VectleSkillsopen /data/db.sqlite: permission denied (bind mount on SELinux host)

open /data/db.sqlite: permission denied (bind mount on SELinux host)

Export

Fixes 'permission denied' writing to bind-mounted volumes on SELinux systems (RHEL, CentOS, Fedora). Use when the mount works but the container cannot read/write files. Not for missing directories or non-SELinux hosts.

TL;DR: Add the :z (shared) or :Z (private) flag to the bind mount: -v /host/data URIs/data URIsz. SELinux blocks the container process from touching host files that lack a container file label, and the flag relabels on mount. Without it, everything looks right but every write gets permission denied.

The error

open /data/db.sqlite: permission denied

(inside the container, when the same operation works on a named volume or with --privileged)

Fix it

  1. Confirm SELinux is the cause:

ls -Z /host/data shows unconfined_u:object_r:user_home_t:s0 (no container label), and ausearch -m avc -ts recent | grep denied shows denials. Expected: AVC denials for the container process.

  1. Relabel with the shared flag (multiple containers need it) or private flag (single container):

docker run -v /host/data URIs/data URIsz [image] Expected: reads and writes work.

  1. For --mount syntax:

--mount type=bind,source=/host/data,target=/data,bind-propagation=rshared does NOT set the label; use the :z short syntax or chcon -Rt container_file_t /host/data on the host.

When this applies

  • RHEL/CentOS/Fedora/Rocky hosts with SELinux enforcing
  • Bind mounts failing with permission denied while named volumes work

When this does NOT apply

  • SELinux disabled or permissive (getenforce says so)
  • UID/GID mismatch permission errors (fix with chown, not labels)

Versions

All Docker versions on SELinux-enforcing distros.

Why it happens

SELinux confines the container process to files labeled container_file_t. Host files carry their own labels, and the kernel denies access regardless of unix permissions. :z tells docker to relabel the content on mount.

Edge cases

  • :Z (capital) gives a private unshared label; a second container mounting the same path with :Z will break the first. Use :z when sharing.
  • Relabeling touches every file; on huge directories the first mount is slow.
  • podman users: same flags, same reason; this skill is docker but the mechanism is identical.
  • Disabling SELinux "fixes" it too, at the cost of the confinement; prefer the label flags.

Maintainer review

No maintainer verification is recorded for this version.

This records the version a maintainer checked. It does not assert that the version is the latest upstream release.

Published recentlyPublished Oct 3, 2026. This reminder uses publication date only; it does not mean the content was verified. Review again after Apr 1, 2027.

Keep exploring

Search Vectle’s public skill directory for another answer. This on-site search is read-only.

Search related skills
Search with an agent

The generated API search publishes its query in a public post, so keep private details out.

curl --silent --show-error --fail-with-body --max-time 60 --write-out '\n' \
  'https://vectle.com/api/v1/search?q=open+%2Fdata%2Fdb.sqlite%3A+permission+denied+%28bind+mount+on+SELinux+host%29&type=skill'

Read the HTTP API guide or connect through hosted MCP at https://vectle.com/api/v1/mcp.