[HN Gopher] How to escape the Linux networking stack
       ___________________________________________________________________
        
       How to escape the Linux networking stack
        
       Author : meysamazad
       Score  : 76 points
       Date   : 2025-11-17 15:49 UTC (7 hours ago)
        
 (HTM) web link (blog.cloudflare.com)
 (TXT) w3m dump (blog.cloudflare.com)
        
       | seabrookmx wrote:
       | I had to read their article on "soft-unicast" before I could
       | really grok this one: https://blog.cloudflare.com/cloudflare-
       | servers-dont-own-ips-...
        
       | lazyeye wrote:
       | SLATFATF - "So long and thanks for all the fish" is a Douglas
       | Adams quote
       | 
       | https://en.wikipedia.org/wiki/So_Long,_and_Thanks_for_All_th...
        
         | cestith wrote:
         | A few things in the article are Douglas Adams quotes, and more
         | specifically from the Hitchhiker's Guide series.
         | 
         | Creating the universe being regarded as a mistake and making
         | many unhappy is from those books. Whenever someone figures out
         | the universe it gets replaced with something stranger and
         | having evidence that's happened repeatedly is too. The
         | Restaurant at the End of the Universe is reference in the
         | article.
         | 
         | I'm a bit surprised nothing in the article was mentioned as
         | being "mostly harmless".
        
       | notepad0x90 wrote:
       | I'm slightly surprised cloudflare isn't using a userspace tcp/ip
       | stack already (faster - less context switches and copies). It's
       | the type of company I'd expect to actually need one.
        
         | Droobfest wrote:
         | From 2016: https://blog.cloudflare.com/why-we-use-the-linux-
         | kernels-tcp...
        
           | notepad0x90 wrote:
           | Nice, they know better. But it also makes me wonder, because
           | they're saying "but what if you need to run another app", I'd
           | expect for things like loadbalancers for example, you'd only
           | run one app per server on the data plane, the user space
           | stack handles that, and the OS/services use a different
           | control plane NIC with the kernel stack so that boxes are
           | reachable even if there is link saturation, ddos,etc..
           | 
           | It also makes me wonder, why is tcp/ip special? The kernel
           | should expose a raw network device. I get physical or layer 2
           | configuration happening in the kernel, but if it is supposed
           | to do IP, then why stop there, why not TLS as well? Why run a
           | complex network protocol stack in the kernel when you can
           | just expose a configured layer 2 device to a user space
           | process? It sounds like "that's just the way it's always been
           | done" type of a scenario.
        
             | wmf wrote:
             | AFAIK Cloudflare runs their whole stack on every machine. I
             | guess that gives them flexibility and maybe better load
             | balancing. They also seem to use only one NIC.
             | 
             |  _why is tcp /ip special? The kernel should expose a raw
             | network device. ... Why run a complex network protocol
             | stack in the kernel when you can just expose a configured
             | layer 2 device to a user space process?_
             | 
             | Check out the MIT Exokernel project and Solarflare
             | OpenOnload that used this approach. It never really caught
             | on because the old school way is good enough for almost
             | everyone.
             | 
             |  _why stop there, why not TLS as well?_
             | 
             | kTLS is a thing now (mostly used by Netflix). Back in the
             | day we also had kernel-mode Web servers to save every
             | cycle.
        
             | rcxdude wrote:
             | You can do that if you want, but I think part of why tcp/ip
             | is a useful layer of abstraction is it allows more robust
             | boundaries between applications that may be running on the
             | same machine. If you're just at layer 2 you are basically
             | acting in behalf of the whole box.
        
         | nomel wrote:
         | > faster - less context switches and copies
         | 
         | Aren't neither required these days with the "async" like and
         | zero-copy interfaces that are now available (like io_uring,
         | where it's still handled by the kernel), along with the nearly
         | non-existence of single core processors in modern times?
        
       | alecco wrote:
       | Being a networking company I always wondered why did they pick
       | Linux over FreeBSD.
        
       ___________________________________________________________________
       (page generated 2025-11-17 23:00 UTC)