Layer-7 (L7) proxies are critical to modern cloud-native systems, yet their performance is increasingly bottlenecked by copying entire payloads across the kernel-user boundary. Existing approaches reduce this overhead but typically sacrifice compatibility with unmodified POSIX applications, introduce new APIs, or require specialized environments. We show that, under conventional OS abstractions, fully eliminating kernel-user copies while preserving standard socket semantics for unmodified proxies is fundamentally impossible. This leads to a practical insight: in common L7 workloads, proxies inspect only small metadata (e.g., HTTP headers) for routing, while forwarding the bulk payload unchanged. Based on this insight, we present Libra, an OS-level selective-copy framework that copies only metadata to the user space and retains the bulk payload in the kernel for forwarding, reducing data movement without breaking compatibility. Libra uses eBPF to identify protocol-specific metadata boundaries and coordinate selective copy and payload reuse across receive and transmit paths, all without modifying the socket API. Implemented in Linux and evaluated with unmodified Nginx and HAProxy, Libra improves plaintext throughput by up to 4.2x and reduces P99 tail latency by over 90%. With hardware-offloaded kTLS, it boosts encrypted throughput by 2.0x and cuts tail latency by 65%.


翻译:第7层(L7)代理对现代云原生系统至关重要,但其性能日益受限于跨内核-用户边界拷贝完整负载的开销。现有方法虽能减少该开销,却通常以牺牲与未修改POSIX应用的兼容性为代价,或引入新API,或需要专用环境。我们证明,在传统操作系统抽象下,完全消除内核-用户拷贝的同时保持未修改代理的标准套接字语义在根本上不可行。由此得出一项实用洞见:在常见L7工作负载中,代理仅检查用于路由的小型元数据(如HTTP头部),而将大块负载原样转发。基于此洞见,我们提出Libra——一种操作系统级选择性拷贝框架,仅将元数据拷贝至用户空间,将大块负载保留在内核中进行转发,从而在不破坏兼容性的前提下减少数据移动。Libra利用eBPF识别协议特定的元数据边界,并协调接收与发送路径间的选择性拷贝与负载重用,全程无需修改套接字API。在Linux上实现,并以未修改的Nginx和HAProxy评估,Libra将明文吞吐量提升高达4.2倍,P99尾部延迟降低超90%。配合硬件卸载的kTLS,加密吞吐量提升2.0倍,尾部延迟降低65%。

0
下载
关闭预览

相关内容

国家标准《信息技术云计算参考架构》
专知会员服务
37+阅读 · 2024年5月24日
LLMCad:快速可扩展的设备上大型语言模型推理
专知会员服务
35+阅读 · 2023年9月11日
佐治亚理工2020《数据库系统实现》课程,不可错过!
专知会员服务
24+阅读 · 2020年10月14日
【数据中台】什么是数据中台?
产业智能官
18+阅读 · 2019年7月30日
基于 SonarQube 的增量代码扫描
DevOps时代
12+阅读 · 2019年7月18日
工行基于MySQL构建分布式架构的转型之路
炼数成金订阅号
15+阅读 · 2019年5月16日
自己动手撸一个分布式IM(即时通讯) 系统
51CTO博客
16+阅读 · 2019年3月20日
Fast-OCNet: 更快更好的OCNet.
极市平台
21+阅读 · 2019年2月10日
React Native 分包哪家强?看这文就够了!
程序人生
13+阅读 · 2019年1月16日
GAFT:一个使用 Python 实现的遗传算法框架
Python开发者
10+阅读 · 2017年8月1日
今日头条推荐系统架构演进之路
QCon
32+阅读 · 2017年6月21日
国家自然科学基金
1+阅读 · 2017年12月31日
国家自然科学基金
1+阅读 · 2015年12月31日
国家自然科学基金
1+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
1+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2014年12月31日
国家自然科学基金
3+阅读 · 2014年12月31日
VIP会员
最新内容
印度精确打击与指挥架构的断层
专知会员服务
4+阅读 · 7月20日
美空军AI完成F-16战斗机自主空战历史性试飞
专知会员服务
6+阅读 · 7月20日
深入Project Maven:为何人工智能在战场上依然失灵
锻造未来士兵:外骨骼、基因工程与赛博格
专知会员服务
7+阅读 · 7月19日
《无人机蜂群通信技术研究》50页
专知会员服务
11+阅读 · 7月19日
相关资讯
【数据中台】什么是数据中台?
产业智能官
18+阅读 · 2019年7月30日
基于 SonarQube 的增量代码扫描
DevOps时代
12+阅读 · 2019年7月18日
工行基于MySQL构建分布式架构的转型之路
炼数成金订阅号
15+阅读 · 2019年5月16日
自己动手撸一个分布式IM(即时通讯) 系统
51CTO博客
16+阅读 · 2019年3月20日
Fast-OCNet: 更快更好的OCNet.
极市平台
21+阅读 · 2019年2月10日
React Native 分包哪家强?看这文就够了!
程序人生
13+阅读 · 2019年1月16日
GAFT:一个使用 Python 实现的遗传算法框架
Python开发者
10+阅读 · 2017年8月1日
今日头条推荐系统架构演进之路
QCon
32+阅读 · 2017年6月21日
相关基金
国家自然科学基金
1+阅读 · 2017年12月31日
国家自然科学基金
1+阅读 · 2015年12月31日
国家自然科学基金
1+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
1+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2014年12月31日
国家自然科学基金
3+阅读 · 2014年12月31日
Top
微信扫码咨询专知VIP会员