MDS Mitigation Impact Four Systems

MDS / Zombie Load mitigation impact tests by Michael Larabel on a future article.

HTML result view exported from: https://openbenchmarking.org/result/1905208-HV-INTELMDS451&rdt&grs.

ProcessorMotherboardChipsetMemoryDiskGraphicsAudioMonitorNetworkOSKernelDesktopDisplay ServerDisplay DriverOpenGLCompilerFile-SystemScreen ResolutionE3-1275 v62 x Xeon 6138 MDS Mitigated MDS Vulnerable MDS Mitigated MDS VulnerableIntel Xeon E3-1275 v6 @ 4.20GHz (4 Cores / 8 Threads)ASUS P10S-M WS (4401 BIOS)Intel Xeon E3-1200 v6/7th16384MBSamsung SSD 970 EVO Plus 500GBIntel HD P630 3GB (1150MHz)Realtek ALC1150LG Ultra HD2 x Intel I210Ubuntu 19.045.0.0-15-generic (x86_64)GNOME Shell 3.32.0X Server 1.20.4modesetting 1.20.44.5 Mesa 19.0.2GCC 8.3.0ext43840x21602 x Intel Xeon Gold 6138 @ 3.70GHz (40 Cores / 80 Threads)TYAN S7106 (V1.02.B20 BIOS)Intel Sky Lake-E DMI3 Registers96256MBSamsung SSD 970 EVO 250GBllvmpipe 93GBVE2282 x Intel I210 + 2 x QLogic cLOM8214 1/10GbE + Mellanox MT264483.3 Mesa 19.0.2 (LLVM 8.0 256 bits)1920x1080OpenBenchmarking.orgCompiler Details- --build=x86_64-linux-gnu --disable-vtable-verify --disable-werror --enable-bootstrap --enable-checking=release --enable-clocale=gnu --enable-default-pie --enable-gnu-unique-object --enable-languages=c,ada,c++,go,brig,d,fortran,objc,obj-c++ --enable-libmpx --enable-libstdcxx-debug --enable-libstdcxx-time=yes --enable-multiarch --enable-multilib --enable-nls --enable-objc-gc=auto --enable-offload-targets=nvptx-none --enable-plugin --enable-shared --enable-threads=posix --host=x86_64-linux-gnu --program-prefix=x86_64-linux-gnu- --target=x86_64-linux-gnu --with-abi=m64 --with-arch-32=i686 --with-default-libstdcxx-abi=new --with-gcc-major-version-only --with-multilib-list=m32,m64,mx32 --with-target-system-zlib --with-tune=generic --without-cuda-driver -v Disk Details- NONE / errors=remount-ro,relatime,rwProcessor Details- Scaling Governor: intel_pstate powersaveJava Details- OpenJDK Runtime Environment (build 11.0.3+7-Ubuntu-1ubuntu219.04.1)Python Details- Python 2.7.16 + Python 3.7.3Security Details- E3-1275 v6: MDS Mitigated: KPTI + l1tf: Mitigation of PTE Inversion; VMX: conditional cache flushes SMT vulnerable + mds: Mitigation of Clear buffers; SMT vulnerable + meltdown: Mitigation of PTI + spec_store_bypass: Mitigation of SSB disabled via prctl and seccomp + spectre_v1: Mitigation of __user pointer sanitization + spectre_v2: Mitigation of Full generic retpoline IBPB: conditional IBRS_FW STIBP: conditional RSB filling - E3-1275 v6: MDS Vulnerable: KPTI + l1tf: Mitigation of PTE Inversion; VMX: conditional cache flushes SMT vulnerable + mds: Vulnerable; SMT vulnerable + meltdown: Mitigation of PTI + spec_store_bypass: Mitigation of SSB disabled via prctl and seccomp + spectre_v1: Mitigation of __user pointer sanitization + spectre_v2: Mitigation of Full generic retpoline IBPB: conditional IBRS_FW STIBP: conditional RSB filling - 2 x Xeon 6138: MDS Mitigated: KPTI + l1tf: Mitigation of PTE Inversion; VMX: conditional cache flushes SMT vulnerable + mds: Mitigation of Clear buffers; SMT vulnerable + meltdown: Mitigation of PTI + spec_store_bypass: Mitigation of SSB disabled via prctl and seccomp + spectre_v1: Mitigation of __user pointer sanitization + spectre_v2: Mitigation of Full generic retpoline IBPB: conditional IBRS_FW STIBP: conditional RSB filling - 2 x Xeon 6138: MDS Vulnerable: KPTI + l1tf: Mitigation of PTE Inversion; VMX: conditional cache flushes SMT vulnerable + mds: Vulnerable; SMT vulnerable + meltdown: Mitigation of PTI + spec_store_bypass: Mitigation of SSB disabled via prctl and seccomp + spectre_v1: Mitigation of __user pointer sanitization + spectre_v2: Mitigation of Full generic retpoline IBPB: conditional IBRS_FW STIBP: conditional RSB filling

openssl: RSA 4096-bit Performancepgbench: Buffer Test - Normal Load - Read Onlybuild-llvm: Time To Compilehackbench: 32 - Processbuild-linux-kernel: Time To Compilectx-clock: Context Switch Timeethr: TCP - Latency - 1ethr: TCP - Latency - 32osbench: Create Threadsgimp: unsharp-maskgimp: auto-levelssockperf: Latency Ping Pongmcperf: Setsockperf: Throughputt-test1: 2mcperf: Getgimp: resizegimp: rotateosbench: Memory Allocationspostmark: Disk Transaction Performancebork: File Encryption Timeosbench: Create Filesosbench: Launch Programsglibc-bench: pthread_onceglibc-bench: ffsllglibc-bench: ffscompilebench: Initial Createstress-ng: System V Message Passingstress-ng: Context Switchingstress-ng: Socket Activitystress-ng: Semaphoresredis: SETpgbench: Buffer Test - Normal Load - Read Writesockperf: Latency Under LoadE3-1275 v62 x Xeon 6138 MDS Mitigated MDS Vulnerable MDS Mitigated MDS Vulnerable1220113823748201131105010.1410.1611.1217.0915.323.08762895464986.521287369.0113.6372.3862506.6113.6048.871.831.831.8353345653281706466382449827722092703449317.9212211201627491631295889.169.1710.5916.6714.942.93788675966266.121423218.8613.4470.2966976.3812.9445.541.711.711.7156572296892009442486756572692158523467015.55784554337515551.9831.7458621.0420.6422.4431.7426.594.66518163855309.269442713.2419.5498.3349018.0516.2456.072.062.062.0550353630472285424118559177924116484941346435.35780357013315446.3431.0434219.8519.9421.6130.8426.194.32509304161639.209944713.0919.3095.8151738.0015.6854.931.941.941.935345732416278449602095818749971654975844036.15OpenBenchmarking.org

OpenSSL

RSA 4096-bit Performance

E3-1275 v62 x Xeon 6138OpenBenchmarking.orgSigns Per Second, More Is BetterOpenSSL 1.1.1RSA 4096-bit PerformanceMDS MitigatedMDS Vulnerable2K4K6K8K10KSE +/- 1.55, N = 3SE +/- 2.29, N = 3SE +/- 21.29, N = 3SE +/- 62.86, N = 312201221784578031. (CC) gcc options: -pthread -m64 -O3 -lssl -lcrypto -ldl

PostgreSQL pgbench

Scaling: Buffer Test - Test: Normal Load - Mode: Read Only

E3-1275 v62 x Xeon 6138OpenBenchmarking.orgTPS, More Is BetterPostgreSQL pgbench 10.3Scaling: Buffer Test - Test: Normal Load - Mode: Read OnlyMDS MitigatedMDS Vulnerable120K240K360K480K600KSE +/- 254.97, N = 3SE +/- 209.97, N = 3SE +/- 2892.47, N = 3SE +/- 3299.92, N = 31138231201625433755701331. (CC) gcc options: -fno-strict-aliasing -fwrapv -O2 -lpgcommon -lpgport -lpq -lpthread -lrt -lcrypt -ldl -lm

Timed LLVM Compilation

Time To Compile

E3-1275 v62 x Xeon 6138OpenBenchmarking.orgSeconds, Fewer Is BetterTimed LLVM Compilation 6.0.1Time To CompileMDS MitigatedMDS Vulnerable160320480640800748749155154

Hackbench

Count: 32 - Type: Process

E3-1275 v62 x Xeon 6138OpenBenchmarking.orgSeconds, Fewer Is BetterHackbenchCount: 32 - Type: ProcessMDS MitigatedMDS Vulnerable4080120160200SE +/- 1.86, N = 3SE +/- 0.90, N = 3SE +/- 0.72, N = 15SE +/- 0.80, N = 12201.00163.0051.9846.341. (CC) gcc options: -lpthread

Timed Linux Kernel Compilation

Time To Compile

E3-1275 v62 x Xeon 6138OpenBenchmarking.orgSeconds, Fewer Is BetterTimed Linux Kernel Compilation 4.18Time To CompileMDS MitigatedMDS Vulnerable306090120150SE +/- 0.82, N = 3SE +/- 0.62, N = 3SE +/- 0.27, N = 15SE +/- 0.33, N = 15131.00129.0031.7431.04

ctx_clock

Context Switch Time

E3-1275 v62 x Xeon 6138OpenBenchmarking.orgClocks, Fewer Is Betterctx_clockContext Switch TimeMDS MitigatedMDS Vulnerable2004006008001000SE +/- 5.03, N = 31050588586342

Ethr

Server Address: localhost - Protocol: TCP - Test: Latency - Threads: 1

E3-1275 v62 x Xeon 6138OpenBenchmarking.orgMicroseconds, Fewer Is BetterEthr 2019-01-02Server Address: localhost - Protocol: TCP - Test: Latency - Threads: 1MDS MitigatedMDS Vulnerable510152025SE +/- 0.03, N = 3SE +/- 0.01, N = 3SE +/- 0.22, N = 15SE +/- 0.27, N = 410.149.1621.0419.85

Ethr

Server Address: localhost - Protocol: TCP - Test: Latency - Threads: 32

E3-1275 v62 x Xeon 6138OpenBenchmarking.orgMicroseconds, Fewer Is BetterEthr 2019-01-02Server Address: localhost - Protocol: TCP - Test: Latency - Threads: 32MDS MitigatedMDS Vulnerable510152025SE +/- 0.04, N = 3SE +/- 0.03, N = 3SE +/- 0.21, N = 3SE +/- 0.17, N = 310.169.1720.6419.94

OSBench

Test: Create Threads

E3-1275 v62 x Xeon 6138OpenBenchmarking.orgus Per Event, Fewer Is BetterOSBenchTest: Create ThreadsMDS MitigatedMDS Vulnerable510152025SE +/- 0.12, N = 7SE +/- 0.11, N = 15SE +/- 0.19, N = 3SE +/- 0.19, N = 311.1210.5922.4421.611. (CC) gcc options: -lm

GIMP

Test: unsharp-mask

E3-1275 v62 x Xeon 6138OpenBenchmarking.orgSeconds, Fewer Is BetterGIMP 2.10.8Test: unsharp-maskMDS MitigatedMDS Vulnerable714212835SE +/- 0.03, N = 3SE +/- 0.02, N = 3SE +/- 0.05, N = 3SE +/- 0.01, N = 317.0916.6731.7430.84

GIMP

Test: auto-levels

E3-1275 v62 x Xeon 6138OpenBenchmarking.orgSeconds, Fewer Is BetterGIMP 2.10.8Test: auto-levelsMDS MitigatedMDS Vulnerable612182430SE +/- 0.09, N = 3SE +/- 0.02, N = 3SE +/- 0.02, N = 3SE +/- 0.05, N = 315.3214.9426.5926.19

Sockperf

Test: Latency Ping Pong

E3-1275 v62 x Xeon 6138OpenBenchmarking.orgusec, Fewer Is BetterSockperf 3.4Test: Latency Ping PongMDS MitigatedMDS Vulnerable1.04852.0973.14554.1945.2425SE +/- 0.02, N = 5SE +/- 0.02, N = 5SE +/- 0.03, N = 25SE +/- 0.03, N = 53.082.934.664.321. (CXX) g++ options: --param -O3 -rdynamic -ldl -lpthread

Memcached mcperf

Method: Set

E3-1275 v62 x Xeon 6138OpenBenchmarking.orgOperations Per Second, More Is BetterMemcached mcperf 1.5.10Method: SetMDS MitigatedMDS Vulnerable20K40K60K80K100KSE +/- 403.15, N = 3SE +/- 557.15, N = 3SE +/- 316.41, N = 3SE +/- 658.78, N = 3762897886751816509301. (CC) gcc options: -O2 -lm -rdynamic

Sockperf

Test: Throughput

E3-1275 v62 x Xeon 6138OpenBenchmarking.orgMessages Per Second, More Is BetterSockperf 3.4Test: ThroughputMDS MitigatedMDS Vulnerable130K260K390K520K650KSE +/- 6082.67, N = 5SE +/- 5413.08, N = 25SE +/- 3753.87, N = 5SE +/- 1726.80, N = 55464985966263855304161631. (CXX) g++ options: --param -O3 -rdynamic -ldl -lpthread

t-test1

Threads: 2

E3-1275 v62 x Xeon 6138OpenBenchmarking.orgSeconds, Fewer Is Bettert-test1 2017-01-13Threads: 2MDS MitigatedMDS Vulnerable3691215SE +/- 0.03, N = 3SE +/- 0.02, N = 3SE +/- 0.07, N = 3SE +/- 0.02, N = 36.526.129.269.201. (CC) gcc options: -pthread

Memcached mcperf

Method: Get

E3-1275 v62 x Xeon 6138OpenBenchmarking.orgOperations Per Second, More Is BetterMemcached mcperf 1.5.10Method: GetMDS MitigatedMDS Vulnerable30K60K90K120K150KSE +/- 336.19, N = 3SE +/- 1267.41, N = 3SE +/- 209.51, N = 3SE +/- 507.49, N = 312873614232194427994471. (CC) gcc options: -O2 -lm -rdynamic

GIMP

Test: resize

E3-1275 v62 x Xeon 6138OpenBenchmarking.orgSeconds, Fewer Is BetterGIMP 2.10.8Test: resizeMDS MitigatedMDS Vulnerable3691215SE +/- 0.10, N = 3SE +/- 0.04, N = 3SE +/- 0.02, N = 3SE +/- 0.10, N = 39.018.8613.2413.09

GIMP

Test: rotate

E3-1275 v62 x Xeon 6138OpenBenchmarking.orgSeconds, Fewer Is BetterGIMP 2.10.8Test: rotateMDS MitigatedMDS Vulnerable510152025SE +/- 0.02, N = 3SE +/- 0.01, N = 3SE +/- 0.02, N = 3SE +/- 0.04, N = 313.6313.4419.5419.30

OSBench

Test: Memory Allocations

E3-1275 v62 x Xeon 6138OpenBenchmarking.orgNs Per Event, Fewer Is BetterOSBenchTest: Memory AllocationsMDS MitigatedMDS Vulnerable20406080100SE +/- 0.14, N = 3SE +/- 0.06, N = 3SE +/- 0.05, N = 3SE +/- 0.22, N = 372.3870.2998.3395.811. (CC) gcc options: -lm

PostMark

Disk Transaction Performance

E3-1275 v62 x Xeon 6138OpenBenchmarking.orgTPS, More Is BetterPostMark 1.51Disk Transaction PerformanceMDS MitigatedMDS Vulnerable14002800420056007000SE +/- 59.33, N = 3SE +/- 35.33, N = 362506697490151731. (CC) gcc options: -O3

Bork File Encrypter

File Encryption Time

E3-1275 v62 x Xeon 6138OpenBenchmarking.orgSeconds, Fewer Is BetterBork File Encrypter 1.4File Encryption TimeMDS MitigatedMDS Vulnerable246810SE +/- 0.07, N = 3SE +/- 0.05, N = 3SE +/- 0.11, N = 3SE +/- 0.02, N = 36.616.388.058.00

OSBench

Test: Create Files

E3-1275 v62 x Xeon 6138OpenBenchmarking.orgus Per Event, Fewer Is BetterOSBenchTest: Create FilesMDS MitigatedMDS Vulnerable48121620SE +/- 0.05, N = 3SE +/- 0.03, N = 3SE +/- 0.03, N = 3SE +/- 0.02, N = 313.6012.9416.2415.681. (CC) gcc options: -lm

OSBench

Test: Launch Programs

E3-1275 v62 x Xeon 6138OpenBenchmarking.orgus Per Event, Fewer Is BetterOSBenchTest: Launch ProgramsMDS MitigatedMDS Vulnerable1326395265SE +/- 0.19, N = 3SE +/- 0.15, N = 3SE +/- 0.50, N = 3SE +/- 0.14, N = 348.8745.5456.0754.931. (CC) gcc options: -lm

glibc bench

Benchmark: pthread_once

E3-1275 v62 x Xeon 6138OpenBenchmarking.orgnanoseconds, Fewer Is Betterglibc bench 1.0Benchmark: pthread_onceMDS MitigatedMDS Vulnerable0.46350.9271.39051.8542.3175SE +/- 0.00, N = 3SE +/- 0.00, N = 3SE +/- 0.00, N = 3SE +/- 0.00, N = 31.831.712.061.94

glibc bench

Benchmark: ffsll

E3-1275 v62 x Xeon 6138OpenBenchmarking.orgnanoseconds, Fewer Is Betterglibc bench 1.0Benchmark: ffsllMDS MitigatedMDS Vulnerable0.46350.9271.39051.8542.3175SE +/- 0.00, N = 3SE +/- 0.00, N = 3SE +/- 0.00, N = 3SE +/- 0.00, N = 31.831.712.061.94

glibc bench

Benchmark: ffs

E3-1275 v62 x Xeon 6138OpenBenchmarking.orgnanoseconds, Fewer Is Betterglibc bench 1.0Benchmark: ffsMDS MitigatedMDS Vulnerable0.46130.92261.38391.84522.3065SE +/- 0.00, N = 3SE +/- 0.00, N = 3SE +/- 0.00, N = 3SE +/- 0.00, N = 31.831.712.051.93

Compile Bench

Test: Initial Create

E3-1275 v62 x Xeon 6138OpenBenchmarking.orgMB/s, More Is BetterCompile Bench 0.6Test: Initial CreateMDS MitigatedMDS Vulnerable120240360480600SE +/- 3.42, N = 3SE +/- 9.09, N = 3SE +/- 2.22, N = 3SE +/- 5.06, N = 3533565503534

Stress-NG

Test: System V Message Passing

E3-1275 v62 x Xeon 6138OpenBenchmarking.orgBogo Ops/s, More Is BetterStress-NG 0.07.26Test: System V Message PassingMDS MitigatedMDS Vulnerable1.5M3M4.5M6M7.5MSE +/- 206175.33, N = 12SE +/- 97616.61, N = 3SE +/- 51841.16, N = 15SE +/- 78632.05, N = 345653287229689536304757324161. (CC) gcc options: -O2 -std=gnu99 -lm -lz -lcrypt -lrt -lpthread -laio -lc

Stress-NG

Test: Context Switching

E3-1275 v62 x Xeon 6138OpenBenchmarking.orgBogo Ops/s, More Is BetterStress-NG 0.07.26Test: Context SwitchingMDS MitigatedMDS Vulnerable6M12M18M24M30MSE +/- 5690.93, N = 3SE +/- 19889.50, N = 3SE +/- 137846.16, N = 3SE +/- 900326.49, N = 151706466200944222854241278449601. (CC) gcc options: -O2 -std=gnu99 -lm -lz -lcrypt -lrt -lpthread -laio -lc

Stress-NG

Test: Socket Activity

E3-1275 v62 x Xeon 6138OpenBenchmarking.orgBogo Ops/s, More Is BetterStress-NG 0.07.26Test: Socket ActivityMDS MitigatedMDS Vulnerable4K8K12K16K20KSE +/- 48.24, N = 3SE +/- 95.69, N = 15SE +/- 288.42, N = 3SE +/- 193.14, N = 123824486718559209581. (CC) gcc options: -O2 -std=gnu99 -lm -lz -lcrypt -lrt -lpthread -laio -lc

Stress-NG

Test: Semaphores

E3-1275 v62 x Xeon 6138OpenBenchmarking.orgBogo Ops/s, More Is BetterStress-NG 0.07.26Test: SemaphoresMDS MitigatedMDS Vulnerable1.2M2.4M3.6M4.8M6MSE +/- 22369.03, N = 3SE +/- 27858.47, N = 3SE +/- 27975.58, N = 15SE +/- 22447.85, N = 1549827725657269177924118749971. (CC) gcc options: -O2 -std=gnu99 -lm -lz -lcrypt -lrt -lpthread -laio -lc

Redis

Test: SET

E3-1275 v62 x Xeon 6138OpenBenchmarking.orgRequests Per Second, More Is BetterRedis 4.0.8Test: SETMDS MitigatedMDS Vulnerable500K1000K1500K2000K2500KSE +/- 23688.81, N = 6SE +/- 16368.00, N = 3SE +/- 24791.61, N = 15SE +/- 28419.85, N = 1520927032158523164849416549751. (CC) gcc options: -ggdb -rdynamic -lm -ldl -pthread

PostgreSQL pgbench

Scaling: Buffer Test - Test: Normal Load - Mode: Read Write

E3-1275 v62 x Xeon 6138OpenBenchmarking.orgTPS, More Is BetterPostgreSQL pgbench 10.3Scaling: Buffer Test - Test: Normal Load - Mode: Read WriteMDS MitigatedMDS Vulnerable3K6K9K12K15KSE +/- 60.22, N = 5SE +/- 18.33, N = 3SE +/- 24.44, N = 3SE +/- 811.59, N = 12449346701346484401. (CC) gcc options: -fno-strict-aliasing -fwrapv -O2 -lpgcommon -lpgport -lpq -lpthread -lrt -lcrypt -ldl -lm

Sockperf

Test: Latency Under Load

E3-1275 v62 x Xeon 6138OpenBenchmarking.orgusec, Fewer Is BetterSockperf 3.4Test: Latency Under LoadMDS MitigatedMDS Vulnerable816243240SE +/- 1.54, N = 20SE +/- 1.32, N = 20SE +/- 0.82, N = 20SE +/- 1.35, N = 2117.9215.5535.3536.151. (CXX) g++ options: --param -O3 -rdynamic -ldl -lpthread


Phoronix Test Suite v10.8.5