Go to file
Dustin 2b40255a61 selinux: Simplify policy for init-storage
As the scope of Aimee OS grows, and other applications are added to it,
the `init-storage` command will have an ever-growing list of file and
directory types to copy from the rootfs image.  Originally, I wanted to
explicitly allow it to only copy files that are found in `/var`, but
this will become untenable very quickly.  As such, to avoid having to
constantly update the SELinux policy for every new application that
stores anything in `/var` at install time, the `aimee_storinit_t` domain
can now manage all "non-security" files, directories, and symbolic
links.  This covers pretty much everything in `/var` except
`/var/log/audit`, while still excluding the most sensitive files (e.g.
`/etc/shadow`),
2023-03-16 18:36:26 -05:00
overlay factory-reset: Remove errant debug command 2023-03-15 21:48:44 -05:00
patches/ebuilds/sys-boot/grub wip: build u-boot with Portage 2023-03-12 12:47:36 -05:00
repos selinux: Simplify policy for init-storage 2023-03-16 18:36:26 -05:00
yellow Omit /var/log/journal from rootfs image 2023-03-15 21:48:44 -05:00
.gitignore build: Implement CONFIGDIR setting 2023-03-15 21:12:04 -05:00
.gitmodules wip: build u-boot with Portage 2023-03-12 12:47:36 -05:00
Makefile build: Implement CONFIGDIR setting 2023-03-15 21:12:04 -05:00
README.md Initial commit 2023-02-13 23:24:36 -06:00
build-grub.sh build: Implement CONFIGDIR setting 2023-03-15 21:12:04 -05:00
build-host-tools.sh build: Implement CONFIGDIR setting 2023-03-15 21:12:04 -05:00
build-kernel.sh build: Implement CONFIGDIR setting 2023-03-15 21:12:04 -05:00
build-rootfs.sh Create subvolumes in init-storage 2023-03-15 21:45:30 -05:00
build-squashfs.sh build: Implement CONFIGDIR setting 2023-03-15 21:12:04 -05:00
build-update.sh build: Implement CONFIGDIR setting 2023-03-15 21:12:04 -05:00
build.sh build: Implement CONFIGDIR setting 2023-03-15 21:12:04 -05:00
config.txt Initial commit 2023-02-13 23:24:36 -06:00
genimage.cfg Support external build directory 2023-03-03 12:36:15 -06:00
genimage.sh build: Implement CONFIGDIR setting 2023-03-15 21:12:04 -05:00
grub.cfg Initial commit 2023-02-13 23:24:36 -06:00
install-update.sh install-update: Fix error message in die function 2023-03-08 11:12:00 -06:00
ocivm.sh build: Implement CONFIGDIR setting 2023-03-15 21:12:04 -05:00
podman-build.sh Add start-container.sh script 2023-02-21 09:58:18 -06:00
post-build.sh build: Implement CONFIGDIR setting 2023-03-15 21:12:04 -05:00
prepare.sh build: Implement CONFIGDIR setting 2023-03-15 21:12:04 -05:00
rebuild-pkg.sh build: Implement CONFIGDIR setting 2023-03-15 21:12:04 -05:00
setup-local-repo.sh build: Implement CONFIGDIR setting 2023-03-15 21:12:04 -05:00
start-container.sh build: Implement CONFIGDIR setting 2023-03-15 21:12:04 -05:00
vm-build.sh vm-build: Add script to build in a microvm 2023-03-08 11:12:00 -06:00

README.md

Errors

SWIOTLB Buffer

OF: reserved mem: failed to allocate memory for node … Can not allocate SWIOTLB buffer earlier and can't now provide you with the DMA bounce buffer

Ensure start_x=1 is in config.txt and start_file/fixup_file are not specified.

U-Boot: Overwrite Reserved Memory

** Reading file would overwrite reserved memory **

Set CONFIG_LMB_MAX_REGIONS=16 in u-boot/.config