summaryrefslogtreecommitdiffstats
path: root/recipes-security/selinux/selinux-python/fix-sepolicy-install-path.patch
diff options
context:
space:
mode:
authorYi Zhao <yi.zhao@windriver.com>2019-09-09 10:03:49 +0800
committerJoe MacDonald <joe_macdonald@mentor.com>2019-09-09 09:56:25 -0400
commit10d4a50fc5b4d6da9dc74247ad5ab5ca0eda68bb (patch)
treed6ccfa1ec820edd99c0dcb0a6ebf9f7f63b76ff5 /recipes-security/selinux/selinux-python/fix-sepolicy-install-path.patch
parent0c9ee0bcb7548ef1e493367b78c49c1b2691c613 (diff)
downloadmeta-selinux-10d4a50fc5b4d6da9dc74247ad5ab5ca0eda68bb.tar.gz
selinux-autorelabel: disable enforcing mode before relabel
The commit b0d31db104d9a4e94bc1409c2ffcc1d82f4a780f introduced an issue when first boot with bootparams="selinux=1 enforcing=1". At first boot, all files are unlabeled including /sbin/setfiles. The relabel operations are not permitted under enforcing mode. So we need to disable enforcing mode before relabel. Signed-off-by: Yi Zhao <yi.zhao@windriver.com> Signed-off-by: Joe MacDonald <joe_macdonald@mentor.com>
Diffstat (limited to 'recipes-security/selinux/selinux-python/fix-sepolicy-install-path.patch')
0 files changed, 0 insertions, 0 deletions