Merge "Set /proc/sys/net/core/bpf_jit_{enable,kallsyms} to 1"
diff --git a/bpfloader/bpfloader.rc b/bpfloader/bpfloader.rc
index 4404c17..e8da02d 100644
--- a/bpfloader/bpfloader.rc
+++ b/bpfloader/bpfloader.rc
@@ -31,3 +31,11 @@
#
rlimit memlock 1073741824 1073741824
oneshot
+
+# Need to make sure this runs *before* the bpfloader.
+on early-init
+ # Enable the eBPF JIT -- but do note that it is likely already force enabled
+ # by the kernel config option BPF_JIT_ALWAYS_ON
+ write /proc/sys/net/core/bpf_jit_enable 1
+ # Enable JIT kallsyms export for privileged users only
+ write /proc/sys/net/core/bpf_jit_kallsyms 1