Libbpf and Linux Kernel Verifier Compatibility for Unprivileged BPF Loading
29.5K reputation · 14 Sept 2020, 18:40 UTC
The goal is to establish whether a given libbpf release can successfully load an unprivileged BPF program that employs CO-RE relocations on a running Linux kernel, taking into account the kernel.unprivileged_bpf_disabled sysctl setting.
Constraints include the kernel version threshold for unprivileged loading (≥5.8 when the sysctl is 0), the verifier tightening introduced in kernels 5.10 and later that may reject programs accepted on earlier releases, the requirement for BTF support (available from kernel 5.4 with CONFIG_DEBUG_INFO_BTF enabled) for CO-RE relocations, the need for clang headers matching the kernel to avoid struct layout mismatches, and the possibility that distribution kernels backport verifier fixes, creating version‑skew uncertainty.
Which minimum kernel version satisfies both the unprivileged loading sysctl and BTF availability for libbpf X.Y?
How does the verifier behavior change between kernel 5.9 and 5.10 affect the acceptability of CO-RE BPF programs compiled with libbpf X.Y?
What steps can be taken to verify that a specific libbpf/kernel/clang combination will allow unprivileged CO-RE program loading without relying on trial and error?