2.6.5-1.349 ignores selinux=0

Stephen Smalley sds at epoch.ncsc.mil
Tue May 4 15:53:05 UTC 2004


On Tue, 2004-05-04 at 11:36, Stephen Smalley wrote:
> On Tue, 2004-05-04 at 11:30, Zach Wilkinson wrote:
> > I didn't have /etc/sysconfig/selinux so I created it and put in the one line
> > SELINUX=disable.
> > I also changed grub.conf to selinux=disable from selinux=0.
> > Neither of these changes made any difference. SELinux still reports
> > "completing initialization" on boot and I still get tons of audit: avc:
> > denied messages.
> > up2date says I'm current.
> 
> The boot option in grub.conf won't work with the new kernel, as the
> kernel configuration option wasn't enabled for it. /etc/syconfig/selinux
> with SELINUX=disabled works here for me, but you need an up-to-date
> kernel and SysVinit.

Note that it is SELINUX=disabled not 'disable' and watch out for
whitespace; looks like the code is overly sensitive to it (no whitespace
anywhere, even trailing).

-- 
Stephen Smalley <sds at epoch.ncsc.mil>
National Security Agency





More information about the fedora-test-list mailing list