data:image/s3,"s3://crabby-images/37cb3/37cb3d0fed140bac6ab3960faceb3e0ceb421929" alt="NXP Semiconductors i.MX6QSabreSD Скачать руководство пользователя страница 64"
Figure 17. Restricting root permissions
1. Root: Turn on and then turn off Selinux
Booleans are shortcuts for the user to modify the SELinux policy dynamically. The policy,
secure_mode_policyload
is one
of these policies, which can deny a root user from changing SELinux running mode. By default, it is Off.
$ getsebool secure_mode_policyload
secure_mode_policyload --> off
Root can turn on SELinux:
$ setenforce 1
Root can then turn off SELinux:
$ setenforce 0
2. root:
enable secure_mode_policyload
Now the SELinux is permissive. Run the
setsebool
command to enable
secure_mode_policyload
:
$ setsebool secure_mode_policyload on
Check the status of
secure_mode_policyload
again:
$ getsebool secure_mode_policyload
secure_mode_policyload --> on
3. Root: Try to turn on and turn off SELinux.
Root can still turn on SELinux:
$ setenforce 1
Root tries to turn off SELinux but gets permission denied:
$ setenforce 0
setenforce: setenforce() failed
NXP Semiconductors
Industrial features
Open Industrial User Guide, Rev. 1.8, 05/2020
User's Guide
64 / 199