From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from gate001.proxmox.com (gate001.proxmox.com [45.144.208.40]) by lore.proxmox.com (Postfix) with ESMTPS id 32D601FF0B3 for ; Wed, 09 Sep 2026 12:45:06 +0200 (CEST) Received: from gate001.proxmox.com (localhost.localdomain [127.0.0.1]) by gate001.proxmox.com (Proxmox) with ESMTP id DD916215D1; Wed, 09 Sep 2026 12:44:32 +0200 (CEST) Message-ID: <83508f39-86aa-4129-8309-7e6047c15781@proxmox.com> Date: Wed, 9 Sep 2026 12:42:43 +0200 MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: superseded: [PATCH proxmox-ebpf v2 0/3] add proxmox-ebpf library To: pve-devel@lists.proxmox.com References: <20260904090458.990888-1-h.laimer@proxmox.com> From: Hannes Laimer Content-Language: en-US In-Reply-To: <20260904090458.990888-1-h.laimer@proxmox.com> Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit X-Bm-Milter-Handled: 55990f41-d878-4baa-be0a-ee34c49e34d2 X-Bm-Transport-Timestamp: 1788950555605 X-SPAM-LEVEL: Spam detection results: 0 AWL 0.520 Adjusted score from AWL reputation of From: address DMARC_MISSING 0.1 Missing DMARC policy KAM_DMARC_STATUS 0.01 Test Rule for DKIM or SPF Failure with Strict Alignment (newer systems) RCVD_IN_DNSWL_MED -2.3 Sender listed at https://www.dnswl.org/, medium trust SPF_HELO_NONE 0.001 SPF: HELO does not publish an SPF Record SPF_PASS -0.001 SPF: sender matches SPF record Message-ID-Hash: GE6L553Y7GBAH2GBVQ45Q4Y2WQKEPVOA X-Message-ID-Hash: GE6L553Y7GBAH2GBVQ45Q4Y2WQKEPVOA X-MailFrom: h.laimer@proxmox.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header X-Mailman-Version: 3.3.10 Precedence: list List-Id: Proxmox VE development discussion List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: superseded-by: https://lore.proxmox.com/pve-devel/20260909103952.1108084-1-h.laimer@proxmox.com/T/#t On 2026-09-04 11:05, Hannes Laimer wrote: > proxmox-ebpf holds the eBPF programs and the code to load and drive > them, grouped into subsystems. It is a library only, whoever needs a > subsystem pulls in just that one through a cargo feature and calls it > from their side. This series is the shared part, the actual > subsystems come as their own series on top. > > The core is the shared subsystem code. It takes care of the whole > lifecycle, from loading and attaching per interface to pinning in > bpffs and tearing down again, so nothing has to keep running and each > call picks up where the last one left off. Updates are handled too, > the compiled object is hashed at build time and that hash plus a > schema version are recorded per subsystem, so a call can tell what > changed. A changed program is swapped onto the existing links without > interrupting traffic, a changed map schema gets a teardown and > rebuild. The BPF C code is also built natively against a small shim, > so the parsing and packet building logic can be tested without a > kernel. Packaging is debcargo like the other rust crates. > > The series applies on top of the scaffolding commit of the repo, which > is not on the list since it carries the vendored vmlinux.h at ~167k > lines. It is on my staff repo along with these three commits. > > v2: > - attach through tcx instead of a clsact qdisc, that qdisc shared its > handle with the one the rate limiter installs > - fix races between concurrent callers in verify, attach and clear > - the pinned state carries schema and fingerprint in its paths, any > other schema pinned is rebuilt, a newer one is refused > - load every program before pinning any and move existing links onto > the new programs after every load > - the apply lock is a typed guard, loading and the full pass exist > only on the exclusive one > > > proxmox-ebpf: > > Hannes Laimer (3): > add the shared tc subsystem code > tests: add a native harness for the BPF C programs > debian: package the crate as a rust library > > .gitignore | 1 + > Cargo.toml | 7 + > Makefile | 48 ++++ > build.rs | 67 +++++ > debian/changelog | 5 + > debian/control | 50 ++++ > debian/copyright | 18 ++ > debian/debcargo.toml | 13 + > debian/source/format | 1 + > src/bpf-shim/bpf/bpf_endian.h | 12 + > src/bpf-shim/bpf/bpf_helpers.h | 32 +++ > src/bpf-shim/bpf_debug.h | 10 + > src/bpf-shim/vmlinux.h | 70 +++++ > src/lib.rs | 3 + > src/subsystem.rs | 476 +++++++++++++++++++++++++++++++++ > src/tc.rs | 187 +++++++++++++ > tests/common/mod.rs | 191 +++++++++++++ > 17 files changed, 1191 insertions(+) > create mode 100644 Makefile > create mode 100644 debian/changelog > create mode 100644 debian/control > create mode 100644 debian/copyright > create mode 100644 debian/debcargo.toml > create mode 100644 debian/source/format > create mode 100644 src/bpf-shim/bpf/bpf_endian.h > create mode 100644 src/bpf-shim/bpf/bpf_helpers.h > create mode 100644 src/bpf-shim/bpf_debug.h > create mode 100644 src/bpf-shim/vmlinux.h > create mode 100644 src/subsystem.rs > create mode 100644 src/tc.rs > create mode 100644 tests/common/mod.rs > > > Summary over all repositories: > 17 files changed, 1191 insertions(+), 0 deletions(-) >