selinux April 2007 archive
Main Archive Page > Month Archives  > selinux archives
selinux: Re: can not boot with strict policy

Re: can not boot with strict policy

From: James Morris <jmorris_at_nospam>
Date: Mon Apr 23 2007 - 17:42:26 GMT
To: Stephen Smalley <sds@tycho.nsa.gov>


On Mon, 23 Apr 2007, Stephen Smalley wrote:

> /lib/libsepol.so.1 should be labeled with shlib_t, not lib_t. Under
> targeted policy, they are aliases for one another. Under strict, they
> are separate types.
>
> Boot with "enforcing=0 single" to come up permissive into single-user
> mode, then run /sbin/fixfiles relabel -F to forcible relabel everything,
> then reboot.

I wonder if we could automate this, so that the autorelabel is also run on boot if you switch between different types of policy. -- James Morris <jmorris@namei.org> -- This message was distributed to subscribers of the selinux mailing list. If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with the words "unsubscribe selinux" without quotes as the message.