Re: lorax - selinux limitation

Vit Ry <[email protected]>
Newsgroups gmane.linux.redhat.anaconda.devel
Message-ID <[email protected]>
And, do you have  "dracut nfs module' installed inside?


 ---- On Wed, 16 Dec 2015 18:32:51 +0300 Dominique Martinet <[email protected]> wrote ---- 
 > Hi,
 > 
 > in el7, in /usr/lib/python2.7/site-packages/pylorax/__init__.py we have
 > this comment/code:
 > # is selinux disabled?
 > # With selinux in enforcing mode the rpcbind package required for
 > # dracut nfs module, which is in turn required by anaconda module,
 > # will not get installed, because it's preinstall scriptlet fails,
 > # resulting in an incomplete initial ramdisk image.
 > # The reason is that the scriptlet runs tools from the shadow-utils
 > # package in chroot, particularly groupadd and useradd to add the
 > # required rpc group and rpc user. This operation fails, because
 > # the selinux context on files in the chroot, that the shadow-utils
 > # tools need to access (/etc/group, /etc/passwd, /etc/shadow etc.),
 > # is wrong and selinux therefore disallows access to these files.
 > logger.info("checking the selinux mode")
 > if selinux.is_selinux_enabled() and selinux.security_getenforce():
 >     logger.critical("selinux must be disabled or in Permissive mode")
 >     sys.exit(1)
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.