Re: Setting context in early boot
Frederick Grose via selinux <[email protected]> Fri, 30 Jan 2026 10:46:16 -0500
| Newsgroups | gmane.linux.redhat.fedora.selinux |
|---|---|
| Message-ID | <CAEcBt+XYQuBP3WmXAYmGoyKaY8YBoBMaBiRW2gEEAabxLiBb4g@mail.gmail.com> |
--===============2660912425873037193==
Content-Type: multipart/alternative; boundary="000000000000d6dabb06499ce11a"
--000000000000d6dabb06499ce11a
Content-Type: text/plain; charset="UTF-8"
Some additional experimental findings:
One may consider labeling these overlay directories during the initramfs
phase of boot to avoid the post switch-root service. This would involve
using load-policy -i and setting the SELinux mode to Permissive, as the
current Fedora policy is not suitable for the initramfs phase of operation.
However, this approach would still require a post switch-root directive to
`setenforce` to the `Enforcing` default. This is because the kernel only
interprets the `enforcing={0|1}` parameter or the `/etc/selinux/config
SELINUX={permissive|enforcing}` setting *once* and very early during each
boot.
Consequently, even if `setenforce Permissive` or `echo 0 >
/sys/fs/selinux/enforcing` is issued during the initramfs phase, certain
critical components will still suffer denials that lead to failed boots.
Permissive mode must be set from the very beginning to enable successful
initramfs labeling of the directories within the context of an unsuitable
policy.
--000000000000d6dabb06499ce11a
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
<div dir=3D"ltr"><div class=3D"gmail_default" style=3D"font-family:trebuche=
t ms,sans-serif;font-size:small;color:#073763"><div>Some additional experim=
ental findings:</div><div><span class=3D"gmail_default"></span>One may cons=
ider labeling these overlay directories during the initramfs phase of boot =
to avoid the post switch-root service. This would involve using load-policy=
-i and setting the SELinux mode to Permissive, as the current Fedora polic=
y is not suitable for the initramfs phase of operation.</div><div><br></div=
><div>However, this approach would still require a post switch-root directi=
ve to `setenforce` to the `Enforcing` default. This is because the kernel o=
nly interprets the `enforcing=3D{0|1}` parameter or the `/etc/selinux/confi=
g SELINUX=3D{permissive|enforcing}` setting <i><b>once</b></i> and very ear=
ly during each boot.</div><div><br></div><div>Consequently, even if `setenf=
orce Permissive` or `echo 0 > /sys/fs/selinux/enforcing` is issued durin=
g the initramfs phase, certain critical components will still suffer denial=
s that lead to failed boots. Permissive mode must be set from the very begi=
nning to enable successful initramfs labeling of the directories within the=
context of an unsuitable policy.</div><div></div></div></div>
--000000000000d6dabb06499ce11a--
--===============2660912425873037193==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline
LS0gCl9fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fCnNlbGlu
dXggbWFpbGluZyBsaXN0IC0tIHNlbGludXhAbGlzdHMuZmVkb3JhcHJvamVjdC5vcmcKVG8gdW5z
dWJzY3JpYmUgc2VuZCBhbiBlbWFpbCB0byBzZWxpbnV4LWxlYXZlQGxpc3RzLmZlZG9yYXByb2pl
Y3Qub3JnCkZlZG9yYSBDb2RlIG9mIENvbmR1Y3Q6IGh0dHBzOi8vZG9jcy5mZWRvcmFwcm9qZWN0
Lm9yZy9lbi1VUy9wcm9qZWN0L2NvZGUtb2YtY29uZHVjdC8KTGlzdCBHdWlkZWxpbmVzOiBodHRw
czovL2ZlZG9yYXByb2plY3Qub3JnL3dpa2kvTWFpbGluZ19saXN0X2d1aWRlbGluZXMKTGlzdCBB
cmNoaXZlczogaHR0cHM6Ly9saXN0cy5mZWRvcmFwcm9qZWN0Lm9yZy9hcmNoaXZlcy9saXN0L3Nl
bGludXhAbGlzdHMuZmVkb3JhcHJvamVjdC5vcmcKRG8gbm90IHJlcGx5IHRvIHNwYW0sIHJlcG9y
dCBpdDogaHR0cHM6Ly9mb3JnZS5mZWRvcmFwcm9qZWN0Lm9yZy9pbmZyYS90aWNrZXRzL2lzc3Vl
cy9uZXcK
--===============2660912425873037193==--