eBPF
Purpose
Guide agents through writing, loading, and debugging eBPF programs using libbpf, bpftrace, and bpftool. Covers map types, program types, verifier errors, XDP networking, and CO-RE portability.
Triggers
- "How do I write an eBPF program to trace system calls?"
- "My eBPF program fails with a verifier error"
- "How do I use bpftrace to trace kernel events?"
- "How do I share data between kernel eBPF and userspace?"
- "How do I write an XDP program for packet filtering?"
- "How do I make my eBPF program portable across kernel versions (CO-RE)?"
Workflow
1. Choose the right tool
2. bpftrace — quick kernel tracing
3. libbpf skeleton — minimal C program
libbpf 1.x API changes:
4. eBPF map types
Use BPF_MAP_TYPE_RINGBUF over PERF_EVENT_ARRAY for new code — lower overhead, variable-size records.
5. Verifier error triage
6. XDP programs
XDP return codes: XDP_PASS, XDP_DROP, XDP_TX (hairpin), XDP_REDIRECT.
7. CO-RE — compile once, run everywhere
CO-RE (Compile Once - Run Everywhere) uses BTF type info to relocate field accesses at load time.
8. BPF ring buffer vs perf buffer
9. BPF iterators
Iterators walk kernel data structures (tasks, maps, TCP sockets) without kprobe overhead per element.
10. BPF atomics
Prefer per-CPU array maps for high-frequency counters; use atomics when aggregating into a single map value.
For the full map types reference, see references/ebpf-map-types.md [blocked].
Related skills
- Use
skills/observability/ebpf-rustfor Aya framework Rust eBPF programs - Use
skills/profilers/linux-perffor perf-based tracing without eBPF - Use
skills/runtimes/binary-hardeningfor seccomp-bpf syscall filtering - Use
skills/low-level-programming/linux-kernel-modulesfor kernel module development - Use
skills/async-io/af-xdpfor XDP_REDIRECT to AF_XDP sockets


