Commit 8d6d51ed authored by Randy Dunlap's avatar Randy Dunlap Committed by Paul Moore

docs: selinux: add '=' signs to kernel boot options

Provide the full kernel boot option string (with ending '=' sign).
They won't work without that and that is how other boot options are
listed.

If used without an '=' sign (as listed here), they cause an "Unknown
parameters" message and are added to init's argument strings,
polluting them.

  Unknown kernel command line parameters "enforcing checkreqprot
    BOOT_IMAGE=/boot/bzImage-517rc6", will be passed to user space.

 Run /sbin/init as init process
   with arguments:
     /sbin/init
     enforcing
     checkreqprot
   with environment:
     HOME=/
     TERM=linux
     BOOT_IMAGE=/boot/bzImage-517rc6
Signed-off-by: default avatarRandy Dunlap <rdunlap@infradead.org>
Cc: Paul Moore <paul@paul-moore.com>
Cc: Stephen Smalley <stephen.smalley.work@gmail.com>
Cc: Eric Paris <eparis@parisplace.org>
Cc: selinux@vger.kernel.org
Cc: Jonathan Corbet <corbet@lwn.net>
[PM: removed bogus 'Fixes' line]
Signed-off-by: default avatarPaul Moore <paul@paul-moore.com>
parent 2bfe15c5
...@@ -550,7 +550,7 @@ ...@@ -550,7 +550,7 @@
nosocket -- Disable socket memory accounting. nosocket -- Disable socket memory accounting.
nokmem -- Disable kernel memory accounting. nokmem -- Disable kernel memory accounting.
checkreqprot [SELINUX] Set initial checkreqprot flag value. checkreqprot= [SELINUX] Set initial checkreqprot flag value.
Format: { "0" | "1" } Format: { "0" | "1" }
See security/selinux/Kconfig help text. See security/selinux/Kconfig help text.
0 -- check protection applied by kernel (includes 0 -- check protection applied by kernel (includes
...@@ -1439,7 +1439,7 @@ ...@@ -1439,7 +1439,7 @@
(in particular on some ATI chipsets). (in particular on some ATI chipsets).
The kernel tries to set a reasonable default. The kernel tries to set a reasonable default.
enforcing [SELINUX] Set initial enforcing status. enforcing= [SELINUX] Set initial enforcing status.
Format: {"0" | "1"} Format: {"0" | "1"}
See security/selinux/Kconfig help text. See security/selinux/Kconfig help text.
0 -- permissive (log only, no denials). 0 -- permissive (log only, no denials).
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment