SELinux denials for Puppet/Passenger (passenger_t)
Issue
- Satellite 6 Capsule (integrated/external) issues SELinux denials for passenger_t or puppet_t domains when synchronizing, promoting or consuming Puppet Manifests.
/var/log/audit/audit.log:type=AVC msg=audit(1452072575.832:235842): avc: denied { getattr } for pid=21547 comm="systemd-logind" path="/dev/shm/MtStrmCommandResponseMessageQueue" dev="tmpfs" ino=23361 scontext=system_u:system_r:systemd_logind_t:s0 tcontext=system_u:object_r:initrc_state_t:s0 tclass=file
Environment
- Red Hat Satellite v 6
- Puppet Enterprise or Puppet that was not shipped with Satellite 6
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.