superseded-by:
https://lore.proxmox.com/pve-devel/[email protected]/T/#t

On 2026-09-04 11:05, Hannes Laimer wrote:
> proxmox-ebpf holds the eBPF programs and the code to load and drive
> them, grouped into subsystems. It is a library only, whoever needs a
> subsystem pulls in just that one through a cargo feature and calls it
> from their side. This series is the shared part, the actual
> subsystems come as their own series on top.
> 
> The core is the shared subsystem code. It takes care of the whole
> lifecycle, from loading and attaching per interface to pinning in
> bpffs and tearing down again, so nothing has to keep running and each
> call picks up where the last one left off. Updates are handled too,
> the compiled object is hashed at build time and that hash plus a
> schema version are recorded per subsystem, so a call can tell what
> changed. A changed program is swapped onto the existing links without
> interrupting traffic, a changed map schema gets a teardown and
> rebuild. The BPF C code is also built natively against a small shim,
> so the parsing and packet building logic can be tested without a
> kernel. Packaging is debcargo like the other rust crates.
> 
> The series applies on top of the scaffolding commit of the repo, which
> is not on the list since it carries the vendored vmlinux.h at ~167k
> lines. It is on my staff repo along with these three commits.
> 
> v2:
>  - attach through tcx instead of a clsact qdisc, that qdisc shared its
>    handle with the one the rate limiter installs
>  - fix races between concurrent callers in verify, attach and clear
>  - the pinned state carries schema and fingerprint in its paths, any
>    other schema pinned is rebuilt, a newer one is refused
>  - load every program before pinning any and move existing links onto
>    the new programs after every load
>  - the apply lock is a typed guard, loading and the full pass exist
>    only on the exclusive one
> 
> 
> proxmox-ebpf:
> 
> Hannes Laimer (3):
>   add the shared tc subsystem code
>   tests: add a native harness for the BPF C programs
>   debian: package the crate as a rust library
> 
>  .gitignore                     |   1 +
>  Cargo.toml                     |   7 +
>  Makefile                       |  48 ++++
>  build.rs                       |  67 +++++
>  debian/changelog               |   5 +
>  debian/control                 |  50 ++++
>  debian/copyright               |  18 ++
>  debian/debcargo.toml           |  13 +
>  debian/source/format           |   1 +
>  src/bpf-shim/bpf/bpf_endian.h  |  12 +
>  src/bpf-shim/bpf/bpf_helpers.h |  32 +++
>  src/bpf-shim/bpf_debug.h       |  10 +
>  src/bpf-shim/vmlinux.h         |  70 +++++
>  src/lib.rs                     |   3 +
>  src/subsystem.rs               | 476 +++++++++++++++++++++++++++++++++
>  src/tc.rs                      | 187 +++++++++++++
>  tests/common/mod.rs            | 191 +++++++++++++
>  17 files changed, 1191 insertions(+)
>  create mode 100644 Makefile
>  create mode 100644 debian/changelog
>  create mode 100644 debian/control
>  create mode 100644 debian/copyright
>  create mode 100644 debian/debcargo.toml
>  create mode 100644 debian/source/format
>  create mode 100644 src/bpf-shim/bpf/bpf_endian.h
>  create mode 100644 src/bpf-shim/bpf/bpf_helpers.h
>  create mode 100644 src/bpf-shim/bpf_debug.h
>  create mode 100644 src/bpf-shim/vmlinux.h
>  create mode 100644 src/subsystem.rs
>  create mode 100644 src/tc.rs
>  create mode 100644 tests/common/mod.rs
> 
> 
> Summary over all repositories:
>   17 files changed, 1191 insertions(+), 0 deletions(-)
> 




Reply via email to