finds.dev← search

// the find

tanelpoder/0xtools

★ 1,822 · Python · GPL-2.0 · updated Nov 2025

0x.Tools: X-Ray vision for Linux systems

0x.Tools is Tanel Poder's eBPF-based rewrite of his long-running Linux thread-activity sampler, now built on modern libbpf/CORE/BTF instead of bcc or bpftrace, paired with xtop, a DuckDB + Textual TUI for slicing the captured samples. It's for people doing low-level Linux performance troubleshooting (on-call SREs, DBAs, kernel-curious engineers) who want per-thread syscall/IO/scheduling visibility without rolling their own eBPF tooling.

Sampling runs inside the kernel via eBPF task iterators, so the userspace driver just triggers it periodically — measured overhead is 0.01-2% of a single core even on a 384-CPU NUMA box, which is a real number from production hardware, not a marketing claim. Capture needs root but reading the resulting CSV/parquet files doesn't, so analysts can work off the same dataset without touching the privileged path. xtop queries the output directly with DuckDB and hand-written SQL fragments (xtop/sql/fragments) instead of inventing a bespoke query layer, so anyone who knows SQL can read or extend it. The repo keeps its three prior failed/superseded implementations (proc-polling, bpftrace, bcc) under experiments/, which is an unusually honest record of what didn't scale well enough to ship.

Kernel requirements are a real tax: 5.11+ for the basics, 5.14+/5.18+ (or a specific vendor backport like RHEL 9.5's UEK7) for full functionality, and a crippled 'make old' build for anything else — this will be a fight on any fleet that isn't on a bleeding-edge kernel. It's a first release of a ground-up rewrite (v3.0.3, 2025-10-23) replacing three earlier approaches, so the on-disk schema and CLI are likely to shift, and most of the real explanation lives in external blog posts rather than in the repo itself. xtop's test directory is mostly one-off debug scripts (test_column_bug.py, test_heatmap_debug.py, test_modal_enter_key_fix.py) rather than a real regression suite, so there's little confidence refactoring the TUI won't silently break something. It's a single-threaded, single-process capture daemon pinned to one host via real-time scheduling — there's nothing here for aggregating or correlating samples across a fleet, you're on your own past one box.

View on GitHub → Homepage ↗

// want more like this?

We dig through GitHub every week and send a few repos picked for what you actually care about — each with an honest take like this one.

Get finds in your inbox → Search again →