Skip to content
Snippets Groups Projects
Commit 3541843a authored by Jeffrey Vander Stoep's avatar Jeffrey Vander Stoep Committed by Gerrit Code Review
Browse files

Merge "Enforce restrictions on kernel module origin"

parents acb07f8a 70159fd3
No related branches found
No related tags found
No related merge requests found
...@@ -545,3 +545,8 @@ neverallow { ...@@ -545,3 +545,8 @@ neverallow {
-ueventd -ueventd
-vold -vold
} fuse_device:chr_file *; } fuse_device:chr_file *;
# Enforce restrictions on kernel module origin.
# Do not allow kernel module loading except from system,
# vendor, and boot partitions.
neverallow * ~{ system_file rootfs }:system module_load;
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment