finds.dev← search

// the find

libbpf/libbpf-rs

★ 1,021 · Rust · NOASSERTION · updated Oct 2026

Minimal and opinionated eBPF tooling for the Rust ecosystem

libbpf-rs is an idiomatic Rust wrapper around the C libbpf library, paired with libbpf-cargo for compiling and embedding BPF programs through normal cargo builds. It's for Rust developers writing eBPF tooling on Linux who want skeleton-based codegen instead of hand-rolling FFI calls to libbpf.

The feature surface is wide and current — ring buffers, user ringbuf, netfilter, tc, xdp, streams, arena maps, uprobe_multi, usdt all have real example programs, not just stubs. CI actually builds a kernel and runs tests against it (build-kernel.yml) instead of mocking the BPF verifier, which is the only way to catch real behavioral regressions. libbpf-cargo wires BPF object compilation into a build.rs so you get skeletons through normal `cargo build` rather than a separate Makefile-based pipeline, which is what most BCC-era tooling still forces on you.

The README is two sentences pointing at subdirectories — there's no quickstart, no sample skeleton usage, so you're reading tests/bin or the examples directory to learn the API shape. It only builds and runs on Linux with BPF support in the kernel; there's no story for developing on macOS or Windows, not even a dev container mentioned anywhere in the tree. It's pinned to libbpf's C API underneath, and the presence of var/patches (patching libbpf for C23 warnings) shows that coupling is already leaking maintenance work into this repo rather than staying cleanly abstracted.

View on GitHub →

// want more like this?

We dig through GitHub every week and send a few repos picked for what you actually care about — each with an honest take like this one.

Get finds in your inbox → Search again →