On Mon, Sep 27, 2021 at 03:34 PM CEST, Daniel Borkmann wrote: > On 9/24/21 11:55 AM, Lorenz Bauer wrote: >> Expose bpf_jit_current as a read only value via sysctl. >> Signed-off-by: Lorenz Bauer <lmb@xxxxxxxxxxxxxx> >> --- I find exposing stats via system configuration variables a bit unexpected. Not sure if there is any example today that we're following. Maybe an entry under /sys/kernel/debug would be a better fit? That way we don't have to commit to a sysctl that might go away if we start charging JIT allocs against memory cgroup quota. Although that brings up question against which cgroup iptables xt_bpf allocations should be charged? Root cgroup?