Skip to content

#138 add a verifier-budget tool that reports processed instructions per BPF program - #139

Open
matthewdevenny wants to merge 1 commit into
mainfrom
matt/verifier-budget
Open

matthewdevenny wants to merge 1 commit into
mainfrom
matt/verifier-budget

Conversation

@matthewdevenny

Copy link
Copy Markdown
Contributor

First step of #138: a tool that measures how many instructions the verifier processes for each cargowall BPF program on the running kernel, so the number can be tracked on every kernel we claim to support instead of only CI's.

  • Loads each program of the three collections in isolation with LogLevelStats, parses processed N insns (or the rejection's Processed N insn), prints a table and appends it to $GITHUB_STEP_SUMMARY. Non-zero exit if any program fails to load.
  • Sets pidns_ino like steps.Start does; at the zero default the namespace walk is pruned as dead code and step_fork / step_task_iter would be under-counted.
  • make verifier-budget runs it locally under sudo.

On the Lima VM (6.17.0-1022-azure, CI's kernel):

Program Processed % of limit
cg_origin_egress 657,658 65.8%
tc_egress 5,546 0.6%
step_fork 1,220 0.1%
step_task_iter 1,095 0.1%
everything else < 60 —

A workflow in madhokie-io/dockcmd runs this on a Blacksmith blacksmith-2vcpu-ubuntu-2404 runner (kernel 6.6) to get the failing number; that job can become the old-kernel gate once the tool is on main.

🤖 Generated with Claude Code

…er BPF program

scripts/ci/verifierbudget loads every program of the three collections on
the running kernel with verifier statistics enabled and prints the
processed-instruction count against the 1M limit, per program, loading
each in isolation so one over-budget program cannot hide the rest. It
sets pidns_ino the way steps.Start does, since at the zero default the
namespace walk is dead code and step_fork would be under-counted. A
markdown table is appended to $GITHUB_STEP_SUMMARY when set; the exit
status is non-zero if any program fails to load, so it can gate CI.

The number is kernel-specific — cg_origin_egress is 657,658 on the
6.17 Azure kernel and rejected at 1,000,001 on Blacksmith's 6.6 — which
is why this needs to run on every kernel we support, not only CI's.
`make verifier-budget` runs it locally.

Signed-off-by: Matthew DeVenny <matt@codecargo.com>

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The new command currently has compile-time API/type errors, and the Make target has phony and environment-propagation issues.

Get a fresh assessment by requesting another Copilot review.

Pull request overview

Adds a Linux tool to measure verifier instruction usage for all CargoWall BPF programs and report results locally or in GitHub Actions.

Changes:

  • Loads each BPF program independently with verifier statistics enabled.
  • Parses processed-instruction counts and writes console/step-summary tables.
  • Adds a make verifier-budget target.
File summaries
File Description
scripts/ci/verifierbudget/main.go Implements verifier-budget measurement and reporting.
Makefile Adds the local measurement target.
Review details

Suppressed comments (1)

scripts/ci/verifierbudget/main.go:180

  • On Linux, unix.Utsname.Release is an int8 array, whereas unix.ByteSliceToString accepts a byte slice, so this call does not type-check. Convert the null-terminated int8 values before returning the release string, as pkg/ebpf/detect.go does for syscall.Utsname.
	return unix.ByteSliceToString(u.Release[:])
  • Files reviewed: 2/2 changed files
  • Comments generated: 3
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

r.err = err
var verr *ebpf.VerifierError
if errors.As(err, &verr) {
r.insns = parseProcessed(strings.Join(verr.Log, "\n"))
Comment thread Makefile
@printf "${GREEN}Running BPF tests (requires root)...${RESET}\n"
sudo go test -v -count=1 ./bpf/ ./pkg/tc/ ./pkg/network/ ./pkg/steps/ ./pkg/origin/

verifier-budget:
Comment thread Makefile

verifier-budget:
@printf "${GREEN}Measuring BPF verifier budget on $$(uname -r) (requires root)...${RESET}\n"
sudo go run ./scripts/ci/verifierbudget
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants