From: John Johansen <john.johansen@canonical.com>
To: Sergey Senozhatsky <senozhatsky@chromium.org>,
Sebastian Andrzej Siewior <bigeasy@linutronix.de>
Cc: Peter Zijlstra <peterz@infradead.org>,
Tomasz Figa <tfiga@chromium.org>,
linux-kernel@vger.kernel.org,
linux-security-module@vger.kernel.org
Subject: Re: apparmor: global buffers spin lock may get contended
Date: Sun, 15 Aug 2021 02:47:28 -0700 [thread overview]
Message-ID: <fbf051ea-5a6b-37d0-e7b7-6513e4da9273@canonical.com> (raw)
In-Reply-To: <YO2S+C7Cw7AS7bsg@google.com>
On 7/13/21 6:19 AM, Sergey Senozhatsky wrote:
> Hi,
>
> We've notices that apparmor has switched from using per-CPU buffer pool
> and per-CPU spin_lock to a global spin_lock in df323337e507a0009d3db1ea.
>
> This seems to be causing some contention on our build machines (with
> quite a bit of cores). Because that global spin lock is a part of the
> stat() sys call (and perhaps some other)
>
> E.g.
>
> - 9.29% 0.00% clang++ [kernel.vmlinux]
> - 9.28% entry_SYSCALL_64_after_hwframe
> - 8.98% do_syscall_64
> - 7.43% __do_sys_newlstat
> - 7.43% vfs_statx
> - 7.18% security_inode_getattr
> - 7.15% apparmor_inode_getattr
> - aa_path_perm
> - 3.53% aa_get_buffer
> - 3.47% _raw_spin_lock
> 3.44% native_queued_spin_lock_slowpath
> - 3.49% aa_put_buffer.part.0
> - 3.45% _raw_spin_lock
> 3.43% native_queued_spin_lock_slowpath
>
> Can we fix this contention?
>
sorry this got filtered to a wrong mailbox. Yes this is something that can
be improved, and was a concern when the switch was made from per-CPU buffers
to the global pool.
We can look into doing a hybrid approach where we can per cpu cache a buffer
from the global pool. The trick will be coming up with when the cached buffer
can be returned so we don't run into the problems that lead to
df323337e507a0009d3db1ea
next prev parent reply other threads:[~2021-08-15 9:47 UTC|newest]
Thread overview: 21+ messages / expand[flat|nested] mbox.gz Atom feed top
2021-07-13 13:19 Sergey Senozhatsky
2021-08-15 9:47 ` John Johansen [this message]
2022-10-28 9:34 ` John Johansen
2022-10-31 3:52 ` Sergey Senozhatsky
2022-10-31 3:55 ` John Johansen
2022-10-31 4:04 ` Sergey Senozhatsky
2023-02-17 0:03 ` John Johansen
2023-02-17 0:08 ` [PATCH v3] " John Johansen
2023-02-17 10:44 ` Sebastian Andrzej Siewior
2023-02-20 8:42 ` John Johansen
2023-02-21 21:27 ` Anil Altinay
2023-06-26 23:35 ` Anil Altinay
[not found] ` <CACCxZWO-+M-J_enENr7q1WDcu1U8vYFoytqJxAh=x-nuP268zA@mail.gmail.com>
2023-06-27 0:31 ` John Johansen
2023-10-06 4:18 ` Sergey Senozhatsky
2023-10-17 9:21 ` [PATCH v5 0/4] apparmor: cache buffers on percpu list if there is lock, contention John Johansen
2023-10-17 9:23 ` [PATCH v5 1/4] " John Johansen
2023-10-17 9:24 ` [PATCH v5 2/4] apparmor: exponential backoff on cache buffer contention John Johansen
2023-10-17 9:25 ` [PATCH v5 3/4] apparmor: experiment with faster backoff on global buffer John Johansen
2023-10-17 9:26 ` [PATCH v5 4/4] apparmor: limit the number of buffers in percpu cache John Johansen
2023-10-26 5:13 ` [PATCH v5 0/4] apparmor: cache buffers on percpu list if there is lock, contention Sergey Senozhatsky
[not found] ` <20221030013028.3557-1-hdanton@sina.com>
2022-10-30 6:32 ` apparmor: global buffers spin lock may get contended John Johansen
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=fbf051ea-5a6b-37d0-e7b7-6513e4da9273@canonical.com \
--to=john.johansen@canonical.com \
--cc=bigeasy@linutronix.de \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-security-module@vger.kernel.org \
--cc=peterz@infradead.org \
--cc=senozhatsky@chromium.org \
--cc=tfiga@chromium.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®