Tune libsemanage Safely with semanage.conf
One stray setting in semanage.conf can point every SELinux policy operation at a server you never meant to trust. This guide covers the semanage.conf(5) file shipped by libsemanage-common 3.5-1build5 on this machine, and does not install SELinux policy or run a policy-changing command.
The route
Jump straight to the step you need, or tick off Done means at the end.
Allow about 15 minutes. You need a shell, a text editor, and root access only for reading or replacing the system file. Read the complete local manual first if your package version differs: the installed file is the authority for the behaviour you can reproduce on your host.
1. Locate and inspect the file
The usual path is /etc/selinux/semanage.conf. Confirm the package and file before editing:
$ dpkg-query -W -f='${Package} ${Version}\n' libsemanage-common
libsemanage-common 3.5-1build5
$ ls -l /etc/selinux/semanage.conf
-rw-r--r-- 1 root root ... /etc/selinux/semanage.conf
Your version and timestamps will differ. If the file is elsewhere, use the path reported by your distribution's package; do not create a second file and assume libsemanage will find it.
Read the effective local configuration without changing it:
$ sudo sed -n '1,240p' /etc/selinux/semanage.conf
On the reference system, the active settings include module-store = direct and expand-check=0. Comments do not configure anything: blank lines and text after # are ignored, and each active line uses a parameter, an equals sign, and a value.
2. Make a recoverable backup
Before changing a root-owned file, preserve its current contents and mode. This command only reads the file and writes a backup alongside it:
$ sudo cp -p /etc/selinux/semanage.conf /etc/selinux/semanage.conf.before-$(date +%Y%m%d-%H%M%S)
$ sudo ls -l /etc/selinux/semanage.conf*
Checkpoint
The second command should show the original file and one timestamped backup. If the backup is missing, stop. To undo a later edit, copy the exact backup back into place, then inspect the restored file:
$ sudo cp -p /etc/selinux/semanage.conf.before-YYYYMMDD-HHMMSS /etc/selinux/semanage.conf
$ sudo sed -n '1,240p' /etc/selinux/semanage.conf
Replace the timestamp placeholder with the filename you actually recorded. Restoration changes persistent configuration, so do it only once you have identified the correct backup.
3. Choose the policy-store connection
The most consequential setting is module-store. The value direct makes libsemanage write to the SELinux policy module store directly, and is the documented default. A value beginning with / is treated as a named Unix socket path for a policy management server. A value such as policy-host.example:4242 selects a remote policy management server over TCP; if no port follows the server name, the documented default is 4242.
Security warning
A remote or socket-backed store is a security boundary, not just a faster transport. Do not paste a hostname from an example into a production file. Confirm who operates the policy management server, how it authenticates clients, and which network path it uses before selecting this mode. If you only need the local policy store, leave the setting as module-store = direct.
For a local-only change, edit with elevated privileges:
$ sudoedit /etc/selinux/semanage.conf
Keep one active module-store line. Add or change only the value you intend to change, and do not remove surrounding comments until you have confirmed the new behaviour. A spelling error or an unreachable socket can make subsequent management commands fail.
4. Adjust rebuild cost only when you have a reason
expand-check controls whether libsemanage checks neverallow rules while executing semanage commands. Its documented values are 0 and 1, and the manual warns that enabling it can impose a large execution-time penalty. The reference file uses expand-check=0. Do not enable it merely because the option sounds safer: decide whether the additional check belongs in your workflow, then measure the effect on a maintenance window.
If you do need the check, make the smallest possible edit:
# Check neverallow rules during semanage operations.
expand-check = 1
There is no service restart command in the semanage.conf(5) documentation. Treat the setting as input read by later libsemanage operations. Test the next operation deliberately, and do not combine this edit with a policy import or module installation on the same change.
5. Review the other settings before touching them
- Path settings need verification first.
rootchanges the alternative root path,store-rootchanges the store root (default/var/lib/selinux), andcompiler-directorypoints at HLL-to-CIL compilers, defaulting to/usr/libexec/selinux/hll. Check ownership, permissions and available space before using any of them. - Generation controls change compatibility.
policy-versionoverrides the default maximum policy version,target-platformacceptsselinuxorxen, andhandle-unknownacceptsdeny,rejectorallowfor unknown kernel permissions. Use these only with a compatibility requirement you can name and test. remove-hllis the dangerous one. Setting it totrueremoves HLL files after compilation, and the manual warns that an updated compiler cannot recreate the original HLL source from the generated CIL. This is destructive and may be irreversible unless the original module is still available. Leave it at its documented default offalseunless you have an inventory and recovery plan.- Retention options affect recompiles.
save-previousandsave-linkedcontrol whether previous policy material is retained.ignore-module-cacheforces HLL modules to be recompiled rather than using cached CIL, which can increase work and expose compiler problems. Change one related setting at a time and keep the backup until the resulting policy operation has been checked.
6. Verify the file without changing policy
There is no standalone syntax-check command documented by semanage.conf(5), and semanage is not installed on the reference machine, so perform a text review instead:
$ sudo sed -n '1,240p' /etc/selinux/semanage.conf
$ sudo grep -nEv '^[[:space:]]*(#|$)' /etc/selinux/semanage.conf
... active configuration lines ...
Check each active line by hand: one recognised parameter, one equals sign, and a value allowed by the manual. Look for duplicate active assignments, accidental leading characters, and a hostname or socket path that was copied from documentation. Then compare the file with the backup:
$ sudo diff -u /etc/selinux/semanage.conf.before-YYYYMMDD-HHMMSS /etc/selinux/semanage.conf
The diff should contain only the intended change. If it contains more, restore the backup and edit again. This review does not prove that a remote server exists or that a generated policy will load; it proves only that the file contains the change you meant to make.
Done means
- Version and path known. The installed package version and the actual configuration path are confirmed.
- Backup exists. A timestamped backup exists and can be restored with an explicit copy command.
- Store setting reviewed.
module-storeis direct unless a reviewed socket or server design requires otherwise. - Changes are justified. Any
expand-check, path, policy-version or retention change has a named operational reason. remove-hllstays false unless the original HLL modules and recovery path are documented.- Diff is clean. The final diff contains only the intended configuration change, and no policy-changing command was bundled into the edit.