netfilter-devel.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
From: Ed W <lists@wildgooses.com>
To: netfilter-devel@vger.kernel.org
Subject: Re: Performance issue due to constant "modprobes"
Date: Fri, 08 Apr 2011 18:11:22 +0100	[thread overview]
Message-ID: <4D9F41BA.1060509@wildgooses.com> (raw)
In-Reply-To: <BANLkTinfSAk0ruyqNcfAgReATbX_OV64EA@mail.gmail.com>

On 08/04/2011 01:47, Maciej Żenczykowski wrote:
>> Does someone have any ideas on how I can finesse these constant (and
>> expensive in my case) modprobes each time we run the iptables command?
> 
> Could you try with an iptables built from iptables git master branch?
> I believe a recent change I submitted (delayed initialization of
> target/matches to prevent module autoloading) may actually fix your
> problem.

Thanks - very helpful!

It was easiest for me to patch my iptables with just your commit and my
results are very promising:

Starting "shorewall"
- using busybox modprobe + released iptables = several minutes...
- module-init-tools + released iptables = 12s
- module-init-tools + your commit = 7.7s
- module-init-tools + patching out modprobe completely = 4.9s

So, whilst your patch has a huge positive benefit, I'm still seeing a
substantial amount of cpu going to useless modprobing.

I don't see an immediate solution, *unless* there is some way to ask the
kernel if some module is already compiled in? I don't immediately see
that this is possible and google didn't turn anything up? I guess the
various xtables modules could export something that allows them to be
detected as loaded, but I sense that this is unlikely to be an
acceptable patch unless others have shown that there is a performance
problem?

Of the rest of my 4.9s, 97% of that is waiting for iptables and tc to do
stuff.  I need to profile further to see where the delays are though

Thanks for your commit above - extremely helpful - grateful if you might
consider whether there is some way to avoid any modprobes at all? (Note
that the -M option appears not to work in iptables at present?)

Thanks

Ed W


--
To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html

  reply	other threads:[~2011-04-08 17:11 UTC|newest]

Thread overview: 33+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2011-04-07 23:16 Performance issue due to constant "modprobes" Ed W
2011-04-08  0:18 ` Jan Engelhardt
2011-04-08 17:11   ` Ed W
2011-04-08  0:47 ` Maciej Żenczykowski
2011-04-08 17:11   ` Ed W [this message]
2011-04-08 19:54     ` Jan Engelhardt
2011-04-08 23:22       ` Ed W
2011-04-08 23:42         ` Jan Engelhardt
2011-04-09 20:39           ` Ed W
2011-04-09 22:30             ` Jan Engelhardt
2011-04-12 21:03               ` Ed W
2011-04-12 22:05                 ` Jan Engelhardt
2011-04-13 11:08                   ` Ed W
2011-04-13 12:06                     ` Jan Engelhardt
2011-04-13  9:10               ` Maciej Żenczykowski
2011-04-13 11:35                 ` Ed W
2011-04-13 12:13                   ` Jan Engelhardt
2011-04-13 12:35                     ` Ed W
2011-04-13 12:45                       ` Jan Engelhardt
2011-04-13 16:45                         ` Ed W
2011-04-13 19:20                           ` Mr Dash Four
2011-04-14  7:07                           ` Maciej Żenczykowski
2011-04-14  7:13                             ` Maciej Żenczykowski
2011-04-14  7:19                               ` Jan Engelhardt
2011-04-18 13:38                                 ` Patrick McHardy
2011-04-18 16:33                               ` Ed W
2011-04-19  1:12                                 ` Maciej Żenczykowski
2011-04-19  9:03                                   ` Maciej Żenczykowski
2011-04-19 16:10                                     ` Ed W
2011-04-20  1:26                                       ` Maciej Żenczykowski
2011-04-20  6:41                                         ` Maciej Żenczykowski
2011-04-20  7:31                                           ` Jozsef Kadlecsik
2011-04-20  8:54                                             ` Ed W

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=4D9F41BA.1060509@wildgooses.com \
    --to=lists@wildgooses.com \
    --cc=netfilter-devel@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).