Skip to content
Snippets Groups Projects
  • Chenbo Feng's avatar
    Allow netutils_wrapper to use pinned bpf program · 2623ebcf
    Chenbo Feng authored
    The netutils_wrapper is a process used by vendor code to update the
    iptable rules on devices. When it update the rules for a specific chain.
    The iptable module will reload the whole chain with the new rule. So
    even the netutils_wrapper do not need to add any rules related to xt_bpf
    module, it will still reloading the existing iptables rules about xt_bpf
    module and need pass through the selinux check again when the rules are
    reloading. So we have to grant it the permission to reuse the pinned
    program in fs_bpf when it modifies the corresponding iptables chain so
    the vendor module will not crash anymore.
    
    Test: device boot and no more denials from netutils_wrapper
    Bug: 72111305
    Change-Id: I62bdfd922c8194c61b13e2855839aee3f1e349be
    2623ebcf