superseded-by: https://lore.proxmox.com/pve-devel/[email protected]/T/#t
On 2026-09-04 11:05, Hannes Laimer wrote: > proxmox-ebpf holds the eBPF programs and the code to load and drive > them, grouped into subsystems. It is a library only, whoever needs a > subsystem pulls in just that one through a cargo feature and calls it > from their side. This series is the shared part, the actual > subsystems come as their own series on top. > > The core is the shared subsystem code. It takes care of the whole > lifecycle, from loading and attaching per interface to pinning in > bpffs and tearing down again, so nothing has to keep running and each > call picks up where the last one left off. Updates are handled too, > the compiled object is hashed at build time and that hash plus a > schema version are recorded per subsystem, so a call can tell what > changed. A changed program is swapped onto the existing links without > interrupting traffic, a changed map schema gets a teardown and > rebuild. The BPF C code is also built natively against a small shim, > so the parsing and packet building logic can be tested without a > kernel. Packaging is debcargo like the other rust crates. > > The series applies on top of the scaffolding commit of the repo, which > is not on the list since it carries the vendored vmlinux.h at ~167k > lines. It is on my staff repo along with these three commits. > > v2: > - attach through tcx instead of a clsact qdisc, that qdisc shared its > handle with the one the rate limiter installs > - fix races between concurrent callers in verify, attach and clear > - the pinned state carries schema and fingerprint in its paths, any > other schema pinned is rebuilt, a newer one is refused > - load every program before pinning any and move existing links onto > the new programs after every load > - the apply lock is a typed guard, loading and the full pass exist > only on the exclusive one > > > proxmox-ebpf: > > Hannes Laimer (3): > add the shared tc subsystem code > tests: add a native harness for the BPF C programs > debian: package the crate as a rust library > > .gitignore | 1 + > Cargo.toml | 7 + > Makefile | 48 ++++ > build.rs | 67 +++++ > debian/changelog | 5 + > debian/control | 50 ++++ > debian/copyright | 18 ++ > debian/debcargo.toml | 13 + > debian/source/format | 1 + > src/bpf-shim/bpf/bpf_endian.h | 12 + > src/bpf-shim/bpf/bpf_helpers.h | 32 +++ > src/bpf-shim/bpf_debug.h | 10 + > src/bpf-shim/vmlinux.h | 70 +++++ > src/lib.rs | 3 + > src/subsystem.rs | 476 +++++++++++++++++++++++++++++++++ > src/tc.rs | 187 +++++++++++++ > tests/common/mod.rs | 191 +++++++++++++ > 17 files changed, 1191 insertions(+) > create mode 100644 Makefile > create mode 100644 debian/changelog > create mode 100644 debian/control > create mode 100644 debian/copyright > create mode 100644 debian/debcargo.toml > create mode 100644 debian/source/format > create mode 100644 src/bpf-shim/bpf/bpf_endian.h > create mode 100644 src/bpf-shim/bpf/bpf_helpers.h > create mode 100644 src/bpf-shim/bpf_debug.h > create mode 100644 src/bpf-shim/vmlinux.h > create mode 100644 src/subsystem.rs > create mode 100644 src/tc.rs > create mode 100644 tests/common/mod.rs > > > Summary over all repositories: > 17 files changed, 1191 insertions(+), 0 deletions(-) >
