From: John Fastabend <john.fastabend@gmail.com>
To: David Ahern <dsahern@kernel.org>, netdev@vger.kernel.org
Cc: davem@davemloft.net, kuba@kernel.org,
prashantbhole.linux@gmail.com, jasowang@redhat.com,
brouer@redhat.com, toke@redhat.com, toshiaki.makita1@gmail.com,
daniel@iogearbox.net, john.fastabend@gmail.com, ast@kernel.org,
kafai@fb.com, songliubraving@fb.com, yhs@fb.com, andriin@fb.com,
dsahern@gmail.com
Subject: RE: [PATCH v3 bpf-next 00/15] net: Add support for XDP in egress path
Date: Mon, 27 Apr 2020 11:25:32 -0700 [thread overview]
Message-ID: <5ea7239c8df43_a372ad3a5ecc5b82c@john-XPS-13-9370.notmuch> (raw)
In-Reply-To: <20200424201428.89514-1-dsahern@kernel.org>
David Ahern wrote:
> From: David Ahern <dsahern@gmail.com>
>
> This series adds support for XDP in the egress path by introducing
> a new XDP attachment type, BPF_XDP_EGRESS, and adding a UAPI to
> if_link.h for attaching the program to a netdevice and reporting
> the program. bpf programs can be run on all packets in the Tx path -
> skbs or redirected xdp frames. The intent is to emulate the current
> RX path for XDP as much as possible to maintain consistency and
> symmetry in the 2 paths with their APIs.
>
> This is a missing primitive for XDP allowing solutions to build small,
> targeted programs properly distributed in the networking path allowing,
> for example, an egress firewall/ACL/traffic verification or packet
> manipulation and encapping an entire ethernet frame whether it is
> locally generated traffic, forwarded via the slow path (ie., full
> stack processing) or xdp redirected frames.
I'm still a bit unsure why the BPF programs would not push logic into
ingress XDP program + skb egress. Is there a case where that does not
work or is it mostly about ease of use for some use case?
Do we have overhead performance numbers? I'm wondering how close the
redirect case with these TX hooks are vs redirect without TX hooks.
The main reason I ask is if it slows performance down by more than say
5% (sort of made up number, but point is some N%) then I don't think
we would recommend using it.
>
> Nothing about running a program in the Tx path requires driver specific
> resources like the Rx path has. Thus, programs can be run in core
> code and attached to the net_device struct similar to skb mode. The
> egress attach is done using the new XDP_FLAGS_EGRESS_MODE flag, and
> is reported by the kernel using the XDP_ATTACHED_EGRESS_CORE attach
> flag with IFLA_XDP_EGRESS_PROG_ID making the api similar to existing
> APIs for XDP.
>
> The locations chosen to run the egress program - __netdev_start_xmit
> before the call to ndo_start_xmit and bq_xmit_all before invoking
> ndo_xdp_xmit - allow follow on patch sets to handle tx queueing and
> setting the queue index if multi-queue with consistency in handling
> both packet formats.
>
> A few of the patches trace back to work done on offloading programs
> from a VM by Jason Wang and Prashant Bole.
The idea for offloading VM programs would be to take a BPF program
from the VM somehow out of band or over mgmt interface and load it
into the egress hook of virtio?
Code LGTM other than a couple suggestions on the test side but I'm
missing something on the use case picture.
Thanks,
John
next prev parent reply other threads:[~2020-04-27 18:25 UTC|newest]
Thread overview: 24+ messages / expand[flat|nested] mbox.gz Atom feed top
2020-04-24 20:14 [PATCH v3 bpf-next 00/15] net: Add support for XDP in egress path David Ahern
2020-04-24 20:14 ` [PATCH v3 bpf-next 01/15] net: Refactor convert_to_xdp_frame David Ahern
2020-04-27 16:19 ` John Fastabend
2020-04-24 20:14 ` [PATCH v3 bpf-next 02/15] net: uapi for XDP programs in the egress path David Ahern
2020-04-24 20:14 ` [PATCH v3 bpf-next 03/15] net: Add XDP setup and query commands for Tx programs David Ahern
2020-04-24 20:14 ` [PATCH v3 bpf-next 04/15] net: Add BPF_XDP_EGRESS as a bpf_attach_type David Ahern
2020-04-24 20:14 ` [PATCH v3 bpf-next 05/15] xdp: Add xdp_txq_info to xdp_buff David Ahern
2020-04-24 20:14 ` [PATCH v3 bpf-next 06/15] net: Rename do_xdp_generic to do_xdp_generic_rx David Ahern
2020-04-24 20:14 ` [PATCH v3 bpf-next 07/15] net: rename netif_receive_generic_xdp to do_generic_xdp_core David Ahern
2020-04-24 20:14 ` [PATCH v3 bpf-next 08/15] net: set XDP egress program on netdevice David Ahern
2020-04-24 20:14 ` [PATCH v3 bpf-next 09/15] net: Support xdp in the Tx path for packets as an skb David Ahern
2020-04-24 20:14 ` [PATCH v3 bpf-next 10/15] net: Support xdp in the Tx path for xdp_frames David Ahern
2020-04-24 20:14 ` [PATCH v3 bpf-next 11/15] libbpf: Add egress XDP support David Ahern
2020-04-24 20:14 ` [PATCH v3 bpf-next 12/15] bpftool: Add support for XDP egress David Ahern
2020-04-27 15:13 ` Toke Høiland-Jørgensen
2020-04-24 20:14 ` [PATCH v3 bpf-next 13/15] selftest: Add test for xdp_egress David Ahern
2020-04-27 17:48 ` John Fastabend
2020-04-27 17:52 ` John Fastabend
2020-04-27 17:58 ` David Ahern
2020-04-24 20:14 ` [PATCH v3 bpf-next 14/15] selftest: Add xdp_egress attach tests David Ahern
2020-04-24 20:14 ` [PATCH v3 bpf-next 15/15] samples/bpf: add XDP egress support to xdp1 David Ahern
2020-04-27 15:21 ` [PATCH v3 bpf-next 00/15] net: Add support for XDP in egress path Toke Høiland-Jørgensen
2020-04-27 18:25 ` John Fastabend [this message]
2020-04-27 18:58 ` David Ahern
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=5ea7239c8df43_a372ad3a5ecc5b82c@john-XPS-13-9370.notmuch \
--to=john.fastabend@gmail.com \
--cc=andriin@fb.com \
--cc=ast@kernel.org \
--cc=brouer@redhat.com \
--cc=daniel@iogearbox.net \
--cc=davem@davemloft.net \
--cc=dsahern@gmail.com \
--cc=dsahern@kernel.org \
--cc=jasowang@redhat.com \
--cc=kafai@fb.com \
--cc=kuba@kernel.org \
--cc=netdev@vger.kernel.org \
--cc=prashantbhole.linux@gmail.com \
--cc=songliubraving@fb.com \
--cc=toke@redhat.com \
--cc=toshiaki.makita1@gmail.com \
--cc=yhs@fb.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox