Skip to content

Rewrite virtio-net IO to be more efficient #530

Draft
mtjhrc wants to merge 18 commits intocontainers:mainfrom
mtjhrc:vectored-io-net
Draft

Rewrite virtio-net IO to be more efficient #530
mtjhrc wants to merge 18 commits intocontainers:mainfrom
mtjhrc:vectored-io-net

Conversation

@mtjhrc
Copy link
Collaborator

@mtjhrc mtjhrc commented Feb 4, 2026

This PR

  • introduces new abstractions for dealing with virtio queues (RxQueueProducer, TxQueueConsumer) in an efficient manner
  • rewrite all 3 virtio-net device backends to use the abstractions (copy straight from guest memory into the backend, no intermediary buffer)
  • new integration tests for virtio-net over tap, passt, gvproxy

TODO:

  • more code cleanup
  • at least some basic benchmark data (e.g. iperf)
  • more manual testing besides the simple integration smoke tests

Adresses: #385, #405
supersedes: #493

@mtjhrc mtjhrc force-pushed the vectored-io-net branch 2 times, most recently from 5220656 to db2af02 Compare February 6, 2026 13:43
@mtjhrc mtjhrc force-pushed the vectored-io-net branch 4 times, most recently from bccf5ac to 3e444c0 Compare February 16, 2026 18:33
mtjhrc and others added 13 commits February 16, 2026 19:34
Signed-off-by: Matej Hrica <mhrica@redhat.com>
Use correct platform-specific library directory (lib vs lib64) and
library path env variable (DYLD_LIBRARY_PATH vs LD_LIBRARY_PATH).

Signed-off-by: Matej Hrica <mhrica@redhat.com>
Signed-off-by: Matej Hrica <mhrica@redhat.com>
Signed-off-by: Matej Hrica <mhrica@redhat.com>
Make TcpTester::run_server also leak the file descriptor for the stream socket.
Closing the fd caused the tests to fail on macOS (they randomly worked on Linux
I suppose).

Signed-off-by: Matej Hrica <mhrica@redhat.com>
Explicitly specify a /tmp directory, this fixes an issue on macOS where the
default tmp path that gets used could be very long, causing unix domain socket
tests to fail due to path length.

Signed-off-by: Matej Hrica <mhrica@redhat.com>
This flag should be used to indicate to libkrun that downstream network
backend wants to receive and transmit the virtio-net header along with
Ethernet frames.

Network backends using this flag can then forward unmodified headers to
another VM or build a sensible virtio_net_hdr (e.g. with GSO fields
correctly set) such that receiving VM handles GSO'd frames properly.

Signed-off-by: Albin Kerouanton <albin.kerouanton@docker.com>
Signed-off-by: Matej Hrica <mhrica@redhat.com>
Signed-off-by: Matej Hrica <mhrica@redhat.com>
Signed-off-by: Matej Hrica <mhrica@redhat.com>
Introduce TxQueueConsumer and RxQueueProducer utilities, which allow consuming
virtio queues as a bunch of iovec vectors. Notably these utilities are different
than the preexisiting descriptor_utilis. The Reader and Writer in descriptor
utilis operate on the order of single descriptor chains and don't allow the
multiple descriptor chains to be processed at once due to borrowing issues,
wheras these the TxQueueConsumer/RxQueueProducer operate on the order of all
descriptors of all descriptor chains at once allowing for batch processing of
the whole queue at once.

Signed-off-by: Matej Hrica <mhrica@redhat.com>
Rewrite the all of the backend (unixstream, unixgram, tap) in terms of the new
RxQueueProducer/TxQueueConsumer abstractions.

Signed-off-by: Matej Hrica <mhrica@redhat.com>
Signed-off-by: Matej Hrica <mhrica@redhat.com>
Restore accidentally deleted guest-agent crate.

Signed-off-by: Matej Hrica <mhrica@redhat.com>
Signed-off-by: Matej Hrica <mhrica@redhat.com>
Signed-off-by: Matej Hrica <mhrica@redhat.com>
Signed-off-by: Matej Hrica <mhrica@redhat.com>
Signed-off-by: Matej Hrica <mhrica@redhat.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants