diff options
| author | Eric Paris <[email protected]> | 2009-08-13 13:45:03 +0000 |
|---|---|---|
| committer | James Morris <[email protected]> | 2009-08-14 01:18:40 +0000 |
| commit | 25354c4fee169710fd9da15f3bb2abaa24dcf933 (patch) | |
| tree | 7fb462945c15ce09392ae858c8ae757290b5ed2d /security/selinux/include/class_to_string.h | |
| parent | security: introducing security_request_module (diff) | |
| download | kernel-25354c4fee169710fd9da15f3bb2abaa24dcf933.tar.gz kernel-25354c4fee169710fd9da15f3bb2abaa24dcf933.zip | |
SELinux: add selinux_kernel_module_request
This patch adds a new selinux hook so SELinux can arbitrate if a given
process should be allowed to trigger a request for the kernel to try to
load a module. This is a different operation than a process trying to load
a module itself, which is already protected by CAP_SYS_MODULE.
Signed-off-by: Eric Paris <[email protected]>
Acked-by: Serge Hallyn <[email protected]>
Signed-off-by: James Morris <[email protected]>
Diffstat (limited to 'security/selinux/include/class_to_string.h')
0 files changed, 0 insertions, 0 deletions
