TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Why is the kernel community replacing iptables with BPF?

54 点作者 lunchbreak大约 7 年前

3 条评论

PhantomGremlin大约 7 年前
An interesting introduction to how Linux currently does packet filtering and how changing to BPF will improve performance.<p>The really amusing thing to me (an OpenBSD user) was the omission of any discussion of the origin of BPF, or even spelling out the acronym (it&#x27;s the Berkeley Packet Filter).<p>Those GPL guys really really hate acknowledging anything to do with Berkeley! :) Even though in this case it&#x27;s not directly the University of California, Berkeley but instead the origin of BPF is the Lawrence Berkeley Laboratory.
评论 #16890487 未加载
评论 #16886613 未加载
评论 #16888262 未加载
indigodaddy大约 7 年前
I posted this on a similar current HN thread about BPF, but also relevant here. See Poettering&#x27;s blog for how you can do very cool access control things via systemd taking advantage of EBPF:<p><a href="http:&#x2F;&#x2F;0pointer.net&#x2F;blog&#x2F;ip-accounting-and-access-lists-with-systemd.html" rel="nofollow">http:&#x2F;&#x2F;0pointer.net&#x2F;blog&#x2F;ip-accounting-and-access-lists-with...</a>
qalmakka大约 7 年前
So what about the elephant in the room, nftables? Are they basically dead in the water now?
评论 #16883479 未加载