Merge "Explicitly set selinux seltype for rules link"

This commit is contained in:
Zuul 2018-07-25 02:41:31 +00:00 committed by Gerrit Code Review
commit 2f5ec4d79a
1 changed files with 7 additions and 1 deletions

View File

@ -125,11 +125,17 @@ class iptables(
notify => $notify_iptables,
}
if $::osfamily == 'redhat' {
$seltype = 'etc_t'
} else {
$seltype = undef
}
file { $::iptables::params::ipv4_rules:
ensure => link,
owner => 'root',
group => 'root',
mode => '0640',
seltype => $seltype,
target => "${::iptables::params::rules_dir}/rules",
require => File["${::iptables::params::rules_dir}/rules"],
notify => $notify_iptables,