aboutsummaryrefslogtreecommitdiff
path: root/sys/netipsec/key_debug.c
diff options
context:
space:
mode:
authorKristof Provost <kp@FreeBSD.org>2022-06-23 20:35:29 +0000
committerKristof Provost <kp@FreeBSD.org>2022-07-19 03:27:20 +0000
commit0361f165f2193a098cfbfeef3a58ec2f1eaac0a1 (patch)
tree8f6082ca374ba9b0b34062781f9c50c98c2a4d51 /sys/netipsec/key_debug.c
parent4eaaacc75535befdb9894cca4e0d8da376328fa4 (diff)
ipsec: replace SECASVAR mtx by rmlock
This mutex is a significant point of contention in the ipsec code, and can be relatively trivially replaced by a read-mostly lock. It does require a separate lock for the replay protection, which we do here by adding a separate mutex. This improves throughput (without replay protection) by 10-15%. MFC after: 3 weeks Sponsored by: Orange Business Services Differential Revision: https://reviews.freebsd.org/D35763
Diffstat (limited to 'sys/netipsec/key_debug.c')
-rw-r--r--sys/netipsec/key_debug.c4
1 files changed, 4 insertions, 0 deletions
diff --git a/sys/netipsec/key_debug.c b/sys/netipsec/key_debug.c
index 4f03d78d434f..58f2d2b614c5 100644
--- a/sys/netipsec/key_debug.c
+++ b/sys/netipsec/key_debug.c
@@ -808,12 +808,15 @@ kdebug_secreplay(struct secreplay *rpl)
{
int len, l;
+ SECREPLAY_LOCK(rpl);
+
IPSEC_ASSERT(rpl != NULL, ("null rpl"));
printf(" secreplay{ count=%lu bitmap_size=%u wsize=%u last=%lu",
rpl->count, rpl->bitmap_size, rpl->wsize, rpl->last);
if (rpl->bitmap == NULL) {
printf(" }\n");
+ SECREPLAY_UNLOCK(rpl);
return;
}
@@ -823,6 +826,7 @@ kdebug_secreplay(struct secreplay *rpl)
printf("%u", (((rpl->bitmap)[len] >> l) & 1) ? 1 : 0);
}
printf(" }\n");
+ SECREPLAY_UNLOCK(rpl);
}
#endif /* IPSEC_DEBUG */