About this project
ebpf-go is a pure Go library from Cilium that provides utilities for loading, compiling, and debugging eBPF programs. It has minimal external dependencies and is intended for use in long-running processes.
The library includes several packages:
- asm: a basic assembler for writing eBPF assembly instructions directly in Go code
- cmd/bpf2go: compiles and embeds eBPF programs written in C within Go code, auto-generating Go code for loading and manipulating eBPF programs and map objects
- link: attaches eBPF programs to various kernel hooks
- perf: reads from PERF_EVENT_ARRAY
- ringbuf: reads from BPF_MAP_TYPE_RINGBUF maps
- features: discovers BPF-related kernel features using native Go, equivalent to bpftool feature probe
- rlimit: lifts the RLIMIT_MEMLOCK constraint on kernels before 5.11
- btf: reads the BPF Type Format
- pin: works with pinned objects on bpffs
The project supports Linux (amd64, arm64) with kernel.org LTS releases, and Windows (amd64) via eBPF for Windows. Other architectures are best effort, and 32-bit architectures are not supported. The library is licensed under MIT and is part of the wider eBPF ecosystem documented at ebpf.io.
Comments
0 people shared their preference · Deer Point appears after 10 participants
Sign in to join the discussion.