Bug 1340312
Summary: | Installing packages with subscription manager results in AVC errors | ||
---|---|---|---|
Product: | [Fedora] Fedora | Reporter: | Andrew Beekhof <abeekhof> |
Component: | libguestfs | Assignee: | Richard W.M. Jones <rjones> |
Status: | CLOSED NOTABUG | QA Contact: | Fedora Extras Quality Assurance <extras-qa> |
Severity: | high | Docs Contact: | |
Priority: | unspecified | ||
Version: | 23 | CC: | abeekhof, dwalsh, mbooth, ptoscano, rjones, virt-maint |
Target Milestone: | --- | ||
Target Release: | --- | ||
Hardware: | Unspecified | ||
OS: | Unspecified | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | If docs needed, set a value | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2016-08-01 12:02:31 UTC | Type: | Bug |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: |
Description
Andrew Beekhof
2016-05-27 01:47:49 UTC
(In reply to Andrew Beekhof from comment #0) > virt-customize -a rhel-guest-image-7.2-20160302.0.x86_64.qcow2 \ > --sm-credentials 'rhn_engineering_XXXX:password:mysecret' \ > --sm-register --sm-attach auto \ > --install "ntp" > --sm-unregister I don't see --selinux-relabel among the arguments. Please use it, when customizing SELinux-enabled guests. Ah, --selinux-relabel did indeed fix it, I've left a note on https://rwmj.wordpress.com/2015/10/03/tip-updating-rhel-7-1-cloud-images-using-virt-customize-and-subscription-manager for anyone that comes after me. Would it make sense to imply --selinux-relabel when --sm-* is in use? Do we ship any images without selinux enabled these days? Is there ever a case when you would want --sm-* and /not/ --selinux-relabel ? (In reply to Andrew Beekhof from comment #2) > Would it make sense to imply --selinux-relabel when --sm-* is in use? > Is there ever a case when you would want --sm-* and /not/ --selinux-relabel ? There are few data points: a) determining whether SELinux is actually used is not easy, there are different places to check (/etc/selinux/config, bootloader configuration, firstboot/init scripts enabling/disabling it, etc) b) using --sm-* cannot imply you need SELinux (see also (a)) c) strictly speaking, you don't need to relabel at each virt-customize/virt-sysprep invocation, but only during the last one before actually using the guest; e.g.: $ virt-customize -a IMG --install foo etc.. [other stuff...] $ virt-customize -a IMG --edit /file etc.. [more stuff...] $ virt-customize -a IMG --selinux-relabel etc.. [boot the guest] Closing as it isn't a bug, but a lack of appropriate SELinux option on the user side/ |