I guess we need a new networking how-to?
Anyone aware of some resources I might have missed?
OK, I guess the nftables wiki is the "how-to": https://wiki.nftables.org/wiki-nftables/index.php/Main_Page
I guess we need a new networking how-to?
Anyone aware of some resources I might have missed?
OK, I guess the nftables wiki is the "how-to": https://wiki.nftables.org/wiki-nftables/index.php/Main_Page
Something I wrote for the ArchWiki [1]:
> BPF is a system used to load and execute bytecode within the kernel dynamically during runtime. It is used in a number of Linux kernel subsystems such as networking (e.g. XDP, tc), tracing (e.g. kprobes, uprobes, tracepoints) and security (e.g. seccomp). It is also useful for advanced network security, performance profiling and dynamic tracing.
> BPF was originally an acronym of "Berkeley Packet Filter" since the original classic BPF was used for packet capture tools for BSD. This eventually evolved into Extended BPF (eBPF), which was shortly afterwards renamed to just BPF (not an acronym). BPF should not be confused with packet filtering tools like iptables or netfilter, although BPF can be used to implement packet filtering tools.
lwn.net has a decent (although 3 years old) intro article [2]. Cilium has a good document on how they use BPF to implement a packet filter [3].
[1] https://wiki.archlinux.org/index.php/Security#BPF_hardening
At any rate, I agree information on bpf as a iptables work-a-like is scarce. This helps a bit:
https://www.netronome.com/blog/bpf-ebpf-xdp-and-bpfilter-wha...
Then there's of course the kernel docs, eg: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/lin...
See also: https://blog.cloudflare.com/introducing-the-bpf-tools/
So unfortunately it makes less sense for one-liners. Case in point: to use the masquerade action in a postrouting/nat chain, you also have to register a (possibly empty) prerouting/nat chain.
You don't have to do that since Linux 4.18: https://wiki.nftables.org/wiki-nftables/index.php/Performing...