From nobody Tue Jun 9 00:59:52 2026 Received: from mail-pj1-f43.google.com (mail-pj1-f43.google.com [209.85.216.43]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 0F9C4175A67 for ; Mon, 25 May 2026 02:59:07 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.43 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779677949; cv=none; b=HLcVbSpxVU/YeY0FUFIWW0OVaWeqHZBH1l9KvE28+FglPpVsB7mbYhZ8J8Vj98oGjJDhA+zw8NsiyIq6TvtlwVWYBNP25j/4oCsEIBP1CVxtB0BAeHn2Vlw0AMI/zUcCwJDC+zQ+n3fPCGE/hjB0vCJ3TiMt+OsIKnwvFoVWdgs= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779677949; c=relaxed/simple; bh=5ZFQ3ioeI1AY7JkHhLJipr22pTr8CzAU/pick9VFC1Q=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=GqarFXdynS0pWxceI1IoRbg+g6q1EyW7/cZ5eoKyu/rJ9d4q0eAygo5t4n1nxYOtYIqy/R58JI/Nbzi0J24Ki/pE94AcC9Ms47G7BXhht8OFbsGrN9gbOjb6r59k0EGZdP2ZuhpijKfgDjaY+mDiaNQH083oDIbvtQXj/7f4D2k= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=gujYcriI; arc=none smtp.client-ip=209.85.216.43 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="gujYcriI" Received: by mail-pj1-f43.google.com with SMTP id 98e67ed59e1d1-369576666d5so4287999a91.0 for ; Sun, 24 May 2026 19:59:07 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1779677947; x=1780282747; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to; bh=xI1NKIYyb75g5GjRIKULuvy86/0Bdgcx6L8+8GI99ps=; b=gujYcriITDZBMa6p7PvVHMsEFvZpFovG7ITBswaxzIY7oJiHvyA29a49265MoxeEVN DEfKJTqhxKjFE8WcoFZav8VcSbX92UkAikhnIQVvYXmn8NmbsabDNaGUVe1IQSBWPyP1 IHr1je5SsYpx+xX2EI0raim4QW0qioUeWTRR22W+TB7Haf7vdU/cM5wHCfC+JiQw1sR7 do5lH5ibTioD6tFFNqvbIdQDlU0pUKj6OHRuIUXaeOnTgfwTunIFewdsXO4uPZm/A1GT o0ZaxFNZRTNkAbSSef2pXSMRZsb3dgn8l9qsqXkK1l9NCaDMjJ080LUowajWl2zhjC9r qwhQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1779677947; x=1780282747; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=xI1NKIYyb75g5GjRIKULuvy86/0Bdgcx6L8+8GI99ps=; b=Mr8d0xHK0Q/bp2Yz4qHde9XhWhKc8Zo7/zGN/vywbRciTeJD4usI+yBf33T6pGb+bm oSplOFf6BI5S8Z8vqqzoWcmwBNJfP8GE+kMKV20a2cQH3GC6X/IGdPpMolVY2Ws7Uxxv XLDcNJySDr0o9EsfxN04eJeBqk+eeHePMuGYs0R8A6fhz1RVx+NvaKM+P6yRZcnnyL6K 8nrRD8dIDnDBo0hyRhlqM6Fp/UJSWV4LwwBEQRFhnPrYkaaA/8rVR8A/Xpn1LlTwHWpZ /9T1OIGcNGpfivVAtkE8bbbBiORlYD5Ub+fg6xsxbyw/6QcZDnLPr+D7FqcZ0JcLpUV0 2Uaw== X-Forwarded-Encrypted: i=1; AFNElJ/UkyHWCsswjz75yhtqsoru4eN5u3RGEWkjCQX7buOivvMufrahOhuEvcIBC3XDr+Sd/G1NWyjT34xlSJk=@vger.kernel.org X-Gm-Message-State: AOJu0YynNzoSak/gD3JnYg9LhWvIidLDSLV/rR+ejDGzqQKPKQ7+m38f 7DKN6J3jN7RxNTFrn+jN1EKTZ01KGC6eXg5741UtDO65MPROVDfwRBLL X-Gm-Gg: Acq92OHLFqTrc1HBakSG4gExW7NyByy0Az6ka8uHe0I0jvWYoem6lQJsJJNdnnBNAwk wCEvqNilgpHNsSCHM5k3luMNJ5NSGw2w7GW3dpp6EFRsPu87ou705zKS22AuSF8ebjRC/edpvP5 XXI5JTAji8S1CDa+TBmzNvUHz7nXfqQEA6fevP18EvU+3bMRzA0/+uh4WMqWCFBumdE/IKyOiHf 37A53OMmc+19O76J9kqm1X//yBejI0uUR9z2430rOwOn+jDBGDKPc/ONx/oJl2l06zy8qirVj1e s1DKuzO2szickCnh/kWcMXgGdMx8fiFSiYMkeKOwzU4auVNW/019KMZ0lmlthcxDgfim9tqfkae 8atBctCxhV5+8jDWc6Mli6ERa+tt8H16kT3vNmcT6ZKaEZ1W7lkp+a1CSjpBpCR16rNVvvHcAPW 699nKRc/CGVuYgvUP8IcKwS4bHmeQ1MBptbVRIyhFmf+ZaVC1cZWcXG3ZwJXDlIfo= X-Received: by 2002:a17:90b:3149:b0:36a:ee1:fc1c with SMTP id 98e67ed59e1d1-36a674c5677mr12829799a91.8.1779677947243; Sun, 24 May 2026 19:59:07 -0700 (PDT) Received: from localhost.localdomain ([2409:891f:1b84:8280:c87f:5f1:b071:95f8]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-36a723dfa2dsm8029365a91.16.2026.05.24.19.59.02 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Sun, 24 May 2026 19:59:06 -0700 (PDT) From: Chuang Wang To: Cc: Chuang Wang , "David S. Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Simon Horman , Stanislav Fomichev , Kuniyuki Iwashima , Samiullah Khawaja , Hangbin Liu , Neal Cardwell , Martin KaFai Lau , netdev@vger.kernel.org, linux-kernel@vger.kernel.org Subject: [PATCH net-next v5] net: reduce RFS/ARFS flow updates by checking LLC affinity Date: Mon, 25 May 2026 10:58:42 +0800 Message-ID: <20260525025854.13982-1-nashuiliang@gmail.com> X-Mailer: git-send-email 2.50.1 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" The current implementation of rps_record_sock_flow() updates the flow table every time a socket is processed on a different CPU. In high-load scenarios, especially with Accelerated RFS (ARFS), this triggers frequent flow steering updates via ndo_rx_flow_steer. For drivers like mlx5 that implement hardware flow steering, these constant updates lead to significant contention on internal driver locks (e.g., arfs_lock). This contention often becomes a performance bottleneck that outweighs the steering benefits. This patch introduces a cache-aware update strategy: the flow record is only updated if the flow migrates across Last Level Cache (LLC) boundaries. This minimizes expensive hardware reconfigurations while preserving cache locality for the application. A new sysctl, net.core.rps_feat_llc_affinity, is added to toggle this feature. Additionally, export sock_rps_record_flow_hash() and sock_rps_record_flow(). This resolves a symbol visibility compilation error triggered by 'tun' using sock_rps_record_flow_hash() in tun_flow_update() when CONFIG_TUN is built as a module. The same logic is applied to SCTP, allowing it to use sock_rps_record_flow() safely when built as a module. Performance Test Results: The patch was tested in a K8s environment (AMD CPU 128*2, 16-core Pod with CPU pinning, mlx5 NIC) using brpc[1] echo_server and rpc_press. rpc_press Commands: for i in {1..8}; do ./rpc_press -proto=3D./echo.proto -method=3Dexample.EchoService.Echo -server=3D:8000 -input=3D'{"message":"hello"}' -qps=3D0 -thread_num=3D512 -connection_type=3Dpooled & done Monitor mlx5e_rx_flow_steer frequency: /usr/share/bcc/tools/funccount -i 1 mlx5e_rx_flow_steer Frequency of mlx5e_rx_flow_steer (via funccount[2]): Before: ~335,000 counts/sec After: ~23,000 counts/sec (reduced by ~93%) System Metrics (after enabling rps_feat_llc_affinity): CPU Utilization: 38% -> 32% CPU PSI (Pressure Stall Information): 20% -> 10% These results demonstrate that filtering updates by LLC affinity significantly reduces driver lock contention and improves overall CPU efficiency under heavy network load. [1] https://github.com/apache/brpc/ [2] https://github.com/iovisor/bcc/blob/master/tools/funccount.py Signed-off-by: Chuang Wang --- v4 -> v5: fix 'modpost: "rps_llc_check" [net/sctp/sctp.ko] undefined!' by k= ernel test robot v3 -> v4: add rps_llc_check by Eric Dumazet v2 -> v3: patch net -> net-next by Jakub Kicinski v1 -> v2: add rps_feat_llc_affinity; add brpc tests include/net/rps.h | 28 ++++---------- net/core/dev.c | 76 ++++++++++++++++++++++++++++++++++++++ net/core/sysctl_net_core.c | 35 ++++++++++++++++++ 3 files changed, 119 insertions(+), 20 deletions(-) diff --git a/include/net/rps.h b/include/net/rps.h index e33c6a2fa8bb..6dacf0888a6c 100644 --- a/include/net/rps.h +++ b/include/net/rps.h @@ -12,6 +12,7 @@ =20 extern struct static_key_false rps_needed; extern struct static_key_false rfs_needed; +extern struct static_key_false rps_feat_llc_affinity; =20 /* * This structure holds an RPS map which can be of variable length. The @@ -55,11 +56,14 @@ struct rps_sock_flow_table { =20 #define RPS_NO_CPU 0xffff =20 +bool rps_llc_check(u32 old_val, u32 new_val); + static inline void rps_record_sock_flow(rps_tag_ptr tag_ptr, u32 hash) { unsigned int index =3D hash & rps_tag_to_mask(tag_ptr); u32 val =3D hash & ~net_hotdata.rps_cpu_mask; struct rps_sock_flow_table *table; + u32 old_val; =20 /* We only give a hint, preemption can change CPU under us */ val |=3D raw_smp_processor_id(); @@ -68,7 +72,8 @@ static inline void rps_record_sock_flow(rps_tag_ptr tag_p= tr, u32 hash) /* The following WRITE_ONCE() is paired with the READ_ONCE() * here, and another one in get_rps_cpu(). */ - if (READ_ONCE(table[index].ent) !=3D val) + old_val =3D READ_ONCE(table[index].ent); + if (old_val !=3D val && rps_llc_check(old_val, val)) WRITE_ONCE(table[index].ent, val); } =20 @@ -136,25 +141,8 @@ static inline bool rfs_is_needed(void) #endif } =20 -static inline void sock_rps_record_flow_hash(__u32 hash) -{ -#ifdef CONFIG_RPS - if (!rfs_is_needed()) - return; - - _sock_rps_record_flow_hash(hash); -#endif -} - -static inline void sock_rps_record_flow(const struct sock *sk) -{ -#ifdef CONFIG_RPS - if (!rfs_is_needed()) - return; - - _sock_rps_record_flow(sk); -#endif -} +void sock_rps_record_flow_hash(__u32 hash); +void sock_rps_record_flow(const struct sock *sk); =20 static inline void sock_rps_delete_flow(const struct sock *sk) { diff --git a/net/core/dev.c b/net/core/dev.c index 26ac8eb9b259..f98216ddaec1 100644 --- a/net/core/dev.c +++ b/net/core/dev.c @@ -4997,6 +4997,8 @@ struct static_key_false rps_needed __read_mostly; EXPORT_SYMBOL(rps_needed); struct static_key_false rfs_needed __read_mostly; EXPORT_SYMBOL(rfs_needed); +struct static_key_false rps_feat_llc_affinity __read_mostly; +EXPORT_SYMBOL(rps_feat_llc_affinity); =20 static u32 rfs_slot(u32 hash, rps_tag_ptr tag_ptr) { @@ -5208,6 +5210,58 @@ static int get_rps_cpu(struct net_device *dev, struc= t sk_buff *skb, return cpu; } =20 +/** + * rps_llc_check - Determine if RPS flow table should be updated + * @old_val: Previous flow record value + * @new_val: Target flow record value + * + * Returns true if the record needs an update. + */ +bool rps_llc_check(u32 old_val, u32 new_val) +{ + u32 old_cpu =3D old_val & ~net_hotdata.rps_cpu_mask; + u32 new_cpu =3D new_val & ~net_hotdata.rps_cpu_mask; + + if (old_val =3D=3D new_val) + return false; + + /* + * RPS LLC Affinity Feature: + * Reduce RFS/ARFS flow updates by checking LLC affinity. + * + * Frequent flow table updates can trigger constant hardware steering + * reconfigurations (e.g., ndo_rx_flow_steer), leading to significant + * contention on driver internal locks (like mlx5's arfs_lock). + * + * This strategy only updates the flow record if it migrates across LLC + * boundaries. This minimizes expensive hardware updates while preserving + * cache locality for the application. + */ + if (static_branch_unlikely(&rps_feat_llc_affinity)) { + /* Force update if the recorded CPU is invalid or has gone offline */ + if (old_cpu >=3D nr_cpu_ids || !cpu_active(old_cpu)) + return true; + + /* + * Force an update if the current task is no longer permitted + * to run on the old_cpu. + */ + if (!cpumask_test_cpu(old_cpu, current->cpus_ptr)) + return true; + + /* + * If CPUs do not share a cache, allow the update to prevent + * expensive remote memory accesses and cache misses. + */ + if (!cpus_share_cache(old_cpu, new_cpu)) + return true; + + return false; + } + + return true; +} + #ifdef CONFIG_RFS_ACCEL =20 /** @@ -5249,6 +5303,28 @@ bool rps_may_expire_flow(struct net_device *dev, u16= rxq_index, } EXPORT_SYMBOL(rps_may_expire_flow); =20 +void sock_rps_record_flow_hash(__u32 hash) +{ +#ifdef CONFIG_RPS + if (!rfs_is_needed()) + return; + + _sock_rps_record_flow_hash(hash); +#endif +} +EXPORT_SYMBOL(sock_rps_record_flow_hash); + +void sock_rps_record_flow(const struct sock *sk) +{ +#ifdef CONFIG_RPS + if (!rfs_is_needed()) + return; + + _sock_rps_record_flow(sk); +#endif +} +EXPORT_SYMBOL(sock_rps_record_flow); + #endif /* CONFIG_RFS_ACCEL */ =20 /* Called from hardirq (IPI) context */ diff --git a/net/core/sysctl_net_core.c b/net/core/sysctl_net_core.c index b508618bfc12..b6d4ebcbb6a6 100644 --- a/net/core/sysctl_net_core.c +++ b/net/core/sysctl_net_core.c @@ -210,6 +210,33 @@ static int rps_sock_flow_sysctl(const struct ctl_table= *table, int write, kvfree_rcu_mightsleep(tofree); return ret; } + +static int rps_feat_llc_affinity_sysctl(const struct ctl_table *table, int= write, + void *buffer, size_t *lenp, loff_t *ppos) +{ + u8 curr_state; + int ret; + const struct ctl_table tmp =3D { + .data =3D &curr_state, + .maxlen =3D sizeof(curr_state), + .mode =3D table->mode, + .extra1 =3D table->extra1, + .extra2 =3D table->extra2 + }; + + curr_state =3D static_branch_unlikely(&rps_feat_llc_affinity) ? 1 : 0; + + ret =3D proc_dou8vec_minmax(&tmp, write, buffer, lenp, ppos); + if (write && ret =3D=3D 0) { + if (curr_state && !static_branch_unlikely(&rps_feat_llc_affinity)) + static_branch_enable(&rps_feat_llc_affinity); + else if (!curr_state && static_branch_unlikely(&rps_feat_llc_affinity)) + static_branch_disable(&rps_feat_llc_affinity); + } + + return ret; +} + #endif /* CONFIG_RPS */ =20 #ifdef CONFIG_NET_FLOW_LIMIT @@ -554,6 +581,14 @@ static struct ctl_table net_core_table[] =3D { .mode =3D 0644, .proc_handler =3D rps_sock_flow_sysctl }, + { + .procname =3D "rps_feat_llc_affinity", + .maxlen =3D sizeof(u8), + .mode =3D 0644, + .proc_handler =3D rps_feat_llc_affinity_sysctl, + .extra1 =3D SYSCTL_ZERO, + .extra2 =3D SYSCTL_ONE + }, #endif #ifdef CONFIG_NET_FLOW_LIMIT { --=20 2.47.3