SELinux is preventing ... / avc: denied { read } for pid=... (permission denied despite correct permissions)
SELinux blocked the access — file permissions look fine, but the file’s security context or a boolean doesn’t allow the service to do it.
Seen on:
Linux
Meaning
On RHEL/Fedora/Rocky/Alma, services run in confined domains. Files moved (not copied) keep their old label, web servers can’t make network connections or read home directories unless booleans allow it, and non-standard ports need labeling.
Common causes
- Files moved with wrong SELinux context (mv keeps the label)
- Boolean not enabled (httpd_can_network_connect, httpd_enable_homedirs)
- Service using a non-standard port
- Custom app paths without file contexts
⚡ Quick fix
- Check the denial: ausearch -m avc -ts recent
- Restore contexts: restorecon -Rv /path
- Enable the right boolean or label the port
Detailed fix by platform
RHEL
- bash
sudo ausearch -m avc -ts recent | tail sudo restorecon -Rv /var/www/html sudo setsebool -P httpd_can_network_connect 1 sudo semanage port -a -t http_port_t -p tcp 8081
How to diagnose
- Mode — getenforce
- Denial — ausearch/audit.log
- Context — ls -Z path
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
Most viewed in Linux
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026