Grumble, slightly incomprehensible comment. By mention of the library and "unprivileged userspace", I meant something like how BPF or iptables works, where complexity of parsing some expression (or rule set) is handled by a library, which produces easily verifiable byte code, which is then handed off to the kernel.