From cb19d80e3a183f5aaa354f7a736a297b3ae26160 Mon Sep 17 00:00:00 2001 From: ergdevops <115262164+ergdevops@users.noreply.github.com> Date: Mon, 24 Aug 2026 22:49:39 +0530 Subject: [PATCH] feat(allocator): enable jemalloc on aarch64-unknown-linux-gnu jemalloc is currently compiled in as the global allocator only for x86_64-unknown-linux-gnu. On arm64 the proxy silently falls back to glibc malloc, which sizes its per-CPU arena budget from the host core count rather than the cgroup limit and in practice does not return freed memory to the OS. Proxy RSS on arm64 therefore ratchets up to peak load and stays there until the pod restarts. Measured against the release/v2.311.0 tag (shipped with edge-25.8.1), patched as in this commit and built natively on arm64, on a Graviton cluster with ~300 pooled HTTP/2 connections per pod: closing all connections released no RSS at all with glibc, and 211MB -> ~20MB (-91%) with jemalloc. Same proxy version, cluster and traffic in both arms; the allocator was the only variable. This was on jemalloc's stock settings -- tikv-jemalloc-sys builds with --with-jemalloc-prefix=_rjem_, so the allocator reads _RJEM_MALLOC_CONF and ignores unprefixed MALLOC_CONF. The x86_64-only gate dates to #1321, which restricted it to the only platform the then-current jemallocator readme listed as fully tested. tikv-jemallocator supports aarch64-unknown-linux-gnu, and deny.toml already audits that target, so widen the gate to cover it. Cargo.lock is unchanged. Verified on main for x86_64: builds, tests pass, and the binary still links jemalloc as its active allocator. An aarch64 cross-build in CI conditions is not verified here. Signed-off-by: ergdevops <115262164+ergdevops@users.noreply.github.com> --- linkerd2-proxy/Cargo.toml | 3 +++ linkerd2-proxy/src/main.rs | 6 +++++- 2 files changed, 8 insertions(+), 1 deletion(-) diff --git a/linkerd2-proxy/Cargo.toml b/linkerd2-proxy/Cargo.toml index 6608529ca8..92638216c9 100644 --- a/linkerd2-proxy/Cargo.toml +++ b/linkerd2-proxy/Cargo.toml @@ -32,5 +32,8 @@ tracing = { workspace = true } [target.x86_64-unknown-linux-gnu.dependencies] tikv-jemallocator = "0.6" +[target.aarch64-unknown-linux-gnu.dependencies] +tikv-jemallocator = "0.6" + [lints.rust] unexpected_cfgs = { level = "warn", check-cfg = ['cfg(tokio_unstable)'] } diff --git a/linkerd2-proxy/src/main.rs b/linkerd2-proxy/src/main.rs index cd7dc86add..75371e82ab 100644 --- a/linkerd2-proxy/src/main.rs +++ b/linkerd2-proxy/src/main.rs @@ -9,7 +9,11 @@ use linkerd_signal as signal; use tokio::{sync::mpsc, time}; use tracing::{debug, info, warn}; -#[cfg(all(target_os = "linux", target_arch = "x86_64", target_env = "gnu"))] +#[cfg(all( + target_os = "linux", + any(target_arch = "x86_64", target_arch = "aarch64"), + target_env = "gnu" +))] #[global_allocator] static GLOBAL: tikv_jemallocator::Jemalloc = tikv_jemallocator::Jemalloc;