10 ms·
Why does this need to be included in the kernel directly and not just as a loadable module?
by 1023bytes 8y ago
Why does this need to be included in the kernel directly and not just as a loadable module?
- viraptor 8y agoWhen the API it relies on changes, the person doing the change will fix WG rather than the WG maintainers. Also it enables you to update the kernel without having to hunt for the matching release of WG separately.
- deleted 8y ago[deleted]
- tinus_hn 8y agoLike most device drivers it can be included in the mainline kernel but compile as a module.
- voxadam 8y agoOn a slight tangent, I wonder how realistic it would be to implement Wireguard as an eBPF program.
- scott00 8y agoThere are three related decisions in how software can be constructed in relation to linux, and it sounds like you might be confusing them a bit. They are: user space vs kernel space, base kernel vs kernel module, in tree vs out of tree. User space vs kernel space is the biggest decision and has a huge impact on nearly every aspect of the software. Wireguard has both user space and kernel space implementations. I'll link you to the Wireguard author's explanation as to why he chose to do a kernel space implementation: https://news.ycombinator.com/item?id=11994544 https://news.ycombinator.com/item?id=11994544 Base kernel vs kernel module is usually an easy one: almost everything that CAN go in a kernel module SHOULD go in a kernel module. Since modules can be loaded only when needed, it avoids using everyone's computing resources on features that not everyone might want. Wireguard is a kernel module. In tree vs out of tree means whether you commit your code into the main linux source tree, or whether you distribute it outside of the linux project. Linux software development practices make it pretty annoying to distribute kernel software out of tree, even if it's a module. Basically, linux doesn't maintain stable APIs or ABIs in kernel space, so if you distribute in binary form you'll need to distribute different versions for every kernel version, and if you distribute in source form, your users will need to recompile whenever they update their kernel, which is pretty often if they're keeping up with security updates. DKMS helps with the recompilation process, but it's still pretty annoying for users. This announcement is about the proposed transition of the wireguard kernel module from out of tree to in tree.
- zx2c4 8y ago> Why does this need to be included in the kernel directly and not just as a loadable module? From the patch: + tristate "WireGuard secure network tunnel" This means that it can be a built-in, a loadable module, or not included at all, depending on what you select when building.