Bug 1237065 - [ISO] warning: %post(samba-vfs-glusterfs-0:4.1.17-7.el6rhs.x86_64) scriptlet failed, exit status 255 seen in install.log
Summary: [ISO] warning: %post(samba-vfs-glusterfs-0:4.1.17-7.el6rhs.x86_64) scriptlet ...
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Red Hat Gluster Storage
Classification: Red Hat Storage
Component: samba
Version: rhgs-3.1
Hardware: Unspecified
OS: Unspecified
urgent
urgent
Target Milestone: ---
: RHGS 3.1.0
Assignee: rhs-smb@redhat.com
QA Contact: Prasanth
URL:
Whiteboard:
Depends On:
Blocks: 1202842
TreeView+ depends on / blocked
 
Reported: 2015-06-30 10:08 UTC by Prasanth
Modified: 2018-07-30 11:54 UTC (History)
16 users (show)

Fixed In Version: glusterfs-3.7.1-10
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2015-07-29 05:08:39 UTC
Embargoed:


Attachments (Terms of Use)
install.log_RHGSS-3.1-20150629.n.0-RHS-x86_64-DVD1.iso (29.88 KB, text/plain)
2015-06-30 10:08 UTC, Prasanth
no flags Details


Links
System ID Private Priority Status Summary Last Updated
Red Hat Bugzilla 1240228 0 urgent CLOSED [SELinux] samba-vfs-glusterfs should have a dependency on selinux packages (RHEL-6.7) 2021-02-22 00:41:40 UTC
Red Hat Product Errata RHSA-2015:1495 0 normal SHIPPED_LIVE Important: Red Hat Gluster Storage 3.1 update 2015-07-29 08:26:26 UTC

Internal Links: 1240228

Description Prasanth 2015-06-30 10:08:28 UTC
Created attachment 1044637 [details]
install.log_RHGSS-3.1-20150629.n.0-RHS-x86_64-DVD1.iso

Description of problem:

Following warning message is seen after an ISO install of RHGS-3.1:

#####
Installing samba-vfs-glusterfs-4.1.17-7.el6rhs.x86_64
Cannot set persistent booleans without managed policy.
warning: %post(samba-vfs-glusterfs-0:4.1.17-7.el6rhs.x86_64) scriptlet failed, exit status 255
Installing samba-common-4.1.17-7.el6rhs.x86_64
Installing samba-4.1.17-7.el6rhs.x86_64
Installing libsmbclient-4.1.17-7.el6rhs.x86_64
Installing samba-winbind-modules-4.1.17-7.el6rhs.x86_64
Installing samba-winbind-4.1.17-7.el6rhs.x86_64
######

Version-Release number of selected component (if applicable):
-----------
RHGSS-3.1-20150629.n.0-RHS-x86_64-DVD1.iso

[root@ ~]# cat /etc/redhat-storage-release 
Red Hat Gluster Storage Server 3.1

[root@ ~]# cat /etc/redhat-release 
Red Hat Enterprise Linux Server release 6.7 (Santiago)

[root@ ~]# rpm -qa selinux\*
selinux-policy-3.7.19-279.el6.noarch
selinux-policy-targeted-3.7.19-279.el6.noarch
-----------

How reproducible: 100%


Steps to Reproduce:
1. Install RHGS-3.1 using the latest available ISO - RHGSS-3.1-20150629.n.0-RHS-x86_64-DVD1.iso
2. Post installation and reboot, check the install.log
3.

Actual results: Warning messages are seen in install.log after the ISO installation. 

Expected results: No warning messages should be seen after an ISO installation


Additional info:

Comment 1 Prasanth 2015-06-30 10:12:10 UTC
More details:

#######
[root@sherrif rpm]# sestatus 
SELinux status:                 enabled
SELinuxfs mount:                /selinux
Current mode:                   enforcing
Mode from config file:          enforcing
Policy version:                 24
Policy from config file:        targeted

[root@ ~]# rpm -qa |grep policycoreutils
policycoreutils-2.0.83-24.el6.x86_64
policycoreutils-python-2.0.83-24.el6.x86_64

[root@ ~]# getsebool -a | grep samba
bacula_use_samba --> off
samba_create_home_dirs --> off
samba_domain_controller --> off
samba_enable_home_dirs --> off
samba_export_all_ro --> off
samba_export_all_rw --> off
samba_load_libgfapi --> off
samba_portmapper --> off
samba_run_unconfined --> off
samba_share_fusefs --> off
samba_share_nfs --> off
sanlock_use_samba --> off
use_samba_home_dirs --> off
virt_use_samba --> off
 
[root@ ~]# rpm -q --scripts samba-vfs-glusterfs
postinstall scriptlet (using /bin/sh):
if getsebool samba_load_libgfapi &>/dev/null; then
        setsebool -P samba_load_libgfapi 1
fi
postuninstall scriptlet (using /bin/sh):
if getsebool samba_load_libgfapi &>/dev/null; then
        setsebool -P samba_load_libgfapi 0
fi
#########

Comment 2 Prasanth 2015-06-30 10:37:07 UTC
On further debugging, I strongly believe that this warning is seen because "samba-vfs-glusterfs" postinstall scriptlet is trying to set some required SELinux boo-leans even before "selinux-policy-*" packages are installed in the system. Hence, it fails to set and throws out a warning message.

Apart from Samba, some other packages (nagios, ctdb, etc) also might try to set similar booleans during their rpm post installation. So a solution that I can think of to avoid this kind of situation is to re-arrange the packages during the package installation so that selinux-policy* packages are installed first before any gluster related packages.

Comment 3 Prasanth 2015-06-30 12:57:07 UTC
Sreenath, is it possible to fix it as mentioned in Comment 2? If you also have some other better options to fix this, please suggest that as well.

Comment 4 Ramesh N 2015-07-01 05:23:02 UTC
This is also applicable for nagios plugins. package 'gluster-nagios-addons' should be installed after all the selinux policy rpms.

Comment 5 Lubos Kocman 2015-07-02 12:18:08 UTC
Hello,

why don't you simply set requires in the samba-vfs-glusterfs for require selinux-policy. Please move this to samba-vfs-glusterfs component.

This won't be done by releng.

Thanks for understanding

Lubos
rel-eng

Comment 6 Niels de Vos 2015-07-02 13:42:58 UTC
This seems to be exactly the same as what I posted in a similar bug against the glusterfs component. Each package that modifies selinux booleans in the rpm scriptlets should have is own dependency on selinux-policy(-targeted). More details in this comment:

  https://bugzilla.redhat.com/show_bug.cgi?id=1238055#c6

Comment 7 Milos Malik 2015-07-03 18:29:22 UTC
I might be wrong because I'm not a developer, but I would like to help you.

Your package should require:
 + policycoreutils package because it brings the setsebool command
 + libselinux-utils package because it brings the getsebool command
 + selinux-policy-targeted or selinux-policy-base (virtual package) because it brings the policy where booleans are defined and stored

There are few packages which change SELinux booleans either by setsebool or semanage:
# rpm -qa --scripts | grep -e setsebool -e semanage

Comment 14 Prasanth 2015-07-17 07:26:34 UTC
Verified as fixed in the latest ISO RHGSS-3.1-20150713.n.0-RHS-x86_64-DVD1.iso

No error/warning messages are seen in the install.log after selecting ALL the available optional packages including Samba.

##############
[root@hamm ~]# cat /etc/redhat-storage-release 
Red Hat Gluster Storage Server 3.1

[root@hamm ~]# cat /etc/redhat-release 
Red Hat Enterprise Linux Server release 6.7 (Santiago)

[root@hamm ~]# rpm -qa selinux\*
selinux-policy-targeted-3.7.19-279.el6.noarch
selinux-policy-3.7.19-279.el6.noarch

[root@hamm ~]# sestatus 
SELinux status:                 enabled
SELinuxfs mount:                /selinux
Current mode:                   enforcing
Mode from config file:          enforcing
Policy version:                 24
Policy from config file:        targeted

[root@hamm ~]# getsebool -a | grep samba
bacula_use_samba --> off
samba_create_home_dirs --> off
samba_domain_controller --> off
samba_enable_home_dirs --> off
samba_export_all_ro --> off
samba_export_all_rw --> off
samba_load_libgfapi --> on
samba_portmapper --> off
samba_run_unconfined --> off
samba_share_fusefs --> off
samba_share_nfs --> off
sanlock_use_samba --> off
use_samba_home_dirs --> off
virt_use_samba --> off

[root@hamm ~]# rpm -q --scripts samba-vfs-glusterfs
postuninstall scriptlet (using /bin/sh):
if type getsebool &>/dev/null && getsebool samba_load_libgfapi &>/dev/null; then
        setsebool -P samba_load_libgfapi 0 &>/dev/null || true
fi
posttrans scriptlet (using /bin/sh):
if type getsebool &>/dev/null && getsebool samba_load_libgfapi &>/dev/null; then
        setsebool -P samba_load_libgfapi 1 &>/dev/null || true
fi
##############

Comment 15 errata-xmlrpc 2015-07-29 05:08:39 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://rhn.redhat.com/errata/RHSA-2015-1495.html


Note You need to log in before you can comment on or make changes to this bug.