Thread (5 messages) 5 messages, 4 authors, 2016-09-20

Re: [PATCH v6 5/6] net: ipv4, ipv6: run cgroup eBPF egress programs

From: Thomas Graf <hidden>
Date: 2016-09-20 16:53:29
Also in: netdev

On 09/20/16 at 04:29pm, Pablo Neira Ayuso wrote:
On Mon, Sep 19, 2016 at 10:56:14PM +0200, Daniel Mack wrote:
[...]
quoted
Why would we artificially limit the use-cases of this implementation if
the way it stands, both filtering and introspection are possible?
Why should we place infrastructure in the kernel to filter packets so
late, and why at postrouting btw, when we can do this way earlier
before any packet is actually sent? No performance impact, no need for
skbuff allocation and *no cycles wasted to evaluate if every packet is
wanted or not*.
I won't argue against filtering at socket level, it is very valuable.
A difference is transparency of enforcement. Dropping at networking
level is accounted for in the usual counters and well understood by
admins. "Dropping" at bind socket level would either involve returning
an error to the application (which may change behaviour of the application)
or require a new form of accounting.

I also want to see packet size, selected source address, outgoing device,
and attach tunnel key metadata to the skb based on the cgroup. All of
which are not available at socket level.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help