bk99.de entertain the web since 1997

io_uring and eBPF are changing Linux programs

Summary

Pekka Enberg and Glauber Costa explain how io_uring and eBPF reduce system calls and run safe programs closer to the kernel. io_uring first appeared in Linux 5.1. eBPF evolved from the Berkeley Packet Filter.

Ideas

  • io_uring exchanges submissions and results via shared ring buffers.
  • Batched operations reduce switches between user space and kernel.
  • eBPF loads verified programs at selected kernel hooks.
  • Maps transfer state between BPF programs and applications.

Insights

  • Programmable kernel paths shift the boundary between operating system and application.
  • Shared memory increases performance and requires careful lifecycle rules.
  • A verifier does not replace every run-time and permission check.

Facts

  • Both interfaces are controlled via normal Linux system calls.

Recommendations

  • Restrict eBPF privileges to the administrator roles that need them.
  • Measure queue depth and latency rather than just maximum throughput.

References

Read the original article

Search the Web Archive