Skip to content
Snippets Groups Projects
  • Chenbo Feng's avatar
    sepolicy: New sepolicy classes and rules about bpf object · 08f92f9c
    Chenbo Feng authored
    Add the new classes for eBPF map and program to limit the access to eBPF
    object. Add corresponding rules to allow netd module initialize bpf
    programs and maps, use the program and read/wirte to eBPF maps.
    
    Test: no bpf sepolicy violations when device boot
    Change-Id: I63c35cd60f1972d4fb36ef2408da8d5f2246f7fd
    08f92f9c