Filtering millions of packets per second on commodity NICs
blog.cloudflare.com
blog.cloudflare.com
https://blog.cloudflare.com/how-to-receive-a-million-packets...
https://blog.cloudflare.com/how-to-achieve-low-latency/
https://blog.cloudflare.com/kernel-bypass/
https://blog.cloudflare.com/single-rx-queue-kernel-bypass-wi...
I hope this gives a bit more context.
I really enjoy the effort you guys put into those detailed blog posts.
You might find this interesting:
https://youtu.be/UcAygzNSxlI?t=7980
https://indico.dns-oarc.net/event/21/contribution/5/material...
Clearly a useful contribution! The linked pull request looks like more of a finished product; I appreciate it even more when companies include the details of the sausage making.
In fact, even GPLv2 would not have imposed an obligation to publish changes here, only a super-strict GPLv3 would.
One data point of course, hardly warrant a far-reaching conclusion; still - that is something very nice to see.
Because if the only processing here is throw-away this still screams for a FPGA in front of the NIC. Someone mentioned higher R&D on a FPGA solution, but clearly there is massive R&D here in just making sure evil packets don't hit a slow code path.
[1] http://dpdk.org/doc/guides/prog_guide/lpm_lib.html#lpm-api-o...
Makes a huge difference for performance!
I'll blog about it on blog.pfsense.org in a few days when I return from Brazil.
http://blogs.cisco.com/performance/mpi-newbie-what-is-operat...
Processes do ioctl(), mmap() and poll() for I/O - all standard system calls implemented by the OS, there is no NIC-specific code in the application. NICs can be switched in and out of netmap mode without reloading modules (and with the cloudflare patch, even sharing the two modes). There are no custom memory pools or hugepages to reserve. Device configuration relies on ethtool and ifconfig etc.
This approach is what let the cloudflare folks implement their traffic steering with zero new code, just a couple of ethtool lines; the change they contributed back to support the split mode is completely agnostic of the specific NIC being used.
This causes huge traffic on RAM and trashes caches all along the way.
even if you could do away with copying e.g. packet_mmap (on linux), context switch will kill you...