BACKPORT: selinux: restrict kernel module loading
[firefly-linux-kernel-4.4.55.git] / security / selinux / include / classmap.h
index 5a4eef59aeff97676e8b2d2ef94bc45ca9315201..b393d29ae85713b85b7822f17571db7f51c5418b 100644 (file)
@@ -32,7 +32,7 @@ struct security_class_mapping secclass_map[] = {
            "setsockcreate", NULL } },
        { "system",
          { "ipc_info", "syslog_read", "syslog_mod",
-           "syslog_console", "module_request", NULL } },
+           "syslog_console", "module_request", "module_load", NULL } },
        { "capability",
          { "chown", "dac_override", "dac_read_search",
            "fowner", "fsetid", "kill", "setgid", "setuid", "setpcap",