Extending eBPF observability to Non-standard execution environments

πŸ“… 2026-09-30
πŸ“ˆ Citations: 0
✨ Influential: 0
πŸ“„ PDF
πŸ€– AI Summary
This study addresses the failure of eBPF-based observability in non-standard execution environments, such as Trusted Execution Environments (TEEs) and Library Operating Systems (LibOSes), caused by constrained memory mechanisms. We propose a general-purpose observation framework that introduces kernel memory extension and secure access mechanisms. Specifically, we design a Lightweight Flexible Probe Performance Measurement Unit (LWFP PMU) and develop two novel probe architectures, SLWFP and ELWFP, overcoming the compatibility barriers of native Linux tools in non-standard environments. Experimental results demonstrate that SLWFP achieves a latency of only 394 ns, outperforming uprobes, while ELWFP incurs approximately 2.8 ΞΌs latency with minimal overhead. The proposed framework successfully enables universal tracing, dynamic instrumentation, flame graph generation, and USDT support within both SGX enclaves and LibOSes.
πŸ“ Abstract
eBPF observability of non-standard execution environments (NEEs) like TEEs or LibOSes is hindered by their unconventional exception-handling and memory-access mechanisms that limit standard Linux tooling. This work introduces two mechanisms that enable eBPF-based observability for NEEs: (1) kernel memory extensions for safely accessing NEE memory from eBPF programs, and (2) a lightweight flexible probe performance measurement unit (LWFP PMU) that provides flexible and generic probing, for NEEs, through the following LWFP: simple (SLWFP), enclave (ELWFP) and extended (ExLWFP) probes. We demonstrate the practicality of these extensions by developing tooling for tracing, stack sampling with Flame Graphs, dynamic instrumentation, timing analysis, and USDT support for Intel SGX enclaves and LibOSes. Performance measurements show that SLWFP probes achieve a latency of 394 ns, outperforming uprobes, which exhibit 25% higher latency, while ELWFP probes incur a latency ~2.8 microseconds, which is practical for enclave observability. The addition of SLWFP introduces negligible overhead to existing uprobe performance. Taken together, this work lays the foundation for closing the long-standing gap between NEE tooling and Linux observability tooling by enabling generic and reusable eBPF tooling for diverse NEE hardware and software architectures.
Problem

Research questions and friction points this paper is trying to address.

eBPF observability
non-standard execution environments
Trusted Execution Environments
LibOS
memory access
Innovation

Methods, ideas, or system contributions that make the work stand out.

eBPF observability
Non-standard execution environments
LWFP PMU
Intel SGX
dynamic instrumentation
πŸ”Ž Similar Papers
No similar papers found.
πŸ’Ό Related Jobs
No related jobs found.
P
Pamenas Kariuki
TU Dresden, Germany
A
AndrΓ© Martin
TU Dresden, Germany
Christof Fetzer
Christof Fetzer
TU Dresden
dependabilitySGXdistributed systemscloud computing