Skip to content

Comment on eBPF Verification Is Untenableparent

Comments

Ok but you can like put a tracepoint on read/write and peek at what’s going through those, no?

Nope. Tracepoint eBPF programs require root to load always. For eBPF you select a program type, and that limits what you can do (aka what helper functions are available to you) and what privileges are required.

I have no idea, because every system I've ever worked on has disabled unprivileged eBPF.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.