kernel

package
v0.0.24 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 15, 2026 License: MIT Imports: 20 Imported by: 0

Documentation

Index

Constants

This section is empty.

Variables

View Source
var ErrXDPUnsupported = errors.New("fh: XDP is unsupported on this platform")

Functions

func BuildXDP

func BuildXDP(source, output string) error

func DefaultXDPPinPath

func DefaultXDPPinPath(interfaceName string) string

DefaultXDPPinPath returns the isolated bpffs directory used by automatic attachment.

func DetachXDP

func DetachXDP(iface string, mode XDPMode) error

func Listen

func Listen(string, *tls.Config, KernelConfig, Host) error

Listen reports that inbound listeners are unavailable on this target.

func NormalizeConfig

func NormalizeConfig(cfg *KernelConfig) error

NormalizeConfig validates cfg and fills platform-specific defaults.

Types

type Host

type Host struct {
	StartServing          func(net.Listener) error
	FinishServing         func()
	AcceptConnection      func(net.Conn) bool
	SetRuntime            func(closer interface{ Close() error }, info KernelRuntimeInfo)
	PrintStartupBanner    func(net.Listener)
	BeginShutdown         func() error
	Closed                func() bool
	NormalizeServeError   func(error, bool) error
	LogInfo               func(string, ...any)
	LogWarn               func(string, ...any)
	AddAcceptErrors       func(uint64)
	AddPinnedThreads      func(int32)
	AddSocketOptionErrors func(uint64)
}

Host connects the transport package to fh's HTTP lifecycle without creating an import cycle between the root package and this package.

type KernelBackend

type KernelBackend string

KernelBackend selects the operating-system-native network reactor used by Listen.

const (
	KernelBackendAuto       KernelBackend = "auto"
	KernelBackendStandard   KernelBackend = "standard"
	KernelBackendNative     KernelBackend = "native"
	KernelBackendEpoll      KernelBackend = "epoll"
	KernelBackendIOUring    KernelBackend = "io_uring"
	KernelBackendKqueue     KernelBackend = "kqueue"
	KernelBackendIOCP       KernelBackend = "iocp"
	KernelBackendEventPorts KernelBackend = "event_ports"
	KernelBackendPollset    KernelBackend = "pollset"
)

type KernelCapabilities

type KernelCapabilities struct {
	OS                 string `json:"os"`
	Arch               string `json:"arch"`
	KernelRelease      string `json:"kernel_release,omitempty"`
	NativePoller       string `json:"native_poller,omitempty"`
	ServerSockets      bool   `json:"server_sockets"`
	RuntimeNetpoll     bool   `json:"runtime_netpoll"`
	Epoll              bool   `json:"epoll"`
	Kqueue             bool   `json:"kqueue"`
	IOCP               bool   `json:"iocp"`
	EventPorts         bool   `json:"event_ports"`
	Pollset            bool   `json:"pollset"`
	ReusePort          bool   `json:"reuse_port"`
	ReusePortBPF       bool   `json:"reuse_port_bpf"`
	IOUring            bool   `json:"io_uring"`
	IOUringFeatures    uint32 `json:"io_uring_features,omitempty"`
	IOUringProbeError  string `json:"io_uring_probe_error,omitempty"`
	BPFFSMounted       bool   `json:"bpffs_mounted"`
	IPToolAvailable    bool   `json:"ip_tool_available"`
	XDPTooling         bool   `json:"xdp_tooling"`
	BPFToolAvailable   bool   `json:"bpftool_available"`
	ClangBPFAvailable  bool   `json:"clang_bpf_available"`
	ClangBPFProbeError string `json:"clang_bpf_probe_error,omitempty"`
}

KernelCapabilities reports locally detectable kernel facilities without attaching programs, changing interfaces, or requiring elevated privileges.

func ProbeKernel

func ProbeKernel() KernelCapabilities

type KernelConfig

type KernelConfig struct {
	Enabled  bool
	Required bool
	Backend  KernelBackend
	Profile  KernelProfile

	PreferIOUring       bool
	StrictSocketOptions bool

	Reactors     int
	ReusePort    bool
	ReusePortBPF bool
	PinThreads   bool
	CPUSet       []int

	Backlog               int
	ReceiveBufferBytes    int
	SendBufferBytes       int
	AcceptErrorBackoffMin time.Duration
	AcceptErrorBackoffMax time.Duration

	TCPNoDelay         bool
	TCPKeepAlive       time.Duration
	TCPKeepAliveIdle   time.Duration
	TCPKeepAliveIntvl  time.Duration
	TCPKeepAliveProbes int
	TCPUserTimeout     time.Duration
	TCPDeferAccept     time.Duration
	TCPFastOpenQueue   int
	BusyPoll           time.Duration

	IOUringEntries uint32
	XDP            XDPConfig
}

KernelConfig enables operating-system-native serving.

func DefaultKernelConfig

func DefaultKernelConfig() KernelConfig

func HighPerformanceKernelConfig

func HighPerformanceKernelConfig() KernelConfig

func ProductionKernelConfig

func ProductionKernelConfig() KernelConfig

type KernelProfile

type KernelProfile string

KernelProfile selects production defaults without hiding the actual backend.

const (
	KernelProfileBalanced      KernelProfile = "balanced"
	KernelProfileThroughput    KernelProfile = "throughput"
	KernelProfileLatency       KernelProfile = "latency"
	KernelProfileCompatibility KernelProfile = "compatibility"
)

type KernelRuntimeInfo

type KernelRuntimeInfo struct {
	Enabled            bool          `json:"enabled"`
	Accelerated        bool          `json:"accelerated"`
	Profile            KernelProfile `json:"profile,omitempty"`
	OS                 string        `json:"os,omitempty"`
	Arch               string        `json:"arch,omitempty"`
	Backend            KernelBackend `json:"backend,omitempty"`
	RequestedBackend   KernelBackend `json:"requested_backend,omitempty"`
	NativePoller       string        `json:"native_poller,omitempty"`
	Reactors           int           `json:"reactors,omitempty"`
	ReusePort          bool          `json:"reuse_port,omitempty"`
	ReusePortBPF       bool          `json:"reuse_port_bpf,omitempty"`
	ThreadsPinned      int           `json:"threads_pinned,omitempty"`
	IOUringProbed      bool          `json:"io_uring_probed,omitempty"`
	IOUringAvailable   bool          `json:"io_uring_available,omitempty"`
	IOUringFeatures    uint32        `json:"io_uring_features,omitempty"`
	IOUringNetworkIO   bool          `json:"io_uring_network_io,omitempty"`
	XDPAttached        bool          `json:"xdp_attached,omitempty"`
	XDPInterface       string        `json:"xdp_interface,omitempty"`
	Accepted           uint64        `json:"accepted"`
	AcceptErrors       uint64        `json:"accept_errors"`
	Dropped            uint64        `json:"dropped"`
	ActiveConnections  uint64        `json:"active_connections"`
	PeakConnections    uint64        `json:"peak_connections"`
	RejectedGlobal     uint64        `json:"rejected_global"`
	RejectedPerIP      uint64        `json:"rejected_per_ip"`
	SocketOptionErrors uint64        `json:"socket_option_errors"`
	FallbackReason     string        `json:"fallback_reason,omitempty"`
}

KernelRuntimeInfo reports what the process actually activated.

type ReadinessConfig

type ReadinessConfig struct {
	Kernel                 KernelConfig
	MaxConnections         int
	MaxConnectionsPerIP    int
	ReadHeaderTimeoutSet   bool
	RequestBodyTimeoutSet  bool
	TLSHandshakeTimeoutSet bool
	IdleTimeoutSet         bool
	DisablePanicRecovery   bool
	FastMode               bool
}

type ReadinessIssue

type ReadinessIssue struct {
	Severity ReadinessSeverity `json:"severity"`
	Code     string            `json:"code"`
	Message  string            `json:"message"`
}

type ReadinessReport

type ReadinessReport struct {
	Ready                     bool              `json:"ready"`
	RequiresWorkloadBenchmark bool              `json:"requires_workload_benchmark"`
	Runtime                   KernelRuntimeInfo `json:"runtime"`
	Issues                    []ReadinessIssue  `json:"issues,omitempty"`
}

func EvaluateReadiness

func EvaluateReadiness(c ReadinessConfig, runtimeInfo KernelRuntimeInfo) ReadinessReport

type ReadinessSeverity

type ReadinessSeverity string
const (
	ReadinessInfo    ReadinessSeverity = "info"
	ReadinessWarning ReadinessSeverity = "warning"
	ReadinessError   ReadinessSeverity = "error"
)

type XDPConfig

type XDPConfig struct {
	Enabled        bool
	Required       bool
	AutoAttach     bool
	Interface      string
	Mode           XDPMode
	ObjectPath     string
	Section        string
	PinPath        string
	ProtectedPorts []uint16
	RatePerSecond  uint64
	Burst          uint64
}

type XDPManager

type XDPManager struct {
	// contains filtered or unexported fields
}

XDPManager owns an optional fh XDP program attachment and its pinned policy maps. Attach and Detach are idempotent. Policy updates require PinPath because bpftool addresses the verified kernel maps through bpffs.

func NewXDPManager

func NewXDPManager(cfg XDPConfig) *XDPManager

func (*XDPManager) Attach

func (m *XDPManager) Attach() error

func (*XDPManager) Attached

func (m *XDPManager) Attached() bool

Attached reports whether this manager successfully attached the program.

func (*XDPManager) BlockIP

func (m *XDPManager) BlockIP(addr netip.Addr) error

BlockIP adds one IPv4 or IPv6 address to the pinned kernel drop map.

func (*XDPManager) Detach

func (m *XDPManager) Detach() error

func (*XDPManager) ProtectPort

func (m *XDPManager) ProtectPort(port uint16) error

func (*XDPManager) SetRateLimit

func (m *XDPManager) SetRateLimit(rate, burst uint64) error

func (*XDPManager) UnblockIP

func (m *XDPManager) UnblockIP(addr netip.Addr) error

UnblockIP removes one IPv4 or IPv6 address from the pinned kernel drop map.

func (*XDPManager) UnprotectPort

func (m *XDPManager) UnprotectPort(port uint16) error

type XDPMode

type XDPMode string
const (
	XDPModeNative  XDPMode = "native"
	XDPModeGeneric XDPMode = "generic"
	XDPModeOffload XDPMode = "offload"
)

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL