Repository navigation
Conversation
Linux accepts writes to /dev/net/tun larger than the interface MTU [1]. gVisor rejects them and copies accepted writes into Go heap storage. Removing that limit would let applications request large heap allocations, whose failures cannot be returned to the writer as syscall errors. MemoryFile, the sentry's file-backed allocator, can report allocation failure. Using it for packet data requires buffers to retain its storage while packets are queued or cloned, even after the TUN file is closed. The buffer package previously supported only Go heap storage. Allow views to take ownership of external storage and release it with the last chunk reference. Preserve that shared ownership across checkpoints and retain copy-on-write semantics. This provides the buffer support for a separate change to TUN's allocation and write-limit handling. [1]: https://github.com/torvalds/linux/blob/830b3c68c/drivers/net/tun.c#L1735 Assisted-by: OpenAI Codex
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Linux accepts writes to /dev/net/tun larger than the interface MTU 1.
gVisor rejects them and copies accepted writes into Go heap storage.
Removing that limit would let applications request large heap
allocations, whose failures cannot be returned to the writer as syscall
errors.
MemoryFile, the sentry's file-backed allocator, can report allocation
failure. Using it for packet data requires buffers to retain its storage
while packets are queued or cloned, even after the TUN file is closed.
The buffer package previously supported only Go heap storage.
Allow views to take ownership of external storage and release it with
the last chunk reference. Preserve that shared ownership across
checkpoints and retain copy-on-write semantics. This provides the buffer
support for a separate change to TUN's allocation and write-limit
handling.
Assisted-by: OpenAI Codex