Issue #8714 has been updated by Sean Millichamp.

Affected Puppet version changed from 2.6.9 to 2.6.13

Darrell,

Thanks for the information.  I have been able to confirm and reproduce this bug 
on both RHEL 6.2 and Fedora 16 with Puppet 2.6.  Not sure WHY yet, but I am 
fairly confident that the bug is in the Puppet SELinux support and not the Ruby 
SELinux bindings (as when I call the same functions manually from irb that 
Puppet ought to be calling to set the context it works just fine).

I will have to dig into this more at a later date. Just wanted to post an 
update confirming I could reproduce this.

Sean
----------------------------------------
Bug #8714: Changing SELinux contexts on symlinks requires the '-h' parameter in 
chcon
https://projects.puppetlabs.com/issues/8714#change-56134

Author: Ioannis Aslanidis
Status: Needs More Information
Priority: Normal
Assignee: Sean Millichamp
Category: SELinux
Target version: 
Affected Puppet version: 2.6.13
Keywords: 
Branch: 


There is a problem when trying to chance SELinux contexts through puppet. Looks 
like puppet does not call **chcon** with the **-h** parameter.

    # ls -ald /home/file/test
    lrwxrwxrwx 1 root root 20 Aug  1 12:23 /home/file/test -> /mnt/file/test

    # chcon -v -t user_home_t test
    failed to change context of test to system_u:object_r:user_home_t
    chcon: failed to change context of test to system_u:object_r:user_home_t: 
Operation not supported

    # chcon -v -h -t user_home_t test
    context of /home/file/test changed to system_u:object_r:user_home_t
    
This results in puppet trying to change the SELinux contexts on every run 
without success and without knowing that it actually failed.


-- 
You have received this notification because you have either subscribed to it, 
or are involved in it.
To change your notification preferences, please click here: 
http://projects.puppetlabs.com/my/account

-- 
You received this message because you are subscribed to the Google Groups 
"Puppet Bugs" group.
To post to this group, send email to [email protected].
To unsubscribe from this group, send email to 
[email protected].
For more options, visit this group at 
http://groups.google.com/group/puppet-bugs?hl=en.

Reply via email to