diff options
| author | Kristof Provost <kp@FreeBSD.org> | 2022-06-23 20:35:29 +0000 |
|---|---|---|
| committer | Kristof Provost <kp@FreeBSD.org> | 2022-07-19 03:27:20 +0000 |
| commit | 0361f165f2193a098cfbfeef3a58ec2f1eaac0a1 (patch) | |
| tree | 8f6082ca374ba9b0b34062781f9c50c98c2a4d51 /sys/netipsec/key_debug.c | |
| parent | 4eaaacc75535befdb9894cca4e0d8da376328fa4 (diff) | |
ipsec: replace SECASVAR mtx by rmlock
This mutex is a significant point of contention in the ipsec code, and
can be relatively trivially replaced by a read-mostly lock.
It does require a separate lock for the replay protection, which we do
here by adding a separate mutex.
This improves throughput (without replay protection) by 10-15%.
MFC after: 3 weeks
Sponsored by: Orange Business Services
Differential Revision: https://reviews.freebsd.org/D35763
Diffstat (limited to 'sys/netipsec/key_debug.c')
| -rw-r--r-- | sys/netipsec/key_debug.c | 4 |
1 files changed, 4 insertions, 0 deletions
diff --git a/sys/netipsec/key_debug.c b/sys/netipsec/key_debug.c index 4f03d78d434f..58f2d2b614c5 100644 --- a/sys/netipsec/key_debug.c +++ b/sys/netipsec/key_debug.c @@ -808,12 +808,15 @@ kdebug_secreplay(struct secreplay *rpl) { int len, l; + SECREPLAY_LOCK(rpl); + IPSEC_ASSERT(rpl != NULL, ("null rpl")); printf(" secreplay{ count=%lu bitmap_size=%u wsize=%u last=%lu", rpl->count, rpl->bitmap_size, rpl->wsize, rpl->last); if (rpl->bitmap == NULL) { printf(" }\n"); + SECREPLAY_UNLOCK(rpl); return; } @@ -823,6 +826,7 @@ kdebug_secreplay(struct secreplay *rpl) printf("%u", (((rpl->bitmap)[len] >> l) & 1) ? 1 : 0); } printf(" }\n"); + SECREPLAY_UNLOCK(rpl); } #endif /* IPSEC_DEBUG */ |
