5–7 Oct 2026
Europe/Prague timezone

BPF FD Loader: Integrity-Verified BPF on Android

5 Oct 2026, 10:45
15m
"Club E" (Prague Congress Centre)

"Club E"

Prague Congress Centre

128
Android MC Android MC

Speaker

Siddharth Nayyar (Google)

Description

On modern Android devices, eBPF loading is strictly confined to early boot by a privileged loader alongside SELinux lockdown of BPF_PROG_LOAD. While this protects the kernel attack surface, it leaves the platform fundamentally rigid: platform services and hardware partners cannot deploy or activate BPF programs on demand. Furthermore, the approach of individual cryptographic signature verification fails in a decentralised client ecosystem comprising several SoC vendors, OEMs, and partners, where managing runtime key-rings in the Generic Kernel Image (GKI) imposes an unsustainable operational burden.

To address this, we introduce the BPF FD Loader driver in Android. Inspired by finit_module(), it allows the kernel to load BPF programs directly from verified file descriptors rather than untrusted userspace memory.

Because BPF lacks an in-kernel linker, our solution leverages upstream BPF Light Skeletons. At runtime, an authorised userspace daemon simply passes an open file descriptor of this ELF to the Android driver via ioctl(). The kernel driver reads the backing file directly before executing the loader, verifying that it originates from an authenticated, read-only partition sealed by Android Verified Boot (AVB) and dm-verity.

In this talk, we present the end-to-end architecture and discuss our roadmap towards standardising file-based BPF loading in the Android ecosystem.

Authors

Presentation materials