by tuananh on 4/15/25, 3:42 PM with 2 comments
by skywhopper on 4/15/25, 5:30 PM
Okay, this is true!
So I’m left wanting to know why the author thinks less rigid “isolation” is a suitable answer to the problem. “JavaScript does something similar” is the only detail I could find. But JavaScript notably does not run in the kernel.
Ultimately this just seems like a post saying “it’s too hard to do everything we want within the current limitations of eBPF. But makes no effort to explain why getting rid of these strictures would be worth the huge security and reliability hole it would be creating, or how they would avoid those issues.
by westurner on 4/15/25, 7:15 PM
> Can [or should] a microkernel run eBPF? [or WASM?]
The performance benefits of running eBPF in the kernel are substantial and justifying, but how much should a kernel or a microkernel do?