权限被拒绝写入mysql日志


8

我只是在Vagrant上测试新的Ubuntu(Vivid 15.04)安装,并遇到mysql问题并登录到自定义位置。

/var/log/syslog我得到

/usr/bin/mysqld_safe: cannot create /var/log/mysqld.log: Permission denied

如果ls -l /var我得到

drwxrwxr-x 10 root syslog 4096 Jun  8 19:52 log

如果我在/ var / log中查找文件不存在

我以为我暂时禁用了apparmor,只是为了确定是那个原因还是其他原因导致了问题,但是不确定它是否仍然造成了问题(编辑:认为它可能仍然处于启用状态,所以不确定这是问题还是简单的原因权限)。

如果我尝试以mysql方式手动创建文件,我也会被拒绝(我暂时允许它bash访问测试,之后将其删除)。

touch /var/log/mysql.log
touch: cannot touch ‘/var/log/mysql.log’: Permission denied

如果我查看另一个正在运行的服务器(centos),它具有上述权限(并以mysql用户身份写入),那么我想知道mysql通常如何获得访问/ var / log目录的权限,以及如何将其获取到通过正常运行访问该文件夹?

这是我的mysql的apparmor配置文件


/usr/sbin/mysqld {
  #include 
  #include 
  #include 
  #include 
  #include 

  capability dac_override,
  capability sys_resource,
  capability setgid,
  capability setuid,

  network tcp,

  /etc/hosts.allow r,
  /etc/hosts.deny r,

  /etc/mysql/** r,
  /usr/lib/mysql/plugin/ r,
  /usr/lib/mysql/plugin/*.so* mr,
  /usr/sbin/mysqld mr,
  /usr/share/mysql/** r,
  /var/log/mysqld.log rw,
  /var/log/mysqld.err rw,
  /var/lib/mysql/ r,
  /var/lib/mysql/** rwk,
  /var/log/mysql/ r,
  /var/log/mysql/* rw,
  /var/run/mysqld/mysqld.pid rw,
  /var/run/mysqld/mysqld.sock w,
  /run/mysqld/mysqld.pid rw,
  /run/mysqld/mysqld.sock w,

  /sys/devices/system/cpu/ r,

/var/log/mysqld.log rw,

  # Site-specific additions and overrides. See local/README for details.
  #include 
}

我也将以上文件添加到了apparmor.d / disable Directoru

注意:我添加了这一行/var/log/mysqld.log rw,它原来不存在,并且存在相同的问题(在执行apparmor重新加载之后)。


apparmor module is loaded.
5 profiles are loaded.
5 profiles are in enforce mode.
   /sbin/dhclient
   /usr/lib/NetworkManager/nm-dhcp-client.action
   /usr/lib/NetworkManager/nm-dhcp-helper
   /usr/lib/connman/scripts/dhclient-script
   /usr/sbin/tcpdump
0 profiles are in complain mode.
1 processes have profiles defined.
1 processes are in enforce mode.
   /sbin/dhclient (565) 
0 processes are in complain mode.
0 processes are unconfined but have a profile defined.

Jun  8 20:33:33 vagrant-ubuntu-vivid-64 systemd[1]: Starting MySQL Community Server...
Jun  8 20:33:33 vagrant-ubuntu-vivid-64 mysqld_safe[11231]: 150608 20:33:33 mysqld_safe Logging to '/var/log/mysqld.log'.
Jun  8 20:33:33 vagrant-ubuntu-vivid-64 mysqld_safe[11231]: touch: cannot touch ‘/var/log/mysqld.log’: Permission denied
Jun  8 20:33:33 vagrant-ubuntu-vivid-64 mysqld_safe[11231]: chmod: cannot access ‘/var/log/mysqld.log’: No such file or directory
Jun  8 20:33:33 vagrant-ubuntu-vivid-64 mysqld_safe[11231]: 150608 20:33:33 mysqld_safe Starting mysqld daemon with databases from /var/lib/mysql
Jun  8 20:33:33 vagrant-ubuntu-vivid-64 mysqld_safe[11231]: /usr/bin/mysqld_safe: 126: /usr/bin/mysqld_safe: cannot create /var/log/mysqld.log: Permission denied

Answers:


12

在我看来,大多数人创建一个新的目录mysql里面的/var/log,改变这个文件夹的所有者给mysql用户。

sudo mkdir /var/log/mysql
sudo chown mysql:mysql /var/log/mysql   

那应该做。确保更新服务器的日志记录位置并重新启动它。测试完成后,重新启用mysql的apparmor配置文件。

By using our site, you acknowledge that you have read and understand our Cookie Policy and Privacy Policy.
Licensed under cc by-sa 3.0 with attribution required.