Bug 1246380

Summary: Can not "service iptables save": restorecon not found
Product: Red Hat Enterprise Linux 7 Reporter: Michael Chapman <redhat-bugzilla>
Component: iptablesAssignee: Thomas Woerner <twoerner>
Status: CLOSED ERRATA QA Contact: Tomas Dolezal <todoleza>
Severity: unspecified Docs Contact:
Priority: unspecified    
Version: 7.3CC: iptables-maint-list, jscotka, oakwhiz
Target Milestone: rc   
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
: 1406860 (view as bug list) Environment:
Last Closed: 2016-11-04 07:51:09 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Michael Chapman 2015-07-24 07:12:36 UTC
The "save" action of the iptables initscript uses restorecon, but the iptables-services package has no dependency on policycoreutils.

# rpm -q iptables-services policycoreutils
iptables-services-1.4.21-13.el7.x86_64
package policycoreutils is not installed
# service iptables save
iptables: Saving firewall rules to /etc/sysconfig/iptables: /usr/libexec/iptables/iptables.init: line 303: restorecon: command not found
[FAILED]

Ideally the initscript would work correctly if restorecon is absent (you can probably assume SELinux is disabled if that's the case). A simpler alternative would be to have iptables-services require policycoreutils.

Comment 5 Thomas Woerner 2016-07-01 10:04:11 UTC
*** Bug 1314962 has been marked as a duplicate of this bug. ***

Comment 9 errata-xmlrpc 2016-11-04 07:51:09 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://rhn.redhat.com/errata/RHBA-2016-2521.html