maybe is time to also require Linux device drivers to be provided as eBPF byte code such that they are JIT/verified when installed for use. They probably require a different nuanced rule verification but should be possible. Then the promise of micro kernel architecture but without its messaging overhead can be realized