Bug 1406860
| Summary: | restorecon location in /usr/libexec/iptables/iptables.init in assumed incorrectly | |||
|---|---|---|---|---|
| Product: | Red Hat Enterprise Linux 7 | Reporter: | Andrew Tumelty <andrew.tumelty> | |
| Component: | iptables | Assignee: | Phil Sutter <psutter> | |
| Status: | CLOSED ERRATA | QA Contact: | Tomas Dolezal <todoleza> | |
| Severity: | medium | Docs Contact: | ||
| Priority: | medium | |||
| Version: | 7.3 | CC: | aloughla, iptables-maint-list, jscotka, oakwhiz, psutter, redhat-bugzilla, todoleza, twoerner | |
| Target Milestone: | rc | |||
| Target Release: | --- | |||
| Hardware: | Unspecified | |||
| OS: | Unspecified | |||
| Whiteboard: | ||||
| Fixed In Version: | iptables-1.4.21-22.el7 | Doc Type: | If docs needed, set a value | |
| Doc Text: | Story Points: | --- | ||
| Clone Of: | 1246380 | |||
| : | 1489118 (view as bug list) | Environment: | ||
| Last Closed: | 2018-04-10 11:28:02 UTC | Type: | Bug | |
| Regression: | --- | Mount Type: | --- | |
| Documentation: | --- | CRM: | ||
| Verified Versions: | Category: | --- | ||
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | ||
| Cloudforms Team: | --- | Target Upstream Version: | ||
| Embargoed: | ||||
| Bug Depends On: | ||||
| Bug Blocks: | 1472751, 1489118 | |||
|
Description
Andrew Tumelty
2016-12-21 16:45:46 UTC
OK, so my proposed solution is to use which:
RESTORECON=$(which restorecon)
This works fine, but only after adjusting selinux policies. After loading the following module into the kernel, everything works fine:
module iptables.init_restorecon 1.0;
require {
type setfiles_exec_t;
type iptables_t;
class file { execute getattr };
}
#============= iptables_t ==============
allow iptables_t setfiles_exec_t:file { execute getattr };
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHEA-2018:0715 |