Skip to content
Snippets Groups Projects
Commit 5f4de67d authored by Chenbo Feng's avatar Chenbo Feng Committed by android-build-merger
Browse files

Fix sepolicy for bpf object am: bfa95fcd am: 585b3bcf

am: cbaad76d

Change-Id: I62c082e6691544cea974a80d5f56164d44c4e496
parents daf1cdfa cbaad76d
No related branches found
No related tags found
No related merge requests found
...@@ -13,8 +13,7 @@ allow bpfloader fs_bpf:dir create_dir_perms; ...@@ -13,8 +13,7 @@ allow bpfloader fs_bpf:dir create_dir_perms;
allow bpfloader fs_bpf:file create_file_perms; allow bpfloader fs_bpf:file create_file_perms;
allow bpfloader devpts:chr_file { read write }; allow bpfloader devpts:chr_file { read write };
# TODO: unknown fd pass denials, need further investigation. allow bpfloader netd:fd use;
dontaudit bpfloader netd:fd use;
# Use pinned bpf map files from netd. # Use pinned bpf map files from netd.
allow bpfloader netd:bpf { map_read map_write }; allow bpfloader netd:bpf { map_read map_write };
......
...@@ -749,8 +749,8 @@ with_asan(` ...@@ -749,8 +749,8 @@ with_asan(`
# allow system_server to read the eBPF maps that stores the traffic stats information amd clean up # allow system_server to read the eBPF maps that stores the traffic stats information amd clean up
# the map after snapshot is recorded # the map after snapshot is recorded
allow system_server fs_bpf:file write; allow system_server fs_bpf:file read;
allow system_server netd:bpf { map_read map_write }; allow system_server netd:bpf map_read;
# ART Profiles. # ART Profiles.
# Allow system_server to open profile snapshots for read. # Allow system_server to open profile snapshots for read.
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment