From nobody Wed Jun 17 02:53:05 2026 Received: from unimail.uni-dortmund.de (mx1.hrz.uni-dortmund.de [129.217.128.51]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D9FF2439010; Tue, 28 Apr 2026 12:41:20 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=129.217.128.51 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1777380090; cv=none; b=M2E9XrpkFTiMzV8KC5T54mWGFww/qv+vNfF7FWmhq17vAwHPdR9z7WRiTpX831hwl3ChgUcEFAjVL+pDBo3WoQlWnfguJNF/eez0li5ciXQvf/ItWBpZjkBspQkC5tKknkXGy+w1J/thWAmYKG1JILn96SX1O7BPIPW9++DY9Hs= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1777380090; c=relaxed/simple; bh=igeIamDKNz2CqpiHk60+LMJNsVn1EVXKQJKILvvCnv0=; h=From:To:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=GuX0ZOKkjJZ796B7IU+em3OotNkZuI1NcxIpDqSw0eBVxUtXwUMHs2nn8+Wpic/LalYVoFA+sErt8vqUy1KoyvxG0iPSFiBPXiv8ch8pFGfXsh7XWma5KO36uZVOIg4N+5YHQhHD3jygovjgo9gzCc/DewgkOMkKbESEwJE4cZ0= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=tu-dortmund.de; spf=pass smtp.mailfrom=tu-dortmund.de; arc=none smtp.client-ip=129.217.128.51 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=tu-dortmund.de Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=tu-dortmund.de Received: from simon-Latitude-5450.cni.e-technik.tu-dortmund.de ([129.217.186.62]) (authenticated bits=0) by unimail.uni-dortmund.de (8.18.2/8.18.2) with ESMTPSA id 63SCewwg012433 (version=TLSv1.3 cipher=TLS_AES_256_GCM_SHA384 bits=256 verify=NOT); Tue, 28 Apr 2026 14:41:00 +0200 (CEST) From: Simon Schippers To: willemdebruijn.kernel@gmail.com, jasowang@redhat.com, andrew+netdev@lunn.ch, davem@davemloft.net, edumazet@google.com, kuba@kernel.org, pabeni@redhat.com, mst@redhat.com, eperezma@redhat.com, leiyang@redhat.com, stephen@networkplumber.org, jon@nutanix.com, tim.gebauer@tu-dortmund.de, simon.schippers@tu-dortmund.de, netdev@vger.kernel.org, linux-kernel@vger.kernel.org, kvm@vger.kernel.org, virtualization@lists.linux.dev Subject: [PATCH net-next v9 1/4] tun/tap: add ptr_ring consume helper with netdev queue wakeup Date: Tue, 28 Apr 2026 14:38:56 +0200 Message-ID: <20260428123859.19578-2-simon.schippers@tu-dortmund.de> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260428123859.19578-1-simon.schippers@tu-dortmund.de> References: <20260428123859.19578-1-simon.schippers@tu-dortmund.de> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Introduce tun_ring_consume() that wraps ptr_ring_consume() and calls __tun_wake_queue(). The latter wakes the stopped netdev subqueue once half of the ring capacity has been consumed, tracked via the new cons_cnt field in tun_file. When the ring is empty the queue is also woken to handle potential races. The point is to allow the queue to be stopped when it gets full, which is required for traffic shaping - implemented by the following "avoid ptr_ring tail-drop when a qdisc is present". Without the corresponding queue stopping, this patch alone causes no regression for a tap setup sending to a qemu VM: 1.136 Mpps to 1.141 Mpps. Details: AMD Ryzen 5 5600X at 4.3 GHz, 3200 MHz RAM, isolated QEMU threads, pktgen sender; Avg over 50 runs @ 100,000,000 packets; SRSO and spectre v2 mitigations disabled. Co-developed-by: Tim Gebauer Signed-off-by: Tim Gebauer Signed-off-by: Simon Schippers --- drivers/net/tun.c | 43 +++++++++++++++++++++++++++++++++++++++---- 1 file changed, 39 insertions(+), 4 deletions(-) diff --git a/drivers/net/tun.c b/drivers/net/tun.c index b183189f1853..e6ee2271732f 100644 --- a/drivers/net/tun.c +++ b/drivers/net/tun.c @@ -145,6 +145,7 @@ struct tun_file { struct list_head next; struct tun_struct *detached; struct ptr_ring tx_ring; + int cons_cnt; struct xdp_rxq_info xdp_rxq; }; =20 @@ -564,6 +565,7 @@ static void tun_queue_purge(struct tun_file *tfile) while ((ptr =3D ptr_ring_consume(&tfile->tx_ring)) !=3D NULL) tun_ptr_free(ptr); =20 + tfile->cons_cnt =3D 0; skb_queue_purge(&tfile->sk.sk_write_queue); skb_queue_purge(&tfile->sk.sk_error_queue); } @@ -730,6 +732,7 @@ static int tun_attach(struct tun_struct *tun, struct fi= le *file, goto out; } =20 + tfile->cons_cnt =3D 0; tfile->queue_index =3D tun->numqueues; tfile->socket.sk->sk_shutdown &=3D ~RCV_SHUTDOWN; =20 @@ -2115,13 +2118,42 @@ static ssize_t tun_put_user(struct tun_struct *tun, return total; } =20 -static void *tun_ring_recv(struct tun_file *tfile, int noblock, int *err) +/* Callers must hold ring.consumer_lock */ +static void __tun_wake_queue(struct tun_struct *tun, struct tun_file *tfil= e) +{ + if (__ptr_ring_empty(&tfile->tx_ring)) + goto wake; + + if (!__netif_subqueue_stopped(tun->dev, tfile->queue_index) || + ++tfile->cons_cnt < tfile->tx_ring.size / 2) + return; + +wake: + netif_wake_subqueue(tun->dev, tfile->queue_index); + tfile->cons_cnt =3D 0; +} + +static void *tun_ring_consume(struct tun_struct *tun, struct tun_file *tfi= le) +{ + void *ptr; + + spin_lock(&tfile->tx_ring.consumer_lock); + ptr =3D __ptr_ring_consume(&tfile->tx_ring); + if (ptr) + __tun_wake_queue(tun, tfile); + + spin_unlock(&tfile->tx_ring.consumer_lock); + return ptr; +} + +static void *tun_ring_recv(struct tun_struct *tun, struct tun_file *tfile, + int noblock, int *err) { DECLARE_WAITQUEUE(wait, current); void *ptr =3D NULL; int error =3D 0; =20 - ptr =3D ptr_ring_consume(&tfile->tx_ring); + ptr =3D tun_ring_consume(tun, tfile); if (ptr) goto out; if (noblock) { @@ -2133,7 +2165,7 @@ static void *tun_ring_recv(struct tun_file *tfile, in= t noblock, int *err) =20 while (1) { set_current_state(TASK_INTERRUPTIBLE); - ptr =3D ptr_ring_consume(&tfile->tx_ring); + ptr =3D tun_ring_consume(tun, tfile); if (ptr) break; if (signal_pending(current)) { @@ -2170,7 +2202,7 @@ static ssize_t tun_do_read(struct tun_struct *tun, st= ruct tun_file *tfile, =20 if (!ptr) { /* Read frames from ring */ - ptr =3D tun_ring_recv(tfile, noblock, &err); + ptr =3D tun_ring_recv(tun, tfile, noblock, &err); if (!ptr) return err; } @@ -3406,6 +3438,8 @@ static int tun_chr_open(struct inode *inode, struct f= ile * file) return -ENOMEM; } =20 + tfile->cons_cnt =3D 0; + mutex_init(&tfile->napi_mutex); RCU_INIT_POINTER(tfile->tun, NULL); tfile->flags =3D 0; @@ -3614,6 +3648,7 @@ static int tun_queue_resize(struct tun_struct *tun) for (i =3D 0; i < tun->numqueues; i++) { tfile =3D rtnl_dereference(tun->tfiles[i]); rings[i] =3D &tfile->tx_ring; + tfile->cons_cnt =3D 0; } list_for_each_entry(tfile, &tun->disabled, next) rings[i++] =3D &tfile->tx_ring; --=20 2.43.0 From nobody Wed Jun 17 02:53:05 2026 Received: from unimail.uni-dortmund.de (mx1.hrz.uni-dortmund.de [129.217.128.51]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 3A48143C065; Tue, 28 Apr 2026 12:41:17 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=129.217.128.51 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1777380089; cv=none; b=uerUCRVF22tq1p0//59U0L+8Tjf4KOivrEJe8OtdoJU1NuGg8+o/p+WBXxVRf/OAGANk+HvSPTyRxRJQM8WI/OhYhDu+ysD806rWE9Gh6pYXc8Wg2gKHJ6gwYuV1COOG6JzQSyD2mZ8Yw2y+079is8bNodjIBvxrX8GkLEhuZ7A= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1777380089; c=relaxed/simple; bh=wWwcAX52K+9LZxkXR5J5Jxga0UfSYQEUweUXrWXOpEU=; h=From:To:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=c5Ad1pOUkd2mphs4qNCQLZ6u/9J/DVEdZItcZx94xMocy7DNlrgDuUccChLmifISe+X4fZA1grPzwaYHGw6b2FrC/IVdLgrXkfDGJt1CmZbTO55KK0ESf74P3lQrqDr+sUZp+5Snf14xaFOzkKNRSd7H4jpYjJcDQRm82ky2os8= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=tu-dortmund.de; spf=pass smtp.mailfrom=tu-dortmund.de; arc=none smtp.client-ip=129.217.128.51 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=tu-dortmund.de Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=tu-dortmund.de Received: from simon-Latitude-5450.cni.e-technik.tu-dortmund.de ([129.217.186.62]) (authenticated bits=0) by unimail.uni-dortmund.de (8.18.2/8.18.2) with ESMTPSA id 63SCewwi012433 (version=TLSv1.3 cipher=TLS_AES_256_GCM_SHA384 bits=256 verify=NOT); Tue, 28 Apr 2026 14:41:00 +0200 (CEST) From: Simon Schippers To: willemdebruijn.kernel@gmail.com, jasowang@redhat.com, andrew+netdev@lunn.ch, davem@davemloft.net, edumazet@google.com, kuba@kernel.org, pabeni@redhat.com, mst@redhat.com, eperezma@redhat.com, leiyang@redhat.com, stephen@networkplumber.org, jon@nutanix.com, tim.gebauer@tu-dortmund.de, simon.schippers@tu-dortmund.de, netdev@vger.kernel.org, linux-kernel@vger.kernel.org, kvm@vger.kernel.org, virtualization@lists.linux.dev Subject: [PATCH net-next v9 2/4] vhost-net: wake queue of tun/tap after ptr_ring consume Date: Tue, 28 Apr 2026 14:38:57 +0200 Message-ID: <20260428123859.19578-3-simon.schippers@tu-dortmund.de> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260428123859.19578-1-simon.schippers@tu-dortmund.de> References: <20260428123859.19578-1-simon.schippers@tu-dortmund.de> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Add tun_wake_queue() to tun.c and export it for use by vhost-net. The function validates that the file belongs to a tun/tap device, dereferences the tun_struct under RCU, and delegates to __tun_wake_queue(). vhost_net_buf_produce() now calls tun_wake_queue() after a successful batched consume of the ring to allow the netdev subqueue to be woken up. The point is to allow the queue to be stopped when it gets full, which is required for traffic shaping - implemented by the following "avoid ptr_ring tail-drop when a qdisc is present". Without the corresponding queue stopping, this patch alone causes no throughput regression for a tap+vhost-net setup sending to a qemu VM: 3.858 Mpps to 3.898 Mpps. Details: AMD Ryzen 5 5600X at 4.3 GHz, 3200 MHz RAM, isolated QEMU threads, XDP drop program active in VM, pktgen sender; Avg over 50 runs @ 100,000,000 packets. SRSO and spectre v2 mitigations disabled. Co-developed-by: Tim Gebauer Signed-off-by: Tim Gebauer Signed-off-by: Simon Schippers --- drivers/net/tun.c | 22 ++++++++++++++++++++++ drivers/vhost/net.c | 21 +++++++++++++++------ include/linux/if_tun.h | 3 +++ 3 files changed, 40 insertions(+), 6 deletions(-) diff --git a/drivers/net/tun.c b/drivers/net/tun.c index e6ee2271732f..efe809597622 100644 --- a/drivers/net/tun.c +++ b/drivers/net/tun.c @@ -3765,6 +3765,28 @@ struct ptr_ring *tun_get_tx_ring(struct file *file) } EXPORT_SYMBOL_GPL(tun_get_tx_ring); =20 +/* Callers must hold ring.consumer_lock */ +void tun_wake_queue(struct file *file) +{ + struct tun_file *tfile; + struct tun_struct *tun; + + if (file->f_op !=3D &tun_fops) + return; + tfile =3D file->private_data; + if (!tfile) + return; + + rcu_read_lock(); + + tun =3D rcu_dereference(tfile->tun); + if (tun) + __tun_wake_queue(tun, tfile); + + rcu_read_unlock(); +} +EXPORT_SYMBOL_GPL(tun_wake_queue); + module_init(tun_init); module_exit(tun_cleanup); MODULE_DESCRIPTION(DRV_DESCRIPTION); diff --git a/drivers/vhost/net.c b/drivers/vhost/net.c index 80965181920c..7fba518ac3cd 100644 --- a/drivers/vhost/net.c +++ b/drivers/vhost/net.c @@ -176,13 +176,21 @@ static void *vhost_net_buf_consume(struct vhost_net_b= uf *rxq) return ret; } =20 -static int vhost_net_buf_produce(struct vhost_net_virtqueue *nvq) +static int vhost_net_buf_produce(struct sock *sk, + struct vhost_net_virtqueue *nvq) { + struct file *file =3D sk->sk_socket->file; struct vhost_net_buf *rxq =3D &nvq->rxq; =20 rxq->head =3D 0; - rxq->tail =3D ptr_ring_consume_batched(nvq->rx_ring, rxq->queue, - VHOST_NET_BATCH); + spin_lock(&nvq->rx_ring->consumer_lock); + rxq->tail =3D __ptr_ring_consume_batched(nvq->rx_ring, rxq->queue, + VHOST_NET_BATCH); + + if (rxq->tail) + tun_wake_queue(file); + + spin_unlock(&nvq->rx_ring->consumer_lock); return rxq->tail; } =20 @@ -209,14 +217,15 @@ static int vhost_net_buf_peek_len(void *ptr) return __skb_array_len_with_tag(ptr); } =20 -static int vhost_net_buf_peek(struct vhost_net_virtqueue *nvq) +static int vhost_net_buf_peek(struct sock *sk, + struct vhost_net_virtqueue *nvq) { struct vhost_net_buf *rxq =3D &nvq->rxq; =20 if (!vhost_net_buf_is_empty(rxq)) goto out; =20 - if (!vhost_net_buf_produce(nvq)) + if (!vhost_net_buf_produce(sk, nvq)) return 0; =20 out: @@ -995,7 +1004,7 @@ static int peek_head_len(struct vhost_net_virtqueue *r= vq, struct sock *sk) unsigned long flags; =20 if (rvq->rx_ring) - return vhost_net_buf_peek(rvq); + return vhost_net_buf_peek(sk, rvq); =20 spin_lock_irqsave(&sk->sk_receive_queue.lock, flags); head =3D skb_peek(&sk->sk_receive_queue); diff --git a/include/linux/if_tun.h b/include/linux/if_tun.h index 80166eb62f41..ab3b4ebca059 100644 --- a/include/linux/if_tun.h +++ b/include/linux/if_tun.h @@ -22,6 +22,7 @@ struct tun_msg_ctl { #if defined(CONFIG_TUN) || defined(CONFIG_TUN_MODULE) struct socket *tun_get_socket(struct file *); struct ptr_ring *tun_get_tx_ring(struct file *file); +void tun_wake_queue(struct file *file); =20 static inline bool tun_is_xdp_frame(void *ptr) { @@ -55,6 +56,8 @@ static inline struct ptr_ring *tun_get_tx_ring(struct fil= e *f) return ERR_PTR(-EINVAL); } =20 +static inline void tun_wake_queue(struct file *f) {} + static inline bool tun_is_xdp_frame(void *ptr) { return false; --=20 2.43.0 From nobody Wed Jun 17 02:53:05 2026 Received: from unimail.uni-dortmund.de (mx1.hrz.uni-dortmund.de [129.217.128.51]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 891C142B72D; Tue, 28 Apr 2026 12:41:20 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=129.217.128.51 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1777380089; cv=none; b=Li7ljSp3S7HQjRdcolRJekawwuWe3GN2KVkuWmwSwmO3TVVmtCYL8jcC+mvWqRszeAKfmj3KSDcUPAtO9RZlzO8mOK5t0owQas/6EI6XNSpx5ATExMl9hPSWTuRx04TPY7svo37DpuwqAwehdQGKwvSYeLGIovgvKXGjyN5iTh4= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1777380089; c=relaxed/simple; bh=9JqgIkM2EaQpzfx516UaEyGa6SvLHt/t3FChNoNlB4M=; h=From:To:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=MkQV+1/KxYj74RT6X5eTRKSTZXJ5cD+N+Er0aw8a9putznWKTCxMzuJIt6dQgfCAEpUCId67YrEw62OKdPl6H1BIJgCBKTLwJlipJD5pPgFJ3Fpa1fnlUdtt5cT7mhg6xf0FqjxzCT1MpYwnUSncYdrMc2roQ3fi9jX02faXJSc= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=tu-dortmund.de; spf=pass smtp.mailfrom=tu-dortmund.de; arc=none smtp.client-ip=129.217.128.51 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=tu-dortmund.de Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=tu-dortmund.de Received: from simon-Latitude-5450.cni.e-technik.tu-dortmund.de ([129.217.186.62]) (authenticated bits=0) by unimail.uni-dortmund.de (8.18.2/8.18.2) with ESMTPSA id 63SCewwk012433 (version=TLSv1.3 cipher=TLS_AES_256_GCM_SHA384 bits=256 verify=NOT); Tue, 28 Apr 2026 14:41:00 +0200 (CEST) From: Simon Schippers To: willemdebruijn.kernel@gmail.com, jasowang@redhat.com, andrew+netdev@lunn.ch, davem@davemloft.net, edumazet@google.com, kuba@kernel.org, pabeni@redhat.com, mst@redhat.com, eperezma@redhat.com, leiyang@redhat.com, stephen@networkplumber.org, jon@nutanix.com, tim.gebauer@tu-dortmund.de, simon.schippers@tu-dortmund.de, netdev@vger.kernel.org, linux-kernel@vger.kernel.org, kvm@vger.kernel.org, virtualization@lists.linux.dev Subject: [PATCH net-next v9 3/4] ptr_ring: move free-space check into separate helper Date: Tue, 28 Apr 2026 14:38:58 +0200 Message-ID: <20260428123859.19578-4-simon.schippers@tu-dortmund.de> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260428123859.19578-1-simon.schippers@tu-dortmund.de> References: <20260428123859.19578-1-simon.schippers@tu-dortmund.de> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" This patch moves the check for available free space for a new entry into a separate function. As a result, __ptr_ring_produce() remains logically unchanged, while the new helper allows callers to determine in advance whether subsequent __ptr_ring_produce() calls will succeed. This information can, for example, be used to temporarily stop producing until __ptr_ring_peek() indicates that space is available again. Co-developed-by: Tim Gebauer Signed-off-by: Tim Gebauer Signed-off-by: Simon Schippers --- include/linux/ptr_ring.h | 14 ++++++++++++-- 1 file changed, 12 insertions(+), 2 deletions(-) diff --git a/include/linux/ptr_ring.h b/include/linux/ptr_ring.h index d2c3629bbe45..b51fe4a484be 100644 --- a/include/linux/ptr_ring.h +++ b/include/linux/ptr_ring.h @@ -96,6 +96,14 @@ static inline bool ptr_ring_full_bh(struct ptr_ring *r) return ret; } =20 +static inline int __ptr_ring_produce_peek(struct ptr_ring *r) +{ + if (unlikely(!r->size) || data_race(r->queue[r->producer])) + return -ENOSPC; + + return 0; +} + /* Note: callers invoking this in a loop must use a compiler barrier, * for example cpu_relax(). Callers must hold producer_lock. * Callers are responsible for making sure pointer that is being queued @@ -103,8 +111,10 @@ static inline bool ptr_ring_full_bh(struct ptr_ring *r) */ static inline int __ptr_ring_produce(struct ptr_ring *r, void *ptr) { - if (unlikely(!r->size) || data_race(r->queue[r->producer])) - return -ENOSPC; + int p =3D __ptr_ring_produce_peek(r); + + if (p) + return p; =20 /* Make sure the pointer we are storing points to a valid data. */ /* Pairs with the dependency ordering in __ptr_ring_consume. */ --=20 2.43.0 From nobody Wed Jun 17 02:53:05 2026 Received: from unimail.uni-dortmund.de (mx1.hrz.uni-dortmund.de [129.217.128.51]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D56D63F7882; Tue, 28 Apr 2026 12:41:20 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=129.217.128.51 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1777380087; cv=none; b=dvsyz8fYiHB0L2Vvk2l8apC1h1RZY53q8PK6vmmABi6XVGieSIzpA3JqtKa8jzGqbkwB+lr4yU4s4jlxAFMRIwrmisBHufULaPgaOnzwPCq9WmaRsyp1sIUpzA3PaClc3lm0V4WydmnqxVmYl12Pck/kpV1l7GVAhUL3wI0GdLU= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1777380087; c=relaxed/simple; bh=/FIAmCE+jTSbIDR44bizH17/rllnYYVWfYT2DpoxWm0=; h=From:To:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=lNgZz9o/Z+eVasw1CGXNGmuaVEtj88Xo43xF0nTYBllpaj4S5ZUB5z/kn39M3ru8jXc60keCRJnpbdPF5Zs5r3SF3IiprKQDOIVR0RV5/qaA8njcEMxydgYFiDItwmM0FzwV0A1Z9xpdUWC7CmEpqOD4CDq7zz2WUU2bhi8FzRo= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=tu-dortmund.de; spf=pass smtp.mailfrom=tu-dortmund.de; arc=none smtp.client-ip=129.217.128.51 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=tu-dortmund.de Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=tu-dortmund.de Received: from simon-Latitude-5450.cni.e-technik.tu-dortmund.de ([129.217.186.62]) (authenticated bits=0) by unimail.uni-dortmund.de (8.18.2/8.18.2) with ESMTPSA id 63SCewwm012433 (version=TLSv1.3 cipher=TLS_AES_256_GCM_SHA384 bits=256 verify=NOT); Tue, 28 Apr 2026 14:41:01 +0200 (CEST) From: Simon Schippers To: willemdebruijn.kernel@gmail.com, jasowang@redhat.com, andrew+netdev@lunn.ch, davem@davemloft.net, edumazet@google.com, kuba@kernel.org, pabeni@redhat.com, mst@redhat.com, eperezma@redhat.com, leiyang@redhat.com, stephen@networkplumber.org, jon@nutanix.com, tim.gebauer@tu-dortmund.de, simon.schippers@tu-dortmund.de, netdev@vger.kernel.org, linux-kernel@vger.kernel.org, kvm@vger.kernel.org, virtualization@lists.linux.dev Subject: [PATCH net-next v9 4/4] tun/tap & vhost-net: avoid ptr_ring tail-drop when a qdisc is present Date: Tue, 28 Apr 2026 14:38:59 +0200 Message-ID: <20260428123859.19578-5-simon.schippers@tu-dortmund.de> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260428123859.19578-1-simon.schippers@tu-dortmund.de> References: <20260428123859.19578-1-simon.schippers@tu-dortmund.de> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" This commit prevents tail-drop when a qdisc is present and the ptr_ring becomes full. Once an entry is successfully produced and the ptr_ring reaches capacity, the netdev queue is stopped instead of dropping subsequent packets. If producing an entry fails anyways due to a race, tun_net_xmit returns NETDEV_TX_BUSY, again avoiding a drop. Such races are expected because LLTX is enabled and the transmit path operates without the usual locking. If no qdisc is present, the previous tail-drop behavior is preserved. The existing __tun_wake_queue() function of the consumer races with the producer for waking/stopping the netdev queue: the consumer may drain the ring just as the producer stops the queue, leading to a permanent stall. To avoid this, the producer re-checks the ring after stopping and wakes the queue itself if space was just made. An smp_mb__after_atomic() is required so the re-peek of the ring sees any drain that the consumer performed. smp_mb__after_atomic() pairs with the test_and_clear_bit() inside of netif_wake_subqueue(): Consumer CPU Producer CPU =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D = =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D __ptr_ring_consume() netif_wake_subqueue() netif_tx_stop_queue() /\ smp_mb__after_atomic() || __ptr_ring_produce_peek() contains RMW operation test_and_clear_bit() /\ || "Fully ordered RMW: smp_mb() before + after" - atomic_t.txt Benchmarks: The benchmarks show a slight regression in raw transmission performance, though no packets are lost anymore. The previously introduced threshold to only wake after the queue stopped and half of the ring was consumed showed to be a descent choice: Waking the queue whenever a consume made space in the ring strongly degrades performance for tap, while waking only when the ring is empty is too late and also hurts throughput for tap & tap+vhost-net. Other ratios (3/4, 7/8) showed similar results (not shown here), so 1/2 was chosen for the sake of simplicity for both tun/tap and tun/tap+vhost-net. Test setup: AMD Ryzen 5 5600X at 4.3 GHz, 3200 MHz RAM, isolated QEMU threads; Average over 50 runs @ 100,000,000 packets. SRSO and spectre v2 mitigations disabled. Note for tap+vhost-net: XDP drop program active in VM -> ~2.5x faster, slower for tap due to more syscalls (high utilization of entry_SYSRETQ_unsafe_stack in perf) +--------------------------+--------------+----------------+----------+ | 1 thread | Stock | Patched with | diff | | sending | | fq_codel qdisc | | +------------+-------------+--------------+----------------+----------+ | TAP | Transmitted | 1.136 Mpps | 1.130 Mpps | -0.6% | | +-------------+--------------+----------------+----------+ | | Lost/s | 3.758 Mpps | 0 pps | | +------------+-------------+--------------+----------------+----------+ | TAP | Transmitted | 3.858 Mpps | 3.816 Mpps | -1.1% | | +-------------+--------------+----------------+----------+ | +vhost-net | Lost/s | 789.8 Kpps | 0 pps | | +------------+-------------+--------------+----------------+----------+ +--------------------------+--------------+----------------+----------+ | 2 threads | Stock | Patched with | diff | | sending | | fq_codel qdisc | | +------------+-------------+--------------+----------------+----------+ | TAP | Transmitted | 1.117 Mpps | 1.087 Mpps | -2.7% | | +-------------+--------------+----------------+----------+ | | Lost/s | 8.476 Mpps | 0 pps | | +------------+-------------+--------------+----------------+----------+ | TAP | Transmitted | 3.679 Mpps | 3.464 Mpps | -5.8% | | +-------------+--------------+----------------+----------+ | +vhost-net | Lost/s | 5.306 Mpps | 0 pps | | +------------+-------------+--------------+----------------+----------+ Co-developed-by: Tim Gebauer Signed-off-by: Tim Gebauer Signed-off-by: Simon Schippers --- drivers/net/tun.c | 30 ++++++++++++++++++++++++++++-- 1 file changed, 28 insertions(+), 2 deletions(-) diff --git a/drivers/net/tun.c b/drivers/net/tun.c index efe809597622..c2a1618cc9db 100644 --- a/drivers/net/tun.c +++ b/drivers/net/tun.c @@ -1011,6 +1011,8 @@ static netdev_tx_t tun_net_xmit(struct sk_buff *skb, = struct net_device *dev) struct netdev_queue *queue; struct tun_file *tfile; int len =3D skb->len; + bool qdisc_present; + int ret; =20 rcu_read_lock(); tfile =3D rcu_dereference(tun->tfiles[txq]); @@ -1065,13 +1067,37 @@ static netdev_tx_t tun_net_xmit(struct sk_buff *skb= , struct net_device *dev) =20 nf_reset_ct(skb); =20 - if (ptr_ring_produce(&tfile->tx_ring, skb)) { + queue =3D netdev_get_tx_queue(dev, txq); + qdisc_present =3D !qdisc_txq_has_no_queue(queue); + + spin_lock(&tfile->tx_ring.producer_lock); + ret =3D __ptr_ring_produce(&tfile->tx_ring, skb); + if (__ptr_ring_produce_peek(&tfile->tx_ring) && qdisc_present) { + netif_tx_stop_queue(queue); + /* Re-peek and wake if the consumer drained the ring + * concurrently in a race. smp_mb__after_atomic() pairs + * with the test_and_clear_bit() of netif_wake_subqueue() + * in __tun_wake_queue(). + */ + smp_mb__after_atomic(); + if (!__ptr_ring_produce_peek(&tfile->tx_ring)) + netif_tx_wake_queue(queue); + } + spin_unlock(&tfile->tx_ring.producer_lock); + + if (ret) { + /* If a qdisc is attached to our virtual device, + * returning NETDEV_TX_BUSY is allowed. + */ + if (qdisc_present) { + rcu_read_unlock(); + return NETDEV_TX_BUSY; + } drop_reason =3D SKB_DROP_REASON_FULL_RING; goto drop; } =20 /* dev->lltx requires to do our own update of trans_start */ - queue =3D netdev_get_tx_queue(dev, txq); txq_trans_cond_update(queue); =20 /* Notify and wake up reader process */ --=20 2.43.0