π€ AI Summary
This study addresses the failure of eBPF-based observability in non-standard execution environments, such as Trusted Execution Environments (TEEs) and Library Operating Systems (LibOSes), caused by constrained memory mechanisms. We propose a general-purpose observation framework that introduces kernel memory extension and secure access mechanisms. Specifically, we design a Lightweight Flexible Probe Performance Measurement Unit (LWFP PMU) and develop two novel probe architectures, SLWFP and ELWFP, overcoming the compatibility barriers of native Linux tools in non-standard environments. Experimental results demonstrate that SLWFP achieves a latency of only 394 ns, outperforming uprobes, while ELWFP incurs approximately 2.8 ΞΌs latency with minimal overhead. The proposed framework successfully enables universal tracing, dynamic instrumentation, flame graph generation, and USDT support within both SGX enclaves and LibOSes.
π Abstract
eBPF observability of non-standard execution environments (NEEs) like TEEs or LibOSes is hindered by their unconventional exception-handling and memory-access mechanisms that limit standard Linux tooling. This work introduces two mechanisms that enable eBPF-based observability for NEEs: (1) kernel memory extensions for safely accessing NEE memory from eBPF programs, and (2) a lightweight flexible probe performance measurement unit (LWFP PMU) that provides flexible and generic probing, for NEEs, through the following LWFP: simple (SLWFP), enclave (ELWFP) and extended (ExLWFP) probes. We demonstrate the practicality of these extensions by developing tooling for tracing, stack sampling with Flame Graphs, dynamic instrumentation, timing analysis, and USDT support for Intel SGX enclaves and LibOSes. Performance measurements show that SLWFP probes achieve a latency of 394 ns, outperforming uprobes, which exhibit 25% higher latency, while ELWFP probes incur a latency ~2.8 microseconds, which is practical for enclave observability. The addition of SLWFP introduces negligible overhead to existing uprobe performance. Taken together, this work lays the foundation for closing the long-standing gap between NEE tooling and Linux observability tooling by enabling generic and reusable eBPF tooling for diverse NEE hardware and software architectures.