Sign in

Paul Chaignon

@pchaigno.bsky.social
188 followers 32 following 106 posts

System security, eBPF, and programmable networks. Working on Cilium's BPF-based datapath. He/him.

PostsRepliesMedia
Paul Chaignon @pchaigno.bsky.social · 23h
Tal Zussman presented bpf_fault at SOSP, the top OS research conference. bpf_fault enables custom page fault handling in the kernel with x6.7 lower latency than the existing userspace solution. Slides: talzussman.com/slides/bpf_f... Paper: dl.acm.org/doi/pdf/10.1... Code: github.com/bpf-fault/bp...
Slide showing how bpf_fault works: a page fault triggers the BPF program, which writes directly into the newly-allocated page.
121
Paul Chaignon @pchaigno.bsky.social · 01/10/2026
I thought sched_ext would give birth to many highly-specialized CPU schedulers. LAVD is proving me wrong by optimizing both gaming and cloud workloads. At @kernelrecipes.bsky.social, Changwoo Min and Gavin Guo present its design and how this was made possible.
Screenshot of the slide showing the domains where LAVD has been and could be used. It started with gaming, has expanded to server fleets, and may be used for AI workloads in the future.
110
Paul Chaignon @pchaigno.bsky.social · 25/09/2026
eBPF programs will be able to use 2048 bytes of stack starting with Linux v7.4! lore.kernel.org/all/20260924...
Screenshot of the new constant holding the 2048 bytes limit from commit ecc441fc774e ("bpf: Size the per-frame verifier structures for a 2 KiB stack").
162
Paul Chaignon @pchaigno.bsky.social · 22/09/2026
New #eBPF ideas merged upstream sometimes take years before they are discovered, reused, and improved by the research community. I didn't want that for netkit, so I proposed writing a paper about it to Daniel. I'll present it at the eBPF workshop next week! pchaigno.github.io/ebpf/2026/09...
pchaigno.github.io
netkit: Specializing Linux Packet Delivery for Container Networks
This post summarizes our netkit paper from the eBPF’26 workshop at ACM SOSP. The netkit paper proposes an eBPF-based datapath to specialize the Linux networking stack and eliminate redundant backlog q...
033
Paul Chaignon @pchaigno.bsky.social · 15/09/2026
We're very lucky to have Dan Williams give the keynote talk at the #eBPF workshop this year! The tentative schedule: ebpf.github.io/2026/schedul....
ebpf.github.io
eBPF'26 — Schedule
Schedule for the fourth eBPF workshop at ACM SOSP, with the papers, their authors, and abstracts.
110
Paul Chaignon @pchaigno.bsky.social · 15/09/2026
AF_XDP copy mode has received less attention than its zero-copy mode. At Netdev 0x1A, Jason Xing showed how he almost doubled the performance of AF_XDP copy mode after methodically profiling it! Slides: netdevconf.info/0x1A/docs/ne... Recording: www.youtube.com/watch?v=nmyu...
Slide showing the second patch sent by Jason Wing, to use more fine-grained locks.
020
Paul Chaignon @pchaigno.bsky.social · 14/09/2026
I've added 25 papers to my list of #eBPF research papers: pchaigno.github.io/bpf/2025/01/...! It includes some papers I had missed, but now also counts papers from additional conferences (hidden by default), such as EuroSys, Usenix ATC, and OOPSLA.
pchaigno.github.io
eBPF Research Papers
Interactive list of eBPF research papers from top conferences according to CSRankings. The list can be filtered according to types of publications (ex., improving, using) and areas (ex., networking, v...
110
Paul Chaignon @pchaigno.bsky.social · 09/09/2026
Now that the camera-ready for SOSP'26 has passed, a lot of papers have their final titles and preprint uploaded! I've updated my list at pchaigno.github.io/academic/202... with the up-to-date info.
pchaigno.github.io
ACM SOSP’26 Papers & Preprints
This post lists the accepted papers at ACM SOSP 2026, along with their preprint version when one was found. An illustration bar plot also shows the distribution of papers across research areas.
010
Paul Chaignon @pchaigno.bsky.social · 03/09/2026
The eBPF Foundation's Research Grant program has run for just 3 years, yet it has already been acknowledged in 9 papers it supported: scholar.google.com/scholar?hl=e.... Most of these have been published in the top conferences and workshops of their field!
Photo of some of the eBPF papers acknowledging the eBPF Foundation research grant.
120
Paul Chaignon @pchaigno.bsky.social · 07/08/2026
The schedule for the #eBPF track at Linux Plumbers 2026 is live: lpc.events/event/20/ses.... Another reason to come to Prague in fall!
lpc.events
Linux Plumbers Conference 2026
The Linux Plumbers Conference (LPC) is a developer conference for the open source community. The LPC brings together the top developers working on the plumbing of Linux - kernel subsys...
030
Paul Chaignon @pchaigno.bsky.social · 07/08/2026
We've published the list of papers and posters accepted at the 4th eBPF workshop, colocated with SOSP'26: ebpf.github.io/2026/papers..... See you all in Prague in September!
Screenshot of the list of accepted papers, with their titles and authors. The accepted posters are not shown on this image.
030
Paul Chaignon @pchaigno.bsky.social · 03/08/2026
SOSP'26, which will host the eBPF workshop this year, published its list of accepted papers. I reproduced the list on my blog to complement it with all the preprints I could find: pchaigno.github.io/academic/202.... Happy reading!
pchaigno.github.io
ACM SOSP’26 Papers & Preprints
This post lists the accepted papers at ACM SOSP 2026, along with their preprint version when one was found. An illustration bar plot also shows the distribution of papers across research areas.
042
Paul Chaignon @pchaigno.bsky.social · 03/08/2026
I had missed that the program and slides of bpfconf 2026 had been published at the beginning of summer: bpfconf.ebpf.io. This year there were talks on BPF Coroutines, KASAN support, backpressure support for sockmap, arena libraries, BPF signing, and a lot more.
120
Paul Chaignon @pchaigno.bsky.social · 31/07/2026
We've received 37 submissions for the eBPF workshop this year, up again from the previous year! We've accepted 15 submissions following the peer-review process. I can't wait to see everyone discuss their work in Prague!
Bar plot of the number of submitted and accepted papers across different research areas, including OS, networking, machine learning, security, compilation, and formal methods (ordered by occurrences in submissions). Each paper may span multiple research areas. Three papers are undergoing minor revisions.
160
Paul Chaignon @pchaigno.bsky.social · 20/07/2026
The program for USENIX Sec'26, one of the top security conferences, is public: www.usenix.org/conference/u...! As usual with security, the scope is large: from the privacy of LLMs to fuzzing for concurrency bugs in the kernel with eBPF, for a total of 364 papers.
Bar plot of the number of papers per topic at the conference. The classification was determined by the conference chairs. I did not include the Enigma talks as they don't have corresponding papers. In the Hardware Security track, 7 papers are still under embargo.
021
Paul Chaignon @pchaigno.bsky.social · 17/07/2026
The list of papers accepted at @sigcomm.bsky.social 2026 has been published: conferences.sigcomm.org/sigcomm/2026...! As usual with the top networking conference, the scope is large: networking for LLMs, certificate revocation in Firefox, end-host networking (inc. eBPF), DPUs, etc.
Bar plot of the SIGCOMM'26 topics, roughly (and manually) categorized based on the titles only. Take with a grain of salt. The sum adds up to more than 110 papers because some papers fit several categories.
000
Paul Chaignon @pchaigno.bsky.social · 16/07/2026
eBPF now has a new type of hashmap, resizable and sometimes drastically faster: lore.kernel.org/bpf/20260605...! I'm expecting it to be released in Linux v7.3. It might be time for some of us to replace our hashmaps.
Plot showing the throughput of lookup operations for both hashmaps, with varying key sizes and two load factors, 75% full and 100% full. The map has max_entries set to 1 million. For small key sizes, the new hashmap is several times faster. The difference lessens as the key size grows. All numbers are from the author of the patchset, Mykyta Yatsenko.
041
Paul Chaignon @pchaigno.bsky.social · 10/07/2026
Apparently, you can now also write BPF programs in Ruby: github.com/yuskesh/spin.... As with the similar Java project, it's actually transpiled to C before being compiled to #eBPF bytecode. People go to great length to keep writing in their favorite language 😅
Example XDP program written in Ruby.
040
Paul Chaignon @pchaigno.bsky.social · 25/06/2026
Tomorrow at 2:30pm, I'll present @cilium.io at the @breizhcamp.org (French) conference! I'll explain how Kubernetes network plugins work, how Cilium leverages #eBPF, and how to secure your cluster with Cilium. www.breizhcamp.org/programme/se...
Screenshot of the title slide for the talk, "Sécuriser son réseau Kubernetes avec Cilium".
021
Paul Chaignon @pchaigno.bsky.social · 11/06/2026
We're extending the deadline for the #eBPF workshop at SOSP'26 by one week, to Friday the 26th of June. That leaves two weeks to finalize your papers!
Screenshot of the Important Dates table from the workshop website.
023
Paul Chaignon @pchaigno.bsky.social · 13/05/2026
The Cilium community adopted a first version of a policy for Generative AI use: github.com/cilium/commu.... Hopefully, that sets clear guidelines and helps us move past the spammy interactions.
Screenshot of the Unacceptable Use section.
001
Paul Chaignon @pchaigno.bsky.social · 05/05/2026
After troubleshooting the BPF selftests one time too many, I decided to keep a few notes on how to solve each issue I encountered: pchaigno.github.io/ebpf/2026/05.... I hope it'll be useful to other Linux contributors!
Illustrative output from a working run of the BPF selftests.
000
Paul Chaignon @pchaigno.bsky.social · 04/05/2026
Running into stack size issues with #eBPF? My colleague Dylan Reimerink wrote a tool to figure out what is taking space on your stack! github.com/cilium/stack...
Example output from the stackwhere tool, showing the variables on the stack, their offset on the stack, how much space they are taking, and where they are declared in the source code.
020
Paul Chaignon @pchaigno.bsky.social · 20/04/2026
We published the Program Committee for the eBPF'26 workshop at SOSP! It highlights the diverse eBPF research community, with experts from networking, formal verification, OS research, security, and more, across both academia and industry. ebpf.github.io/2026
110
Paul Chaignon @pchaigno.bsky.social · 10/03/2026
I've updated the list of academic #eBPF papers with recent papers from SOSP'25, S&P'25, and CCS'25: pchaigno.github.io/bpf/2025/01/.... That makes 19 eBPF papers published in the top conferences in 2025 vs. 17 in 2024.
pchaigno.github.io
eBPF Research Papers
Interactive list of eBPF research papers from top conferences according to CSRankings. The list can be filtered according to types of publications (ex., improving, using) and areas (ex., networking, v...
121
Paul Chaignon @pchaigno.bsky.social · 04/03/2026
SOSP'26 published the list of accepted workshops for this year: sigops.org/s/conference...! Looks like the #eBPF workshop is in good company, in between HotStorage and PLOS 😄
Screenshot of the workshops page on the SOSP'26 website, showing the 11 accepted workshops, including HotStorage'26, eBPF'26, and PLOS'26.
043
Paul Chaignon @pchaigno.bsky.social · 24/02/2026
The call for papers for the eBPF'26 workshop is open: ebpf.github.io/2026/cfp.html. This year, the workshop will be hosted by the SOSP conference, the top academic conference in OS research! The deadline for submissions is June 19th, in just over 4 months.
Photo of Prague with the castle on the hill, taken by Wikimedia user Tilman2007 and licensed under CC BY-SA 4.0 (https://creativecommons.org/licenses/by-sa/4.0). Three eBPF bees are added on top, flying over the castle.
033
Paul Chaignon @pchaigno.bsky.social · 20/01/2026
Following our talk at Plumbers, we're starting a series of articles with Mahé Tardy on the state pruning optimization in the #eBPF verifier. I'm kicking off this series with a timeline of the main changes: pchaigno.github.io/ebpf/2026/01....
Screenshot of the top of the timeline, showing the first five commits. The timeline has release numbers, years, links to the commits and explanations. Some commits include a "Read more" link to a dedicated blog post.
111
Paul Chaignon @pchaigno.bsky.social · 20/01/2026
My colleague Mahé Tardy wrote a blog post covering state pruning points in the #eBPF verifier: mtardy.com/posts/prune-.... State pruning is an optimization to the eBPF verifier to help it scale to larger programs. Pruning points are instructions in the program where this optimization is triggered.
Figure from Mahé's blog post showing where pruning points are placed in case of jumps. The pruning points are the instructions with bold borders. They are typically placed on the target instruction for unconditional jumps as well as on the jump itself for conditional jumps.
030
Paul Chaignon @pchaigno.bsky.social · 20/01/2026
In his latest blog, @vincent.bernat.ch looked at how to load balance uneven traffic flows across multiple workers all listening on the same port: vincent.bernat.ch/en/blog/2026.... And of course, eBPF can help here! As usual, very easy to follow along and with code walkthroughs.
vincent.bernat.ch
Using eBPF to load-balance traffic across UDP sockets with Go
Learn how to implement eBPF-based load balancing for UDP sockets in Go. The article also covers graceful restarts.
022
Paul Chaignon @pchaigno.bsky.social · 15/01/2026
There's a new eBPF sandbox by David Ventura to learn BPF development with exercises and detailed explanations: ebpf.party. Looks great for a first quick introduction!
Screenshot of the top of the website, showing the first 6 exercises (out of 12).
043
Paul Chaignon @pchaigno.bsky.social · 14/01/2026
I updated my blog post on the @sigcomm.bsky.social #eBPF workshop with slides for most presentations over the past three years! pchaigno.github.io/ebpf/2025/09... This was possible thanks to Sebastiano Miano who kept archives from the workshops over the years 🙏
Screenshot of the top of the blog post.
030
Paul Chaignon @pchaigno.bsky.social · 23/12/2025
Syzkaller has been fuzzing Linux patchsets since August! It already caught more than 100 bugs before they were merged. At #LinuxPlumbers, Aleksandr Nogikh explained why your patchset may not be covered. Website: ci.syzbot.org Slides: lpc.events/event/19/con... Video: www.youtube.com/watch?v=69Pj...
Slide showing some stats on syzbot reporting. It found 105 bugs in patchsets between August and early December. It fails to determine the base tree in 12.5% of cases.
000
Paul Chaignon @pchaigno.bsky.social · 22/12/2025
After accelerating pod networking with netkit devices, @cilium.io will tackle the challenge of KubeVirt pods. At #LinuxPlumbers, Daniel Borkmann et al. explained what it will look like and the required changes. Recording: www.youtube.com/watch?v=_Qy4... Slides: lpc.events/event/19/con...
Slide showing the future packet path for KubeVirt pods with netkit devices.
122
Paul Chaignon @pchaigno.bsky.social · 18/12/2025
Peilin Ye gave an easy-to-follow introduction to the new BPF_ATOMIC instructions for Load-Acquire and Store-Release in eBPF. Only at #LinuxPlumbers! ;) Recording: www.youtube.com/watch?v=iF7J... Slides: lpc.events/event/19/con...
Motivational slide showing a possible concurrency issue with a simple BPF example detected by herd7.
010
Paul Chaignon @pchaigno.bsky.social · 18/12/2025
Justin Ngai presented a BPF regex engine to be able to match file paths and command lines in the kernel. He explained how it works, its limitations, and some of the challenges involved. #LinuxPlumbers Recording: youtu.be/n0xMU3XkXYM Slides: lpc.events/event/19/con...
Slide showing the high-level idea with the different steps involved, from the regex string to the BPF maps and programs.
010
Paul Chaignon @pchaigno.bsky.social · 17/12/2025
Related to the previous #LinuxPlumbers talk, Raman Shukhau implemented and presented a small DNS server in eBPF! Recording: www.youtube.com/watch?v=di2R... Slides: lpc.events/event/19/con...
Slide listing the advantages and limitations of using this BPF-based DNS server to resolve external queries. It includes performance numbers showing it improves the throughput and latency.
011
Paul Chaignon @pchaigno.bsky.social · 17/12/2025
Cilium can enforce network policies based on FQDNs using a userspace proxy. At #LinuxPlumbers, @hemanthmalla.bsky.social proposed to move this to the kernel by implementing DNS parsing in #eBPF! Recording: www.youtube.com/watch?v=ecQo... Demo: youtu.be/0qmQ1bTBLHo Slides: lpc.events/event/19/con...
Slide showing the overal architecture of parsing DNS over TCP for Cilium using eBPF.
032
Paul Chaignon @pchaigno.bsky.social · 16/12/2025
Work on the BPF Verifier Visualizer (bpfvv) is continuing! Ihor Solodrai and Jordan Rome presented the many new features at #LinuxPlumbers. Recording: www.youtube.com/watch?v=-_P1... Slides: lpc.events/event/19/con...
Screenshot of the bpfvv UI showing the C code, the corresponding BPF bytecode, and the current state of registers and stack slots.
020
Paul Chaignon @pchaigno.bsky.social · 16/12/2025
After a great recap of how uprobes work, Jiri Olsa presented recent optimizations and discussed how uprobes could overwrite userspace functions. As usual with Jiri, the slides are minimalist but effective #LinuxPlumbers Recording: www.youtube.com/watch?v=sydT... Slides: lpc.events/event/19/con...
Slide showing how the trampoline call improves on the basic uprobes hooking using the new uretprobe(2) syscall.
020
Paul Chaignon @pchaigno.bsky.social · 15/12/2025
At #LinuxPlumbers, @breakawaybilly.bsky.social presented what the eBPF Foundation is doing, where its funds are going, and asked the attendees what should be next. Recording: www.youtube.com/live/ZLRngpd... Slides: lpc.events/event/19/con...
Slide showing the $225k grant received by the eBPF Foundation from the Alpha-Omega project and what it will be used for. The slide mentions enabling KASAN, security reviews of the main JIT compilers, checking the verifier-to-JIT integrity, and an assessment of unprivileged surfaces.
072
Paul Chaignon @pchaigno.bsky.social · 10/12/2025
For the past month, with my colleague @mahe.bsky.social, we've been looking into the BPF verifier's state pruning. Tomorrow, we're giving an introduction to this verification optimization at Linux Plumbers: lpc.events/event/19/con...!
Screenshot of a slide of the presentation, showing the timeline of the main state pruning improvements in the verifier.
051
Paul Chaignon @pchaigno.bsky.social · 18/11/2025
The HotNets 2025 program and papers are available! Similar mix of topics as SIGCOMM, with lots of AI, some host networking, some LEO, some eBPF... conferences.sigcomm.org/hotnets/2025...
conferences.sigcomm.org
HotNets 2025: Program
021
Paul Chaignon @pchaigno.bsky.social · 27/10/2025
The talks for the Networking track of Linux Plumbers 2025 are up! An XDP API redesign, rich packet metadata, XDP offload to AMD GPUs... There are a few #eBPF topics, but also many classic networking talks. lpc.events/event/19/ses...
lpc.events
Linux Plumbers Conference 2025
The Linux Plumbers Conference (LPC) is a developer conference for the open source community. The LPC brings together the top developers working on the plumbing of Linux - kernel subsys...
040
Paul Chaignon @pchaigno.bsky.social · 24/10/2025
At GNU Tools Cauldron, Eduard Zingerman presented 4 examples of compiler optimizations that can break #eBPF verification in Linux. The discussion then focused on how to mitigate this in GCC, with a potential -fverifiable flag. Video: www.youtube.com/watch?v=DgiE... Article: lwn.net/Articles/103...
Slide presenting the first example in which a compiler optimization breaks eBPF verification.
100
Paul Chaignon @pchaigno.bsky.social · 16/10/2025
Agni is now able to formally verify core #eBPF verifier logic in ~10 minutes! And all LTS kernels are covered daily! github.com/bpfverif/agn...
141
Paul Chaignon @pchaigno.bsky.social · 15/10/2025
At Kernel Recipes, Roman Gushchin presented his work on customizing the Linux out-of-memory handling with #eBPF. It allows you to control when the OOM killer is triggered and how to free memory (typically, what to kill). Code: lore.kernel.org/bpf/20250818... Video: www.youtube.com/watch?v=pgDI...
Slide showing a kernel stack trace when using BPF OOM to control what is killed. The blue part is the normal OOM killer being triggered. The green part is the BPF program being called. The yellow part shows the call to the new kfunc to kill a process. And finally, the orange text displays which BPF policy was used for the OOM.
021
Paul Chaignon @pchaigno.bsky.social · 08/10/2025
The list of talks accepted for the #eBPF track at Linux Plumbers 2025 has been published: lpc.events/event/19/ses...! See you in Tokyo! (You may need to click on Contribution list to see the talks.)
The Linux Plumbers background picture with giant eBPF bees circling around the Tokyo and Roppongi Hills Mori towers.
021
Paul Chaignon @pchaigno.bsky.social · 06/10/2025
I've added 6 recent research papers on eBPF to my list, from SIGCOMM'25, SOSP'25, and IEEE S&P'25: pchaigno.github.io/bpf/2025/01/....
Screenshot of the top of the list, showing the interactive selectors and the 6 new papers.
020
Paul Chaignon @pchaigno.bsky.social · 23/09/2025
I've written a guide on how to test BPF verifier changes using Cilium's collection of #eBPF programs: pchaigno.github.io/ebpf/2025/09...
pchaigno.github.io
Test Verifier Changes on Cilium’s BPF Programs
This post describes how to use Cilium’s large BPF programs to test and evaluate your changes to the Linux BPF verifier or to any other aspect of the kernel.
030