About this project

ebpf-go is a pure Go library from Cilium that provides utilities for loading, compiling, and debugging eBPF programs. It has minimal external dependencies and is intended for use in long-running processes. The library includes several packages: - asm: a basic assembler for writing eBPF assembly instructions directly in Go code - cmd/bpf2go: compiles and embeds eBPF programs written in C within Go code, auto-generating Go code for loading and manipulating eBPF programs and map objects - link: attaches eBPF programs to various kernel hooks - perf: reads from PERF_EVENT_ARRAY - ringbuf: reads from BPF_MAP_TYPE_RINGBUF maps - features: discovers BPF-related kernel features using native Go, equivalent to bpftool feature probe - rlimit: lifts the RLIMIT_MEMLOCK constraint on kernels before 5.11 - btf: reads the BPF Type Format - pin: works with pinned objects on bpffs The project supports Linux (amd64, arm64) with kernel.org LTS releases, and Windows (amd64) via eBPF for Windows. Other architectures are best effort, and 32-bit architectures are not supported. The library is licensed under MIT and is part of the wider eBPF ecosystem documented at ebpf.io.