kmesh icon indicating copy to clipboard operation
kmesh copied to clipboard

support xdp auth with tail call

Open weli-l opened this issue 1 year ago • 6 comments

What type of PR is this?

What this PR does / why we need it:

Which issue(s) this PR fixes: Fixes #

Special notes for your reviewer:

Does this PR introduce a user-facing change?:


weli-l avatar Sep 19 '24 07:09 weli-l

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by: Once this PR has been reviewed and has the lgtm label, please assign kevin-wangzefeng for approval. For more information see the Kubernetes Code Review Process.

The full list of commands accepted by this bot can be found here.

Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment Approvers can cancel approval by writing /approve cancel in a comment

kmesh-bot avatar Sep 19 '24 07:09 kmesh-bot

Codecov Report

Attention: Patch coverage is 60.00000% with 4 lines in your changes missing coverage. Please review.

Project coverage is 54.43%. Comparing base (0a7735d) to head (aa98335). Report is 281 commits behind head on main.

Files with missing lines Patch % Lines
pkg/bpf/workload/xdp.go 60.00% 2 Missing and 2 partials :warning:
Files with missing lines Coverage Δ
pkg/bpf/workload/xdp.go 55.38% <60.00%> (ø)

... and 8 files with indirect coverage changes


Continue to review full report in Codecov by Sentry.

Legend - Click here to learn more Δ = absolute <relative> (impact), ø = not affected, ? = missing data Powered by Codecov. Last update 99e0c0c...aa98335. Read the comment docs.


🚨 Try these New Features:

codecov[bot] avatar Sep 19 '24 08:09 codecov[bot]

Wanna to know why do we need tailcall here

hzxuzhonghu avatar Sep 20 '24 01:09 hzxuzhonghu

Wanna to know why do we need tailcall here

Because the subsequent authentication rules will support srcip, dstip, namespce, etc., but if tailcall is not used, the bytes of the ebpf program will be too large (up to 1000000 bytes), and it will not pass the verification of the verifier.

weli-l avatar Sep 20 '24 01:09 weli-l

got it

hzxuzhonghu avatar Sep 20 '24 01:09 hzxuzhonghu

It is recommended that this modification be merged after version 0.5 is released.

supercharge-xsy avatar Sep 20 '24 03:09 supercharge-xsy