Topic23 problems· 4 reviewed

Linux Permissions and Access

23 incident problems about Linux Permissions and Access. Start with the reviewed ones.

Read first

Recommended problems

Reviewed problems first, then problems with detailed scenarios.

All problems (23)

LINUX-006The application cannot read filesA scenario that narrows down the root cause, centered on checking permissions, owner, and the execution account together, in the situation of the application being unable to read files because permissions changed after a deploy script.ReviewedLinuxIntermediate19 minFreeLINUX-031SELinux context breaks web content after rsync-based restoreFile ownership and permissions look correct after a restore, but the service still cannot read content because the restored paths lost the expected SELinux labels.ReviewedLinuxIntermediate21 minFreeLINUX-056SSH key is valid but included config disables PubkeyAuthentication later in the chainAuthorized keys and file permissions look healthy, yet login falls back to password because a later include file overrides the expected sshd setting.ReviewedLinuxIntermediate17 minFreeLINUX-063sudoers include file is ignoredThe rule is written correctly, yet sudo behavior never changes because the included file fails the safety checks and is silently skipped.ReviewedLinuxBeginner13 minFreeLINUX-017Only the operations automation account fails to run a command due to a sudoers rule differenceCovers a situation where human accounts work but only the automation account is blocked on a specific command due to different permissions.LinuxIntermediate19 minFreeLINUX-075pam_faillock keeps accounts blocked after LDAP recoveryDirectory authentication is healthy again, but users still cannot log in because the host-local lock records survived the upstream outage.LinuxIntermediate16 minFreeLINUX-089rsync backup over SSH stallsNetwork reachability is fine, but the batch backup never starts because the negotiated SSH crypto overlap disappeared during a hardening change.LinuxIntermediate16 minFreeLINUX-084sudo NOPASSWD rule is present but a later group rule still forces password promptsThe expected privilege rule exists, but one broader matching policy lower in the evaluation path overrides the operator's assumption about effective behavior.LinuxIntermediate13 minFreeLINUX-086sshd Match block for a bastion subnet disables agent forwarding on one host class onlySSH works broadly, but a specific bastion path behaves differently because a later Match clause quietly changes capabilities for one source range.LinuxIntermediate15 minFreeLINUX-076tmpfiles.d recreates the runtime directory with the wrong owner after rebootPermissions look correct before restart, but the service fails after boot because tmpfiles recreated the path with ownership that no longer matches the daemon user.LinuxIntermediate15 minFreeLINUX-066SELinux blocks the new content rootPermissions and ownership look correct, but the service still gets denied because the moved directory kept the wrong security context.LinuxIntermediate16 minFreeLINUX-094SELinux context is correct on the binary but the parent directory type still blocks traversalThe executable label looks valid, yet access fails because one parent directory retains a context that denies the path traversal required to reach the file.LinuxIntermediate16 minFreeLINUX-070SSSD cache preserves deleted group membership and sudo access lingers after offboardingThe identity source is already updated, but one host still grants privileged access because its local cache did not expire when the account changed.LinuxIntermediate17 minFreeLINUX-024File exists but service user cannot follow parent directoryFile exists but service user cannot follow parent directory is a hands-on troubleshooting drill. The file permission looks fine, but one directory in the path denies execute permission and breaks access. Azure Linux Service Operations needs to be checked by narrowing scope, re...LinuxBeginner14 minFreeLINUX-038Sudoers drop-in order silently reintroduces password promptsThe main sudoers file looks correct, but a later drop-in overrides the intended NOPASSWD rule and breaks the automation path.LinuxBeginner14 minFreeLINUX-052Application helper failsThe binary exists and permissions look correct, but the helper script or unpacked runtime tool cannot execute because the temporary mount has a stricter policy than the application expects.LinuxBeginner15 minFreeLINUX-077Rsync restore with numeric-ids shifts file ownershipThe backup looks intact, but the restored application loses access because numeric UID preservation no longer matches the target system account layout.LinuxAdvanced20 minProLINUX-097AppArmor profile loads but one helper binary escapes mediationPrimary commands are constrained, yet a helper path stays unrestricted because the profile pattern never matched the deployed binary location.LinuxAdvanced17 minProLINUX-088SELinux policy module loads successfully but a file transition rule never matches the deployed pathThe custom policy is present, yet denials continue because the actual path used in deployment does not trigger the transition rule the author expected.LinuxAdvanced19 minProLINUX-1489A PAM faillock reset succeeds and remote users still failUsers remain locked out only on nodes with home-mounted identity caches after a faillock reset.LinuxAdvanced10 minPro