Article 6XK6V [$] Allowing BPF programs more access to the network

[$] Allowing BPF programs more access to the network

by
daroc
from LWN.net on (#6XK6V)

Mahe Tardy led two sessions about some of the challenges that he, Kornilios Kourtis,and John Fastabend have run into in their work onTetragon (Apache-licensed BPF-based security monitoring software)at the Linux Storage, Filesystem, Memory Management, and BPF Summit. The sessionprompted discussion about the feasibility of letting BPF programssend data over the network, as well as potential new kfuncs to let BPF firewallssend TCP reset packets. Tardy presented several possible ways that these couldbe accomplished.

External Content
Source RSS or Atom Feed
Feed Location http://lwn.net/headlines/rss
Feed Title LWN.net
Feed Link https://lwn.net/
Reply 0 comments