| Message ID | cover.1789746543.git.ralf@mandelbit.com |
|---|---|
| Headers |
Return-Path: <openvpn-devel-bounces@lists.sourceforge.net>
Delivered-To: patchwork@openvpn.net
Received: by 2002:a05:7000:6446:b0:8a0:ea1f:253a with SMTP id n6csp8968840mag;
Fri, 18 Sep 2026 09:04:28 -0700 (PDT)
X-Forwarded-Encrypted: i=2;
AKwUvBz6+U4ZKXiphK/7yInQ8upotLAtjwJWxiPppN+krhr/0xeKRIGirDuRsX2AcltNb2E1PAaf7bbnmzw=@openvpn.net
X-Received: by 2002:a05:6808:1383:b0:490:315d:e0d5 with SMTP id
5614622812f47-4ccf6a75030mr3577421b6e.16.1789747467961;
Fri, 18 Sep 2026 09:04:27 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1789747467; cv=none;
d=google.com; s=arc-20260327;
b=NgGcwQ6t6tbeAs9hlLxuEVH7C9aakbw4XfV/+9RP1SIc7kPkVj7SaUBF7Gjr5NAorA
3X3A1nlPZxxlBNVrxwz9aWHTkc+Zba6+ve/qjrf6d+QzKD0NcB/1xynL+tw9sshm4DGA
qcTG1vpIyJ+IW0hw8m21kOvs92kzFYW/uS5fNMc5JkgJI9Z8pxIjr6OxuYGrWaG77EH2
DTpUK614pajoC0Bfa7bl69j+xck0X1M7Ybq4TYX0ztLd5wwo/BWqM+qI8omVTNwY6j+y
vCrgssixvYRLQZFuECkUSyuSUtY/eh95w5FPUWBCctm+7i8De6BBmGoG5p3nGUWVYNVP
R9Jg==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com;
s=arc-20260327;
h=errors-to:content-transfer-encoding:list-subscribe:list-help
:list-post:list-archive:list-unsubscribe:list-id:precedence:subject
:mime-version:message-id:date:to:from:dkim-signature:dkim-signature
:dkim-signature:dkim-signature;
bh=Rq910n7i8iaoEMUvRumBUHwIyYvAvIPFE//liwM1y18=;
fh=4NbAC/LsuMLI0S0hprUlLSLCiHwg6SCAifhH718Jh0Q=;
b=CUiXzdQ/TIKJaNBA3ICI3gKORK+2RfIl4m/GzZDvI6SW5rWMThfbHhDE8EjXdcaOc5
fg2zkl9O8lqHK8BtH8tHw0XMD2cbErJ8T/KIgpm4WuX1GyI+Mk1GISwdaJ8TdH8irH5J
L85AeW/cbFqAldHo5b7k9LmnEgO2xpYocAaDocoxsPB0hy2BAgDO87UrvXOGAGTPRMEE
7R6j9QxAqP5ieyysvDlE5hLI0XibQjwzqaZImwsJDfWIAMJjhAndquiRU46ZSHRwtV0N
wPItHLefaBuq7JIDK37PIPyC1mXXP+djpxaB5gEtOr1aM0S5VUAe6d/57im9NSIgPIrg
vGPw==;
dara=google.com
ARC-Authentication-Results: i=1; mx.google.com;
dkim=pass header.i=@lists.sourceforge.net header.s=beta
header.b="Uolntg/t";
dkim=neutral (body hash did not verify) header.i=@sourceforge.net
header.s=x header.b="WC9ocB/C";
dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x
header.b=k2M7N73t;
dkim=neutral (body hash did not verify) header.i=@mandelbit.com
header.s=MBO0001 header.b=qQDcfOKn;
spf=pass (google.com: domain of
openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as
permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net
Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7])
by mx.google.com with ESMTPS id
5614622812f47-4cd67456f68si3084133b6e.18.2026.09.18.09.04.27
(version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128);
Fri, 18 Sep 2026 09:04:27 -0700 (PDT)
Received-SPF: pass (google.com: domain of
openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as
permitted sender) client-ip=216.105.38.7;
Authentication-Results: mx.google.com;
dkim=pass header.i=@lists.sourceforge.net header.s=beta
header.b="Uolntg/t";
dkim=neutral (body hash did not verify) header.i=@sourceforge.net
header.s=x header.b="WC9ocB/C";
dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x
header.b=k2M7N73t;
dkim=neutral (body hash did not verify) header.i=@mandelbit.com
header.s=MBO0001 header.b=qQDcfOKn;
spf=pass (google.com: domain of
openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as
permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed;
d=lists.sourceforge.net; s=beta; h=Content-Transfer-Encoding:Content-Type:
List-Subscribe:List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id:
Subject:MIME-Version:Message-ID:Date:To:From:Sender:Reply-To:Cc:Content-ID:
Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc
:Resent-Message-ID:In-Reply-To:References:List-Owner;
bh=Rq910n7i8iaoEMUvRumBUHwIyYvAvIPFE//liwM1y18=; b=Uolntg/tONE3DSTK30YmUrJDzK
FYjnjHX8mU3ylhmfv0PnUFlGDwFgj81npMn5RWvhgRKj8VqyGU3wOfHMWl6lHhTtbm2qz20aiKVIm
OGVoxuUb4zoXfEFScrbLS/gv/LBfRFPy/OgT6N/o3MEIKmY8OcC68oQECdVm+BLriofk=;
Received: from [127.0.0.1] (helo=sfs-ml-1.v29.lw.sourceforge.com)
by sfs-ml-1.v29.lw.sourceforge.com with esmtp (Exim 4.95)
(envelope-from <openvpn-devel-bounces@lists.sourceforge.net>)
id 1x7b4a-0001NG-PN;
Fri, 18 Sep 2026 16:04:22 +0000
Received: from [172.30.29.66] (helo=mx.sourceforge.net)
by sfs-ml-1.v29.lw.sourceforge.com with esmtps (TLS1.2) tls
TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95)
(envelope-from <ralf@mandelbit.com>) id 1x7b4a-0001N9-2a
for openvpn-devel@lists.sourceforge.net;
Fri, 18 Sep 2026 16:04:21 +0000
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed;
d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:Message-ID:
Date:Subject:To:From:Sender:Reply-To:Cc:Content-Type:Content-ID:
Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc
:Resent-Message-ID:In-Reply-To:References:List-Id:List-Help:List-Unsubscribe:
List-Subscribe:List-Post:List-Owner:List-Archive;
bh=J+yScSW4ny0b6vJ0yzKcenAItF+fa+Z4lWggbUTy7Ks=; b=WC9ocB/C+zLOoaaO/WRoDWK5em
h1bpuOk1THN2sUo8PdXMB3s5dYDuwWtKqG0oQ6A743VrRAIx7y92vMaGf7/lpQx1PsCBdk4tOXG4S
6Wi+6kE85UyjhNk9H8bTpeuNwx4X25G9Li7lPRkb2G9OaMb+lvck+YwApvJ1x8R+ECqo=;
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x
;
h=Content-Transfer-Encoding:MIME-Version:Message-ID:Date:Subject:To:From:
Sender:Reply-To:Cc:Content-Type:Content-ID:Content-Description:Resent-Date:
Resent-From:Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:In-Reply-To:
References:List-Id:List-Help:List-Unsubscribe:List-Subscribe:List-Post:
List-Owner:List-Archive; bh=J+yScSW4ny0b6vJ0yzKcenAItF+fa+Z4lWggbUTy7Ks=; b=k
2M7N73t1OiP8bbs8MA43bTUYO2A5AdZVGCfpv08xokpaD3qJ7xYIoK+NIGPHiUecoylKi2hb6jRD9
xKaoNHh/X9DRBKAMqH4jANoH9vsymMONNpuP0AwX/I1B2SubUjPYXe+gV9+2xFXDQV8ixBt6Wp8mV
oIsfcoHs62W0QDRo=;
Received: from mout-b-210.mailbox.org ([195.10.208.40])
by sfi-mx-1.v28.lw.sourceforge.com with esmtps
(TLS1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.95)
id 1x7b4V-0006Sr-UU for openvpn-devel@lists.sourceforge.net;
Fri, 18 Sep 2026 16:04:21 +0000
Received: from smtp1.mailbox.org (smtp1.mailbox.org [10.196.197.1])
(using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)
key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest
SHA256)
(No client certificate requested)
by mout-b-210.mailbox.org (Postfix) with ESMTPS id 4hmcrC2T3SzFqqX
for <openvpn-devel@lists.sourceforge.net>;
Fri, 18 Sep 2026 18:04:11 +0200 (CEST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mandelbit.com;
s=MBO0001; t=1789747451;
h=from:from:reply-to:subject:subject:date:date:message-id:message-id:
to:to:cc:mime-version:mime-version:
content-transfer-encoding:content-transfer-encoding;
bh=J+yScSW4ny0b6vJ0yzKcenAItF+fa+Z4lWggbUTy7Ks=;
b=qQDcfOKnK+MsGfRlMhi/2rNs8K8cZ51DtV7Tm5QzfRYDuS79iZ7lIOq44kHhtz0K3jfTUC
R8q3Zn+Mr0afVIyT0CqymxO1DgG8d7lKKkQhdHbktZLVsyznXeyjqXlWL/CtmIRe+aem/6
spKFraZYjIaX7JYH2hoajVuLcP7ow+GeloQMAkJEzJ+AAb+/7/H1u4X2QCI8rnfPnQPWQq
Gn968kWiGGT1gLgmKsd9//9u2NslKBT4UbjWrwbNk1gLRv1tMlSK5fWCItgiLOfFrv+q+7
vuv7U1pIATJtxT6X/LAn4BPMNTuDT+YWsYyG5mjjKVFnjBokXODXnD3GA9NLnQ==
From: Ralf Lici <ralf@mandelbit.com>
To: openvpn-devel@lists.sourceforge.net
Date: Fri, 18 Sep 2026 18:03:34 +0200
Message-ID: <cover.1789746543.git.ralf@mandelbit.com>
MIME-Version: 1.0
X-Spam-Score: -0.2 (/)
X-Spam-Report: Spam detection software,
running on the system "sfi-spamd-2.hosts.colo.sdot.me",
has NOT identified this incoming email as spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
the administrator of that system for details.
Content preview: Hi, Currently ovpn holds peer and key-slot references while
packets are being processed and until asynchronous crypto completes. With
traffic for one peer spread across CPUs, the shared kref cachelines th [...]
Content analysis details: (-0.2 points, 5.0 required)
pts rule name description
---- ----------------------
--------------------------------------------------
-0.1 DKIM_VALID Message has at least one valid DKIM or DK signature
-0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from author's
domain
-0.1 DKIM_VALID_EF Message has a valid DKIM or DK signature from
envelope-from domain
0.1 DKIM_SIGNED Message has a DKIM or DK signature,
not necessarily valid
X-Headers-End: 1x7b4V-0006Sr-UU
Subject: [Openvpn-devel] [PATCH ovpn net-next v2 0/2] ovpn: reduce
reference-count contention
X-BeenThere: openvpn-devel@lists.sourceforge.net
X-Mailman-Version: 2.1.21
Precedence: list
List-Id: <openvpn-devel.lists.sourceforge.net>
List-Unsubscribe: <https://lists.sourceforge.net/lists/options/openvpn-devel>,
<mailto:openvpn-devel-request@lists.sourceforge.net?subject=unsubscribe>
List-Archive:
<http://sourceforge.net/mailarchive/forum.php?forum_name=openvpn-devel>
List-Post: <mailto:openvpn-devel@lists.sourceforge.net>
List-Help: <mailto:openvpn-devel-request@lists.sourceforge.net?subject=help>
List-Subscribe: <https://lists.sourceforge.net/lists/listinfo/openvpn-devel>,
<mailto:openvpn-devel-request@lists.sourceforge.net?subject=subscribe>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: openvpn-devel-bounces@lists.sourceforge.net
X-getmail-retrieved-from-mailbox: Inbox
X-GMAIL-THRID: 1876686241103133468
X-GMAIL-MSGID: 1876686241103133468
|
| Series |
ovpn: reduce reference-count contention
|
|
Message
Ralf Lici
Sept. 18, 2026, 4:03 p.m. UTC
Hi, Currently ovpn holds peer and key-slot references while packets are being processed and until asynchronous crypto completes. With traffic for one peer spread across CPUs, the shared kref cachelines therefore become contended even though both objects are normally long-lived. This series converts both references to percpu_ref while preserving their existing RCU-delayed destruction. The individual patch messages describe the memory cost and cache-to-cache measurements. The test used one peer, one AES-128-GCM key and 32 TCP streams on a 32-logical-CPU Ryzen 9 9950X with a ConnectX-5 hairpin. The encrypted RX flow used one source port and one receive queue, so only TX exercised CPU fan-out. perf c2c showed that each shared reference cacheline disappeared after its respective conversion. Thanks, Ralf Lici Mandelbit Srl --- Changes since v1 https://lore.kernel.org/openvpn-devel/cover.1789658051.git.ralf@mandelbit.com/ - In 1/2, distinguish reference acquisitions which extend existing peer ownership from RCU lookups which must reject dying peers. (Sashiko) - In 2/2, avoid a nested RCU callback during key-slot release which could outlive the ovpn workqueue during module unload. (Sashiko) Ralf Lici (2): ovpn: use percpu references for peers ovpn: use percpu references for key slots drivers/net/ovpn/crypto.c | 16 +++++++-------- drivers/net/ovpn/crypto.h | 27 ++++++++++++++++++++----- drivers/net/ovpn/crypto_aead.c | 17 ++++++++++++---- drivers/net/ovpn/io.c | 6 +----- drivers/net/ovpn/netlink.c | 6 +++--- drivers/net/ovpn/peer.c | 37 +++++++++++++++++++++------------- drivers/net/ovpn/peer.h | 37 ++++++++++++++++++++++++++++------ drivers/net/ovpn/tcp.c | 23 ++++++++++----------- 8 files changed, 112 insertions(+), 57 deletions(-) base-commit: b8e9e7d82e7eefd5d2d528469d94ec20e96b38c3