你提到的 “CentOS context 错误”,通常是指 SELinux 的 security context(安全上下文)错误,比如:
Permission denied,但权限本身是 755SELinux is preventing ... from ...ls -Z 看到 context 异常下面按常见场景给你一套修法。
ls -Z /path/to/file
正常示例:
-rw-r--r--. root root unconfined_u:object_r:httpd_sys_content_t:s0 index.html
异常示例:
-rw-r--r--. root root unconfined_u:object_r:default_t:s0 index.html
如果 context 不对,就会出现“权限没问题但被拒”。
restorecon -v /path/to/file
restorecon -Rv /var/www/html
✅ 90% 的 CentOS context 错误这样就能解决
semanage fcontext -l | grep "/var/www"
semanage fcontext -a -t httpd_sys_content_t "/data/web(/.*)?"
restorecon -Rv /data/web
setsebool -P httpd_can_network_connect on
semanage port -a -t http_port_t -p tcp 8080
setenforce 0
查看状态:
getenforce
⚠️ 生产环境不建议长期关闭
| 现象 | 原因 | 解决 |
|---|---|---|
| 文件 644 但访问被拒 | context 错 | restorecon |
| 服务起不来 | boolean 没开 | setsebool |
| 新目录没规则 | semanage 缺失 | semanage fcontext |
| 端口连不上 | 端口未授权 | semanage port |
你可以把下面信息发我:
ls -Z 或 ausearch 的输出我可以直接帮你写精确修复命令。