* init.cfg (require_selinux_): Ensure we call is_selinux_enabled().
* src/id.c (main): Add a note about the coupling of error messages.
---
 init.cfg | 4 ++++
 src/id.c | 3 ++-
 2 files changed, 6 insertions(+), 1 deletion(-)

diff --git a/init.cfg b/init.cfg
index 3f2055511..c79a86178 100644
--- a/init.cfg
+++ b/init.cfg
@@ -127,6 +127,10 @@ require_selinux_()
       skip_ "this $selinux_missing_ lacks SELinux support"
     ;;
   esac
+
+  # In a container, selinux may not be enabled, check is_selinux_enabled() with
+  id -Z 0 2>&1 | grep 'works only on .*enabled kernel' \
+    && skip_ 'selinux is disabled'
 }
 
 # Return the SELinux type component if available
diff --git a/src/id.c b/src/id.c
index b5a307721..f8c5b5f8f 100644
--- a/src/id.c
+++ b/src/id.c
@@ -165,7 +165,8 @@ main (int argc, char **argv)
           break;
 
         case 'Z':
-          /* politely decline if we're not on a SELinux/SMACK-enabled kernel. 
*/
+          /* politely decline if we're not on a SELinux/SMACK-enabled kernel.
+             Keep require_selinux_ in tests in sync with these messages.  */
 #ifdef HAVE_SMACK
           if (!selinux_enabled && !smack_enabled)
             error (EXIT_FAILURE, 0,
-- 
2.55.0


Reply via email to