All of lore.kernel.org
 help / color / mirror / Atom feed
From: "Daniel P. Berrangé" <berrange@redhat.com>
To: Markus Armbruster <armbru@redhat.com>
Cc: Andrew Melnychenko <andrew@daynix.com>,
	jasowang@redhat.com, mst@redhat.com, eblake@redhat.com,
	qemu-devel@nongnu.org, yuri.benditovich@daynix.com,
	yan@daynix.com
Subject: Re: [PATCH v2 5/6] qmp: Added new command to retrieve eBPF blob.
Date: Tue, 16 May 2023 16:18:50 +0100	[thread overview]
Message-ID: <ZGOe2i1ia1qdMuJm@redhat.com> (raw)
In-Reply-To: <87lehonwnj.fsf@pond.sub.org>

On Tue, May 16, 2023 at 05:06:24PM +0200, Markus Armbruster wrote:
> Daniel P. Berrangé <berrange@redhat.com> writes:
> 
> > On Tue, May 16, 2023 at 04:04:39PM +0200, Markus Armbruster wrote:
> >> Daniel P. Berrangé <berrange@redhat.com> writes:
> >> 
> >> > On Tue, May 16, 2023 at 12:23:28PM +0200, Markus Armbruster wrote:
> >> >> Daniel P. Berrangé <berrange@redhat.com> writes:
> >> >> 
> >> >> > On Tue, May 16, 2023 at 10:47:52AM +0200, Markus Armbruster wrote:
> >> >> 
> >> >> [...]
> >> >> 
> >> >> >> So, this is basically a way to retrieve an eBPF program by some
> >> >> >> well-known name.
> >> >> >> 
> >> >> >> Ignorant question: how are these programs desposited?
> >> >> >
> >> >> > The eBPF code blob is linked into QEMU at build time. THis API lets
> >> >> > libvirt fetch it from QEMU, in base64 format. When libvirt later
> >> >> > creates NICs, it can attach the eBPF code blob to the TAP device (which
> >> >> > requires elevated privilleges that QEMU lacks). NB, libvirt would fetch
> >> >> > the eBPF code from QEMU when probing capabilities, as once a VM is
> >> >> > running it is untrusted.
> >> >> 
> >> >> Okay, I can see how that helps.  I trust the blob is in a read-only
> >> >> segment.  Ideally, libvirt fetches it before the guest runs.
> >> >
> >> > Whether the blob is in a read-only segment or not isn't important,
> >> > because it transits writable memory in the QMP command marshalling.
> >> 
> >> True.  We could bypass marshalling.  Unclean hack.  Or we could sign the
> >> bits cryptograhically.  Key management headaches.  Not worth it, because
> >> fetching it before QEMU becomes untrusted is easier.
> >> 
> >> However, I now wonder why we fetch it from QEMU.  Why not ship it with
> >> QEMU?
> >
> > Fetching it from QEMU gives us a strong guarantee that the eBPF
> > code actually matches the QEMU binary we're talking to, which is
> > useful if you're dealing with RPMs which can be upgraded behind
> > your back, or have multiple parallel installs of QEMU.
> 
> Yes, but what makes this one different from all the other things that
> need to match?

Many of the external resources QEMU uses don't need to be a precise
match to a QEMU version, it is sufficient for them to be of "version
X or newer".  eBPF programs need to be a precise match, because the
QEMU code has assumptions about the eBPF code it uses, such as the
configuration maps present.

There is another example where a perfect match is needed - loadable
.so modules. eg if you're running QEMU and trigger dlopen of a QEMU
module, the loaded module needs to come from the perfect matching
build. Most distros don't solve that, but there was something added
a while back that let QEMU load modules from a specific location.

The idea was that the RPM/Deb package manager can upgrade the
modules, but the modules from the previously installed QEMU would be
kept in somewhere temporary like /var/run/...., so that pre-existing
running QEMU could still load the exact matched .sos. While that hack
kinda works it has too many moving parts for my liking, leaving failure
scenarios open. IMHO, being able to directly fetch the resource 
directly from QEMU is a better strategy for eBPF programs, as it
eliminates more of the failure scenarios with very little effort.

With regards,
Daniel
-- 
|: https://berrange.com      -o-    https://www.flickr.com/photos/dberrange :|
|: https://libvirt.org         -o-            https://fstop138.berrange.com :|
|: https://entangle-photo.org    -o-    https://www.instagram.com/dberrange :|



  reply	other threads:[~2023-05-16 15:19 UTC|newest]

Thread overview: 26+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2023-05-12 12:28 [PATCH v2 0/6] eBPF RSS through QMP support Andrew Melnychenko
2023-05-12 12:28 ` [PATCH v2 1/6] ebpf: Added eBPF map update through mmap Andrew Melnychenko
2023-05-15  9:34   ` Daniel P. Berrangé
2023-05-12 12:28 ` [PATCH v2 2/6] ebpf: Added eBPF initialization by fds Andrew Melnychenko
2023-05-15  9:35   ` Daniel P. Berrangé
2023-05-12 12:28 ` [PATCH v2 3/6] virtio-net: Added property to load eBPF RSS with fds Andrew Melnychenko
2023-05-15  9:38   ` Daniel P. Berrangé
2023-05-15 10:53     ` Andrew Melnichenko
2023-05-16 21:21     ` Eric Blake
2023-05-12 12:29 ` [PATCH v2 4/6] ebpf: Added declaration/initialization routines Andrew Melnychenko
2023-05-15  9:44   ` Daniel P. Berrangé
2023-05-12 12:29 ` [PATCH v2 5/6] qmp: Added new command to retrieve eBPF blob Andrew Melnychenko
2023-05-15  9:50   ` Daniel P. Berrangé
2023-05-16  8:47     ` Markus Armbruster
2023-05-16  8:54       ` Daniel P. Berrangé
2023-05-16 10:23         ` Markus Armbruster
2023-05-16 10:29           ` Daniel P. Berrangé
2023-05-16 14:04             ` Markus Armbruster
2023-05-16 14:35               ` Daniel P. Berrangé
2023-05-16 15:06                 ` Markus Armbruster
2023-05-16 15:18                   ` Daniel P. Berrangé [this message]
2023-05-22 10:50                     ` Markus Armbruster
2023-05-12 12:29 ` [PATCH v2 6/6] ebpf: Updated eBPF program and skeleton Andrew Melnychenko
2023-05-15  9:53   ` Daniel P. Berrangé
2023-05-16 21:29   ` Eric Blake
2023-05-12 12:31 ` [PATCH v2 0/6] eBPF RSS through QMP support Andrew Melnichenko

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=ZGOe2i1ia1qdMuJm@redhat.com \
    --to=berrange@redhat.com \
    --cc=andrew@daynix.com \
    --cc=armbru@redhat.com \
    --cc=eblake@redhat.com \
    --cc=jasowang@redhat.com \
    --cc=mst@redhat.com \
    --cc=qemu-devel@nongnu.org \
    --cc=yan@daynix.com \
    --cc=yuri.benditovich@daynix.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.