From: Hannes Laimer <h.laimer@proxmox.com>
To: pve-devel@lists.proxmox.com
Subject: superseded: [PATCH proxmox-ebpf v2 0/3] add proxmox-ebpf library
Date: Wed, 9 Sep 2026 12:42:43 +0200 [thread overview]
Message-ID: <83508f39-86aa-4129-8309-7e6047c15781@proxmox.com> (raw)
In-Reply-To: <20260904090458.990888-1-h.laimer@proxmox.com>
superseded-by:
https://lore.proxmox.com/pve-devel/20260909103952.1108084-1-h.laimer@proxmox.com/T/#t
On 2026-09-04 11:05, Hannes Laimer wrote:
> proxmox-ebpf holds the eBPF programs and the code to load and drive
> them, grouped into subsystems. It is a library only, whoever needs a
> subsystem pulls in just that one through a cargo feature and calls it
> from their side. This series is the shared part, the actual
> subsystems come as their own series on top.
>
> The core is the shared subsystem code. It takes care of the whole
> lifecycle, from loading and attaching per interface to pinning in
> bpffs and tearing down again, so nothing has to keep running and each
> call picks up where the last one left off. Updates are handled too,
> the compiled object is hashed at build time and that hash plus a
> schema version are recorded per subsystem, so a call can tell what
> changed. A changed program is swapped onto the existing links without
> interrupting traffic, a changed map schema gets a teardown and
> rebuild. The BPF C code is also built natively against a small shim,
> so the parsing and packet building logic can be tested without a
> kernel. Packaging is debcargo like the other rust crates.
>
> The series applies on top of the scaffolding commit of the repo, which
> is not on the list since it carries the vendored vmlinux.h at ~167k
> lines. It is on my staff repo along with these three commits.
>
> v2:
> - attach through tcx instead of a clsact qdisc, that qdisc shared its
> handle with the one the rate limiter installs
> - fix races between concurrent callers in verify, attach and clear
> - the pinned state carries schema and fingerprint in its paths, any
> other schema pinned is rebuilt, a newer one is refused
> - load every program before pinning any and move existing links onto
> the new programs after every load
> - the apply lock is a typed guard, loading and the full pass exist
> only on the exclusive one
>
>
> proxmox-ebpf:
>
> Hannes Laimer (3):
> add the shared tc subsystem code
> tests: add a native harness for the BPF C programs
> debian: package the crate as a rust library
>
> .gitignore | 1 +
> Cargo.toml | 7 +
> Makefile | 48 ++++
> build.rs | 67 +++++
> debian/changelog | 5 +
> debian/control | 50 ++++
> debian/copyright | 18 ++
> debian/debcargo.toml | 13 +
> debian/source/format | 1 +
> src/bpf-shim/bpf/bpf_endian.h | 12 +
> src/bpf-shim/bpf/bpf_helpers.h | 32 +++
> src/bpf-shim/bpf_debug.h | 10 +
> src/bpf-shim/vmlinux.h | 70 +++++
> src/lib.rs | 3 +
> src/subsystem.rs | 476 +++++++++++++++++++++++++++++++++
> src/tc.rs | 187 +++++++++++++
> tests/common/mod.rs | 191 +++++++++++++
> 17 files changed, 1191 insertions(+)
> create mode 100644 Makefile
> create mode 100644 debian/changelog
> create mode 100644 debian/control
> create mode 100644 debian/copyright
> create mode 100644 debian/debcargo.toml
> create mode 100644 debian/source/format
> create mode 100644 src/bpf-shim/bpf/bpf_endian.h
> create mode 100644 src/bpf-shim/bpf/bpf_helpers.h
> create mode 100644 src/bpf-shim/bpf_debug.h
> create mode 100644 src/bpf-shim/vmlinux.h
> create mode 100644 src/subsystem.rs
> create mode 100644 src/tc.rs
> create mode 100644 tests/common/mod.rs
>
>
> Summary over all repositories:
> 17 files changed, 1191 insertions(+), 0 deletions(-)
>
prev parent reply other threads:[~2026-09-09 10:45 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-04 9:04 [PATCH proxmox-ebpf v2 0/3] add proxmox-ebpf library Hannes Laimer
2026-09-04 9:04 ` [PATCH proxmox-ebpf v2 1/3] add the shared tc subsystem code Hannes Laimer
2026-09-04 9:04 ` [PATCH proxmox-ebpf v2 2/3] tests: add a native harness for the BPF C programs Hannes Laimer
2026-09-04 9:04 ` [PATCH proxmox-ebpf v2 3/3] debian: package the crate as a rust library Hannes Laimer
2026-09-09 10:42 ` Hannes Laimer [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=83508f39-86aa-4129-8309-7e6047c15781@proxmox.com \
--to=h.laimer@proxmox.com \
--cc=pve-devel@lists.proxmox.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox