From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from gate001.proxmox.com (gate001.proxmox.com [IPv6:2a0f:8001:1:32::40]) by lore.proxmox.com (Postfix) with ESMTPS id 5E6AF1FF0B3 for ; Wed, 09 Sep 2026 12:40:50 +0200 (CEST) Received: from gate001.proxmox.com (localhost.localdomain [127.0.0.1]) by gate001.proxmox.com (Proxmox) with ESMTP id 5898321590; Wed, 09 Sep 2026 12:40:34 +0200 (CEST) From: Hannes Laimer To: pve-devel@lists.proxmox.com Subject: [PATCH proxmox-ebpf v3 0/3] add proxmox-ebpf library Date: Wed, 9 Sep 2026 12:39:49 +0200 Message-ID: <20260909103952.1108084-1-h.laimer@proxmox.com> X-Mailer: git-send-email 2.47.3 MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-Bm-Milter-Handled: 55990f41-d878-4baa-be0a-ee34c49e34d2 X-Bm-Transport-Timestamp: 1788950388724 X-SPAM-LEVEL: Spam detection results: 0 AWL 0.570 Adjusted score from AWL reputation of From: address DMARC_MISSING 0.1 Missing DMARC policy KAM_DMARC_STATUS 0.01 Test Rule for DKIM or SPF Failure with Strict Alignment (newer systems) RCVD_IN_DNSWL_MED -2.3 Sender listed at https://www.dnswl.org/, medium trust SPF_HELO_NONE 0.001 SPF: HELO does not publish an SPF Record SPF_PASS -0.001 SPF: sender matches SPF record Message-ID-Hash: 5Z64NA7RT7TFOG2FSDCNRHOGRNBJIWAA X-Message-ID-Hash: 5Z64NA7RT7TFOG2FSDCNRHOGRNBJIWAA X-MailFrom: h.laimer@proxmox.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header X-Mailman-Version: 3.3.10 Precedence: list List-Id: Proxmox VE development discussion List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: proxmox-ebpf holds the eBPF programs and the code to load and drive them, grouped into subsystems. It is a library only, whoever needs a subsystem pulls in just that one through a cargo feature and calls it from their side. This series is the shared part, the actual subsystems come as their own series on top. The core is the shared subsystem code. It takes care of the whole lifecycle, from loading and attaching per interface to pinning in bpffs and tearing down again. So nothing has to keep running, and each call picks up where the last one left off. Updates are handled too. The compiled object is hashed at build time and that hash plus a schema version are recorded per subsystem, so a call can tell what changed. A changed program is swapped onto the existing links without interrupting traffic, a changed map schema gets a teardown and rebuild. The BPF C code is also built natively against a small shim, so the parsing and packet building logic can be tested without a kernel. Packaging is debcargo like the other rust crates. Changes carry a generation, a counter under /run. An apply notes its generation before it runs, so an older apply is dropped. So is a single change older than the last apply, that apply already read the change's input. A single change holds a lock while it reads and writes its entry and gets the generation of the last apply with it. That is all the lib does with the number. The subsystem decides when a change draws one, before or after it reads its input, and what an entry's generation means when a newer or an older one arrives. So the ordering rules live with the map they order. The series applies on top of the scaffolding commit of the repo, which is not on the list since it carries the vendored vmlinux.h at ~167k lines. It is on my staff repo along with these three commits. note: like for the dhcp series, this is only v3 due to me missing a problem and assuming it was fixed too fast. sorry for the noise also here :) proxmox-ebpf: Hannes Laimer (3): add the shared tc subsystem code tests: add a native harness for the BPF C programs debian: package the crate as a rust library .gitignore | 1 + Cargo.toml | 7 + Makefile | 54 ++ build.rs | 67 +++ debian/changelog | 5 + debian/control | 50 ++ debian/copyright | 26 + debian/debcargo.toml | 13 + debian/source/format | 1 + src/bpf-shim/bpf/bpf_endian.h | 12 + src/bpf-shim/bpf/bpf_helpers.h | 34 ++ src/bpf-shim/bpf_debug.h | 10 + src/bpf-shim/vmlinux.h | 70 +++ src/lib.rs | 3 + src/subsystem.rs | 901 +++++++++++++++++++++++++++++++++ src/tc.rs | 257 ++++++++++ tests/common/mod.rs | 209 ++++++++ tests/harness.rs | 65 +++ 18 files changed, 1785 insertions(+) create mode 100644 Makefile create mode 100644 debian/changelog create mode 100644 debian/control create mode 100644 debian/copyright create mode 100644 debian/debcargo.toml create mode 100644 debian/source/format create mode 100644 src/bpf-shim/bpf/bpf_endian.h create mode 100644 src/bpf-shim/bpf/bpf_helpers.h create mode 100644 src/bpf-shim/bpf_debug.h create mode 100644 src/bpf-shim/vmlinux.h create mode 100644 src/subsystem.rs create mode 100644 src/tc.rs create mode 100644 tests/common/mod.rs create mode 100644 tests/harness.rs Summary over all repositories: 18 files changed, 1785 insertions(+), 0 deletions(-) -- Generated by murpp 0.12.0