Files
linux/Documentation
Kees Cook 3d43321b70 modules: sysctl to block module loading
Implement a sysctl file that disables module-loading system-wide since
there is no longer a viable way to remove CAP_SYS_MODULE after the system
bounding capability set was removed in 2.6.25.

Value can only be set to "1", and is tested only if standard capability
checks allow CAP_SYS_MODULE.  Given existing /dev/mem protections, this
should allow administrators a one-way method to block module loading
after initial boot-time module loading has finished.

Signed-off-by: Kees Cook <kees.cook@canonical.com>
Acked-by: Serge Hallyn <serue@us.ibm.com>
Signed-off-by: James Morris <jmorris@namei.org>
2009-04-03 11:47:11 +11:00
..
2009-03-24 10:52:46 +11:00
2008-10-30 11:38:45 -07:00
2007-07-19 10:04:47 -07:00
2008-02-14 00:16:13 -05:00
2008-10-16 11:21:30 -07:00
2008-04-25 13:27:03 +01:00
2008-02-03 15:54:28 +02:00
2008-10-30 11:38:45 -07:00
2009-01-06 17:21:00 +01:00
2008-10-30 11:38:47 -07:00
2009-01-14 21:42:51 +01:00
2008-01-11 18:22:30 -06:00
2007-05-09 08:57:56 +02:00
2005-04-16 15:20:36 -07:00
2008-10-30 11:38:45 -07:00
2008-10-16 11:21:29 -07:00
2009-02-04 16:43:44 -08:00
2009-03-10 15:55:11 -07:00
2008-04-29 02:49:47 -04:00
2006-11-30 04:58:40 +01:00
2009-03-24 16:20:36 -07:00
2009-01-06 15:59:03 -08:00
2008-10-30 11:38:45 -07:00
2008-12-03 16:09:53 -07:00
2008-07-25 10:53:30 -07:00
2008-11-12 17:17:18 -08:00
2007-10-19 11:53:34 -07:00
2008-11-14 10:39:26 +11:00
2009-03-26 15:45:43 -07:00
2006-11-30 04:58:40 +01:00
2008-11-28 13:15:14 +01:00
2008-10-16 11:21:40 -07:00
2008-03-24 19:22:19 -07:00
2005-04-16 15:20:36 -07:00
2007-10-18 14:37:32 -07:00
2005-04-16 15:20:36 -07:00
2008-02-06 10:41:09 -08:00
2008-10-20 15:43:10 +02:00
2009-03-16 07:55:37 -07:00
2009-03-16 07:55:37 -07:00
2008-08-12 16:07:30 -07:00
2008-07-21 14:22:18 +10:00
2005-04-16 15:20:36 -07:00
2005-04-16 15:20:36 -07:00
2005-04-16 15:20:36 -07:00
2005-04-16 15:20:36 -07:00
2008-11-12 17:17:17 -08:00
2007-02-11 10:51:35 -08:00
2006-06-27 17:32:47 -07:00
2008-02-06 10:41:14 -08:00
2005-04-16 15:20:36 -07:00
2005-06-21 18:46:32 -07:00
2005-04-16 15:20:36 -07:00
2007-10-17 08:43:06 -07:00
2005-04-16 15:20:36 -07:00
2005-04-16 15:20:36 -07:00
2005-04-16 15:20:36 -07:00
2005-04-16 15:20:36 -07:00
2005-04-16 15:20:36 -07:00