OSDN Git Service

selinux: revert SECINITSID_INIT support
authorPaul Moore <paul@paul-moore.com>
Tue, 8 Aug 2023 02:57:22 +0000 (22:57 -0400)
committerPaul Moore <paul@paul-moore.com>
Wed, 9 Aug 2023 14:51:13 +0000 (10:51 -0400)
commit817199e006e514e6c39a17ed2e9fece1bd56b898
treef450f46e3941356c1b9aae3d7fbe26af4e2f9cd4
parent2b86e04bce141311c3a68940be2c8d5984274fca
selinux: revert SECINITSID_INIT support

This commit reverts 5b0eea835d4e ("selinux: introduce an initial SID
for early boot processes") as it was found to cause problems on
distros with old SELinux userspace tools/libraries, specifically
Ubuntu 16.04.

Hopefully we will be able to re-add this functionality at a later
date, but let's revert this for now to help ensure a stable and
backwards compatible SELinux tree.

Link: https://lore.kernel.org/selinux/87edkseqf8.fsf@mail.lhotse
Acked-by: Ondrej Mosnacek <omosnace@redhat.com>
Signed-off-by: Paul Moore <paul@paul-moore.com>
security/selinux/hooks.c
security/selinux/include/initial_sid_to_string.h
security/selinux/include/policycap.h
security/selinux/include/policycap_names.h
security/selinux/include/security.h
security/selinux/ss/policydb.c