program-type/BPF_PROG_TYPE_SCHED_CLS: Add netkit section - #297
Merged
dylandreimerink merged 1 commit intoSep 10, 2026
Merged
Conversation
The page's attach-type table already lists BPF_NETKIT_PRIMARY and BPF_NETKIT_PEER, but nothing on the page explains what netkit is or how its semantics differ from qdisc-based attachment. Add a section under Attachment covering: what a netkit device pair is and that programs run in the transmit path without any qdisc, which end of the pair each attach type runs on, primary-only attachment management, the netkit_action return codes (including that unknown codes drop instead of mapping to NEXT like tcx), the per-end default policy including blackhole, and the L3/L2 device modes. All behavior verified against drivers/net/netkit.c and include/uapi/linux/if_link.h. Fixes: isovalent#91 Signed-off-by: Ashwani Yadav <22ashwaniyadav@gmail.com>
dylandreimerink
approved these changes
Sep 10, 2026
Collaborator
|
That all looks good and accurate, thank you for picking this up 🙏 |
Contributor
Author
|
Thanks for the merge, Dylan! 🙏 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #91
The attach-type table on the page already lists
BPF_NETKIT_PRIMARYandBPF_NETKIT_PEER, but nothing explains what netkit is or how its semantics differ from qdisc-based attachment. This adds a### netkitsection under Attachment, after the tcx material, covering:BPF_NETKIT_PRIMARY= host-to-container direction,BPF_NETKIT_PEER= the container's outgoing traffic)netkit_dev_fetchrejects the peer ifindex with-EACCES), so a workload inside the container cannot touch the policy attached to its own peernetkit_actionreturn codes, including one behavior difference from tcx worth calling out: unknown return codes drop the packet (thedefault:case innetkit_xmit) instead of being mapped toNEXTblackholevariant for default-deny setups, plus theNETKIT_L3/NETKIT_L2device modesOne note on the issue text: the default policy is actually
NETKIT_PASSfor both ends (netkit_new_linkindrivers/net/netkit.c) - devices only drop by default when created with theblackholepolicy, so the section describes default-deny as opt-in.Everything is verified against
drivers/net/netkit.candinclude/uapi/linux/if_link.hat v7.2; the feature tag links to the netkitintroduction commit (35dfaad7188c, "netkit, bpf: Add bpf programmable net
device", v6.7).