Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Net tile v2: ARP/routing isolation #3619

Open
ripatel-fd opened this issue Dec 4, 2024 · 0 comments
Open

Net tile v2: ARP/routing isolation #3619

ripatel-fd opened this issue Dec 4, 2024 · 0 comments
Assignees

Comments

@ripatel-fd
Copy link
Contributor

Currently, the net tile handles sensitive interactions with a netlink socket on the same process that does packet handling.

Control and data paths should be separated here-
The net tile should do issuing of ARP requests and routing table lookups over shared memory.
This allows for a stricter seccomp policy.

ARP and routing code to be moved to a different process.
ARP can possibly be moved to eBPF.

@ripatel-fd ripatel-fd self-assigned this Dec 4, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant