Netdev List
 help / color / mirror / Atom feed
* [PATCH net-next 00/15] Gated tracepoints for skb lifecycle (free+clone)
@ 2026-09-28 11:40 Jakub Sitnicki
  2026-09-28 11:40 ` [PATCH net-next 01/15] bpf: Add gated tracepoints for skb life-cycle Jakub Sitnicki
                   ` (15 more replies)
  0 siblings, 16 replies; 18+ messages in thread
From: Jakub Sitnicki @ 2026-09-28 11:40 UTC (permalink / raw)
  To: netdev, Alexei Starovoitov, Jakub Kicinski, Kuniyuki Iwashima,
	Paolo Abeni, Stanislav Fomichev
  Cc: bpf, kernel-team, Daniel Borkmann, John Fastabend,
	Andrii Nakryiko, Eduard Zingerman, Kumar Kartikeya Dwivedi,
	Martin KaFai Lau, Song Liu, Yonghong Song, Jiri Olsa,
	Emil Tsalapatis, David S. Miller, Eric Dumazet, Simon Horman,
	Jesper Dangaard Brouer, Willem de Bruijn

This patch set implements Alexei's idea of gated tracepoints for skb lifecycle
events, which offers an alternative to an skb extension for BPF metadata [1]. I
have kept it down to a usable minimum - patches introduce gated tracepoints only
for skb consume/drop and clone/copy.

* Implementation

... is pretty straightforward. Please see patch 1 description for details.

One note - at first I tried to use of skb extensions - the free bit left in
skb->active_extensions and the skb_ext_reset/put/copy code paths. That turned
out to be a wrong direction. A "special" skb extension that doesn't require
space allocated in skb->extensions slab makes the logic messier.

Hence, I went back to simplest possible approach of having a dedicated bit
directly in sk_buff and adding callbacks directly from core networking code.

* Performance

Early results I've posted on Friday [2] were wrong. I owe a correction. They
were heavily skewed by KVM halt polling being enabled. That led to some
nonsensical numbers sometimes - like a plain TC packet counter measuring as more
expensive than TC + skb extensions.

New, stable, reproducible results tell a different story - gated tracepoints are
~2.5x more expensive than skb extensions:

| variant           | Δ busy         | ns/pkt @146k |
|-------------------|----------------|--------------|
| gated tracepoints | +16.4 ± 2.8 pp | ≈ +1125      |
| bpf skb ext       | +6.6 ± 1.1 pp  | ≈ +450       |

Setup:
- 146k pps spread over 3 flows,
- 36B UDP msgs over loopback,
- 6 measured vCPUs on pinned cores clamped @ 2.7 GHz,
- per-packet metadata on every packet,
- KVM halt polling disabled on host.

I've published full benchmark results + setup + code on GH [3].

* Final thoughts

Even though gated tracepoints are more CPU intensive, I think they offer a
better building platform for users. Every user/tenant manages their own metadata
stash and they can select an allocation strategy that best fits their use case.

There is extra CPU overhead, but the fact that we need to pay it only for
packets that we're tracing makes it palatable. As I mentioned earlier, we attach
metadata to less than 1% of skbs today. Naturally, we would be looking to lower
the gated-tracepoints cost.

There is also potential for giving users finer-grained control over metadata
lifetime in the future by adding tracepoints on skb scrub, GRO merge, or TCP
coalesce/collapse.

While we can make either solution work because we don't have tenants with access
to BPF in production, others might not have that luxury. Now would be a good
time for folks operating K8S environments to speak up.

Looking forward to feedback,
-jkbs

PS. I'm prepping for Plumbers this week so probably won't be able to circle back
to this until next week.

[1] https://lore.kernel.org/all/20260910-bpf-meta-inside-skb-ext-v2-0-0b21e42180b0@cloudflare.com/
[2] http://msgid.link/87fqyypp67.fsf@cloudflare.com/
[3] https://github.com/jsitnicki/skb-metadata-bench/blob/main/REPORT.md

Signed-off-by: Jakub Sitnicki <jakub@cloudflare.com>
---
Jakub Sitnicki (15):
      bpf: Add gated tracepoints for skb life-cycle
      bpf: Add bpf_skb_fclone_orig() kfunc
      bpf: Accept trusted pointers to kern ctx type for kfunc ctx args
      bpf: Allow access to bpf_sock_ops_kern->skb
      selftests/bpf: Basic tests for metadata passing with gated skb tracepoints
      selftests/bpf: Test passing metadata across veth and GRE
      selftests/bpf: Test metadata passing to cgroup_skb and sk_filter hooks
      selftests/bpf: Test passing metadata to sock_ops and LSM hooks
      selftests/bpf: Test passing metadata to kfree_skb tracepoint
      selftests/bpf: Test passing metadata to TCP egress
      selftests/bpf: Test passing metadata to netfilter hook
      selftests/bpf: Test passing metadata to/from LWT hooks
      selftests/bpf: Test passing metadata to seg6local End.BPF hook
      selftests/bpf: Test passing metadata to sk_skb stream verdict hook
      selftests/bpf: Use non-trivial test payload in xdp_context tests

 include/linux/skbuff.h                             |   38 +
 include/trace/events/skb.h                         |   57 +
 kernel/bpf/verifier.c                              |   22 +
 net/Kconfig                                        |    9 +
 net/core/dev.c                                     |    1 +
 net/core/filter.c                                  |  112 ++
 net/core/gro.c                                     |    1 +
 net/core/skbuff.c                                  |   25 +
 tools/testing/selftests/bpf/config                 |    2 +
 .../selftests/bpf/prog_tests/socket_helpers.h      |    1 +
 .../bpf/prog_tests/xdp_context_test_run.c          | 1399 +++++++++++++++++++-
 tools/testing/selftests/bpf/progs/test_xdp_meta.c  |  395 +++++-
 12 files changed, 2049 insertions(+), 13 deletions(-)


^ permalink raw reply	[flat|nested] 18+ messages in thread

end of thread, other threads:[~2026-10-02 12:47 UTC | newest]

Thread overview: 18+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-28 11:40 [PATCH net-next 00/15] Gated tracepoints for skb lifecycle (free+clone) Jakub Sitnicki
2026-09-28 11:40 ` [PATCH net-next 01/15] bpf: Add gated tracepoints for skb life-cycle Jakub Sitnicki
2026-09-28 11:40 ` [PATCH net-next 02/15] bpf: Add bpf_skb_fclone_orig() kfunc Jakub Sitnicki
2026-09-28 11:40 ` [PATCH net-next 03/15] bpf: Accept trusted pointers to kern ctx type for kfunc ctx args Jakub Sitnicki
2026-09-28 11:40 ` [PATCH net-next 04/15] bpf: Allow access to bpf_sock_ops_kern->skb Jakub Sitnicki
2026-09-28 11:40 ` [PATCH net-next 05/15] selftests/bpf: Basic tests for metadata passing with gated skb tracepoints Jakub Sitnicki
2026-09-28 11:40 ` [PATCH net-next 06/15] selftests/bpf: Test passing metadata across veth and GRE Jakub Sitnicki
2026-09-28 11:40 ` [PATCH net-next 07/15] selftests/bpf: Test metadata passing to cgroup_skb and sk_filter hooks Jakub Sitnicki
2026-09-28 11:40 ` [PATCH net-next 08/15] selftests/bpf: Test passing metadata to sock_ops and LSM hooks Jakub Sitnicki
2026-09-28 11:40 ` [PATCH net-next 09/15] selftests/bpf: Test passing metadata to kfree_skb tracepoint Jakub Sitnicki
2026-09-28 11:40 ` [PATCH net-next 10/15] selftests/bpf: Test passing metadata to TCP egress Jakub Sitnicki
2026-09-28 11:40 ` [PATCH net-next 11/15] selftests/bpf: Test passing metadata to netfilter hook Jakub Sitnicki
2026-09-28 11:40 ` [PATCH net-next 12/15] selftests/bpf: Test passing metadata to/from LWT hooks Jakub Sitnicki
2026-09-28 11:40 ` [PATCH net-next 13/15] selftests/bpf: Test passing metadata to seg6local End.BPF hook Jakub Sitnicki
2026-09-28 11:40 ` [PATCH net-next 14/15] selftests/bpf: Test passing metadata to sk_skb stream verdict hook Jakub Sitnicki
2026-09-28 11:40 ` [PATCH net-next 15/15] selftests/bpf: Use non-trivial test payload in xdp_context tests Jakub Sitnicki
2026-10-02  1:45 ` [PATCH net-next 00/15] Gated tracepoints for skb lifecycle (free+clone) Jakub Kicinski
2026-10-02 12:47   ` Jakub Sitnicki

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox