diff options
author | Bill Nottingham <notting@redhat.com> | 2010-11-16 21:05:02 -0500 |
---|---|---|
committer | Bill Nottingham <notting@redhat.com> | 2010-11-16 21:05:02 -0500 |
commit | 3c46ef163cd34ef360c0c0322b4d90e3c3dad457 (patch) | |
tree | 2bdb147b62c957600bf6d35c0706f6b15d4f2e7c /systemd/fedora-autorelabel | |
parent | 7eaac898d086ea2a3dc2da549e192c5f164a5751 (diff) | |
parent | cc5b400dd6bad85f5d7b8e4a889134d3668e20a4 (diff) | |
download | initscripts-3c46ef163cd34ef360c0c0322b4d90e3c3dad457.tar initscripts-3c46ef163cd34ef360c0c0322b4d90e3c3dad457.tar.gz initscripts-3c46ef163cd34ef360c0c0322b4d90e3c3dad457.tar.bz2 initscripts-3c46ef163cd34ef360c0c0322b4d90e3c3dad457.tar.xz initscripts-3c46ef163cd34ef360c0c0322b4d90e3c3dad457.zip |
Merge branch 'systemd-branch'
Diffstat (limited to 'systemd/fedora-autorelabel')
-rwxr-xr-x | systemd/fedora-autorelabel | 84 |
1 files changed, 84 insertions, 0 deletions
diff --git a/systemd/fedora-autorelabel b/systemd/fedora-autorelabel new file mode 100755 index 00000000..f5e4db29 --- /dev/null +++ b/systemd/fedora-autorelabel @@ -0,0 +1,84 @@ +#!/bin/bash +# +# Do automatic relabelling +# + +. /etc/init.d/functions + +PLYMOUTH= +[ -x /usr/bin/plymouth ] && PLYMOUTH=yes + +# Check SELinux status +SELINUX_STATE= +if [ -e "/selinux/enforce" ] && [ "$(cat /proc/self/attr/current)" != "kernel" ]; then + if [ -r "/selinux/enforce" ] ; then + SELINUX_STATE=$(cat "/selinux/enforce") + else + # assume enforcing if you can't read it + SELINUX_STATE=1 + fi +fi + +disable_selinux() { + echo $"*** Warning -- SELinux is active" + echo $"*** Disabling security enforcement for system recovery." + echo $"*** Run 'setenforce 1' to reenable." + echo "0" > "/selinux/enforce" +} + +relabel_selinux() { + # if /sbin/init is not labeled correctly this process is running in the + # wrong context, so a reboot will be required after relabel + AUTORELABEL= + . /etc/selinux/config + echo "0" > /selinux/enforce + [ -n "$PLYMOUTH" ] && plymouth --hide-splash + + if [ "$AUTORELABEL" = "0" ]; then + echo + echo $"*** Warning -- SELinux ${SELINUXTYPE} policy relabel is required. " + echo $"*** /etc/selinux/config indicates you want to manually fix labeling" + echo $"*** problems. Dropping you to a shell; the system will reboot" + echo $"*** when you leave the shell." + sulogin + + else + echo + echo $"*** Warning -- SELinux ${SELINUXTYPE} policy relabel is required." + echo $"*** Relabeling could take a very long time, depending on file" + echo $"*** system size and speed of hard drives." + + /sbin/fixfiles -F restore > /dev/null 2>&1 + fi + rm -f /.autorelabel + echo $"Unmounting file systems" + umount -a + mount -n -o remount,ro / + echo $"Automatic reboot in progress." + reboot -f +} + +[ -z "${cmdline}" ] && cmdline=$(cat /proc/cmdline) + +# Clean up SELinux labels +if [ -n "$SELINUX_STATE" ]; then + restorecon /etc/mtab /etc/ld.so.cache /etc/blkid/blkid.tab /etc/resolv.conf >/dev/null 2>&1 +fi + +# If relabeling, relabel mount points. +if [ -n "$SELINUX_STATE" -a "$READONLY" != "yes" ]; then + if strstr "$cmdline" autorelabel || [ -f /.autorelabel ] ; then + restorecon $(awk '!/^#/ && $4 !~ /noauto/ && $2 ~ /^\// { print $2 }' /etc/fstab) >/dev/null 2>&1 + fi +fi + +# Check to see if a full relabel is needed +if [ -n "$SELINUX_STATE" -a "$READONLY" != "yes" ]; then + if strstr "$cmdline" autorelabel || [ -f /.autorelabel ] ; then + relabel_selinux + fi +else + if [ "$READONLY" != "yes" ] && [ -d /etc/selinux ]; then + [ -f /.autorelabel ] || touch /.autorelabel + fi +fi |