On getting tc classifier fully programmable with cls bpf.
On getting tc classifier fully programmable with cls bpf.
复制标题
关于使用 cls bpf 完全编程 tc 分类器。
DOI:
--
复制
发表时间:
2016
期刊:
影响因子:
--
通讯作者:
Daniel Borkmann
中科院分区:
文献类型:
--
作者:
Daniel Borkmann
Berkely Packet Filter, short BPF, is an instruction set architecture that was designed long ago in 1993 [18] [1] as a generic packet filtering solution for applications such as libpcap/tcpdump and is long present in Linux kernels, where it is also being used outside of networking, e.g. in seccomp BPF [15] for system call filtering. In recent years, the Linux community replaced the nowadays referred to as classic BPF (cBPF) interpreter inside the kernel with a new instruction set architecture called ”extended BPF” (eBPF) [21] [23] [22] [24] that brings far more flexibility and programmability aspects compared to its predecessor, and new use cases along with it such as tracing [27] or more recently KCM [17]. Along with the interpreter replacement, also the just-in-time (JIT) compiler has been upgraded to translate eBPF [25] for running programs with native performance. With eBPF support that has been added to the kernel’s cls bpf classifier [8] in the traffic control layer [8], tc has gained a powerful member to program Linux’ data plane with a tight integration to the kernel’s networking stack and related tooling as well as different underlying programming paradigms compared to its cBPF predecessor. In this paper, we provide a basic overview of eBPF, its interaction with tc, and discuss some of the recent work that went into eBPF that has been done by the Linux networking community. The intention of this paper is not to provide complete coverage of all eBPF aspects, but rather tries to be a informational starting point for people interested in its architecture and