eBPF Userspace API¶
eBPF is a kernel mechanism to provide a sandboxed runtime environment in the Linux kernel for runtime extension and instrumentation without changing kernel source code or loading kernel modules. eBPF programs can be attached to various kernel subsystems, including networking, tracing and Linux security modules (LSM).
For internal kernel documentation on eBPF, see BPF Documentation.