Skip to content
Snippets Groups Projects
  • Chenbo Feng's avatar
    Add sepolicy to lock down bpf access · 566411ed
    Chenbo Feng authored
    Add a new set of sepolicy for the process that only netd use to load
    and run ebpf programs. It is the only process that can load eBPF
    programs into the kernel and is only used to do that. Add some
    neverallow rules regarding which processes have access to bpf objects.
    
    Test: program successfully loaded and pinned at sys/fs/bpf after device
    boot. No selinux violation for bpfloader
    Bug: 30950746
    
    Change-Id: Ia6bb1afda29ae0749bdc368e2dfc5faa12e81b2f
    566411ed