Re: [yocto] [meta-selinux][PATCH] selinux-autorelabel: disable enforcing mode before relabel

2019-09-05 Thread Yi Zhao
On 9/5/19 7:57 PM, Joe MacDonald wrote: [[meta-selinux][PATCH] selinux-autorelabel: disable enforcing mode before relabel] On 19.09.05 (Thu 16:57) Yi Zhao wrote: The commit b0d31db104d9a4e94bc1409c2ffcc1d82f4a780f introduced an issue when first boot with bootparams="selinux=1 enforcing=1". A

Re: [yocto] [meta-selinux][PATCH] selinux-init: use systemd (re)labelling

2019-09-05 Thread Joe MacDonald
[Re: [yocto] [meta-selinux][PATCH] selinux-init: use systemd (re)labelling] On 19.09.05 (Thu 13:55) Mark Asselstine wrote: > On Friday, August 23, 2019 2:19:53 P.M. EDT Mark Asselstine wrote: > > Boot loops were being seen when booting with selinux enabled, when the > > init system in use is syst

Re: [yocto] [meta-selinux][PATCH] selinux-init: use systemd (re)labelling

2019-09-05 Thread Mark Asselstine
On Friday, August 23, 2019 2:19:53 P.M. EDT Mark Asselstine wrote: > Boot loops were being seen when booting with selinux enabled, when the > init system in use is systemd. Once logs were retrieved from the > failing system the error was found to be > > selinux-init.sh[284]: /sbin/restorecon: Coul

Re: [yocto] in-tree module dependency

2019-09-05 Thread Matteo Facchinetti
Il giorno mer 4 set 2019 alle ore 18:41 Matteo Facchinetti < matteo.facchine...@sirius-es.it> ha scritto: > > > Il giorno mer 4 set 2019 alle ore 16:23 Khem Raj ha > scritto: > >> >> >> On Wed, Sep 4, 2019 at 7:10 AM Matteo Facchinetti < >> matteo.facchine...@sirius-es.it> wrote: >> >>> >>> >>> I

Re: [yocto] [meta-selinux][PATCH] selinux-autorelabel: disable enforcing mode before relabel

2019-09-05 Thread Joe MacDonald
[[meta-selinux][PATCH] selinux-autorelabel: disable enforcing mode before relabel] On 19.09.05 (Thu 16:57) Yi Zhao wrote: > The commit b0d31db104d9a4e94bc1409c2ffcc1d82f4a780f introduced an issue > when first boot with bootparams="selinux=1 enforcing=1". At first boot, > all files are unlabeled i

[yocto] [meta-selinux][PATCH] selinux-autorelabel: disable enforcing mode before relabel

2019-09-05 Thread Yi Zhao
The commit b0d31db104d9a4e94bc1409c2ffcc1d82f4a780f introduced an issue when first boot with bootparams="selinux=1 enforcing=1". At first boot, all files are unlabeled including /sbin/fixfiles. The relabel operation is not permitted under enforcing mode. Set /sys/fs/selinux/enforce to 0 to ensure t