eBPF
Running verified programs inside the kernel to observe and steer it: hooks and program types, maps, the verifier's safety model, tracing, XDP and tc networking, and the libbpf and bcc toolchains. Interviewers ask because eBPF now sits under modern observability, service meshes, and runtime security, so knowing it means knowing how those products actually work.
on this pageshowhide
explore
- Verifier and Safety Model6 questions
- Program Types and Hooks5 questions
- Maps and Helpers5 questions
- Tracing and Observability5 questions
- Networking: XDP and tc6 questions
- Tooling: libbpf and bcc6 questions
questions
page 2 of 2In eBPF, a cgroup program and a BPF LSM program both sit outside the tracing hooks and both can make the kernel refuse an operation. What does each one attach to, and what does its return value control?
basics
~20 sA cgroup program attaches to a cgroup v2 directory and governs every process inside it; a BPF LSM program attaches to a kernel security hook. In both cases the return value decides whether the kernel allows the operation to proceed.
You want to time a function inside a running user-space application using bpftrace's `uprobe` and `uretprobe` probes. How does a uprobe actually attach to the process, roughly what does each hit cost compared with a kernel tracepoint, and which kinds of binary make this approach unreliable?
basics
~20 sA uprobe patches a breakpoint instruction into a private copy of the target's executable page, so every thread that reaches that address traps into the kernel and runs the BPF program. Each hit costs roughly a microsecond, far more than a tracepoint. Stripped, statically linked, Go and JIT-compiled binaries make it unreliable.
Most Linux distributions ship with unprivileged eBPF disabled via kernel.unprivileged_bpf_disabled. If the verifier already proves every program safe, why is unprivileged loading turned off, and how would you decide what privileges to grant eBPF tooling across a fleet?
basics
~20 sThe verifier proves architectural safety, not speculative-execution safety, and it is itself a large piece of attack surface whose bugs have been privilege escalations. Distributions therefore disable unprivileged loading and expect eBPF tooling to run with CAP_BPF plus the capability its program type needs.
showing 31–33 of 33