From: Ed W <lists@wildgooses.com>
To: netfilter-devel@vger.kernel.org
Subject: Re: Performance issue due to constant "modprobes"
Date: Fri, 08 Apr 2011 18:11:22 +0100 [thread overview]
Message-ID: <4D9F41BA.1060509@wildgooses.com> (raw)
In-Reply-To: <BANLkTinfSAk0ruyqNcfAgReATbX_OV64EA@mail.gmail.com>
On 08/04/2011 01:47, Maciej Żenczykowski wrote:
>> Does someone have any ideas on how I can finesse these constant (and
>> expensive in my case) modprobes each time we run the iptables command?
>
> Could you try with an iptables built from iptables git master branch?
> I believe a recent change I submitted (delayed initialization of
> target/matches to prevent module autoloading) may actually fix your
> problem.
Thanks - very helpful!
It was easiest for me to patch my iptables with just your commit and my
results are very promising:
Starting "shorewall"
- using busybox modprobe + released iptables = several minutes...
- module-init-tools + released iptables = 12s
- module-init-tools + your commit = 7.7s
- module-init-tools + patching out modprobe completely = 4.9s
So, whilst your patch has a huge positive benefit, I'm still seeing a
substantial amount of cpu going to useless modprobing.
I don't see an immediate solution, *unless* there is some way to ask the
kernel if some module is already compiled in? I don't immediately see
that this is possible and google didn't turn anything up? I guess the
various xtables modules could export something that allows them to be
detected as loaded, but I sense that this is unlikely to be an
acceptable patch unless others have shown that there is a performance
problem?
Of the rest of my 4.9s, 97% of that is waiting for iptables and tc to do
stuff. I need to profile further to see where the delays are though
Thanks for your commit above - extremely helpful - grateful if you might
consider whether there is some way to avoid any modprobes at all? (Note
that the -M option appears not to work in iptables at present?)
Thanks
Ed W
--
To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
next prev parent reply other threads:[~2011-04-08 17:11 UTC|newest]
Thread overview: 33+ messages / expand[flat|nested] mbox.gz Atom feed top
2011-04-07 23:16 Performance issue due to constant "modprobes" Ed W
2011-04-08 0:18 ` Jan Engelhardt
2011-04-08 17:11 ` Ed W
2011-04-08 0:47 ` Maciej Żenczykowski
2011-04-08 17:11 ` Ed W [this message]
2011-04-08 19:54 ` Jan Engelhardt
2011-04-08 23:22 ` Ed W
2011-04-08 23:42 ` Jan Engelhardt
2011-04-09 20:39 ` Ed W
2011-04-09 22:30 ` Jan Engelhardt
2011-04-12 21:03 ` Ed W
2011-04-12 22:05 ` Jan Engelhardt
2011-04-13 11:08 ` Ed W
2011-04-13 12:06 ` Jan Engelhardt
2011-04-13 9:10 ` Maciej Żenczykowski
2011-04-13 11:35 ` Ed W
2011-04-13 12:13 ` Jan Engelhardt
2011-04-13 12:35 ` Ed W
2011-04-13 12:45 ` Jan Engelhardt
2011-04-13 16:45 ` Ed W
2011-04-13 19:20 ` Mr Dash Four
2011-04-14 7:07 ` Maciej Żenczykowski
2011-04-14 7:13 ` Maciej Żenczykowski
2011-04-14 7:19 ` Jan Engelhardt
2011-04-18 13:38 ` Patrick McHardy
2011-04-18 16:33 ` Ed W
2011-04-19 1:12 ` Maciej Żenczykowski
2011-04-19 9:03 ` Maciej Żenczykowski
2011-04-19 16:10 ` Ed W
2011-04-20 1:26 ` Maciej Żenczykowski
2011-04-20 6:41 ` Maciej Żenczykowski
2011-04-20 7:31 ` Jozsef Kadlecsik
2011-04-20 8:54 ` Ed W
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=4D9F41BA.1060509@wildgooses.com \
--to=lists@wildgooses.com \
--cc=netfilter-devel@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).