Hi,

This series is a reworked version of my earlier RFC exploring how ovpn
can preserve GSO and GRO batching across its data path. Since sending
the RFC, I spent more time profiling the paths on different systems and
refining the implementation. The result is a smaller series with some
additional optimizations and a fresh set of measurements.

On transmit, it lets GSO skbs reach ovpn, completes each inner packet's
checksum during software segmentation and, when the layout permits,
encrypts the resulting packets directly into a UDP GSO aggregate.
Ordinary packets and frag-list GSO children retain the existing in-place
encryption path. Packet IDs for a UDP GSO batch are reserved as a single
range instead of one segment at a time.

On receive, ovpn uses UDP GRO to collect compatible DATA_V2 records in a
frag-list, then detaches and authenticates each record independently.
Small transmit and receive prefetch changes use the resulting lookahead
to overlap memory access with encryption and decryption.

On two directly connected 100-Gbit/s mlx5 ports, five interleaved iperf3
-t 60 -O 10 single-flow AES-128-GCM runs in each direction raised mean
throughput from 12.053 to 24.166 Gbit/s forward and from 10.992 to
23.558 Gbit/s reverse. Individual patch messages contain the
intermediate measurements and test details.

Thanks,

Ralf Lici
Mandelbit Srl

---
Changes since RFC v4 
https://lore.kernel.org/openvpn-devel/[email protected]/
- Drop the opt-in direct GRO mode and the generic GRO ownership change
  it required. The series now retains the complete outer receive stack.
- Preserve safe page-backed payload fragments during GSO segmentation
  and map them directly into the AEAD source scatterlist.
- Reserve one consecutive packet-ID range for each UDP GSO batch instead
  of updating the counter once per segment.
- Extend transmit prefetch to the first payload fragment of segments
  encrypted into a UDP GSO aggregate.
- Refresh the GSO, GRO and prefetch measurements using two directly
  connected 100-Gbit/s mlx5 ports.

Ralf Lici (8):
  ovpn: advertise checksum offload for GSO packets
  ovpn: accept frag-list GSO input
  ovpn: refactor AEAD encryption helpers
  ovpn: convert GSO input into UDP GSO output
  ovpn: reserve packet-ID ranges for UDP GSO batches
  ovpn: coalesce UDP data records with GRO
  ovpn: prefetch encrypted records before GRO batch decryption
  ovpn: prefetch GSO segments before encryption

 drivers/net/ovpn/crypto_aead.c | 171 +++++++++++++----
 drivers/net/ovpn/crypto_aead.h |   4 +
 drivers/net/ovpn/io.c          | 339 ++++++++++++++++++++++++++++++---
 drivers/net/ovpn/io.h          |  18 +-
 drivers/net/ovpn/main.c        |   5 +-
 drivers/net/ovpn/pktid.h       |  48 +++++
 drivers/net/ovpn/proto.h       |   4 +
 drivers/net/ovpn/skb.h         |  27 ++-
 drivers/net/ovpn/stats.h       |  16 +-
 drivers/net/ovpn/tcp.c         |   4 +-
 drivers/net/ovpn/udp.c         | 258 ++++++++++++++++++++++++-
 net/core/gro.c                 |   1 +
 net/ipv4/udp_offload.c         |   3 +-
 13 files changed, 810 insertions(+), 88 deletions(-)


base-commit: b8e9e7d82e7eefd5d2d528469d94ec20e96b38c3
-- 
2.55.0


_______________________________________________
Openvpn-devel mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/openvpn-devel

Reply via email to