automounter is trying to execute something that it is not supposed to, this could indicate an intrusion attempt. SELinux has prevented vbetool from performing an unsafe memory operation. SELinux has prevented wine from performing an unsafe memory operation. SELinux is preventing $SOURCE_PATH "$ACCESS" access on $TARGET_PATH. SELinux is preventing $SOURCE_PATH "$ACCESS" access to $TARGET_PATH. SELinux is preventing $SOURCE_PATH "$ACCESS" to $TARGET_PATH. SELinux is preventing $SOURCE_PATH access to a leaked $TARGET_PATH file descriptor. SELinux is preventing $SOURCE_PATH from binding to port $PORT_NUMBER. SELinux is preventing $SOURCE_PATH from changing the access protection of memory on the heap. SELinux is preventing $SOURCE_PATH from connecting to port $PORT_NUMBER. SELinux is preventing $SOURCE_PATH from creating a file with a context of $SOURCE_TYPE on a filesystem. SELinux is preventing $SOURCE_PATH from loading $TARGET_PATH which requires text relocation. SELinux is preventing $SOURCE_PATH from making the program stack executable. SELinux is preventing Samba ($SOURCE_PATH) "$ACCESS" access to $TARGET_PATH. SELinux is preventing cvs ($SOURCE_PATH) "$ACCESS" access to $TARGET_PATH SELinux is preventing the $SOURCE_PATH from executing potentially mislabeled files $TARGET_PATH. SELinux is preventing the http daemon from sending mail. SELinux is preventing xen ($SOURCE_PATH) "$ACCESS" access to $TARGET_PATH. SELinux policy is preventing an httpd script from writing to a public directory. SELinux policy is preventing an httpd script from writing to a public directory. If httpd is not setup to write to public directories, this could signal an intrusion attempt. SELinux prevented $SOURCE from mounting on the file or directory "$TARGET_PATH" (type "$TARGET_TYPE"). SELinux prevented httpd $ACCESS access to http files. SELinux prevented the ftp daemon from $ACCESS files stored on a CIFS filesystem. SELinux prevented the ftp daemon from $ACCESS files stored on a NFS filesystem. The $SOURCE application attempted to change the access protection of memory on the heap (e.g., allocated using malloc). This is a potential security problem. Applications should not be doing this. Applications are sometimes coded incorrectly and request this permission. The SELinux Memory Protection Tests web page explains how to remove this requirement. If $SOURCE does not work and you need it to work, you can configure SELinux temporarily to allow this access until the application is fixed. Please file a bug report against this package. Use a command like "cp -p" to preserve all permissions except SELinux context. You can alter the file context by executing chcon -R -t rsync_data_t '$TARGET_PATH' You must also change the default file context files on the system in order to preserve them even on a full relabel. "semanage fcontext -a -t rsync_data_t '$FIX_TARGET_PATH'" You can alter the file context by executing chcon -R -t samba_share_t '$TARGET_PATH' You must also change the default file context files on the system in order to preserve them even on a full relabel. "semanage fcontext -a -t samba_share_t '$FIX_TARGET_PATH'" You can alter the file context by executing chcon -t public_content_t '$TARGET_PATH' You must also change the default file context files on the system in order to preserve them even on a full relabel. "semanage fcontext -a -t public_content_t '$FIX_TARGET_PATH'" You can alter the file context by executing chcon -t swapfile_t '$TARGET_PATH' You must also change the default file context files on the system in order to preserve them even on a full relabel. "semanage fcontext -a -t swapfile_t '$FIX_TARGET_PATH'" You can alter the file context by executing chcon -t virt_image_t '$TARGET_PATH' You must also change the default file context files on the system in order to preserve them even on a full relabel. "semanage fcontext -a -t virt_image_t '$FIX_TARGET_PATH'" You can alter the file context by executing chcon -t xen_image_t '$TARGET_PATH' You must also change the default file context files on the system in order to preserve them even on a full relabel. "semanage fcontext -a -t xen_image_t '$FIX_TARGET_PATH'" You can execute the following command as root to relabel your computer system: "touch /.autorelabel; reboot" You can generate a local policy module to allow this access - see FAQ Please file a bug report. You can generate a local policy module to allow this access - see FAQ You can restore the default system context to this file by executing the restorecon command. restorecon '$SOURCE_PATH'. You can restore the default system context to this file by executing the restorecon command. restorecon '$TARGET_PATH', if this file is a directory, you can recursively restore using restorecon -R '$TARGET_PATH'. Your system may be seriously compromised! Your system may be seriously compromised! $SOURCE_PATH attempted to mmap low kernel memory. Your system may be seriously compromised! $SOURCE_PATH tried to load a kernel module. Your system may be seriously compromised! $SOURCE_PATH tried to modify SELinux enforcement. Your system may be seriously compromised! $SOURCE_PATH tried to modify kernel configuration. Disable IPV6 properly. Either remove the mozplluger package by executing 'yum remove mozplugger' Or turn off enforcement of SELinux over the Firefox plugins. setsebool -P unconfined_mozilla_plugin_transition 0 If you decide to continue to run the program in question you will need to allow this operation. This can be done on the command line by executing: # setsebool -P mmap_low_allowed 1 You tried to place a type on a %s that is not a file type. This is not allowed, you must assigne a file type. You can list all file types using the seinfo command. seinfo -afile_type -x Changing the "$BOOLEAN" and "$WRITE_BOOLEAN" booleans to true will allow this access: "setsebool -P $BOOLEAN=1 $WRITE_BOOLEAN=1". warning: setting the "$WRITE_BOOLEAN" boolean to true will allow the ftp daemon to write to all public content (files and directories with type public_content_t) in addition to writing to files and directories on CIFS filesystems. # semanage fcontext -a -t SIMILAR_TYPE '$FIX_TARGET_PATH' # restorecon -v '$FIX_TARGET_PATH'# semanage fcontext -a -t samba_share_t '$FIX_TARGET_PATH%s' # restorecon %s -v '$FIX_TARGET_PATH'# semanage fcontext -a -t virt_image_t '$FIX_TARGET_PATH' # restorecon -v '$FIX_TARGET_PATH'# semanage port -a -t %s -p %s $PORT_NUMBER# semanage port -a -t PORT_TYPE -p %s $PORT_NUMBER where PORT_TYPE is one of the following: %s.A process might be attempting to hack into your system.Add net.ipv6.conf.all.disable_ipv6 = 1 to /etc/sysctl.conf Contact your security administrator and report this issue.Restore ContextRestore ContextSELinux is preventing $SOURCE_PATH "$ACCESS" access.Turn off memory protectionYou can read '%s' man page for more details.You might have been hacked.You must tell SELinux about this by enabling the '%s' boolean. You need to change the label on $FIX_TARGET_PATHYou need to change the label on $TARGET_BASE_PATHYou need to change the label on $TARGET_BASE_PATH to public_content_t or public_content_rw_t.You need to change the label on $TARGET_BASE_PATH'You need to change the label on $TARGET_PATH to a type of a similar device.You need to change the label on '$FIX_TARGET_PATH'You should report this as a bug. You can generate a local policy module to allow this access.You should report this as a bug. You can generate a local policy module to dontaudit this access.execstack -c %sif you think that you might have been hackedsetsebool -P %s %sturn on full auditing to get path information about the offending file and generate the error again.use a command like "cp -p" to preserve all permissions except SELinux context.you can run restorecon.you may be under attack by a hacker, since confined applications should never need this access.you may be under attack by a hacker, since confined applications should not need this access.you may be under attack by a hacker, this is a very dangerous access.you must change the labeling on $TARGET_PATH.you must fix the labels.you must move the cert file to the ~/.cert directoryyou must pick a valid file label.you must remove the mozplugger package.you must setup SELinux to allow thisyou must tell SELinux about thisyou must tell SELinux about this by enabling the 'httpd_unified' and 'http_enable_cgi' booleansyou must tell SELinux about this by enabling the vbetool_mmap_zero_ignore boolean.you must tell SELinux about this by enabling the wine_mmap_zero_ignore boolean.you must turn off SELinux controls on the Chrome plugins.you must turn off SELinux controls on the Firefox plugins.you need to add labels to it.you need to change the label on $TARGET_PATH to public_content_rw_t, and potentially turn on the allow_httpd_sys_script_anon_write boolean.you need to fully relabel.you need to report a bug. This is a potentially dangerous access.you need to report a bug. This is a potentially dangerous access.you need to set /proc/sys/net/ipv6/conf/all/disable_ipv6 to 1 and do not blacklist the module'you need to use a different command. You are not allowed to preserve the SELinux context on the target file system.you should clear the execstack flag and see if $SOURCE_PATH works correctly. Report this as a bug on %s. You can clear the exestack flag by executing:Project-Id-Version: PACKAGE VERSION Report-Msgid-Bugs-To: PO-Revision-Date: 2017-08-31 08:31-0400 Last-Translator: Copied by Zanata Language-Team: Assamese (http://www.transifex.com/projects/p/fedora/language/as/) Language: as MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Plural-Forms: nplurals=2; plural=(n != 1); X-Generator: Zanata 4.6.2 dac_override āφ⧰⧁ dac_read_search āĻ•ā§āώāĻŽāϤāĻžāϏāĻŽā§‚āĻšā§‡ āϏāĻžāϧāĻžā§°āĻŖāϤ āχāĻ‚āĻ—āĻŋāϤ āĻĻāĻŋā§Ÿā§‡ āϝ⧇ ⧰⧁āϟ āĻĒā§ā§°āĻ•ā§ā§°āĻŋ⧟āĻžā§° āĻ…āύ⧁āĻŽāϤāĻŋ āĻĢā§āϞ⧇āĻ—āϏāĻŽā§‚āĻšā§° āωāĻĒā§°āϤ āύāĻŋā§°ā§āĻ­ā§° āϕ⧰āĻŋ āĻāϟāĻž āĻĢāĻžāχāϞāϞ⧇ āĻ…āĻ­āĻŋāĻ—āĻŽ āύāĻžāχāĨ¤ āχ āϏāĻžāϧāĻžā§°āĻŖāϤ āĻŦ⧁āϜāĻžā§Ÿ āφāĻĒā§‹āύāĻžā§° āĻ­ā§‚āϞ āĻ…āϧāĻŋāĻ•āĻžā§°āĻ¤ā§āĻŦ/āĻ…āύ⧁āĻŽāϤāĻŋ āĻĨāĻ•āĻž āĻ•āĻŋāϛ⧁āĻŽāĻžāύ āĻĢāĻžāχāϞ āφāϛ⧇āĨ¤ SELinux āĻ $SOURCE āĻĻā§āĻŦāĻžā§°āĻž āĻ…āύ⧁⧰⧋āϧ āϕ⧰āĻž āĻ…āĻ­āĻŋāĻ—āĻŽ āύāĻžāĻ•āϚ āϕ⧰āĻŋāϞ⧇āĨ¤ āĻāχ āĻ…āĻ­āĻŋāĻ—āĻŽ $SOURCE āĻĻā§āĻŦāĻžā§°āĻž āĻĒā§ā§°ā§Ÿā§‹āϜāύ āĻšāĻŦ āĻŦ⧁āϞāĻŋ āφāĻļāĻž āϕ⧰āĻž āĻšā§‹ā§ąāĻž āύāĻžāχ āφ⧰⧁ āĻāχ āϏāĻ‚āϕ⧇āϤ⧇ āĻāϟāĻž āĻ…āύāĻžāϧāĻŋāĻ•āĻžā§° āĻĒā§ā§°ā§ąā§‡āĻļā§° āχāĻ‚āĻ—āĻŋāϤ āĻĻāĻŋāĻŦ āĻĒāĻžā§°ā§‡āĨ¤ āϏāĻŽā§āĻ­āĻŦ āĻšāĻŦ āĻĒāĻžā§°ā§‡ āϝ⧇ āĻāĻĒā§āϞāĻŋāϕ⧇āϚāύ⧰ āĻŦāĻŋāĻļ⧇āώ āϏāĻ‚āĻ¸ā§āϕ⧰āĻŖ āĻ…āĻĨāĻŦāĻž āϏāς⧰⧂āĻĒ⧇ āĻ‡ā§ŸāĻžā§° āĻ…āϤāĻŋā§°āĻŋāĻ•ā§āϤ āĻ…āĻ­āĻŋāĻ—āĻŽā§° āĻĒā§ā§°ā§Ÿā§‹āϜāĻ¨ā§€ā§ŸāϤāĻž āĻĻ⧇āĻ–āĻžāχ āφāϛ⧇āĨ¤ restorecon -v '$TARGET_PATH' āĻ…āĻĨāĻŦāĻž chcon -t SIMILAR_TYPE '$TARGET_PATH' āĻšā§‡āĻˇā§āϟāĻž āϕ⧰āĻ• "$BOOLEAN" āĻŦ⧁āϞāĻŋ⧟āĻžāύāĻ• true āϞ⧇ āϏāϞāύāĻŋ āϕ⧰āĻŋāϞ⧇ āĻāχ āĻ…āĻ­āĻŋāĻ—āĻŽā§° āĻ…āύ⧁āĻŽāϤāĻŋ āĻĒā§‹ā§ąāĻž āϝāĻžāĻŦ: "setsebool -P $BOOLEAN=1" "$BOOLEAN" āĻŦ⧁āϞāĻŋ⧟āĻžāύāĻ• true āϞ⧇ āϏāϞāύāĻŋ āϕ⧰āĻŋāϞ⧇ āĻāχ āĻ…āĻ­āĻŋāĻ—āĻŽā§° āĻ…āύ⧁āĻŽāϤāĻŋ āĻĒā§‹ā§ąāĻž āϝāĻžāĻŦ: "setsebool -P $BOOLEAN=1āĨ¤" "$allow_ftpd_use_nfs" āĻŦ⧁āϞāĻŋ⧟āĻžāύāĻ• true āϞ⧇ āϏāϞāύāĻŋ āϕ⧰āĻŋāϞ⧇ āĻāχ āĻ…āĻ­āĻŋāĻ—āĻŽā§° āĻ…āύ⧁āĻŽāϤāĻŋ āĻĒā§‹ā§ąāĻž āϝāĻžāĻŦ: "setsebool -P allow_ftpd_use_nfs=1āĨ¤" file_context āĻ• mnt_t āϞ⧇ āϏāϞāύāĻŋ āϕ⧰āĻŋāϞ⧇ āĻĢāĻžāχāϞ āϚāĻŋāĻ¸ā§āĻŸā§‡āĻŽ āĻŽāĻžāωāĻ¨ā§āϟ āϕ⧰āĻŋāĻŦāϞ⧇ āĻŽāĻžāωāĻ¨ā§āϟ⧰ āĻ…āύ⧁āĻŽāϤāĻŋ āĻĻāĻŋāĻŦ: "chcon -t mnt_t '$TARGET_PATH'āĨ¤" āφāĻĒ⧁āύāĻŋ āϞāĻ—āϤ⧇ āϚāĻŋāĻ¸ā§āĻŸā§‡āĻŽāϤ āĻ…āĻŦāĻŋāĻ•āĻ˛ā§āĻĒāĻŋāϤ āĻĢāĻžāχāϞ āĻĒā§°āĻŋāĻĒā§ā§°ā§‡āĻ•ā§āώāϤāĻŋāϤ āĻĢāĻžāχāϞāϏāĻŽā§‚āĻš āϏāϞāύāĻŋ āϕ⧰āĻŋāĻŦ āϞāĻžāĻ—āĻŋāĻŦ āϝāĻžāϤ⧇ āϏāĻŋāĻšāϤāĻ• āĻāϟāĻž āϏāĻŽā§āĻĒā§‚ā§°ā§āĻŖ āĻĒ⧁āύ⧰āϞ⧇āĻŦ⧇āϞāϤ āϏāς⧰āĻ•ā§āώ⧰āĻŖ āϕ⧰āĻŋāĻŦ āĻĒāĻžā§°āĻŋāĨ¤ "semanage fcontext -a -t mnt_t '$FIX_TARGET_PATH'" āϝāĻĻāĻŋ httpd āĻ¸ā§āĻ•ā§ā§°āĻŋāĻĒā§āϟāϏāĻŽā§‚āĻšāĻ• ā§°āĻžāϜāĻšā§ā§ąāĻž āĻĄāĻžāχ⧰⧇āĻ•āϟ⧰āĻŋāϏāĻŽā§‚āĻšāϞ⧇ āϞāĻŋāĻ–āĻžā§° āĻ…āύ⧁āĻŽāϤāĻŋ āĻĻāĻŋāĻŦ āϞāĻžāϗ⧇ āφāĻĒ⧁āύāĻŋ $BOOLEAN āĻŦ⧁āϞāĻŋ⧟āĻžāύ āĻ…āύ āϕ⧰āĻŋāĻŦ āϞāĻžāĻ—āĻŋāĻŦ āφ⧰⧁ ā§°āĻžāϜāĻšā§ā§ąāĻž āĻĄāĻžāχ⧰⧇āĻ•āϟ⧰āĻŋā§° āĻĢāĻžāχāϞ āĻĒā§°āĻŋāĻĒā§ā§°ā§‡āĻ•ā§āώāϤāĻŋāϤāĻ• public_content_rw_t āϞ⧇ āϏāϞāύāĻŋ āϕ⧰āĻŋāĻŦ āϞāĻžāĻ—āĻŋāĻŦāĨ¤ āĻ…āϧāĻŋāĻ• āϤāĻĨā§āϝ⧰ āĻŦāĻžāĻŦ⧇ httpd_selinux man āĻĒ⧃āĻˇā§āĻ āĻž āĻĒā§āĻ•: "setsebool -P $BOOLEAN=1; chcon -t public_content_rw_t " āĻāϟāĻž āϏāĻŽā§āĻĒā§‚ā§°ā§āĻŖ āĻĒ⧁āύ⧰āϞ⧇āĻŦ⧇āϞāϤ ā§°āĻžāϜāĻšā§ā§ąāĻž āĻĄāĻžāχ⧰⧇āĻ•āϟ⧰āĻŋ āϏāς⧰āĻ•ā§āώāĻŖ āϕ⧰āĻŋāĻŦāϞ⧇ āφāĻĒ⧁āύāĻŋ āϚāĻŋāĻ¸ā§āĻŸā§‡āĻŽāϤ āĻ…āĻŦāĻŋāĻ•āĻ˛ā§āĻĒāĻŋāϤ āĻĢāĻžāχāϞ āĻĒā§°āĻŋāĻĒā§ā§°ā§‡āĻ•ā§āώāϤāĻŋāϤ āϞ⧇āĻŦ⧇āϞ āĻĨāĻ•āĻž āĻĢāĻžāχāϞāϏāĻŽā§‚āĻš āϏāϞāύāĻŋ āϕ⧰āĻŋāĻŦ āϞāĻžāĻ—āĻŋāĻŦāĨ¤ "semanage fcontext -a -t public_content_rw_t " āϝāĻĻāĻŋ āφāĻĒ⧁āύāĻŋ $SOURCE āĻ• āϚāϞāĻžāĻŦ āĻŦāĻŋāϚāĻžā§°ā§‡, āφāĻĒ⧁āύāĻŋ $BOOLEAN āĻŦ⧁āϞāĻŋ⧟āĻžāύ āĻ…āύ āϕ⧰āĻŋāĻŦ āϞāĻžāĻ—āĻŋāĻŦāĨ¤ āĻŽāύ āϕ⧰āĻŋāĻŦ: āĻāχ āĻŦ⧁āϞāĻŋ⧟āĻžāύ⧇ āϚāĻŋāĻ¸ā§āĻŸā§‡āĻŽā§° āϏāĻ•āϞ⧋ āĻāĻĒā§āϞāĻŋāϕ⧇āϚāύ⧰ āωāĻĒā§°āϤ āĻĒā§ā§°āĻ­āĻžā§ą āĻĒ⧇āϞāĻžāĻŦāĨ¤ āϝāĻĻāĻŋ āφāĻĒ⧁āύāĻŋ httpd āĻŽā§‡āχāϞ āĻĒā§ā§°ā§‡ā§°āĻŖ āϕ⧰āĻžāĻŦ āĻŦāĻŋāϚāĻžā§°ā§‡ āφāĻĒ⧁āύāĻŋ $BOOLEAN boolean: "setsebool -P $BOOLEAN=1" āĻ…āύ āϕ⧰āĻŋāĻŦ āϞāĻžāĻ—āĻŋāĻŦ āϝāĻĻāĻŋ āφāĻĒ⧁āύāĻŋ $SOURCE āĻ• āĻĒā§‹ā§°ā§āϟ $PORT_NUMBER āϞ⧇ āϏāĻ‚āϝ⧋āĻ— āϕ⧰āĻžā§° āĻ…āύ⧁āĻŽāϤāĻŋ āĻĻāĻŋāĻŦ āĻŦāĻŋāϚāĻžā§°ā§‡, āφāĻĒ⧁āύāĻŋ # semanage port -a -t PORT_TYPE -p %s $PORT_NUMBER āĻāĻ•ā§āϏāĻŋāĻ•āĻŋāωāϟ āϕ⧰āĻŋāĻŦ āĻĒāĻžā§°āĻŋāĻŦ āϝāϤ PORT_TYPE āĻšāϞ āύāĻŋāĻŽā§āύāϞāĻŋāĻ–āĻŋāϤ⧰ āĻāϟāĻž: %s. āϝāĻĻāĻŋ āĻāχ āϚāĻŋāĻ¸ā§āĻŸā§‡āĻŽ āĻāϟāĻž NIS āĻ•ā§āϞāĻžāĻāĻ¨ā§āϟ āĻšāĻŋāϚāĻžāĻĒ⧇ āϚāϞāĻŋ āφāϛ⧇, allow_ypbind āĻŦ⧁āϞāĻŋ⧟āĻžāύāĻ• āĻ…āύ āϕ⧰āĻŋāϞ⧇ āϏāĻŽāĻ¸ā§āϝāĻž āĻ āĻŋāĻ• āĻšāĻŦ āĻĒāĻžā§°ā§‡āĨ¤ setsebool -P allow_ypbind=1āĨ¤ āϝāĻĻāĻŋ āφāĻĒ⧁āύāĻŋ $SOURCE āĻ• $PORT_NUMBER ā§° āϏ⧈āϤ⧇ āϏāĻ‚āϝ⧋āĻ— āϕ⧰āĻžā§° āĻ…āύ⧁āĻŽāϤāĻŋ āĻĻāĻŋāĻŦ āĻŦāĻŋāϚāĻžā§°ā§‡, āφāĻĒ⧁āύāĻŋ āĻāĻ•ā§āϏāĻŋāĻ•āĻŋāωāϟ āϕ⧰āĻŋāĻŦ āĻĒāĻžā§°āĻŋāĻŦ # sandbox -X -t sandbox_net_t $SOURCE āϝāĻĻāĻŋ āφāĻĒ⧁āύāĻŋ $SOURCE āĻ• $PORT_NUMBER āϞ⧇ āϏāĻ‚āϝ⧋āĻ— āϕ⧰āĻžāĻŦ āĻŦāĻŋāϚāĻžā§°ā§‡, āφāĻĒ⧁āύāĻŋ āĻĒā§ā§°ā§‡ā§°āĻŖ āϕ⧰āĻŋāĻŦ āĻĒāĻžā§°ā§‡ # semanage port -a -t PORT_TYPE -p %s $PORT_NUMBER āϝāϤ PORT_TYPE āύāĻŋāĻŽā§āύāϞāĻŋāĻ–āĻŋāϤ⧰ āĻāϟāĻž: %s. āϝāĻĻāĻŋ āφāĻĒ⧁āύāĻŋ $TARGET_PATH ā§° āĻĢāĻžāχāϞ āĻĒā§°āĻŋāĻĒā§ā§°ā§‡āĻ•ā§āώāϤāĻŋāϤ āϏāϞāύāĻŋ āϕ⧰āĻŋāĻŦ āĻŦāĻŋāϚāĻžā§°ā§‡ āϝāĻžāϤ⧇ āĻ¸ā§āĻŦāĻŽāĻžāωāĻ¨ā§āϟāĻžā§°ā§‡ āĻ‡ā§ŸāĻžāĻ• āĻāĻ•ā§āϏāĻŋāĻ•āĻŋāωāϟ āϕ⧰āĻŋāĻŦ āĻĒāĻžā§°ā§‡ āφāĻĒ⧁āύāĻŋ "chcon -t bin_t $TARGET_PATH" āĻāĻ•ā§āϏāĻŋāĻ•āĻŋāωāϟ āϕ⧰āĻŋāĻŦ āĻĒāĻžā§°āĻŋāĻŦāĨ¤ āϝāĻĻāĻŋ āφāĻĒ⧁āύāĻŋ āĻ‡ā§ŸāĻžāĻ• āĻāϟāĻž āĻĒ⧁āύ⧰āϞ⧇āĻŦ⧇āϞ āĻĒā§°āĻž āĻŦāϚāĻžāĻŦ āĻŦāĻŋāϚāĻžā§°āĻŋāϛ⧇, āφāĻĒ⧁āύāĻŋ āĻ¸ā§āĻĨāĻžā§Ÿā§€āĻ­āĻžā§ąā§‡ āĻĢāĻžāχāϞ āĻĒā§°āĻŋāĻĒā§ā§°ā§‡āĻ•ā§āώāϤāĻŋāϤ: execute "semanage fcontext -a -t bin_t '$FIX_TARGET_PATH'" āϏāϞāύāĻŋ āϕ⧰āĻŋāĻŦ āϞāĻžāĻ—āĻŋāĻŦāĨ¤ SELinux āĻ $SOURCE āĻĻā§āĻŦāĻžā§°āĻž āĻ…āύ⧁⧰⧋āϧ āϕ⧰āĻž āĻ…āĻ­āĻŋāĻ—āĻŽ āύāĻžāĻ•āϚ āϕ⧰āĻŋāϞ⧇āĨ¤ āĻāχ āĻ…āĻ­āĻŋāĻ—āĻŽ $SOURCE āĻĻā§āĻŦāĻžā§°āĻž āĻĒā§ā§°ā§Ÿā§‹āϜāύ āĻšāĻŦ āĻŦ⧁āϞāĻŋ āφāĻļāĻž āϕ⧰āĻž āĻšā§‹ā§ąāĻž āύāĻžāχ āφ⧰⧁ āĻāχ āϏāĻ‚āϕ⧇āϤ⧇ āĻāϟāĻž āĻ…āύāĻžāϧāĻŋāĻ•āĻžā§° āĻĒā§ā§°ā§ąā§‡āĻļā§° āχāĻ‚āĻ—āĻŋāϤ āĻĻāĻŋāĻŦ āĻĒāĻžā§°ā§‡āĨ¤ āϏāĻŽā§āĻ­āĻŦ āĻšāĻŦ āĻĒāĻžā§°ā§‡ āϝ⧇ āĻāĻĒā§āϞāĻŋāϕ⧇āϚāύ⧰ āĻŦāĻŋāĻļ⧇āώ āϏāĻ‚āĻ¸ā§āϕ⧰āĻŖ āĻ…āĻĨāĻŦāĻž āϏāς⧰⧂āĻĒ⧇ āĻ‡ā§ŸāĻžā§° āĻ…āϤāĻŋā§°āĻŋāĻ•ā§āϤ āĻ…āĻ­āĻŋāĻ—āĻŽā§° āĻĒā§ā§°ā§Ÿā§‹āϜāĻ¨ā§€ā§ŸāϤāĻž āĻĻ⧇āĻ–āĻžāχ āφāϛ⧇āĨ¤ SELinux āĻ $SOURCE āĻ•āĻŽāĻžāĻ¨ā§āĻĄ āĻĻā§āĻŦāĻžā§°āĻž āĻ…āύ⧁⧰⧋āϧ āϕ⧰āĻž āĻ…āĻ­āĻŋāĻ—āĻŽ āύāĻžāĻ•āϚ āϕ⧰āĻŋāϞ⧇āĨ¤ āĻāύ⧇ āϞāĻžāĻ—āĻŋāϛ⧇ āϝ⧇āύ āχ āĻšā§Ÿ āĻāϟāĻž āω⧰⧁āĻ– āĻŦāĻŋā§ąā§°āĻ• āĻ…āĻĨāĻŦāĻž $SOURCE āφāωāϟāĻĒ⧁āϟāĻ• āĻāύ⧇ āĻāϟāĻž āĻĢāĻžāχāϞāϞ⧇ āĻĒ⧁āύ⧰āύāĻŋā§°ā§āĻĻ⧇āĻļ āϕ⧰āĻž āĻšā§ˆāϛ⧇ āϝāϞ⧈ āϤāĻžā§° āĻ…āĻ­āĻŋāĻ—āĻŽā§° āĻ…āύ⧁āĻŽāϤāĻŋ āύāĻžāχāĨ¤ āω⧰⧁āĻ–āϏāĻŽā§‚āĻš āϏāĻžāϧāĻžā§°āĻŖāϤ āωāĻĒ⧇āĻ•ā§āώāĻž āϕ⧰āĻŋāĻŦ āĻĒāĻžā§°āĻŋ āϝāĻŋāĻšā§‡āϤ⧁ SELinux āĻ āω⧰⧁āĻ– āĻŦāĻ¨ā§āϧ āϕ⧰āĻŋ āĻ¤ā§ā§°ā§āϟāĻŋā§° āϏāĻ‚āĻŦāĻžāĻĻ āĻĻāĻŋ āφāϛ⧇āĨ¤ āĻāĻĒā§āϞāĻŋāϕ⧇āϚāύ⧇ āĻŦāĻŋā§ąā§°āĻ• āĻŦā§āĻ¯ā§ąāĻšāĻžā§° āύāϕ⧰⧇, āĻ¸ā§‡ā§Ÿā§‡āĻšā§‡ āχ āϏāĻ āĻŋāĻ•āĻ­āĻžā§ąā§‡ āϚāϞāĻŋāĻŦāĨ¤ āϝāĻĻāĻŋ āχ āĻāϟāĻž āĻĒ⧁āύ⧰āύāĻŋā§°ā§āĻĻ⧇āĻļ āĻšā§Ÿ, āφāĻĒ⧁āύāĻŋ $TARGET_PATH āϤ āφāωāϟāĻĒ⧁āϟ āύāĻžāĻĒāĻžāĻŦāĨ¤ āφāĻĒ⧁āύāĻŋ selinux-policy āϤ āĻāϟāĻž bugzilla āϏ⧃āϜāύ āϕ⧰āĻŋāĻŦ āϞāĻžāĻ—āĻŋāĻŦ, āφ⧰⧁ āχ āϏāĻ āĻŋāĻ• āĻĒ⧇āϕ⧇āχāϜ āϞ⧈āϕ⧇ āĻĻāĻŋāĻļ āĻĒāĻžāĻŦāĨ¤ āφāĻĒ⧁āύāĻŋ avc āĻ• āϏ⧁⧰āĻ•ā§āώāĻŋāϤāĻ­āĻžā§ąā§‡ āωāĻĒ⧇āĻ•ā§āώāĻž āϕ⧰āĻŋāĻŦ āĻĒāĻžā§°āĻŋāĻŦāĨ¤ SELinux āĻ $SOURCE āĻĻā§āĻŦāĻžā§°āĻž āĻ…āύ⧁⧰⧋āϧ āϕ⧰āĻž $TARGET_PATH āύāĻžāĻ•āϚ āϕ⧰āĻŋāϞ⧇āĨ¤ $TARGET_PATH ā§° āĻāϟāĻž āĻĒ⧃āĻĨāĻ• āĻĒā§ā§°āĻ—ā§ā§°āĻžāĻŽ āĻĻā§āĻŦāĻžā§°āĻž āĻ…āĻ‚āĻļā§€āĻĻāĻžā§°ā§€ āϕ⧰āĻŋāĻŦāϞ⧇ āĻŦā§āĻ¯ā§ąāĻšā§ƒāϤ āĻāϟāĻž āĻĒā§°āĻŋāĻĒā§ā§°ā§‡āĻ•ā§āώāϤāĻŋāϤ āφāϛ⧇āĨ¤ āϝāĻĻāĻŋ āφāĻĒ⧁āύāĻŋ $SOURCE ā§° āĻĒā§°āĻž $TARGET_PATH āĻ…āĻ‚āĻļā§€āĻĻāĻžā§°ā§€ āϕ⧰āĻŋāĻŦ āĻŦāĻŋāϚāĻžā§°ā§‡, āφāĻĒ⧁āύāĻŋ āĻ‡ā§ŸāĻžā§° āĻĢāĻžāχāϞ āĻĒā§°āĻŋāĻĒā§ā§°ā§‡āĻ•ā§āώāϤāĻŋāϤ public_content_t āϞ⧇ āϏāϞāύāĻŋ āϕ⧰āĻŋāĻŦ āϞāĻžāĻ—āĻŋāĻŦāĨ¤ āϝāĻĻāĻŋ āφāĻĒ⧁āύāĻŋ āĻāχ āĻ…āĻ­āĻŋāĻ—āĻŽā§° āĻ…āύ⧁āĻŽāϤāĻŋ āĻĻāĻŋāĻŦ āύāĻŋāĻŦāĻŋāϚāĻžā§°ā§‡, āχ āĻāϟāĻž āĻ…āύāĻžāϧāĻŋāĻ•āĻžā§° āĻĒā§ā§°ā§ąā§‡āĻļā§° āχāĻ‚āĻ—āĻŋāϤ āĻĻāĻŋāĻŦ āĻĒāĻžā§°ā§‡āĨ¤ SELinux āĻ $TARGET_PATH āϞ⧇ cvs āĻ…āĻ­āĻŋāĻ—āĻŽ āύāĻžāĻ•āϚ āϕ⧰āĻŋāϞ⧇āĨ¤ āϝāĻĻāĻŋ āχ āĻāϟāĻž CVS āĻ­āρ⧰āĻžāϞ āĻšā§Ÿ āĻ‡ā§ŸāĻžā§° āĻāϟāĻž āĻĢāĻžāχāϞ āĻĒā§°āĻŋāĻĒā§ā§°ā§‡āĻ•ā§āώāϤāĻŋāϤ āϞ⧇āĻŦ⧇āϞ cvs_data_t āĻĨāĻžāĻ•āĻŋāĻŦ āϞāĻžāĻ—āĻŋāĻŦāĨ¤ āϝāĻĻāĻŋ āφāĻĒ⧁āύāĻŋ $TARGET_PATH āĻ• āĻāϟāĻž CVS āĻ­āρ⧰āĻžāϞ āĻšāĻŋāϚāĻžāĻĒ⧇ āĻŦā§āĻ¯ā§ąāĻšāĻžā§° āϕ⧰āĻŋāĻŦ āύāĻŋāĻŦāĻŋāϚāĻžā§°ā§‡ āχ āĻāϟāĻž āĻŦāĻžāĻ— āĻšāĻŦ āĻĒāĻžā§°ā§‡ āĻ…āĻĨāĻŦāĻž āχ āĻāϟāĻž āĻ…āύāĻžāϧāĻŋāĻ•āĻžā§° āĻĒā§ā§°ā§ąā§‡āĻļā§° āχāĻ‚āĻ—āĻŋāϤ āĻšāĻŦ āĻĒāĻžā§°ā§‡āĨ¤ SELinux āĻ $TARGET_PATH āϞ⧇ xen āĻ…āĻ­āĻŋāĻ—āĻŽ āύāĻžāĻ•āϚ āϕ⧰āĻŋāϞ⧇āĨ¤ āϝāĻĻāĻŋ āχ āĻāϟāĻž XEN āĻ›āĻŦāĻŋ āĻšā§Ÿ, āĻ‡ā§ŸāĻžā§° āĻāϟāĻž xen_image_t āĻĢāĻžāχāϞ āĻĒā§°āĻŋāĻĒā§ā§°ā§‡āĻ•ā§āώāϤāĻŋāϤ āϞ⧇āĻŦ⧇āϞ āĻĨāĻžāĻ•āĻŋāĻŦ āϞāĻžāĻ—āĻŋāĻŦāĨ¤ āϚāĻŋāĻ¸ā§āĻŸā§‡āĻŽ āĻĄāĻžāχ⧰⧇āĻ•āϟ⧰āĻŋ /var/lib/xen/images āϤ āĻ›āĻŦāĻŋ āĻĢāĻžāχāϞāϏāĻŽā§‚āĻš āϏāĻ āĻŋāĻ•āĻ­āĻžā§ąā§‡ āϞ⧇āĻŦ⧇āϞ āϕ⧰āĻŋāĻŦāϞ⧇ āϏāĻ‚āĻ¸ā§āĻĨāĻžāĻĒāĻŋāϤāĨ¤ āφāĻŽāĻŋ āωāĻĒāĻĻ⧇āĻļ āĻĻāĻŋāĻ“ āϝ⧇ āφāĻĒ⧁āύāĻŋ āφāĻĒā§‹āύāĻžā§° āĻ›āĻŦāĻŋ āĻĢāĻžāχāϞāĻ• /var/lib/xen/images āĻ›āĻŦāĻŋāϤ āĻ•āĻĒāĻŋ āϕ⧰āĻ•āĨ¤ āϝāĻĻāĻŋ āφāĻĒ⧁āύāĻŋ āϏāρāϚāĻžāĻ•ā§ˆ āφāĻĒā§‹āύāĻžā§° xen āĻ›āĻŦāĻŋ āĻĢāĻžāχāϞāϏāĻŽā§‚āĻšāĻ• āĻŦā§°ā§āϤāĻŽāĻžāύ āĻĄāĻžāχ⧰⧇āĻ•āϟ⧰āĻŋāϤ āĻŦāĻŋāϚāĻžā§°ā§‡, āφāĻĒ⧁āύāĻŋ chcon āĻŦā§āĻ¯ā§ąāĻšāĻžā§° āϕ⧰āĻŋ $TARGET_PATH āĻ• xen_image_t āĻšāĻŋāϚāĻžāĻĒ⧇ āĻĒ⧁āύ⧰ āϞ⧇āĻŦ⧇āϞ āϕ⧰āĻŋāĻŦ āĻĒāĻžā§°āĻŋāĻŦāĨ¤ āφāĻĒ⧁āύāĻŋ āϞāĻ—āϤ⧇ āĻāχ āύāϤ⧁āύ āĻĒāĻĨāĻ• āϚāĻŋāĻ¸ā§āĻŸā§‡āĻŽ āĻ…āĻŦāĻŋāĻ•āĻ˛ā§āĻĒāĻŋāϤ āϝ⧋āĻ— āϕ⧰āĻŋāĻŦāϞ⧇ semanage fcontext -a -t xen_image_t '$FIX_TARGET_PATH' āĻāĻ•ā§āϏāĻŋāĻ•āĻŋāωāϟ āϕ⧰āĻŋāĻŦ āϞāĻžāĻ—āĻŋāĻŦāĨ¤ āϝāĻĻāĻŋ āφāĻĒ⧁āύāĻŋ $TARGET_PATH āĻ• āĻāϟāĻž xen āĻ›āĻŦāĻŋ āĻšāĻŋāϚāĻžāĻĒ⧇ āĻŦā§āĻ¯ā§ąāĻšāĻžā§° āϕ⧰āĻŋāĻŽ āĻŦ⧁āϞāĻŋ āĻ­āĻŦāĻž āύāĻžāχ āχ āĻāϟāĻž āĻŦāĻžāĻ— āĻ…āĻĨāĻŦāĻž āĻāϟāĻž āĻ…āύāĻžāϧāĻŋāĻ•āĻžā§° āĻĒā§ā§°ā§ąā§‡āĻļā§° āχāĻ‚āĻ—āĻŋāϤ āĻĻāĻŋāĻŦ āĻĒāĻžā§°ā§‡āĨ¤ SELinux āĻ āĻŦāĻŋāĻ­ā§ąā§€ā§ŸāĻ­āĻžā§ąā§‡ āϭ⧁āϞ āϞ⧇āĻŦ⧇āϞ āϕ⧰āĻž āĻĢāĻžāχāϞāϏāĻŽā§‚āĻš $TARGET_PATH āϞ⧇ $SOURCE āĻ…āĻ­āĻŋāĻ—āĻŽ āύāĻžāĻ•āϚ āϕ⧰āĻŋāϛ⧇āĨ¤ āχ āĻŦ⧁āϜāĻžā§Ÿ āϝ⧇ SELinux āĻ httpd āĻ• āĻāχ āĻĢāĻžāχāϞāϏāĻŽā§‚āĻš āĻŦā§āĻ¯ā§ąāĻšāĻžā§° āϕ⧰āĻžā§° āĻ…āύ⧁āĻŽāϤāĻŋ āύāĻŋāĻĻāĻŋāĻŦāĨ¤ āϝāĻĻāĻŋ httpd āĻ• āĻāχ āĻĢāĻžāχāϞāϏāĻŽā§‚āĻšāϞ⧇ āĻ…āĻ­āĻŋāĻ—āĻŽ āĻĻāĻŋāĻŦ āϞāĻžāϗ⧇ āφāĻĒ⧁āύāĻŋ āĻĢāĻžāχāϞ āĻĒā§°āĻŋāĻĒā§ā§°ā§‡āĻ•ā§āώāϤāĻŋāϤāĻ• āύāĻŋāĻŽā§āύāϞāĻŋāĻ–āĻŋāϤ āϧ⧰āĻŖāϏāĻŽā§‚āĻšā§° āĻāϟāĻžāϞ⧇, %s āϏāϞāύāĻŋ āϕ⧰āĻŋāĻŦ āϞāĻžāĻ—āĻŋāĻŦāĨ¤ āĻŦāĻšā§āϤ⧋ āϤ⧃āϤāĻŋ⧟ āĻĻāϞ āĻāĻĒā§āϞāĻŋāϕ⧇āϚāύāϏāĻŽā§‚āĻšā§‡ āĻĄāĻžāχ⧰⧇āĻ•āϟ⧰āĻŋāϏāĻŽā§‚āĻšāϤ html āĻĢāĻžāχāϞāϏāĻŽā§‚āĻš āχāύāĻ¸ā§āϟāϞ āϕ⧰⧇ āϝāĻžāĻ• SELinux āύāĻŋāϤāĻŋā§Ÿā§‡ āφāĻ—āϤāĻŋ⧟āĻžāĻ•ā§ˆ āĻ•āĻŦ āĻ¨ā§‹ā§ąāĻžā§°ā§‡āĨ¤ āĻāχ āĻĄāĻžāχ⧰⧇āĻ•āϟ⧰āĻŋāϏāĻŽā§‚āĻšāĻ• āĻāϟāĻž āĻĢāĻžāχāϞ āĻĒā§°āĻŋāĻĒā§ā§°ā§‡āϤāĻŋāϤ⧰ āϏāĻšāĻžā§ŸāϤ āϞ⧇āĻŦ⧇āϞ āϕ⧰āĻŋāĻŦ āϞāĻžāĻ—āĻŋāĻŦ āϝāĻžāĻ• httpd āĻ āĻ…āĻ­āĻŋāĻ—āĻŽ āϕ⧰āĻŋāĻŦ āĻĒāĻžā§°ā§‡āĨ¤ SELinux āĻ $SOURCE_PATH āĻ• āĻŦāĻŋāĻ­ā§ąā§€ā§ŸāĻ­āĻžā§ąā§‡ āϭ⧁āϞ āϧ⧰āϪ⧇ āϞ⧇āĻŦ⧇āϞ āϕ⧰āĻž āĻĢāĻžāχāϞāϏāĻŽā§‚āĻš $TARGET_PATH āĻāĻ•ā§āϏāĻŋāĻ•āĻŋāωāϟ āϕ⧰āĻž āύāĻžāĻ•āϚ āϕ⧰āĻŋāϛ⧇āĨ¤ āĻ¸ā§āĻŦāĻŽāĻžāωāĻ¨ā§āϟāĻžā§°āĻ• āϏāς⧰⧂āĻĒ āĻĢāĻžāχāϞāϏāĻŽā§‚āĻš āĻāĻ•ā§āϏāĻŋāĻ•āĻŋāωāϟ āϕ⧰āĻŋāĻŦāϞ⧇ āϏāĻ‚āĻ¸ā§āĻĨāĻžāĻĒāύ āϕ⧰āĻŋāĻŦ āĻĒāĻžā§°āĻŋāĨ¤ āϝāĻĻāĻŋ $TARGET_PATH āĻāϟāĻž āĻ¸ā§āĻŦāĻŽāĻžāωāĻ¨ā§āϟ āĻāĻ•ā§āϏāĻŋāĻ•āĻŋāωāĻŸā§‡āĻŦ⧁āϞ āϏāς⧰⧂āĻĒ āĻĢāĻžāχāϞ āĻ‡ā§ŸāĻžā§° bin_t āϞ⧇āĻŦ⧇āϞ āĻĨāĻžāĻ•āĻŋāĻŦ āϞāĻžāĻ—āĻŋāĻŦāĨ¤ āϝāĻĻāĻŋ āĻ¸ā§āĻŦāĻŽāĻžāωāĻ¨ā§āϟāĻžā§°ā§‡ āĻāĻ•ā§āϏāĻŋāĻ•āĻŋāωāϟ āϕ⧰āĻŋāĻŦ āύāϞāĻ—āĻž āĻ•āĻŋāĻŦāĻžāĻ• āĻāĻ•ā§āϏāĻŋāĻ•āĻŋāωāϟ āϕ⧰āĻžā§° āĻšā§‡āĻˇā§āϟāĻž āϕ⧰āĻŋ āφāϛ⧇, āχ āĻāϟāĻž āĻ…āύāĻžāϧāĻŋāĻ•āĻžā§° āĻĒā§ā§°ā§ąā§‡āĻļā§° āχāĻ‚āĻ—āĻŋāϤ āĻĻāĻŋāĻŦ āĻĒāĻžā§°ā§‡āĨ¤ SELinux āĻ vbetool āĻ• āĻāϟāĻž āĻ…āϏ⧁⧰āĻ•ā§āώāĻŋāϤ āĻŽā§‡āĻŽā§°āĻŋ āĻ•āĻžā§°ā§āĻ¯ā§āϝ āĻĒā§°āĻŋā§ąā§‡āĻļāύ āϕ⧰āĻžā§° āĻĒā§°āĻž āĻĒā§ā§°āϤāĻŋā§°ā§‹āϧ āϕ⧰āĻŋāϛ⧇āĨ¤ SELinux āĻ wine āĻ• āĻāϟāĻž āĻ…āϏ⧁⧰āĻ•ā§āώāĻŋāϤ āĻŽā§‡āĻŽā§°āĻŋ āĻ•āĻžā§°ā§āĻ¯ā§āϝ āĻĒā§°āĻŋā§ąā§‡āĻļāύ āϕ⧰āĻžā§° āĻĒā§°āĻž āĻĒā§ā§°āϤāĻŋā§°ā§‹āϧ āϕ⧰āĻŋāϛ⧇āĨ¤ SELinux āĻ $TARGET_PATH āϤ $SOURCE_PATH "$ACCESS" āĻ…āĻ­āĻŋāĻ—āĻŽ āĻĒā§ā§°āϤāĻŋā§°ā§‹āϧ āϕ⧰āĻŋ āφāϛ⧇āĨ¤ SELinux āĻ $TARGET_PATH āϞ⧇ $SOURCE_PATH "$ACCESS" āĻ…āĻ­āĻŋāĻ—āĻŽ āĻĒā§ā§°āϤāĻŋā§°ā§‹āϧ āϕ⧰āĻŋ āφāϛ⧇āĨ¤ SELinux āĻ $TARGET_PATH āϞ⧇ $SOURCE_PATH "$ACCESS" āĻ…āĻ­āĻŋāĻ—āĻŽ āĻĒā§ā§°āϤāĻŋā§°ā§‹āϧ āϕ⧰āĻŋ āφāϛ⧇āĨ¤ SELinux āĻ āĻāϟāĻž $TARGET_PATH āĻĢāĻžāχāϞ āĻŦāĻŋā§ąā§°āĻ•āϞ⧇ $SOURCE_PATH āĻ…āĻ­āĻŋāĻ—āĻŽ āĻĒā§ā§°āϤāĻŋā§°ā§‹āϧ āϕ⧰āĻŋ āφāϛ⧇āĨ¤ SELinux āĻ $SOURCE_PATH āĻ• āĻĒā§‹ā§°ā§āϟ $PORT_NUMBER āϞāĻ—āϤ āϏāĻ‚āϝ⧋āĻ— āϕ⧰āĻžā§° āĻĒā§°āĻž āĻĒā§ā§°āϤāĻŋā§°ā§‹āϧ āϕ⧰āĻŋ āφāϛ⧇āĨ¤ SELinux āĻ $SOURCE_PATH āĻ• āĻšāĻŋāĻĒāϤ āĻŽā§‡āĻŽā§°āĻŋā§° āĻ…āĻ­āĻŋāĻ—āĻŽ āϏ⧁⧰āĻ•ā§āώāĻž āϏāϞāύāĻŋ āϕ⧰āĻžā§° āĻĒā§°āĻž āĻĒā§ā§°āϤāĻŋā§°ā§‹āϧ āϕ⧰āĻŋ āφāϛ⧇āĨ¤ SELinux āĻ $SOURCE_PATH āĻ• āĻĒā§‹ā§°ā§āϟ $PORT_NUMBER āϞāĻ—āϤ āϏāĻ‚āϝ⧋āĻ— āϕ⧰āĻžā§° āĻĒā§°āĻž āĻĒā§ā§°āϤāĻŋā§°ā§‹āϧ āϕ⧰āĻŋ āφāϛ⧇āĨ¤ SELinux āĻ $SOURCE_PATH āĻ• āĻāϟāĻž āĻĢāĻžāχāϞāϚāĻŋāĻ¸ā§āĻŸā§‡āĻŽāϤ $SOURCE_TYPE ā§° āĻāϟāĻž āĻĒā§°āĻŋāĻĒā§ā§°ā§‡āĻ•ā§āώāϤāĻŋāϤ⧰ āϏ⧈āϤ⧇ āĻāϟāĻž āĻĢāĻžāχāϞ āϏ⧃āĻˇā§āϟāĻŋ āϕ⧰āĻžā§° āĻĒā§°āĻž āĻĒā§ā§°āϤāĻŋā§°ā§‹āϧ āϕ⧰āĻŋ āφāϛ⧇āĨ¤ SELinux āĻ $SOURCE_PATH āĻ• $TARGET_PATH āϞ'āĻĄ āϕ⧰āĻžā§° āĻĒā§°āĻž āĻĒā§ā§°āϤāĻŋā§°ā§‹āϧ āϕ⧰āĻŋ āφāϛ⧇ āϝāĻžā§° āĻĒāĻžāĻ  āφāĻŦāĻ¨ā§āϟāύ⧰ āĻĒā§ā§°ā§Ÿā§‹āϜāύāĨ¤ SELinux āĻ $SOURCE_PATH āĻ• āĻĒā§ā§°āĻ—ā§ā§°āĻžāĻŽ āĻ¸ā§āĻŸā§‡āĻ•āĻ• āĻāĻ•ā§āϏāĻŋāĻ•āĻŋāωāĻŸā§‡āĻŦ⧁āϞ āϕ⧰āĻžā§° āĻĒā§°āĻž āĻĒā§ā§°āϤāĻŋā§°ā§‹āϧ āϕ⧰āĻŋ āφāϛ⧇āĨ¤ SELinux āĻ $TARGET_PATH āϞ⧇ Samba ($SOURCE_PATH) "$ACCESS" āĻ…āĻ­āĻŋāĻ—āĻŽ āĻĒā§ā§°āϤāĻŋā§°ā§‹āϧ āϕ⧰āĻŋ āφāϛ⧇āĨ¤ SELinux āĻ $TARGET_PATH āϞ⧇ cvs ($SOURCE_PATH) "$ACCESS" āĻ…āĻ­āĻŋāĻ—āĻŽ āĻĒā§ā§°āϤāĻŋā§°ā§‹āϧ āϕ⧰āĻŋ āφāϛ⧇ SELinux āĻ $SOURCE_PATH āĻ• āĻŦāĻŋāĻ­ā§ąā§€ā§ŸāĻ­āĻžā§ąā§‡ āϭ⧁āϞāϞ⧇āĻŦ⧇āϞ āĻĢāĻžāχāϞ $TARGET_PATH āĻāĻ•ā§āϏāĻŋāĻ•āĻŋāωāϟ āϕ⧰āĻžā§° āĻĒā§°āĻž āĻĒā§ā§°āϤāĻŋā§°ā§‹āϧ āϕ⧰āĻŋ āφāϛ⧇āĨ¤ SELinux āĻ http āĻĄāĻŋāĻŽāύāĻ• āĻŽā§‡āχāϞ āĻāĻ•ā§āϏāĻŋāĻ•āĻŋāωāϟ āϕ⧰āĻžā§° āĻĒā§°āĻž āĻĒā§ā§°āϤāĻŋā§°ā§‹āϧ āϕ⧰āĻŋ āφāϛ⧇āĨ¤ SELinux āĻ $TARGET_PATH āϞ⧇ xen ($SOURCE_PATH) "$ACCESS" āĻ…āĻ­āĻŋāĻ—āĻŽ āĻĒā§ā§°āϤāĻŋā§°ā§‹āϧ āϕ⧰āĻŋ āφāϛ⧇āĨ¤ SELinux āύ⧀āϤāĻŋā§Ÿā§‡ āĻāϟāĻž httpd āϞāĻŋāĻĒāĻŋāĻ• āĻāϟāĻž ā§°āĻžāϜāĻšā§ā§ąāĻž āĻĄāĻžāχ⧰⧇āĻ•āϟ⧰āĻŋāϞ⧇ āϞāĻŋāĻ–āĻžā§° āĻĒā§°āĻž āĻĒā§ā§°āϤāĻŋā§°ā§‹āϧ āϕ⧰āĻŋ āφāϛ⧇āĨ¤ SELinux āύ⧀āϤāĻŋā§Ÿā§‡ āĻāϟāĻž httpd āϞāĻŋāĻĒāĻŋāĻ• āĻāϟāĻž ā§°āĻžāϜāĻšā§ā§ąāĻž āĻĄāĻžāχ⧰⧇āĻ•āϟ⧰āĻŋāϞ⧇ āϞāĻŋāĻ–āĻžā§° āĻĒā§°āĻž āĻĒā§ā§°āϤāĻŋā§°ā§‹āϧ āϕ⧰āĻŋ āφāϛ⧇āĨ¤ āϝāĻĻāĻŋ httpd āĻ• ā§°āĻžāϜāĻšā§ā§ąāĻž āĻĄāĻžāχ⧰⧇āĻ•āϟ⧰āĻŋāϞ⧇ āϞāĻŋāĻ–āĻžā§° āĻŦāĻžāĻŦ⧇ āϏāĻ‚āĻšāϤ āϕ⧰āĻž āĻšā§‹ā§ąāĻž āύāĻžāχ, āχ āĻāϟāĻž āĻ…āύāĻžāϧāĻŋāĻ•āĻžā§° āĻĒā§ā§°ā§ąā§‡āĻļā§° āĻšā§‡āĻˇā§āϟāĻž āχāĻ‚āĻ—āĻŋāϤ āϕ⧰āĻŋāĻŦ āĻĒāĻžā§°ā§‡āĨ¤ SELinux āĻ $SOURCE āĻ• āĻĢāĻžāχāϞ āĻ…āĻĨāĻŦāĻž āĻĄāĻžāχ⧰⧇āĻ•āϟ⧰āĻŋāϤ āĻŽāĻžāωāĻ¨ā§āϟ āϕ⧰āĻžā§° āĻĒā§°āĻž āĻĒā§ā§°āϤāĻŋā§°ā§‹āϧ āϕ⧰āĻŋāĻ›āĻŋāϞ "$TARGET_PATH" (type "$TARGET_TYPE")āĨ¤ SELinux http āĻĢāĻžāχāϞāϏāĻŽā§‚āĻšāϞ⧇ httpd $ACCESS āĻ…āĻ­āĻŋāĻ—āĻŽ āĻĒā§ā§°āϤāĻŋā§°ā§‹āϧ āϕ⧰āĻŋāϞ⧇āĨ¤ SELinux āĻ ftp āĻĄāĻŋāĻŽāύāĻ• āĻāϟāĻž CIFS āĻĢāĻžāχāϞāϚāĻŋāĻ¸ā§āĻŸā§‡āĻŽāϤ āϏāς⧰āĻ•ā§āώāĻŋāϤ āĻĢāĻžāχāϞāϏāĻŽā§‚āĻš $ACCESS ā§° āĻĒā§°āĻž āĻĒā§ā§°āϤāĻŋā§°ā§‹āϧ āϕ⧰āĻŋāϞ⧇āĨ¤ SELinux āĻ ftp āĻĄāĻŋāĻŽāύāĻ• āĻāϟāĻž NFS āĻĢāĻžāχāϞāϚāĻŋāĻ¸ā§āĻŸā§‡āĻŽāϤ āϏāς⧰āĻ•ā§āώāĻŋāϤ āĻĢāĻžāχāϞāϏāĻŽā§‚āĻš $ACCESS ā§° āĻĒā§°āĻž āĻĒā§ā§°āϤāĻŋā§°ā§‹āϧ āϕ⧰āĻŋāϞ⧇āĨ¤ $SOURCE āĻāĻĒā§āϞāĻŋāϕ⧇āϚāύ⧇ āĻšāĻŋāĻĒāϤ āĻŽā§‡āĻŽā§°āĻŋā§° āĻ…āĻ­āĻŋāĻ—āĻŽ āϏ⧁⧰āĻ•ā§āώāĻž āĻĒā§°āĻŋā§ąā§°ā§āϤāύ āϕ⧰āĻžā§° āĻšā§‡āĻˇā§āϟāĻž āϕ⧰āĻŋāϛ⧇ (āωāĻĻāĻžāĻšā§°āĻŖāĻ¸ā§āĻŦā§°ā§‚āĻĒ, malloc āĻŦā§āĻ¯ā§ąāĻšāĻžā§° āϕ⧰āĻŋ āφāĻŦāĻ¨ā§āϟāĻŋāϤ)āĨ¤ āχ āĻāϟāĻž āĻŦāĻŋāĻ­ā§ąā§€ā§Ÿ āϏ⧁⧰āĻ•ā§āώāĻž āϏāĻŽāĻ¸ā§āϝāĻžāĨ¤ āĻāĻĒā§āϞāĻŋāϕ⧇āϚāύāϏāĻŽā§‚āĻšā§‡ āĻāύ⧇ āϕ⧰āĻŋāĻŦ āύāĻžāϞāĻžāϗ⧇āĨ¤ āĻāĻĒā§āϞāĻŋāϕ⧇āϚāύāϏāĻŽā§‚āĻš āϕ⧇āϤāĻŋ⧟āĻžāĻŦāĻž āĻ­ā§‚āϞāĻ­āĻžā§ąā§‡ āĻ•'āĻĄ āϕ⧰āĻž āĻĨāĻžāϕ⧇ āφ⧰⧁ āĻāχ āĻ…āύ⧁āĻŽāϤāĻŋ āĻ…āύ⧁⧰⧋āϧ āϕ⧰⧇āĨ¤ SELinux āĻŽā§‡āĻŽā§°āĻŋ āϏ⧁⧰āĻ•ā§āώāĻž āĻĒā§°āĻŋāĻ•ā§āώāĻžāϏāĻŽā§‚āĻš ā§ąā§‡āĻŦ āĻĒ⧃āĻˇā§āĻ āĻžā§Ÿ āϕ⧇āύ⧇āĻĻ⧰⧇ āĻāχ āĻĒā§ā§°ā§Ÿā§‹āϜāĻ¨ā§€ā§ŸāϤāĻž āφāĻ¤ā§°ā§‹ā§ąāĻž āĻšāĻŦ āϤāĻžā§° āĻŦāĻŋā§ąā§°āĻŖ āĻĻāĻŋā§Ÿā§‡āĨ¤ āϝāĻĻāĻŋ $SOURCE āĻ•āĻžā§°ā§āĻ¯ā§āϝ āύāϕ⧰⧇ āφ⧰⧁ āφāĻĒ⧁āύāĻŋ āĻ‡ā§ŸāĻžāĻ• āĻ•āĻžā§°ā§āĻ¯ā§āϝāϤ āϕ⧰āĻŋāĻŦ āĻŦāĻŋāϚāĻžā§°ā§‡, āφāĻĒ⧁āύāĻŋ SELinux āĻ• āĻ…āĻ¸ā§āĻĨāĻžā§Ÿā§€āĻ­āĻžā§ąā§‡ āĻāχ āĻ…āĻ­āĻŋāĻ—āĻŽā§° āĻ…āύ⧁āĻŽāϤāĻŋ āĻĻāĻŋāĻŦāϞ⧇ āϏāς⧰⧂āĻĒāĻŖ āϕ⧰āĻŋāĻŦ āĻĒāĻžā§°ā§‡ āϝ⧇āϤāĻŋ⧟āĻžāϞ⧈āϕ⧇ āĻāĻĒā§āϞāĻŋāϕ⧇āϚāύ āĻ āĻŋāĻ• āĻšā§ˆ āύāĻžāϝāĻžā§ŸāĨ¤ āĻ…āύ⧁āĻ—ā§ā§°āĻš āϕ⧰āĻŋ āĻāχ āĻĒ⧇āϕ⧇āχāϜ⧰ āĻŦāĻŋāĻĒā§°āĻŋāϤ⧇ āĻāϟāĻž āĻŦāĻžāĻ— āϏāĻ‚āĻŦāĻžāĻĻ āϜāĻŽāĻž āĻĻāĻŋ⧟āĻ•āĨ¤ SELinux āĻĒā§°āĻŋāĻĒā§ā§°ā§‡āĻ•ā§āώāϤāĻŋāϤ⧰ āĻŦāĻžāĻšāĻŋ⧰⧇ āϏāĻ•āϞ⧋ āĻ…āύ⧁āĻŽāϤāĻŋ āϏāς⧰āĻ•ā§āώāĻŖ āϕ⧰āĻŋāĻŦāϞ⧇ "cp -p" ā§° āύāĻŋāϚāĻŋāύāĻž āĻāϟāĻž āĻ•āĻŽāĻžāĻ¨ā§āĻĄ āĻŦā§āĻ¯ā§ąāĻšāĻžā§° āϕ⧰āĻ•āĨ¤ āφāĻĒ⧁āύāĻŋ chcon -R -t rsync_data_t '$TARGET_PATH' āĻāĻ•ā§āϏāĻŋāĻ•āĻŋāωāϟ āϕ⧰āĻŋ āĻĢāĻžāχāϞ āĻĒā§°āĻŋāĻĒā§ā§°ā§‡āĻ•ā§āώāϤāĻŋāϤ āϏāϞāύāĻŋ āϕ⧰āĻŋāĻŦ āĻĒāĻžā§°āĻŋāĻŦ āφāĻĒ⧁āύāĻŋ āϞāĻ—āϤ⧇ āϚāĻŋāĻ¸ā§āĻŸā§‡āĻŽāϤ āĻ…āĻŦāĻŋāĻ•āĻ˛ā§āĻĒāĻŋāϤ āĻĢāĻžāχāϞ āĻĒā§°āĻŋāĻĒā§ā§°ā§‡āĻ•ā§āώāϤāĻŋāϤ āĻĢāĻžāχāϞāϏāĻŽā§‚āĻš āϏāϞāύāĻŋ āϕ⧰āĻŋāĻŦ āϞāĻžāĻ—āĻŋāĻŦ āϏāĻŋāĻšāϤāĻ• āĻāϟāĻž āϏāĻŽā§āĻĒā§‚ā§°ā§āĻŖ āĻĒ⧁āύ⧰āϞ⧇āĻŦ⧇āϞāϤ āϏāς⧰āĻ•ā§āώāĻŖ āϕ⧰āĻŋāĻŦāϞ⧇āĨ¤ "semanage fcontext -a -t rsync_data_t '$FIX_TARGET_PATH'" āφāĻĒ⧁āύāĻŋ chcon -R -t samba_share_t '$TARGET_PATH' āĻāĻ•ā§āϏāĻŋāĻ•āĻŋāωāϟ āϕ⧰āĻŋ āĻĢāĻžāχāϞ āĻĒā§°āĻŋāĻĒā§ā§°ā§‡āĻ•ā§āώāϤāĻŋāϤ āϏāϞāύāĻŋ āϕ⧰āĻŋāĻŦ āĻĒāĻžā§°āĻŋāĻŦ āφāĻĒ⧁āύāĻŋ āϞāĻ—āϤ⧇ āϚāĻŋāĻ¸ā§āĻŸā§‡āĻŽāϤ āĻ…āĻŦāĻŋāĻ•āĻ˛ā§āĻĒāĻŋāϤ āĻĢāĻžāχāϞ āĻĒā§°āĻŋāĻĒā§ā§°ā§‡āĻ•ā§āώāϤāĻŋāϤ āĻĢāĻžāχāϞāϏāĻŽā§‚āĻš āϏāϞāύāĻŋ āϕ⧰āĻŋāĻŦ āϞāĻžāĻ—āĻŋāĻŦ āϝāĻžāϤ⧇ āϏāĻŋāĻšāϤāĻ• āĻāϟāĻž āϏāĻŽā§āĻĒā§‚ā§°ā§āĻŖ āĻĒ⧁āύ⧰āϞ⧇āĻŦ⧇āϞāϤ āϏāς⧰āĻ•ā§āώ⧰āĻŖ āϕ⧰āĻŋāĻŦ āĻĒāĻžā§°āĻŋāĨ¤ "semanage fcontext -a -t samba_share_t '$FIX_TARGET_PATH'" āφāĻĒ⧁āύāĻŋ āĻĢāĻžāχāϞ āĻĒā§°āĻŋāĻĒā§ā§°ā§‡āĻ•ā§āώāϤāĻŋāϤāĻ• chcon -t public_content_t '$TARGET_PATH' āĻāĻ•ā§āϏāĻŋāĻ•āĻŋāωāϟ āϕ⧰āĻŋ āϏāϞāύāĻŋ āϕ⧰āĻŋāĻŦ āĻĒāĻžā§°āĻŋāĻŦ āφāĻĒ⧁āύāĻŋ āϞāĻ—āϤ⧇ āϚāĻŋāĻ¸ā§āĻŸā§‡āĻŽā§° āĻ…āĻŦāĻŋāĻ•āĻ˛ā§āĻĒāĻŋāϤ āĻĢāĻžāχāϞ āĻĒā§°āĻŋāĻĒā§ā§°ā§‡āĻ•ā§āώāϤāĻŋāϤ āĻĢāĻžāχāϞāϏāĻŽā§‚āĻš āϏāϞāύāĻŋ āϕ⧰āĻŋāĻŦ āϞāĻžāĻ—āĻŋāĻŦ āϝāĻžāϤ⧇ āϏāĻŋāĻšāϤāĻ• āĻāϟāĻž āϏāĻŽā§āĻĒā§‚ā§°ā§āĻŖ āĻĒ⧁āύ⧰āϞ⧇āĻŦ⧇āϞāϤ āϏāς⧰āĻ•ā§āώāĻŖ āϕ⧰āĻŋāĻŦ āĻĒāĻžā§°āĻŋāĨ¤ "semanage fcontext -a -t public_content_t '$FIX_TARGET_PATH'" āφāĻĒ⧁āύāĻŋ chcon -t swapfile_t '$TARGET_PATH' āĻāĻ•ā§āϏāĻŋāĻ•āĻŋāωāϟ āϕ⧰āĻŋ āĻĢāĻžāχāϞ āĻĒā§°āĻŋāĻĒā§ā§°ā§‡āĻ•ā§āώāϤāĻŋāϤ āϏāϞāύāĻŋ āϕ⧰āĻŋāĻŦ āĻĒāĻžā§°āĻŋāĻŦ āφāĻĒ⧁āύāĻŋ āϞāĻ—āϤ⧇ āϚāĻŋāĻ¸ā§āĻŸā§‡āĻŽāϤ āĻ…āĻŦāĻŋāĻ•āĻ˛ā§āĻĒāĻŋāϤ āĻĢāĻžāχāϞ āĻĒā§°āĻŋāĻĒā§ā§°ā§‡āĻ•ā§āώāϤāĻŋāϤ āĻĢāĻžāχāϞāϏāĻŽā§‚āĻš āϏāϞāύāĻŋ āϕ⧰āĻŋāĻŦ āϞāĻžāĻ—āĻŋāĻŦ āϝāĻžāϤ⧇ āϏāĻŋāĻšāϤāĻ• āĻāϟāĻž āϏāĻŽā§āĻĒā§‚ā§°ā§āĻŖ āĻĒ⧁āύ⧰āϞ⧇āĻŦ⧇āϞāϤ āϏāς⧰āĻ•ā§āώāĻŖ āϕ⧰āĻŋāĻŦ āĻĒāĻžā§°āĻŋāĨ¤ "semanage fcontext -a -t swapfile_t '$FIX_TARGET_PATH'" āφāĻĒ⧁āύāĻŋ āĻĢāĻžāχāϞ āĻĒā§°āĻŋāĻĒā§ā§°ā§‡āĻ•ā§āώāϤāĻŋāϤāĻ• chcon -t virt_image_t '$TARGET_PATH' āĻāĻ•ā§āϏāĻŋāĻ•āĻŋāωāϟ āϕ⧰āĻŋ āϏāϞāύāĻŋ āϕ⧰āĻŋāĻŦ āĻĒāĻžā§°āĻŋāĻŦ āφāĻĒ⧁āύāĻŋ āϞāĻ—āϤ⧇ āϚāĻŋāĻ¸ā§āĻŸā§‡āĻŽāϤ āĻ…āĻŦāĻŋāĻ•āĻ˛ā§āĻĒāĻŋāϤ āĻĢāĻžāχāϞ āĻĒā§°āĻŋāĻĒā§ā§°ā§‡āĻ•ā§āώāϤāĻŋāϤ āĻĢāĻžāχāϞāϏāĻŽā§‚āĻš āϏāϞāύāĻŋ āϕ⧰āĻŋāĻŦ āϞāĻžāĻ—āĻŋāĻŦ āϝāĻžāϤ⧇ āϏāĻŋāĻšāϤāĻ• āĻāϟāĻž āϏāĻŽā§āĻĒā§‚ā§°ā§āĻŖ āĻĒ⧁āύ⧰ āϞ⧇āĻŦ⧇āϞāϤ āϏāς⧰āĻ•ā§āώāĻŖ āϕ⧰āĻŋāĻŦ āĻĒāĻžā§°āĻŋāĨ¤ "semanage fcontext -a -t virt_image_t '$FIX_TARGET_PATH'" āφāĻĒ⧁āύāĻŋ chcon -t xen_image_t '$TARGET_PATH' āĻāĻ•ā§āϏāĻŋāĻ•āĻŋāωāϟ āϕ⧰āĻŋ āĻĢāĻžāχāϞ āĻĒā§°āĻŋāĻĒā§ā§°ā§‡āĻ•ā§āώāϤāĻŋāϤ āϏāϞāύāĻŋ āϕ⧰āĻŋāĻŦ āĻĒāĻžā§°āĻŋāĻŦ āφāĻĒ⧁āύāĻŋ āϞāĻ—āϤ⧇ āϚāĻŋāĻ¸ā§āĻŸā§‡āĻŽā§° āĻ…āĻŦāĻŋāĻ•āĻ˛ā§āĻĒāĻŋāϤ āĻĢāĻžāχāϞ āĻĒā§°āĻŋāĻĒā§ā§°ā§‡āĻ•ā§āώāϤāĻŋāϤ āĻĢāĻžāχāϞāϏāĻŽā§‚āĻš āϏāϞāύāĻŋ āϕ⧰āĻŋāĻŦ āϞāĻžāĻ—āĻŋāĻŦ āϝāĻžāϤ⧇ āϏāĻŋāĻšāϤāĻ• āĻāϟāĻž āϏāĻŽā§āĻĒā§‚ā§°ā§āĻŖ āĻĒ⧁āύ⧰āϞ⧇āĻŦ⧇āϞāϤ āϏāς⧰āĻ•ā§āώāĻŖ āϕ⧰āĻŋāĻŦ āĻĒāĻžā§°āĻŋāĨ¤ "semanage fcontext -a -t xen_image_t '$FIX_TARGET_PATH'" āφāĻĒ⧁āύāĻŋ āφāĻĒā§‹āύāĻžā§° āĻ•āĻŽāĻĒāĻŋāωāϟāĻžā§° āϚāĻŋāĻ¸ā§āĻŸā§‡āĻŽ āĻĒ⧁āύ⧰ āϞ⧇āĻŦ⧇āϞ āϕ⧰āĻŋāĻŦāϞ⧇ āύāĻŋāĻŽā§āύāϞāĻŋāĻ–āĻŋāϤ āĻ•āĻŽāĻžāĻ¨ā§āĻĄāĻ• ⧰⧁āϟ āĻšāĻŋāϚāĻžāĻĒ⧇ āĻĒā§ā§°ā§‡ā§°āĻŖ āϕ⧰āĻŋāĻŦ āĻĒāĻžā§°ā§‡: "touch /.autorelabel; reboot" āφāĻĒ⧁āύāĻŋ āĻāχ āĻ…āĻ­āĻŋāĻ—āĻŽā§° āĻ…āύ⧁āĻŽāϤāĻŋ āĻĻāĻŋāĻŦāϞ⧇ āĻāϟāĻž āĻ¸ā§āĻĨāĻžāĻ¨ā§€ā§Ÿ āύ⧀āϤāĻŋ āĻŽāĻĄāĻŋāωāϞ āϏ⧃āϜāύ āϕ⧰āĻŋāĻŦ āĻĒāĻžā§°ā§‡ - FAQ āϚāĻžāĻ“āĻ• āĻ…āύ⧁āĻ—ā§ā§°āĻš āϕ⧰āĻŋ āĻāϟāĻž āĻŦāĻžāĻ— āϏāĻ‚āĻŦāĻžāĻĻ āϜāĻŽāĻž āĻĻāĻŋ⧟āĻ•āĨ¤ āφāĻĒ⧁āύāĻŋ āĻāχ āĻ…āĻ­āĻŋāĻ—āĻŽā§° āĻ…āύ⧁āĻŽāϤāĻŋ āĻĻāĻŋāĻŦāϞ⧇ āĻāϟāĻž āĻ¸ā§āĻĨāĻžāĻ¨ā§€ā§Ÿ āύ⧀āϤāĻŋ āĻŽāĻĄāĻŋāωāϞ āϏ⧃āϜāύ āϕ⧰āĻŋāĻŦ āĻĒāĻžā§°ā§‡ - FAQ āϚāĻžāĻ“āĻ• āφāĻĒ⧁āύāĻŋ āĻāχ āĻĢāĻžāχāϞāϞ⧈ āĻ…āĻŦāĻŋāĻ•āĻ˛ā§āĻĒāĻŋāϤ āϚāĻŋāĻ¸ā§āĻŸā§‡āĻŽ āĻĒā§°āĻŋāĻĒā§ā§°ā§‡āĻ•ā§āώāϤāĻŋāϤ āĻĒ⧁āύ⧰⧁āĻĻā§āϧāĻžā§° āϕ⧰āĻŋāĻŦ āĻĒāĻžā§°āĻŋāĻŦ restorecon āĻ•āĻŽāĻžāĻ¨ā§āĻĄ āĻāĻ•ā§āϏāĻŋāĻ•āĻŋāωāϟ āϕ⧰āĻŋāĨ¤ restorecon '$SOURCE_PATH'. āφāĻĒ⧁āύāĻŋ restorecon āĻ•āĻŽāĻžāĻ¨ā§āĻĄ āĻāĻ•ā§āϏāĻŋāĻ•āĻŋāωāϟ āϕ⧰āĻŋ āĻ…āĻŦāĻŋāĻ•āĻ˛ā§āĻĒāĻŋāϤ āϚāĻŋāĻ¸ā§āĻŸā§‡āĻŽ āĻĒā§°āĻŋāĻĒā§ā§°ā§‡āĻ•ā§āώāϤāĻŋāϤāĻ• āĻāχ āĻĢāĻžāχāϞāϞ⧇ āĻĒ⧁āύ⧰āωāĻĻā§āϧāĻžā§° āϕ⧰āĻŋāĻŦ āĻĒāĻžā§°āĻŋāĻŦāĨ¤ restorecon '$TARGET_PATH', āϝāĻĻāĻŋ āĻāχ āĻĢāĻžāχāϞ āĻāϟāĻž āĻĄāĻžāχ⧰⧇āĻ•āϟ⧰āĻŋ āĻšā§Ÿ, āφāĻĒ⧁āύāĻŋ restorecon -R '$TARGET_PATH' āĻŦā§āĻ¯ā§ąāĻšāĻžā§° āϕ⧰āĻŋ āĻŦāĻžā§°āĻ‚āĻŦāĻžā§° āĻĒ⧁āύ⧰āωāĻĻā§āϧāĻžā§° āϕ⧰āĻŋāĻŦ āĻĒāĻžā§°āĻŋāĻŦāĨ¤ āφāĻĒā§‹āύāĻžā§° āϚāĻŋāĻ¸ā§āĻŸā§‡āĻŽāϤ āϗ⧁⧰⧁āϤ⧰āĻ­āĻžā§ąā§‡ āϏāĻžāϞ āϏāϞāύāĻŋ āĻšāĻŦ āĻĒāĻžā§°ā§‡! āφāĻĒā§‹āύāĻžā§° āϚāĻŋāĻ¸ā§āĻŸā§‡āĻŽ āϗ⧁⧰⧁āϤ⧰āĻ­āĻžā§ąā§‡ āϏāĻžāϞ āϏāϞāύāĻŋ āĻšāĻŦ āĻĒāĻžā§°ā§‡! $SOURCE_PATH āĻ āύāĻŋāĻŽā§āύ āĻ•āĻžā§°āύ⧇āϞ āĻŽā§‡āĻŽā§°āĻŋ mmap āϕ⧰āĻžā§° āĻšā§‡āĻˇā§āϟāĻž āϕ⧰āĻŋāĻ›āĻŋāϞāĨ¤ āφāĻĒā§‹āύāĻžā§° āϚāĻŋāĻ¸ā§āĻŸā§‡āĻŽāϤ āϗ⧁⧰āϤ⧰āĻ­āĻžā§ąā§‡ āϏāĻžāϞ āϏāϞāύāĻŋ āĻšāĻŦ āĻĒāĻžā§°ā§‡! $SOURCE_PATH āĻ āĻāϟāĻž āĻ•āĻžā§°āύ⧇āϞ āĻŽāĻĄāĻŋāωāϞ āϞ'āĻĄ āϕ⧰āĻžā§° āĻšā§‡āĻˇā§āϟāĻž āϕ⧰āĻŋāĻ›āĻŋāϞāĨ¤ āφāĻĒā§‹āύāĻžā§° āϚāĻŋāĻ¸ā§āĻŸā§‡āĻŽāϤ āϗ⧁⧰⧁āϤ⧰āĻ­āĻžā§ąā§‡ āϏāĻžāϞ āϏāϞāύāĻŋ āĻšāĻŦ āĻĒāĻžā§°ā§‡! $SOURCE_PATH āĻ SELinux āĻŦāĻ˛ā§ąā§Žāϕ⧰āĻŖ āϏāϞāύāĻŋ āϕ⧰āĻžā§° āĻšā§‡āĻˇā§āϟāĻž āϕ⧰āĻŋāĻ›āĻŋāϞāĨ¤ āφāĻĒā§‹āύāĻžā§° āϚāĻŋāĻ¸ā§āĻŸā§‡āĻŽāϤ āϗ⧁⧰⧁āϤ⧰āĻ­āĻžā§ąā§‡ āϏāĻžāϞ āϏāĻžāϞāύāĻŋ āĻšāĻŦ āĻĒāĻžā§°ā§‡! $SOURCE_PATH āĻ āĻ•āĻžā§°āύ⧇āϞ āϏāς⧰⧂āĻĒ āϏāϞāύāĻŋ āϕ⧰āĻžā§° āĻšā§‡āĻˇā§āϟāĻž āϕ⧰āĻŋāĻ›āĻŋāϞāĨ¤ IPV6 āϏāĻ āĻŋāĻ•āĻ­āĻžā§ąā§‡ āĻ…āϏāĻžāĻŽā§°ā§āĻĨāĻŦāĻžāύ āϕ⧰āĻ•āĨ¤ āĻšā§Ÿ mozplluger āĻĒ⧇āϕ⧇āχāϜāĻ• 'yum remove mozplugger' āĻāĻ•ā§āϏāĻŋāĻ•āĻŋāωāϟ āϕ⧰āĻŋ āφāϤ⧰āĻžāĻ“āĻ• āĻ…āĻĨāĻŦāĻž Firefox āĻĒā§āϞāĻžāĻ—āĻŋāύāϏāĻŽā§‚āĻšāϤ SELinux enforcement āĻŦāĻ¨ā§āϧ āϕ⧰āĻ•āĨ¤ setsebool -P unconfined_mozilla_plugin_transition 0 āϝāĻĻāĻŋ āφāĻĒ⧁āύāĻŋ āĻĒā§ā§°āĻ—ā§ā§°āĻžāĻŽāĻ• āĻĒā§ā§°āĻļā§āύāϤ āϚāϞāĻžāĻŦāϞ⧇ āύāĻŋā§°ā§āϧāĻžā§°āύ āϕ⧰āĻŋāϛ⧇ āφāĻĒā§‹āύāĻžā§° āĻāχ āĻ•āĻžā§°ā§āĻ¯ā§āϝāĻ• āĻ…āύ⧁āĻŽāϤāĻŋ āĻĻāĻŋ⧟āĻžā§° āĻĒā§ā§°ā§Ÿā§‹āϜāύ āĻšāĻŦ āĻ‡ā§ŸāĻžāĻ• āĻ•āĻŽāĻžāĻ¨ā§āĻĄ āĻļāĻžā§°ā§€āϤ āϕ⧰āĻŋāĻŦ āĻĒā§°āĻž āϝāĻžāĻŦ āĻāĻ•ā§āϏāĻŋāĻ•āĻŋāωāϟ āϕ⧰āĻŋ: # setsebool -P mmap_low_allowed 1 āφāĻĒ⧁āύāĻŋ āĻāϟāĻž %s āϤ āĻāϟāĻž āϧ⧰āĻŖ āĻ¸ā§āĻĨāĻžāĻĒāύ āϕ⧰āĻŋāĻŦ āĻšā§‡āĻˇā§āϟāĻž āϕ⧰āĻŋāϛ⧇ āϝāĻŋ āĻāϟāĻž āĻĢāĻžāχāϞ āϧ⧰āĻŖ āύāĻšā§ŸāĨ¤ āĻ‡ā§ŸāĻžā§° āĻ…āύ⧁āĻŽāϤāĻŋ āύāĻžāχ, āφāĻĒ⧁āύāĻŋ āĻāϟāĻž āĻĢāĻžāχāϞ āϧ⧰āĻŖ āϧāĻžā§°ā§āĻ¯ā§āϝ āϕ⧰āĻŋāĻŦ āϞāĻžāĻ—āĻŋāĻŦāĨ¤ āφāĻĒ⧁āύāĻŋ seinfo āĻ•āĻŽāĻžāĻ¨ā§āĻĄ āĻŦā§āĻ¯ā§ąāĻšāĻžā§° āϕ⧰āĻŋ āϏāĻ•āϞ⧋ āĻĢāĻžāχāϞ āϧ⧰āĻŖ āϤāĻžāϞāĻŋāĻ•āĻžāϭ⧁āĻ•ā§āϤ āϕ⧰āĻŋāĻŦ āĻĒāĻžā§°āĻŋāĻŦāĨ¤ seinfo -afile_type -x "$BOOLEAN" āφ⧰⧁ "$WRITE_BOOLEAN" āĻŦ⧁āϞāĻŋ⧟āĻžāύāϏāĻŽā§‚āĻšāĻ• true āϞ⧇ āϏāϞāύāĻŋ āϕ⧰āĻŋāϞ⧇ āĻ…āĻ­āĻŋāĻ—āĻŽ āĻĒā§‹ā§ąāĻž āϝāĻžāĻŦ: "setsebool -P $BOOLEAN=1 $WRITE_BOOLEAN=1". āϏāĻ¤ā§°ā§āĻ•āĻŦāĻžā§°ā§āϤāĻž: "$WRITE_BOOLEAN" āĻŦ⧁āϞāĻŋ⧟āĻžāύāĻ• true āϞ⧇ āϏāĻ‚āĻšāϤāĻŋ āϕ⧰āĻŋāϞ⧇ ftp āĻĄāĻŋāĻŽāύāĻ• āϏāĻ•āϞ⧋ ā§°āĻžāϜāĻšā§ā§ąāĻž āϏāĻŽāϞāϞ⧇ (āϧ⧰āĻŖ public_content_t ā§° āϏ⧈āϤ⧇ āĻĢāĻžāχāϞāϏāĻŽā§‚āĻš āφ⧰⧁ āĻĄāĻžāχ⧰⧇āĻ•āϟ⧰āĻŋāϏāĻŽā§‚āĻš ) āϞāĻŋāĻ–āĻžā§° āĻ…āύ⧁āĻŽāϤāĻŋ āĻĻāĻŋ⧟āĻž āĻšāĻŦ CIFS āĻĢāĻžāχāϞāϚāĻŋāĻ¸ā§āĻŸā§‡āĻŽāϏāĻŽā§‚āĻšāϤ āĻĢāĻžāχāϞāϏāĻŽā§‚āĻš āφ⧰⧁ āĻĄāĻžāχ⧰⧇āĻ•āϟ⧰āĻŋāϏāĻŽā§‚āĻšāϞ⧇ āϞāĻŋāĻ–āĻžā§° āĻ…āϤāĻŋā§°āĻŋāĻ•ā§āϤ⧇āĨ¤ # semanage fcontext -a -t SIMILAR_TYPE '$FIX_TARGET_PATH' # restorecon -v '$FIX_TARGET_PATH'# semanage fcontext -a -t samba_share_t '$FIX_TARGET_PATH%s' # restorecon %s -v '$FIX_TARGET_PATH'# semanage fcontext -a -t virt_image_t '$FIX_TARGET_PATH' # restorecon -v '$FIX_TARGET_PATH'# semanage port -a -t %s -p %s $PORT_NUMBER# semanage port -a -t PORT_TYPE -p %s $PORT_NUMBER āϝāϤ PORT_TYPE āύāĻŋāĻŽā§āύāϞāĻŋāĻ–āĻŋāϤ⧰ āĻāϟāĻž: %sāĨ¤āĻāϟāĻž āĻĒā§ā§°āĻ•ā§ā§°āĻŋ⧟āĻžā§Ÿ āĻšā§ŸāϤ⧋ āφāĻĒā§‹āύāĻžā§° āϚāĻŋāĻ¸ā§āĻŸā§‡āĻŽ āĻšā§‡āĻ• āϕ⧰āĻžā§° āĻšā§‡āĻˇā§āϟāĻž āϕ⧰āĻŋ āφāϛ⧇āĨ¤net.ipv6.conf.all.disable_ipv6 = 1 āĻ• /etc/sysctl.conf āϞ⧇ āϝ⧋āĻ— āϕ⧰āĻ• āφāĻĒā§‹āύāĻžā§° āϏ⧁⧰āĻ•ā§āώāĻž āĻĒā§ā§°āĻļāĻžāϏāϕ⧰ āϏ⧈āϤ⧇ āϝ⧋āĻ—āĻžāϝ⧋āĻ— āϕ⧰āĻ• āφ⧰⧁ āĻāχ āĻŦāĻŋāĻˇā§Ÿā§‡ āϏ⧂āĻšā§€āϤ āϕ⧰āĻ•āĨ¤āĻĒ⧁āύ⧰⧁āĻĻā§āϧāĻžā§° āĻĒā§°āĻŋāĻĒā§ā§°ā§‡āĻ•ā§āώāϤāĻŋāϤāĻĒā§°āĻŋāĻĒā§ā§°ā§‡āĻ•ā§āώāϤāĻŋāϤ āĻĒ⧁āύ⧰⧁āĻĻā§āϧāĻžā§° āϕ⧰āĻ•SELinux āĻ $SOURCE_PATH "$ACCESS" āĻ…āĻ­āĻŋāĻ—āĻŽ āĻĒā§ā§°āϤāĻŋā§°ā§‹āϧ āϕ⧰āĻŋ āφāϛ⧇āĨ¤āĻŽā§‡āĻŽā§°āĻŋ āϏ⧁⧰āĻ•ā§āώāĻž āĻŦāĻ¨ā§āϧ āϕ⧰āĻ•āĻ…āϧāĻŋāĻ• āĻŦāĻŋā§ąā§°āĻŖā§° āĻŦāĻžāĻŦ⧇ āφāĻĒ⧁āύāĻŋ '%s' man āĻĒ⧃āĻˇā§āĻ āĻž āĻĒā§āĻŋāĻŦ āĻĒāĻžā§°ā§‡āĨ¤āφāĻĒā§‹āύāĻžāĻ• āĻšā§ŸāϤ⧋ āĻšā§‡āĻ• āϕ⧰āĻž āĻšā§ˆāϛ⧇āĨ¤āφāĻĒ⧁āύāĻŋ '%s' āĻŦ⧁āϞāĻŋ⧟āĻžāύ āϏāĻžāĻŽā§°ā§āĻĨāĻŦāĻžāύ āϕ⧰āĻŋ SELinux āĻ• āĻ‡ā§ŸāĻžā§° āĻŦāĻŋāĻˇā§Ÿā§‡ āĻ•āĻŦ āϞāĻžāĻ—āĻŋāĻŦāĨ¤ āφāĻĒ⧁āύāĻŋ $FIX_TARGET_PATH āϤ āϞ⧇āĻŦ⧇āϞ āϏāϞāύāĻŋ āϕ⧰āĻŋāĻŦ āϞāĻžāĻ—āĻŋāĻŦāφāĻĒ⧁āύāĻŋ $TARGET_BASE_PATH ā§° āϞ⧇āĻŦ⧇āϞ āϏāϞāύāĻŋ āϕ⧰āĻŋāĻŦ āϞāĻžāĻ—āĻŋāĻŦāφāĻĒ⧁āύāĻŋ $TARGET_BASE_PATH to public_content_t āĻ…āĻĨāĻŦāĻž public_content_rw_t āϤ āϞ⧇āĻŦ⧇āϞ āϏāϞāύāĻŋ āϕ⧰āĻŋāĻŦ āϞāĻžāĻ—āĻŋāĻŦāĨ¤āφāĻĒ⧁āύāĻŋ āϞ⧇āĻŦ⧇āϞāĻ• $TARGET_BASE_PATH' āϤ āϏāϞāύāĻŋ āϕ⧰āĻŋāĻŦ āϞāĻžāĻ—āĻŋāĻŦāφāĻĒ⧁āύāĻŋ $TARGET_PATH ā§° āϞ⧇āĻŦ⧇āϞāĻ• āĻāϟāĻž āϏāĻĻ⧃āĻļ āϝāĻ¨ā§āĻ¤ā§ā§°ā§° āϧ⧰āĻŖāϞ⧇ āϏāϞāύāĻŋ āϕ⧰āĻŋāĻŦ āϞāĻžāĻ—āĻŋāĻŦāĨ¤āφāĻĒ⧁āύāĻŋ '$FIX_TARGET_PATH' āϤ āϞ⧇āĻŦ⧇āϞ āϏāϞāύāĻŋ āϕ⧰āĻŋāĻŦ āϞāĻžāĻ—āĻŋāĻŦ'āφāĻĒ⧁āύāĻŋ āĻ‡ā§ŸāĻžāĻ• āĻāϟāĻž āĻŦāĻžāĻ— āĻšāĻŋāϚāĻžāĻĒ⧇ āϏāĻ‚āĻŦāĻžāĻĻ āĻĻāĻŋāĻŦ āϞāĻžāĻ—āĻŋāĻŦāĨ¤ āφāĻĒ⧁āύāĻŋ āĻāχ āĻ…āĻ­āĻŋāĻ—āĻŽā§° āĻ…āύ⧁āĻŽāϤāĻŋ āĻĻāĻŋāĻŦāϞ⧇ āĻāϟāĻž āĻ¸ā§āĻĨāĻžāĻ¨ā§€ā§Ÿ āύ⧀āϤāĻŋ āĻŽāĻĄāĻŋāωāϞ āϏ⧃āϜāύ āϕ⧰āĻŋāĻŦ āĻĒāĻžā§°ā§‡āĨ¤āφāĻĒ⧁āύāĻŋ āĻ‡ā§ŸāĻžāĻ• āĻāϟāĻž āĻŦāĻžāĻ— āĻšāĻŋāϚāĻžāĻĒ⧇ āϏāĻ‚āĻŦāĻžāĻĻ āĻĻāĻŋāĻŦ āϞāĻžāĻ—āĻŋāĻŦāĨ¤ āφāĻĒ⧁āύāĻŋ āĻāχ āĻ…āĻ­āĻŋāĻ—āĻŽ āĻŦāĻŋāĻļā§āϞ⧇āώāĻŖā§° āĻ…āύ⧁āĻŽāϤāĻŋ āύāĻŋāĻĻāĻŋāĻŦāϞ⧇ āĻāϟāĻž āĻ¸ā§āĻĨāĻžāĻ¨ā§€ā§Ÿ āύ⧀āϤāĻŋ āĻŽāĻĄāĻŋāωāϞ āϏ⧃āϜāύ āϕ⧰āĻŋāĻŦ āĻĒāĻžā§°ā§‡āĨ¤execstack -c %sāϝāĻĻāĻŋ āφāĻĒ⧁āύāĻŋ āĻ­āĻžā§ąā§‡ āφāĻĒā§‹āύāĻžāĻ• āĻšā§‡āĻ• āϕ⧰āĻž āĻšā§ˆāϛ⧇setsebool -P %s %sāύāĻŋ⧟āĻŽ āύāĻŽāύāĻž āĻĢāĻžāχāϞ⧰ āĻĒāĻĨ āϤāĻĨā§āϝ āĻĒā§ā§°āĻžāĻĒā§āϤ āϕ⧰āĻŋāĻŦāϞ⧇ āφ⧰⧁ āĻ¤ā§ā§°ā§āϟāĻŋāĻ• āφāĻ•ā§Œ āϏ⧃āϜāύ āϕ⧰āĻŋāĻŦāϞ⧇ āϏāĻŽā§āĻĒā§‚ā§°ā§āĻŖ āϏāĻŽā§āĻĒāĻžāĻĻāύ āφ⧰āĻŽā§āĻ­ āϕ⧰āĻ•āĨ¤SELinux āĻĒā§°āĻŋāĻĒā§ā§°ā§‡āĻ•ā§āώāϤāĻŋāϤ⧰ āĻŦāĻžāĻšāĻŋ⧰⧇ āϏāĻ•āϞ⧋ āĻ…āύ⧁āĻŽāϤāĻŋ āϏāς⧰āĻ•ā§āώāĻŖ āϕ⧰āĻŋāĻŦāϞ⧇ "cp -p" ā§° āύāĻŋāϚāĻŋāύāĻž āĻāϟāĻž āĻ•āĻŽāĻžāĻ¨ā§āĻĄ āĻŦā§āĻ¯ā§ąāĻšāĻžā§° āϕ⧰āĻ•āĨ¤āφāĻĒ⧁āύāĻŋ restorecon āϚāϞāĻžāĻŦ āĻĒāĻžā§°āĻŋāĻŦāĨ¤āφāĻĒ⧁āύāĻŋ āĻāϜāύ āĻšā§‡āĻ•āĻžā§° āĻĻā§āĻŦāĻžā§°āĻž āφāĻ•ā§ā§°āĻŽāĻŖā§° āϏāĻ¨ā§āĻŽā§āĻ–āĻŋāύ āĻšāĻŦ āĻĒāĻžā§°ā§‡, āϝāĻŋāĻšā§‡āϤ⧁ āĻ—ā§‹āĻĒāĻŖ āĻāĻĒā§āϞāĻŋāϕ⧇āϚāύāϏāĻŽā§‚āĻšā§° āĻāχ āĻ…āĻ­āĻŋāĻ—āĻŽā§° āϕ⧇āϤāĻŋ⧟āĻžāĻ“ āĻĒā§ā§°ā§Ÿā§‹āϜāύ āύāĻšā§ŸāĨ¤āφāĻĒ⧁āύāĻŋ āĻāϜāύ āĻšā§‡āĻ•āĻžā§° āĻĻā§āĻŦāĻžā§°āĻž āφāĻ•ā§ā§°āĻŽāĻŖā§° āϏāĻ¨ā§āĻŽā§āĻ–āĻŋāύ āĻšāĻŦ āĻĒāĻžā§°ā§‡, āϝāĻŋāĻšā§‡āϤ⧁ āĻ—ā§‹āĻĒāĻŖ āĻāĻĒā§āϞāĻŋāϕ⧇āϚāύāϏāĻŽā§‚āĻšā§° āĻāχ āĻ…āĻ­āĻŋāĻ—āĻŽā§° āĻĒā§ā§°ā§Ÿā§‹āϜāύ āύāĻšā§ŸāĨ¤āφāĻĒ⧁āύāĻŋ āĻāϜāύ āĻšā§‡āĻ•āĻžā§° āĻĻā§āĻŦāĻžā§°āĻž āφāĻ•ā§ā§°āĻŽāĻŖā§° āϏāĻ¨ā§āĻŽā§āĻ–āĻŋāύ āĻšāĻŦ āĻĒāĻžā§°ā§‡, āχ āĻāϟāĻž āĻ…āϤāĻŋ āĻŦāĻŋāĻĒāĻĻāϜāύāĻ• āĻ…āĻ­āĻŋāĻ—āĻŽāĨ¤āφāĻĒ⧁āύāĻŋ $TARGET_PATH āϤ āϞ⧇āĻŦ⧇āϞāĻŋāĻ‚ āϏāϞāύāĻŋ āϕ⧰āĻŋāĻŦ āϞāĻžāĻ—āĻŋāĻŦāĨ¤āφāĻĒ⧁āύāĻŋ āϞ⧇āĻŦ⧇āϞāϏāĻŽā§‚āĻš āĻ āĻŋāĻ• āϕ⧰āĻŋāĻŦ āϞāĻžāĻ—āĻŋāĻŦāĨ¤āφāĻĒ⧁āύāĻŋ cert āĻĢāĻžāχāϞāĻ• ~/.cert āĻĄāĻžāχ⧰⧇āĻ•āϟ⧰āĻŋāϞ⧇ āĻ¸ā§āĻĨāĻžāύāĻžāĻ¨ā§āϤ⧰ āϕ⧰āĻŋāĻŦ āϞāĻžāĻ—āĻŋāĻŦāφāĻĒ⧁āύāĻŋ āĻāϟāĻž āĻŦ⧈āϧ āĻĢāĻžāχāϞ āϞ⧇āĻŦ⧇āϞ āĻŦāĻžāĻ›āĻŋāĻŦ āϞāĻžāĻ—āĻŋāĻŦāĨ¤āφāĻĒ⧁āύāĻŋ mozplugger āĻĒ⧇āϕ⧇āχāϜ āφāϤ⧰āĻžāĻŦ āϞāĻžāĻ—āĻŋāĻŦāĨ¤āĻ‡ā§ŸāĻžā§° āĻ…āύ⧁āĻŽāϤāĻŋ āĻĻāĻŋāĻŦāϞ⧇ āφāĻĒ⧁āύāĻŋ SELinux āϏāĻ‚āĻ¸ā§āĻĨāĻžāĻĒāύ āϕ⧰āĻŋāĻŦ āϞāĻžāĻ—āĻŋāĻŦāφāĻĒ⧁āύāĻŋ SELinux āĻ• āĻ‡ā§ŸāĻžā§° āĻŦāĻŋāĻˇā§Ÿā§‡ āϏ⧂āĻšā§€āϤ āϕ⧰āĻŋāĻŦ āϞāĻžāϗ⧇āφāĻĒ⧁āύāĻŋ SELinux ā§° āĻ‡ā§ŸāĻžā§° āĻŦāĻŋāĻˇā§Ÿā§‡ 'httpd_unified' āφ⧰⧁ 'http_enable_cgi' āĻŦ⧁āϞāĻŋ⧟āĻžāύāϏāĻŽā§‚āĻš āϏāĻžāĻŽā§°ā§āĻĨāĻŦāĻžāύ āϕ⧰āĻŋ āĻ•āĻŦ āϞāĻžāĻ—āĻŋāĻŦāφāĻĒ⧁āύāĻŋ vbetool_mmap_zero_ignore āĻŦ⧁āϞāĻŋ⧟āĻžāύ āϏāĻžāĻŽā§°ā§āĻĨāĻŦāĻžāύ āϕ⧰āĻŋ SELinux āĻ• āĻ‡ā§ŸāĻžā§° āĻŦāĻŋāĻˇā§Ÿā§‡ āĻ•āĻŦ āϞāĻžāĻ—āĻŋāĻŦāĨ¤āφāĻĒ⧁āύāĻŋ SELinux āĻ• āĻ‡ā§ŸāĻžā§° āĻŦāĻŋāĻˇā§Ÿā§‡ wine_mmap_zero_ignore āĻŦ⧁āϞāĻŋ⧟āĻžāύ āϏāĻžāĻŽā§°ā§āĻĨāĻŦāĻžāύ āϕ⧰āĻŋ āĻ•āĻŦ āϞāĻžāĻ—āĻŋāĻŦāĨ¤āφāĻĒ⧁āύāĻŋ Chrome āĻĒā§āϞāĻžāĻ—āĻŋāύāϏāĻŽā§‚āĻšāϤ SELinux āύāĻŋ⧟āĻ¨ā§āĻ¤ā§ā§°āĻŖāϏāĻŽā§‚āĻš āĻŦāĻ¨ā§āϧ āϕ⧰āĻŋāĻŦ āϞāĻžāĻ—āĻŋāĻŦāĨ¤āφāĻĒ⧁āύāĻŋ Firefox āĻĒā§āϞāĻžāĻ—āĻŋāύāϏāĻŽā§‚āĻšāϤ SELinux āύāĻŋ⧟āĻ¨ā§āĻ¤ā§ā§°āύāϏāĻŽā§‚āĻš āĻŦāĻ¨ā§āϧ āϕ⧰āĻŋāĻŦ āϞāĻžāĻ—āĻŋāĻŦāĨ¤āφāĻĒ⧁āύāĻŋ āĻ‡ā§ŸāĻžāϤ āϞ⧇āĻŦ⧇āϞāϏāĻŽā§‚āĻš āϝ⧋āĻ— āϕ⧰āĻŋāĻŦ āϞāĻžāĻ—āĻŋāĻŦāĨ¤āφāĻĒ⧁āύāĻŋ $TARGET_PATH āϤ āϞ⧇āĻŦ⧇āϞāĻ• public_content_rw_t āϞ⧇ āϏāϞāύāĻŋ āϕ⧰āĻŋāĻŦ, āφ⧰⧁ āĻŦāĻŋāĻ­ā§ąā§€ā§ŸāĻ­āĻžā§ąā§‡ allow_httpd_sys_script_anon_write āĻŦ⧁āϞāĻŋ⧟āĻžāύ āĻ…āύ āϕ⧰āĻŋāĻŦ āϞāĻžāĻ—āĻŋāĻŦāĨ¤āφāĻĒ⧁āύāĻŋ āϏāĻŽā§āĻĒā§‚ā§°ā§āĻŖāĻ­āĻžā§ąā§‡ āĻĒ⧁āύ⧰ āϞ⧇āĻŦ⧇āϞ āϕ⧰āĻŋāĻŦ āϞāĻžāĻ—āĻŋāĻŦāĨ¤āφāĻĒ⧁āύāĻŋ āĻāϟāĻž āĻŦāĻžāĻ— āϜāĻŽāĻž āĻĻāĻŋāĻŦ āϞāĻžāĻ—āĻŋāĻŦāĨ¤ āχ āĻŦāĻŋāĻ­ā§ąā§€ā§ŸāĻ­āĻžā§ąā§‡ āĻŦāĻŋāĻĒāĻĻāϜāύāĻ• āĻ…āĻ­āĻŋāĻ—āĻŽāĨ¤āφāĻĒ⧁āύāĻŋ āĻāϟāĻž āĻŦāĻžāĻ— āϜāĻŽāĻž āĻĻāĻŋāĻŦ āϞāĻžāĻ—āĻŋāĻŦāĨ¤ āχ āĻŦāĻŋāĻ­ā§ąā§€ā§ŸāĻ­āĻžā§ąā§‡ āĻŦāĻŋāĻĒāĻĻāϜāύāĻ• āĻ…āĻ­āĻŋāĻ—āĻŽāĨ¤āφāĻĒ⧁āύāĻŋ /proc/sys/net/ipv6/conf/all/disable_ipv6 to āĻ• 1 āϞ⧇ āϏāĻ‚āĻšāϤāĻŋ āϕ⧰āĻŋāĻŦ āϞāĻžāĻ—āĻŋāĻŦ āφ⧰⧁ āĻŽāĻĄāĻŋāωāϞāĻ• āĻŦā§āϞ⧇āĻ•āϞāĻŋāĻ¸ā§āϟ āϕ⧰āĻŋāĻŦ āϞāĻžāĻ—āĻŋāĻŦāφāĻĒ⧁āύāĻŋ āĻāϟāĻž āĻŦ⧇āϞ⧇āĻ— āĻ•āĻŽāĻžāĻ¨ā§āĻĄ āĻŦā§āĻ¯ā§ąāĻšāĻžā§° āϕ⧰āĻŋāĻŦ āϞāĻžāĻ—āĻŋāĻŦāĨ¤ āφāĻĒā§‹āύāĻžāĻ• āϞāĻ•ā§āĻˇā§āϝ āĻĢāĻžāχāϞāϚāĻŋāĻ¸ā§āĻŸā§‡āĻŽāϤ SELinux āĻĒā§°āĻŋāĻĒā§ā§°ā§‡āĻ•ā§āώāϤāĻŋāϤ āϏāς⧰āĻ•ā§āώāĻŖ āϕ⧰āĻžā§° āĻ…āύ⧁āĻŽāϤāĻŋ āύāĻžāχāĨ¤āφāĻĒ⧁āύāĻŋ execstack āĻĢā§āϞ⧇āĻ— āĻĒā§°āĻŋāĻˇā§āĻ•āĻžā§° āϕ⧰āĻŋ āϚāĻžāĻŦ āϞāĻžāϗ⧇ āϝāĻĻāĻŋ $SOURCE_PATH āϏāĻ āĻŋāĻ•āĻ­āĻžā§ąā§‡ āĻ•āĻžā§°ā§āĻ¯ā§āϝ āϕ⧰⧇āĨ¤ āĻ‡ā§ŸāĻžāĻ• %s āϤ āĻāϟāĻž āĻŦāĻžāĻ— āĻšāĻŋāϚāĻžāĻĒ⧇ āϏāĻ‚āĻŦāĻžāĻĻ āϕ⧰āĻ•āĨ¤ āφāĻĒ⧁āύāĻŋ exestack āĻĢā§āϞ⧇āĻ—āĻ• āĻĒā§°āĻŋāĻˇā§āĻ•āĻžā§° āϕ⧰āĻŋāĻŦ āĻĒāĻžā§°āĻŋāĻŦ āĻĒā§ā§°ā§‡ā§°āĻŖ āϕ⧰āĻŋ: