Posts mit dem Label infiniband werden angezeigt. Alle Posts anzeigen
Posts mit dem Label infiniband werden angezeigt. Alle Posts anzeigen

Mittwoch, 10. Januar 2018

Lustrefs: a big performance hit on lfs find after patch of: CVE-2017-5754 CVE-2017-5753 CVE-2017-5715


Disable: sh set-protection.sh 0
time lfs find /lustre/arm2arm/| wc -l
1454706

real    0m14.941s
user    0m1.633s
sys    0m10.770s
 Enable: sh set-protection.sh 0

time lfs find /lustre/arm2arm/| wc -l
1454706

real    0m10.468s
user    0m0.959s
sys    0m5.521s

Let us hope that the situation will change in the near future....

 And the script set-protection.sh content is:

 #!/bin/bash
[ ! -d  /sys/kernel/debug/x86 ]&& mount -t debugfs debugfs /sys/kernel/debug
echo $1 > /sys/kernel/debug/x86/pti_enabled
echo $1 > /sys/kernel/debug/x86/ibrs_enabled
echo $1 > /sys/kernel/debug/x86/ibpb_enabled

Enable or disable Meltdown and Spectre attack protection on CentOS

After kernel and microcode update one can enable or disable the protection:
Enable:
sh ./set-protection.sh 1
or
Disable:
sh ./set-protection.sh 0 

And the script content is:
 #!/bin/bash
[ ! -d  /sys/kernel/debug/x86 ]&& mount -t debugfs debugfs /sys/kernel/debug
echo $1 > /sys/kernel/debug/x86/pti_enabled
echo $1 > /sys/kernel/debug/x86/ibrs_enabled
echo $1 > /sys/kernel/debug/x86/ibpb_enabled
Q:Why should I disable the protection?
A: If you enable the protection you might accounter the performance degradation.
For some tasks one can enable or disable it:
Synthetic test iperf3 shows network performance over IB degradation about x2:
node01:iperf3 -s
node02:iperf3 -c node01.ib

Enabled:

[ ID] Interval           Transfer     Bandwidth       Retr
[  4]   0.00-10.00  sec  8.70 GBytes  7.48 Gbits/sec    0             sender
[  4]   0.00-10.00  sec  8.70 GBytes  7.47 Gbits/sec                  receiver

Disabled:
[ ID] Interval           Transfer     Bandwidth       Retr
[  4]   0.00-10.00  sec  17.6 GBytes  15.1 Gbits/sec    0             sender
[  4]   0.00-10.00  sec  17.6 GBytes  15.1 Gbits/sec                  receiver






[node01~]#ibstat
CA 'mlx4_0'
    CA type: MT4099
    Number of ports: 1
    Firmware version: 2.40.7000
    Hardware version: 0
    Node GUID: 0xXXXXXXX
    System image GUID: 0xXXXXXXX
    Port 1:
        State: Active
        Physical state: LinkUp
        Rate: 56
        Base lid: 338
        LMC: 0
        SM lid: 3
        Capability mask: 0xXXXXXX
        Port GUID: 0xXXXXXXX
        Link layer: InfiniBand

Mittwoch, 17. September 2014

OpenSM lid and more...

On centOS 6.5
yum groupinstall "Infiniband Support"
yum install infiniband-diags

Infiniband diagnostics tools are containing nice "weapons" to eliminate network BUGS.
One of them is:
 saquery - query InfiniBand subnet administration attributes



 it looks like this:

NodeRecord dump:
                lid.....................0x7D
                reserved................0x0
                base_version............0x1
                class_version...........0x1
                node_type...............Switch
                num_ports...............36
                sys_guid................0xf452140300365230
                node_guid...............0xf452140300365230
                port_guid...............0xf452140300365230
                partition_cap...........0x8
                device_id...............0xC738
                revision................0xA2
                port_num................0
                vendor_id...............0x2C9
                NodeDescription.........MF0;switch-cf2826:SX6036/U1