- 23871ea selinux: bpfloader: add fs_bpf:dir read and open by Neill Kapron · 9 months ago
- 28960d3 allow non bpfloader creation of bpf maps by Maciej Żenczykowski · 2 years, 3 months ago
- ea1bd5d lmkd: Add sepolicy rules around bpf for lmkd by Carlos Galo · 1 year, 6 months ago
- 3230efb Merge "bpfloader: allow bpffs_type:dir setattr" into main by Treehugger Robot · 1 year, 6 months ago
- 93a3d62 bpfloader: allow bpffs_type:dir setattr by Maciej Żenczykowski · 1 year, 6 months ago
- 446c8c0 bpfloader: allowing reading proc_bpf:file by Maciej Żenczykowski · 1 year, 6 months ago
- f83e395 bpfloader - relax neverallows for map_read/write/prog_run by Maciej Żenczykowski · 1 year, 6 months ago
- 37ca69e sepolicy: allow netutils_wrapper access to fs_bpf_vendor by Maciej Żenczykowski · 1 year, 10 months ago
- baea641 Rename uprobe_private to uprobestats for BPFs. by Yu-Ting Tseng · 1 year, 8 months ago
- 3e8e8ea Revert "Revert "SELinux policy changes for uprobe."" by Yu-Ting Tseng · 2 years ago
- 52c8a2e netd/netutils_wrapper/network_stack/system_server - allow getattr on bpf progs/maps by Maciej Żenczykowski · 2 years, 5 months ago
- 39617ac Merge "sepolicy - move proc bpf writes from bpfloader.rc to bpfloader binary" by Treehugger Robot · 2 years, 9 months ago
- 4a96086 sepolicy - move proc bpf writes from bpfloader.rc to bpfloader binary by Maciej Żenczykowski · 2 years, 9 months ago
- 9a76805 bpf - neverallow improvements/cleanups by Maciej Żenczykowski · 2 years, 9 months ago
- e14e69a add fs_bpf_loader selinux type by Maciej Żenczykowski · 2 years, 9 months ago
- ebb45f9 remove init/vendor_init access to bpffs_type by Maciej Żenczykowski · 2 years, 9 months ago
- d5098f9 allow bpfloader to create symbolic links in /sys/fs/bpf by Maciej Żenczykowski · 3 years, 2 months ago
- 1fcf7c8 selinux: allow bpfloader bpffs_type:file getattr by Maciej Żenczykowski · 3 years, 2 months ago
- b13921c much more finegrained bpf selinux privs for networking mainline by Maciej Żenczykowski · 3 years, 4 months ago
- 52862a3 Add sepolicies to allow hal_health_default to load BPFs. by Stephane Lee · 3 years, 6 months ago
- 6598175 bpfdomain: attribute for domain which can use BPF by Steven Moreland · 3 years, 7 months ago
- c27d24c Allow BPF programs from vendor. by Steven Moreland · 6 years ago
- 233d4aa bpfloader: use kernel logs by Steven Moreland · 3 years, 7 months ago
- dbe2684 Allow bpfloader to execute btfloader by Connor O'Brien · 3 years, 8 months ago
- fd3e9d8 mediaprovider_app can access BPF resources by Alessio Balsini · 3 years, 10 months ago
- e3e26b7 Allow bpfloader to read fuse's bpf_prog number by Paul Lawrence · 3 years, 10 months ago
- 3702f33 introduce new 'proc_bpf' for bpf related sysctls by Maciej Żenczykowski · 3 years, 10 months ago
- ea2941b sepolicy: Allow lmkd to access bpf map to read GPU allocation statistics by Suren Baghdasaryan · 4 years, 3 months ago
- 94c3068 grant bpfloader NET_ADMIN capability by Maciej Żenczykowski · 4 years, 6 months ago
- d68cb48 apply 'fs_bpf_tethering' label to /sys/fs/bpf/tethering by Maciej Żenczykowski · 4 years, 7 months ago
- 8c11cc3 bpfloader.te - allow creation of subdirectories of /sys/fs/bpf by Maciej Żenczykowski · 4 years, 8 months ago
- 48c600f Allow network_stack to update eBPF map by markchien · 4 years, 10 months ago
- ef76c53 grant bpfloader ability to fetch the fd of pinned bpf programs by Maciej Żenczykowski · 5 years ago
- 4b63ce9 GPU Memory: add sepolicy rules around bpf for gpuservice by Yiwei Zhang · 6 years ago
- 49c73b0 cut down bpf related privileges by Maciej Żenczykowski · 6 years ago
- 1189fac grant bpfloader CAP_CHOWN by Maciej Żenczykowski · 6 years ago
- e3f0b2c Allow system_server to attach bpf programs to tracepoints by Connor O'Brien · 6 years ago
- 487fcb8 selinux - netd - tighten down bpf policy by Maciej Żenczykowski · 6 years ago
- b76a639 Add permissions for bpf.progs_loaded property by Joel Fernandes · 7 years ago
- 147cf64 Allow executing bpfloader from init and modify rules by Joel Fernandes · 7 years ago
- 4bf4788 Assign bpfloader with CAP_SYS_ADMIN by Joel Fernandes · 7 years ago
- 7b57104 Use bpfloader to create bpf maps instead of netd by Chenbo Feng · 7 years ago
- 5e37271 Introduce system_file_type by Nick Kralevich · 7 years ago
- 095fbea Strengthen ptrace neverallow rules by Nick Kralevich · 7 years ago
- 7ed266c sepolicy: Fix references to self:capability by Benjamin Gordon · 7 years ago
- d65f26f Hide bpfloader sys_admin denials. by Joel Galenson · 7 years ago
- be9b15c Allow netutils_wrapper to use pinned bpf program by Chenbo Feng · 7 years ago
- 68ef8c0 Allow netd to setup xt_bpf iptable rules by Chenbo Feng · 7 years ago
- 6cd70c2 Fix sepolicy for bpf object by Chenbo Feng · 8 years ago
- 566411e Add sepolicy to lock down bpf access by Chenbo Feng · 8 years ago