Documentation
¶
Index ¶
- Variables
- func BuildXDP(source, output string) error
- func DefaultXDPPinPath(interfaceName string) string
- func DetachXDP(iface string, mode XDPMode) error
- func Listen(string, *tls.Config, KernelConfig, Host) error
- func NormalizeConfig(cfg *KernelConfig) error
- type Host
- type KernelBackend
- type KernelCapabilities
- type KernelConfig
- type KernelProfile
- type KernelRuntimeInfo
- type ReadinessConfig
- type ReadinessIssue
- type ReadinessReport
- type ReadinessSeverity
- type XDPConfig
- type XDPManager
- func (m *XDPManager) Attach() error
- func (m *XDPManager) Attached() bool
- func (m *XDPManager) BlockIP(addr netip.Addr) error
- func (m *XDPManager) Detach() error
- func (m *XDPManager) ProtectPort(port uint16) error
- func (m *XDPManager) SetRateLimit(rate, burst uint64) error
- func (m *XDPManager) UnblockIP(addr netip.Addr) error
- func (m *XDPManager) UnprotectPort(port uint16) error
- type XDPMode
Constants ¶
This section is empty.
Variables ¶
var ErrXDPUnsupported = errors.New("fh: XDP is unsupported on this platform")
Functions ¶
func DefaultXDPPinPath ¶
DefaultXDPPinPath returns the isolated bpffs directory used by automatic attachment.
func NormalizeConfig ¶
func NormalizeConfig(cfg *KernelConfig) error
NormalizeConfig validates cfg and fills platform-specific defaults.
Types ¶
type Host ¶
type Host struct {
StartServing func(net.Listener) error
FinishServing func()
AcceptConnection func(net.Conn) bool
SetRuntime func(closer interface{ Close() error }, info KernelRuntimeInfo)
PrintStartupBanner func(net.Listener)
BeginShutdown func() error
Closed func() bool
NormalizeServeError func(error, bool) error
LogInfo func(string, ...any)
LogWarn func(string, ...any)
AddAcceptErrors func(uint64)
AddPinnedThreads func(int32)
AddSocketOptionErrors func(uint64)
}
Host connects the transport package to fh's HTTP lifecycle without creating an import cycle between the root package and this package.
type KernelBackend ¶
type KernelBackend string
KernelBackend selects the operating-system-native network reactor used by Listen.
const ( KernelBackendAuto KernelBackend = "auto" KernelBackendStandard KernelBackend = "standard" KernelBackendNative KernelBackend = "native" KernelBackendEpoll KernelBackend = "epoll" KernelBackendIOUring KernelBackend = "io_uring" KernelBackendKqueue KernelBackend = "kqueue" KernelBackendIOCP KernelBackend = "iocp" KernelBackendEventPorts KernelBackend = "event_ports" KernelBackendPollset KernelBackend = "pollset" )
type KernelCapabilities ¶
type KernelCapabilities struct {
OS string `json:"os"`
Arch string `json:"arch"`
KernelRelease string `json:"kernel_release,omitempty"`
NativePoller string `json:"native_poller,omitempty"`
ServerSockets bool `json:"server_sockets"`
RuntimeNetpoll bool `json:"runtime_netpoll"`
Epoll bool `json:"epoll"`
Kqueue bool `json:"kqueue"`
IOCP bool `json:"iocp"`
EventPorts bool `json:"event_ports"`
Pollset bool `json:"pollset"`
ReusePort bool `json:"reuse_port"`
ReusePortBPF bool `json:"reuse_port_bpf"`
IOUring bool `json:"io_uring"`
IOUringFeatures uint32 `json:"io_uring_features,omitempty"`
IOUringProbeError string `json:"io_uring_probe_error,omitempty"`
BPFFSMounted bool `json:"bpffs_mounted"`
IPToolAvailable bool `json:"ip_tool_available"`
XDPTooling bool `json:"xdp_tooling"`
BPFToolAvailable bool `json:"bpftool_available"`
ClangBPFAvailable bool `json:"clang_bpf_available"`
ClangBPFProbeError string `json:"clang_bpf_probe_error,omitempty"`
}
KernelCapabilities reports locally detectable kernel facilities without attaching programs, changing interfaces, or requiring elevated privileges.
func ProbeKernel ¶
func ProbeKernel() KernelCapabilities
type KernelConfig ¶
type KernelConfig struct {
Enabled bool
Required bool
Backend KernelBackend
Profile KernelProfile
PreferIOUring bool
StrictSocketOptions bool
Reactors int
ReusePort bool
ReusePortBPF bool
PinThreads bool
CPUSet []int
Backlog int
ReceiveBufferBytes int
SendBufferBytes int
AcceptErrorBackoffMin time.Duration
AcceptErrorBackoffMax time.Duration
TCPNoDelay bool
TCPKeepAlive time.Duration
TCPKeepAliveIdle time.Duration
TCPKeepAliveIntvl time.Duration
TCPKeepAliveProbes int
TCPUserTimeout time.Duration
TCPDeferAccept time.Duration
TCPFastOpenQueue int
BusyPoll time.Duration
IOUringEntries uint32
XDP XDPConfig
}
KernelConfig enables operating-system-native serving.
func DefaultKernelConfig ¶
func DefaultKernelConfig() KernelConfig
func HighPerformanceKernelConfig ¶
func HighPerformanceKernelConfig() KernelConfig
func ProductionKernelConfig ¶
func ProductionKernelConfig() KernelConfig
type KernelProfile ¶
type KernelProfile string
KernelProfile selects production defaults without hiding the actual backend.
const ( KernelProfileBalanced KernelProfile = "balanced" KernelProfileThroughput KernelProfile = "throughput" KernelProfileLatency KernelProfile = "latency" KernelProfileCompatibility KernelProfile = "compatibility" )
type KernelRuntimeInfo ¶
type KernelRuntimeInfo struct {
Enabled bool `json:"enabled"`
Accelerated bool `json:"accelerated"`
Profile KernelProfile `json:"profile,omitempty"`
OS string `json:"os,omitempty"`
Arch string `json:"arch,omitempty"`
Backend KernelBackend `json:"backend,omitempty"`
RequestedBackend KernelBackend `json:"requested_backend,omitempty"`
NativePoller string `json:"native_poller,omitempty"`
Reactors int `json:"reactors,omitempty"`
ReusePort bool `json:"reuse_port,omitempty"`
ReusePortBPF bool `json:"reuse_port_bpf,omitempty"`
ThreadsPinned int `json:"threads_pinned,omitempty"`
IOUringProbed bool `json:"io_uring_probed,omitempty"`
IOUringAvailable bool `json:"io_uring_available,omitempty"`
IOUringFeatures uint32 `json:"io_uring_features,omitempty"`
IOUringNetworkIO bool `json:"io_uring_network_io,omitempty"`
XDPAttached bool `json:"xdp_attached,omitempty"`
XDPInterface string `json:"xdp_interface,omitempty"`
Accepted uint64 `json:"accepted"`
AcceptErrors uint64 `json:"accept_errors"`
Dropped uint64 `json:"dropped"`
ActiveConnections uint64 `json:"active_connections"`
PeakConnections uint64 `json:"peak_connections"`
RejectedGlobal uint64 `json:"rejected_global"`
RejectedPerIP uint64 `json:"rejected_per_ip"`
SocketOptionErrors uint64 `json:"socket_option_errors"`
FallbackReason string `json:"fallback_reason,omitempty"`
}
KernelRuntimeInfo reports what the process actually activated.
type ReadinessConfig ¶
type ReadinessIssue ¶
type ReadinessIssue struct {
Severity ReadinessSeverity `json:"severity"`
Code string `json:"code"`
Message string `json:"message"`
}
type ReadinessReport ¶
type ReadinessReport struct {
Ready bool `json:"ready"`
RequiresWorkloadBenchmark bool `json:"requires_workload_benchmark"`
Runtime KernelRuntimeInfo `json:"runtime"`
Issues []ReadinessIssue `json:"issues,omitempty"`
}
func EvaluateReadiness ¶
func EvaluateReadiness(c ReadinessConfig, runtimeInfo KernelRuntimeInfo) ReadinessReport
type ReadinessSeverity ¶
type ReadinessSeverity string
const ( ReadinessInfo ReadinessSeverity = "info" ReadinessWarning ReadinessSeverity = "warning" ReadinessError ReadinessSeverity = "error" )
type XDPManager ¶
type XDPManager struct {
// contains filtered or unexported fields
}
XDPManager owns an optional fh XDP program attachment and its pinned policy maps. Attach and Detach are idempotent. Policy updates require PinPath because bpftool addresses the verified kernel maps through bpffs.
func NewXDPManager ¶
func NewXDPManager(cfg XDPConfig) *XDPManager
func (*XDPManager) Attach ¶
func (m *XDPManager) Attach() error
func (*XDPManager) Attached ¶
func (m *XDPManager) Attached() bool
Attached reports whether this manager successfully attached the program.
func (*XDPManager) BlockIP ¶
func (m *XDPManager) BlockIP(addr netip.Addr) error
BlockIP adds one IPv4 or IPv6 address to the pinned kernel drop map.
func (*XDPManager) Detach ¶
func (m *XDPManager) Detach() error
func (*XDPManager) ProtectPort ¶
func (m *XDPManager) ProtectPort(port uint16) error
func (*XDPManager) SetRateLimit ¶
func (m *XDPManager) SetRateLimit(rate, burst uint64) error
func (*XDPManager) UnblockIP ¶
func (m *XDPManager) UnblockIP(addr netip.Addr) error
UnblockIP removes one IPv4 or IPv6 address from the pinned kernel drop map.
func (*XDPManager) UnprotectPort ¶
func (m *XDPManager) UnprotectPort(port uint16) error