commit: 8c1a98b2fd43d509a82d3a92e3c49669c4d4ae59
Author: Guido Trentalancia <guido <AT> trentalancia <DOT> com>
AuthorDate: Sun Aug 31 19:49:14 2025 +0000
Commit: Jason Zaman <perfinion <AT> gentoo <DOT> org>
CommitDate: Sun Nov 16 00:13:57 2025 +0000
URL:
https://gitweb.gentoo.org/proj/hardened-refpolicy.git/commit/?id=8c1a98b2
Add the new firmware_load permission.
Signed-off-by: Guido Trentalancia <guido <AT> trentalancia.com>
Signed-off-by: Jason Zaman <perfinion <AT> gentoo.org>
policy/flask/access_vectors | 1 +
1 file changed, 1 insertion(+)
diff --git a/policy/flask/access_vectors b/policy/flask/access_vectors
index 58a559ca1..caca27fb9 100644
--- a/policy/flask/access_vectors
+++ b/policy/flask/access_vectors
@@ -410,6 +410,7 @@ class system
syslog_console
module_request
module_load
+ firmware_load
# these are overloaded userspace
# permissions from systemd