Cyril Soldani

dblp:162/5286 · DBLP profile ↗
← Back
6ranked-venue papers
0as first author
4since 2021 · last 2025
0009-0004-9117-9508ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 3 · 3 since 2021Computer networks · 2 · 1 since 2021
YearPublicationVenuePosition
2025 Memory Matters: Load-Time Deduplication for Unikernels
abstract
Unikernels offer strong isolation and performance benefits over traditional virtual machines, but their specialized, statically linked design complicates memory deduplication—particularly in multi-tenant environments. Traditional approaches like Kernel Samepage Merging (KSM) struggle with convergence delays, high CPU usage, and unpredictable memory savings. Dynamic linking improves memory reuse but compromises performance, simplicity, and security. We present Spacer-SLT, a novel load time deduplication mechanism that eliminates the need for memory scanners. Spacer-SLT extracts common libraries into a shared pool and uses a custom Firecracker-based loader to enable instant, deterministic memory deduplication at launch time. Unlike KSM, it introduces no runtime overhead and maintains the benefits of static linking, including performance and reduced attack surface.
Gaulthier Gain, Benoit Knott, Cyril Soldani, Laurent Mathy
SoCC3
2022 Want more unikernels?: inflate them!
abstract
Unikernels are on the rise in the cloud. These lightweight virtual machines (VMs) specialized to a single application offer the same level of isolation as full-blown VMs, while providing performance superior to standard Linux-based VMs or even to containers. However, their inherent specialization renders memory deduplication ineffective, causing unikernels, in practice, to consume more memory than their small memory footprint would suggest. This makes them less advantageous when thousands of SaaS and/or FaaS unikernels instances have to run on the same server.
Gaulthier Gain, Cyril Soldani, Felipe Huici, Laurent Mathy
SoCC2
2021 Unikraft: fast, specialized unikernels the easy way
abstract
Unikernels are famous for providing excellent performance in terms of boot times, throughput and memory consumption, to name a few metrics. However, they are infamous for making it hard and extremely time consuming to extract such performance, and for needing significant engineering effort in order to port applications to them. We introduce Unikraft, a novel micro-library OS that (1) fully modularizes OS primitives so that it is easy to customize the unikernel and include only relevant components and (2) exposes a set of composable, performance-oriented APIs in order to make it easy for developers to obtain high performance.
Simon Kuenzer, Vlad-Andrei Badoiu, Hugo Lefeuvre, Sharan Santhanam, Alexander Jung 0002, Gaulthier Gain, Cyril Soldani, Costin Lupu, Stefan Teodorescu, Costi Raducanu, Cristian Banu, Laurent Mathy, Razvan Deaconescu, Costin Raiciu, Felipe Huici
EuroSys7
2021 Combined Stateful Classification and Session Splicing for High-Speed NFV Service Chaining
abstract
Network functionssuch as firewalls, NAT, DPI, content-aware optimizers, and load-balancers are increasingly realized as software to reduce costs and enable outsourcing. To meet performance requirements thesevirtualnetwork functions (VNFs) often bypass the kernel and use their own user-space networking stack. A naïve realization of a chain of VNFs will exchange raw packets, leading to many redundant operations, wasting resources. In this work, we design a system to execute a pipeline of VNFs. We provide the user facilities to define (i) a traffic class of interest for the VNF, (ii) a session to group the packets (such as the TCP 4-tuple), and (iii) the amount of space per session. The system synthesizes a classifier and builds an efficient flow table that when possible will automatically be partially offloaded and accelerated by the network interface. We utilize an abstract view of flows to support seamless inspection and modification of the content of any flow (such as TCP or HTTP). By applying only surgical modifications to the protocol headers, we avoid the need for a complex, hard-to-maintain user-space TCP stack and can chain multiple VNFswithout re-constructing the stream multiple times, allowing up to 5x improvement over standard approaches.
Tom Barbette, Cyril Soldani, Laurent Mathy
IEEE/ACM Trans. Netw.2
2018 Building a chain of high-speed VNFs in no time: Invited Paper
abstract
To cope with the growing performance needs of appliances in datacenters or the network edge, current middle-box functionalities such as firewalls, NAT, DPI, content-aware optimizers or load-balancers are often implemented on multiple (perhaps virtual) machines. In this work, we design a system able to run a pipeline of VNFs with a high level of parallelism to handle many flows. We provide the user facilities to define the traffic class of interest for the VNF, a definition of session to group the packets such as the TCP 4-tuples, and the amount of space per sessions. The system will then synthesize the classification and build a unique, efficient flow table. We build an abstract view of flows and use it to implement support for seamless inspection and modification of the content of any flow (such as TCP or HTTP), automatically reflecting a consistent view, across layers, of flows modified on-the-fly. Our prototype gives rise to a user-space software NFV data-plane enabling easy implementation of middlebox functionalities, as well as the deployment of complex scenarios. Our prototype implementation is able to handle our testbed limit of -34 Gbps of HTTP requests (for 8-KB files) through a service chain of multiples stateful VNFs, on a single Xeon core.
Tom Barbette, Cyril Soldani, Romain Gaillard, Laurent Mathy
HPSR2
2015 Fast Userspace Packet Processing
abstract
In recent years, we have witnessed the emergence of high speed packet I/O frameworks, bringing unprecedented network performance to userspace. Using the Click modular router, we rst review and quantitatively compare several such packet I/O frameworks, showing their superiority to kernel-based forwarding. We then reconsider the issue of software packet processing, in the context of modern commodity hardware with hardware multi-queues, multi-core processors and non-uniform memory access. Through a combination of existing techniques and improvements of our own, we derive modern general principles for the design of software packet processors. Our implementation of a fast packet processor framework, integrating a faster Click with both Netmap and DPDK, ex-hibits up-to about 2.3x speed-up compared to other software implementations, when used as an IP router.
Tom Barbette, Cyril Soldani, Laurent Mathy
ANCS2