login vsi company logo login vsi company logo 250x40

Testing Meltdown and Spectre patches: VMware ESXI v1

Meltdown and Spectre

In my previous Blogpost about testing Meltdown and Spectre patches, the results focused on XenServer. In this blogpost we are going to talk about ESXI and the performance impact we measured in our labs.

After all the news and hectic around Meltdown and Spectre it seems things are calming down a bit. Recent talks are focusing more on next generation exploits rather than the performance impact. The Login VSI Meltdown and Spectre emergency edition has been a great success and helped many of our customers, vendors and community friends. I’d like to share some results from our internal performance validation labs where I’ve conducted tests on a large number of operating systems measuring the impact of patches on the OS, Hypervisor and BIOS level. Please keep in mind that this is a lab environment, results will vary on your own systems.

I focused on Windows Server 2012R2 and Windows Server 2016 for these tests and started with a clean image that was optimized for performance with VMware OSOT. With every test I added a new layer of patches, adding the layers of mitigation one at a time.

Meltdown & Spectre

Applied Patches:

ScenarioAdded Patch
Clean Windows 2012R2 feb. 2018 updates / Windows Server 2016 (Update feb 2018)
Microsoft Patch (MS) KB4056898 for 2012R2, KB4056890 for 2016
Microsoft & Hypervisor Patch (MS-HV) ESXi650-201803001 (52456)
Microsoft, Hypervisor and Microcode Patch (MS-HV-MCU) Dell R730 Bios ver. 2.7.1

The results

When we look at the results for Microsoft Server 2016 we see that the results are like the 2012R2 tests. But the impact is just slightly less (about 15-20%).

Of course as always, these tests are done in our lab and results may vary upon testing your own hardware and software combination.

VSIMax VMware
VSImax Results, higher is better

VSIBase VMware
VSIBase results, lower is better

Percentile Impact 2016 VMware
2016 % Impact closest to 0 is best

Conclusion

We’ve learned that Hypervisors react different to Meltdown and Spectre, versions, vendors and the order of patching will have an impact on how performance is affected. Its therefore recommended to run simulations in your own environment as mileage will vary. In the blogpost written by my colleague Blair we do see that the impact on Server 2016 is less than we see on Server 2012R2.

This raises again a number of new questions:

  1. Which level of the Meltdown and Spectre patches impact the ESXI hypervisor the most?
  2. How does optimization of the VM influence the test results?
  3. How do other hypervisors behave after implementing the Meltdown and Spectre patches?

What’s next

These tests were performed with Windows Server operating systems. I am currently switching focus to Client operating systems namely Windows 10 and Windows 7 to see what kind of impact we can deduce here.   

About the Lab used for these tests

Automate, automate, automate. In our VDILIKEAPRO test lab we have minimized human interaction (and thus error) by making sure all processes are executed fully automatic. For example the base images are created using the Microsoft Deployment Toolkit where as a next step PowerShell magic (thanks Henk & Sonny!) takes over and automatically clones the VM’s 6 times on a single host, prepares them for use, and runs 10 automated test cycles. Results are then averaged ignoring the first run.

All the connections to the target machines are done using the RDP protocol. And the Login VSI default workload for this type of testing, the Knowledge Worker workload, was used for all tests.

VDILIKEAPRO Laboratories

Physical Virtual Infrastructure

About the author

Tom Willemsen is a Support Engineer at Login VSI and helps customers and gives advice about testing with Login VSI. He loves to travel, read about history, and see different cultures. In his free time, Tom likes to game and watch movies.


Tags: VSImax, Spectre, Meltdown, VSIbase

Popular Blogs

Windows Virtual Desktop - Update - December 2019

Windows Virtual Desktop Enhanced in the Latest Update

A lot has already been written about WVD in the last months. And while I had my initial concerns on this service many people are suggesting that they are willing to move to a platform like WVD in the next two years. Continue Reading
Login VSI - Press Release - Login VSI Releases Login Enterprise 4.0

[Press Release] Login VSI Releases Login Enterprise 4.0

Login VSI Releases Login Enterprise 4.0 New Application Load Testing Functionality Maximizes End-User Experience Continue Reading
Login VSI and Ymor Form Partnership to Deliver Performance Improvement to Business-Critical Applications

[Press Release] Login VSI and Ymor Form Partnership to Deliver Performance Improvement to Business-Critical Applications

The partnership offers a total solution for enterprise organizations to monitor and test business-critical applications from end-to-end via VDI or in the Cloud. Ymor offers various monitoring solutions, used to test and monitor the performance of critical business chains from end-to-end. In VDI environments, Ymor can now offer the monitoring solutions of Login VSI. Continue Reading
[Press Release] IGEL Expands Alliance with Login VSI; Integrates Login Enterprise into IGEL OS 11.03

[Press Release] IGEL Expands Alliance with Login VSI

Integrating Login Enterprise into IGEL OS 11.03 The combined solution enables IT organizations to leverage their IGEL infrastructure to continuously test the performance and availability of virtual and cloud workspaces. Continue Reading
Login VSI - Validating Your Remote Infrastructure at Scale - Man at Desk

Enabling Your Remote Workforce

Given recent global events, a majority of my users may need to work remotely. Many of our customers have been asking us if we can help them test the user-experience for their remote workforce, as well as the infrastructure that delivers it. We have seen requests range from the quality of the remote user-experience to the ability of their VPN to handle the throughput of a large volume of concurrent connections. Continue Reading
Login VSI Releases Login Enterprise 4.1

[Press Release] Login VSI Releases Login Enterprise 4.1

Login VSI Releases Login Enterprise 4.1 Comprehensive Testing Platform Ensures Business Continuity Continue Reading