Q: An application runs fine, but SELinux denies a critical system call with "Permission Denied" (avc denial). Standard Unix permissions show the file is readable. How do you diagnose and temporarily allow the access?
SELinux is a Mandatory Access Control (MAC) layer that sits above traditional Unix permissions (DAC). Even if a file is 644, SELinux can ...
#Linux #Linux / SRE — Scenario-Based Interview Questions #L2 #SRE #Systems #Troubleshooting
🎙️ Candidate Opening & Architectural Context
""Never reboot a server blindly; always capture top process telemetry, lsof descriptors, and thread dumps first. The interviewer is testing: Mandatory Access Control (MAC) vs Discretionary Access Control (DAC), SELinux policy debugging.. I structure my answer around systematic triage first, root cause analysis second, and permanent remediation third.""
Advertisement
🛠️ Production Runbook & Step-by-Step Resolution
1️⃣
Initial Diagnostics & Root Cause Analysis
SELinux is a Mandatory Access Control (MAC) layer that sits *above* traditional Unix permissions (DAC). Even if a file is 644, SELinux can block access if the policy says the process's domain is not allowed.
- Check the audit log:
audit2whyorgrep AVC /var/log/audit/audit.logshows the exact denial. Example: - Temporary fix (debug mode): Set SELinux to Permissive mode for the domain:
- Permanent fix: Either:
2️⃣
Remediation & Permanent Safeguards
When a denial occurs: This shows httpd_t domain trying to read a user_home_t file—denied by policy. This logs denials but allows the process to operate, helping identify which accesses are actually needed.
type=AVC msg=... avc: denied { read } for pid=1234 comm="apache" name="config.txt" scontext=system_u:system_r:httpd_t:s0 tcontext=staff_u:object_r:user_home_t:s0
- Change the file's SELinux context:
chcon -t httpd_sys_rw_content_t /var/www/config.txt - Write a custom policy module using
audit2allowto automatically generate rules from audit logs.
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Pro-Tip: Check the audit log: audit2why or grep AVC /var/log/audit/audit.log shows the exact denial. Example:."
⚡ 60-Second Elevator Pitch Talking Points
- Check the audit log: audit2why or grep AVC /var/log/audit/audit.log shows the exact denial. Example:
- Temporary fix (debug mode): Set SELinux to Permissive mode for the domain:
- Permanent fix: Either:
Advertisement