skip to content

eBPF

Running verified programs inside the kernel to observe and steer it: hooks and program types, maps, the verifier's safety model, tracing, XDP and tc networking, and the libbpf and bcc toolchains. Interviewers ask because eBPF now sits under modern observability, service meshes, and runtime security, so knowing it means knowing how those products actually work.

on this pageshow

explore

questions

page 2 of 2

In eBPF, a cgroup program and a BPF LSM program both sit outside the tracing hooks and both can make the kernel refuse an operation. What does each one attach to, and what does its return value control?

level: seniorimportance: nice to knowfreq 28%

basics

~20 s

A cgroup program attaches to a cgroup v2 directory and governs every process inside it; a BPF LSM program attaches to a kernel security hook. In both cases the return value decides whether the kernel allows the operation to proceed.

open as a page

You want to time a function inside a running user-space application using bpftrace's `uprobe` and `uretprobe` probes. How does a uprobe actually attach to the process, roughly what does each hit cost compared with a kernel tracepoint, and which kinds of binary make this approach unreliable?

level: seniorimportance: nice to knowfreq 24%

basics

~20 s

A uprobe patches a breakpoint instruction into a private copy of the target's executable page, so every thread that reaches that address traps into the kernel and runs the BPF program. Each hit costs roughly a microsecond, far more than a tracepoint. Stripped, statically linked, Go and JIT-compiled binaries make it unreliable.

open as a page

Most Linux distributions ship with unprivileged eBPF disabled via kernel.unprivileged_bpf_disabled. If the verifier already proves every program safe, why is unprivileged loading turned off, and how would you decide what privileges to grant eBPF tooling across a fleet?

level: principalimportance: nice to knowfreq 26%

basics

~20 s

The verifier proves architectural safety, not speculative-execution safety, and it is itself a large piece of attack surface whose bugs have been privilege escalations. Distributions therefore disable unprivileged loading and expect eBPF tooling to run with CAP_BPF plus the capability its program type needs.

open as a page

showing 31–33 of 33