[PATCH net-next 00/12] net: bridge: vlan: optimize standard fdb fwding path
From: Nikolay Aleksandrov <razor@blackwall.org>
Date: 2026-09-30 07:14:53
Also in:
bridge
Hi,
This patch-set is a follow-up after the bridge flood fwding path
optimizations and applies the same idea to the standard fdb fwding path.
We are able to remove 2 vlan hash lookups in the standard fdb fwding
path by caching the port-VLAN pointer in the fdb, to do that we switch the
fdb dst to an opaque type that can be either a port pointer or vlan pointer
differentiated by a bit. The field is a struct and also has a __private tag
so we can catch direct users, it should be used only via the helpers.
Sharing a field makes it easier to pass it around and also allows us to
save struct space for the fast-path. Interesting case is when an fdb is
promoted from a raw port to port-VLAN on the same port, it needs to be
handled carefully so we use cmpxchg to make sure we don't generate
deletion/replace notifications because it doesn't change the port.
I tested VLAN deletion after these changes (we now wait a grace period for
every delete) and the hit was ~20% reduction in deleted VLANs / sec
deleting 4k VLANs took 14ms more and on my VM the VLANs deleted / sec went
from 63k to 52k / sec. The complexity to batch them is not worth it.
Note again internal sashiko finds some pre-existing issues - I will take
care of those separately as usual.
Overall the improvement is +10% Mpps and -10% cycles spent in fdb fwding:
64 byte vlan packets, 4k randomized fdb hits with 4k fdbs, 5 million
packets passed 5 times for every case
VIDs Ports Mpps Gbps CPU1 cycles/input
before after gain before after before after reduction
64 8/2 2.375486 2.635811 11.0% 1.216 1.350 1724.6 1553.7 9.9%
64 8/4 2.376731 2.636459 10.9% 1.217 1.350 1714.8 1554.7 9.3%
64 8/8 2.376621 2.635783 10.9% 1.217 1.350 1722.6 1553.2 9.8%
64 32/2 2.375876 2.637897 11.0% 1.216 1.351 1726.7 1552.3 10.1%
64 32/16 2.376442 2.636426 10.9% 1.217 1.350 1721.3 1554.2 9.7%
64 32/32 2.376763 2.636268 10.9% 1.217 1.350 1726.8 1553.5 10.0%
64 64/2 2.375678 2.638707 11.1% 1.216 1.351 1725.0 1552.1 10.0%
64 64/32 2.376681 2.637359 11.0% 1.217 1.350 1725.1 1555.9 9.8%
64 64/64 2.376787 2.638396 11.0% 1.217 1.351 1722.8 1550.9 10.0%
1024 8/2 2.263768 2.498881 10.4% 1.159 1.279 1808.5 1637.1 9.5%
1024 8/4 2.264519 2.499075 10.4% 1.159 1.280 1807.6 1638.8 9.3%
1024 8/8 2.263551 2.499231 10.4% 1.159 1.280 1812.0 1640.2 9.5%
1024 32/2 2.263841 2.499120 10.4% 1.159 1.280 1806.8 1639.6 9.3%
1024 32/16 2.263990 2.499562 10.4% 1.159 1.280 1806.1 1639.2 9.2%
1024 32/32 2.263719 2.498905 10.4% 1.159 1.279 1807.7 1639.3 9.3%
1024 64/2 2.263635 2.501889 10.5% 1.159 1.281 1809.4 1635.6 9.6%
1024 64/32 2.264467 2.500359 10.4% 1.159 1.280 1806.5 1633.0 9.6%
1024 64/64 2.240494 2.470246 10.3% 1.147 1.265 1810.0 1637.1 9.6%
This information has been also included in the commit that removes the
lookups.
Quick patch overview:
Patch 01 - adds the new opaque destination type with its basic helpers
Patch 02 - uses the new dsts for standard port fdb destinations
Patch 03 - adds port-VLAN pointer support to the destination type
Patch 04 - changes ingress helpers so we can get rid of the vid argument
and pass a vlan pointer around
Patch 05 - passes VLAN pointers instead of vid to br_fdb_update
Patch 06 - consolidates vlan fdb cleanups, that will allow us to clean
entries in one pass later on
Patch 07 - splits vlan unpublishing from hash and flood array from deletion
that will be needed to optimize bulk deletes and flushes
Patch 08 - makes sure that readers cannot publish the vlan dst before
cleaning up all fdbs that use it
Patch 09 - factors out the fdb update path to prepare it for port-VLAN dsts
Patch 10 - the first port-VLAN publishing, fdbs can now have port-VLAN dsts
Patch 11 - port-VLAN dst publishing for configured entries
Patch 12 - remove 2 vlan hash lookups in fdb fwding fast-path
For sashiko:
[Severity: High]
Could nbp_vlan_delete() in net/bridge/br_vlan.c avoid waiting for a network
RCU grace period once per VLAN while RTNL is held?
Nik: Yes, it could but the complexity this brings is not worth it.
See above.
[Severity: High]
Could this synchronize_net() in
net/bridge/br_vlan.c:nbp_vlan_delete() be batched by its callers?
Nik: Yes, it could but again same thing - it is not worth the complexity
and deleting VLANs is still fast enough.
Thanks,
Nik
Nikolay Aleksandrov (12):
net: bridge: introduce a bridge destination type
net: bridge: use net_bridge_dst for fdb destinations
net: bridge: add VLAN support to bridge destinations
net: bridge: vlan: return VLAN entries from ingress helpers
net: bridge: fdb: pass VLAN entries to learning updates
net: bridge: fdb: consolidate port-VLAN cleanup
net: bridge: vlan: split unpublishing from deletion
net: bridge: vlan: quiesce readers before freeing port VLANs
net: bridge: fdb: factor out existing entry updates
net: bridge: fdb: cache port VLANs in learned entries
net: bridge: fdb: cache VLAN destinations in configured entries
net: bridge: fdb: avoid VLAN lookups in unicast forwarding
include/trace/events/bridge.h | 7 +-
net/bridge/br.c | 2 +-
net/bridge/br_arp_nd_proxy.c | 4 +-
net/bridge/br_device.c | 9 +-
net/bridge/br_fdb.c | 270 +++++++++++++++--------
net/bridge/br_forward.c | 24 +-
net/bridge/br_if.c | 13 +-
net/bridge/br_input.c | 26 ++-
net/bridge/br_mrp.c | 6 +-
net/bridge/br_netlink.c | 2 +-
net/bridge/br_private.h | 157 ++++++++++++-
net/bridge/br_stp_if.c | 2 +-
net/bridge/br_switchdev.c | 2 +-
net/bridge/br_sysfs_if.c | 3 +-
net/bridge/br_vlan.c | 107 +++++----
net/bridge/netfilter/nft_reject_bridge.c | 8 +-
16 files changed, 448 insertions(+), 194 deletions(-)
--
2.47.3