How Do I Profile eBPF Code? (naveensrinivasan.com)

91 points by snaveen 5 hours ago

6 comments:

by okzgn 4 hours ago

Here are some complementary resources/papers:

1. Performance of eBPF LSM Hooks: https://dl.acm.org/doi/10.1145/3672197.3673431 (Analyzes the overhead introduced by LSM/tracing hooks on the kernel).

2. Performance of eBPF Maps: https://dl.acm.org/doi/10.1145/3672197.3673430 (Useful context for the htab_map_hash bottleneck shown in the perf report).

3. Network eBPF performance: https://blog.apnic.net/2026/03/25/demystifying-performance-o... (Great broader context on eBPF overhead).

by snaveen 4 hours ago

Thank you for these references! I wasn't aware of these papers.

by tanelpoder 3 hours ago

Last month I wrote a tool called "brr" - eBPF Runtime Reporter and Profiler. It displays a bpftop-like eBPF program summary, but you can also zoom into any program to see its source code lines (if available) and profile the eBPF program activity and any kernel code activity called/caused by the eBPF program for the full picture of where your eBPF program time/latency is spent.

I wrote it mostly with Codex for my own use, but just pushed the latest release to GitHub (with screenshots) in case anyone else is interested:

https://github.com/tanelpoder/brr

by jeffbee 4 hours ago

In addition to cycles, I suggest gathering TLB miss rates. eBPF isn't magical and any maps of significant size may pollute your virtual address translation caches. The last time someone asked me to profile eBPF at work, over 90% of the cycle time was attributable to page table walks, and this also had severe collateral impact on the applications.

by snaveen 3 hours ago

Thank you for the additional insights.

by 000000001 3 hours ago

Lob and Mob.

Data from: Hacker News, provided by Hacker News (unofficial) API