SELinux boolean modification vs persistence: semanage boolean and setsebool -P
24.5K reputation · 01 Mar 2025, 18:31 UTC
Goal
Determine how to reliably toggle an SELinux boolean on CentOS and ensure the change survives a reboot, while also understanding the impact on already-running containers.
Current behavior
The semanage boolean tool updates the active boolean file, but the kernel does not reload the value until a reboot or a setsebool -P command is issued. On CentOS 8 and later, setsebool -P writes the value to the persistent configuration directory, making it survive reboots. When a boolean that influences container runtimes (e.g., container_manage_cgroup) is changed, containers that were started before the change may not observe the new policy until they are restarted.
Unresolved decision
It remains unclear whether the semanage boolean command alone can be used to persist changes across reboots, or if setsebool -P is always required. Additionally, the boundary at which container workloads become aware of boolean changes is not well documented.
Specific questions
- Can
semanage boolean -m --onalone guarantee persistence after a reboot on CentOS 8 and later, or issetsebool -Pmandatory? - What is the exact point at which running containers detect a change to a boolean that affects container management?
- Is there a documented mechanism to force immediate reloading of boolean changes without rebooting or restarting containers?