5 ms·
Someone has started working on P4 support [0] for Snabb Switch [1]. I think a language like P4 will be great for sharing switching logic. I hope we will see r
by neopallium 10y ago
Someone has started working on P4 support [0] for Snabb Switch [1].
I think a language like P4 will be great for sharing switching logic. I hope we will see re-usable modules written in P4 that can be shared.
0. https://github.com/esbullington/snabbp4 https://github.com/esbullington/snabbp4
1. https://github.com/snabbco/snabb https://github.com/snabbco/snabb
- mino 10y agoSnabb is a great project. Current P4 support is [0]: a working lexer and parser for the full p4 language (version 1.1: working release). There are plenty of unit tests, but I'm sure there are still bugs (not yet a lot of p4 v1.1 code to test out at this point, most existing p4 code is v1.0 which has some significant differences). Also, P4 support in OpenVSwitch is coming too. 0. https://groups.google.com/d/msg/snabb-devel/GkWONJcuF4E/Tc8PQH9vCQAJ https://groups.google.com/d/msg/snabb-devel/GkWONJcuF4E/Tc8P...
- neopallium 10y agoI am interested in Snabb and other methods of doing high performance packet processing to help with developing DDOS protection methods that could be implemented without expensive hardware. If DDOS filtering modules can be written in P4, then they could be used on software switches and maybe even compiled into packet filters that run before packets are processed by the Linux kernel (or compiled into a kernel-bypass module for embedding in an application). I think we really need to have better support for low-level high performance packet filtering (i.e. before the packet gets to higher levels in the kernel). With multi-gigabit networking becoming cheaper, we really should have better support for dropping bad traffic. How about a switch layer that runs in the kernel? Physical NICs and virtual NICs could be handled by the switch layer (programmed using P4 or eBPF). The kernel would only have to handle packets it receives from the virtual NICs. This would allow packet filtering and even some routing to happen without having to go through the kernels network-stack. The software switch layer would work like a data-plane with the kernel as the control-plane (like a lot of hardware routers/switches). If the computer has specialized hardware (smart NICs, co-processors), then the switch logic (P4 code) could be handled in that hardware instead of on the CPU.
- mino 10y ago> How about a switch layer that runs in the kernel? That's what openvswitch.ko is doing already. I agree that P4 is interesting also in this perspective: having the compiled P4 blob being ran either by the CPU or, if available, in hardware by a smart NIC.