diff options
| author | Dmitry Vyukov <dvyukov@google.com> | 2018-09-05 12:50:53 +0200 |
|---|---|---|
| committer | Dmitry Vyukov <dvyukov@google.com> | 2018-09-05 12:50:53 +0200 |
| commit | 196410e4f5665d4d2bf6c818d06f1c8d03cfa8cc (patch) | |
| tree | 265ed8521703c1f2faa86db345cb028dd53750e4 /tools | |
| parent | 49312e6d5ef379cce29c1bb583008ac3b163b1ff (diff) | |
dashboard/config: re-enable selinux
Upstream "selinux: fix mounting of cgroup2 under older policies"
commit fixes mounting of cgroup2 under wheezy selinux policy.
So don't disable selinux on start.
Create separate cmdline arguments that enable selinux and apparmor.
Diffstat (limited to 'tools')
| -rwxr-xr-x | tools/create-gce-image.sh | 3 | ||||
| -rwxr-xr-x | tools/create-image.sh | 1 |
2 files changed, 0 insertions, 4 deletions
diff --git a/tools/create-gce-image.sh b/tools/create-gce-image.sh index 177c208ee..0db7fc065 100755 --- a/tools/create-gce-image.sh +++ b/tools/create-gce-image.sh @@ -108,9 +108,6 @@ for i in {0..31}; do echo "KERNEL==\"binder$i\", NAME=\"binder$i\", MODE=\"0666\"" | \ sudo tee -a disk.mnt/etc/udev/50-binder.rules done -# We disable selinux for now because the default policy on wheezy prevents -# mounting of cgroup2 (and stretch we don't know how to configure yet). -echo 'SELINUX=disabled' | sudo tee disk.mnt/etc/selinux/config # sysctls echo "kernel.printk = 7 4 1 3" | sudo tee -a disk.mnt/etc/sysctl.conf diff --git a/tools/create-image.sh b/tools/create-image.sh index a0ad610c8..91eb0a133 100755 --- a/tools/create-image.sh +++ b/tools/create-image.sh @@ -19,7 +19,6 @@ echo 'T0:23:respawn:/sbin/getty -L ttyS0 115200 vt100' | sudo tee -a $DIR/etc/in printf '\nauto eth0\niface eth0 inet dhcp\n' | sudo tee -a $DIR/etc/network/interfaces echo 'debugfs /sys/kernel/debug debugfs defaults 0 0' | sudo tee -a $DIR/etc/fstab echo 'binfmt_misc /proc/sys/fs/binfmt_misc binfmt_misc defaults 0 0' | sudo tee -a $DIR/etc/fstab -echo 'SELINUX=disabled' | sudo tee $DIR/etc/selinux/config echo "kernel.printk = 7 4 1 3" | sudo tee -a $DIR/etc/sysctl.conf echo 'debug.exception-trace = 0' | sudo tee -a $DIR/etc/sysctl.conf echo "net.core.bpf_jit_enable = 1" | sudo tee -a $DIR/etc/sysctl.conf |
