hn.today

Show HN: DOOM in the kernel, or fibers in eBPF

ayles.github.io47 points11 comments

This describes BPF Capsule, a compiler and runtime that reshapes large C/C++/no_std Rust programs so the unmodified Linux eBPF verifier and JIT will accept and run them. The project demonstrates the technique by running DOOM inside the kernel: initialization, game logic, and rendering execute entirely in-kernel with one BPF invocation per game tick. The work also runs Lua, QuickJS, SQLite, zlib, wasm3, llama2.c and CPython 3.14 under the same scheme and lets Lua/Python inspect live packets. It targets ordinary kernels (oldest profile Linux 5.15) on x86-64 and arm64 and is runnable with a Nix command plus a WAD file.

The technical challenge is the verifier’s strict model: only five argument registers, 512 bytes of stack, acyclic call graphs, limited function count, an instruction-budgeting verifier, and pointer provenance tracking that forbids storing and later dereferencing raw pointers. The solution pipeline progressed from hand-trimming to userland uBPF testing, then LLVM passes that launder pointers (double bookkeeping to restore provenance), force loops into a verifier-provable form, and eventually implement a software VM of regions, fibers, and a managed stack inside eBPF. The result shows complex application logic can run in-kernel without patches, but only after substantial automated transformations to preserve the verifier’s proof obligations and work around LLVM optimizer rewrites.

Read on ayles.github.io11 comments on Hacker News

Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.

More in Security

The daily digest

Today's best Hacker News stories, summarized and screenshotted, one email a day.