Skip to content

netlink List implementation - #38

Merged
k8s-ci-robot merged 5 commits into
kubernetes-sigs:masterfrom
aojea:netlink
May 20, 2026
Merged

k8s-ci-robot merged 5 commits into
kubernetes-sigs:masterfrom
aojea:netlink

Conversation

@aojea

@aojea aojea commented Feb 24, 2026 •

Copy link
Copy Markdown
Contributor

Implement List() method using netlink directly to avoid the overhead of
calling the nft user space progam and parsing its output. Also, reducing
the exposure to bugs or problems caused by skew versions of the binary
when running inside containers.

@aojea
aojea requested a review from danwinship February 24, 2026 18:31
@k8s-ci-robot k8s-ci-robot added do-not-merge/work-in-progress Indicates that a PR should not merge because it is a work in progress. size/XXL Denotes a PR that changes 1000+ lines, ignoring generated files. cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. labels Feb 24, 2026
@aojea
aojea force-pushed the netlink branch 2 times, most recently from fcd74dc to 93119c2 Compare February 25, 2026 08:42
Comment thread nftables.go
@aojea
aojea force-pushed the netlink branch 2 times, most recently from 5dd8893 to f66b4f6 Compare February 25, 2026 11:26
@aojea aojea changed the title [WIP] netlink List implementation netlink List implementation Feb 25, 2026
@k8s-ci-robot k8s-ci-robot removed the do-not-merge/work-in-progress Indicates that a PR should not merge because it is a work in progress. label Feb 25, 2026
@danwinship

Copy link
Copy Markdown
Collaborator

To get further improvements, we would need to reduce pointers, and
change knftables.Rule to use values instead of pointers for Handle, Index, etc.
This would save millions of allocations at scale but is a breaking change.

In general if you are listing large numbers of rules, you're probably doing something wrong anyway, in terms of good nftables architecture. (kube-proxy never calls ListRules. Calico does, and I haven't looked into exactly what they're doing, but I suspect it's mostly because they were trying to make the nftables backend work roughly the same way as the iptables backend.)

We could optimize the Handle allocation without breaking API by allocating a single []int along with the []*Rule and allocating all of the handles out of that. (Though you'd want to fix the code to pre-allocate those arrays to the right length first in that case to avoid blocking GC of every intermediate version of the handle array.)

This would be less memory-efficient than the current system in the case where someone lists a lot of rules and then keeps a handle to just one of them, but again, "probably doing something wrong anyway".

(Despite what the comment says, neither the old nor the new code sets Index from ListRules)

Comment thread netlink.go Outdated
Comment thread netlink.go Outdated
Comment thread netlink.go Outdated
Comment thread netlink.go Outdated
Comment thread netlink.go Outdated
Comment thread netlink.go Outdated
Comment thread netlink.go
Comment thread netlink.go Outdated
Comment thread netlink.go Outdated
Comment thread nftables.go Outdated
Comment thread netlink.go Outdated
@k8s-ci-robot k8s-ci-robot added the needs-rebase Indicates a PR cannot be merged because it has merge conflicts with HEAD. label Mar 4, 2026
@aojea
aojea force-pushed the netlink branch 4 times, most recently from 87ac32d to 45d427b Compare March 6, 2026 09:07
@k8s-ci-robot k8s-ci-robot removed the needs-rebase Indicates a PR cannot be merged because it has merge conflicts with HEAD. label Mar 6, 2026
@aojea
aojea force-pushed the netlink branch 3 times, most recently from 41f4670 to 94c2b8e Compare March 6, 2026 15:15
@aojea

aojea commented Mar 17, 2026

Copy link
Copy Markdown
Contributor Author

@danwinship what do we want to do with this? do we wait?

@danwinship

Copy link
Copy Markdown
Collaborator

I think we should backport the --terse fix to 1.35 and 1.34, and then work on netlink List() support (and maybe more) for 1.37.

@aojea

aojea commented Mar 17, 2026

Copy link
Copy Markdown
Contributor Author

I see you already tagged itv0.0.21 with the terse fix

Comment thread hack/test-integration.sh Outdated
Comment thread hack/test-integration.sh Outdated
Comment thread netlink.go Outdated
Comment thread netlink.go Outdated
Comment thread netlink.go
Comment thread netlink.go Outdated
Comment thread netlink.go Outdated
Comment thread nftables.go
Comment thread netlink.go Outdated
aojea added 3 commits May 18, 2026 10:54
Implement List() and ListAll() methods using netlink  to avoid the overhead of
calling the nft user space progam and parsing its output. Also, reducing
the exposure to bugs or problems caused by skew versions of the binary
when running inside containers.

hack/benchmark.sh
Running benchmarks in a new network namespace...
goos: linux
goarch: amd64
pkg: sigs.k8s.io/knftables
cpu: Intel(R) Xeon(R) CPU @ 2.60GHz
BenchmarkListChains_NFT_10-48           	     470	   2478369 ns/op	   66330 B/op	     355 allocs/op
BenchmarkListChains_NFT_100-48          	     387	   3078343 ns/op	  194767 B/op	    2528 allocs/op
BenchmarkListChains_NFT_1000-48         	     132	   9170438 ns/op	 1426811 B/op	   24140 allocs/op
BenchmarkListChains_NFT_10000-48        	      15	  72816515 ns/op	13834120 B/op	  240164 allocs/op
BenchmarkListChains_Netlink_10-48       	   15865	     70282 ns/op	   23651 B/op	     185 allocs/op
BenchmarkListChains_Netlink_100-48      	    6636	    171288 ns/op	   84800 B/op	    1059 allocs/op
BenchmarkListChains_Netlink_1000-48     	    1080	   1139143 ns/op	  747940 B/op	    9727 allocs/op
BenchmarkListChains_Netlink_10000-48    	      60	  22861672 ns/op	 8053831 B/op	   96576 allocs/op
PASS
ok  	sigs.k8s.io/knftables	14.964s
@aojea

aojea commented May 18, 2026

Copy link
Copy Markdown
Contributor Author

@danwinship finally get to it, addressed your comments and bumped dependencies, there is some work needed to fix the jobs with the golang update

on: [pull_request]
name: Test
env:
GO_VERSION: 1.25.x

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

should we be doing the .go-version thing like other repos?

@danwinship

Copy link
Copy Markdown
Collaborator

/lgtm
/approve

we can do .go-version later if we want

@k8s-ci-robot k8s-ci-robot added the lgtm "Looks good to me", indicates that a PR is ready to be merged. label May 20, 2026
@k8s-ci-robot

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: aojea, danwinship

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@k8s-ci-robot k8s-ci-robot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label May 20, 2026
@k8s-ci-robot
k8s-ci-robot merged commit f2c1170 into kubernetes-sigs:master May 20, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. lgtm "Looks good to me", indicates that a PR is ready to be merged. size/XXL Denotes a PR that changes 1000+ lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants