War Story – The Mystery of the Very Long GC Pauses in .NET Windows Service
tooslowexception.com
tooslowexception.com
Anti Virus Scanners? At this point, all of them.
Servers, though. I get defense in depth and all that, but running antivirus seems like a step too far. Your servers should be locked down and only running well-tested software. Least permissions for all web processes, etc. Why risk slowing down or corrupting your server processes for a small increase in protection in an unlikely scenario?
We found it by attaching WinDbg and finding this dll on crashing threads’ call stack.
Disabled McAfee, problem solved.
We opened a ticket, they never fixed it while I worked on the project.
In the end we dumped Windows as a platform since customer IT would never sign off on deploying a server image without AV, and rewrote everything in Java, deploying using Linux containers, where IT has no power.
Cheaper, faster, less crashy.
I think I'm inclined to agree with him. The underlying problem isn't a symptom of something unique and crazy that one unique AV vendor is doing. It's a symptom of something standard (but crazy) that enterprise AV solutions do.
If monkey patching every process on the system at run-time is something you view as evil, then he's already named and shamed the entire antivirus software industry, and now you know to steer clear of antivirus. Which you were probably already doing, anyway, to the extent that IT lets you.
If you see it as an inevitable part of running AV, and view AV as essential, then there's not really anything to shame. It was an honest bug relating to an obscure corner case. I hope they've already filed a bug report, so just keep your AV up to date and it should get fixed.
I am not affiliated with AV software.
I work at a big accountancy firm as a software developer so IT is quite security minded, and while our ThinkPad T470p notebooks aren't top of the line, they should be at least faster than my Dell Latitude E6520 of 2012 which both have i7 CPU.
We run Symantec Endpoint Protection and this antimalware software is quite intrusive. I had an exception for a week to run with Symantec completely disabled, and never had a better working laptop. Still quite slow, but a good bit faster than usual.
Since the Spectre microcode updates performance has only been getting worse.
Needless to say, this resulted in an email from IT informing me of the unusual activity on my system, and when I told them it was deleting software that I was writing, they had to get approval from two levels of management that it was actually my job to be writing software and it should be allowed by SEP.
So did anyone figure out why the anti-virus was causing problems on a single box only and not the others?
> In fact, only completely uninstalling the antivirus was a proper fix – excluding only .NET assemblies was not enough.
Our enterprise databases store the data on high-performance SAN devices, and these are not slow. We moved from local spinning-rust drives to SAN SSDs, and our performance improved.
Better to configure the databse to allocate less than the available system memory and refuse writes when it's out of free memory.
Of course, due to Windows no-overcommit policy, it's better to have a large page file almost always. That ensures your RAM is going to be used efficiently and not as a simple backing store that's never actually referenced.
This is regime where GC languages simply can't coexist with aggressive swapping. You have to either disable swapping (somehow), or use something like a shared library doing something like the Linux mlockall for the runtime heap.
I believe there is something similar to mlockall you can do on windows to somewhat prevent swapping out the heap, but unfortunately I can't recall it right now.