samples: bpf: large eBPF program in C
authorAlexei Starovoitov <ast@plumgrid.com>
Mon, 1 Dec 2014 23:06:39 +0000 (15:06 -0800)
committerDavid S. Miller <davem@davemloft.net>
Sat, 6 Dec 2014 05:47:34 +0000 (21:47 -0800)
commitfbe3310840c65f3cf97dd90d23e177d061c376f2
treeee28163a6c53e0131fd2d3d626d02b0610eaed2b
parenta80857822b0c2ed608c93504bd3687b78f20c619
samples: bpf: large eBPF program in C

sockex2_kern.c is purposefully large eBPF program in C.
llvm compiles ~200 lines of C code into ~300 eBPF instructions.

It's similar to __skb_flow_dissect() to demonstrate that complex packet parsing
can be done by eBPF.
Then it uses (struct flow_keys)->dst IP address (or hash of ipv6 dst) to keep
stats of number of packets per IP.
User space loads eBPF program, attaches it to loopback interface and prints
dest_ip->#packets stats every second.

Usage:
$sudo samples/bpf/sockex2
ip 127.0.0.1 count 19
ip 127.0.0.1 count 178115
ip 127.0.0.1 count 369437
ip 127.0.0.1 count 559841
ip 127.0.0.1 count 750539

Signed-off-by: Alexei Starovoitov <ast@plumgrid.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
samples/bpf/Makefile
samples/bpf/sockex2_kern.c [new file with mode: 0644]
samples/bpf/sockex2_user.c [new file with mode: 0644]