Merci Bruno,
Super alors c'est justement particulier apparemment en live car visiblement j'ai 2 accès aux fichiers système
-
ordinateur : /etc/apparmor.d (ici pas de usr.sbin.mysqld)
-
casper-rw : /media/ubuntu/casper-rw/upper/etc/apparmor.d/local/
usr.sbin.mysqld
# vim:syntax=apparmor
# Last Modified: Tue Feb 09 15:28:30 2016
#include <tunables/global>
/usr/sbin/mysqld {
#include <abstractions/base>
#include <abstractions/nameservice>
#include <abstractions/user-tmp>
#include <abstractions/mysql>
#include <abstractions/winbind>
# Allow system resource access
/proc/*/status r,
/sys/devices/system/cpu/ r,
/sys/devices/system/node/ r,
/sys/devices/system/node/** r,
capability sys_resource,
capability dac_override,
capability dac_read_search,
capability setuid,
capability setgid,
# Allow network access
network tcp,
/etc/hosts.allow r,
/etc/hosts.deny r,
# Allow config access
/etc/mysql/** r,
# Allow pid, socket, socket lock file access
/var/run/mysqld/mysqld.pid rw,
/var/run/mysqld/mysqld.sock rw,
/var/run/mysqld/mysqld.sock.lock rw,
/run/mysqld/mysqld.pid rw,
/run/mysqld/mysqld.sock rw,
/run/mysqld/mysqld.sock.lock rw,
# Allow systemd notify messages
/{,var/}run/systemd/notify w,
# Allow execution of server binary
/usr/sbin/mysqld mr,
/usr/sbin/mysqld-debug mr,
# Allow plugin access
/usr/lib/mysql/plugin/ r,
/usr/lib/mysql/plugin/*.so* mr,
# Allow error msg and charset access
/usr/share/mysql/ r,
/usr/share/mysql/** r,
# Allow data dir access
/var/lib/mysql/ r,
/var/lib/mysql/** rwk,
# Allow data files dir access
/var/lib/mysql-files/ r,
/var/lib/mysql-files/** rwk,
# Allow keyring dir access
/var/lib/mysql-keyring/ r,
/var/lib/mysql-keyring/** rwk,
# Allow log file access
/var/log/mysql.err rw,
/var/log/mysql.log rw,
/var/log/mysql/ r,
/var/log/mysql/** rw,
# Allow read access to OpenSSL config
/etc/ssl/openssl.cnf r,
# Site-specific additions and overrides. See local/README for details.
#include <local/usr.sbin.mysqld>
}
Est-ce parlant?
Est-ce possible de modifier les informations de ce fichier pour renvoyer aux bons répertoires?
En effet Rock'n'Roll 😉 comme tu disais plus loin!!
Dans ce fichier, dois-je carrément tout remplacer pour que les instructions renvoient aux bons répertoires ?
Ça ferait :
# vim:syntax=apparmor
# Last Modified: Tue Feb 09 15:28:30 2016
#include <tunables/global>
/media/ubuntu/casper-rw/upper/usr/sbin/mysqld {
#include <abstractions/base>
#include <abstractions/nameservice>
#include <abstractions/user-tmp>
#include <abstractions/mysql>
#include <abstractions/winbind>
# Allow system resource access
/media/ubuntu/casper-rw/upper/proc/*/status r,
/media/ubuntu/casper-rw/upper/sys/devices/system/cpu/ r,
/media/ubuntu/casper-rw/upper/sys/devices/system/node/ r,
/media/ubuntu/casper-rw/upper/sys/devices/system/node/** r,
capability sys_resource,
capability dac_override,
capability dac_read_search,
capability setuid,
capability setgid,
# Allow network access
network tcp,
/media/ubuntu/casper-rw/upper/etc/hosts.allow r,
/media/ubuntu/casper-rw/upper/etc/hosts.deny r,
# Allow config access
/media/ubuntu/casper-rw/upper/etc/mysql/** r,
# Allow pid, socket, socket lock file access
/media/ubuntu/casper-rw/upper/var/run/mysqld/mysqld.pid rw,
/media/ubuntu/casper-rw/upper/var/run/mysqld/mysqld.sock rw,
/media/ubuntu/casper-rw/upper/var/run/mysqld/mysqld.sock.lock rw,
/media/ubuntu/casper-rw/upper/run/mysqld/mysqld.pid rw,
/media/ubuntu/casper-rw/upper/run/mysqld/mysqld.sock rw,
/media/ubuntu/casper-rw/upper/run/mysqld/mysqld.sock.lock rw,
# Allow systemd notify messages
/{,/media/ubuntu/casper-rw/uppervar/}run/systemd/notify w,
# Allow execution of server binary
/media/ubuntu/casper-rw/upper/usr/sbin/mysqld mr,
/media/ubuntu/casper-rw/upper/usr/sbin/mysqld-debug mr,
# Allow plugin access
/media/ubuntu/casper-rw/upper/usr/lib/mysql/plugin/ r,
/media/ubuntu/casper-rw/upper/usr/lib/mysql/plugin/*.so* mr,
# Allow error msg and charset access
/media/ubuntu/casper-rw/upper/usr/share/mysql/ r,
/media/ubuntu/casper-rw/upper/usr/share/mysql/** r,
# Allow data dir access
/media/ubuntu/casper-rw/upper/var/lib/mysql/ r,
/media/ubuntu/casper-rw/upper/var/lib/mysql/** rwk,
# Allow data files dir access
/media/ubuntu/casper-rw/upper/var/lib/mysql-files/ r,
/media/ubuntu/casper-rw/upper/var/lib/mysql-files/** rwk,
# Allow keyring dir access
/media/ubuntu/casper-rw/upper/var/lib/mysql-keyring/ r,
/media/ubuntu/casper-rw/upper/var/lib/mysql-keyring/** rwk,
# Allow log file access
/media/ubuntu/casper-rw/upper/var/log/mysql.err rw,
/media/ubuntu/casper-rw/upper/var/log/mysql.log rw,
/media/ubuntu/casper-rw/upper/var/log/mysql/ r,
/media/ubuntu/casper-rw/upper/var/log/mysql/** rw,
# Allow read access to OpenSSL config
/media/ubuntu/casper-rw/upper/etc/ssl/openssl.cnf r,
# Site-specific additions and overrides. See local/README for details.
#include <local/usr.sbin.mysqld>
}
Ou peut-être faudrait-il créer des fichiers-miroir aux emplacements où les dossiers/fichiers sont sensés se trouver, comme ce fichier notamment pour commencer...