80 FatalError(
"Error creating thread %s: you do not have "
81 "support for DPDK enabled, on Linux host please recompile "
96 #define MIN_ZERO_POLL_COUNT 10U
97 #define MIN_ZERO_POLL_COUNT_TO_SLEEP 10U
98 #define MINIMUM_SLEEP_TIME_US 1U
99 #define STANDARD_SLEEP_TIME_US 100U
100 #define MAX_EPOLL_TIMEOUT_MS 500U
101 static rte_spinlock_t intr_lock[RTE_MAX_ETHPORTS];
106 typedef struct DPDKThreadVars_ {
115 uint16_t capture_dpdk_packets;
116 uint16_t capture_dpdk_rx_errs;
117 uint16_t capture_dpdk_imissed;
118 uint16_t capture_dpdk_rx_no_mbufs;
119 uint16_t capture_dpdk_ierrors;
120 uint16_t capture_dpdk_tx_errs;
125 uint16_t out_port_id;
133 int32_t port_socket_id;
134 struct rte_mempool *pkt_mempool;
135 struct rte_mbuf *received_mbufs[BURST_SIZE];
140 static void ReceiveDPDKThreadExitStats(
ThreadVars *,
void *);
148 static void DPDKFreeMbufArray(
struct rte_mbuf **mbuf_array, uint16_t mbuf_cnt, uint16_t
offset);
149 static bool InterruptsRXEnable(uint16_t port_id, uint16_t queue_id)
151 uint32_t event_data = port_id << UINT16_WIDTH | queue_id;
152 int32_t ret = rte_eth_dev_rx_intr_ctl_q(port_id, queue_id, RTE_EPOLL_PER_THREAD,
153 RTE_INTR_EVENT_ADD, (
void *)((uintptr_t)event_data));
156 SCLogError(
"%s-Q%d: failed to enable interrupt mode: %s", DPDKGetPortNameByPortID(port_id),
157 queue_id, rte_strerror(-ret));
163 static inline uint32_t InterruptsSleepHeuristic(uint32_t no_pkt_polls_count)
165 if (no_pkt_polls_count < MIN_ZERO_POLL_COUNT_TO_SLEEP)
166 return MINIMUM_SLEEP_TIME_US;
168 return STANDARD_SLEEP_TIME_US;
171 static inline void InterruptsTurnOnOff(uint16_t port_id, uint16_t queue_id,
bool on)
173 rte_spinlock_lock(&(intr_lock[port_id]));
176 rte_eth_dev_rx_intr_enable(port_id, queue_id);
178 rte_eth_dev_rx_intr_disable(port_id, queue_id);
180 rte_spinlock_unlock(&(intr_lock[port_id]));
183 static inline void DPDKFreeMbufArray(
184 struct rte_mbuf **mbuf_array, uint16_t mbuf_cnt, uint16_t
offset)
186 for (
int i =
offset; i < mbuf_cnt; i++) {
187 rte_pktmbuf_free(mbuf_array[i]);
191 static void DevicePostStartPMDSpecificActions(DPDKThreadVars *ptv,
const char *driver_name)
193 if (strcmp(driver_name,
"net_bonding") == 0) {
194 driver_name = BondingDeviceDriverGet(ptv->port_id);
199 if (strcmp(driver_name,
"net_i40e") == 0)
200 i40eDeviceSetRSS(ptv->port_id, ptv->threads);
203 static void DevicePreClosePMDSpecificActions(DPDKThreadVars *ptv,
const char *driver_name)
205 if (strcmp(driver_name,
"net_bonding") == 0) {
206 driver_name = BondingDeviceDriverGet(ptv->port_id);
209 if (strcmp(driver_name,
"net_i40e") == 0) {
210 #if RTE_VERSION > RTE_VERSION_NUM(20, 0, 0, 0)
212 struct rte_flow_error flush_error = { 0 };
213 int32_t retval = rte_flow_flush(ptv->port_id, &flush_error);
215 SCLogError(
"%s: unable to flush rte_flow rules: %s Flush error msg: %s",
216 ptv->livedev->dev, rte_strerror(-retval), flush_error.message);
226 static int GetNumaNode(
void)
231 #if defined(__linux__)
232 cpu = sched_getcpu();
233 node = numa_node_of_cpu(cpu);
235 SCLogWarning(
"NUMA node retrieval is not supported on this OS.");
273 static inline void DPDKDumpCounters(DPDKThreadVars *ptv)
278 if (ptv->queue_id == 0) {
279 struct rte_eth_stats eth_stats;
280 int retval = rte_eth_stats_get(ptv->port_id, ð_stats);
282 SCLogError(
"%s: failed to get stats: %s", ptv->livedev->dev, rte_strerror(-retval));
287 ptv->pkts + eth_stats.imissed + eth_stats.ierrors + eth_stats.rx_nombuf);
289 eth_stats.ipackets + eth_stats.imissed + eth_stats.ierrors + eth_stats.rx_nombuf);
291 eth_stats.imissed + eth_stats.ierrors + eth_stats.rx_nombuf);
292 StatsSetUI64(ptv->tv, ptv->capture_dpdk_imissed, eth_stats.imissed);
293 StatsSetUI64(ptv->tv, ptv->capture_dpdk_rx_no_mbufs, eth_stats.rx_nombuf);
294 StatsSetUI64(ptv->tv, ptv->capture_dpdk_ierrors, eth_stats.ierrors);
295 StatsSetUI64(ptv->tv, ptv->capture_dpdk_tx_errs, eth_stats.oerrors);
297 ptv->livedev->drop, eth_stats.imissed + eth_stats.ierrors + eth_stats.rx_nombuf);
299 StatsSetUI64(ptv->tv, ptv->capture_dpdk_packets, ptv->pkts);
303 static void DPDKReleasePacket(
Packet *p)
312 #
if defined(RTE_LIBRTE_I40E_PMD) || defined(RTE_LIBRTE_IXGBE_PMD) || defined(RTE_LIBRTE_ICE_PMD)
313 && !(PacketIsICMPv6(p) && PacketGetICMPv6(p)->
type == 143)
318 rte_eth_tx_burst(p->dpdk_v.out_port_id, p->dpdk_v.out_queue_id, &p->dpdk_v.mbuf, 1);
325 retval = rte_eth_tx_burst(
326 p->dpdk_v.out_port_id, p->dpdk_v.out_queue_id, &p->dpdk_v.mbuf, 1);
328 SCLogDebug(
"Unable to transmit the packet on port %u queue %u",
329 p->dpdk_v.out_port_id, p->dpdk_v.out_queue_id);
330 rte_pktmbuf_free(p->dpdk_v.mbuf);
331 p->dpdk_v.mbuf = NULL;
335 rte_pktmbuf_free(p->dpdk_v.mbuf);
336 p->dpdk_v.mbuf = NULL;
350 rte_eth_stats_reset(ptv->port_id);
351 rte_eth_xstats_reset(ptv->port_id);
353 if (ptv->intr_enabled && !InterruptsRXEnable(ptv->port_id, ptv->queue_id))
359 static inline void LoopHandleTimeoutOnIdle(
ThreadVars *
tv)
361 static thread_local uint64_t last_timeout_msec = 0;
364 if (msecs > last_timeout_msec + 100) {
365 TmThreadsCaptureHandleTimeout(
tv, NULL);
366 last_timeout_msec = msecs;
374 static inline bool RXPacketCountHeuristic(
ThreadVars *
tv, DPDKThreadVars *ptv, uint16_t nb_rx)
376 static thread_local uint32_t zero_pkt_polls_cnt = 0;
379 zero_pkt_polls_cnt = 0;
383 LoopHandleTimeoutOnIdle(
tv);
384 if (!ptv->intr_enabled)
387 zero_pkt_polls_cnt++;
388 if (zero_pkt_polls_cnt <= MIN_ZERO_POLL_COUNT)
391 uint32_t pwd_idle_hint = InterruptsSleepHeuristic(zero_pkt_polls_cnt);
392 if (pwd_idle_hint < STANDARD_SLEEP_TIME_US) {
393 rte_delay_us(pwd_idle_hint);
395 InterruptsTurnOnOff(ptv->port_id, ptv->queue_id,
true);
396 struct rte_epoll_event event;
397 rte_epoll_wait(RTE_EPOLL_PER_THREAD, &event, 1, MAX_EPOLL_TIMEOUT_MS);
398 InterruptsTurnOnOff(ptv->port_id, ptv->queue_id,
false);
409 static inline Packet *PacketInitFromMbuf(DPDKThreadVars *ptv,
struct rte_mbuf *mbuf)
422 p->dpdk_v.mbuf = mbuf;
424 p->dpdk_v.copy_mode = ptv->copy_mode;
425 p->dpdk_v.out_port_id = ptv->out_port_id;
426 p->dpdk_v.out_queue_id = ptv->queue_id;
432 uint64_t ol_flags = p->dpdk_v.mbuf->ol_flags;
433 if ((ol_flags & RTE_MBUF_F_RX_IP_CKSUM_MASK) == RTE_MBUF_F_RX_IP_CKSUM_GOOD &&
434 (ol_flags & RTE_MBUF_F_RX_L4_CKSUM_MASK) == RTE_MBUF_F_RX_L4_CKSUM_GOOD) {
435 SCLogDebug(
"HW detected GOOD IP and L4 chsum, ignoring validation");
438 if ((ol_flags & RTE_MBUF_F_RX_IP_CKSUM_MASK) == RTE_MBUF_F_RX_IP_CKSUM_BAD) {
444 if ((ol_flags & RTE_MBUF_F_RX_L4_CKSUM_MASK) == RTE_MBUF_F_RX_L4_CKSUM_BAD) {
455 static inline void DPDKSegmentedMbufWarning(
struct rte_mbuf *mbuf)
457 static thread_local
bool segmented_mbufs_warned =
false;
458 if (!segmented_mbufs_warned && !rte_pktmbuf_is_contiguous(mbuf)) {
459 char warn_s[] =
"Segmented mbufs detected! Redmine Ticket #6012 "
460 "Check your configuration or report the issue";
461 enum rte_proc_type_t eal_t = rte_eal_process_type();
462 if (eal_t == RTE_PROC_SECONDARY) {
464 "try to increase mbuf size in your primary application",
466 }
else if (eal_t == RTE_PROC_PRIMARY) {
468 "try to increase MTU in your suricata.yaml",
472 segmented_mbufs_warned =
true;
476 static void HandleShutdown(DPDKThreadVars *ptv)
480 while (
SC_ATOMIC_GET(ptv->workers_sync->worker_checked_in) < ptv->workers_sync->worker_cnt) {
483 if (ptv->queue_id == 0) {
490 rte_eth_dev_stop(ptv->out_port_id);
493 rte_eth_dev_stop(ptv->port_id);
496 DPDKDumpCounters(ptv);
499 static void PeriodicDPDKDumpCounters(DPDKThreadVars *ptv)
501 static thread_local
SCTime_t last_dump = { 0 };
504 if (current_time.
secs != last_dump.secs) {
505 DPDKDumpCounters(ptv);
506 last_dump = current_time;
516 DPDKThreadVars *ptv = (DPDKThreadVars *)data;
517 ptv->slot = ((
TmSlot *)slot)->slot_next;
518 TmEcode ret = ReceiveDPDKLoopInit(
tv, ptv);
529 rte_eth_rx_burst(ptv->port_id, ptv->queue_id, ptv->received_mbufs, BURST_SIZE);
530 if (RXPacketCountHeuristic(
tv, ptv, nb_rx)) {
534 ptv->pkts += (uint64_t)nb_rx;
535 for (uint16_t i = 0; i < nb_rx; i++) {
536 Packet *p = PacketInitFromMbuf(ptv, ptv->received_mbufs[i]);
538 rte_pktmbuf_free(ptv->received_mbufs[i]);
541 DPDKSegmentedMbufWarning(ptv->received_mbufs[i]);
542 PacketSetData(p, rte_pktmbuf_mtod(p->dpdk_v.mbuf, uint8_t *),
543 rte_pktmbuf_pkt_len(p->dpdk_v.mbuf));
544 if (TmThreadsSlotProcessPkt(ptv->tv, ptv->slot, p) !=
TM_ECODE_OK) {
546 DPDKFreeMbufArray(ptv->received_mbufs, nb_rx - i - 1, i + 1);
551 PeriodicDPDKDumpCounters(ptv);
569 int retval, thread_numa;
570 DPDKThreadVars *ptv = NULL;
573 if (initdata == NULL) {
574 SCLogError(
"DPDK configuration is NULL in thread initialization");
578 ptv =
SCCalloc(1,
sizeof(DPDKThreadVars));
596 ptv->copy_mode = dpdk_config->copy_mode;
597 ptv->checksum_mode = dpdk_config->checksum_mode;
599 ptv->threads = dpdk_config->threads;
600 ptv->intr_enabled = (dpdk_config->flags &
DPDK_IRQ_MODE) ?
true :
false;
601 ptv->port_id = dpdk_config->port_id;
602 ptv->out_port_id = dpdk_config->out_port_id;
603 ptv->port_socket_id = dpdk_config->socket_id;
605 ptv->pkt_mempool = dpdk_config->pkt_mempool;
606 dpdk_config->pkt_mempool = NULL;
608 thread_numa = GetNumaNode();
609 if (thread_numa >= 0 && ptv->port_socket_id != SOCKET_ID_ANY &&
610 thread_numa != ptv->port_socket_id) {
612 SCLogPerf(
"%s: NIC is on NUMA %d, thread on NUMA %d", dpdk_config->iface,
613 ptv->port_socket_id, thread_numa);
616 ptv->workers_sync = dpdk_config->workers_sync;
618 ptv->queue_id = queue_id;
621 if (queue_id == dpdk_config->threads - 1) {
622 retval = rte_eth_dev_start(ptv->port_id);
624 SCLogError(
"%s: error (%s) during device startup", dpdk_config->iface,
625 rte_strerror(-retval));
629 struct rte_eth_dev_info dev_info;
630 retval = rte_eth_dev_info_get(ptv->port_id, &dev_info);
632 SCLogError(
"%s: error (%s) when getting device info", dpdk_config->iface,
633 rte_strerror(-retval));
638 DevicePostStartPMDSpecificActions(ptv, dev_info.driver_name);
640 uint16_t inconsistent_numa_cnt =
SC_ATOMIC_GET(dpdk_config->inconsistent_numa_cnt);
641 if (inconsistent_numa_cnt > 0 && ptv->port_socket_id != SOCKET_ID_ANY) {
642 SCLogWarning(
"%s: NIC is on NUMA %d, %u threads on different NUMA node(s)",
643 dpdk_config->iface, ptv->port_socket_id, inconsistent_numa_cnt);
644 }
else if (ptv->port_socket_id == SOCKET_ID_ANY && rte_socket_count() > 1) {
646 "%s: unable to determine NIC's NUMA node, degraded performance can be expected",
649 if (ptv->intr_enabled) {
650 rte_spinlock_init(&intr_lock[ptv->port_id]);
655 dpdk_config->DerefFunc(dpdk_config);
659 if (dpdk_config != NULL)
660 dpdk_config->DerefFunc(dpdk_config);
666 static void PrintDPDKPortXstats(uint32_t port_id,
const char *port_name)
668 struct rte_eth_xstat *xstats;
669 struct rte_eth_xstat_name *xstats_names;
671 int32_t
len = rte_eth_xstats_get(port_id, NULL, 0);
673 FatalError(
"Error (%s) getting count of rte_eth_xstats failed on port %s",
674 rte_strerror(-
len), port_name);
678 FatalError(
"Failed to allocate memory for the rte_eth_xstat structure");
680 int32_t ret = rte_eth_xstats_get(port_id, xstats,
len);
681 if (ret < 0 || ret >
len) {
683 FatalError(
"Error (%s) getting rte_eth_xstats failed on port %s", rte_strerror(-ret),
686 xstats_names =
SCCalloc(
len,
sizeof(*xstats_names));
687 if (xstats_names == NULL) {
689 FatalError(
"Failed to allocate memory for the rte_eth_xstat_name array");
691 ret = rte_eth_xstats_get_names(port_id, xstats_names,
len);
692 if (ret < 0 || ret >
len) {
695 FatalError(
"Error (%s) getting names of rte_eth_xstats failed on port %s",
696 rte_strerror(-ret), port_name);
698 for (int32_t i = 0; i <
len; i++) {
699 if (xstats[i].value > 0)
700 SCLogPerf(
"Port %u (%s) - %s: %" PRIu64, port_id, port_name, xstats_names[i].name,
713 static void ReceiveDPDKThreadExitStats(
ThreadVars *
tv,
void *data)
717 DPDKThreadVars *ptv = (DPDKThreadVars *)data;
719 if (ptv->queue_id == 0) {
720 struct rte_eth_stats eth_stats;
721 PrintDPDKPortXstats(ptv->port_id, ptv->livedev->dev);
722 retval = rte_eth_stats_get(ptv->port_id, ð_stats);
724 SCLogError(
"%s: failed to get stats (%s)", ptv->livedev->dev, strerror(-retval));
727 SCLogPerf(
"%s: total RX stats: packets %" PRIu64
" bytes: %" PRIu64
" missed: %" PRIu64
728 " errors: %" PRIu64
" nombufs: %" PRIu64,
729 ptv->livedev->dev, eth_stats.ipackets, eth_stats.ibytes, eth_stats.imissed,
730 eth_stats.ierrors, eth_stats.rx_nombuf);
732 SCLogPerf(
"%s: total TX stats: packets %" PRIu64
" bytes: %" PRIu64
" errors: %" PRIu64,
733 ptv->livedev->dev, eth_stats.opackets, eth_stats.obytes, eth_stats.oerrors);
736 DPDKDumpCounters(ptv);
748 DPDKThreadVars *ptv = (DPDKThreadVars *)data;
750 if (ptv->queue_id == 0) {
751 struct rte_eth_dev_info dev_info;
752 int retval = rte_eth_dev_info_get(ptv->port_id, &dev_info);
754 SCLogError(
"%s: error (%s) when getting device info", ptv->livedev->dev,
755 rte_strerror(-retval));
759 DevicePreClosePMDSpecificActions(ptv, dev_info.driver_name);
761 if (ptv->workers_sync) {
762 SCFree(ptv->workers_sync);
766 ptv->pkt_mempool = NULL;