Verified programs can party: optimizing kernel extensions via post-verification merging
Hsuan-Chi Kuo, Kai-Hsun Chen, Yicheng Lu, Dan Williams, Sibin Mohan, Tianyin Xu
摘要
Operating system (OS) extensions are more popular than ever. For example, Linux BPF is marketed as a "superpower" that allows user programs to be downloaded into the kernel, verified to be safe and executed at kernel hook points. So, BPF extensions have high performance and are often placed at performance-critical paths for tracing and filtering.
However, although BPF extension programs execute in a shared kernel environment and are already individually verified, they are often executed independently in chains. We observe that the chain pattern has large performance overhead, due to indirect jumps penalized by security mitigations (e.g., Spectre), loops, and memory accesses.
In this paper, we argue for a separation of concerns. We propose to decouple the execution of BPF extensions from their verification requirements-BPF extension programs can be collectively optimized, after each BPF extension program is individually verified and loaded into the shared kernel.
We present KFuse, a framework that dynamically and automatically merges chains of BPF programs by transforming indirect jumps into direct jumps, unrolling loops, and saving memory accesses, without loss of security or flexibility. KFuse can merge BPF programs that are (1) installed by multiple principals, (2) maintained to be modular and
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper9
- Finding Correctness Bugs in eBPF Verifier with Structured and Sanitized ProgramHao Sun, Yiru Xu, Jianzhong Liu, Yuheng Shen 等EuroSys 2024 · 被引用 24 次
- Merlin: Multi-tier Optimization of eBPF Code for Performance and CompactnessJinsong Mao, Hailun Ding, Juan Zhai, Shiqing MaASPLOS 2024 · 被引用 15 次
- NetEdit: An Orchestration Platform for eBPF Network Functions at ScaleTheophilus A. Benson, Prashanth Kannan, Prankur Gupta, Balasubramanian Madhavan 等SIGCOMM 2024 · 被引用 11 次
- eNetSTL: Towards an In-kernel Library for High-Performance eBPF-based Network FunctionsBin Yang, Dian Shen, Junxue Zhang, Hanlin Yang 等EuroSys 2025 · 被引用 9 次
- Revealing the Unstable Foundations of eBPF-Based Kernel ExtensionsShawn Wanxiang Zhong, Jing Liu, Andrea C. Arpaci-Dusseau, Remzi H. Arpaci-DusseauEuroSys 2025 · 被引用 4 次
它引用的顶会 Paper11
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin 等S&P 2019 · 被引用 2,435 次
- Meltdown: Reading Kernel Memory from User SpaceMoritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher 等USENIX Security 2018 · 被引用 1,456 次
- Twine: A Unified Cluster Management System for Shared InfrastructureChunqiang Tang, Kenny Yu, Kaushik Veeraraghavan, Jonathan Kaldor 等OSDI 2020 · 被引用 107 次
- Specification and verification in the field: Applying formal methods to BPF just-in-time compilers in the Linux kernelLuke Nelson, Jacob Van Geffen, Emina Torlak, Xi WangOSDI 2020 · 被引用 72 次
- SANRAZOR: Reducing Redundant Sanitizer Checks in C/C++ ProgramsJiang Zhang, Shuai Wang, Manuel Rigger, Pinjia He 等OSDI 2021 · 被引用 38 次
相关 Paper
- Fast, Flexible, and Practical Kernel ExtensionsKumar Kartikeya Dwivedi, Rishabh R. Iyer, Sanidhya KashyapSOSP 2024 · 被引用 7 次
- Synthesizing safe and efficient kernel extensions for packet processingQiongwen Xu, Michael D. Wong, Tanvi Wagle, Srinivas Narayana 等SIGCOMM 2021 · 被引用 30 次
- VEP: A Two-stage Verification Toolchain for Full eBPF ProgrammabilityXiwei Wu, Yueyang Feng, Tianyi Huang, Xiaoyang Lu 等NSDI 2025 · 被引用 8 次
- Approximation Enforced Execution of Untrusted Linux Kernel ExtensionsHao Sun, Zhendong SuUSENIX Security 2025
- BeeBox: Hardening BPF against Transient Execution AttacksDi Jin, Alexander J. Gaidis, Vasileios P. KemerlisUSENIX Security 2024 · 被引用 10 次
