Merge "Enforce restrictions on kernel module origin" into nyc-dev
diff --git a/domain.te b/domain.te
index d7333c5..5171fb3 100644
--- a/domain.te
+++ b/domain.te
@@ -560,3 +560,8 @@
   -installd
   -profman
 } profman_exec:file no_x_file_perms;
+
+# Enforce restrictions on kernel module origin.
+# Do not allow kernel module loading except from system,
+# vendor, and boot partitions.
+neverallow * ~{ system_file rootfs }:system module_load;