diff --git a/libselinux-bindings.spec b/libselinux-bindings.spec index 29738a0..26dc685 100644 --- a/libselinux-bindings.spec +++ b/libselinux-bindings.spec @@ -1,7 +1,7 @@ # # spec file for package libselinux-bindings # -# Copyright (c) 2021 SUSE LLC +# Copyright (c) 2022 SUSE LLC # # All modifications and additions to the file contributed by third parties # remain the property of their copyright owners, unless otherwise agreed diff --git a/libselinux.changes b/libselinux.changes index c71fbca..a07a262 100644 --- a/libselinux.changes +++ b/libselinux.changes @@ -1,3 +1,10 @@ +------------------------------------------------------------------- +Tue Feb 15 07:49:43 UTC 2022 - Johannes Segitz + +- Add Requires for exact libselinux1 version for selinux-tools +- Simplyfied check for correct boot paramaters in selinux-ready + (bsc#1195361) + ------------------------------------------------------------------- Thu Nov 11 13:25:30 UTC 2021 - Johannes Segitz diff --git a/libselinux.spec b/libselinux.spec index c7546b6..3eeb3d9 100644 --- a/libselinux.spec +++ b/libselinux.spec @@ -1,7 +1,7 @@ # # spec file for package libselinux # -# Copyright (c) 2021 SUSE LLC +# Copyright (c) 2022 SUSE LLC # # All modifications and additions to the file contributed by third parties # remain the property of their copyright owners, unless otherwise agreed @@ -56,6 +56,7 @@ Security.) Summary: SELinux command-line utilities Group: System/Base Provides: libselinux-utils = %{version}-%{release} +Requires: libselinux1 = %{version} %description -n selinux-tools Security-enhanced Linux is a feature of the kernel and some diff --git a/selinux-ready b/selinux-ready index 60a53a1..789e0c0 100644 --- a/selinux-ready +++ b/selinux-ready @@ -51,36 +51,16 @@ check_filesystem() check_boot() { - BPARAM1="security=selinux" - BPARAM2="selinux=1" - printf "\tcheck_boot: Assuming GRUB2 as bootloader.\n" - # look for parameters of the current kernel - CURRENT_KERNEL=$(uname -r) - OTHERS="" - RETVAL="FAIL" - while read BLINE - do - K=$(echo $BLINE | awk -F' ' '{print $2}') - KERNEL=$(basename $K) - K=$(echo $KERNEL | sed s/vmlinuz-//) - - if [ "$K" == "$CURRENT_KERNEL" ]; then - INITRD=initrd-$K - RETVAL="OK" - else - OTHERS="$KERNEL $OTHERS" - fi - done < <(grep -- $BPARAM1 /boot/grub2/grub.cfg 2>/dev/null | grep -- $BPARAM2) - - if [ "$RETVAL" == OK ]; then - printf "\tcheck_boot: OK. Current kernel '$KERNEL' has boot-parameters '$BPARAM1 $BPARAM2'\n" - printf "\tcheck_boot: OK. Other kernels with correct parameters: $OTHERS\n" + BPARAM1="security=selinux" + BPARAM2="selinux=1" + if grep $BPARAM1 /proc/cmdline | grep $BPARAM2 >/dev/null; then + printf "\tcheck_boot: OK. Current kernel has boot-parameters '$BPARAM1 $BPARAM2'\n" return 0 else printf "\tcheck_boot: ERR. Boot-parameter missing for booting the kernel.\n" - printf "\t Please use YaST2 to add 'security=selinux selinux=1' to the kernel boot-parameter list.\n" + printf "\t Please add 'security=selinux selinux=1' to the kernel boot-parameter list.\n" return 1 fi }