Назад | Перейти на главную страницу

AppArmor отрицает изменения в mysqld.cnf

У меня возникла следующая проблема с MySQL на экземпляре Ubuntu 16.04.3 LTS с активированным AppArmor.

Проблема возникает при изменении MySQL bind-address к чему-либо, кроме 127.0.0.X, и перезапускает MySQL. Если я изменю настройку обратно, MySQL снова полностью перезапустится. В журнале четко указано, что AppArmor обнаружил изменение и не примет его, но как заставить AppArmor принять мое изменение без ущерба для модели безопасности?

Я попытался изменить файл cnf из разных мест, но результат в любом случае тот же. Этот конкретный вывод журнала связан с изменением /etc/mysql/mysql.conf.d/mysqld.cnf.

Вывод консоли после перезапуска

root@MyServer:~# service mysql restart
Job for mysql.service failed because the control process exited with error code. See "systemctl status mysql.service" and "journalctl -xe" for details.

Выход Journalctl

root@MyServer:~# journalctl -xe
-- Defined-By: systemd
-- Support: http://lists.freedesktop.org/mailman/listinfo/systemd-devel
-- 
-- Unit mysql.service has finished shutting down.
Oct 23 19:34:20 MyServer systemd[1]: Starting MySQL Community Server...
-- Subject: Unit mysql.service has begun start-up
-- Defined-By: systemd
-- Support: http://lists.freedesktop.org/mailman/listinfo/systemd-devel
-- 
-- Unit mysql.service has begun starting up.
Oct 23 19:34:20 MyServer kernel: audit_printk_skb: 12 callbacks suppressed
Oct 23 19:34:20 MyServer kernel: audit: type=1400 audit(1508787260.641:135): apparmor="DENIED" operation="open" profile="/usr/sbin/mysqld" name="/proc/7278/status" pid=7278 comm="mysqld" requested_mask="r" denied_mask="r" fsuid=113 ouid=113
Oct 23 19:34:20 MyServer audit[7278]: AVC apparmor="DENIED" operation="open" profile="/usr/sbin/mysqld" name="/proc/7278/status" pid=7278 comm="mysqld" requested_mask="r" denied_mask="r" fsuid=113 ouid=113
Oct 23 19:34:20 MyServer audit[7278]: AVC apparmor="DENIED" operation="open" profile="/usr/sbin/mysqld" name="/sys/devices/system/node/" pid=7278 comm="mysqld" requested_mask="r" denied_mask="r" fsuid=113 ouid=0
Oct 23 19:34:20 MyServer audit[7278]: AVC apparmor="DENIED" operation="open" profile="/usr/sbin/mysqld" name="/proc/7278/status" pid=7278 comm="mysqld" requested_mask="r" denied_mask="r" fsuid=113 ouid=113
Oct 23 19:34:20 MyServer kernel: audit: type=1400 audit(1508787260.653:136): apparmor="DENIED" operation="open" profile="/usr/sbin/mysqld" name="/sys/devices/system/node/" pid=7278 comm="mysqld" requested_mask="r" denied_mask="r" fsuid=113 ouid=0
Oct 23 19:34:20 MyServer kernel: audit: type=1400 audit(1508787260.653:137): apparmor="DENIED" operation="open" profile="/usr/sbin/mysqld" name="/proc/7278/status" pid=7278 comm="mysqld" requested_mask="r" denied_mask="r" fsuid=113 ouid=113
Oct 23 19:34:22 MyServer systemd[1]: mysql.service: Main process exited, code=exited, status=1/FAILURE
Oct 23 19:34:46 MyServer kernel: [UFW BLOCK] IN=eth0 OUT= MAC=ba:3f:d6:c5:XX:XX:f4:a7:39:d7:XX:XX:XX:XX SRC=XX.XX.XX.XX DST=XXX.XXX.XX.XX LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=36512 PROTO=TCP SPT=46090 DPT=3128 WINDOW=1024 RES=0x00 SYN URGP=0 
Oct 23 19:34:46 MyServer kernel: IN=eth0 OUT= MAC=ba:3f:d6:c5:XX:XX:f4:a7:39:d7:XX:XX:XX:XX SRC=XX.XX.XX.XX DST=XXX.XXX.XX.XX LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=36512 PROTO=TCP SPT=46090 DPT=3128 WINDOW=1024 RES=0x00 SYN URGP=0 
Oct 23 19:34:50 MyServer systemd[1]: Failed to start MySQL Community Server.
-- Subject: Unit mysql.service has failed
-- Defined-By: systemd
-- Support: http://lists.freedesktop.org/mailman/listinfo/systemd-devel
-- 
-- Unit mysql.service has failed.
-- 
-- The result is failed.
Oct 23 19:34:50 MyServer systemd[1]: mysql.service: Unit entered failed state.
Oct 23 19:34:50 MyServer systemd[1]: mysql.service: Failed with result 'exit-code'.
Oct 23 19:34:51 MyServer systemd[1]: mysql.service: Service hold-off time over, scheduling restart.
Oct 23 19:34:51 MyServer systemd[1]: Stopped MySQL Community Server.
-- Subject: Unit mysql.service has finished shutting down
-- Defined-By: systemd
-- Support: http://lists.freedesktop.org/mailman/listinfo/systemd-devel
-- 
-- Unit mysql.service has finished shutting down.
Oct 23 19:34:51 MyServer systemd[1]: Starting MySQL Community Server...
-- Subject: Unit mysql.service has begun start-up
-- Defined-By: systemd
-- Support: http://lists.freedesktop.org/mailman/listinfo/systemd-devel
-- 
-- Unit mysql.service has begun starting up.
Oct 23 19:34:51 MyServer audit[7381]: AVC apparmor="DENIED" operation="open" profile="/usr/sbin/mysqld" name="/proc/7381/status" pid=7381 comm="mysqld" requested_mask="r" denied_mask="r" fsuid=113 ouid=113
Oct 23 19:34:51 MyServer kernel: audit: type=1400 audit(1508787291.145:138): apparmor="DENIED" operation="open" profile="/usr/sbin/mysqld" name="/proc/7381/status" pid=7381 comm="mysqld" requested_mask="r" denied_mask="r" fsuid=113 ouid=113
Oct 23 19:34:51 MyServer audit[7381]: AVC apparmor="DENIED" operation="open" profile="/usr/sbin/mysqld" name="/sys/devices/system/node/" pid=7381 comm="mysqld" requested_mask="r" denied_mask="r" fsuid=113 ouid=0
Oct 23 19:34:51 MyServer audit[7381]: AVC apparmor="DENIED" operation="open" profile="/usr/sbin/mysqld" name="/proc/7381/status" pid=7381 comm="mysqld" requested_mask="r" denied_mask="r" fsuid=113 ouid=113
Oct 23 19:34:51 MyServer kernel: audit: type=1400 audit(1508787291.149:139): apparmor="DENIED" operation="open" profile="/usr/sbin/mysqld" name="/sys/devices/system/node/" pid=7381 comm="mysqld" requested_mask="r" denied_mask="r" fsuid=113 ouid=0
Oct 23 19:34:51 MyServer kernel: audit: type=1400 audit(1508787291.149:140): apparmor="DENIED" operation="open" profile="/usr/sbin/mysqld" name="/proc/7381/status" pid=7381 comm="mysqld" requested_mask="r" denied_mask="r" fsuid=113 ouid=113
Oct 23 19:34:53 MyServer systemd[1]: mysql.service: Main process exited, code=exited, status=1/FAILURE