We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
2 parents b66c51c + 113205a commit 438b1deCopy full SHA for 438b1de
2 files changed
policy/modules/system/modutils.te
@@ -33,7 +33,7 @@ ifdef(`init_systemd',`
33
# insmod local policy
34
#
35
36
-allow kmod_t self:capability { dac_override dac_read_search net_raw sys_nice sys_tty_config };
+allow kmod_t self:capability { dac_override dac_read_search net_raw net_admin sys_nice sys_tty_config };
37
allow kmod_t self:process { execmem sigchld sigkill signal signull sigstop };
38
# for the radeon/amdgpu modules
39
dontaudit kmod_t self:capability sys_admin;
testing/sechecker.ini
@@ -273,6 +273,7 @@ exempt_source = arpwatch_t
273
iscsid_t
274
kernel_t
275
kismet_t
276
+ kmod_t # See https://lore.kernel.org/selinux/c247a57d-b4a9-4c77-9334-c338e5457a48@oss.qualcomm.com/
277
krb5kdc_t
278
kubeadm_t
279
kubelet_t
0 commit comments