2 ms·
If you're just pushing raw bytes down a socket, you can use sendfile(2) to direct cached data directly to the NIC without copying it to a private buffer first.
by Freaky 11y ago
If you're just pushing raw bytes down a socket, you can use sendfile(2) to direct cached data directly to the NIC without copying it to a private buffer first. This is a pretty big deal at 40Gbps, and Netflix have funded quite a bit of work towards improving it:
https://secure.freshbsd.org/search?project=freebsd&q=netflix+sendfile
TLS kicks all that in the teeth - each encrypted stream needs its own private buffer which has to go in and out of the CPU before it gets anywhere near the NIC. That costs memory bandwidth (a mere 400Gbps with quad-channel DDR3), memory you could have otherwise used as cache (keeping in mind you need to hold onto it until the client ACKs it), and CPU cycles (probably still a decent chunk of overhead even with AES-NI).