Withdraw my recommendation about BPF_JIT
CLIP OS wiki and Kees say that BPF interpreter is worse for the kernel security than BPF_JIT. So for now I withdraw my recommendation about BPF_JIT. N.B. LOCKDOWN disables BPF_SYSCALL, but not BPF_JIT.
Showing
Please
register
or
sign in
to comment