From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1759977AbZDLHYs (ORCPT ); Sun, 12 Apr 2009 03:24:48 -0400 Received: (majordomo@vger.kernel.org) by vger.kernel.org id S1758300AbZDLHXU (ORCPT ); Sun, 12 Apr 2009 03:23:20 -0400 Received: from tservice.net.ru ([195.178.208.66]:53792 "EHLO tservice.net.ru" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1758168AbZDLHXS (ORCPT ); Sun, 12 Apr 2009 03:23:18 -0400 Date: Sun, 12 Apr 2009 11:23:12 +0400 From: Evgeniy Polyakov To: "Paul E. McKenney" Cc: Linus Torvalds , David Miller , Ingo Molnar , Lai Jiangshan , shemminger@vyatta.com, jeff.chua.linux@gmail.com, dada1@cosmosbay.com, jengelh@medozas.de, kaber@trash.net, r000n@r000n.net, Linux Kernel Mailing List , netfilter-devel@vger.kernel.org, netdev@vger.kernel.org Subject: Re: iptables very slow after commit 784544739a25c30637397ace5489eeb6e15d7d49 Message-ID: <20090412072312.GA24580@ioremap.net> References: <20090410095246.4fdccb56@s6510> <20090410.182507.140306636.davem@davemloft.net> <20090411041533.GB6822@linux.vnet.ibm.com> <20090412003445.GK6822@linux.vnet.ibm.com> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20090412003445.GK6822@linux.vnet.ibm.com> User-Agent: Mutt/1.5.13 (2006-08-11) Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Hi. On Sat, Apr 11, 2009 at 05:34:45PM -0700, Paul E. McKenney (paulmck@linux.vnet.ibm.com) wrote: > The issue at this point seems to be the need to get accurate snapshots > of various counters -- there are a number of Linux networking users who > need to account for every byte flowing through their systems. However, If we add or change the rule we can not know if iptables' return to userspace does mean that rule started to act. There may be other queues already filled with the packets which could match the new rule (like receiving socket buffer). So effectively we want it to take effect very soon. What if there will be a timer which will synchronize RCU-added states, so if we update single rule - it will take effect in a second, and if we update bunch of them - during the delay second we pretty much can load them all. -- Evgeniy Polyakov