Merge "Set /proc/sys/net/core/bpf_jit_{enable,kallsyms} to 1"
diff --git a/bpfloader/bpfloader.rc b/bpfloader/bpfloader.rc
index 4404c17..e8da02d 100644
--- a/bpfloader/bpfloader.rc
+++ b/bpfloader/bpfloader.rc
@@ -31,3 +31,11 @@
     #
     rlimit memlock 1073741824 1073741824
     oneshot
+
+# Need to make sure this runs *before* the bpfloader.
+on early-init
+    # Enable the eBPF JIT -- but do note that it is likely already force enabled
+    # by the kernel config option BPF_JIT_ALWAYS_ON
+    write /proc/sys/net/core/bpf_jit_enable 1
+    # Enable JIT kallsyms export for privileged users only
+    write /proc/sys/net/core/bpf_jit_kallsyms 1