Thread (4 messages) flat view 4 messages, 2 authors, 2014-07-30

Re: [PATCH RFC v3 net-next 3/3] samples: bpf: eBPF dropmon example in C

From: Frank Ch. Eigler <hidden>
Date: 2014-07-30 15:46:20
Also in: lkml, netdev

ast wrote earlier:
[...]
dtrace/systemtap/ktap approach is to use one script file that should provide
all desired functionality. That architectural decision overcomplicated their
implementations.

eBPF follows split model: everything that needs to process millions of events
per second needs to run in kernel and needs to be short and deterministic,
all other things like aggregation and nice graphs should run in user space.
[...]
For the record, this is not entirely accurate as to dtrace.  dtrace
delegates aggregation and most reporting to userspace.  Also,
systemtap is "short and deterministic" even for aggregations & nice
graphs, but since it limits its storage & cpu consumption, its
arrays/reports cannot get super large.

[...]
+SEC("events/skb/kfree_skb")
+int bpf_prog2(struct bpf_context *ctx)
+{
+[...]
+	value = bpf_map_lookup_elem(&my_map, &loc);
+	if (value)
+		(*(long *) value) += 1;
+	else
+		bpf_map_update_elem(&my_map, &loc, &init_val);
+	return 0;
+}
What kind of locking/serialization is provided by the ebpf runtime
over shared variables such as my_map?


- FChE
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help