Skip to content

Common Errors Quick Reference

This page collects the most common error messages and their solutions encountered during day-to-day administration of EL systems (AlmaLinux, Rocky Linux, CentOS, etc.), organized by category for quick lookup.

The package is not in any enabled repository.

Confirm the package name and search
$ dnf search <keyword>
Check if EPEL repository needs to be enabled
$ sudo dnf install -y epel-release
$ dnf search <package-name>

”This command has to be run with superuser privileges”

Section titled “”This command has to be run with superuser privileges””

Root privileges are required. Add sudo before the command.

Run with sudo
$ sudo dnf install <package-name>

If the user is not in the sudoers list:

Add the user to the wheel group (requires root)
$ su -
# usermod -aG wheel <username>

“Error: Failed to download metadata for repo ‘xxx’”

Section titled ““Error: Failed to download metadata for repo ‘xxx’””

Repository metadata download failed. This may be a network issue or an expired repository URL.

Clear cache and retry
$ sudo dnf clean all
$ sudo dnf makecache
Check the repository configuration file
$ cat /etc/yum.repos.d/<repo-name>.repo
If the repository is no longer needed, disable it
$ sudo dnf config-manager --set-disabled <repo-ID>

For EOL CentOS 8, official repositories have been taken offline. You need to migrate to AlmaLinux or Rocky Linux.

”Error: Transaction check error: file xxx from install of yyy conflicts with file from package zzz”

Section titled “”Error: Transaction check error: file xxx from install of yyy conflicts with file from package zzz””

Package file conflict.

Allow replacing conflicting packages
$ sudo dnf install <package-name> --allowerasing
View conflicting files between two packages
$ rpm -ql <package1> | sort > /tmp/pkg1.txt
$ rpm -ql <package2> | sort > /tmp/pkg2.txt
$ comm -12 /tmp/pkg1.txt /tmp/pkg2.txt

”Curl error (28): Timeout was reached”

Section titled “”Curl error (28): Timeout was reached””

Download timed out. Network issue or unreachable mirror.

Test connectivity to the mirror
$ curl -I https://mirror.example.com/
Switch to a faster mirror (AlmaLinux example)
$ sudo sed -i 's|^mirrorlist=|#mirrorlist=|g' /etc/yum.repos.d/almalinux*.repo
$ sudo sed -i 's|^# baseurl=https://repo.almalinux.org|baseurl=https://mirrors.aliyun.com|g' /etc/yum.repos.d/almalinux*.repo
$ sudo dnf makecache

The 32-bit and 64-bit versions of the same package have mismatched versions.

Sync to fix
$ sudo dnf distro-sync <package-name>
If the 32-bit version is not needed
$ sudo dnf remove <package-name>.i686

”Job for xxx.service failed because the control process exited with error code”

Section titled “”Job for xxx.service failed because the control process exited with error code””

Service failed to start.

View service status and error details
$ systemctl status <service-name>
View the full service log
$ journalctl -u <service-name> -n 50 --no-pager
Check configuration file syntax (nginx example)
$ nginx -t
Check configuration file syntax (httpd example)
$ httpd -t

The service is masked and cannot be started.

Unmask the service
$ sudo systemctl unmask <service-name>
$ sudo systemctl start <service-name>

”xxx.service: Failed with result ‘exit-code’”

Section titled “”xxx.service: Failed with result ‘exit-code’””

The service started but exited abnormally.

View the exit status code
$ systemctl show <service-name> -p ExecMainStatus
View the last few log entries
$ journalctl -u <service-name> -e --no-pager

Common causes: configuration file syntax error, port already in use, insufficient permissions, dependent service not started.

Check if a port is occupied by another process
$ sudo ss -tlnp | grep :<port-number>

”Failed to start xxx.service: Unit not found”

Section titled “”Failed to start xxx.service: Unit not found””

The service unit file does not exist.

Confirm the package is installed
$ rpm -qa | grep <package-name>
Find the correct service name
$ systemctl list-unit-files | grep <keyword>

”Permission denied” but file permissions are correct

Section titled “”Permission denied” but file permissions are correct”

The most common SELinux issue. Unix file permissions are correct, but the SELinux security context does not match.

Check for AVC denial records
$ sudo ausearch -m avc -ts recent
Install and use sealert for recommendations
$ sudo dnf install -y setroubleshoot-server
$ sudo sealert -a /var/log/audit/audit.log | head -60
Restore the default SELinux context for files
$ sudo restorecon -Rv /path/to/files

”SELinux is preventing xxx from yyy access on zzz”

Section titled “”SELinux is preventing xxx from yyy access on zzz””

An SELinux policy is blocking an operation.

View detailed information and fix suggestions
$ sudo ausearch -m avc -ts recent | audit2why
If it is a known legitimate operation, generate and install a policy module
$ sudo ausearch -m avc -ts recent | audit2allow -M my_policy
$ sudo semodule -i my_policy.pp

For example, configuring Apache to listen on port 8888:

View SELinux-allowed HTTP ports
$ sudo semanage port -l | grep http_port_t
Add a custom port
$ sudo semanage port -a -t http_port_t -p tcp 8888

Web Service Cannot Access User Home Directory Content

Section titled “Web Service Cannot Access User Home Directory Content”
Enable the httpd home directory access boolean
$ sudo setsebool -P httpd_enable_homedirs on
Allow httpd to make network connections (e.g., for reverse proxy)
$ sudo setsebool -P httpd_can_network_connect on

No route to the destination.

Check the routing table
$ ip route show
Check for a default route
$ ip route show default

If there is no default route:

Temporarily add a default route
$ sudo ip route add default via <gateway-IP>
Permanently configure the gateway via nmcli
$ sudo nmcli connection modify "connection-name" ipv4.gateway <gateway-IP>
$ sudo nmcli connection up "connection-name"

No service is listening on the target port.

Confirm the target port is listening
$ sudo ss -tlnp | grep :<port>
Confirm the service is running
$ systemctl status <service-name>

DNS resolution failed.

Check DNS configuration
$ cat /etc/resolv.conf
Test if the DNS server is reachable
$ ping -c 2 $(grep nameserver /etc/resolv.conf | head -1 | awk '{print $2}')
Test with a manually specified DNS server
$ dig @8.8.8.8 <domain>

The port is already occupied by another process.

Find the process using the port
$ sudo ss -tlnp | grep :<port>
$ sudo lsof -i :<port>
Kill the occupying process (after confirming it is safe)
$ sudo kill <PID>

Disk space is insufficient.

View disk usage
$ df -h
Find the largest directories
$ sudo du -sh /* 2>/dev/null | sort -rh | head -10
Quickly free space
$ sudo dnf clean all
$ sudo journalctl --vacuum-size=100M
$ sudo find /tmp -type f -atime +7 -delete

If df -h shows space is available but the error persists:

Check inode usage
$ df -i

Inode exhaustion is usually caused by a large number of small files in a single directory:

Find directories using the most inodes
$ sudo find / -xdev -printf '%h\n' | sort | uniq -c | sort -rn | head -10

“Structure needs cleaning” / Filesystem Errors

Section titled ““Structure needs cleaning” / Filesystem Errors”

Filesystem corruption.

Unmount the partition and run a filesystem check
$ sudo umount /dev/sda2
$ sudo fsck -y /dev/sda2

Warning: Never run fsck on a mounted filesystem. If it is the root partition, you must operate from rescue mode.

The filesystem was forcibly switched to read-only mode, usually because disk errors were detected.

Check system logs for disk errors
$ dmesg | grep -i -E '(error|fail|read.only|EXT4-fs)'
Try remounting as read-write
$ sudo mount -o remount,rw /

If remounting fails, it indicates a hardware issue with the disk and repair from rescue mode is needed.

/boot Space Insufficient Causing Kernel Installation Failure

Section titled “/boot Space Insufficient Causing Kernel Installation Failure”
View /boot partition usage
$ df -h /boot
List installed kernels
$ rpm -qa kernel-core | sort -V
Remove old kernels, keeping only the latest two
$ sudo dnf remove --oldinstallonly --setopt installonly_limit=2 kernel

”Operation not permitted” (even as root)

Section titled “”Operation not permitted” (even as root)”

The file may have the immutable attribute set.

View the file's extended attributes
$ lsattr <file-path>

If you see the i flag (immutable):

Remove the immutable attribute
$ sudo chattr -i <file-path>

The command is not in the PATH, or the corresponding package is not installed.

Find which package provides the command
$ dnf provides <command-name>
If it is a command under sbin, use the full path as root
$ /usr/sbin/<command-name>
Confirm the PATH environment variable
$ echo $PATH

”cannot create regular file: Permission denied”

Section titled “”cannot create regular file: Permission denied””
Check the target directory permissions
$ ls -la <target-directory>
Check the directory's SELinux context
$ ls -laZ <target-directory>
Check the directory's ACL rules
$ getfacl <target-directory>

”WARNING: REMOTE HOST IDENTIFICATION HAS CHANGED!”

Section titled “”WARNING: REMOTE HOST IDENTIFICATION HAS CHANGED!””

The server key has changed (common after OS reinstallation or migration).

Remove the old host key after confirming it is safe
$ ssh-keygen -R <hostname-or-IP>

”Permission denied (publickey,gssapi-keyex,gssapi-with-mic)”

Section titled “”Permission denied (publickey,gssapi-keyex,gssapi-with-mic)””

Key authentication failed, and the server has password authentication disabled.

Check SSH server configuration
$ sudo grep -E '(PasswordAuthentication|PubkeyAuthentication|PermitRootLogin)' /etc/ssh/sshd_config
Check key file permissions (client side)
$ ls -la ~/.ssh/
$ chmod 700 ~/.ssh
$ chmod 600 ~/.ssh/id_rsa
$ chmod 644 ~/.ssh/id_rsa.pub
Check authorized_keys permissions (server side)
$ chmod 700 ~/.ssh
$ chmod 600 ~/.ssh/authorized_keys