MySQL移動數據目錄出現權限問題

MySQL移動數據目錄出現權限問題

環境: ubuntu 14.04.4 LTSmysql

現象

今天把/var/lib/mysql下的數據文件移動到其餘目錄下,以後發現啓動mysql報錯,而且mysql沒法運行。具體的操做以下sql

# service mysql stop
# mv /var/lib/mysql /data
# serivce mysql start

報出的錯誤信息爲:ubuntu

170425  9:55:36 [Warning] Using unique option prefix myisam-recover instead of myisam-recover-options is deprecated and will be removed in a future release. Please use the full name instead.
170425  9:55:36 [Note] Plugin 'FEDERATED' is disabled.
/usr/sbin/mysqld: Can't find file: './mysql/plugin.frm' (errno: 13)
170425  9:55:36 [ERROR] Can't open the mysql.plugin table. Please run mysql_upgrade to create it.
170425  9:55:36 InnoDB: The InnoDB memory heap is disabled
170425  9:55:36 InnoDB: Mutexes and rw_locks use GCC atomic builtins
170425  9:55:36 InnoDB: Compressed tables use zlib 1.2.8
170425  9:55:36 InnoDB: Using Linux native AIO
170425  9:55:36 InnoDB: Initializing buffer pool, size = 128.0M
170425  9:55:36 InnoDB: Completed initialization of buffer pool
170425  9:55:36  InnoDB: Operating system error number 13 in a file operation.
InnoDB: The error means mysqld does not have the access rights to
InnoDB: the directory.
InnoDB: File name ./ibdata1
InnoDB: File operation call: 'open'.
InnoDB: Cannot continue operation.

緣由

最初覺得是簡單的權限問題,就把/data/mysql目錄賦權給mysql用戶app

# chown -R mysql:mysql /data/mysql

可是再次啓動mysql後,仍是遇到一樣的錯誤。上網查了一下,緣由是因爲現今的Linux系統都採用AppArmor來限制文件和目錄的執行權限。tcp

解決辦法

因此須要配置AppArmor讓mysqld能夠訪問/data/mysql目錄。具體操做以下:ide

# vi /etc/apparmor.d/usr.sbin.mysqld

在此文件末尾增長你的目錄(能夠按照/var/lib/mysql的目錄改)ui

/usr/sbin/mysqld {
  #include <abstractions/base>
  #include <abstractions/nameservice>
  #include <abstractions/user-tmp>
  #include <abstractions/mysql>
  #include <abstractions/winbind>

  capability dac_override,
  capability sys_resource,
  capability setgid,
  capability setuid,

  network tcp,

  /etc/hosts.allow r,
  /etc/hosts.deny r,

  /etc/mysql/*.pem r,
  /etc/mysql/conf.d/ r,
  /etc/mysql/conf.d/* r,
  /etc/mysql/*.cnf r,
  /usr/lib/mysql/plugin/ r,
  /usr/lib/mysql/plugin/*.so* mr,
  /usr/sbin/mysqld mr,
  /usr/share/mysql/** r,
  /var/log/mysql.log rw,
  /var/log/mysql.err rw,
  /var/lib/mysql/ r,
  /var/lib/mysql/** rwk,
  /var/lib/mysql-files/ r,
  /var/lib/mysql-files/** rwk,
  /var/log/mysql/ r,
  /var/log/mysql/* rw,
  /var/run/mysqld/mysqld.pid rw,
  /var/run/mysqld/mysqld.sock w,
  /run/mysqld/mysqld.pid rw,
  /run/mysqld/mysqld.sock w,

  /sys/devices/system/cpu/ r,
  # Site-specific additions and overrides. See local/README for details.
  #include <local/usr.sbin.mysqld>
  /data/mysql/ r,
  /data/mysql/** rwk,
}

若是不寫第一句的/data/mysql/ r,則mysql能啓動,可是進入mysql後輸入命令會提示下面錯誤:atom

ERROR 1018 (HY000): Can't read dir of '.' (errno: 13

@完.net


參考:code

相關文章
相關標籤/搜索