Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
build_library: set correct SELinux contexts in final images
We need to basically run `restorecon -R -v /` on all files in the final rootfs, before finalizing the image. Without doing that, nearly every file will have `unlabeled_t` as its context. Then with recent versions of selinux-base, some critical actions would not work correctly in SELinux enforcing mode, e.g., loading Kernel modules. To be able to run `restorecon`, `/sys/fs/selinux` has to be mounted. Without that, it will silently skip relabelling.
- Loading branch information