microsoft / microsoft/retina

Compatibility matrix for Retina's eBPF programs across kernels — useful?

Open
#2,460 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Go
Stars
3.2k
Forks
304
Avg merge
1d 19h
Merged PRs (30d)
78

Description

Hi Retina team,

I maintain [bpfcompat](https://github.com/Kernel-Guard/bpfcompat) (Apache-2.0): it boots real distro kernels in disposable QEMU/KVM VMs, load/attach-validates a compiled `.bpf.o`, and reports a per-kernel pass/fail matrix with classified failure reasons (missing BTF, CO-RE relocation, unsupported map/program/attach type).

Retina's eBPF plugins (conntrack, dropreason, dns, …) run across AKS and a wide range of other distros/kernels — exactly the compatibility surface bpfcompat targets. I'd be happy to run Retina's compiled objects across a kernel spread and share the matrix as complementary evidence / a possible non-blocking CI lane.

Context: a [Falco modern_bpf reference matrix](https://github.com/Kernel-Guard/bpfcompat/blob/main/docs/case-study-falco-modern-bpf.md) and an [enterprise/backported-kernel matrix](https://github.com/Kernel-Guard/bpfcompat/blob/main/docs/case-study-enterprise-kernels.md) (RHEL 8/9/10, Oracle UEK, Amazon Linux 2 incl. the no-BTF 4.14, openSUSE — 14/14). [Live demo](https://bpfcompat.kernelguard.net).

Would a published per-kernel matrix for the plugins (or a CI lane that gates on it) be useful? Happy to put one together.

_Independent test of a public project; not affiliated with or endorsed by Microsoft/Retina._

Contributor guide

Open the contributing guide

Research direction

Begin with Retina's conntrack, dropreason, and dns compiled .bpf.o outputs and bpfcompat's two linked case studies. Done is defined by whether the team accepts a published per-kernel matrix or a non-blocking CI lane, with the supported kernel scope and pass/fail criteria recorded.

Written by the indexing model from the issue text.

Assessment

Tech stack
go, kubernetes
Domain
observability, testing
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.