New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Modularize ipcache BPF listener #29194
Modularize ipcache BPF listener #29194
Conversation
/test |
ad19eae
to
7c663f3
Compare
They are leftovers from 84901e4 ("bpf, ipcache: unconditionally assume LPM trie delete/dump support") and not used anymore. Hence, let's just drop them as a preparatory step to convert the listener into a cell. Signed-off-by: Marco Iorio <marco.iorio@isovalent.com>
Break the daemon dependency, as a preparation for the subsequent conversion of the listener into a cell. Signed-off-by: Marco Iorio <marco.iorio@isovalent.com>
Crafting a dedicated unit test revealed that this logic was broken, because we considered an entry for deletion if and only if it the given prefix was not found in the ipcache struct, and the source of the corresponding identity was either kvstore or local. But when the prefix is not found, we retrieve the default value of the identity type, which will never match the source filter. Now, considering that: * the ipcache map gets recreated from scratch at every agent restart, * the garbage collection logic was triggered only when either Cilium was configured in kvstore mode or was connected to at least one remote cluster, * the etcd watcher already implements a dedicated logic to replay possibly missed deletion events both after relist and in case of complete reconnection, * fixing this logic would likely expose us to even more headaches, given that we may remove entries when the ipcache is not yet fully synchronized from the other sources, causing the removal of valid entries and the disruption of existing connections, let's just remove it. Signed-off-by: Marco Iorio <marco.iorio@isovalent.com>
Following the removal of the only non-empty implementation of OnIPIdentityCacheGC, let's simplify the IPIdentityMappingListener interface by dropping it altogether. Let's also remove the ForEachListener ipcache method, which is no longer used. Signed-off-by: Marco Iorio <marco.iorio@isovalent.com>
This makes explicit which methods are actually used and allows swapping implementations, e.g., for mocking purposes. Signed-off-by: Marco Iorio <marco.iorio@isovalent.com>
Convert the ipcache bpf listener into a cell, to increase modularity and remove its initialization from the main daemon start-up logic. The main difference being that now we register it into the ipcache module using AddListener, instead of SetListeners. While this doesn't cause any differences at the moment (given that we are anticipating the initialization and the ipcache is still empty at that point), it prevents possible future ordering issues if any other invoke function also calls AddListener, as SetListeners would blindly override any registered listener. Signed-off-by: Marco Iorio <marco.iorio@isovalent.com>
7c663f3
to
92dc5bc
Compare
Rebased onto main, let's see if that makes CI happier. |
/test |
@brb @jrajahalme Ping |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The WG changes LGTM, thanks.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Nice to review PRs that mostly remove dead code :-)
Convert the ipcache BPF listener module into a cell. Additionally drop the existing ipcache map garbage collection logic, which turned out to be buggy and not really effective, as well as not necessary. Please review commit by commit, and refer to the individual commit messages for additional details.
Related: #28004