How eBPF Works

Load a sandboxed program, prove it safe, JIT it, and attach it to a kernel hook

How eBPF Works Load a sandboxed program, prove it safe, JIT it, and attach it to a kernel hook User Space Linux Kernel Loader · libbpf / bcc · User Space Loader libbpf / bcc User-Space App · reads results · User Space User-Space App reads results Verifier · proves safety · Linux Kernel Verifier proves safety JIT Compiler · bytecode to native · Linux Kernel JIT Compiler bytecode to native eBPF Program · runs in kernel · Linux Kernel eBPF Program runs in kernel Maps · kernel to user · Linux Kernel Maps kernel to user Tracepoints / kprobes · observability · Linux Kernel Tracepoints / kprobes observability XDP / TC · networking · Linux Kernel XDP / TC networking LSM / seccomp · security · Linux Kernel LSM / seccomp security load bytecode if safe JIT + attach runs on event read / write results Legend Backend Frontend Security Database

Programs, not modules

  • • You write a small program that runs in the kernel
  • • Loaded at runtime — no kernel rebuild or reboot
  • • The same model powers tracing, networking, and security

Safe by verification

  • • The verifier proves the program can't crash or loop forever
  • • Rejected programs never run — safety is checked before load
  • • This is why running kernel code is safe

Maps share state

  • • Maps are the channel between kernel program and user space
  • • The program writes results; the app reads them
  • • No copying the whole kernel's data out — just what you need