| Summary: | speed up yum update if selinux disabled | ||
|---|---|---|---|
| Product: | [Fedora] Fedora | Reporter: | Tom Horsley <horsley1953> |
| Component: | selinux-policy-targeted | Assignee: | Miroslav Grepl <mgrepl> |
| Status: | CLOSED WONTFIX | QA Contact: | Ben Levenson <benl> |
| Severity: | unspecified | Docs Contact: | |
| Priority: | unspecified | ||
| Version: | 14 | CC: | dwalsh |
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | Bug Fix | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2011-03-29 17:58:32 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
|
Description
Tom Horsley
2011-03-26 14:08:50 UTC
I guess I would look for what requires it. rpm -q --whatrequires selinux-policy-targeted SELinux policy is recompiling the policy when the package gets installed, this should only be taking 10-20 seconds. It can not be changed to not do this, since it would blow up if someone was to turn on the selinux. I would figure out which package requires it and see if we can remove the requirement. Seems entirely possible to me to wait till selinux is enabled, and then recompile the policy. Since that will never happen on my system, I'd never have to wait for it :-). The dependency thing is more mysterious. I've never observed anything that depends on selinux-policy-targeted. In fact, if I try doing a yum erase right now, it says the only thing it will remove is that one package, yet if I remove it and continue to do regular yum updates, it eventually always seems to reappear (at least that was always what happened in the past before I gave up trying to remove it). Maybe an occasional dependency crops up then gets removed before I notice any specific reason the package reappeared? Not that simple. Since enabling SELinux is just editing /etc/selinux/config, no way for the user to know to recompile policy. selinux-policy-targeted should not get installed unless selinux-policy-targeted or selinux-policy-base is required, or perhaps when you do a upgrade install from one Fedora to the next. I would just remove the package and see if you can figure out how it got reinstalled. Yea, I went ahead and did that again, and this time added an exclusion in the /etc/uum.conf file to prevent it from installing it again. If something depends on it, I should at least get update errors now. |