From 470087031c1e6e8d4abd889a0cb4030ca3c4a735 Mon Sep 17 00:00:00 2001 From: Adam Duskett Date: Mon, 9 Oct 2023 18:18:17 +0200 Subject: [PATCH] package/pkg-generic: auto-install selinux modules only for upstream refpolicy The description of REFPOLICY_CUSTOM_GIT states: The custom refpolicy must define the full policy explicitly, and must be a fork of the original refpolicy, to have the same build system. When this is selected, only the custom policy definition are taken into account and all the modules of the policy are built into the binary policy. Currently, if a user definess their own policy, a package containing a selinux directory would add to their custom policy, which is not what they would want. Disable applying selinux policies in selinux/ directories for custom git refpolicies. Signed-off-by: Adam Duskett Signed-off-by: Thomas Petazzoni (cherry picked from commit 5f6e6080570d542852b416a72f04a07760808c7e) Signed-off-by: Peter Korsgaard --- package/pkg-generic.mk | 3 +++ 1 file changed, 3 insertions(+) diff --git a/package/pkg-generic.mk b/package/pkg-generic.mk index 30570840a4..597424148c 100644 --- a/package/pkg-generic.mk +++ b/package/pkg-generic.mk @@ -1220,8 +1220,11 @@ KEEP_PYTHON_PY_FILES += $$($(2)_KEEP_PY_FILES) ifneq ($$($(2)_SELINUX_MODULES),) PACKAGES_SELINUX_MODULES += $$($(2)_SELINUX_MODULES) endif + +ifeq ($(BR2_PACKAGE_REFPOLICY_UPSTREAM_VERSION),y) PACKAGES_SELINUX_EXTRA_MODULES_DIRS += \ $$(if $$(wildcard $$($(2)_PKGDIR)/selinux),$$($(2)_PKGDIR)/selinux) +endif ifeq ($$($(2)_SITE_METHOD),svn) DL_TOOLS_DEPENDENCIES += svn