Kernel optimization method, system and device based on eBPF and medium
By combining the eBPF kernel hook program with the routing kernel module, the performance bottleneck and scalability issues of the Linux kernel network stack are resolved, achieving efficient data flow routing and transmission processes, and improving the performance and security of network adapters.
Patent Information
- Application Number
- CN202511065096.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-31
- Publication Date
- 2025-11-11
AI Technical Summary
The Linux kernel network stack suffers from performance bottlenecks, poor scalability, and difficulty in observation in high-performance networks. Furthermore, eBPF technology has deficiencies in compatibility, development framework, and debugging tools, and the routing kernel module is susceptible to kernel crashes and security vulnerabilities.
By using the eBPF kernel hook program to intercept data packets at multiple kernel eBPF loading points and program interception points selected by the user, and performing route queries with the routing kernel module, combined with eBPF map and BPF helper functions, a specific data packet processing flow is implemented.
It improves the transmission performance of data streams, provides flexible routing capabilities, reduces development costs and debugging complexity, and enhances the reliability and security of the system.
Smart Images

Figure CN120935091A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of Linux kernel network optimization technology, specifically to a kernel optimization method, system, device, and medium based on eBPF. Background Technology
[0002] The current Linux kernel network stack employs a layered processing model, responsible for processing network packets from the physical layer to the application layer. Its main core components include: Driver layer: The network card writes packets to kernel memory (sk_buff structure) via DMA, triggering soft interrupts (such as NAPI) for packet reception scheduling. Protocol stack layer: Processes the link layer (MAC), network layer (IP), and transport layer (TCP / UDP) sequentially, executing routing, fragmentation, congestion control, and other logic. Netfilter framework: Provides hooks such as PREROUTING, FORWARD, and POSTROUTING, supporting firewall (iptables / nftables), NAT, and other functions. Socket interface: Ultimately delivers data to user-space applications (such as HTTP services) or forwards it to other network devices.
[0003] However, Linux has the following specific problems: ① It is a performance bottleneck in high-performance networks, as data packets need to be processed layer by layer through the network stack, resulting in high latency (microseconds) and low throughput (especially in high-speed network scenarios); ② Poor scalability: the protocol stack logic is fixed in the kernel, and modifications require recompilation, while new features depend on kernel version upgrades; ③ Difficult to observe: network status (such as packet loss and queue backlog) is difficult to track in real time, and debugging is highly complex.
[0004] eBPF (Extended Berkeley Packet Filter) is a revolutionary kernel technology that allows sandboxed programs to run securely within the kernel, dynamically extending kernel functionality without modifying the kernel source code or loading routing kernel modules. Originally designed for efficient packet filtering (such as tcpdump), it has now expanded to multiple areas including networking, security, observability, performance tuning, and hardware acceleration. eBPF kernel hooks ensure secure execution through a JIT compiler and a rigorous verifier, preventing kernel crashes or resource abuse.
[0005] eBPF technology currently covers various scenarios such as network acceleration, security auditing, and performance analysis (e.g., the BCC toolchain). However, the specific problems are as follows: ① The number of instructions is limited, dynamic loops are not supported, and helper functions are needed to access kernel data; ② ABI differences between different kernel versions may cause compatibility issues, which need to be solved by CO-RE (Compile Once-Run Everywhere) technology; ③ Familiarity with kernel mechanisms and eBPF toolchains (e.g., libbpf, BCC) is required, and debugging tools are not yet perfect; ④ Development frameworks (e.g., BCC / libbpf) and release standards are not yet unified.
[0006] A routing kernel module is a code component that is dynamically loaded into the operating system kernel and runs, allowing for the extension of kernel functionality without recompiling or restarting the kernel. Routing kernel modules are typically used in scenarios such as device driver development, file system support, and network protocol stack enhancement. They can directly access kernel data structures and hardware resources, providing low-level system control capabilities. However, routing kernel modules have the following drawbacks: ① Defects in the module code may cause kernel crashes (such as null pointer references), affecting system reliability; ② Routing kernel modules possess kernel privileges, making them vulnerable to exploitation (such as privilege escalation attacks); ③ Routing kernel modules need to be adapted for different kernel versions, and API changes may cause the module to malfunction; ④ Kernel-mode errors are difficult to track, requiring dedicated tools such as printk or kgdb.
[0007] Therefore, how to improve the transmission performance of specific data streams and specify special routing and transmission processes for data streams to provide services for dedicated network adapters is a technical problem that urgently needs to be solved. Summary of the Invention
[0008] The technical objective of this invention is to provide a kernel optimization method, system, device, and medium based on eBPF to address the problem of how to improve the transmission performance of specific data streams and specify special routing and transmission processes for data streams, thereby providing services for dedicated network adapters.
[0009] The technical task of this invention is achieved in the following manner: a kernel optimization method based on eBPF, which involves an eBPF kernel hook program intercepting data packets at multiple kernel eBPF loading points and program interception points selected by the user, and performing route queries with the routing kernel module to complete the selection of operation functions and routing parameters; the routing kernel module completes routing decisions based on various complex routing requirements, configuration conditions, data packet conditions, and environmental conditions, and returns the query results to the eBPF kernel hook program, which then executes them.
[0010] As a preferred embodiment, the data packet receiving process is as follows:
[0011] (1) The network adapter copies data packets from the storage system to the Linux memory based on the driver and performs route lookup with the routing kernel module to complete the selection of operation functions and routing parameters;
[0012] (2) In the Linux network stack processing flow, the eBPF kernel hook program intercepts data packets at different network stack locations based on the information contained in the data packets, and provides optimization for specified data packets based on the interception location and the information carried by the data packets.
[0013] (3) After the eBPF kernel hook program completes data interception, based on the interception location and the information carried by the data packet, it calls the routing interface provided by the routing kernel module, provides the routing parameters contained in the data packet, and the routing kernel module completes the routing decision.
[0014] (4) The routing kernel module is a separate module that provides functions that can be called by the eBPF kernel hook program within the kernel; at the same time, it calculates and determines the processing method and parameters of the corresponding data packets according to the user configuration.
[0015] (5) The routing kernel module returns the result after the call to the eBPF kernel hook program, which then executes the result to provide a specific processing flow for the specified data packet; the result after the call includes the processing method and parameters.
[0016] (6) The eBPF kernel hook program temporarily stores the corresponding processing methods and executes them directly in the next processing, thereby improving processing performance.
[0017] As a preferred method, the data packet is sent as follows:
[0018] ① The data packet is sent from user space to the kernel network stack via the send() interface, and then executed according to the standard procedure.
[0019] ② The eBPF kernel hook program intercepts data packets at different network stack locations and determines whether to complete the interception at that point based on the information contained in the data packet; similarly, for a specified data packet, the eBPF kernel hook program performs a route query to the routing kernel module based on the data packet information after interception.
[0020] ③ The routing kernel module returns a call response; the call response includes the processing method and parameters for the corresponding data packet;
[0021] ④ Based on the response from the routing kernel module, the eBPF kernel hook program completes the packet sending, which is the optimized packet sending process.
[0022] As a preferred option, the eBPF hook points of the eBPF kernel hook program include XDP hook, TC ingress hook, kprobe / ip_output, kretprobe / _inet_lookup_skb, kprobe / sys_sendto, kprobe / tcp_connect, and kprobe / sys_setsockopt;
[0023] Among them, the receiving path of the eBPF kernel hook program is to intercept at the L2 layer through the XDP hook or to intercept at the L3 / L4 layer through the TCingress hook.
[0024] The eBPF kernel hook program intercepts the sending path by binding the sys_sendto, sys_sendmsg, ip_output, and tcp_connect system calls through TC egress and kprobe.
[0025] The control class calls of the eBPF kernel hook program monitor user-space socket configuration actions through sys_setsockopt.
[0026] As a preferred option, the working process of the eBPF kernel hook program is as follows:
[0027] (1) Extract key fields from the message; among which, key fields include IP, Port and protocol type;
[0028] (2) Compare the intercepted information with the cached results using the eBPF map, and determine whether a hit occurs:
[0029] ①If it hits, use it directly;
[0030] ② If no match is found, construct query parameters and call the kernel module decision function through the BPF helper or the kernel module communication interface;
[0031] (3) Process the message according to the returned processing action; the processing actions include rewriting the destination address, selecting the routing path, marking and modifying the queue;
[0032] (4) Cache the decision results in a per-cpu map / hash map to optimize duplicate queries.
[0033] More preferably, the routing kernel module provides access to data structures via the kernel space interface functions BPF helper or bpf_probe_read_kernel() called by eBPF, and supports complex routing rule configurations. It implements high-performance LRU or LFU caching mechanisms to accelerate access to high-frequency routing table entries, while synchronizing with the routing table or policy database. The routing rules include: IP / Port / DSCP / user ID multi-factor matching, policy priority, and load or link state environment factors.
[0034] The specific design and implementation methods of the routing kernel module are as follows:
[0035] ① Provides a user-space configuration interface via Netlink;
[0036] ② The routing kernel module securely updates the routing decision data structure via RCU;
[0037] ③ Routing policy rules are stored in a hash table, and BPF map is used to share access results.
[0038] An eBPF-based kernel optimization system, comprising an eBPF user-space management module, user-space control tools, an eBPF kernel hook module, and a routing kernel module;
[0039] The eBPF user-mode management module manages the lifecycle of eBPF kernel hook programs, specifies the eBPF hook points of eBPF kernel hook programs, and maintains the use of map and perf events.
[0040] User-space control tools are used to add, modify, and delete policies, view cache hit status, perform performance statistics, import business scenario configuration templates, support dynamic configuration synchronization to the routing kernel module, push configurations through the Netlink channel or BPF map interface, and have a rule rollback mechanism.
[0041] The eBPF kernel hook module is used to select multiple kernel eBPF loading points and program interception points for packet interception, and communicates with the kernel module to complete the selection of operation functions and routing parameters.
[0042] The routing kernel module is used to make routing decisions based on various complex routing requirements, configuration conditions, packet conditions, and environmental conditions, and returns the query results to the eBPF kernel hook program module, which then executes them.
[0043] As a preferred option, the eBPF hook points of the eBPF kernel hook program module include XDP hook, TC ingresshook, kprobe / ip_output, kretprobe / _inet_lookup_skb, kprobe / sys_sendto, kprobe / tcp_connect, and kprobe / sys_setsockopt;
[0044] Among them, the receiving path of the eBPF kernel hook program module is to intercept at the L2 layer through the XDP hook or to intercept at the L3 / L4 layer through the TCingress hook.
[0045] The eBPF kernel hook module intercepts the sending path by binding the sys_sendto, sys_sendmsg, ip_output, and tcp_connect system calls through TC egress and kprobe.
[0046] The control class calls of the eBPF kernel hook program module are monitored through sys_setsockopt to monitor user-mode socket configuration actions.
[0047] The specific working process of the eBPF kernel hook program module is as follows:
[0048] (1) Extract key fields from the message; among which, key fields include IP, Port and protocol type;
[0049] (2) Compare the intercepted information with the cached results using the eBPF map, and determine whether a hit occurs:
[0050] ①If it hits, use it directly;
[0051] ② If no match is found, construct query parameters and call the kernel module decision function through the BPF helper or the kernel module communication interface;
[0052] (3) Process the message according to the returned processing action; the processing actions include rewriting the destination address, selecting the routing path, marking and modifying the queue;
[0053] (4) Cache the decision results in a per-cpu map / hash map to optimize duplicate queries;
[0054] The routing kernel module provides access to data structures via the kernel space interface functions BPF helper or bpf_probe_read_kernel(), which are called by eBPF. It also supports complex routing rule configurations, implements high-performance LRU or LFU caching mechanisms to accelerate access to high-frequency routing table entries, and synchronizes with the routing table or policy database. The routing rules include: IP / Port / DSCP / user ID multi-factor matching, policy priority, and load or link state environment factors.
[0055] The specific design and implementation methods of the routing kernel module are as follows:
[0056] ① Provides a user-space configuration interface via Netlink;
[0057] ② The routing kernel module securely updates the routing decision data structure via RCU;
[0058] ③ Routing policy rules are stored in a hash table, and BPF map is used to share access results.
[0059] An electronic device includes: a memory and at least one processor;
[0060] The memory contains computer programs;
[0061] The at least one processor executes the computer program stored in the memory, causing the at least one processor to perform the eBPF-based kernel optimization method as described above.
[0062] A computer-readable storage medium storing a computer program that can be executed by a processor to implement the eBPF-based kernel optimization method described above.
[0063] The kernel optimization method, system, device, and medium based on eBPF of the present invention have the following advantages:
[0064] (i) Based on eBPF technology, this invention can flexibly select routes for specified data packets in multiple kernel processing stages according to the characteristics of data packet fields. Based on kernel module technology, it can provide more open routing capabilities. This invention provides a usable solution for new network routing and routing optimization methods.
[0065] (ii) This invention establishes a routing path that can bypass the network stack, thereby improving the transmission performance of certain specific data streams and performing special routing and transmission processes for specified data streams, thereby providing services for dedicated network adapters;
[0066] (iii) The present invention can construct a new processing flow for a specified data packet based on the information contained in the data packet, and can construct a new data packet processing flow outside the network stack, thereby improving the processing performance of Linux and providing new selectable data paths for the network adapter;
[0067] (iv) The introduction of eBPF technology in this invention can improve the iteration speed and allow users with different needs to modify it according to their own situation, so that users can realize customized network processing methods with lower learning costs, improve development efficiency and reduce human resource input.
[0068] (v) This invention uses eBPF technology to flexibly manage and control various hook points that can be used to intercept data packets, and uses kernel modules to efficiently and quickly select routing methods while meeting user needs.
[0069] (vi) The eBPF kernel hook program of the present invention can intercept Linux network stack processing data packets at the kernel mount point and program hook point selected by the user, and the eBPF kernel hook program can complete function calls with the kernel module, thereby obtaining from the kernel module's decision how the eBPF intercepted data packets should be processed next. The kernel module program needs to be able to provide kernel functions to provide routing decisions for external calls. The kernel module can adopt many performance optimization methods of previous routing software, such as caching high-frequency routing table entries. Attached Figure Description
[0070] The invention will be further described below with reference to the accompanying drawings.
[0071] Appendix Figure 1 This is a flowchart illustrating the kernel optimization method based on eBPF.
[0072] Appendix Figure 2 This is a schematic diagram of the structure of the kernel optimization method based on eBPF. Detailed Implementation
[0073] The following detailed description of the eBPF-based kernel optimization method, system, device, and medium of the present invention is provided with reference to the accompanying drawings and specific embodiments.
[0074] Example 1:
[0075] As attached Figure 1As shown, this embodiment provides a kernel optimization method based on eBPF. This method involves an eBPF kernel hook program intercepting data packets at multiple kernel eBPF loading points and program interception points selected by the user, and performing route queries with the routing kernel module to complete the selection of operation functions and routing parameters. The routing kernel module completes the routing decision based on various complex routing requirements, configuration conditions, data packet conditions, and environmental conditions, and returns the query results to the eBPF kernel hook program, which then executes the results.
[0076] The data packet receiving process in this embodiment is as follows:
[0077] (1) The network adapter copies data packets from the storage system to the Linux memory based on the driver and performs route lookup with the routing kernel module to complete the selection of operation functions and routing parameters;
[0078] (2) In the Linux network stack processing flow, the eBPF kernel hook program intercepts data packets at different network stack locations based on the information contained in the data packets, and provides optimization for specified data packets based on the interception location and the information carried by the data packets.
[0079] (3) After the eBPF kernel hook program completes data interception, based on the interception location and the information carried by the data packet, it calls the routing interface provided by the routing kernel module, provides the routing parameters contained in the data packet, and the routing kernel module completes the routing decision.
[0080] (4) The routing kernel module is a separate module that provides functions that can be called by the eBPF kernel hook program within the kernel; at the same time, it calculates and determines the processing method and parameters of the corresponding data packets according to the user configuration.
[0081] (5) The routing kernel module returns the result after the call to the eBPF kernel hook program, which then executes the result to provide a specific processing flow for the specified data packet; the result after the call includes the processing method and parameters.
[0082] (6) The eBPF kernel hook program temporarily stores the corresponding processing methods and executes them directly in the next processing, thereby improving processing performance.
[0083] The data packet transmission in this embodiment is as follows:
[0084] ① The data packet is sent from user space to the kernel network stack via the send() interface, and then executed according to the standard procedure.
[0085] ② The eBPF kernel hook program intercepts data packets at different network stack locations and determines whether to complete the interception at that point based on the information contained in the data packet; similarly, for a specified data packet, the eBPF kernel hook program performs a route query to the routing kernel module based on the data packet information after interception.
[0086] ③ The routing kernel module returns a call response; the call response includes the processing method and parameters for the corresponding data packet;
[0087] ④ Based on the response from the routing kernel module, the eBPF kernel hook program completes the packet sending, which is the optimized packet sending process.
[0088] In this embodiment, the eBPF hook points of the eBPF kernel hook program include XDP hook, TC ingresshook, kprobe / ip_output, kretprobe / _inet_lookup_skb, kprobe / sys_sendto, kprobe / tcp_connect, and kprobe / sys_setsockopt;
[0089] Among them, the receiving path of the eBPF kernel hook program is to intercept at the L2 layer through the XDP hook or to intercept at the L3 / L4 layer through the TCingress hook.
[0090] The eBPF kernel hook program intercepts the sending path by binding the sys_sendto, sys_sendmsg, ip_output, and tcp_connect system calls through TC egress and kprobe.
[0091] The control class calls of the eBPF kernel hook program monitor user-space socket configuration actions through sys_setsockopt.
[0092] The specific working process of the eBPF kernel hook program in this embodiment is as follows:
[0093] (1) Extract key fields from the message; among which, key fields include IP, Port and protocol type;
[0094] (2) Compare the intercepted information with the cached results using the eBPF map, and determine whether a hit occurs:
[0095] ①If it hits, use it directly;
[0096] ② If no match is found, construct query parameters and call the kernel module decision function through the BPF helper or the kernel module communication interface;
[0097] (3) Process the message according to the returned processing action; the processing actions include rewriting the destination address, selecting the routing path, marking and modifying the queue;
[0098] (4) Cache the decision results in a per-cpu map / hash map to optimize duplicate queries.
[0099] In this embodiment, the routing kernel module provides access to data structures via the kernel space interface functions BPF helper or bpf_probe_read_kernel() called by eBPF, and supports complex routing rule configurations. It implements high-performance LRU or LFU caching mechanisms to accelerate access to high-frequency routing table entries, while synchronizing with the routing table or policy database. The routing rules include: IP / Port / DSCP / user ID multi-factor matching, policy priority, and load or link state environmental factors.
[0100] The specific design and implementation method of the routing kernel module in this embodiment is as follows:
[0101] ① Provides a user-space configuration interface via Netlink;
[0102] ② The routing kernel module securely updates the routing decision data structure via RCU;
[0103] ③ Routing policy rules are stored in a hash table, and BPF map is used to share access results.
[0104] Example 2:
[0105] This embodiment provides a kernel optimization system based on eBPF, which includes an eBPF user-space management program module, a user-space control tool, an eBPF kernel hook program module, and a routing kernel module.
[0106] The eBPF user-mode management module manages the lifecycle of eBPF kernel hook programs, specifies the eBPF hook points of eBPF kernel hook programs, and maintains the use of map and perf events.
[0107] User-space control tools are used to add, modify, and delete policies, view cache hit status, perform performance statistics, import business scenario configuration templates, support dynamic configuration synchronization to the routing kernel module, push configurations through the Netlink channel or BPF map interface, and have a rule rollback mechanism.
[0108] The eBPF kernel hook module is used to select multiple kernel eBPF loading points and program interception points for packet interception, and communicates with the kernel module to complete the selection of operation functions and routing parameters.
[0109] The routing kernel module is used to make routing decisions based on various complex routing requirements, configuration conditions, packet conditions, and environmental conditions, and returns the query results to the eBPF kernel hook program module, which then executes them.
[0110] In this embodiment, the eBPF hook points of the eBPF kernel hook program module include XDP hook, TC ingresshook, kprobe / ip_output, kretprobe / _inet_lookup_skb, kprobe / sys_sendto, kprobe / tcp_connect, and kprobe / sys_setsockopt;
[0111] Among them, the receiving path of the eBPF kernel hook program module is to intercept at the L2 layer through the XDP hook or to intercept at the L3 / L4 layer through the TCingress hook.
[0112] The eBPF kernel hook module intercepts the sending path by binding the sys_sendto, sys_sendmsg, ip_output, and tcp_connect system calls through TC egress and kprobe.
[0113] The control class calls of the eBPF kernel hook program module are monitored through sys_setsockopt to monitor user-mode socket configuration actions.
[0114] The specific working process of the eBPF kernel hook program module in this embodiment is as follows:
[0115] (1) Extract key fields from the message; among which, key fields include IP, Port and protocol type;
[0116] (2) Compare the intercepted information with the cached results using the eBPF map, and determine whether a hit occurs:
[0117] ①If it hits, use it directly;
[0118] ② If no match is found, construct query parameters and call the kernel module decision function through the BPF helper or the kernel module communication interface;
[0119] (3) Process the message according to the returned processing action; the processing actions include rewriting the destination address, selecting the routing path, marking and modifying the queue;
[0120] (4) Cache the decision results in a per-cpu map / hash map to optimize duplicate queries.
[0121] In this embodiment, the routing kernel module provides access to data structures via the kernel space interface functions BPF helper or bpf_probe_read_kernel() called by eBPF, and supports complex routing rule configurations. It implements high-performance LRU or LFU caching mechanisms to accelerate access to high-frequency routing table entries, while synchronizing with the routing table or policy database. The routing rules include: IP / Port / DSCP / user ID multi-factor matching, policy priority, and load or link state environmental factors.
[0122] The specific design and implementation method of the routing kernel module in this embodiment is as follows:
[0123] ① Provides a user-space configuration interface via Netlink;
[0124] ② The routing kernel module securely updates the routing decision data structure via RCU;
[0125] ③ Routing policy rules are stored in a hash table, and BPF map is used to share access results.
[0126] Example 3:
[0127] This invention also provides an electronic device, including: a memory and a processor;
[0128] The memory stores the instructions executed by the computer.
[0129] The processor executes computer execution instructions stored in the memory, causing the processor to perform the eBPF-based kernel optimization method in any embodiment of the present invention.
[0130] The processor can be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), off-the-shelf programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The processor can be a microprocessor or any conventional processor.
[0131] Memory is used to store computer programs and / or modules. The processor implements various functions of the electronic device by running or executing the computer programs and / or modules stored in the memory, and by accessing data stored in the memory. Memory can mainly include a program storage area and a data storage area. The program storage area can store the operating system, at least one application program required for a function, etc.; the data storage area can store data created based on the use of the terminal, etc. In addition, memory can also include high-speed random access memory, and can also include non-volatile memory, such as hard disks, RAM, plug-in hard disks, smart memory cards (SMC), secure digital cards (SD cards), flash memory cards, at least one disk storage device, flash memory devices, or other volatile solid-state storage devices.
[0132] Example 4:
[0133] This embodiment also provides a computer-readable storage medium storing multiple instructions, which are loaded by a processor to cause the processor to execute the eBPF-based kernel optimization method according to any embodiment of the present invention. Specifically, a system or apparatus equipped with a storage medium may be provided, on which software program code implementing the functions of any of the above embodiments is stored, and the computer (or CPU or MPU) of the system or apparatus can read and execute the program code stored in the storage medium.
[0134] In this case, the program code read from the storage medium can itself implement the function of any of the above embodiments, and therefore the program code and the storage medium storing the program code constitute part of the present invention.
[0135] Storage media embodiments for providing program code include floppy disks, hard disks, magneto-optical disks, optical disks (such as CD-ROM, CD-R, CD-RW, DVD-ROM, DVD-RYM, DVD-RW, DVD+RW), magnetic tapes, non-volatile memory cards, and ROMs. Alternatively, program code can be downloaded from a server computer via a communication network.
[0136] Furthermore, it should be clear that not only can the program code read by the computer be executed, but also the operating system or other components operating on the computer can be instructed based on the program code to perform some or all of the actual operations, thereby realizing the function of any of the embodiments described above.
[0137] Furthermore, it is understood that the program code read from the storage medium is written to the memory set in the expansion board inserted into the computer or to the memory set in the expansion unit connected to the computer. Then, based on the instructions of the program code, the CPU or other components installed on the expansion board or expansion unit execute some and all of the actual operations, thereby realizing the function of any of the embodiments described above.
[0138] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some or all of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present invention.
Claims
1. A kernel optimization method based on eBPF, characterized in that, This method involves the eBPF kernel hook program intercepting data packets at multiple kernel eBPF loading points and program interception points selected by the user, and performing route queries with the routing kernel module to complete the selection of operation functions and routing parameters. The routing kernel module makes routing decisions based on various complex routing requirements, configuration conditions, data packet conditions, and environmental conditions, and returns the query results to the eBPF kernel hook program, which then executes them.
2. The kernel optimization method based on eBPF according to claim 1, characterized in that, The data packet reception process is as follows: (1) The network adapter copies data packets from the storage system to the Linux memory based on the driver and performs route lookup with the routing kernel module to complete the selection of operation functions and routing parameters; (2) In the Linux network stack processing flow, the eBPF kernel hook program intercepts data packets at different network stack locations based on the information contained in the data packets, and provides optimization for specified data packets based on the interception location and the information carried by the data packets. (3) After the eBPF kernel hook program completes data interception, based on the interception location and the information carried by the data packet, it calls the routing interface provided by the routing kernel module, provides the routing parameters contained in the data packet, and the routing kernel module completes the routing decision. (4) The routing kernel module provides functions that can be called by the eBPF kernel hook program within the kernel; at the same time, it calculates and determines the processing method and parameters of the corresponding data packets according to the user configuration. (5) The routing kernel module returns the result after the call to the eBPF kernel hook program, which then executes the result to provide a specific processing flow for the specified data packet; the result after the call includes the processing method and parameters. (6) The eBPF kernel hook program temporarily stores the corresponding processing methods and executes them directly in the next processing, thereby improving processing performance.
3. The kernel optimization method based on eBPF according to claim 1, characterized in that, The data packet transmission is as follows: ① The data packet is sent from user space to the kernel network stack via the send() interface, and then executed according to the standard procedure. ② The eBPF kernel hook program intercepts data packets at different network stack locations and determines whether to complete the interception at that point based on the information contained in the data packet; similarly, for a specified data packet, the eBPF kernel hook program performs a route query to the routing kernel module based on the data packet information after interception. ③ The routing kernel module returns a call response; the call response includes the processing method and parameters for the corresponding data packet; ④ Based on the response from the routing kernel module, the eBPF kernel hook program completes the packet sending, which is the optimized packet sending process.
4. The kernel optimization method based on eBPF according to claim 1, characterized in that, The eBPF kernel hook points include XDP hook, TC ingress hook, kprobe / ip_output, kretprobe / _inet_lookup_skb, kprobe / sys_sendto, kprobe / tcp_connect, and kprobe / sys_setsockopt; The receiving path of the eBPF kernel hook program is to intercept at the L2 layer through XDP hook or at the L3 / L4 layer through TC ingress hook. The eBPF kernel hook program intercepts the sending path by binding the sys_sendto, sys_sendmsg, ip_output, and tcp_connect system calls through TC egress and kprobe. The control class calls of the eBPF kernel hook program monitor user-space socket configuration actions through sys_setsockopt.
5. The kernel optimization method based on eBPF according to claim 1, characterized in that, The specific working process of the eBPF kernel hook program is as follows: (1) Extract key fields from the message; among which, key fields include IP, Port and protocol type; (2) Compare the intercepted information with the cached results using the eBPF map, and determine whether a hit occurs: ①If it hits, use it directly; ② If no match is found, construct query parameters and call the kernel module decision function through the BPF helper or the kernel module communication interface; (3) Process the message according to the returned processing action; the processing actions include rewriting the destination address, selecting the routing path, marking and modifying the queue; (4) Cache the decision results in a per-cpu map / hash map to optimize duplicate queries.
6. The kernel optimization method based on eBPF according to any one of claims 1-5, characterized in that, The routing kernel module provides access to data structures via the kernel space interface functions BPF helper or bpf_probe_read_kernel(), which are called by eBPF. It also supports complex routing rule configurations, implements high-performance LRU or LFU caching mechanisms to accelerate access to high-frequency routing table entries, and synchronizes with the routing table or policy database. The routing rules include: IP / Port / DSCP / user ID multi-factor matching, policy priority, and load or link state environment factors. The specific design and implementation methods of the routing kernel module are as follows: ① Provides a user-space configuration interface via Netlink; ② The routing kernel module securely updates the routing decision data structure via RCU; ③ Routing policy rules are stored in a hash table, and BPF map is used to share access results.
7. A kernel optimization system based on eBPF, characterized in that, The system includes an eBPF user-space management module, user-space control tools, an eBPF kernel hook module, and a routing kernel module; The eBPF user-mode management module manages the lifecycle of eBPF kernel hook programs, specifies the eBPF hook points of eBPF kernel hook programs, and maintains the use of map and perf events. User-space control tools are used to add, modify, and delete policies, view cache hit status, perform performance statistics, import business scenario configuration templates, support dynamic configuration synchronization to the routing kernel module, push configurations through the Netlink channel or BPF map interface, and have a rule rollback mechanism. The eBPF kernel hook module is used to select multiple kernel eBPF loading points and program interception points for packet interception, and communicates with the kernel module to complete the selection of operation functions and routing parameters. The routing kernel module is used to make routing decisions based on various complex routing requirements, configuration conditions, packet conditions, and environmental conditions, and returns the query results to the eBPF kernel hook program module, which then executes them.
8. The kernel optimization system based on eBPF according to claim 7, characterized in that, The eBPF hook points of the eBPF kernel hook program module include XDP hook, TC ingress hook, kprobe / ip_output, kretprobe / _inet_lookup_skb, kprobe / sys_sendto, kprobe / tcp_connect, and kprobe / sys_setsockopt; Among them, the receiving path of the eBPF kernel hook program module is to intercept at the L2 layer through the XDP hook or to intercept at the L3 / L4 layer through the TCingress hook. The eBPF kernel hook module intercepts the sending path by binding the sys_sendto, sys_sendmsg, ip_output, and tcp_connect system calls through TC egress and kprobe. The control class calls of the eBPF kernel hook program module are monitored through sys_setsockopt to monitor user-mode socket configuration actions. The specific working process of the eBPF kernel hook program module is as follows: (1) Extract key fields from the message; among which, key fields include IP, Port and protocol type; (2) Compare the intercepted information with the cached results using the eBPF map, and determine whether a hit occurs: ①If it hits, use it directly; ② If no match is found, construct query parameters and call the kernel module decision function through the BPF helper or the kernel module communication interface; (3) Process the message according to the returned processing action; the processing actions include rewriting the destination address, selecting the routing path, marking and modifying the queue; (4) Cache the decision results in a per-cpu map / hash map to optimize duplicate queries; The routing kernel module provides access to data structures via the kernel space interface functions BPF helper or bpf_probe_read_kernel(), which are called by eBPF. It also supports complex routing rule configurations, implements high-performance LRU or LFU caching mechanisms to accelerate access to high-frequency routing table entries, and synchronizes with the routing table or policy database. The routing rules include: IP / Port / DSCP / user ID multi-factor matching, policy priority, and load or link state environment factors. The specific design and implementation methods of the routing kernel module are as follows: ① Provides a user-space configuration interface via Netlink; ② The routing kernel module securely updates the routing decision data structure via RCU; ③ Routing policy rules are stored in a hash table, and BPF map is used to share access results.
9. An electronic device, characterized in that, include: Memory and at least one processor; The memory contains computer programs; The at least one processor executes the computer program stored in the memory, causing the at least one processor to perform the eBPF-based kernel optimization method as described in any one of claims 1 to 6.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that can be executed by a processor to implement the eBPF-based kernel optimization method as described in any one of claims 1 to 6.
Citation Information
Cited By
Message processing method and system for detecting netfilter through eBPF
CN121509559A
Full-link network fault diagnosis method and system based on eBPF
CN122226586A
An eBPF-based full-link network fault diagnosis method and system
CN122226586B