Skip to content
CAI
Software that uses CAICheck a score

aya-rs/aya

68.9

Adequate · 30 September 2026

148.8k

lines of production code

Rust

primary language

2

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a comprehensive Rust library and toolchain for developing, building, and running eBPF programs on the Linux kernel. It provides userspace APIs for loading, attaching, and managing diverse eBPF program types and map structures, while offering kernel-side macros and bindings for writing safe eBPF code. The project also includes specialized crates for parsing eBPF object files, generating Rust bindings from kernel headers, and handling high-performance logging via ring buffers.

How it got here

2021 — Bazel migration and API modernization

19 changes.

The project migrated its build infrastructure to Bazel and reorganized into a Rust workspace, while simultaneously removing legacy BPF module roots and generated bindings. This period focused on a comprehensive API refactor that introduced new eBPF map and program types, decoupled perf event handling, and updated the library to Rust 2024 with stricter error handling and feature-probing capabilities.

2022–2023 — aya-obj extraction and logging overhaul

21 changes.

The project extracted eBPF object file parsing and BTF handling into a standalone aya-obj crate to decouple core logic from the main framework. Simultaneously, the aya-log ecosystem was overhauled with a new ring-buffer transport, compile-time format validation, and stricter type safety. These changes were supported by expanded integration tests and the introduction of aya-tool for automated BPF type generation.

2024–2026 — multi-architecture expansion and map ecosystem

18 changes.

The project significantly expanded its supported architectures to include MIPS, LoongArch64, and PowerPC64, while refactoring the macro library for modularity. It introduced a comprehensive suite of new eBPF map types, including XDP redirection, performance event arrays, and BTF-compatible structures, alongside a new centralized build system.

Features

Add Linux kernel header wrappers

A new header file, linux\_wrapper.h, has been added to the aya-obj/include directory. This file aggregates includes for various Linux kernel headers related to BPF, BTF, hardware breakpoints, network interfaces, netfilter, packet classification, and routing, providing a centralized set of definitions for the library.

aya-obj/include · high confidence

Add eBPF perf event array map support

Introduces new \PerfEventArray\ and \PerfEventByteArray\ map types in the \aya-ebpf\ crate, enabling eBPF programs to read performance counter values (including counter, enabled, and running nanoseconds) and output event data to userspace. This allows developers to instrument and monitor performance metrics directly from within eBPF programs using the standard Linux perf event infrastructure.

ebpf/aya-ebpf/src/maps/perf · high confidence

Add format string parser with display hints for MAC, IP, and pointer types

The \aya-log-parser\ library now includes a parser for log format strings that recognizes specific display hints within curly braces. Users can now use \:mac\ or \:MAC\ for MAC addresses, \:i\ for IP addresses, and \:p\ for raw pointer types, in addition to existing hex formats (\:x\, \:X\). The parser correctly handles escaped braces (\{{\, \}}\) and returns structured fragments (literals and parameters) for downstream processing.

aya-log-parser/src · high confidence

Add program type and attach-type bindings for Cgroup, XDP, and SK\_REUSEPORT

The \aya-obj/src/programs\ module now exposes structured Rust enums for attaching and identifying several BPF program types. Users can now specify attach points for Cgroup programs (skb, sock, sock\_addr, and sockopt), XDP programs (interface, cpumap, devmap), and SK\_REUSEPORT programs (select, select\_or\_migrate) via strongly-typed enums (\CgroupSkbAttachType\, \CgroupSockAttachType\, \CgroupSockAddrAttachType\, \CgroupSockoptAttachType\, \XdpAttachType\, \SkReuseportAttachType\). Additionally, \types.rs\ provides a \TryFrom\<u32\>\ implementation for \bpf\_prog\_type\, allowing conversion from raw u32 program type IDs to the corresponding enum variants, covering a wide range of program types including Cgroup, XDP, SK\_SKB, SK\_REUSEPORT, and others.

aya-obj/src/programs · high confidence

Add socket map types (SockMap, SockHash, ReusePortSockArray)

Users can now store and manage TCP/UDP sockets within eBPF maps using three new map types: SockMap (array of sockets, kernel 4.14+), SockHash (hash map of sockets, kernel 4.18+), and ReusePortSockArray (for SO\_REUSEPORT groups, kernel 4.19+). These maps allow eBPF programs to inspect, filter, or redirect network buffers on specific sockets, and their file descriptors can be used to attach programs like SkMsg and SkSkb.

aya/src/maps/sock · high confidence

The library now supports several new eBPF program types, including CgroupDevice, CgroupSkb, CgroupSock, CgroupSockAddr, CgroupSockopt, CgroupSysctl, FEntry, FExit, and FlowDissector. These additions allow users to attach eBPF programs to cgroups for device access control, network filtering, socket address inspection, socket option modification, sysctl monitoring, and flow dissection, as well as to kernel function entry and exit points for tracing. The implementation uses a unified link management system that automatically selects the appropriate attachment mechanism (bpf\_link\_create for kernels 5.7+ or bpf\_prog\_attach for older kernels) based on the running kernel version, ensuring compatibility across different kernel versions.

aya/src/programs · high confidence

Add unified eBPF bindings header

A new \bindings.h\ header has been added to the \ebpf/aya-ebpf-bindings/include\ directory to consolidate necessary Linux and eBPF system headers. This header includes definitions for \\_\_wsum\, standard eBPF helpers, BPF types, performance event structures (specifically exposing \PERF\_MAX\_STACK\_DEPTH\), traffic control actions, and ptrace interfaces, providing a single inclusion point for these dependencies.

ebpf/aya-ebpf-bindings/include · high confidence

Added Bazel build support and libbpf submodule for xtask

The xtask component now includes a Bazel build configuration (BUILD.bazel) defining the Rust crate, and integrates the libbpf library as a Git submodule. This enables building and testing xtask using the Bazel build system.

xtask · high confidence

Added eBPF panic handler and Bazel build configuration

The ebpf-panic crate now provides a panic handler for eBPF Rust targets that loops indefinitely, causing the eBPF verifier to reject the program with an error if a panic occurs. A Bazel build file (BUILD.bazel) has been added to define the crate using the aya\_rust\_crate rule, enabling it to be built and tested within the Bazel workspace.

ebpf-panic · high confidence

Expanded architecture support and raw tracepoint argument handling

The aya-ebpf library now supports additional BPF target architectures, including LoongArch64, MIPS, MIPS64, PowerPC64, and s390x, enabling eBPF programs to run on these platforms. Additionally, the library introduces support for handling raw tracepoint arguments via the new \args\ module, which provides architecture-specific layouts for extracting arguments from \pt\_regs\ structures. This change also includes updates to helper functions and bindings to ensure compatibility with these new architectures.

ebpf/aya-ebpf/src · high confidence

Extracted eBPF build logic into aya-build crate

The eBPF compilation logic has been extracted into a new \aya-build\ crate, providing a \build\_ebpf\ function that orchestrates the build process for eBPF binaries. This change introduces support for configuring the Rust toolchain (including nightly versions and \RUSTC\_BOOTSTRAP\ handling), allows opting out of the build via the \AYA\_BUILD\_SKIP\ environment variable, and ensures correct target architecture detection (e.g., \bpfel\/\bpfeb\) and BTF generation. It also handles feature flags and default feature toggles for the packages being built, centralizing the build configuration previously scattered across the project.

aya-build/src · high confidence

Initial release of aya-obj for standalone eBPF object parsing

The \aya-obj\ crate is now available as a standalone library for parsing eBPF ELF object files, including BTF and relocation support. This allows projects to handle eBPF object files independently of the main \aya\ crate. The release includes a Bazel build configuration, integration tests against \rbpf\, and documentation.

aya-obj · high confidence

Introduce Bazel build system and project governance documentation

The repository now supports building and testing via Bazel, adding configuration files (.bazelrc, MODULE.bazel, BUILD.bazel) and a lockfile (MODULE.bazel.lock) that define dependencies such as rules\_rust, llvm, and libbpf, along with hermetic toolchains for Rust nightly and stable versions. This change also adds foundational project governance and contribution documentation, including CONTRIBUTING.md, GOVERNANCE.md, CODE\_OF\_CONDUCT.md, MAINTAINERS.md, and AGENTS.md, to guide community participation and maintainer responsibilities.

(repo-wide) · high confidence

Introduce aya-ebpf-cty crate for C type aliases

The new \aya-ebpf-cty\ crate provides type aliases to C types (such as \c\_int\, \c\_uint\, and \c\_char\) specifically for use with bindgen in eBPF contexts. It includes architecture-specific definitions for BPF targets (aarch64, arm, powerpc64, riscv64, s390x, mips, loongarch64, mips64, x86\_64) and standard host architectures, along with a Bazel build rule and a build script to emit the necessary \CARGO\_CFG\_BPF\_TARGET\_ARCH\ configuration.

ebpf/aya-ebpf-cty · high confidence

Introduce aya-log-common crate for shared logging types and formatters

The aya-log-common crate is introduced to provide shared types and traits for the aya-log ecosystem. It defines the \Level\ enum for log severity, \ArgumentKind\ and \DisplayHint\ enums to specify data types and formatting hints (such as IP, MAC, hex, and pointer formats), and formatter traits (\DefaultFormatter\, \LowerHexFormatter\, \IpFormatter\, etc.) that enable type-specific display logic. The \Argument\ trait is sealed and implemented for various primitive types (integers, floats, IPs, bytes, pointers) to safely serialize data from eBPF to userspace.

aya-log-common/src · high confidence

Introduce aya-obj as a standalone eBPF object file parsing library

The \aya-obj\ crate is now available as a separate, standalone library for parsing eBPF object files, including BTF and relocation support. This change extracts the object file handling code from the main \aya\ crate, allowing other projects to use eBPF object parsing without depending on the full \aya\ framework. The library provides APIs to parse ELF objects, resolve kernel symbols (ksyms) via BTF and \/proc/kallsyms\, handle map and program relocations, and manage BTF type information.

aya-obj/src · high confidence

Introduce aya-tool binary for generating Rust bindings

A new command-line interface has been added to the aya-tool crate, allowing users to generate Rust bindings for kernel types. The tool supports two input modes: reading from a BTF file (defaulting to /sys/kernel/btf/vmlinux) or from a C header file. It accepts a list of type names to generate bindings for and passes additional arguments to bindgen, outputting the resulting Rust code to standard output.

aya-tool/src/bin · high confidence

Introduce aya-tool for automated BPF type generation

The aya-tool crate has been introduced to provide automated code generation for BPF programs. It exposes a public API via \lib.rs\ that includes \bindgen\ for configuring the bindgen builder (with options like \clang\_macro\_fallback\ and specific enum styles) and \generate\ for orchestrating the creation of Rust bindings from BTF or C header files using external tools like \bpftool\ and \bindgen\. This allows users to automatically generate type definitions for BPF contexts and kernel structures.

aya-tool/src · high confidence

Introduce low-level eBPF system call and feature-probing APIs

The \aya/src/sys\ module now exposes a comprehensive set of low-level system call wrappers for eBPF operations (including map creation, program loading, and object pinning) alongside a new feature-probing API. This API allows applications to detect host kernel capabilities on demand—such as BTF support, multi-uprobe link creation, and specific BPF helper availability—before attempting to load or attach programs. The implementation also introduces a testable syscall interface (\Syscall\ enum) to facilitate mocking in unit tests.

aya/src/sys · high confidence

New BTF-compatible eBPF map types and map-of-maps support

The \aya-ebpf\ crate now exposes a comprehensive set of BTF-compatible map types in the \btf\_maps\ module, allowing eBPF programs to declare maps with explicit type information for better loader compatibility and safety. This release adds implementations for Array, PerCpuArray, BloomFilter, CgroupArray, CgroupStorage, PerCpuCgroupStorage, CgrpStorage, CpuMap, DevMap, DevMapHash, HashMap, LruHashMap, LruPerCpuHashMap, PerCpuHashMap, InodeStorage, LpmTrie, PerfEventArray, PerfEventByteArray, ProgramArray, Queue, ReusePortSockArray, RingBuf, SkStorage, SockHash, SockMap, Stack, StackTrace, and XskMap. Additionally, it introduces \ArrayOfMaps\ and \HashOfMaps\, which enable dynamic map selection at runtime by storing references to other BPF maps, with fused lookup methods to optimize performance.

_ebpf/aya-ebpf/src/btf\maps · high confidence

New XDP map types: CpuMap, DevMap, DevMapHash, and XskMap

The \aya-ebpf\ crate now provides dedicated types for XDP redirection maps, allowing programs to redirect packets to specific CPU cores, network interfaces, or AF\_XDP sockets. This change introduces \CpuMap\ for CPU-based redirection, \DevMap\ and \DevMapHash\ for network device redirection (supporting both array and hash key lookups), and \XskMap\ for directing traffic to AF\_XDP sockets. Each type includes constructors for standard and pinned maps, as well as helper methods like \redirect\, \get\, and \get\_ifindex\ to facilitate packet processing within XDP programs.

ebpf/aya-ebpf/src/maps/xdp · high confidence

New array-based map types: Array, CgroupArray, PerCpuArray, and ProgramArray

The \aya/src/maps/array\ module introduces four new eBPF map types to the library. \Array\ provides a fixed-size array for generic data types, \PerCpuArray\ offers per-CPU storage for values, \CgroupArray\ allows storing cgroup file descriptors for membership checks, and \ProgramArray\ serves as a jump table for eBPF tail calls. These types replace previous implementations (such as the old \ProgramArray\ structure) with a unified API that includes bounds checking, iteration support, and specific methods like \clear\_index\ for program arrays.

aya/src/maps/array · high confidence

New code generator for Aya and Aya-ebpf bindings

The \xtask/src/codegen\ module now provides a dedicated code generator that produces Rust bindings for the Aya userspace library and the Aya-ebpf kernel-side library. It generates architecture-specific bindings for nine architectures (x86\_64, ARMv7, AArch64, RISCV64, PowerPC64, S390X, Mips, Mips64, LoongArch64) using \aya\_tool::bindgen\ and libbpf headers, handling BPF, BTF, PERF, NETLINK, and NETFILTER types. The generator also extracts and expands BPF helper functions into safe Rust wrappers for the ebpf bindings.

xtask/src/codegen · high confidence

New eBPF map types and API refinements

The \aya-ebpf\ maps module now includes support for several new eBPF map types: \RingBuf\ for high-performance ring buffers, \BloomFilter\ for probabilistic set membership, \CgroupArray\ for cgroup-based access control, and \CgroupStorage\/\PerCpuCgroupStorage\ for per-cgroup data (marked as deprecated in favor of newer kernel types). Additionally, \Array\ and \PerCpuArray\ now expose a \set\ method for writing values, and \Queue\ and \Stack\ maps now include a \peek\ method to inspect elements without removal. The \BloomFilter\ API has been updated to take \&self\ in all methods, and \SockMap\ redirect methods are now safe to use.

ebpf/aya-ebpf/src/maps · high confidence

New eBPF program context types for FEntry, FExit, LSM, Flow Dissector, and Device programs

The \aya-ebpf\ library now provides dedicated context structs for several new and existing eBPF program types, allowing users to write programs for Function Entry/Exit (FEntry/FExit), Linux Security Module (LSM) hooks, Flow Dissectors, and cgroup device access. \FEntryContext\ and \FExitContext\ expose argument access via BTF, with \FExitContext\ additionally providing a \ret()\ method to read the probed function's return value (requiring Linux 5.17+). \LsmContext\ provides access to LSM hook arguments and the previous program's return value. \FlowDissectorContext\ wraps \SkBuff\ to expose flow keys and packet data for flow dissector programs, while \DeviceContext\ provides the raw pointer for cgroup device programs. These contexts are exported from the \programs\ module and implement the \EbpfContext\ trait.

ebpf/aya-ebpf/src/programs · high confidence

New map types and storage APIs added to aya::maps

The \aya/src/maps\ module now exposes several new eBPF map types and storage APIs. Users can now work with Bloom filters (\BloomFilter\), LPM tries (\LpmTrie\), and new FIFO/Stack data structures (\Queue\, \Stack\). Additionally, new storage map types are available for cgroups (\CgrpStorage\), inodes (\InodeStorage\), and sockets (\SkStorage\), alongside support for maps of maps (\ArrayOfMaps\, \HashOfMaps\). The module also introduces \RingBuf\ for efficient event transfer from eBPF programs to userspace and provides a \MapInfo\ API for querying metadata about loaded eBPF maps.

aya/src/maps · high confidence

New script to resolve immutable Rust toolchains

Added \scripts/rust\_toolchains.py\, a Python utility that queries the Rust distribution server to resolve the latest stable, beta, or nightly channels to specific, immutable toolchain versions and corresponding \rustc\ commit hashes. This enables CI and build systems to pin builds to exact, reproducible Rust compiler versions rather than floating channel tags.

python · high confidence

Regenerated Linux kernel bindings for multiple architectures

The generated Linux kernel bindings in aya-obj have been regenerated using rust-bindgen 0.73.2, adding support for MIPS, MIPS64, LoongArch64, PowerPC64, and s390x architectures alongside existing ones like AArch64, ARMv7, and RISC-V. This update ensures the library can correctly interpret kernel data structures on these additional platforms.

aya-obj/src/generated · high confidence

Replaced Rust xtask scripts with a modular CLI architecture

The xtask build tool has been rewritten in Rust, replacing previous shell-based scripts with a structured CLI using clap. This new tool provides dedicated subcommands for running clippy checks (including BPF targets), generating documentation, managing public API diffs, and executing integration tests in local or VM environments. It also introduces automated downloading of Ubuntu mainline kernel packages and improved HTTP client handling with caching and timeouts.

xtask/src · high confidence

Support for chained XDP programs in CPU and device maps

The \CpuMap\, \DevMap\, and \DevMapHash\ types now support chaining additional XDP programs. On kernels that support the \ProgId\ feature (Linux 5.8+ for device maps, 5.9+ for CPU maps), users can pass a \ProgramFd\ to the \set\ or \insert\ methods to attach a secondary program that runs before packet processing or transmission. On older kernels, these methods will return a \ChainedProgramNotSupported\ error if a program is provided, ensuring backward compatibility.

aya/src/maps/xdp · high confidence

Test-distro now includes a custom init, depmod, and modprobe implementation

The test-distro component now bundles its own minimal init process, module dependency generator (depmod), and module loader (modprobe) to support in-VM testing. The new init process mounts essential filesystems (proc, dev, sysfs, debugfs, bpffs, cgroup2, securityfs), reads kernel command-line arguments for test parameters, and executes all binaries found in /bin. The depmod tool scans kernel modules for .modinfo sections to generate a modules.alias file, supporting both xz and zstd compression. The modprobe tool resolves module aliases from modules.alias and loads the corresponding kernel modules, also handling compressed modules. These tools are designed specifically for the test environment and are not intended for production use.

test-distro/src · high confidence

aya-ebpf-bindings v0.2.0 adds MIPS64 support and updates generated bindings

The aya-ebpf-bindings crate has been updated to version 0.2.0, introducing support for the MIPS64 architecture alongside existing architectures like x86\_64, aarch64, and riscv64. This release includes regenerated bindings from libbpf, which pulls in the latest kernel constants and MIPS/LoongArch64 support. Additionally, the crate now exposes the PERF\_MAX\_STACK\_DEPTH constant, allowing users to access this specific eBPF configuration value. The update also incorporates general lint and build fixes to ensure the generated code remains warning-free across all supported targets.

ebpf/aya-ebpf-bindings · high confidence

Removals

Removal of BPF and perf event syscall wrappers

The BPF map operations (create, load, lookup, update, delete, next key) and perf event helpers (open, probe, tracepoint, ioctl) previously provided in src/syscalls have been removed. This eliminates the local syscall abstraction layer and its associated test-faking infrastructure for these specific kernel interfaces.

src/syscalls · high confidence

Removal of BPF module and library root

The \src/bpf.rs\ file containing the \Bpf\ struct, its error types, and helper methods for accessing maps and programs has been deleted, along with the \src/lib.rs\ file that re-exported these items. This removes the public API surface for loading and interacting with BPF objects, maps, and programs from this location.

src · high confidence

Removal of BPF program management module

The \src/programs\ module, which previously provided the \Program\ enum and concrete types (KProbe, UProbe, TracePoint, SocketFilter, Xdp) for loading and attaching BPF programs, has been completely removed. This eliminates the library's built-in capability to manage BPF program lifecycles and attach them to various kernel hooks via the public API.

src/programs · high confidence

Architecture

Migrate BTF parsing and relocation logic to aya-obj

The BTF (BPF Type Format) parsing, type definitions, relocation engine, and \.ksyms\ support have been moved from the main \aya\ crate into the new \aya-obj\ crate. This change centralizes all BTF object handling—including the \Btf\ struct, \BtfError\ types, \BtfRelocationError\, and the \extern\_types\ module for kernel symbol resolution—within \aya-obj/src/btf\, making \aya-obj\ the single source of truth for BTF object representation and relocation logic.

aya-obj/src/btf · high confidence

Proc-macro library refactored into modular program-type handlers

The \aya-ebpf-macros\ crate has been restructured from a single monolithic implementation into a modular architecture where each eBPF program type (such as kprobe, cgroup\_skb, fentry, and lsm) is handled by its own dedicated source file. This change introduces a shared \Args\ parser to standardize attribute parsing and updates the generated code to use the \\#\[unsafe(...)\]\ syntax for link sections and exports, ensuring compatibility with newer Rust editions.

aya-ebpf-macros/src · high confidence

Behavioural changes

Added cross-compilation support and argument parsing stubs for CI builds

The CI environment now supports cross-compilation from macOS to Linux musl by introducing a wrapper script that overrides the archiver and ranlib tools to ensure correct ELF format generation. Additionally, a stub header for the GNU argument parsing library (argp) has been added to provide necessary type definitions and function declarations, enabling code that relies on this library to compile within the CI environment.

ci · high confidence

Automated Rust toolchain management and build linting

The scripts directory now includes a Python utility to read and update Rust toolchain versions in the Bazel MODULE.bazel file, ensuring stable and nightly pins are managed programmatically. Additionally, a Bazel build file has been added to enforce Python linting and type-checking via ruff and ty, while the previous shell-based binding generation script has been removed.

scripts · high confidence

Aya library core refactoring and new eBPF program support

The aya library has been restructured with a core refactor of the Map API, renaming the main loader from BpfLoader to EbpfLoader (with BpfLoader deprecated), and introducing lazy loading of custom BTF sources. New eBPF program types are now supported, including BPF\_PROG\_TYPE\_CGROUP\_SKB, SkMsg, SkLookup, BPF\_PROG\_TYPE\_SK\_REUSEPORT, BPF\_PROG\_TYPE\_EXT, BPF\_PROG\_TYPE\_CGROUP\_DEVICE, BPF\_PROG\_TYPE\_CGROUP\_SOCK\_ADDR, BPF\_PROG\_TYPE\_CGROUP\_SYSCTL, Flow Dissector, Lirc, PerfEvent, SockOps, CgroupStorage, PerCpuCgroupStorage, InodeStorage, CgrpStorage, CgroupArray, and BPF\_MAP\_TYPE\_SK\_STORAGE. The library now supports multi-point uprobe attachments, cookies for uprobe, sleepable programs, and custom XDP flags. Kernel version handling has been improved to avoid panics on indeterminate versions and to handle WSL kernel version strings. Error handling has been refined with new error types like PinError and MapError::SyscallError, and the VerifierLogLevel now uses bitflags. The library also adds support for BTF maps, ring buffers, and various map types like PerCpuHashMap, StackTraceMap, and Lru/LruPerCpu hash maps.

aya/src · high confidence

Aya v0.14.0 introduces breaking API changes and raises MSRV to Rust 1.85

This release updates the Aya eBPF library to v0.14.0, requiring an upgrade to Rust 1.85.0 due to the move to the Rust 2024 edition. The release includes several breaking changes: the \name\ parameter in \aya::Bpf::programs\ now resolves function names from the ELF symbol table rather than section names; the Maps API has been reworked to return \Option\<&Map\>\ or \Option\<&mut Map\>\ instead of \MapRef\/\MapRefMut\, with a new \take\_map\ method added; the \ProgramFd\ trait has been removed in favor of \fd()\ methods; \BpfLoader::set\_global\ now accepts \Into\<aya::GlobalData\>\ and includes a \must\_exist\ argument; and BTF types have moved to the \aya-obj\ crate. Additionally, \AsyncPerfEventArray\ and \AsyncPerfEventArrayBuffer\ have been removed, and the \obj\ alias for \aya-obj\ has been dropped.

aya · high confidence

Bazel build support and MIPS register context implementation

The aya-ebpf crate now includes a Bazel build system (BUILD.bazel) to allow building and testing via Bazel, alongside a new build script (build.rs) that configures Rust check-cfg attributes. Additionally, the library now implements the FromPtRegs trait for the MIPS architecture, enabling access to processor register state within MIPS eBPF programs.

ebpf/aya-ebpf · high confidence

Decoupled perf event buffer API from PerfEventArray

The perf event buffer API has been refactored to decouple the buffer management from the map structure. Users now create a \PerfEventArrayBuffer\ via \PerfEventArrayBuffer::open\ and explicitly insert it into a \PerfEventArray\ using \set\, rather than relying on a coupled \AsyncPerfEventArray\ or internal buffer handling. This change introduces a new \PerfEvent\ enum to represent samples and lost events, and updates the consumption API to use \for\_each\, \fold\, and \try\_fold\ methods on the buffer, providing a more flexible and explicit event processing model.

aya/src/maps/perf · high confidence

Proc-macro logging now validates format strings and argument types at compile time

The \aya-log-ebpf-macros\ crate now parses format strings and validates that provided arguments implement the required display traits (e.g., \DefaultFormatter\, \IpFormatter\, \LowerMacFormatter\) during compilation. This change introduces compile-time checks for format string syntax and argument compatibility, ensuring that invalid format specifiers or mismatched types are caught early rather than causing runtime issues or silent failures in eBPF programs.

aya-log-ebpf-macros/src · high confidence

Refactored hash map API with dedicated Per-CPU support

The hash map implementation has been reorganized into a dedicated module, introducing a new \PerCpuHashMap\ type that allows eBPF programs to store separate values for each CPU, which helps minimize lock contention. The standard \HashMap\ and the new \PerCpuHashMap\ now support \TryFrom\ conversions from generic map objects, enabling safer initialization from both standard hash maps (\BPF\_MAP\_TYPE\_HASH\, \BPF\_MAP\_TYPE\_LRU\_HASH\) and per-CPU variants (\BPF\_MAP\_TYPE\_PERCPU\_HASH\, \BPF\_MAP\_TYPE\_LRU\_PERCPU\_HASH\). Additionally, the API now returns a specific \MapError::KeyNotFound\ error when a lookup fails, providing clearer error handling for users.

_aya/src/maps/hash\map · high confidence

The netlink subsystem in \aya/src/sys/netlink\ has been restructured to replace the previous implementation with a new typed request builder API (\request.rs\) that constructs messages using \writev\ for efficient I/O. This change introduces specific builder types for XDP link operations (\Link\, \Xdp\) and traffic control filters (\Tc\, \Bpf\), enforcing compile-time safety through state machines that prevent invalid attribute sequences (e.g., repeated XDP or classid attributes). The module also consolidates netlink socket handling and error types (\NetlinkError\) into a dedicated module structure, improving the reliability and type safety of kernel communication for XDP and TC operations.

aya/src/sys/netlink · high confidence

Refactoring of BPF map handling internals

The \src/maps\ module has been restructured to improve code organization and type safety. The \hash\_map.rs\ file was deleted, with its \MapKeys\ and \MapIter\ iterators moved to the parent module and made generic to remove unnecessary \Clone\ bounds. Additionally, the \Map\ struct's internal file descriptor is now wrapped in a \RefCell\ to manage mutability more safely, and a new \ProgramArray\ map type has been added to support program reference maps.

src/maps · high confidence

Removal of generated BPF and perf bindings

The generated Rust bindings for BPF instructions and Linux perf events, previously located in src/generated, have been removed from the codebase. This deletion eliminates the automatically generated structures and constants (such as bpf\_insn and perf\_event\_attr) that were produced by rust-bindgen, indicating a shift in how these low-level kernel interfaces are handled or integrated within the project.

src/generated · high confidence

aya-log v0.3.0: Renamed to EbpfLogger, removed tokio dependency, and added load-time log level masking

The aya-log library has been updated to version 0.3.0, introducing several breaking and behavioral changes for users. The primary API change is the renaming of \BpfLogger\ to \EbpfLogger\ (with \Bpf\ types generally renamed to \Ebpf\), though type aliases are provided for backward compatibility. The library no longer bundles the \tokio\ dependency; users must now provide their own executor and handle async reading of logs. Additionally, a new load-time log level masking feature allows users to selectively enable or disable log levels (e.g., via \AYA\_LOG\_LEVEL\) before loading the eBPF program, which helps reduce instruction count and avoid verifier limits. The underlying logging mechanism also switched from \AsyncPerfEventArray\ to \RingBuf\.

aya-log · high confidence

aya-log-common v0.2.0: Ring-buffer transport, sealed Argument trait, and raw pointer logging

The aya-log-common crate has been updated to version 0.2.0, introducing a breaking change by switching the underlying log transport from AsyncPerfEventArray to the RingBuf. This aligns the shared types for the new ring-buffer transport used by aya-log. Additionally, the Argument trait is now sealed, preventing downstream crates from implementing log argument types. A new feature allows logging raw pointer values using the :p display hint, which formats them with a 0x prefix. The crate also includes a Bazel build file (BUILD.bazel) and symlinks for license files.

aya-log-common · high confidence

aya-log-ebpf v0.2.0: zero-copy ring buffer logging and raw pointer support

The aya-log-ebpf crate has been updated to v0.2.0, introducing a significant performance improvement by replacing the previous AsyncPerfEventArray with a RingBuf for zero-copy log writes, which lowers instruction counts inside eBPF probes but requires Linux 5.8 or later. This release also adds support for logging raw pointer types using the \:p\ display hint, implements a load-time log level mask to optimize disabled log levels out entirely, and provides a helper for safely loading global variables. Additionally, the crate now uses the \Global\ type (renamed from \EbpfGlobal\) and aligns with the workspace's Rust 2024 edition and lint settings.

ebpf/aya-log-ebpf · high confidence

aya-log: Switch to RingBuf and rename BpfLogger to EbpfLogger

The aya-log user-space library now uses the RingBuf map API instead of the previous map implementation, providing a more efficient zero-copy mechanism for reading log records from eBPF programs. Additionally, the \BpfLogger\ type has been renamed to \EbpfLogger\ to align with broader naming conventions in the Aya ecosystem, with \BpfLogger\ marked as deprecated. The library also implements \AsFd\ for \EbpfLogger\, allowing it to be used with async I/O frameworks like Tokio for non-blocking log consumption.

aya-log/src · high confidence

Test coverage

Add Bazel build and test graph for integration tests; Expanded BPF integration tests for relocation, ksyms, and map pinning; Expanded integration test coverage for eBPF maps, relocations, and kernel features; Integration test suite structure and BPF binary loading; New Bazel build system for integration tests.

Dependencies

Project restructured into a Rust workspace with updated dependencies

The project has been reorganized from a single crate into a Cargo workspace containing multiple crates (aya, aya-ebpf, aya-log, etc.), moving the codebase to Rust edition 2024 and raising the minimum supported Rust version to 1.98.0. This change introduces a centralized dependency management section in the root Cargo.toml, updating key libraries such as syn to 3.0, object to 0.40, nix to 0.31.1, and clap to 4.x, while also adding new tooling crates like aya-build and aya-tool to support the expanded architecture.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 70 → 69 (-1.0)
  • Rubric changed (rubric-2026.09.11 → rubric-2026.09.18) — scores are not directly comparable.

Lenses

  • Code Health 87 → 87 (+0.4)
  • Architecture 99 → 95 (-3.9)
  • Maturity 58 → 58 (+0.1)
  • Readiness 73 → 71 (-1.8)
  • Security 83 → 85 (+1.8)

Resolved (52)

  • Documentation: no installation or build instructions (README.md)
  • Duplicated block (11 lines × 18) (aya-obj/src/generated/linux_bindings_aarch64.rs)
  • Duplicated block (11 lines × 18) (aya-obj/src/generated/linux_bindings_aarch64.rs)
  • Duplicated block (11 lines × 18) (aya-obj/src/generated/linux_bindings_aarch64.rs)
  • Duplicated block (11 lines × 18) (aya-obj/src/generated/linux_bindings_aarch64.rs)
  • Duplicated block (11 lines × 9) (aya-obj/src/generated/linux_bindings_aarch64.rs)
  • Duplicated block (13 lines × 18) (aya-obj/src/generated/linux_bindings_aarch64.rs)
  • Duplicated block (13 lines × 18) (aya-obj/src/generated/linux_bindings_aarch64.rs)
  • Duplicated block (15 lines × 2) (aya/src/sys/netlink.rs)
  • Duplicated block (6 lines × 18) (aya-obj/src/generated/linux_bindings_aarch64.rs)
  • Duplicated block (6 lines × 18) (aya-obj/src/generated/linux_bindings_aarch64.rs)
  • Duplicated block (6 lines × 9) (aya-obj/src/generated/linux_bindings_aarch64.rs)
  • Duplicated block (8 lines × 18) (aya-obj/src/generated/linux_bindings_aarch64.rs)
  • Duplicated block (8 lines × 2) (aya/src/sys/netlink.rs)
  • Duplicated block (8 lines × 9) (ebpf/aya-ebpf-bindings/src/aarch64/helpers.rs)
  • Duplicated block (8 lines × 9) (ebpf/aya-ebpf-bindings/src/aarch64/helpers.rs)
  • Duplicated block (9 lines × 18) (aya-obj/src/generated/linux_bindings_aarch64.rs)
  • Duplicated block (9 lines × 18) (aya-obj/src/generated/linux_bindings_aarch64.rs)
  • Duplicated block (9 lines × 18) (aya-obj/src/generated/linux_bindings_aarch64.rs)
  • Duplicated block (9 lines × 3) (ebpf/aya-ebpf-bindings/src/s390x/bindings.rs)
  • …and 32 more

New (133)

  • ClassTooLong: per_lowcore_bits (ebpf/aya-ebpf-bindings/src/s390x/bindings.rs)
  • Duplicate intent/types. 'CgrpStorage' appears to be a shorter alias or duplicate of 'CgroupStorage' (and potentially 'PerCpuCgroupStorage' depending on the underlying BPF map type). Having both 'cgrp' and 'cgroup' variants for what is likely the same BPF map type (BPF_MAP_TYPE_CGROUP_STORAGE) creates confusion.
  • Duplicated block (10 lines × 36) (aya-obj/src/generated/linux_bindings_aarch64.rs)
  • Duplicated block (12 lines × 18) (aya-obj/src/generated/linux_bindings_aarch64.rs)
  • Duplicated block (12 lines × 2) (aya/src/programs/sk_msg.rs)
  • Duplicated block (12 lines × 2) (test-distro/src/init.rs)
  • Duplicated block (13 lines × 36) (aya-obj/src/generated/linux_bindings_aarch64.rs)
  • Duplicated block (16 lines × 36) (aya-obj/src/generated/linux_bindings_aarch64.rs)
  • Duplicated block (17 lines × 36) (aya-obj/src/generated/linux_bindings_aarch64.rs)
  • Duplicated block (19 lines × 18) (aya-obj/src/generated/linux_bindings_aarch64.rs)
  • Duplicated block (19 lines × 36) (aya-obj/src/generated/linux_bindings_aarch64.rs)
  • Duplicated block (23 lines × 18) (aya-obj/src/generated/linux_bindings_aarch64.rs)
  • Duplicated block (25 lines × 18) (aya-obj/src/generated/linux_bindings_aarch64.rs)
  • Duplicated block (26 lines × 18) (aya-obj/src/generated/linux_bindings_aarch64.rs)
  • Duplicated block (27 lines × 18) (aya-obj/src/generated/linux_bindings_aarch64.rs)
  • Duplicated block (27 lines × 18) (aya-obj/src/generated/linux_bindings_aarch64.rs)
  • Duplicated block (30 lines × 18) (aya-obj/src/generated/linux_bindings_aarch64.rs)
  • Duplicated block (35 lines × 18) (aya-obj/src/generated/linux_bindings_aarch64.rs)
  • Duplicated block (4–9 lines × 36) (aya-obj/src/generated/linux_bindings_aarch64.rs)
  • Duplicated block (6 lines × 36) (aya-obj/src/generated/linux_bindings_aarch64.rs)
  • …and 113 more

Changes since last survey

  • 68 commits — 65 feature/other, 3 fixes

By area

  • (root) — 20 commits
  • aya/src — 18 commits
  • aya-obj/src — 7 commits
  • test/integration-test — 5 commits
  • .github/workflows — 4 commits
  • xtask/src — 4 commits
  • test-distro/src — 2 commits
  • test/integration-ebpf — 2 commits
  • aya-log-common/src — 1 commit
  • ebpf-panic/Cargo.toml — 1 commit
  • ebpf/aya-ebpf — 1 commit
  • ebpf/aya-ebpf-bindings — 1 commit
  • xtask/BUILD.bazel — 1 commit
  • xtask/public-api — 1 commit

Notable commits

  • fix: aya, aya-ebpf: fix BTF ring buffer definitions
  • fix: aya-obj: fix flexible array relocations
  • fix: aya-obj: fix nested BTF array sizes
  • change: Simplify some conditional compilation
  • change: aya, aya-ebpf: support reading perf event counters from eBPF
  • change: aya-ebpf: TcContext: add set_tc_classid
  • change: aya-ebpf: check ring buffer alignment statically
  • change: aya-log: restore logging of IPv6 segments
  • change: aya-obj: distinguish linked functions by section
  • change: aya-obj: explain relocation bounds errors
  • change: aya-obj: reject mismatched function info
  • change: aya-obj: use Option::map_or_default
  • change: aya: accept 256-byte TC program names
  • change: aya: add RingBuf::create()
  • change: aya: add a multi-uprobe support probe
  • change: aya: build typed netlink requests with writev
  • change: aya: decouple perf event buffer API from PerfEventArray
  • change: aya: derive map probe sizes from types
  • change: aya: document Pod's safety requirements
  • change: aya: move netlink into a module directory
  • …and 48 more

Architecture

  • Unchanged — 0 containers · 1 contexts · 0 edges

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

aya-rs/aya was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 30 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 485295105e36882e0142816cf65aaf716f3a87dd — the exact code this score is about.
  • Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-cb25ca4feafa.