saltstack / saltstack/salt

[BUG] selinux.fcontext_policy_present fails the first time: selinux module could not be loaded

Open
#65,718 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

bug needs-triage
Dominant language
Python
Stars
15.7k
Forks
5.6k
Avg merge
2d 44m
Merged PRs (30d)
80

Description

Description
The first time state.apply is called, the state fails. The second time works as expected.

     Comment: State 'selinux.fcontext_policy_present' was not found in SLS 'files.mystate'
              Reason: 'selinux' __virtual__ returned False: selinux module could not be loaded

Setup

/custom/scripts_selinux:
  selinux.fcontext_policy_present:
    - name: /custom/scripts(/.*)?
    - filetype: a
    - sel_type: bin_t

Please be as specific as possible and give set-up details.

  • [X ] VM running on a cloud service, please be explicit and add details

AWS, called from user-data in Launch Template of AlmaLinux 9 x86_64 AMI, during initial boot.

Steps to Reproduce the behavior
Launch Template calls salt-call state.apply on initial boot and fails.

2023-12-17 02:49:55,409 [salt.state       :323 ][ERROR   ][11453] State 'selinux.fcontext_policy_present' was not found in SLS 'files.mystate'
Reason: 'selinux' __virtual__ returned False: selinux module could not be loaded

Expected behavior
I expected the state to be applied the first time salt-call state.apply was executed.

Screenshots
N/A

Versions Report

Minion
Salt Version:
          Salt: 3006.5
 
Python Version:
        Python: 3.10.13 (main, Nov 15 2023, 04:34:27) [GCC 11.2.0]
 
Dependency Versions:
          cffi: 1.14.6
      cherrypy: 18.6.1
      dateutil: 2.8.1
     docker-py: Not Installed
         gitdb: Not Installed
     gitpython: Not Installed
        Jinja2: 3.1.2
       libgit2: Not Installed
  looseversion: 1.0.2
      M2Crypto: Not Installed
          Mako: Not Installed
       msgpack: 1.0.2
  msgpack-pure: Not Installed
  mysql-python: Not Installed
     packaging: 22.0
     pycparser: 2.21
      pycrypto: Not Installed
  pycryptodome: 3.9.8
        pygit2: Not Installed
  python-gnupg: 0.4.8
        PyYAML: 6.0.1
         PyZMQ: 23.2.0
        relenv: 0.14.2
         smmap: Not Installed
       timelib: 0.2.4
       Tornado: 4.5.3
           ZMQ: 4.3.4
 
System Versions:
          dist: almalinux 9.3 Shamrock Pampas Cat
        locale: utf-8
       machine: x86_64
       release: 5.14.0-362.8.1.el9_3.x86_64
        system: Linux
       version: AlmaLinux 9.3 Shamrock Pampas Cat
Master
Salt Version:
          Salt: 3006.5
 
Python Version:
        Python: 3.10.13 (main, Nov 15 2023, 04:34:27) [GCC 11.2.0]
 
Dependency Versions:
          cffi: 1.14.6
      cherrypy: unknown
      dateutil: 2.8.1
     docker-py: Not Installed
         gitdb: Not Installed
     gitpython: Not Installed
        Jinja2: 3.1.2
       libgit2: Not Installed
  looseversion: 1.0.2
      M2Crypto: Not Installed
          Mako: Not Installed
       msgpack: 1.0.2
  msgpack-pure: Not Installed
  mysql-python: Not Installed
     packaging: 22.0
     pycparser: 2.21
      pycrypto: Not Installed
  pycryptodome: 3.9.8
        pygit2: Not Installed
  python-gnupg: 0.4.8
        PyYAML: 6.0.1
         PyZMQ: 23.2.0
        relenv: 0.14.2
         smmap: Not Installed
       timelib: 0.2.4
       Tornado: 4.5.3
           ZMQ: 4.3.4
 
System Versions:
          dist: centos 7.9.2009 Core
        locale: utf-8
       machine: x86_64
       release: 3.10.0-1160.105.1.el7.x86_64
        system: Linux
       version: CentOS Linux 7.9.2009 Core

Additional context
salt-call state.apply is called from user-data (fails), then manually in SSH (succeeds)

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Reproduce the initial-boot failure on the reported AWS AlmaLinux 9 setup by running salt-call state.apply from user-data, then compare it with the successful second invocation over SSH. Trace why the selinux module cannot load on the first run; done means selinux.fcontext_policy_present applies successfully on the first invocation.

Written by the indexing model from the issue text.

Assessment

Tech stack
linux, python
Domain
devops, infrastructure, operating-systems
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.