Skip to main content
Technical proposal SIMD-0178 Review

SBPF Static Syscalls

  1. Idea
  2. Draft
  3. Review
  4. Accept
  5. Implement
  6. Active

Decision brief

Why this proposal matters

This SIMD introduces static syscalls, using the eBPF call instruction encoding, to remove runtime relocations while keeping compatibility with the eBPF encoding.

Source-backed reading aid · source language: EN

Proposal at a glance

What changes

  • The following must go into effect if and only if a program indicates the SBPF version 0x03 or higher in its ELF header e_flags field, according to the specification of SIMD-0161.
  • We follow the encoding referenced in the eBPF specification for encoding static syscalls. That means we must use the call instruction (opcode 0x85) with the source register field set to zero. The immediate field must be filled with a registered syscall hash code. For more reference on the SBF ISA format, see the spec document.
  • We define the hash code for a syscall as the murmur32 hash of its respective name. The 32-bit immediate value of the call instruction must be the integer representation of such a hash. For instance, the code for abort is given by murmur32("abort"), so the instruction hexadecimal representation should look like 85 00 00 00 11 1a fc b6.

Stakeholder map

Who is affected

Builders & client teams Medium impact

The changes proposed in this SIMD are transparent to dApp developers. The compiler toolchain will emit correct code for the specified SBF version. Static syscalls obviate relocations for call instructions and move the virtual machine closer to eliminating relocations altogether, which can bring considerable performance improvements.

Action requirement unknown
Validators & operators Impact unknown

No proposal-specific evidence was found for this group.

Action requirement unknown
Users & stakers Impact unknown

No proposal-specific evidence was found for this group.

Action requirement unknown
Governance & ecosystem Impact unknown

No proposal-specific evidence was found for this group.

Action requirement unknown

Exact source revision

Full proposal document

Source-language document. Technical identifiers and evidence remain unchanged. 0616093b2952

Summary

This SIMD introduces static syscalls, using the eBPF call instruction encoding, to remove runtime relocations while keeping compatibility with the eBPF encoding.

Motivation

The resolution of syscalls during ELF loading requires relocating addresses, which is a performance burden for the validator. Relocations require an entire copy of the ELF file in memory to either relocate addresses we fetch from the symbol table or offset addresses to after the start of the virtual machine's memory. Moreover, relocations pose security concerns, as they allow the arbitrary modification of program headers and programs sections. Introducing static syscalls allows us to resolve all program relocations during link time.

Dependencies

This proposal depends on the following previously accepted proposal:

  • SIMD-0189: SBPF stricter ELF headers

    Deprecation of PT_DYNAMIC header for SBPFv3 programs

New Terminology

None.

Detailed Design

The following must go into effect if and only if a program indicates the SBPF version 0x03 or higher in its ELF header e_flags field, according to the specification of SIMD-0161.

Static syscall instruction

We follow the encoding referenced in the eBPF specification for encoding static syscalls. That means we must use the call instruction (opcode 0x85) with the source register field set to zero. The immediate field must be filled with a registered syscall hash code. For more reference on the SBF ISA format, see the spec document.

We define the hash code for a syscall as the murmur32 hash of its respective name. The 32-bit immediate value of the call instruction must be the integer representation of such a hash. For instance, the code for abort is given by murmur32("abort"), so the instruction hexadecimal representation should look like 85 00 00 00 11 1a fc b6.

Consequently, system calls in the Solana SDK and in any related compiler tools must be registered as function pointers, whose address is the murmur32 hash of their name.

This new instruction comes together with modifications in the semantics of the instruction opcode 0x85 with source register set to one, which must only refer to internal calls and its immediate field must only be interpreted as a relative address to jump from the program counter.

As static syscalls don't use dynamic text-based relocations, the PT_DYNAMIC program header, along with the .dynamic, .dynsym, .dynstr and .rel.dyn section header entries will no longer be required to invoke static syscalls for any SBPFv3 program and will be omitted by default.

Albeit rare, hash collisions may occur depending on the syscall name, so care must be taken not to introduce names whose hash collides with existing ones. We expect core developers to rely on proper testing to identify such cases when registering a new syscall in the program loader. It is worth pointing that the solution proposed in this document is an improvement over the existing mechanism that does not realiably distinguish internal and external calls.

Alternatives Considered

None.

Impact

The changes proposed in this SIMD are transparent to dApp developers. The compiler toolchain will emit correct code for the specified SBF version. Static syscalls obviate relocations for call instructions and move the virtual machine closer to eliminating relocations altogether, which can bring considerable performance improvements.

Security Considerations

None.

Evidence graph

Related proposals and rollout

One or more sources are unavailable.

Upstream review record

Upstream discussion & review

GitHub review is editorial context, not evidence of on-chain support, voting, or outcome.

PR #178 · merged SIMD-0178: SBPF Static Syscalls 93 comments and reviews · Apr 6, 2026
@t-nelson

ok yeah i don't really care how collisions are handled so much as i didn't seem them mentioned here despite their existing pretty clearly being possible. i'm guessing something like "care must be taken not to introduce syscall names that produce hash collisions" would be appropriate?

GitHub ↗
@LucasSte

that sounds appropriate to me. I did just that in https://github.com/solana-foundation/solana-improvement-documents/pull/178/commits/4f80c3750c931074c370a6356d7f04fa8b7a4a36.

GitHub ↗
@LucasSte

In https://github.com/solana-foundation/solana-improvement-documents/pull/178/commits/9c37a5a3254a9bef1773002359061491d839fb9d, I condensed all the three previous remarks in a paragraph about collisions.

GitHub ↗
@jacobcreech

Seems reasonable to get out the door.

GitHub ↗
@bw-solana

Latest looks good from my side 👍

GitHub ↗
@simd-botbot

✅ All approvals received! @LucasSte, you can now merge this by commenting /merge. ✅ Status: Ready to merge

GitHub ↗
@simd-botbot

✅ Merge successful! LucasSte(https://github.com/LucasSte)'s PR has been merged.

GitHub ↗

simd.watch community discussion · SIMD-0178

Powered by Giscus · Sign in with GitHub to comment

Community comments load when this section approaches the viewport.

Provenance

Evidence & technical details

Rollout or chain data, source revisions, freshness and integrity.
1

SIMD

Deployment Status

Document lifecycleReview
CategoryCore protocol
Devnetinactive
Testnetinactive
Mainnet-Betainactive
BUwGLeF3Lxyfv1J1wY8biFHBB2hrk2QhbNftQf3VV3cC

Exact source revision

Sources & integrity

  • Proposal document pinned_commit_blob
    0616093b2952ed6de52c4a27d66aadd11d48d4f9
  • simd-document document · current · Sep 11, 2026
    0616093b2952ed6de52c4a27d66aadd11d48d4f9

One or more sources are unavailable.