logo

Using CO:RE to Achieve Portable Tracee eBPF Code

ID: 0af33522-d7a0-5f05-87fb-6591f30f913f

STIX ID: report--0af33522-d7a0-5f05-87fb-6591f30f913f

Feed Name: Aqua Security Blog

Date Published: 2021-09-02

Date Updated: 2026-04-26

...
...

This blog details how the Tracee runtime security tool adopted libbpf's CO:RE to handle kernel structure changes across Linux versions: the team committed a generated vmlinux.h, updated their READ_KERN macro to use bpf_core_read (with associated un-nesting changes), maintained missing system macro headers, mitigated verifier and BPF stack-size issues, and implemented a distribution approach that embeds a CO:RE-enabled BPF object while falling back to kernel-specific objects when needed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.