Description of problem: It seems that selinux-policy allows /var/vdsm(/.*)? files to have two different SELinux contexts. I believe that one of the contexts should be removed. Version-Release number of selected component (if applicable): selinux-policy-targeted-2.4.6-252.el5 selinux-policy-2.4.6-252.el5 yum-3.2.22-20.el5 How reproducible: always Steps to Reproduce: 1. yum -y install <package> 2. look at the end of /var/log/messages # semanage fcontext -l | grep vdsm /var/vdsm(/.*)? all files system_u:object_r:qemu_var_run_t:s0 /var/vdsm(/.*)? all files system_u:object_r:virt_var_lib_t:s0 Actual results: Jul 17 03:16:21 hp-rx1620-01 : /etc/selinux/targeted/contexts/files/file_contexts: Multiple different specifications for /var/vdsm(/.*)? (system_u:object_r:virt_var_lib_t:s0 and system_u:object_r:qemu_var_run_t:s0). Jul 17 03:16:21 hp-rx1620-01 : /etc/selinux/targeted/contexts/files/file_contexts: Multiple different specifications for /var/vdsm(/.*)? (system_u:object_r:virt_var_lib_t:s0 and system_u:object_r:qemu_var_run_t:s0). Jul 17 03:16:44 hp-rx1620-01 yum: Installed: selinux-policy-devel-2.4.6-252.el5.noarch Expected results: Jul 17 03:16:44 hp-rx1620-01 yum: Installed: selinux-policy-devel-2.4.6-252.el5.noarch Additional info: reproducible on all architectures
Fixed in selinux-policy-2.4.6-253.el5.src.rpm
Things seems lots happier on my system with 2.4.6-253.el5. I received 12 of the messages between 06:51 and 07:45, upgraded to the new packages and haven't seen another message to this point (currently 09:43.) Holding off marking as verified until some additional test results come in and the package itself is included in a build.
An advisory has been issued which should help the problem described in this bug report. This report is therefore being closed with a resolution of ERRATA. For more information on therefore solution and/or where to find the updated files, please follow the link below. You may reopen this bug report if the solution does not work for you. http://rhn.redhat.com/errata/RHBA-2009-1242.html