diff options
| author | Dmitry Vyukov <dvyukov@google.com> | 2018-09-05 12:50:53 +0200 |
|---|---|---|
| committer | Dmitry Vyukov <dvyukov@google.com> | 2018-09-05 12:50:53 +0200 |
| commit | 196410e4f5665d4d2bf6c818d06f1c8d03cfa8cc (patch) | |
| tree | 265ed8521703c1f2faa86db345cb028dd53750e4 /pkg/build | |
| parent | 49312e6d5ef379cce29c1bb583008ac3b163b1ff (diff) | |
dashboard/config: re-enable selinux
Upstream "selinux: fix mounting of cgroup2 under older policies"
commit fixes mounting of cgroup2 under wheezy selinux policy.
So don't disable selinux on start.
Create separate cmdline arguments that enable selinux and apparmor.
Diffstat (limited to 'pkg/build')
| -rw-r--r-- | pkg/build/linux_generated.go | 1 |
1 files changed, 0 insertions, 1 deletions
diff --git a/pkg/build/linux_generated.go b/pkg/build/linux_generated.go index 11a00bba4..14df94954 100644 --- a/pkg/build/linux_generated.go +++ b/pkg/build/linux_generated.go @@ -67,7 +67,6 @@ for i in {0..31}; do echo "KERNEL==\"binder$i\", NAME=\"binder$i\", MODE=\"0666\"" | \ sudo tee -a disk.mnt/etc/udev/50-binder.rules done -echo 'SELINUX=disabled' | sudo tee disk.mnt/etc/selinux/config echo "kernel.printk = 7 4 1 3" | sudo tee -a disk.mnt/etc/sysctl.conf echo "debug.exception-trace = 0" | sudo tee -a disk.mnt/etc/sysctl.conf |
