mirror of
https://github.com/netbirdio/gvisor.git
synced 2026-05-22 17:12:49 -07:00
The existing redirect mode uses XDP to maximize performance but is not suitably secure: packets are copied directly from the driver into a userspace buffer (UMEM). But because the UMEM is shared among all processes with a socket open on a particular NIC queue, sandboxes using redirect mode all map the same UMEM and thus can read each other's packets. Tunnel mode instead installs an eBPF program that copies packets from the host's NIC driver into a per-sandbox NIC driver. This incurs an additional copy, but there is no longer memory shared between sandboxes. Benchmarking tunnel mode with redis-benchmark shows a performance gain over standard Docker networking of 20%. Redirect mode showed a 30% improvement. PiperOrigin-RevId: 595746162
31 lines
1.0 KiB
Go
31 lines
1.0 KiB
Go
// Copyright 2023 The gVisor Authors.
|
|
//
|
|
// Licensed under the Apache License, Version 2.0 (the "License");
|
|
// you may not use this file except in compliance with the License.
|
|
// You may obtain a copy of the License at
|
|
//
|
|
// http://www.apache.org/licenses/LICENSE-2.0
|
|
//
|
|
// Unless required by applicable law or agreed to in writing, software
|
|
// distributed under the License is distributed on an "AS IS" BASIS,
|
|
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
// See the License for the specific language governing permissions and
|
|
// limitations under the License.
|
|
|
|
// Package bpf provides compiled bpf programs as byte slices.
|
|
package bpf
|
|
|
|
import _ "embed"
|
|
|
|
// AFXDPProgram is a BPF program that, when attached to a device, redirects all
|
|
// packets to a single AF_XDP socket unconditionally.
|
|
//
|
|
//go:embed af_xdp_ebpf.o
|
|
var AFXDPProgram []byte
|
|
|
|
// TunnelVethProgram is a BPF program that redirects all packets to exit via
|
|
// another device.
|
|
//
|
|
//go:embed tunnel_veth_ebpf.o
|
|
var TunnelVethProgram []byte
|