From: Harald Hoyer Date: Wed, 9 Sep 2009 15:06:21 +0000 (+0200) Subject: selinux-loadpolicy: do not mount /proc and /selinux X-Git-Tag: 002~58 X-Git-Url: http://git.ipfire.org/gitweb.cgi?a=commitdiff_plain;h=94eb3cf22255b17ab5bc79aaadb828ddb4ec94ac;p=thirdparty%2Fdracut.git selinux-loadpolicy: do not mount /proc and /selinux load_policy already does these things for us --- diff --git a/modules.d/99base/selinux-loadpolicy.sh b/modules.d/99base/selinux-loadpolicy.sh index 84b365770..eaaf3373c 100755 --- a/modules.d/99base/selinux-loadpolicy.sh +++ b/modules.d/99base/selinux-loadpolicy.sh @@ -4,19 +4,20 @@ if [ -x "$NEWROOT/usr/sbin/load_policy" -o -x "$NEWROOT/sbin/load_policy" ] && [ -e "$NEWROOT/etc/sysconfig/selinux" ]; then info "Loading SELinux policy" { - # load_policy does mount /proc and /selinux in libselinux,selinux_init_load_policy() + # load_policy does mount /proc and /selinux in libselinux,selinux_init_load_policy() + if [ -x "$NEWROOT/sbin/load_policy" ]; then + chroot "$NEWROOT" /sbin/load_policy -i + ret=$? + else + chroot "$NEWROOT" /usr/sbin/load_policy -i + ret=$? + fi + } 2>&1 | vinfo - if [ -x "$NEWROOT/sbin/load_policy" ]; then - chroot "$NEWROOT" /sbin/load_policy -i 2>&1 - else - chroot "$NEWROOT" /usr/sbin/load_policy -i 2>&1 - fi - - if [ $? -eq 3 ]; then + if [ $ret -eq 3 ]; then warn "Initial SELinux policy load failed and enforcing mode requested." warn "Not continuing" sleep 100d exit 1 fi - } | vinfo fi