netfilter-devel.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* [PATCH v3 nf-next 0/3] netfilter: x_tables: pack percpu counter allocations
@ 2016-11-22 13:44 Florian Westphal
  2016-11-22 13:44 ` [PATCH v3 nf-next 1/3] netfilter: x_tables: pass xt_counters struct instead of packet counter Florian Westphal
                   ` (3 more replies)
  0 siblings, 4 replies; 5+ messages in thread
From: Florian Westphal @ 2016-11-22 13:44 UTC (permalink / raw)
  To: netfilter-devel

... to speed up iptables(-restore) calls.

Especially a pattern like

for i in $(seq 1 1000) ; iptables -A FORWARD ;done

is expensive, because adding the rule doubles the percpu counters (allocate
		2nd blob, then free old one, including its percpu counters).
This causes frequent expansion and shrinking of percpu memory pool.

This change batches calls to the allocator by packing multiple counters
in 4k memory chunks.

Heavily based on suggestions from Eric Dumazet.

The only change in v3 is in patch #2 which assigned garbage on UP
(was fixed by next patch, but better to not do it in first place).

^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2016-12-04 20:10 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2016-11-22 13:44 [PATCH v3 nf-next 0/3] netfilter: x_tables: pack percpu counter allocations Florian Westphal
2016-11-22 13:44 ` [PATCH v3 nf-next 1/3] netfilter: x_tables: pass xt_counters struct instead of packet counter Florian Westphal
2016-11-22 13:44 ` [PATCH v3 nf-next 2/3] netfilter: x_tables: pass xt_counters struct to counter allocator Florian Westphal
2016-11-22 13:44 ` [PATCH v3 nf-next 3/3] netfilter: x_tables: pack percpu counter allocations Florian Westphal
2016-12-04 20:09 ` [PATCH v3 nf-next 0/3] " Pablo Neira Ayuso

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).