Thread (31 messages) flat view 31 messages, 8 authors, 2017-02-14

Re: [PATCH RFC v2 1/8] xdp: Infrastructure to generalize XDP

From: David Miller <davem@davemloft.net>
Date: 2017-02-10 17:06:50

From: Tom Herbert <redacted>
Date: Thu, 9 Feb 2017 20:55:34 -0800
On Thu, Feb 9, 2017 at 7:33 PM, David Miller [off-list ref] wrote:
quoted
From: Tom Herbert <redacted>
Date: Thu, 9 Feb 2017 18:29:54 -0800
quoted
So we have thousands or LOC coming into drivers every day anyway with
all those properties anyway, so this "restricted" environment solves
at best 1% of the problem.
What you must understand is that no matter what someone outside of
upstream writes into an eBPF program, it's safe, and we can absolutely
prove this with the verifier and the invariants of the execution
environment.
This is the exact same argument the userspace stack proponents will
use-- put your stack in userspace and you can't crash the host.
Sounds like we can therefore meet that requirement and keep them in
the kernel networking path, which supports all of our values and goals
precisely.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help