{"repo":"dropbox/goebpf","free":true,"listed":false,"github":"https://github.com/dropbox/goebpf","clone":"git clone https://github.com/dropbox/goebpf.git","description":"Library to work with eBPF programs from Go","language":"Go","stars":1168,"topics":["ebpf","golang","xdp","bpf","perfevents","go","golang-library","xdpdump","cats","cats-effect"],"license":null,"category":"dev-tools","readme_excerpt":"Go eBPF A nice and convenient way to work with eBPF programs / perf events from Go. Requirements - Go 1.11+ - Linux Kernel 4.15+ Supported eBPF features - eBPF programs - SocketFilter - XDP - Kprobe / Kretprobe - tc-cls ( tc-act is partially implemented, currently) - Perf Events Support for other program types / features can be added in future. Meanwhile your contributions are warmly welcomed.. :) Installation Quick start Consider very simple example of Read / Load / Attach Like it? Check our examples Perf Events Currently library has support for one, most popular use case of perf events: where eBPF map key maps to cpu id . So eBPF and go parts actually bind cpu id to map index. It maybe as simple as: And the go part: Looks simple? Check our full XDP dump example Kprobes Library currently has support for kprobes and kretprobes . It can be as simple as: And the go part: Simple? Check exec dump example Good readings - XDP Tutorials - Cilium BPF and XDP Reference Guide - Prototype Kernel: XDP - AF XDP: Accelerating networking - eBPF, part 1: Past, Present, and Future - eBPF, part 2: Syscall and Map Types - Oracle Blog: A Tour of eBPF Program Types - Oracle Blog: eBPF Helper Functions - Oracle Blog: Communicating with Userspace","default_branch":null,"files":null,"tree":[],"storefront":"/r/dropbox","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/dropbox/goebpf/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}