IP Library Granted Patent US 12,360,798
Granted Patent B2
US 12,360,798 · App. 18/745,825 · Granted Jul 15, 2025

Offloading packet processing programs from virtual machines to a hypervisor and efficiently executing the offloaded packet processing programs

Inventors: Bo Chen (Beijing, CN); Songtao Zheng (Beijing, CN); Shu Wu (Beijing, CN); Bingqing Shao (Beijing, CN); Yi Liao (Beijing, CN); Danqi Sun (Beijing, CN)
Assignee: VMware LLC
G06F9/45558G06F2009/45595
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,360,798
App. No.
18/745,825
Granted
Jul 15, 2025
Kind
B2
Abstract

In one set of embodiments, a hypervisor of a host system can receive a packet processing program from a virtual network interface controller (NIC) driver of a virtual machine (VM) running on the hypervisor. The hypervisor can then attach the packet processing program to a first execution point in a physical NIC driver of the hypervisor and to a second execution point in a virtual NIC backend of the hypervisor, where the virtual NIC backend corresponds to a virtual NIC of the VM that originated the packet processing program.

Claims (49)

1. A host system comprising:

a processor;

a storage medium comprising instructions executable by the processor; and

a network interface card (NIC), the NIC being configured to receive an ingress packet and extract a destination address from the ingress packet;

wherein the processor is configured to execute the instructions to:

instantiate a hypervisor running a virtual machine (VM), the VM comprising a virtual NIC driver, the hypervisor comprising a physical NIC driver associated with the NIC;

configure a packet processing program from the virtual NIC driver;

attach the packet processing program to a first execution point in the physical NIC driver;

attach the packet processing program to a second execution point in a virtual NIC backend of the hypervisor; and

select between the first execution point and the second execution point;

wherein the physical NIC driver is configured to:

determine whether the destination address is associated with the packet processing program or any other packet processing program attached to the first execution point, and

execute the packet processing program against the ingress network packet and to allocate hypervisor networking stack metadata for the ingress network packet.

2. The host system of claim 1 , wherein the virtual NIC backend corresponds to the virtual NIC driver originated from the packet processing program.

3. The host system of claim 1 , wherein the packet processing program is expressed in a bytecode.

4. The host system of claim 1 , wherein the packet processing program is verified and compiled by the hypervisor prior to being attached to the first and second execution points.

5. The host system of claim 1 , wherein the virtual NIC backend is configured to receive a network packet from a networking stack of the hypervisor, the network packet including hypervisor networking stack metadata, and to determine whether the hypervisor networking stack metadata includes an indication that the packet processing program was previously executed against the network packet at the first execution point.

6. The host system of claim 5 , wherein if the hypervisor networking stack metadata does not include the indication, the virtual NIC backend is configured to execute the packet processing program against the network packet.

7. A method comprising:

instantiating a hypervisor running a virtual machine (VM), the VM comprising a virtual network interface card (NIC) driver, the hypervisor comprising a physical NIC driver associated with the NIC;

configuring a packet processing program from the virtual NIC driver;

receiving an ingress packet by a physical;

extracting a destination address from the ingress packet;

attaching the packet processing program to a first execution point in the physical NIC driver;

attaching the packet processing program to a second execution point in a virtual NIC backend of the hypervisor; and

selecting between the first execution point and the second execution point based at least on the destination address

wherein the physical NIC driver is configured to:

determine whether the destination address is associated with the packet processing program or any other packet processing program attached to the first execution point, and

execute the packet processing program against the ingress network packet and to allocate hypervisor networking stack metadata for the ingress network packet.

8. The method of claim 7 , further comprising executing the packet processing program against the ingress network packet by the physical NIC driver.

9. The method of claim 8 , further comprising allocating hypervisor networking stack metadata for the ingress network packet.

10. The method of claim 9 , further comprising including an indication in the hypervisor networking stack metadata that the packet processing program has been executed against the ingress network packet.

11. The method of claim 7 , further comprising determining, by the physical NIC driver, whether the ingress network packet was received by a physical NIC in a hardware RX queue that is mapped to a packet processing program-attached virtual NIC backend, the hardware RX queue being associated with an RX filter that causes the physical NIC to automatically place all ingress traffic destined for the packet processing program-attached virtual NIC backend into the hardware RX queue.

12. A method comprising:

instantiating a hypervisor running a virtual machine (VM), the VM comprising a virtual network interface card (NIC) driver, the hypervisor comprising a physical NIC driver associated with the NIC;

configuring a packet processing program from the virtual NIC driver;

receiving a network packet from a networking stack of the hypervisor, the network packet including hypervisor networking stack metadata;

attaching the packet processing program to a first execution point in the physical NIC driver;

attaching the packet processing program to a second execution point in a virtual NIC backend of the hypervisor; and

selecting between the first execution point and the second execution point based at least on the hypervisor networking stack metadata;

wherein the physical NIC driver is configured to:

determine whether the destination address is associated with the packet processing program or any other packet processing program attached to the first execution point, and

execute the packet processing program against the ingress network packet and to allocate hypervisor networking stack metadata for the ingress network packet.

13. The method of claim 12 , further comprising determining whether the hypervisor networking stack metadata includes an indication that the packet processing program was previously executed against the network packet at the first execution point.

14. The method of claim 13 , further comprising if the hypervisor networking stack metadata does not include the indication, executing, by the virtual NIC backend, the packet processing program against the network packet.

15. The method of claim 12 , wherein the first execution point is located in a receive path (RX) of the physical NIC driver that receives and handles ingress network packets.

16. The method of claim 12 , wherein the packet processing program is expressed in a bytecode.

17. The method of claim 12 , wherein the packet processing program is verified and compiled by the hypervisor prior to being attached to the first and second execution points.

18. The method of claim 12 , wherein the hypervisor is configured to determine an optimal execution point for the packet processing program between the physical NIC driver and the virtual NIC backend.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 3, 2024
From: CHEN, BO; ZHENG, SONGTAO; WU, SHU; SHAO, BINGQING; LIAO, YI; SUN, DANQI
To: VMWARE, INC.
Reel/Frame 067902/0950 →
CHANGE OF NAME Recorded Jul 3, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 068119/0850 →
Continuity (2)
Continuation 16971243
Related Publication 20240338240A1 · Oct 10, 2024
References Cited (32)
US 8149709B2 · Srinivasan · 2012 [cited by examiner]
US 8930690B2 · Zuo · 2015 [cited by examiner]
US 9703589B2 · Zheng · 2017 [cited by applicant]
US 10164911B2 · Lakshmanan · 2018 [cited by applicant]
US 10581636B1 · Skorodumov · 2020 [cited by applicant]
US 10592380B2 · Borello · 2020 [cited by examiner]
US 10616099B2 · Tsirkin · 2020 [cited by applicant]
US 10623372B2 · Wang · 2020 [cited by examiner]
US 10657095B2 · Srivastava · 2020 [cited by applicant]
US 10795717B2 · Paul · 2020 [cited by applicant]
US 10904167B2 · Tsirkin · 2021 [cited by examiner]
US 10965601B2 · Jiang · 2021 [cited by examiner]
US 11283699B2 · Chen · 2022 [cited by applicant]
US 11336756B2 · Waskiewicz, Jr. · 2022 [cited by examiner]
US 12014197B2 · Chen · 2024 [cited by examiner]
US 20050111454A1 · Narjala · 2005 [cited by examiner]
US 20100257269A1 · Clark · 2010 [cited by applicant]
US 20120005521A1 · Droux · 2012 [cited by applicant]
US 20130254766A1 · Zuo · 2013 [cited by applicant]
US 20150058847A1 · Zheng · 2015 [cited by applicant]
US 20160253192A1 · Singaravelu · 2016 [cited by applicant]
US 20180217858A1 · Moolenaar · 2018 [cited by applicant]
US 20190068491A1 · Tsirkin · 2019 [cited by applicant]
US 20190109714A1 · Clark · 2019 [cited by applicant]
US 20190173841A1 · Wang · 2019 [cited by applicant]
US 20200028785A1 · Ang · 2020 [cited by applicant]
US 20200344182A1 · Tsirkin · 2020 [cited by applicant]
US 20210064443A1 · Tsirkin · 2021 [cited by applicant]
US 20210152642A1 · Ilan · 2021 [cited by applicant]
Jorgensen et al.; “The express Data Path: Fast Programmable Packet Processing in the Operating System Kernel”; ACM ISBN 978-1-4503-6080-7/18/12; https://doi.org/10.1145/3281411.3281443; (Jorgensen_2018.pdf; pp. 54-66) (… [cited by examiner]
Vieira, et al., “Fast Packet Processing with eBPF and XDP: Concepts, Code, Challenges, and Applications” ACM Computing Surveys, vol. 53, No. 1, Article 16. Publication date: Feb. 2020; (Vieira_2020.pdf; pp. 1-36) (Year:… [cited by applicant]
Hohlfeld, et al., “Demystifying the Performance of XDP BPF” 2019 IEEE Conference on Network Softwarization (Hohlfeld_2019.pdf; pp. 208-212) (Year: 2019). [cited by applicant]