What we are missing from linux today is a networking subsystem that allows for configurable efficient hardware offloading.
Without hacking up everything, like it is done in consumer routers these days.
Will BPF handle that better than nftables?
Without hacking up everything, like it is done in consumer routers these days.
Will BPF handle that better than nftables?
Tools in iproute2 package are being updated too, so typically you would attach and offload programs to hardware with `tc`- or `ip`-based command lines.
[1] https://www.networkworld.com/article/3016992/security/junipe...
[2] https://www.theregister.co.uk/2015/09/15/compromised_cisco_r...
[3] https://en.wikipedia.org/wiki/Intel_Management_Engine#Securi...