Home / Alt manpages / semanage.conf(5)

  • semanage.conf(5)
  • File format
  • linux

Tune libsemanage Safely with semanage.conf

One stray setting in semanage.conf can point every SELinux policy operation at a server you never meant to trust. This guide covers the semanage.conf(5) file shipped by libsemanage-common 3.5-1build5 on this machine, and does not install SELinux policy or run a policy-changing command.

Allow about 15 minutes. You need a shell, a text editor, and root access only for reading or replacing the system file. Read the complete local manual first if your package version differs: the installed file is the authority for the behaviour you can reproduce on your host.

1. Locate and inspect the file

The usual path is /etc/selinux/semanage.conf. Confirm the package and file before editing:

$ dpkg-query -W -f='${Package} ${Version}\n' libsemanage-common
libsemanage-common 3.5-1build5
$ ls -l /etc/selinux/semanage.conf
-rw-r--r-- 1 root root ... /etc/selinux/semanage.conf

Your version and timestamps will differ. If the file is elsewhere, use the path reported by your distribution's package; do not create a second file and assume libsemanage will find it.

Read the effective local configuration without changing it:

$ sudo sed -n '1,240p' /etc/selinux/semanage.conf

On the reference system, the active settings include module-store = direct and expand-check=0. Comments do not configure anything: blank lines and text after # are ignored, and each active line uses a parameter, an equals sign, and a value.

2. Make a recoverable backup

Before changing a root-owned file, preserve its current contents and mode. This command only reads the file and writes a backup alongside it:

$ sudo cp -p /etc/selinux/semanage.conf /etc/selinux/semanage.conf.before-$(date +%Y%m%d-%H%M%S)
$ sudo ls -l /etc/selinux/semanage.conf*

Checkpoint

The second command should show the original file and one timestamped backup. If the backup is missing, stop. To undo a later edit, copy the exact backup back into place, then inspect the restored file:

$ sudo cp -p /etc/selinux/semanage.conf.before-YYYYMMDD-HHMMSS /etc/selinux/semanage.conf
$ sudo sed -n '1,240p' /etc/selinux/semanage.conf

Replace the timestamp placeholder with the filename you actually recorded. Restoration changes persistent configuration, so do it only once you have identified the correct backup.

3. Choose the policy-store connection

The most consequential setting is module-store. The value direct makes libsemanage write to the SELinux policy module store directly, and is the documented default. A value beginning with / is treated as a named Unix socket path for a policy management server. A value such as policy-host.example:4242 selects a remote policy management server over TCP; if no port follows the server name, the documented default is 4242.

Security warning

A remote or socket-backed store is a security boundary, not just a faster transport. Do not paste a hostname from an example into a production file. Confirm who operates the policy management server, how it authenticates clients, and which network path it uses before selecting this mode. If you only need the local policy store, leave the setting as module-store = direct.

For a local-only change, edit with elevated privileges:

$ sudoedit /etc/selinux/semanage.conf

Keep one active module-store line. Add or change only the value you intend to change, and do not remove surrounding comments until you have confirmed the new behaviour. A spelling error or an unreachable socket can make subsequent management commands fail.

4. Adjust rebuild cost only when you have a reason

expand-check controls whether libsemanage checks neverallow rules while executing semanage commands. Its documented values are 0 and 1, and the manual warns that enabling it can impose a large execution-time penalty. The reference file uses expand-check=0. Do not enable it merely because the option sounds safer: decide whether the additional check belongs in your workflow, then measure the effect on a maintenance window.

If you do need the check, make the smallest possible edit:

# Check neverallow rules during semanage operations.
expand-check = 1

There is no service restart command in the semanage.conf(5) documentation. Treat the setting as input read by later libsemanage operations. Test the next operation deliberately, and do not combine this edit with a policy import or module installation on the same change.

5. Review the other settings before touching them

  • Path settings need verification first. root changes the alternative root path, store-root changes the store root (default /var/lib/selinux), and compiler-directory points at HLL-to-CIL compilers, defaulting to /usr/libexec/selinux/hll. Check ownership, permissions and available space before using any of them.
  • Generation controls change compatibility. policy-version overrides the default maximum policy version, target-platform accepts selinux or xen, and handle-unknown accepts deny, reject or allow for unknown kernel permissions. Use these only with a compatibility requirement you can name and test.
  • remove-hll is the dangerous one. Setting it to true removes HLL files after compilation, and the manual warns that an updated compiler cannot recreate the original HLL source from the generated CIL. This is destructive and may be irreversible unless the original module is still available. Leave it at its documented default of false unless you have an inventory and recovery plan.
  • Retention options affect recompiles. save-previous and save-linked control whether previous policy material is retained. ignore-module-cache forces HLL modules to be recompiled rather than using cached CIL, which can increase work and expose compiler problems. Change one related setting at a time and keep the backup until the resulting policy operation has been checked.

6. Verify the file without changing policy

There is no standalone syntax-check command documented by semanage.conf(5), and semanage is not installed on the reference machine, so perform a text review instead:

$ sudo sed -n '1,240p' /etc/selinux/semanage.conf
$ sudo grep -nEv '^[[:space:]]*(#|$)' /etc/selinux/semanage.conf
  ... active configuration lines ...

Check each active line by hand: one recognised parameter, one equals sign, and a value allowed by the manual. Look for duplicate active assignments, accidental leading characters, and a hostname or socket path that was copied from documentation. Then compare the file with the backup:

$ sudo diff -u /etc/selinux/semanage.conf.before-YYYYMMDD-HHMMSS /etc/selinux/semanage.conf

The diff should contain only the intended change. If it contains more, restore the backup and edit again. This review does not prove that a remote server exists or that a generated policy will load; it proves only that the file contains the change you meant to make.

Done means

  • Version and path known. The installed package version and the actual configuration path are confirmed.
  • Backup exists. A timestamped backup exists and can be restored with an explicit copy command.
  • Store setting reviewed. module-store is direct unless a reviewed socket or server design requires otherwise.
  • Changes are justified. Any expand-check, path, policy-version or retention change has a named operational reason.
  • remove-hll stays false unless the original HLL modules and recovery path are documented.
  • Diff is clean. The final diff contains only the intended configuration change, and no policy-changing command was bundled into the edit.