Bug 202092 - IPsec replay counter is probably not MP safe
Summary: IPsec replay counter is probably not MP safe
Status: New
Alias: None
Product: Base System
Classification: Unclassified
Component: kern (show other bugs)
Version: CURRENT
Hardware: Any Any
: --- Affects Only Me
Assignee: George V. Neville-Neil
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2015-08-04 20:21 UTC by John-Mark Gurney
Modified: 2019-05-20 10:37 UTC (History)
1 user (show)

See Also:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description John-Mark Gurney freebsd_committer freebsd_triage 2015-08-04 20:21:13 UTC
It is likely that the IPsec replay counters are not MP safe.  There is a lock in the SA, but not around the replay counters.  This could cause issues w/ high PPS and RSS which is becoming more common.
Comment 1 Andrey V. Elsukov freebsd_committer freebsd_triage 2019-05-20 10:37:32 UTC
It seems this is no longer the problem in the current code.