SELinux Denials: Troubleshooting with ausearch - 夜莺博客

SELinux Denials: Troubleshooting with ausearch

Disabling SELinux to make an application work is the most expensive shortcut in Linux administration: you trade a precise, fixable label problem for an entire class of uncontrolled access. This guide follows the correct escalation path for a denial - read the audit log, translate the message, fix the label with restorecon or semanage fcontext, adjust a boolean if one exists, and only then generate a minimal policy module. It also covers the two failure modes that waste the most time: dontaudit rules hiding the evidence, and chcon being mistaken for a permanent fix.

Read the denial

ausearch -m AVC,USER_AVC -ts recent
ausearch -m AVC -ts today | audit2why
grep AVC /var/log/audit/audit.log | tail -50
sealert -a /var/log/audit/audit.log      # if setroubleshoot is installed

An AVC message contains the source context (scontext, the process), the target context (tcontext, the file, socket or port), the class of access, and a permissive= flag. Read all four before changing anything: the same denial text has completely different fixes depending on which side of it is misfiled.

Missing denials: dontaudit

semodule -DB     # disable dontaudit rules temporarily
# reproduce the failure
semodule -B      # re-enable them

If your scenario is being blocked but no AVC message appears, a dontaudit rule is silencing the log. Turn the rules off, reproduce the behaviour, then turn them back on - remembering that dontaudit exists to keep logs usable in normal operation.

Fix 1: labels, the most common cause

restorecon -Rv /var/www/html
semanage fcontext -a -t httpd_sys_content_t "/srv/myapp(/.*)?"
restorecon -Rv /srv/myapp
semanage fcontext -l | grep "/var/www"

Files copied with cp, moved across filesystems or created in a non-standard directory inherit the wrong context. restorecon re-applies what policy says the path should have; semanage fcontext teaches policy about a custom path so that the label survives relabels. Never use chcon as the final fix - it changes only the runtime label and is lost at the next relabel. If labels are inconsistent system-wide, touch /.autorelabel && reboot is the blunt but correct instrument.

Fix 2: ports and booleans

semanage port -a -t http_port_t -p tcp 8080
getsebool -a | grep httpd
setsebool -P httpd_can_network_connect on

Services may only bind to port types defined for them; a custom port needs semanage port. Booleans exist precisely so that common variations do not require custom policy - always prefer a boolean over module writing, and always use -P so the change persists across reboots.

Fix 3: a minimal local policy - last resort

ausearch -m AVC -ts today | audit2allow -M myapp_fix
cat myapp_fix.te      # read it before loading
semodule -i myapp_fix.pp
semodule -l | grep myapp
semodule -r myapp_fix # remove if it turns out to be wrong

Read the generated .te file. If it grants broad types such as unconfined_t, or allows far more than the denial needed, the fix is wrong - refine the input with more specific ausearch filters instead of widening the policy.

Related: auditd rules and ausearch investigations for the audit framework itself, and fail2ban with nftables for host-level access control that complements SELinux enforcement.

原文链接:https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/9/html/using_selinux/troubleshooting-problems-related-to-selinux_using-selinux