HNHacker News
TopNewBestAskShowJobs

dangisafascist

-2 karma · joined July 8, 2017

submissionscomments
dangisafascist··on Linux tracing systems and how they fit together
Sure but how common is that case? How common are multi-tenant Linux systems with untrusted users that give those specific permissions? Do you want untrusted users sniffing the packets of others?
dangisafascist··on Linux tracing systems and how they fit together
The bpf() system call and SOCK_RAW both require root. Is there an example of using bpf that doesn't require root?
dangisafascist··on Linux tracing systems and how they fit together
For experimentation and testing, a kernel module for each rule doesn't seem unworkable. Just hide all the details behind a nice tool.

For production, placing all rules in a single module seems best. If you could avoid the overhead of executing BPF in production, wouldn't you?

I agree with the privilege argument but I don't think normal users can filter packets or add tracing with the current situation either.

dangisafascist··on Linux tracing systems and how they fit together
If you write your kernel module in eBPF (by pre-compiling to native code) it can't crash either.
dangisafascist··on Linux tracing systems and how they fit together
I'm not arguing against eBPF the language. It's safety guarantees make sense to me.

I'm arguing against the in-kernel eBPF infrastructure: bpf system call, the JIT and the VM.

I think it makes more sense to just compile eBPF (or rust or whatever safe language you want) to a kernel module.

dangisafascist··on Linux tracing systems and how they fit together
I can but I don't see why that is necessary. It's plain to see that it's possible and performs better in production since it avoids the JIT step.

https://github.com/tsgates/rust.ko

dangisafascist··on Linux tracing systems and how they fit together
I'm not sure this argument makes sense. Avoiding accidentally crashing the kernel doesn't require a BPF layer.

For instance, you could just write your kernel module in a sufficiently safe language, like Rust, and have the same benefits. You could even pre-compile eBPF for the exact same level of safety. Still no need for the bpf() system call or the eBPF VM or JIT in the kernel.

dangisafascist··on Linux tracing systems and how they fit together
I'm confused why BPF exists in the first place. Can't we just compile kernel modules that hook into the tracing infrastructure?

It seems like a webassembly for the kernel but local software has the benefits of knowing the platform it is running on. I.e. Why compile C code to eBPF, when I can just compile to native code directly?

I can potentially see it solving a permissions problem, where you want to give unprivileged users in a multi-tenant setup the ability to run hooks in the kernel. Is that actually a common use case? I don't think it is.