Had some free time last week so I made a visual explainer on how eBPF lets Linux run user-loaded code inside the kernel.
It follows a small program through Clang, the
bpf() syscall, the verifier, JIT compilation, attach points, maps and ring buffers.It also covers bpftrace, XDP, BPF LSM, sched_ext, and what happens when the verifier gets it wrong.
link for anyone interested
Feedback welcome :)
https://redd.it/1uzojc6
@r_linux