Skip to content

Conversation

Danny-Wei
Copy link
Member

@Danny-Wei Danny-Wei commented Sep 23, 2025

What this PR does

Modifies the built-in-rules.json file used by Policy Advisor to add BPF enforcer-compatible permission aliases (e.g., write, append) to file rule permissions fields. This enables the Policy Advisor to correctly parse behavior data collected by the BPF enforcer with the BehaviorModeling mode, ensuring it can generate valid policy templates.

Key Features Added

Updated file rule permissions arrays in built-in-rules.json to include both AppArmor-style abbreviations and BPF-compatible full names.

@Danny-Wei Danny-Wei changed the title feat: policy-advisor can use the behavior data of bpf enforcer to generate policy template feat: Update built-in-rules.json to Support BPF Enforcer Behavior Modeling Data Sep 23, 2025
@Danny-Wei Danny-Wei changed the title feat: Update built-in-rules.json to Support BPF Enforcer Behavior Modeling Data Update built-in-rules.json to Support BPF Enforcer Behavior Modeling Data Sep 23, 2025
@Danny-Wei Danny-Wei added this to the v0.9 milestone Sep 23, 2025
@Danny-Wei Danny-Wei merged commit 5fefbd7 into main Sep 24, 2025
6 checks passed
@Danny-Wei Danny-Wei added the feature New feature label Oct 20, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

feature New feature

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants