実行時にログファイルの名前を変更する権限が拒否されるのはなぜですか? logrotate
?以下のログファイルは、rajohns
以下のコマンドを実行してログインしたのと同じユーザーが所有していますlogrotate
。
$猫/etc/logrotate.d/judgecard-api-0.0.1
/var/log/judgecard-api-0.0.1.log {
su rajohns rajohns
weekly
rotate 4
create 0777 rajohns rajohns
missingok
notifempty
postrotate
systemctl restart judgecard-api-0.0.1.service > /dev/null
endscript
}
$ls -l /var/log/judgecard-api-0.0.1.log
-rwxrwxrwx 1 rajohns rajohns 10578 Feb 12 23:01 /var/log/judgecard-api-0.0.1.log
$ sudo logrotate -vf -s ~/logrotate_test_status_file Judgecard-api-0.0.1
reading config file judgecard-api-0.0.1
Handling 1 logs
rotating pattern: /var/log/judgecard-api-0.0.1.log forced from command line (4 rotations)
empty log files are not rotated, old logs are removed
switching euid to 1000 and egid to 1000
considering log /var/log/judgecard-api-0.0.1.log
log needs rotating
rotating log /var/log/judgecard-api-0.0.1.log, log->rotateCount is 4
dateext suffix '-20180212'
glob pattern '-[0-9][0-9][0-9][0-9][0-9][0-9][0-9][0-9]'
renaming /var/log/judgecard-api-0.0.1.log.4 to /var/log/judgecard-api-0.0.1.log.5 (rotatecount 4, logstart 1, i 4),
old log /var/log/judgecard-api-0.0.1.log.4 does not exist
renaming /var/log/judgecard-api-0.0.1.log.3 to /var/log/judgecard-api-0.0.1.log.4 (rotatecount 4, logstart 1, i 3),
old log /var/log/judgecard-api-0.0.1.log.3 does not exist
renaming /var/log/judgecard-api-0.0.1.log.2 to /var/log/judgecard-api-0.0.1.log.3 (rotatecount 4, logstart 1, i 2),
old log /var/log/judgecard-api-0.0.1.log.2 does not exist
renaming /var/log/judgecard-api-0.0.1.log.1 to /var/log/judgecard-api-0.0.1.log.2 (rotatecount 4, logstart 1, i 1),
old log /var/log/judgecard-api-0.0.1.log.1 does not exist
renaming /var/log/judgecard-api-0.0.1.log.0 to /var/log/judgecard-api-0.0.1.log.1 (rotatecount 4, logstart 1, i 0),
old log /var/log/judgecard-api-0.0.1.log.0 does not exist
log /var/log/judgecard-api-0.0.1.log.5 doesn't exist -- won't try to dispose of it
renaming /var/log/judgecard-api-0.0.1.log to /var/log/judgecard-api-0.0.1.log.1
error: failed to rename /var/log/judgecard-api-0.0.1.log to /var/log/judgecard-api-0.0.1.log.1: Permission denied
switching euid to 0 and egid to 0
答え1
明らかに、そのディレクトリは通常root:admに属しているため、/ var / logの回転に失敗しました。
Apacheや他の人を見て、彼らが何をしているのかを見ることができます。
一般的なアプローチは、/var/logの下にサブディレクトリを作成し、他のユーザーをその所有者にすることです。
sudo mkdir /var/log/judgecards
chown rajohns /var/log/judgecards
次に、古いログを移動し、ここでアプリケーションの新しいログを作成します。