Q: A user complains they cannot execute a script (`./script.sh`), getting a "Permission denied" error. They own the file and have `rwx` permissions. What else could cause this?
Even if the file has chmod +x and the user owns it, execution can be blocked by:
#Linux #Linux / SRE — Scenario-Based Interview Questions #L1 #SRE #Systems #Troubleshooting
🎙️ Candidate Opening & Architectural Context
""Never reboot a server blindly; always capture top process telemetry, lsof descriptors, and thread dumps first. The interviewer is testing: Filesystem mount options, SELinux/AppArmor, shell interpretation.. I structure my answer around systematic triage first, root cause analysis second, and permanent remediation third.""
Advertisement
🛠️ Production Runbook & Step-by-Step Resolution
1️⃣
Initial Diagnostics & Root Cause Analysis
Even if the file has chmod +x and the user owns it, execution can be blocked by:
- Mount options: The filesystem where the script resides might be mounted with the
noexecflag (often used for/tmpor/var/tmpfor security). You can check this by runningmount | grep noexec. - Interpreter path: The script's shebang (
#!/bin/bash) might point to a missing interpreter, or the interpreter itself lacks execute permissions. - SELinux/AppArmor: Mandatory Access Control policies might block the execution. Checking
dmesgor/var/log/audit/audit.logwill reveal SELinux denials.
2️⃣
Remediation & Permanent Safeguards
- Improper ACLs: Extended ACLs (checked via
getfacl script.sh) might have a deny rule superseding standard POSIX permissions.
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Pro-Tip: Mount options: The filesystem where the script resides might be mounted with the noexec flag (often used for /tmp or /var/tmp for ."
⚡ 60-Second Elevator Pitch Talking Points
- Mount options: The filesystem where the script resides might be mounted with the noexec flag (oft...
- Interpreter path: The script's shebang (#!/bin/bash) might point to a missing interpreter, or the...
- SELinux/AppArmor: Mandatory Access Control policies might block the execution. Checking dmesg or ...
Advertisement