logoalt Hacker News

tptacektoday at 4:36 PM1 replyview on HN

eBPF's limitations are as much about reliability as security. The bounded loop restriction, for instance, prevents eBPF programs from locking up your machine.


Replies

loegtoday at 5:45 PM

You could still imagine terminating these programs after some bounded time or cycle count. It isn't as good as static verification, but it's certainly more flexible.

show 1 reply