pub(crate) fn have_selinux_policy(root: &Dir) -> Result<bool>
Query whether SELinux is apparently enabled in the target root