On getting tc classifier fully programmable with cls bpf.

On getting tc classifier fully programmable with cls bpf.
复制标题

关于使用 cls bpf 完全编程 tc 分类器。

DOI:
--
复制
发表时间:
2016
期刊:
影响因子:
--
通讯作者:
Daniel Borkmann
Daniel Borkmann
中科院分区:
--
文献类型:
--
作者:
Daniel Borkmann

文献摘要

被引文献

相似文献

Berkely Packet Filter,简称BPF,是很久以前设计于1993[18][1]的指令集体系结构,作为libpCap/tcpump等应用程序的通用数据包过滤解决方案,并长期存在于Linux内核中,在网络之外也被使用,例如在seccomp BPF[15]中用于系统调用过滤。近年来,Linux社区在内核中用名为“扩展BPF”(EBPF)[21][23][22][24]的新指令集体系结构取代了目前被称为经典BPF(CBPF)的解释器,与它的前身相比,它带来了更多的灵活性和可编程性方面,并伴随着新的用例,如跟踪[27]或最近的KCM[17]。随着解释器的更换,即时(JIT)编译器也进行了升级,以翻译eBPF[25],以便以本机性能运行程序。随着eBPF支持被添加到内核的CLS BPF分类器[8]中的流量控制层[8],TC获得了一个强大的成员来编程Linux的数据平面,与内核的网络堆栈和相关工具紧密集成,以及与其前身cBPF不同的底层编程范例。在本文中,我们提供了eBPF的基本概述及其与TC的交互,并讨论了Linux网络社区最近在eBPF方面所做的一些工作。本文的目的不是全面介绍eBPF的所有方面,而是试图为对其体系结构和
Berkely Packet Filter, short BPF, is an instruction set architecture that was designed long ago in 1993 [18] [1] as a generic packet filtering solution for applications such as libpcap/tcpdump and is long present in Linux kernels, where it is also being used outside of networking, e.g. in seccomp BPF [15] for system call filtering. In recent years, the Linux community replaced the nowadays referred to as classic BPF (cBPF) interpreter inside the kernel with a new instruction set architecture called ”extended BPF” (eBPF) [21] [23] [22] [24] that brings far more flexibility and programmability aspects compared to its predecessor, and new use cases along with it such as tracing [27] or more recently KCM [17]. Along with the interpreter replacement, also the just-in-time (JIT) compiler has been upgraded to translate eBPF [25] for running programs with native performance. With eBPF support that has been added to the kernel’s cls bpf classifier [8] in the traffic control layer [8], tc has gained a powerful member to program Linux’ data plane with a tight integration to the kernel’s networking stack and related tooling as well as different underlying programming paradigms compared to its cBPF predecessor. In this paper, we provide a basic overview of eBPF, its interaction with tc, and discuss some of the recent work that went into eBPF that has been done by the Linux networking community. The intention of this paper is not to provide complete coverage of all eBPF aspects, but rather tries to be a informational starting point for people interested in its architecture and