Linux · SELinux & AppArmor

You keep seeing AppArmor 'audit' denials in the logs for a program that otherwise seems to work. What do frequent audit messages usually mean, and what are your options?

Answer locked. Get the free KnowCard app to reveal it — plus spaced-repetition review so it actually sticks.

Get it on App StoreGet it on Google Play

This is one card from the KnowCard library — thousands more across SAP, Linux, Python and more. In the app you get the answer, AI explanations, and cards that come back right before you would forget them. Free to start on iOS, Android or the web.

More in SELinux & AppArmor

A daemon already runs under its own restricted account with the right rwx permissions, yet you also want the kernel to stop it touching directories it has no business in even if it is hijacked. What extra layer provides this?
When a running process violates an SELinux rule, many people assume SELinux kills the offending program. What does it actually do?
Administrators frequently switch SELinux off the moment the first problem appears. What two structural criticisms of SELinux drive that reaction?
You want to see the SELinux context of a file. Which command shows it, and where is that context physically stored?
A file ended up with the wrong SELinux context. You reach for restorecon vs chcon — what is the practical difference between the two?
You serve HTML from a non-standard directory like /var/myotherserver and want the correct SELinux context to survive future restorecon runs. What's the durable fix?

Start learning today

Free to start — download the app or use it in your browser.

Get it on App StoreGet it on Google Play