From: guido@trentalancia.net (Guido Trentalancia) Date: Sat, 17 Dec 2016 19:08:40 +0100 Subject: [refpolicy] [PATCH] udev: always enable kernel module loading Message-ID: <1481998120.13429.3.camel@trentalancia.net> To: refpolicy@oss.tresys.com List-Id: refpolicy.oss.tresys.com The udev daemon should be able to load kernel modules not only on systems using systemd but also on systems using former versions of the udev daemon. Signed-off-by: Guido Trentalancia --- policy/modules/system/udev.te | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) --- a/policy/modules/system/udev.te 2016-10-29 16:29:13.457156292 +0200 +++ b/policy/modules/system/udev.te 2016-12-17 18:15:12.803396548 +0100 @@ -79,6 +79,7 @@ manage_lnk_files_pattern(udev_t, udev_va manage_sock_files_pattern(udev_t, udev_var_run_t, udev_var_run_t) files_pid_filetrans(udev_t, udev_var_run_t, dir, "udev") +kernel_load_module(udev_t) kernel_read_system_state(udev_t) kernel_request_load_module(udev_t) kernel_getattr_core_if(udev_t) @@ -220,8 +221,6 @@ ifdef(`distro_redhat',` ') ifdef(`init_systemd',` - kernel_load_module(udev_t) - files_search_kernel_modules(udev_t) fs_read_cgroup_files(udev_t)