mirror of
https://github.com/netbirdio/gvisor.git
synced 2026-05-22 17:12:49 -07:00
This commit supports a third-party network stack as a plugin stack for gVisor. The overall plugin package structure is the following: - pkg/sentry/socket/plugin: Interfaces for initializing plugin network stack. It will be used in network setting up during sandbox creating. - pkg/sentry/socket/plugin/stack: Glue layer for plugin stack's socket and stack ops with sentry. It will also register plugin stack operations if imported. - pkg/sentry/socket/plugin/cgo: Interfaces defined in C for plugin network stack to support. To build target runsc-plugin-stack, which imports pkg/sentry/socket/plugin/stack package and enables CGO: bazel build --config=plugin-tldk runsc:runsc-plugin-stack (i.e. --config=plugin-tldk indicates that using TLDK as plugin stack) By using runsc-plugin-stack binary and setting "--network=plugin" in runtimeArgs, user can use third-party network stack instead of netstack embedded in gVisor to get better network performance. Redis benchmark with following setups: 1. KVM platform 2. 4 physical cores for target pod 3. target pod as redis server Runc: $redis-benchmark -h [target ip] -n 100000 -t get,set -q SET: 115207.38 requests per second, p50=0.215 msec GET: 92336.11 requests per second, p50=0.279 msec $redis-benchmark -h [target ip] -n 100000 -t get,set -q SET: 113895.21 requests per second, p50=0.247 msec GET: 96899.23 requests per second, p50=0.271 msec $redis-benchmark -h [target ip] -n 100000 -t get,set -q SET: 126582.27 requests per second, p50=0.199 msec GET: 95969.28 requests per second, p50=0.271 msec Runsc with plugin stack: $redis-benchmark -h [target ip] -n 100000 -t get,set -q SET: 123915.74 requests per second, p50=0.343 msec GET: 115473.45 requests per second, p50=0.335 msec $redis-benchmark -h [target ip] -n 100000 -t get,set -q SET: 120918.98 requests per second, p50=0.351 msec GET: 117647.05 requests per second, p50=0.351 msec $redis-benchmark -h [target ip] -n 100000 -t get,set -q SET: 119904.08 requests per second, p50=0.367 msec GET: 112739.57 requests per second, p50=0.375 msec Runsc with netstack: $redis-benchmark -h [target ip] -n 100000 -t get,set -q SET: 59952.04 requests per second, p50=0.759 msec GET: 61162.08 requests per second, p50=0.631 msec $redis-benchmark -h [target ip] -n 100000 -t get,set -q SET: 52219.32 requests per second, p50=0.719 msec GET: 58719.91 requests per second, p50=0.663 msec $redis-benchmark -h [target ip] -n 100000 -t get,set -q SET: 59952.04 requests per second, p50=0.751 msec GET: 60827.25 requests per second, p50=0.751 msec Updates https://github.com/google/gvisor/issues/9266 Co-developed-by: Tianyu Zhou <wentong.zty@antgroup.com> Signed-off-by: Anqi Shen <amy.saq@antgroup.com>
129 lines
3.2 KiB
Go
129 lines
3.2 KiB
Go
// Copyright 2018 The gVisor Authors.
|
|
//
|
|
// Licensed under the Apache License, Version 2.0 (the "License");
|
|
// you may not use this file except in compliance with the License.
|
|
// You may obtain a copy of the License at
|
|
//
|
|
// http://www.apache.org/licenses/LICENSE-2.0
|
|
//
|
|
// Unless required by applicable law or agreed to in writing, software
|
|
// distributed under the License is distributed on an "AS IS" BASIS,
|
|
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
// See the License for the specific language governing permissions and
|
|
// limitations under the License.
|
|
|
|
package linux
|
|
|
|
const (
|
|
// IFNAMSIZ is the size of the name field for IFReq.
|
|
IFNAMSIZ = 16
|
|
)
|
|
|
|
// IFReq is an interface request.
|
|
//
|
|
// +marshal
|
|
type IFReq struct {
|
|
// IFName is an encoded name, normally null-terminated. This should be
|
|
// accessed via the Name and SetName functions.
|
|
IFName [IFNAMSIZ]byte
|
|
|
|
// Data is the union of the following structures:
|
|
//
|
|
// struct sockaddr ifr_addr;
|
|
// struct sockaddr ifr_dstaddr;
|
|
// struct sockaddr ifr_broadaddr;
|
|
// struct sockaddr ifr_netmask;
|
|
// struct sockaddr ifr_hwaddr;
|
|
// short ifr_flags;
|
|
// int ifr_ifindex;
|
|
// int ifr_metric;
|
|
// int ifr_mtu;
|
|
// struct ifmap ifr_map;
|
|
// char ifr_slave[IFNAMSIZ];
|
|
// char ifr_newname[IFNAMSIZ];
|
|
// char *ifr_data;
|
|
Data [24]byte
|
|
}
|
|
|
|
// Name returns the name.
|
|
func (ifr *IFReq) Name() string {
|
|
for c := 0; c < len(ifr.IFName); c++ {
|
|
if ifr.IFName[c] == 0 {
|
|
return string(ifr.IFName[:c])
|
|
}
|
|
}
|
|
return string(ifr.IFName[:])
|
|
}
|
|
|
|
// SetName sets the name.
|
|
func (ifr *IFReq) SetName(name string) {
|
|
n := copy(ifr.IFName[:], []byte(name))
|
|
clear(ifr.IFName[n:])
|
|
}
|
|
|
|
// SizeOfIFReq is the binary size of an IFReq struct (40 bytes).
|
|
var SizeOfIFReq = (*IFReq)(nil).SizeBytes()
|
|
|
|
// IFMap contains interface hardware parameters.
|
|
type IFMap struct {
|
|
MemStart uint64
|
|
MemEnd uint64
|
|
BaseAddr int16
|
|
IRQ byte
|
|
DMA byte
|
|
Port byte
|
|
_ [3]byte // Pad to sizeof(struct ifmap).
|
|
}
|
|
|
|
// IFConf is used to return a list of interfaces and their addresses. See
|
|
// netdevice(7) and struct ifconf for more detail on its use.
|
|
//
|
|
// +marshal
|
|
type IFConf struct {
|
|
Len int32
|
|
_ [4]byte // Pad to sizeof(struct ifconf).
|
|
Ptr uint64
|
|
}
|
|
|
|
// SizeOfIFConf is the binary size of an IFConf struct (16 bytes).
|
|
var SizeOfIFConf = (*IFConf)(nil).SizeBytes()
|
|
|
|
// EthtoolCmd is a marshallable type to be able to easily copyin the
|
|
// the command for an SIOCETHTOOL ioctl.
|
|
//
|
|
// +marshal
|
|
type EthtoolCmd uint32
|
|
|
|
const (
|
|
// ETHTOOL_GFEATURES is the command to SIOCETHTOOL to query device
|
|
// features.
|
|
// See: <linux/ethtool.h>
|
|
ETHTOOL_GFEATURES EthtoolCmd = 0x3a
|
|
)
|
|
|
|
// EthtoolGFeatures is used to return a list of device features.
|
|
// See: <linux/ethtool.h>
|
|
//
|
|
// +marshal
|
|
type EthtoolGFeatures struct {
|
|
Cmd uint32
|
|
Size uint32
|
|
}
|
|
|
|
// EthtoolGetFeaturesBlock is used to return state of upto 32 device
|
|
// features.
|
|
// See: <linux/ethtool.h>
|
|
//
|
|
// +marshal
|
|
type EthtoolGetFeaturesBlock struct {
|
|
Available uint32
|
|
Requested uint32
|
|
Active uint32
|
|
NeverChanged uint32
|
|
}
|
|
|
|
const (
|
|
// LOOPBACK_IFINDEX is defined in include/net/flow.h.
|
|
LOOPBACK_IFINDEX = 1
|
|
)
|