Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 14 May 2010 09:32:08 -0400
From:      Alexander Sack <pisymbol@gmail.com>
To:        Andrew Gallatin <gallatin@cs.duke.edu>
Cc:        Murat Balaban <murat@enderunix.org>, freebsd-net@freebsd.org, freebsd-performance@freebsd.org
Subject:   Re: Intel 10Gb
Message-ID:  <AANLkTikROvNKUmpax-CbhEyj5o7TW0hfV_x79Bm_nU2V@mail.gmail.com>
In-Reply-To: <20100511135103.GA29403@grapeape2.cs.duke.edu>
References:  <AANLkTimMrsM08Rmdr-l6RFu83VkqFw0Pk2sHxpV5Yl5x@mail.gmail.com> <4BE52856.3000601@unsane.co.uk> <1273323582.3304.31.camel@efe> <20100511135103.GA29403@grapeape2.cs.duke.edu>

next in thread | previous in thread | raw e-mail | index | archive | help
On Tue, May 11, 2010 at 9:51 AM, Andrew Gallatin <gallatin@cs.duke.edu> wro=
te:
> Murat Balaban [murat@enderunix.org] wrote:
>>
>> Much of the FreeBSD networking stack has been made parallel in order to
>> cope with high packet rates at 10 Gig/sec operation.
>>
>> I've seen good numbers (near 10 Gig) in my tests involving TCP/UDP
>> send/receive. (latest Intel driver).
>>
>> As far as BPF is concerned, above statement does not hold true,
>> since there is some work that needs to be done here in terms
>> of BPF locking and parallelism. My tests show that there
>> is a high lock contention around "bpf interface lock", resulting
>> in input errors at high packet rates and with many bpf devices.
>
> If you're interested in 10GbE packet sniffing at line rate on the
> cheap, have a look at the Myri10GE "sniffer" interface. =A0This is a
> special software package that takes a normal mxge(4) NIC, and replaces
> the driver/firmware with a "myri_snf" driver/firmware which is
> optimized for packet sniffing.
>
> Using this driver/firmware combo, we can receive minimal packets at
> line rate (14.8Mpps) to userspace. =A0You can even access this using a
> libpcap interface. =A0The trick is that the fast paths are OS-bypass,
> and don't suffer from OS overheads, like lock contention. =A0See
> http://www.myri.com/scs/SNF/doc/index.html for details.

But your timestamps will be atrocious at 10G speeds.  Myricom doesn't
timestamp packets AFAIK.  If you want reliable timestamps you need to
look at companies like Endace, Napatech, etc.

We do a lot of packet capture and work on bpf(4) all the time.  My
biggest concern for reliable 10G packet capture is timestamps.  The
call to microtime up in catchpacket() is not going to cut it (it
barely cuts it for GIGE line rate speeds).

I'd be interested in doing the multi-queue bpf(4) myself (perhaps I
should ask? I don't know if non-summer-of-code folks are allowed?).
I believe the goal is not so much throughput but cache affinity.  It
would be nice if say the listener application (libpcap) could bind
itself to the same core that the driver's queue is receiving packets
on so everything from catching to post-processing all work with a very
warm cache (theoretically).  I think that's the idea.

It would also allow multiple applications to subscribe to potentially
different queues that are doing some form of load balancing.  Again,
Intel's 82599 chipset supports flow based queues (albeit the size of
the flow table is limited).

Note, zero-copy bpf(4) is your friend in all use cases at 10G speeds!  :)

-aps

PS I am not sure but Intel also supports writing packets directly in
cache (yet I thought the 82599 driver actually does a prefetch anyway
which had me confused on why that helps)



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?AANLkTikROvNKUmpax-CbhEyj5o7TW0hfV_x79Bm_nU2V>