Issue #8714 has been updated by Darrell Fuhriman.
I'm encountering this with a simple:
file {'/Users':
ensure => '/home',
seltype => 'user_home_t',
}
I'm running 2.7.9 on Centos 6.2 (both client and server)
Misc Versions:
selinux-policy-3.7.19-126.el6.3.noarch
libselinux-2.0.94-5.2.el6.x86_64
libselinux-ruby-2.0.94-5.2.el6.x86_64
libselinux-utils-2.0.94-5.2.el6.x86_64
selinux-policy-targeted-3.7.19-126.el6.3.noarch
I'm happy to help debug.
----------------------------------------
Bug #8714: Changing SELinux contexts on symlinks requires the '-h' parameter in
chcon
https://projects.puppetlabs.com/issues/8714
Author: Ioannis Aslanidis
Status: Needs More Information
Priority: Normal
Assignee: Sean Millichamp
Category: SELinux
Target version:
Affected Puppet version: 2.6.9
Keywords:
Branch:
There is a problem when trying to chance SELinux contexts through puppet. Looks
like puppet does not call **chcon** with the **-h** parameter.
# ls -ald /home/file/test
lrwxrwxrwx 1 root root 20 Aug 1 12:23 /home/file/test -> /mnt/file/test
# chcon -v -t user_home_t test
failed to change context of test to system_u:object_r:user_home_t
chcon: failed to change context of test to system_u:object_r:user_home_t:
Operation not supported
# chcon -v -h -t user_home_t test
context of /home/file/test changed to system_u:object_r:user_home_t
This results in puppet trying to change the SELinux contexts on every run
without success and without knowing that it actually failed.
--
You have received this notification because you have either subscribed to it,
or are involved in it.
To change your notification preferences, please click here:
http://projects.puppetlabs.com/my/account
--
You received this message because you are subscribed to the Google Groups
"Puppet Bugs" group.
To post to this group, send email to [email protected].
To unsubscribe from this group, send email to
[email protected].
For more options, visit this group at
http://groups.google.com/group/puppet-bugs?hl=en.