3 ms·
> To lock an instance into a 6PN network, all we really need is a trivial BPF program that enforces the “don’t cross the streams” rule: you can’t send packets b
by jamescun 6y ago
> To lock an instance into a 6PN network, all we really need is a trivial BPF program that enforces the “don’t cross the streams” rule: you can’t send packets between different 6PN prefixes.
Are you using eBPF for this egress filtering? My (hopefully mis)understanding is XDP programmes, the higher performance cousin of eBPF, can only work on ingress packets currently.
- ignoramous 6y agoNot OP, but see https://news.ycombinator.com/item?id=24848391 https://news.ycombinator.com/item?id=24848391 > The unlucky bit is WireGuard. XDP doesn't really work on WireGuard; it only pretends to (with the "xdpgeneric" interface that runs in the TCP/IP stack, after socket buffers are allocated). Among the problems: WireGuard doesn't have link-layer headers, and XDP wants it to; the discrepancy jams up the socket code if you try to pass a packet with XDP_OK. We janked our way around this with XDP_REDIRECT, and Jason Donenfeld even wrote a patch, but the XDP developers were not enthused, just about the concept of XDP running on WireGuard at all, and so we ended up implementing the worker side of this in TC BPF.
- jamescun 6y agoThanks!