Commit fe7570c
authored
OS Guard: Remove unnecessary SELinux context mapping and enable SELinux and IPE lockout module (microsoft#14546)
tardev-snapshotter is not present or used in our linuxguard / osguard
images. So remove SELinux label for it.
Also enable azureci_prod SELinux module to prevent tampering with
SELinux and IPE settings at runtime.
Signed-off-by: Chris Co <chrco@microsoft.com>1 parent 00befca commit fe7570c
File tree
3 files changed
+1
-2
lines changed- toolkit/imageconfigs
- files
- linuxguard
- osguard
- scripts/common
3 files changed
+1
-2
lines changedLines changed: 0 additions & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
16 | 16 | | |
17 | 17 | | |
18 | 18 | | |
19 | | - | |
20 | 19 | | |
21 | 20 | | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
16 | 16 | | |
17 | 17 | | |
18 | 18 | | |
19 | | - | |
20 | 19 | | |
21 | 20 | | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
30 | 30 | | |
31 | 31 | | |
32 | 32 | | |
| 33 | + | |
33 | 34 | | |
34 | 35 | | |
35 | 36 | | |
| |||
0 commit comments