Thread (27 messages) 27 messages, 8 authors, 2022-09-07

Re: [PATCH nf-next] netfilter: nf_tables: add ebpf expression

From: Florian Westphal <fw@strlen.de>
Date: 2022-08-31 15:54:09
Also in: bpf, netfilter-devel

Alexei Starovoitov [off-list ref] wrote:
quoted
1 and 2 have the upside that its easy to handle a 'file not found'
error.
I'm strongly against calling into bpf from the inner guts of nft.
Nack to all options discussed in this thread.
None of them make any sense.
-v please.  I can just rework userspace to allow going via xt_bpf
but its brain damaged.

This helps gradually moving towards move epbf for those that
still heavily rely on the classic forwarding path.

If you are open to BPF_PROG_TYPE_NETFILTER I can go that route
as well, raw bpf program attachment via NF_HOOK and the bpf dispatcher,
but it will take significantly longer to get there.

It involves reviving
https://lore.kernel.org/netfilter-devel/20211014121046.29329-1-fw@strlen.de/ (local)

as a first stage/merge goal.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help