kernel: don't setenforce if kernel is already permissive
This commit is contained in:
@@ -89,4 +89,12 @@ void setenforce(bool enforce) {
|
||||
#ifdef CONFIG_SECURITY_SELINUX_DEVELOP
|
||||
selinux_state.enforcing = enforce;
|
||||
#endif
|
||||
}
|
||||
|
||||
bool getenforce() {
|
||||
#ifdef CONFIG_SECURITY_SELINUX_DEVELOP
|
||||
return selinux_state.enforcing;
|
||||
#else
|
||||
return false;
|
||||
#endif
|
||||
}
|
||||
@@ -5,4 +5,6 @@ void setup_selinux();
|
||||
|
||||
void setenforce(bool);
|
||||
|
||||
bool getenforce();
|
||||
|
||||
#endif
|
||||
Reference in New Issue
Block a user