eBPF
A verified in-kernel execution technology that lets programs attach to Linux events for observability, networking, security, and controlled packet or system-call processing.
Linux Context
eBPF executes verifier-approved programs at selected kernel attachment points and can be JIT-compiled to native instructions. Maps provide structured data exchange between kernel and user space, while program types such as kprobe, tracepoint, socket, and XDP support observability, networking, and security use cases.
Kernel Boundary
eBPF is not equivalent to loading an unrestricted kernel module. The verifier, helper and kfunc interfaces, attachment model, privileges, and kernel configuration are part of the execution and security boundary.
Related Linux Concepts
- XDP
- BPF Map
- Tracing
- Kernel
Source
- https://docs.kernel.org/bpf/