fix(configuration): disable selinux with selinux=0 on el9 when the feature is off

This commit is contained in:
2026-08-31 13:45:06 +02:00
parent a9a9706f2c
commit a795535305
2 changed files with 10 additions and 4 deletions

View File

@@ -43,11 +43,14 @@
}} }}
grub_root_flags: >- grub_root_flags: >-
{{ ['rootflags=subvol=@'] if system_cfg.filesystem == 'btrfs' else [] }} {{ ['rootflags=subvol=@'] if system_cfg.filesystem == 'btrfs' else [] }}
grub_selinux_args: >-
{{ [] if system_cfg.features.selinux.enabled | bool else ['selinux=0'] }}
# String-concat (not list-concat like grub_kernel_cmdline_base below): ansible-lint's # String-concat (not list-concat like grub_kernel_cmdline_base below): ansible-lint's
# jinja render trips on list+list when grub_lvm_args leads the expression here. # jinja render trips on list+list when grub_lvm_args leads the expression here.
grub_cmdline_linux_base: >- grub_cmdline_linux_base: >-
{{ {{
((grub_lvm_args | join(' ')) ~ ' ' ~ (_hardware_profile_kernel_params | default([]) | join(' '))) | trim ((grub_lvm_args | join(' ')) ~ ' ' ~ (grub_selinux_args | join(' ')) ~ ' '
~ (_hardware_profile_kernel_params | default([]) | join(' '))) | trim
}} }}
grub_kernel_cmdline_base: >- grub_kernel_cmdline_base: >-
{{ {{
@@ -57,6 +60,7 @@
+ ['ro'] + ['ro']
+ grub_lvm_args + grub_lvm_args
+ grub_root_flags + grub_root_flags
+ grub_selinux_args
+ (_hardware_profile_kernel_params | default([])) + (_hardware_profile_kernel_params | default([]))
) )
| join(' ') | join(' ')

View File

@@ -22,10 +22,12 @@
mode: "0644" mode: "0644"
# Fedora: setfiles segfaults during bootstrap chroot relabeling, so SELinux # Fedora: setfiles segfaults during bootstrap chroot relabeling, so SELinux
# is left permissive and expected to relabel on first boot. # is left permissive and expected to relabel on first boot. Opting out writes
- name: Disable SELinux # disabled here and selinux=0 on the kernel cmdline (grub.yml), the only form
# EL9 honours.
- name: Set the SELinux mode
when: os == "fedora" or not system_cfg.features.selinux.enabled | bool when: os == "fedora" or not system_cfg.features.selinux.enabled | bool
ansible.builtin.lineinfile: ansible.builtin.lineinfile:
path: /mnt/etc/selinux/config path: /mnt/etc/selinux/config
regexp: ^SELINUX= regexp: ^SELINUX=
line: SELINUX=permissive line: "SELINUX={{ 'permissive' if system_cfg.features.selinux.enabled | bool else 'disabled' }}"