AVC Denials: Your Starting Point
When SELinux blocks something, it writes an AVC (Access Vector Cache) message to the audit log. Learning to read these is the most important SELinux skill.
Finding AVC Messages
# Direct audit log
grep AVC /var/log/audit/audit.log
# Structured search
ausearch -m AVC,USER_AVC -ts recent
# Human-readable
journalctl -t setroubleshootMaster this topic with hands-on labs
Go beyond reading — build real projects in sandboxed environments with expert video guidance.
Browse Courses →Reading an AVC Message
type=AVC msg=audit(1770796878.691:181): avc: denied { getattr }
for pid=12187 comm="httpd"
path="/srv/webroot/index.html"
scontext=system_u:system_r:httpd_t:s0
tcontext=unconfined_u:object_r:var_t:s0
tclass=file permissive=0- denied { getattr } — the blocked permission
- comm="httpd" — the process
- scontext=...httpd_t — source type (process)
- tcontext=...var_t — target type (file)
- tclass=file — object class
The Troubleshooting Workflow
1. Verify mode and context
getenforce
ls -Z /path/to/file
ps -eZ | grep process_name2. Check AVC logs
ausearch -m AVC,USER_AVC -ts recent3. Decide: label fix or boolean?
- Wrong label →
semanage fcontext+restorecon - Missing behavior →
setsebool
4. Custom policy as last resort
Get weekly IT automation tips
Docker, Ansible, Terraform, MLOps — curated insights delivered to your inbox. No spam.
Subscribe Free →audit2allow: Use With Caution
grep AVC /var/log/audit/audit.log | audit2allowOutput:
allow httpd_t var_t:file getattr;Warning: This allows httpd_t to access all var_t files. The correct fix is relabeling, not overly permissive policy.
Common Denial Patterns
| Denial | Likely Fix |
|---|---|
| Wrong file type | Relabel with semanage fcontext |
name_connect denied | Enable boolean (httpd_can_network_connect) |
| Write denied on upload dir | Label as httpd_sys_rw_content_t |
Master this workflow in our SELinux for System Admins course.
---
Ready to go deeper?
This article is part of a hands-on learning path. Continue building your skills with SELinux for System Admins on CopyPasteLearn.
Ready to learn by doing?
Stop reading tutorials — start building. Expert video courses with hands-on labs in real sandboxed environments.
Related Articles
SELinux Cheat Sheet for RHEL
Quick reference for essential SELinux commands on RHEL 9/10. Modes, contexts, labels, booleans, logs, and troubleshooting in one page.
SELinux Upload Directories Guide
Properly label writable upload directories for Apache with SELinux. Use httpd_sys_rw_content_t to allow writes without disabling security.
SELinux for Apache and PHP-FPM
Configure Apache with PHP-FPM over TCP on RHEL with SELinux enforcing. Diagnose and fix name_connect denials using the correct SELinux boolean and audit tools.
TypeScript Express Tutorial 2026
Build a production REST API with TypeScript and Express. Complete tutorial covering project setup, routing, middleware, and deployment.
Ubuntu 24.04 LTS: Safe Choice
Ubuntu 24.04 LTS offers five years of support, the largest ecosystem, and unmatched hardware compatibility. Why it remains the safest mainstream Linux choice.
Ubuntu 26.04 Makes sudo-rs Default
Ubuntu 26.04 LTS replaces the 44-year-old C sudo with sudo-rs, a Rust rewrite. Learn what changes, why it matters for security, and what else ships.
Explore topics
Browse more articles on the topics covered here.