They should probably put it behind its own capability like CAP_LOAD_EBPF.
Forcing signed ebpf will also help though.
We definitely hit this one at some point: https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1763454
We also ran into a couple of similar but unrelated panic bugs on much newer kernels on non-Ubuntu distros.
It'll be valuable to learn this, so that we might be able to proactively address them. Ebpf is the core of our product.
I've personally never found obtaining a working kernel tree to be difficult, certainly easier than a working BCC toolchain. Or all of the various compiler flags needed for clang not to emit code incompatible with the verifier.
The verifier is definitely annoying, especially at first, but I found myself sort of quickly working out the verifier's expected idiom, and a lot of it can be wrapped with macros.
All of this drama pales in comparison to writing freestyle C code in the Linux kernel without causing random panics.