summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorZuul <zuul@review.openstack.org>2018-07-25 02:41:31 +0000
committerGerrit Code Review <review@openstack.org>2018-07-25 02:41:31 +0000
commit2f5ec4d79ad3cf6e6a09877d98d76feb32669f6a (patch)
treec5044de8363d46141d0b2d49f235d23c9d9d4bbd
parent182b59aae2dd6de99fe2608e6353b5208fea055b (diff)
parentcef0960c6dccf9e12be5166586e17a49348963b0 (diff)
Merge "Explicitly set selinux seltype for rules link"HEADmaster
-rw-r--r--manifests/init.pp8
1 files changed, 7 insertions, 1 deletions
diff --git a/manifests/init.pp b/manifests/init.pp
index 9690e67..e264384 100644
--- a/manifests/init.pp
+++ b/manifests/init.pp
@@ -125,11 +125,17 @@ class iptables(
125 notify => $notify_iptables, 125 notify => $notify_iptables,
126 } 126 }
127 127
128 if $::osfamily == 'redhat' {
129 $seltype = 'etc_t'
130 } else {
131 $seltype = undef
132 }
133
128 file { $::iptables::params::ipv4_rules: 134 file { $::iptables::params::ipv4_rules:
129 ensure => link, 135 ensure => link,
130 owner => 'root', 136 owner => 'root',
131 group => 'root', 137 group => 'root',
132 mode => '0640', 138 seltype => $seltype,
133 target => "${::iptables::params::rules_dir}/rules", 139 target => "${::iptables::params::rules_dir}/rules",
134 require => File["${::iptables::params::rules_dir}/rules"], 140 require => File["${::iptables::params::rules_dir}/rules"],
135 notify => $notify_iptables, 141 notify => $notify_iptables,