I can confirm Marc's assessment regarding Yama. On Ubuntu 10.04 (without yama): $ ln -s /forcefsck /var/lock/selinux-relabel $ sudo touch /var/lock/selinux-relabel $ test -e /forcefsck && echo yes yes $
On 10.10 and higher (all versions confirmed): $ ln -s /forcefsck /var/lock/selinux-relabel $ sudo touch /var/lock/selinux-relabel touch: cannot touch `/var/lock/selinux-relabel': Permission denied $ test -e /forcefsck && echo yes $
I can confirm Marc's assessment regarding Yama. On Ubuntu 10.04 (without yama): selinux- relabel selinux- relabel
$ ln -s /forcefsck /var/lock/
$ sudo touch /var/lock/
$ test -e /forcefsck && echo yes
yes
$
On 10.10 and higher (all versions confirmed): selinux- relabel selinux- relabel selinux- relabel' : Permission denied
$ ln -s /forcefsck /var/lock/
$ sudo touch /var/lock/
touch: cannot touch `/var/lock/
$ test -e /forcefsck && echo yes
$