From: cpebenito@tresys.com (Christopher J. PeBenito) Date: Wed, 09 Feb 2011 09:43:15 -0500 Subject: [refpolicy] [PATCH 1/1] Allow modprobe to request module load In-Reply-To: <20110206142743.GA10802@siphos.be> References: <20110206142743.GA10802@siphos.be> Message-ID: <4D52A803.4020303@tresys.com> To: refpolicy@oss.tresys.com List-Id: refpolicy.oss.tresys.com On 2/6/2011 9:27 AM, Sven Vermeulen wrote: > The modprobe utility is sometimes used (for instance for ALSA) to request > the Linux kernel to load a module (through aliases) rather than explicitly > loading the module. Merged. > Signed-off-by: Sven Vermeulen > --- > policy/modules/system/modutils.te | 1 + > 1 files changed, 1 insertions(+), 0 deletions(-) > > diff --git a/policy/modules/system/modutils.te b/policy/modules/system/modutils.te > index 74a4466..882b50c 100644 > --- a/policy/modules/system/modutils.te > +++ b/policy/modules/system/modutils.te > @@ -119,6 +119,7 @@ read_files_pattern(insmod_t, modules_dep_t, modules_dep_t) > can_exec(insmod_t, insmod_exec_t) > > kernel_load_module(insmod_t) > +kernel_request_load_module(insmod_t) > kernel_read_system_state(insmod_t) > kernel_read_network_state(insmod_t) > kernel_write_proc_files(insmod_t) -- Chris PeBenito Tresys Technology, LLC www.tresys.com | oss.tresys.com