From: Eric Wong Date: Mon, 24 Jun 2019 02:52:44 +0000 (+0000) Subject: daemon: use SSL_MODE_RELEASE_BUFFERS X-Git-Tag: v1.2.0~156^2~16 X-Git-Url: http://www.git.stargrave.org/?a=commitdiff_plain;h=87a03babc14247d4eac489beb95abba47cf4f358;p=public-inbox.git daemon: use SSL_MODE_RELEASE_BUFFERS 34K per idle connection adds up to large amounts of memory; especially with the speed of malloc nowadays compared to the cost of cache misses or worse, swapping. --- diff --git a/lib/PublicInbox/Daemon.pm b/lib/PublicInbox/Daemon.pm index 55103f40..c4481555 100644 --- a/lib/PublicInbox/Daemon.pm +++ b/lib/PublicInbox/Daemon.pm @@ -59,6 +59,16 @@ sub accept_tls_opt ($) { } my $ctx = IO::Socket::SSL::SSL_Context->new(%ctx_opt) or die 'SSL_Context->new: '.PublicInbox::TLS::err(); + + # save ~34K per idle connection (cf. SSL_CTX_set_mode(3ssl)) + # RSS goes from 346MB to 171MB with 10K idle NNTPS clients on amd64 + # cf. https://rt.cpan.org/Ticket/Display.html?id=129463 + my $mode = eval { Net::SSLeay::MODE_RELEASE_BUFFERS() }; + if ($mode && $ctx->{context}) { + eval { Net::SSLeay::CTX_set_mode($ctx->{context}, $mode) }; + warn "W: $@ (setting SSL_MODE_RELEASE_BUFFERS)\n" if $@; + } + { SSL_server => 1, SSL_startHandshake => 0, SSL_reuse_ctx => $ctx }; }