#138 add a verifier-budget tool that reports processed instructions per BPF program - #139
Open
matthewdevenny wants to merge 1 commit into
Open
matthewdevenny wants to merge 1 commit into
matthewdevenny wants to merge 1 commit into
Conversation
…er BPF program scripts/ci/verifierbudget loads every program of the three collections on the running kernel with verifier statistics enabled and prints the processed-instruction count against the 1M limit, per program, loading each in isolation so one over-budget program cannot hide the rest. It sets pidns_ino the way steps.Start does, since at the zero default the namespace walk is dead code and step_fork would be under-counted. A markdown table is appended to $GITHUB_STEP_SUMMARY when set; the exit status is non-zero if any program fails to load, so it can gate CI. The number is kernel-specific — cg_origin_egress is 657,658 on the 6.17 Azure kernel and rejected at 1,000,001 on Blacksmith's 6.6 — which is why this needs to run on every kernel we support, not only CI's. `make verifier-budget` runs it locally. Signed-off-by: Matthew DeVenny <matt@codecargo.com>
There was a problem hiding this comment.
🟡 Changes recommended
The new command currently has compile-time API/type errors, and the Make target has phony and environment-propagation issues.
Get a fresh assessment by requesting another Copilot review.
Pull request overview
Adds a Linux tool to measure verifier instruction usage for all CargoWall BPF programs and report results locally or in GitHub Actions.
Changes:
- Loads each BPF program independently with verifier statistics enabled.
- Parses processed-instruction counts and writes console/step-summary tables.
- Adds a
make verifier-budgettarget.
File summaries
| File | Description |
|---|---|
scripts/ci/verifierbudget/main.go |
Implements verifier-budget measurement and reporting. |
Makefile |
Adds the local measurement target. |
Review details
Suppressed comments (1)
scripts/ci/verifierbudget/main.go:180
- On Linux, unix.Utsname.Release is an int8 array, whereas unix.ByteSliceToString accepts a byte slice, so this call does not type-check. Convert the null-terminated int8 values before returning the release string, as pkg/ebpf/detect.go does for syscall.Utsname.
return unix.ByteSliceToString(u.Release[:])
- Files reviewed: 2/2 changed files
- Comments generated: 3
- Review effort level: Lite
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| r.err = err | ||
| var verr *ebpf.VerifierError | ||
| if errors.As(err, &verr) { | ||
| r.insns = parseProcessed(strings.Join(verr.Log, "\n")) |
| @printf "${GREEN}Running BPF tests (requires root)...${RESET}\n" | ||
| sudo go test -v -count=1 ./bpf/ ./pkg/tc/ ./pkg/network/ ./pkg/steps/ ./pkg/origin/ | ||
|
|
||
| verifier-budget: |
|
|
||
| verifier-budget: | ||
| @printf "${GREEN}Measuring BPF verifier budget on $$(uname -r) (requires root)...${RESET}\n" | ||
| sudo go run ./scripts/ci/verifierbudget |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
First step of #138: a tool that measures how many instructions the verifier processes for each cargowall BPF program on the running kernel, so the number can be tracked on every kernel we claim to support instead of only CI's.
LogLevelStats, parsesprocessed N insns(or the rejection'sProcessed N insn), prints a table and appends it to$GITHUB_STEP_SUMMARY. Non-zero exit if any program fails to load.pidns_inolikesteps.Startdoes; at the zero default the namespace walk is pruned as dead code andstep_fork/step_task_iterwould be under-counted.make verifier-budgetruns it locally under sudo.On the Lima VM (6.17.0-1022-azure, CI's kernel):
cg_origin_egresstc_egressstep_forkstep_task_iterA workflow in madhokie-io/dockcmd runs this on a Blacksmith
blacksmith-2vcpu-ubuntu-2404runner (kernel 6.6) to get the failing number; that job can become the old-kernel gate once the tool is onmain.🤖 Generated with Claude Code