[PATCH] wireguard: convert index_hashtable and pubkey_hashtable into rhashtables
someguy at effective-light.com
Thu Sep 9 01:56:12 UTC 2021
On Wed, Sep 8 2021 at 01:27:12 PM +0200, Jason A. Donenfeld
<Jason at zx2c4.com> wrote:
> - What's performance like? Does the abstraction of rhashtable
> introduce overhead? These are used in fast paths -- for every packet
> -- so being quick is important.
Are you familiar with any (micro)benchmarks (for WireGuard) that, you
believe would be particularly informative in assessing the outlined
> - How does this interact with the timing side channel concerns in the
> comment of the file? Will the time required to find an unused index
> leak the number of items in the hash table? Do we need stochastic
> masking? Or is the construction of rhashtable such that we always get
> ball-park same time?
I think the maintainers of rhashtable are best positioned to answer
questions (I have cc'd them).
More information about the WireGuard