π€ AI Summary
This work addresses silent errors in eBPF applications caused by type inconsistencies across the kernel, user-space loaders, and shared maps. To resolve this, the authors propose KernelScript, a domain-specific language featuring the first cross-boundary type system that uniformly models maps, program handles, and execution contexts, ensuring type safety within a single source. KernelScript integrates seamlessly with the libbpf toolchain through a typed DSL design, cross-boundary type checking, and C code generation. Evaluation on 43 eBPF workloads demonstrates that KernelScript detects cross-boundary errors at compile time that standard C/libbpf implementations miss, reduces cross-component code changes by a factor of five, and produces code fully compatible with the existing eBPF ecosystem.
π Abstract
eBPF lets developers extend Linux with custom packet processing, tracing, and scheduling logic, and a verifier proves before execution that the code will not crash the kernel. The programming model, however, is fragmented: a single application spans kernel code, a userspace loader, and shared maps, yet the relationships among these pieces go unchecked. E.g. A map or event type defined differently on each side silently corrupts shared state. We observe that these cross-boundary relationships duplicate information that a type system can unify. We present KernelScript, a DSL that types maps, program handles, and execution domains in one source, then compiles to standard C through the original toolchain. We evaluate KernelScript on 43 eBPF workloads covering XDP, TC, kprobe, tracepoint, and struct_ops. KernelScript rejects cross-boundary bugs at compile time that standard C/libbpf still builds and loads, a unified source shrinks the diffs for cross-boundary changes by 5x, and generated code remains compatible with the existing toolchain.