KernelScript: Cross-Boundary Typed DSL for eBPF Applications

πŸ“… 2026-07-26
πŸ“ˆ Citations: 0
✨ Influential: 0
πŸ“„ PDF
πŸ€– AI Summary
This work addresses silent errors in eBPF applications caused by type inconsistencies across the kernel, user-space loaders, and shared maps. To resolve this, the authors propose KernelScript, a domain-specific language featuring the first cross-boundary type system that uniformly models maps, program handles, and execution contexts, ensuring type safety within a single source. KernelScript integrates seamlessly with the libbpf toolchain through a typed DSL design, cross-boundary type checking, and C code generation. Evaluation on 43 eBPF workloads demonstrates that KernelScript detects cross-boundary errors at compile time that standard C/libbpf implementations miss, reduces cross-component code changes by a factor of five, and produces code fully compatible with the existing eBPF ecosystem.
πŸ“ Abstract
eBPF lets developers extend Linux with custom packet processing, tracing, and scheduling logic, and a verifier proves before execution that the code will not crash the kernel. The programming model, however, is fragmented: a single application spans kernel code, a userspace loader, and shared maps, yet the relationships among these pieces go unchecked. E.g. A map or event type defined differently on each side silently corrupts shared state. We observe that these cross-boundary relationships duplicate information that a type system can unify. We present KernelScript, a DSL that types maps, program handles, and execution domains in one source, then compiles to standard C through the original toolchain. We evaluate KernelScript on 43 eBPF workloads covering XDP, TC, kprobe, tracepoint, and struct_ops. KernelScript rejects cross-boundary bugs at compile time that standard C/libbpf still builds and loads, a unified source shrinks the diffs for cross-boundary changes by 5x, and generated code remains compatible with the existing toolchain.
Problem

Research questions and friction points this paper is trying to address.

eBPF
cross-boundary
type system
kernel programming
shared state
Innovation

Methods, ideas, or system contributions that make the work stand out.

eBPF
type system
domain-specific language
cross-boundary verification
KernelScript
πŸ”Ž Similar Papers
2024-04-30International Symposium on Recent Advances in Intrusion DetectionCitations: 0