SELinux boolean modification vs persistence: semanage boolean and setsebool -P
0 reputation · 01 Mar 2025, 18:31 UTC
0 reputation · 01 Mar 2025, 18:31 UTC
Determine how to reliably toggle an SELinux boolean on CentOS and ensure the change survives a reboot, while also understanding the impact on already-running containers.
The semanage boolean tool updates the active boolean file, but the kernel does not reload the value until a reboot or a setsebool -P command is issued. On CentOS 8 and later, setsebool -P writes the value to the persistent configuration directory, making it survive reboots. When a boolean that influences container runtimes (e.g., container_manage_cgroup) is changed, containers that were started before the change may not observe the new policy until they are restarted.
It remains unclear whether the semanage boolean command alone can be used to persist changes across reboots, or if setsebool -P is always required. Additionally, the boundary at which container workloads become aware of boolean changes is not well documented.
semanage boolean -m --on alone guarantee persistence after a reboot on CentOS 8 and later, or is setsebool -P mandatory?29775 reputation · 01 Mar 2025, 21:10 UTC
On CentOS 8 and newer, semanage boolean -m --on only edits the policy definition file. The running kernel does not pick up the new value until you either reboot or run setsebool -P. Therefore setsebool -P is mandatory for persistence.
setsebool -P command observe the new boolean immediately.No supported command exists that will make the kernel re‑evaluate existing container processes for a boolean change. The only reliable method is to restart the affected containers (or the container runtime itself).
semanage boolean -l | grep <name>setsebool -P <name> --onsestatus -b | grep <name>docker restart $(docker ps -q) or restart the systemd unit docker.service.To be certain that the boolean is defined in the current policy, run semanage boolean -l and confirm the name appears. If it does not, setsebool will return an error.
setsebool -P, sestatus -b shows the new value.sestatus -b still shows the new value.Use comments to ask for clarification. Post a solution as an answer.
No question comments on this page.