⚡ ~/naveed Interview Prep
⚡ Portfolio Home ✍️ Engineering Blog Deep Dives 🎯 Interview Hub 998+ Scenarios ☸️ Kubernetes Mastery Hub 24 Modules 🎮 DevOps Arcade & Quizzes Subnet Blitz ⚡ 🗺️ DevOps Roadmaps PDFs & Guides 🤖 Morpheus Analysis AI Quant ↗ 🛠️ Developer Tools Utilities 🧪 Labs & Experiments 📄 Interactive CV & Certs 🔗 All Links & Socials ⚡ Join The Dispatch (Weekly SRE Newsletter) →
Senior DevOps / SRE [L2] Linux Linux / SRE — Scenario-Based Interview Questions Production Scenario [L2]

Q: An application runs fine, but SELinux denies a critical system call with "Permission Denied" (avc denial). Standard Unix permissions show the file is readable. How do you diagnose and temporarily allow the access?

SELinux is a Mandatory Access Control (MAC) layer that sits above traditional Unix permissions (DAC). Even if a file is 644, SELinux can ...

#Linux #Linux / SRE — Scenario-Based Interview Questions #L2 #SRE #Systems #Troubleshooting
🎙️ Candidate Opening & Architectural Context
""Never reboot a server blindly; always capture top process telemetry, lsof descriptors, and thread dumps first. The interviewer is testing: Mandatory Access Control (MAC) vs Discretionary Access Control (DAC), SELinux policy debugging.. I structure my answer around systematic triage first, root cause analysis second, and permanent remediation third.""
Advertisement

🛠️ Production Runbook & Step-by-Step Resolution

1️⃣

Initial Diagnostics & Root Cause Analysis

SELinux is a Mandatory Access Control (MAC) layer that sits *above* traditional Unix permissions (DAC). Even if a file is 644, SELinux can block access if the policy says the process's domain is not allowed.

  • Check the audit log: audit2why or grep AVC /var/log/audit/audit.log shows the exact denial. Example:
  • Temporary fix (debug mode): Set SELinux to Permissive mode for the domain:
  • Permanent fix: Either:
2️⃣

Remediation & Permanent Safeguards

When a denial occurs: This shows httpd_t domain trying to read a user_home_t file—denied by policy. This logs denials but allows the process to operate, helping identify which accesses are actually needed.

type=AVC msg=... avc: denied { read } for pid=1234 comm="apache" name="config.txt" scontext=system_u:system_r:httpd_t:s0 tcontext=staff_u:object_r:user_home_t:s0
  • Change the file's SELinux context: chcon -t httpd_sys_rw_content_t /var/www/config.txt
  • Write a custom policy module using audit2allow to automatically generate rules from audit logs.
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Pro-Tip: Check the audit log: audit2why or grep AVC /var/log/audit/audit.log shows the exact denial. Example:."
⚡ 60-Second Elevator Pitch Talking Points
  • Check the audit log: audit2why or grep AVC /var/log/audit/audit.log shows the exact denial. Example:
  • Temporary fix (debug mode): Set SELinux to Permissive mode for the domain:
  • Permanent fix: Either:
Advertisement
Want more Linux scenarios?
Explore our complete collection of scenario-based Linux interview runbooks.
Browse All Linux Questions →

📚 Related Production Scenarios in Linux