- Sources: primary, code, discussion
- Summary: A post dated 2026-09-11 describes caching policy lookups per inode inside an eBPF security agent. The benchmark opened the same file 200,000 times, and the author reports kernel cycles falling from 28 billion to 3.03 billion. Hardlinks take a fallback path outside the cache, which the author describes as choosing accuracy over cache coverage.
- Why it matters: The cache lives inside the agent, so an operator collects the reported reduction from an upgrade alone without rewriting a single policy.
send feedback on this story