avc: denied 🐧 Linux

SELinux is preventing ... / avc: denied { read } for pid=... (permission denied despite correct permissions)

SELinux blocked the access — file permissions look fine, but the file’s security context or a boolean doesn’t allow the service to do it.

Seen on: Linux

Meaning

On RHEL/Fedora/Rocky/Alma, services run in confined domains. Files moved (not copied) keep their old label, web servers can’t make network connections or read home directories unless booleans allow it, and non-standard ports need labeling.

Common causes

  • Files moved with wrong SELinux context (mv keeps the label)
  • Boolean not enabled (httpd_can_network_connect, httpd_enable_homedirs)
  • Service using a non-standard port
  • Custom app paths without file contexts

⚡ Quick fix

  1. Check the denial: ausearch -m avc -ts recent
  2. Restore contexts: restorecon -Rv /path
  3. Enable the right boolean or label the port

Detailed fix by platform

RHEL

  1. bash
    sudo ausearch -m avc -ts recent | tail
    sudo restorecon -Rv /var/www/html
    sudo setsebool -P httpd_can_network_connect 1
    sudo semanage port -a -t http_port_t -p tcp 8081

How to diagnose

  1. Mode — getenforce
  2. Denial — ausearch/audit.log
  3. Context — ls -Z path

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.