NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #438 by repository stars
Last release today
07 Oct 2026
Ships on a steady schedule
a new release about every 2 weeks
Rarely documented
notes for 8 of 36 stable releases
Nothing withdrawn
no release was ever pulled
9 years old
1167 releases · first in 2017
Nothing published for this version
Nothing published for this version
Nothing published for this version
One column per quarter.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
…the latest releases of Linux. We also made a breaking change to BTF caching, please read those notes. And of course a few fixes, improvements and mino…
Hi everyone! Today we announce the v0.22.0 release of ebpf-go. We ship Linux 7.1 compatibility, older versions of the library will not work on 7.1 kernels and above, so please upgrade if you are targeting the latest releases of Linux. We also made a breaking change to BTF caching, please read those notes. And of course a few fixes, improvements and minor features.
In kernel 7.1 the BTF header was extended to introduce a new feature called BTF layout. This change caused our BTF parser to fail when parsing vmlinux for this kernel. This has been fixed in this latest release, we recommend upgrading to this latest release to avoid breakage on 7.1 and newer kernels.
See #2042 for details. Special thanks to @Capricornus007 for making the bug report that allowed us to fix this in a timely manner.
Some BPF-related actions require the user to have root privileges (CAP_SYS_ADMIN). One example is loading and attaching programs that can inspect kernel memory. In some environments, you may want to permit a known good process to load such BPF programs, but you don't want to grant it CAP_SYS_ADMIN to avoid privilege escalation if that process gets compromised.
BPF tokens are a mechanism that allows a privileged process to delegate fine-grained BPF capabilities to an unprivileged process. The process of delegating is complex and typically handled by a container runtime such as LXC or a process manager like systemd. This part of the handshake is currently out of scope of ebpf-go, as the library is not in charge of process creation where this delegation takes place.
However, the consuming side is what's included in this release. ebpf-go will automatically detect when the current process is running in a namespace where a BPF token is provided, and will automatically try to obtain an use it for interacting with the BPF syscall. Unlike libbpf, this currently requires no extra configuration on behalf of the application.
See #1953 for more details.
Package btf used to cache kernel (vmlinux) BTF specs globally. This is a significant time gain when loading multiple Collections in a row. However, doing so comes at a fairly significant memory cost (~20 MiB), so users could flush this cache with btf.FlushKernelSpec. Unfortunately, the caching behaviour being opt-out means users would typically discover it while investigating memory usage, and would then have to find an appropriate time during execution to call the flush function. This was always a band-aid for something we didn't have a clear solution to.
With this update, we've removed the global cache and the btf.FlushKernelSpec function, which may slow down subsequent collection loading on busy systems. To opt back in, users can now maintain their own cache object, obtained from btf.NewCache and pass it to NewCollectionWithOptions via CollectionOptions.Cache. Typically, you would put this in a global variable in a bpf-related package in your application, or keep it around in function scope if you load multiple collections in a row.
See #1988 for more details. Thank you @matthyx for these changes.
go fix in CI, fix nil derefs in reflect usage by @ti-mo in #1998Full Changelog: v0.21.0...v0.22.0
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Please note that this version comes with a few breaking changes for XDP users that may require some intervention based on your use case, so please rea…
Hi, everyone! The Cilium project is proud to announce v0.21.0 of ebpf-go, our first major 2026 feature release. Please note that this version comes with a few breaking changes for XDP users that may require some intervention based on your use case, so please read the following section carefully before upgrading! We've also removed some long-deprecated APIs.
This release saw a change to the ELF parsing logic, specifically to XDP programs. Previously, XDP programs had their ProgramSpec.AttachType set to AttachNone. Prompted by upstream changes in Linux 6.18, XDP programs now come with an AttachXDP attach type. This change ensures compatibility with kernels going forward, as well as better interoperability with libbpf-based tools using shared PROG_ARRAY maps.
tl;dr: Linux 6.18 and later disallows mixing attach types within the same program array.
If your application uses a pinned program array, you may need to manually change the attach type of your XDP programs to AttachNone before they are loaded to ensure they can still be inserted into maps containing pre-upgrade programs.
The same goes for BPF links. If you're updating an XDP link created by an older version of ebpf-go, you need to ensure your XDP program is loaded with the same attach type the link was initially created with, or updating will fail with EINVAL.
For an example of how to deal with this change, here's the the Cilium PR that implemented logic to try both attach types when updating links.
ebpf-for-windows was upgraded from 0.21.0 to v1.0.0-rc1. efW made breaking changes to the names of helper functions, our API has been updated to match:
asm.WindowsFnMemcmp -> asm.WindowsFnMemcmpSasm.WindowsFnMemcpy -> asm.WindowsFnMemcpySasm.WindowsFnMemmove -> asm.WindowsFnMemmoveSMapSpecs and resolving function-pointer members. link.AttachStructOps has been added to allow attaching a StructOpsMap as a link. A sched_ext example can be found here.ProgramSpec and MapSpec, meaning linked objects (produced via bpftool gen object) are now handled correctly.btf.Builder can now deduplicate types while generating a BTF blob. Deduplication can be enabled by passing BuilderOptions to NewBuilder with the Deduplication field set to true.ProgramSpec.Compatible was added — ProgramSpec.Tag is now deprecated. The new ProgramSpec.Compatible method compares a loaded program's tag against both SHA-1 and SHA-256 hashes of the spec, ensuring correct behaviour across kernels — including kernel v6.18+, which switched to SHA-256 for program hashing.ProgramInfo.Name is now sourced from BTF func info when available to provide the full program name if it's longer than 15 bytes.Executable.Symbol to resolve addresses to a symbol and relative offset.HaveBPFLinkKprobeMulti, HaveBPFLinkUprobeMulti, and HaveBPFLinkKprobeSession are now exported from the features package, making it easier to probe for multi-attach support before loading programs.RunOptions.BatchSize option has been added to support batching when running programs.CAP_SYS_ADMIN — Loading programs with weak kfuncs on kernels that don't have the kfunc no longer fails with "operation not permitted" when the caller lacks CAP_SYS_ADMIN. The permission error is now treated as "not found" for weak kfuncs.QueryResult.HaveLinkInfo heuristic — The heuristic has been updated to check for at least one attached program with a non-zero link ID, fixing a false positive introduced by a kernel change that began populating the revision field for cgroup queries.In this release we have removed a number of features which had been deprecated for a while.
CollectionSpec.RewriteMaps - Pass CollectionOptions.MapReplacements when loading the CollectionCollectionSpec.RewriteConstants - Use CollectionSpec.Variables instead.NewLinkFromFD - Use NewFromFD instead.HaveProgType - Use HaveProgramType instead.IsUnreferencedSymbol - Use errors.Is(err, asm.ErrUnreferencedSymbol) instead.Instruction.RewriteMapPtr - Use Instruction.AssociateMap instead. If you cannot provide a Map, wrap an fd in a type implementing FDer.Instruction.Sym - Use Instruction.WithSymbol instead.Instruction.MapPtr - Use Instruction.Map instead.Memory.Size now returns an uint32 instead of an intVariable.Size now returns an uint32 instead of an uint64VariableSpec.MapName has been removed, use VariableSpec.SectionName instead.VariableSpec.Offset is no longer a method, and is now a field.VariableSpec.Size now returns an uint32 instead of a uint64.VariableSpec.Type is no longer a method, and is now a field.KprobeInfo.Address has been changed from a method into a field.KprobeInfo.Missed has been changed from a method into a field.KprobeMultiInfo.AddressCount has been removed, use len(KprobeMultiInfo.Address) instead.KprobeMultiInfo.Flags has been changed from a method into a field.KprobeMultiInfo.Missed has been changed from a method into a field.NetNsInfo.NetnsIno was renamed to NetNsInfo.NetnsInodeNetfilterInfo.Hooknum has been renamed to NetfilterInfo.Hook and changed from an uint32 to a NetfilterInetHookNetfilterInfo.Pf has been renamed to NetfilterInfo.ProtocolFamily and changed from an uint32 to a NetfilterProtocolFamilyTracingInfo.TargetObjId has been renamed to NetfilterInfo.TargetObjectIdWe exported methods and types from the btf package. This allowed us to directly assign BTF func info, line info and CO-RE relocations to instructions from outside of the btf package, making some methods unneeded and thus got removed.
ExtInfos.Assign has been removed, use WithFuncMetadata, Instruction.WithSource, and WithCORERelocationMetadata instead.AssignMetadataToInstructions has been removed, use WithFuncMetadata, Instruction.WithSource, and WithCORERelocationMetadata instead.CORERelocationInfos was renamed to CORERelocationOffsets.NewBuilder now takes an additional BuilderOptions. This can be left nil.ProgramSpec.Tag, and introduce ProgramSpec.Compatible by @dylandreimerink in #1932CAP_SYS_ADMIN by @dylandreimerink in #1950Full Changelog: v0.20.0...v0.21.0
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →