Page MenuHomeFreeBSD

TCP: remove special treatment for hardware (ifnet) TLS
ClosedPublic

Authored by gallatin on Aug 18 2020, 3:20 PM.
Tags
None
Referenced Files
Unknown Object (File)
Sat, Jan 25, 2:52 AM
Unknown Object (File)
Sat, Jan 18, 4:57 AM
Unknown Object (File)
Dec 12 2024, 9:46 PM
Unknown Object (File)
Oct 19 2024, 1:18 AM
Unknown Object (File)
Oct 5 2024, 5:46 PM
Unknown Object (File)
Sep 25 2024, 10:30 AM
Unknown Object (File)
Sep 25 2024, 10:29 AM
Unknown Object (File)
Sep 25 2024, 10:29 AM
Subscribers

Details

Summary

Remove most special treatment for ifnet TLS in the TCP stack, except for code to avoid mixing handshakes and bulk data.

This code made heroic efforts to send down entire TLS records to NICs. It was added to improve the PCIe bus efficiency of older TLS offload NICs which did not keep state per-session, and so would need to re-DMA the first part(s) of a TLS record if a TLS record was sent in multiple TCP packets or TSOs. Newer TLS offload NICs do not need this feature.

At Netflix, we've run extensive QoE tests which show that this feature reduces client quality metrics, presumably because the effort to send TLS records atomically causes the server to both wait too long to send data (leading to buffers running dry), and to send too much data at once (leading to packet loss).

Diff Detail

Repository
rS FreeBSD src repository - subversion
Lint
Lint Not Applicable
Unit
Tests Not Applicable