Aborting, target uses selinux but Python bindings (libselinux-Python) aren't installed

Viewed 36858

I am trying to run Ansible playbook command and getting an error as below.

fatal: [localhost]: FAILED! => {"changed": false, "msg": "Aborting, target
uses selinux but python bindings (libselinux-python) aren't installed!"}

When I checked for libselinux-python, it showsit is already available.

[root@host all]# sudo yum list installed |grep libselinux-python
libselinux-python3.x86_64            2.5-15.el7              @rhel-7-server-rpms

Please provide your input if anyone has faced and resolved this.

Below are my Python and Ansible versions installed on server.

[root@ xxx bin]# python --version
Python 3.6.5

[root@xxx bin]# which python
/root/.pyenv/shims/python

[root@xxx bin]# ansible --version
ansible 2.9.9
  config file = /etc/ansible/ansible.cfg
  configured module search path = ['/root/.ansible/plugins/modules', '/usr/share/ansible/plugins/modules']
  ansible python module location = /root/.pyenv/versions/3.6.5/lib/python3.6/site-packages/ansible
  executable location = /root/.pyenv/versions/3.6.5/bin/ansible
  python version = 3.6.5 (default, Jun 18 2020, 17:32:20) [GCC 4.8.5 20150623 (Red Hat 4.8.5-39)]

[root@ xxx bin]#
11 Answers

I've just lost a whole day to this and I managed to solve it running sudo yum install libselinux-python3

Or alternatively one can install selinux in your current Python venv: pip install selinux.

Below is what I've done to get around this problem.

For Python3 on RHEL, you can install SE Linux with

sudo yum install -y libselinux-python3

Then create a virtual environment to isolate your dependencies and give it access to the system site-packages directory:

python3 -m venv .venv --system-site-packages

If you don't use --system-site-packages, your virtual environment won't be able to access selinux since its placed in /usr/lib64/python3.6/site-packages.

Then activate this virtual environment and run your ansible playbook commands:

source .venv/bin/activate
ansible-playbook -i my_inventory my_playbook.yml -vvv
deactivate

Its usually bad practice to modify PYTHONPATH as shown in one of the below answers, even though it works.

These answers may be a little old now, so I'll say that while using Rocky Linux 8.4 (RHEL clone) the package names in dnf have changed from the Ansible docs. Ansible says it should be policycoreutils-python but it's actually python3-policycoreutils and python3-libselinux.

So you can install it with:

dnf install python3-policycoreutils python3-libselinux

selinux package installed under /usr/lib64/python3.6/site-packages was not accessible by python ansible. After configuring PYTHONPATH in .bash_profile. issue got resolved.

export PYTHONPATH=/usr/lib64/python3.6/site-packages

Leaving this answer here as it may help someone.

In my case I was receiving the dreaded "Aborting, target uses selinux but python bindings (libselinux-python) aren't installed!" while running my Ansible playbook even though I had libselinux-python package installed on my target host. Even though the ansible python interpreter was using python2.7 on the target, I decided to install libselinux-python3 as well, to no avail.

After hours of debugging, it turns out the issue stemmed from the shell environment of the user on the target host under which the ansible tasks were running.

What was happening is that this playbook created a user on the target host, created a python virtual environment for this user and set the PYTHON_PATH of this user to his python virtual environment. And since the ansible interpreter_python was set to python, when the template tasks were running as this user it used his custom python environment which of course does not inherit the libselinux-python from the OS and the error message was generated.

I removed the custom PYTHON_PATH=/path/to/env/python from this user's ~/.bash_profile and lo and behold the playbook works!

TL;DR: Check that the user under which the ansible tasks that fails runs on the target host does not have a custom python environment set in his environment variables.

I struggled with this for awhile, even after reading the answers here. My confusion was that while I did need to install libselinux-python3 I needed it on the host machines. I kept installing it on the ansible server and not understanding why that didn't work, because I'm an idiot ;).

To ensure that the library was installed on every host I added an extra line to install libselinux-python3 before I run any of the modules dependent on it.

- name: install python selinux library required by future ansible modules
  become: true
  yum:
    name: libselinux-python3
    state: present
    update_cache: true

this fixed my later commands that were previously failing.

Installing libselinux-python3 on both node and host didn't work for me until I install pip install selinux on the host(the one which has ansible on it) did the trick for me.

Modify as you wish but this is what worked for me:

- name: Install pip
  vars:
      ansible_python_interpreter: /usr/bin/python
  yum:
    name: python-pip
    update_cache: yes
    state: present

- name: Install python modules
  pip:
    name: "{{ item.name }}"
    state: present
  environment:
    HTTP_PROXY: 'http://your-proxy.com:80'
    HTTPS_PROXY: 'http://your-proxy.com:80'
  with_items:
  - { name: selinux }

In my case, I had to just set SELINUX=disabled in /etc/selinux/config file.

We recently added some RHEL 8 hosts to our environment and I got a similar error message the first time I tried to run a playbook on one. I verified that python3-libselinux was installed on the target host. I finally tracked my issue down to the default transport method in our ansible.cfg file - someone had changed it to "paramiko". I set it back to "smart" and was able to run the play without any further errors.

Related