Thread (15 messages) flat view 15 messages, 4 authors, 2016-01-21

Re: Kernel memory leak in bnx2x driver with vxlan tunnel

From: Eric Dumazet <hidden>
Date: 2016-01-19 22:47:36

On Tue, 2016-01-19 at 13:07 -0800, Jesse Gross wrote:
On Thu, Jan 14, 2016 at 9:17 AM, John [off-list ref] wrote:
quoted
I'm getting what seems to be a kernel memory leak while doing a TCP
throughput test between two VMs on identical systems, in order to test a
broadcom NIC's performance with a kernel 4.4.0-rc8 and OpenVSwitch version
2.4.90. The host system of the receiving (server) VM leaks memory during the
throughput test. The memory leaks fast enough to make the system completely
unusable within five minutes. Once I stop the throughput test, the memory
stops
leaking. A couple of times, the kernel on the host system has actually
killed
the qemu process for me, but this doesn't happen reliably. The leaked memory
doesn't become available again even after the VM is killed.
It looks like the problem is in napi_skb_finish(). If we when do
GRO_MERGED_FREE we have NAPI_GRO_CB(skb)->free ==
NAPI_GRO_FREE_STOLEN_HEAD then we will just free the skb memory itself
but not any of the associated elements. Historically, this would have
been OK but these days we will have allocated a dst entry already for
tunnel metadata, which will get leaked.

If we don't have NAPI_GRO_FREE_STOLEN_HEAD then we'll do a
__kfree_skb(), which will release the dst entry. That would explain
why some drivers have the problem but not others since the memory is
laid out differently.

Wow.... What is the purpose of using skb_dst_set() on skb before calling
gro_cells_receive() exactly ?

Commit 2e15ea390e6f4466655066d97e22ec66870a042c changelog is not
helpful :

    Following patch create new tunnel flag which enable
    tunnel metadata collection on given device.

This is rather strange since later the dst is thrown away with the
skb_valid_dst() test.

Note also that IP early demux is broken as well, since it does not use
skb_valid_dst() but a simple :

if (sysctl_ip_early_demux && !skb_dst(skb) && !skb->sk) {
 ...
}
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help