)]}'
{"manifests/neutron.pp":[{"author":{"_account_id":14985,"name":"Alex Schultz","email":"aschultz@next-development.com","username":"mwhahaha"},"change_message_id":"f6f5beec0089f875b0932b7f9fa567e97a210cf9","unresolved":false,"context_lines":[{"line_number":43,"context_line":""},{"line_number":44,"context_line":"  if ($::operatingsystem \u003d\u003d \u0027CentOS\u0027) and (versioncmp($::operatingsystemmajrelease, \u00278\u0027) \u003d\u003d 0) {"},{"line_number":45,"context_line":"    # os_neutron_dac_override should be on to start privsep-helper"},{"line_number":46,"context_line":"    # See https://bugzilla.redhat.com/show_bug.cgi?id\u003d1850973"},{"line_number":47,"context_line":"    selboolean { \u0027os_neutron_dac_override\u0027:"},{"line_number":48,"context_line":"      persistent \u003d\u003e true,"},{"line_number":49,"context_line":"      value      \u003d\u003e on,"}],"source_content_type":"text/x-puppet","patch_set":1,"id":"9f560f44_e50f1d2d","line":46,"updated":"2020-08-28 15:48:08.000000000","message":"This should get fixed in openstack-selinux, do we have a patch over there for that?","commit_id":"0461077f2dcec9d5394650b23b60bc509444b01f"},{"author":{"_account_id":14985,"name":"Alex Schultz","email":"aschultz@next-development.com","username":"mwhahaha"},"change_message_id":"7c9db67517e61ce2bc555a59d91ed8279b2a39a7","unresolved":false,"context_lines":[{"line_number":43,"context_line":""},{"line_number":44,"context_line":"  if ($::operatingsystem \u003d\u003d \u0027CentOS\u0027) and (versioncmp($::operatingsystemmajrelease, \u00278\u0027) \u003d\u003d 0) {"},{"line_number":45,"context_line":"    # os_neutron_dac_override should be on to start privsep-helper"},{"line_number":46,"context_line":"    # See https://bugzilla.redhat.com/show_bug.cgi?id\u003d1850973"},{"line_number":47,"context_line":"    selboolean { \u0027os_neutron_dac_override\u0027:"},{"line_number":48,"context_line":"      persistent \u003d\u003e true,"},{"line_number":49,"context_line":"      value      \u003d\u003e on,"}],"source_content_type":"text/x-puppet","patch_set":1,"id":"9f560f44_e570bd76","line":46,"in_reply_to":"9f560f44_6534adad","updated":"2020-08-28 15:58:52.000000000","message":"Yea don\u0027t know how this affects our containerized version. It\u0027s fine we can do this, i just wondering what the long term fix is because this seems like a hack","commit_id":"0461077f2dcec9d5394650b23b60bc509444b01f"},{"author":{"_account_id":16137,"name":"Tobias Urdin","email":"tobias.urdin@binero.com","username":"tobasco"},"change_message_id":"81892273b854e0e7db777986349b108457fd45a3","unresolved":false,"context_lines":[{"line_number":43,"context_line":""},{"line_number":44,"context_line":"  if ($::operatingsystem \u003d\u003d \u0027CentOS\u0027) and (versioncmp($::operatingsystemmajrelease, \u00278\u0027) \u003d\u003d 0) {"},{"line_number":45,"context_line":"    # os_neutron_dac_override should be on to start privsep-helper"},{"line_number":46,"context_line":"    # See https://bugzilla.redhat.com/show_bug.cgi?id\u003d1850973"},{"line_number":47,"context_line":"    selboolean { \u0027os_neutron_dac_override\u0027:"},{"line_number":48,"context_line":"      persistent \u003d\u003e true,"},{"line_number":49,"context_line":"      value      \u003d\u003e on,"}],"source_content_type":"text/x-puppet","patch_set":1,"id":"9f560f44_6534adad","line":46,"in_reply_to":"9f560f44_e50f1d2d","updated":"2020-08-28 15:56:34.000000000","message":"It\u0027s fixed there, by adding a boolean, that\u0027s the fix. I think the core issue is in Neutron\u0027s usage of sudo/permissions in the first place. We wouldn\u0027t want to enable dac_override by default [1].\n\n[1] https://danwalsh.livejournal.com/79643.html","commit_id":"0461077f2dcec9d5394650b23b60bc509444b01f"}]}
