io_uring and eBPF are changing Linux programs
Summary
Pekka Enberg and Glauber Costa explain how io_uring and eBPF reduce system calls and run safe programs closer to the kernel. io_uring first appeared in Linux 5.1. eBPF evolved from the Berkeley Packet Filter.
Ideas
- io_uring exchanges submissions and results via shared ring buffers.
- Batched operations reduce switches between user space and kernel.
- eBPF loads verified programs at selected kernel hooks.
- Maps transfer state between BPF programs and applications.
Insights
- Programmable kernel paths shift the boundary between operating system and application.
- Shared memory increases performance and requires careful lifecycle rules.
- A verifier does not replace every run-time and permission check.
Facts
- Both interfaces are controlled via normal Linux system calls.
Recommendations
- Restrict eBPF privileges to the administrator roles that need them.
- Measure queue depth and latency rather than just maximum throughput.
References
Links to the original source and the Web Archive open in a new tab.