Skip to content
Snippets Groups Projects
Commit cbaad76d authored by Chenbo Feng's avatar Chenbo Feng Committed by android-build-merger
Browse files

Fix sepolicy for bpf object am: bfa95fcd

am: 585b3bcf

Change-Id: I214e9ab30d322398757761da46879ab3685f5fdb
parents a6b8414b 585b3bcf
No related branches found
No related tags found
No related merge requests found
...@@ -13,8 +13,7 @@ allow bpfloader fs_bpf:dir create_dir_perms; ...@@ -13,8 +13,7 @@ allow bpfloader fs_bpf:dir create_dir_perms;
allow bpfloader fs_bpf:file create_file_perms; allow bpfloader fs_bpf:file create_file_perms;
allow bpfloader devpts:chr_file { read write }; allow bpfloader devpts:chr_file { read write };
# TODO: unknown fd pass denials, need further investigation. allow bpfloader netd:fd use;
dontaudit bpfloader netd:fd use;
# Use pinned bpf map files from netd. # Use pinned bpf map files from netd.
allow bpfloader netd:bpf { map_read map_write }; allow bpfloader netd:bpf { map_read map_write };
......
...@@ -749,8 +749,8 @@ with_asan(` ...@@ -749,8 +749,8 @@ with_asan(`
# allow system_server to read the eBPF maps that stores the traffic stats information amd clean up # allow system_server to read the eBPF maps that stores the traffic stats information amd clean up
# the map after snapshot is recorded # the map after snapshot is recorded
allow system_server fs_bpf:file write; allow system_server fs_bpf:file read;
allow system_server netd:bpf { map_read map_write }; allow system_server netd:bpf map_read;
# ART Profiles. # ART Profiles.
# Allow system_server to open profile snapshots for read. # Allow system_server to open profile snapshots for read.
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment