Skip to content

Rewrite virtio-net IO to be more efficient #530

Draft
mtjhrc wants to merge 14 commits intocontainers:mainfrom
mtjhrc:vectored-io-net
Draft

Rewrite virtio-net IO to be more efficient #530
mtjhrc wants to merge 14 commits intocontainers:mainfrom
mtjhrc:vectored-io-net

Conversation

@mtjhrc
Copy link
Collaborator

@mtjhrc mtjhrc commented Feb 4, 2026

This PR

  • introduces new abstractions for dealing with virtio queues (RxQueueProducer, TxQueueConsumer) in an efficient manner
  • rewrite all 3 virtio-net device backends to use the abstractions (copy straight from guest memory into the backend, no intermediary buffer)
  • new integration tests for virtio-net over tap, passt, gvproxy

TODO:

  • more code cleanup
  • at least some basic benchmark data (e.g. iperf)
  • more manual testing besides the simple integration smoke tests

Adresses: #385, #405
supersedes: #493

mtjhrc and others added 14 commits February 3, 2026 17:26
Signed-off-by: Matej Hrica <mhrica@redhat.com>
Use correct platform-specific library directory (lib vs lib64) and
library path env variable (DYLD_LIBRARY_PATH vs LD_LIBRARY_PATH).

Signed-off-by: Matej Hrica <mhrica@redhat.com>
Signed-off-by: Matej Hrica <mhrica@redhat.com>
Signed-off-by: Matej Hrica <mhrica@redhat.com>
Signed-off-by: Matej Hrica <mhrica@redhat.com>
Introduce a function to query at runtime whether a specific feature
was enabled at build time. This allows applications to check for
optional capabilities before attempting to use them.

Signed-off-by: Matej Hrica <mhrica@redhat.com>
Signed-off-by: Matej Hrica <mhrica@redhat.com>
On macOS, the test runner binary needs to be signed with
com.apple.security.hypervisor entitlement to use the Hypervisor
framework for running VMs.

Signed-off-by: Matej Hrica <mhrica@redhat.com>
This flag should be used to indicate to libkrun that downstream network
backend wants to receive and transmit the virtio-net header along with
Ethernet frames.

Network backends using this flag can then forward unmodified headers to
another VM or build a sensible virtio_net_hdr (e.g. with GSO fields
correctly set) such that receiving VM handles GSO'd frames properly.

Signed-off-by: Albin Kerouanton <albin.kerouanton@docker.com>
Signed-off-by: Matej Hrica <mhrica@redhat.com>
Signed-off-by: Matej Hrica <mhrica@redhat.com>
Signed-off-by: Matej Hrica <mhrica@redhat.com>
Introduce TxQueueConsumer and RxQueueProducer utilities, which allow consuming
virtio queues as a bunch of iovec vectors. Notably these utilities are different
than the preexisiting descriptor_utilis. The Reader and Writer in descriptor
utilis operate on the order of single descriptor chains and don't allow the
multiple descriptor chains to be processed at once due to borrowing issues,
wheras these the TxQueueConsumer/RxQueueProducer operate on the order of all
descriptors of all descriptor chains at once allowing for batch processing of
the whole queue at once.

Signed-off-by: Matej Hrica <mhrica@redhat.com>
Rewrite the all of the backend (unixstream, unixgram, tap) in terms of the new
RxQueueProducer/TxQueueConsumer abstractions.

Signed-off-by: Matej Hrica <mhrica@redhat.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants