From nobody Thu Feb 20 09:35:26 2025 X-Original-To: dev-commits-src-main@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4Yz7R247Wtz5nc6q; Thu, 20 Feb 2025 09:35:26 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R11" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4Yz7R23Qbyz3L8J; Thu, 20 Feb 2025 09:35:26 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1740044126; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=kQgQy1B3LLyg+M2+8Cpbk2BUlstsRJ3+5vCecXWiQMs=; b=O/OQjvEwW0FqF5tBD77Je8aV650rAstg51fhj6+fXJsB3Hdlr9dfA/aiPEDm+dcj/HDpHW GcGGxjs0Cy/0yS6tjo2mKXXC3v8wPZZxHzvbK3H2sC1qZMGE3b0lBr84unN7HEVcEfqnrV 9+SCOJSPeSzbljLfRHeo2DgnqkIK9OwRGb0200nLd0yPiQA8DLTp7VMsAz1Zrt172LgAwa eek9Rs2xuoR0FcbTTSN2GdCT5GKTNLMwmlGGUg7a7BuxlAgZLloEHD72ueGbAEWOUI+Qyn ej1bNOO+5MpUlnqvRanI4DGHxwwhpUHKl7Bji9Twoox1URjtjG5nhyxFfmJKdw== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1740044126; a=rsa-sha256; cv=none; b=lHeRMV/quas6fuMDVN5VDMRY0UbXx4BlathCC2Fzvr8iB+kYZIRq8SIbJ+GECI/c9ljxSB eLn++BsK2h7ndrqvj6Lfj1ySx4mj32EivN80RasGARD8jepGzlnHq61YousQCMbkyyxHds NQBBaFFSJNrc9LkcbG67Tle66NtIl5hdAf+Q1IkcpIGAvlJgqzTDsFxQMOq/A1ljfXztd5 Rp11xPGHkcaOaDozGSQgoAPhOYTatpYOXS/5lVf9Lj0W9lCWA15vJA/8aHJA5TtHYhKGkz GMLY3eK5FTEYVit7tCQ8oysE8/JN9wt71RtmC7WIzT+LQk9WGduT/Tn0vBF9bA== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1740044126; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=kQgQy1B3LLyg+M2+8Cpbk2BUlstsRJ3+5vCecXWiQMs=; b=WQ6L3FiVDH+ykp47X9JM4eB6Pp5nsoilzfaXUw3uPoQdVQ9WtXuKY7L+cviArHm/xWYYZS kKeqej3nFQ9HbZFbvWNXYXs6qVyIwO8dNjwOV09sqJ34h9aEVMTro4Xie4HCuuny6FNpg0 Kc6gcpR0WKDHTkZ0KOEL/EpZQtGP1dCRgjUbKP70JgB7Se5rBWHqU8Dt3bCG+26UH6eVNo HkDNBfpHPpKu94KRhPkHQApsRbxI3rCy3/zMfWFtwCTjloEVf0KCp/HBJwvqXcj/W1I5nK 392ytey07HxdVmuHHN1OZJ8H+Gu+neblb6P1pWZ5wtWAzxUXSrRqR84GFwhhmg== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id 4Yz7R231jGzmkv; Thu, 20 Feb 2025 09:35:26 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from gitrepo.freebsd.org ([127.0.1.44]) by gitrepo.freebsd.org (8.18.1/8.18.1) with ESMTP id 51K9ZQ2h031999; Thu, 20 Feb 2025 09:35:26 GMT (envelope-from git@gitrepo.freebsd.org) Received: (from git@localhost) by gitrepo.freebsd.org (8.18.1/8.18.1/Submit) id 51K9ZQWh031996; Thu, 20 Feb 2025 09:35:26 GMT (envelope-from git) Date: Thu, 20 Feb 2025 09:35:26 GMT Message-Id: <202502200935.51K9ZQWh031996@gitrepo.freebsd.org> To: src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-main@FreeBSD.org From: Kristof Provost Subject: git: bc830a1acca6 - main - pf: use siphash for pf_lb List-Id: Commit messages for the main branch of the src repository List-Archive: https://lists.freebsd.org/archives/dev-commits-src-main List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-src-main@freebsd.org Sender: owner-dev-commits-src-main@FreeBSD.org MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: kp X-Git-Repository: src X-Git-Refname: refs/heads/main X-Git-Reftype: branch X-Git-Commit: bc830a1acca67b74283d40d7ebdb048f9af3567e Auto-Submitted: auto-generated The branch main has been updated by kp: URL: https://cgit.FreeBSD.org/src/commit/?id=bc830a1acca67b74283d40d7ebdb048f9af3567e commit bc830a1acca67b74283d40d7ebdb048f9af3567e Author: Kristof Provost AuthorDate: 2025-02-12 16:56:45 +0000 Commit: Kristof Provost CommitDate: 2025-02-20 08:25:50 +0000 pf: use siphash for pf_lb for ipv6, we stretch it out a bit, but good enough. ok reyk Obtained from: OpenBSD, tedu , a558d13e2f Sponsored by: Rubicon Communications, LLC ("Netgate") --- sys/netpfil/pf/pf_lb.c | 60 +++++++++++++++++++------------------------------- 1 file changed, 23 insertions(+), 37 deletions(-) diff --git a/sys/netpfil/pf/pf_lb.c b/sys/netpfil/pf/pf_lb.c index 9c2d7b4c71b6..dce0520793fa 100644 --- a/sys/netpfil/pf/pf_lb.c +++ b/sys/netpfil/pf/pf_lb.c @@ -47,6 +47,8 @@ #include #include +#include + #include #include #include @@ -82,19 +84,6 @@ static int pf_get_sport(struct pf_pdesc *, struct pf_krule *, pf_sn_types_t); static bool pf_islinklocal(const sa_family_t, const struct pf_addr *); -#define mix(a,b,c) \ - do { \ - a -= b; a -= c; a ^= (c >> 13); \ - b -= c; b -= a; b ^= (a << 8); \ - c -= a; c -= b; c ^= (b >> 13); \ - a -= b; a -= c; a ^= (c >> 12); \ - b -= c; b -= a; b ^= (a << 16); \ - c -= a; c -= b; c ^= (b >> 5); \ - a -= b; a -= c; a ^= (c >> 3); \ - b -= c; b -= a; b ^= (a << 10); \ - c -= a; c -= b; c ^= (b >> 15); \ - } while (0) - /* * hash function based on bridge_hash in if_bridge.c */ @@ -102,38 +91,35 @@ static void pf_hash(struct pf_addr *inaddr, struct pf_addr *hash, struct pf_poolhashkey *key, sa_family_t af) { - u_int32_t a = 0x9e3779b9, b = 0x9e3779b9, c = key->key32[0]; + SIPHASH_CTX ctx; +#ifdef INET6 + union { + uint64_t hash64; + uint32_t hash32[2]; + } h; +#endif + + _Static_assert(sizeof(*key) >= SIPHASH_KEY_LENGTH, ""); switch (af) { #ifdef INET case AF_INET: - a += inaddr->addr32[0]; - b += key->key32[1]; - mix(a, b, c); - hash->addr32[0] = c + key->key32[2]; + hash->addr32[0] = SipHash24(&ctx, (const uint8_t *)key, + &inaddr->addr32[0], sizeof(inaddr->addr32[0])); break; #endif /* INET */ #ifdef INET6 case AF_INET6: - a += inaddr->addr32[0]; - b += inaddr->addr32[2]; - mix(a, b, c); - hash->addr32[0] = c; - a += inaddr->addr32[1]; - b += inaddr->addr32[3]; - c += key->key32[1]; - mix(a, b, c); - hash->addr32[1] = c; - a += inaddr->addr32[2]; - b += inaddr->addr32[1]; - c += key->key32[2]; - mix(a, b, c); - hash->addr32[2] = c; - a += inaddr->addr32[3]; - b += inaddr->addr32[0]; - c += key->key32[3]; - mix(a, b, c); - hash->addr32[3] = c; + h.hash64 = SipHash24(&ctx, (const uint8_t *)key, + &inaddr->addr32[0], 4 * sizeof(inaddr->addr32[0])); + hash->addr32[0] = h.hash32[0]; + hash->addr32[1] = h.hash32[1]; + /* + * siphash isn't big enough, but flipping it around is + * good enough here. + */ + hash->addr32[2] = ~h.hash32[1]; + hash->addr32[3] = ~h.hash32[0]; break; #endif /* INET6 */ }