Red Hat Bugzilla – Bug 988855
semanage fails in %post when installing a plugin
Last modified: 2013-11-28 08:49:13 EST
Description of problem:
ovirt-node-plugin-vdsm sets a number of selinux rules (virt_use_nfs, virt_use_sanlock, etc). When running edit-node, these are not getting set correctly.
Version-Release number of selected component (if applicable):
Steps to Reproduce:
1.take base image and inject ovirt-node-plugin-vdsm
2.boot the image
3.check virt_use_nfs virt_use_sanlock sanlock_use_nfs booleans
all are off
all are on
Created attachment 783361 [details]
These are all on by default since we turn them on in ovirt-node-selinux.
It fails in edit-node since we disable selinux and setsebool won't run.
A workaround is:
Write the boolean into /etc/selinux/targeted/modules/active/booleans.local
I checked with selinux folks and that should work fine but filed a bz to add an offline option to make this easier.
This has been addressed with th selinux specific sub-package.