eBPF (extended Berkeley Packet Filter) is a Linux kernel technology that lets you run sandboxed programs inside the kernel without modifying kernel source code or loading kernel modules. For CPU profiling, this means you can instrument any function — in your application, in libc, in the kernel itself — with microsecond resolution and no process restarts.
Why eBPF over perf. Traditional perf works by sampling the call stack at a fixed frequency (typically 99 Hz). eBPF probes can trigger on specific events — a function entry, a syscall, a kernel tracepoint — giving you exact counts rather than statistical samples. For infrequent but expensive operations (slow disk IOs, page faults, scheduling delays), event-based tracing is far more precise than sampling.
Key tools built on eBPF.
*bpftrace*: A high-level scripting language for ad-hoc eBPF programs. One-liners for most diagnostics. For example, you can trace read() syscall latency for a specific PID in a single bpftrace one-liner using the syscalls:sys_enter_read and sys_exit_read tracepoints.
*BCC (BPF Compiler Collection)*: Python-wrapped eBPF programs for common diagnostics. execsnoop, opensnoop, biolatency, cpudist, and offcputime are all available here.
*Parca / Polar Signals*: Continuous eBPF profiling as a service. Low enough overhead (typically <1% CPU) to run in production permanently.
*Pixie*: Kubernetes-native eBPF observability. Auto-instruments HTTP, gRPC, MySQL, Redis without code changes.
When to use it over perf/strace. Use eBPF when you need exact counts rather than statistical samples, you need to correlate events across processes (e.g. scheduler latency + application response time), or you need kernel-level visibility without a kernel debug build.
Minimum kernel version. eBPF for profiling requires Linux 4.9+. Most production distributions (Ubuntu 18.04+, Debian 10+, RHEL 8+) include a sufficient kernel. Check with: uname -r.
Getting started. Install bpftrace with: apt-get install bpftrace (Ubuntu 20.04+). Run bpftrace -l to list available tracepoints on your kernel. Start with the one-liners in the bpftrace tools/ directory — they cover 90% of common profiling use cases.