Fast, Flexible, and Practical Kernel Extensions
Kumar Kartikeya Dwivedi, Rishabh R. Iyer, Sanidhya Kashyap
Abstract
The ability to safely extend OS kernel functionality is a longstanding goal in OS design, with the widespread use of the eBPF framework in Linux and Windows demonstrating the benefits of such extensibility. However, existing solutions for kernel extensibility (including eBPF) are limited and constrain users either in the extent of functionality that they can offload to the kernel or the performance overheads incurred by their extensions.
We present KFlex: a new approach to kernel extensibility that strikes an improved balance between the expressivity and performance of kernel extensions. To do so, KFlex separates the safety of kernel-owned resources (e.g., kernel memory) from the safety of extension-specific resources (e.g., extension memory). This separation enables KFlex to use distinct, bespoke mechanisms to enforce each safety property-automated verification and lightweight runtime checks, respectively-which enables the offload of diverse functionality while incurring low runtime overheads.
We realize KFlex in the context of Linux. We demonstrate that KFlex enables users to offload functionality that cannot be offloaded today and provides significant end-to-end performance benefits for applications. Several of KFlex's proposed mechanisms have been upstreamed into the Linux kernel mainline, with efforts ongoing for full integration.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 2b49bf94-d5db-46b1-9473-4f736c2f54b2Cited by top-tier papers10
- eTran: Extensible Kernel Transport with eBPFZhongjie Chen, Qingkai Meng, ChonLam Lao, Yifan Liu et al.NSDI 2025 · 17 citations
- VEP: A Two-stage Verification Toolchain for Full eBPF ProgrammabilityXiwei Wu, Yueyang Feng, Tianyi Huang, Xiaoyang Lu et al.NSDI 2025 · 8 citations
- Extending Applications Safely and EfficientlyYusheng Zheng, Tong Yu, Yiwei Yang, Yanpeng Hu et al.OSDI 2025 · 7 citations
- Revealing the Unstable Foundations of eBPF-Based Kernel ExtensionsShawn Wanxiang Zhong, Jing Liu, Andrea C. Arpaci-Dusseau, Remzi H. Arpaci-DusseauEuroSys 2025 · 4 citations
- SoK: Challenges and Paths Toward Memory Safety for eBPFKaiming Huang, Mathias Payer, Zhiyun Qian, Jack Sampson et al.S&P 2025
Builds on10
- A large scale analysis of hundreds of in-memory cache clusters at TwitterJuncheng Yang, Yao Yue, K. V. RashmiOSDI 2020 · 245 citations
- BMC: Accelerating Memcached using Safe In-kernel Caching and Pre-stack ProcessingYoann Ghigoff, Julien Sopena, Kahina Lazri, Antoine Blin et al.NSDI 2021 · 79 citations
- Electrode: Accelerating Distributed Protocols with eBPFYang Zhou, Zezhou Wang, Sowmya Dharanipragada, Minlan YuNSDI 2023 · 78 citations
- DINT: Fast In-Kernel Distributed Transactions with eBPFYang Zhou, Xingyu Xiang, Matthew Kiley, Sowmya Dharanipragada et al.NSDI 2024 · 40 citations
- High Velocity Kernel File Systems with BentoSamantha Miller, Kaiyuan Zhang, Mengqi Chen, Ryan Jennings et al.FAST 2021 · 28 citations
Related papers
- Prove It to the Kernel: Precise Extension Analysis via Proof-Guided Abstraction RefinementHao Sun, Zhendong SuSOSP 2025
- Verified programs can party: optimizing kernel extensions via post-verification mergingHsuan-Chi Kuo, Kai-Hsun Chen, Yicheng Lu, Dan Williams et al.EuroSys 2022 · 17 citations
- Rex: Closing the language-verifier gap with safe and usable kernel extensionsJinghao Jia, Ruowen Qin, Milo Craun, Egor Lukiyanov et al.USENIX ATC 2025 · 11 citations
- Approximation Enforced Execution of Untrusted Linux Kernel ExtensionsHao Sun, Zhendong SuUSENIX Security 2025
- FlexOS: towards flexible OS isolationHugo Lefeuvre, Vlad-Andrei Badoiu, Alexander Jung, Stefan Lucian Teodorescu et al.ASPLOS 2022 · 36 citations
