How Do I Profile eBPF Code?

(naveensrinivasan.com)

69 points | by snaveen 2 hours ago

4 comments

  • tanelpoder 7 minutes ago
    Last month I wrote a tool called "brr" - eBPF Runtime Reporter and Profiler. It displays a bpftop-like eBPF program summary, but you can also zoom into any program to see its source code lines (if available) and profile the eBPF program activity and any kernel code activity called/caused by the eBPF program for the full picture of where your eBPF program time/latency is going.

    I wrote it mostly with Codex for my own use, but just pushed the latest release to GitHub (with screenshots) in case anyone else is interested:

    https://github.com/tanelpoder/brr

  • okzgn 1 hour ago
    Here are some complementary resources/papers:

    1. Performance of eBPF LSM Hooks: https://dl.acm.org/doi/10.1145/3672197.3673431 (Analyzes the overhead introduced by LSM/tracing hooks on the kernel).

    2. Performance of eBPF Maps: https://dl.acm.org/doi/10.1145/3672197.3673430 (Useful context for the htab_map_hash bottleneck shown in the perf report).

    3. Network eBPF performance: https://blog.apnic.net/2026/03/25/demystifying-performance-o... (Great broader context on eBPF overhead).

    • snaveen 1 hour ago
      Thank you for these references! I wasn't aware of these papers.
    • tanelpoder 37 minutes ago
      [dead]
  • jeffbee 1 hour ago
    In addition to cycles, I suggest gathering TLB miss rates. eBPF isn't magical and any maps of significant size may pollute your virtual address translation caches. The last time someone asked me to profile eBPF at work, over 90% of the cycle time was attributable to page table walks, and this also had severe collateral impact on the applications.
    • snaveen 54 minutes ago
      Thank you for the additional insights.
  • 000000001 47 minutes ago
    Lob and Mob.