build_library: Forbid SELinux policy packages in sysexts

Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
This commit is contained in:
Krzesimir Nowak 2025-09-05 15:55:28 +02:00
parent b84b28dc9d
commit 5aa4b7da2a
2 changed files with 3 additions and 0 deletions

View File

@ -267,6 +267,7 @@ create_prod_sysexts() {
--image_builddir="${BUILD_DIR}" \
--install_root_basename="${name}-extra-sysext-rootfs" \
${mangle_script:+--manglefs_script=${mangle_script}} \
--forbidden_packages='sec-policy/selinux-.*;selinux policy packages must be in base image' \
"${name}" "${pkg_array[@]}"
delta_generator \
-private_key "/usr/share/update_engine/update-payload-key.key.pem" \
@ -311,6 +312,7 @@ create_oem_sysexts() {
--image_builddir="${BUILD_DIR}" \
--metapkgs="${metapkg}" \
--install_root_basename="${name}-oem-sysext-rootfs" \
--forbidden_packages='sec-policy/selinux-.*;selinux policy packages must be in base image' \
--compression=none \
${mangle_script:+--manglefs_script="${mangle_script}"} \
"${name}"

View File

@ -73,6 +73,7 @@ create_prod_sysext() {
--generate_pkginfo \
--compression=none \
--install_root_basename="${name}-base-sysext-rootfs" \
--forbidden_packages='sec-policy/selinux-.*;selinux policy packages must be in base image' \
"${build_sysext_opts[@]}" \
"${name}" "${grp_pkg[@]}"