Skip to content
Snippets Groups Projects
Commit 3fc55e55 authored by Jeffrey Vander Stoep's avatar Jeffrey Vander Stoep Committed by Android (Google) Code Review
Browse files

Merge "Enforce restrictions on kernel module origin" into nyc-dev

parents 10908ff2 66344009
No related branches found
No related tags found
No related merge requests found
......@@ -560,3 +560,8 @@ neverallow {
-installd
-profman
} profman_exec:file no_x_file_perms;
# Enforce restrictions on kernel module origin.
# Do not allow kernel module loading except from system,
# vendor, and boot partitions.
neverallow * ~{ system_file rootfs }:system module_load;
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment