From nobody Tue Aug 25 18:17:46 2026 X-Original-To: dev-commits-src-all@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4hTwxR3gJBz6pmJK for ; Tue, 25 Aug 2026 18:17:47 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "YR2" (not verified)) by mx1.freebsd.org (Postfix) with ESMTPS id 4hTwxR0rhvz3n19 for ; Tue, 25 Aug 2026 18:17:47 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1787681867; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=4IzESiTKxkVX36AKibtYoG2dmcy5JacSUr0yT8Swm08=; b=Pe8RTSAmSQW0dxKmxx3JQ0PZzzgnwjdn5oYsr68iNUaeqSdNrA/RTw6WTff2NxB6+umfVh BY3PEhP5tsxUQQ1ETpl0PQpMS8wBdGiReby0WK0Mdfd0+V5Jkkxk3375lw3oId8mPgbcYe XNYh891Su2UM7IUctfT8RbSy528ESLDDMQG3Bwlw4q0AVGQet47MpUBHzbVq9zGfmdZTHW 6tlnfXK0kPnRVITD8bqNz9ZjT68JuU57dddnFI8hm7lEHI8aLUEomdGkVJqga0mClg/Hvi Uo+xXMiwPpORx0JvvHzH2kLzAPzPr5gQN6VvqvM+XBPG+grlmmtfZya8znctgw== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1787681867; a=rsa-sha256; cv=none; b=Y65+mbUj2+VrAMpOMb2j8ul6Ny0OAef7KN3wG+LUXPeeRoYxobpKmgWrGXieOEM+Ea1EPZ r9HCCLlj2KyS0V0VwvdHfkcKLOQ69+Tf7LFPMBf0yGEtI0gV44Qonq3FaGCxhscqmRL+Xw 4lU6tWERDosa+aqTHtu7BYgm5fCkCvCrgQsDDtQfKnghnXGVVr2OdM5Oses+cQZ2tR6AT7 p2wzDkpVF6hdEJKI7oQjqG7FM4TlhNahmLEEjsNOJnD6paOmV16JzR9RP2sc7MTL7fVZ8X 2aJ59qKuYcF0A09eO1cwuxdaVqGeRqsdmFJd3iUzVRt56KSKmptD+fIJzmlfOw== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1787681867; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=4IzESiTKxkVX36AKibtYoG2dmcy5JacSUr0yT8Swm08=; b=ESIzijGyn8Un/eV69nsQ9nhj3yhyXnFJTFJzXRcUzx6t75SiRXFTP5fFarn8/u+UmZyudW h9S4VbXe4F5xE0c3laJtOI+zblbnUaXpJTE6mvqr0l8epDNurTNYvFjHe70+vAptr+mXj7 mTcacwdZqVTlMRAhDBozTI7DW2/YtbMoARZKurWcElcB3+7ZCr10iOBoVe3p1/h57XjovF gctt/jbTPZBmTjsLeHcCmwYsnZcArMpYKFSX5sz13O5aSr6ZtTnS/2qjc9Ncw0+IcEBCro YR54kaYcahanYmmSqLdymqPvn3HOHS9zQvl+oEeJHjZrAnva77y+dmToh+/IIQ== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) by mxrelay.nyi.freebsd.org (Postfix) with ESMTP id 4hTwxQ6rjzz12Y9 for ; Tue, 25 Aug 2026 18:17:46 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from git (uid 1279) (envelope-from git@FreeBSD.org) id 41090 by gitrepo.freebsd.org (DragonFly Mail Agent v0.13+ on gitrepo.freebsd.org); Tue, 25 Aug 2026 18:17:46 +0000 To: src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-main@FreeBSD.org From: Mark Johnston Subject: git: 918fbc947356 - main - pf: Re-optimize state key handling List-Id: Commit messages for all branches of the src repository List-Archive: https://lists.freebsd.org/archives/dev-commits-src-all List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-src-all@freebsd.org Sender: owner-dev-commits-src-all@FreeBSD.org List-Id: List-Post: List-Help: List-Subscribe: List-Unsubscribe: List-Owner: Precedence: list MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: markj X-Git-Repository: src X-Git-Refname: refs/heads/main X-Git-Reftype: branch X-Git-Commit: 918fbc947356c1434760b1bc0deb8558283ce8c5 Auto-Submitted: auto-generated Date: Tue, 25 Aug 2026 18:17:46 +0000 Message-Id: <6a8ddc4a.41090.4df61566@gitrepo.freebsd.org> The branch main has been updated by markj: URL: https://cgit.FreeBSD.org/src/commit/?id=918fbc947356c1434760b1bc0deb8558283ce8c5 commit 918fbc947356c1434760b1bc0deb8558283ce8c5 Author: Mark Johnston AuthorDate: 2026-08-25 18:09:37 +0000 Commit: Mark Johnston CommitDate: 2026-08-25 18:10:36 +0000 pf: Re-optimize state key handling pf states may be looked up using one of two keys: the stack key or the wire key. For states involving address translation, these will be distinct; the stack key describes the addresses seen by the local network stack, and the wire key has the translated addresses. Historically, pf would avoid allocating separate keys if both are identical. This changed in commit fcdb520c1b4e ("pf: nat64") to always allocate separate state key structures. Incidentally, OpenBSD seems to maintain the optimization, but also has an explicit reference count embedded in state keys. The change breaks another optimization: pf_state_key_attach() still uses state key pointer equality to check whether the stack and wire keys are equal, so those checks are always false after the aforementioned commit. Thus we never skip the second key lookup, even when that's possible (i.e., no address translation is involved). So, for some rulesets we're consuming more memory than needed and performing more state key lookups than needed. The behaviour of always looking up the stack key also happens to break some existing rulesets involving RDR and divert-to, which is how I noticed the problem. I think those rulesets effectively worked by accident before, but it seems worth restoring the optimization regardless. Reviewed by: kp MFC after: 2 weeks Fixes: fcdb520c1b4e ("pf: nat64") Sponsored by: OPNsense Sponsored by: Klara, Inc. Differential Revision: https://reviews.freebsd.org/D58922 --- sys/netpfil/pf/pf.c | 25 +++++++++++++++---------- sys/netpfil/pf/pf_lb.c | 11 ++++++++++- 2 files changed, 25 insertions(+), 11 deletions(-) diff --git a/sys/netpfil/pf/pf.c b/sys/netpfil/pf/pf.c index 7dc9d59e8300..9f19f8203cd5 100644 --- a/sys/netpfil/pf/pf.c +++ b/sys/netpfil/pf/pf.c @@ -1988,14 +1988,14 @@ pf_state_key_setup(struct pf_pdesc *pd, u_int16_t sport, u_int16_t dport, (*sk)->proto = pd->proto; (*sk)->af = pd->af; - *nk = pf_state_key_clone(*sk); - if (*nk == NULL) { - uma_zfree(V_pf_state_key_z, *sk); - *sk = NULL; - return (ENOMEM); - } - if (pd->af != pd->naf) { + *nk = pf_state_key_clone(*sk); + if (*nk == NULL) { + uma_zfree(V_pf_state_key_z, *sk); + *sk = NULL; + return (ENOMEM); + } + (*sk)->port[pd->sidx] = pd->osport; (*sk)->port[pd->didx] = pd->odport; @@ -2033,6 +2033,8 @@ pf_state_key_setup(struct pf_pdesc *pd, u_int16_t sport, u_int16_t dport, default: (*nk)->proto = pd->proto; } + } else { + *nk = *sk; } return (0); @@ -6595,7 +6597,8 @@ pf_test_rule(struct pf_krule **rm, struct pf_kstate **sm, } } else { uma_zfree(V_pf_state_key_z, ctx.sk); - uma_zfree(V_pf_state_key_z, ctx.nk); + if (ctx.sk != ctx.nk) + uma_zfree(V_pf_state_key_z, ctx.nk); ctx.sk = ctx.nk = NULL; pf_udp_mapping_release(ctx.udp_mapping); } @@ -6622,7 +6625,8 @@ pf_test_rule(struct pf_krule **rm, struct pf_kstate **sm, cleanup: uma_zfree(V_pf_state_key_z, ctx.sk); - uma_zfree(V_pf_state_key_z, ctx.nk); + if (ctx.sk != ctx.nk) + uma_zfree(V_pf_state_key_z, ctx.nk); pf_udp_mapping_release(ctx.udp_mapping); *reason = ctx.reason; @@ -6958,7 +6962,8 @@ pf_create_state(struct pf_krule *r, struct pf_test_ctx *ctx, csfailed: uma_zfree(V_pf_state_key_z, ctx->sk); - uma_zfree(V_pf_state_key_z, ctx->nk); + if (ctx->sk != ctx->nk) + uma_zfree(V_pf_state_key_z, ctx->nk); for (pf_sn_types_t sn_type=0; sn_typensport, pd->ndport, &ctx->sk, &ctx->nk)) return (PFRES_MEMORY); + if (ctx->sk == ctx->nk) { + ctx->nk = pf_state_key_clone(ctx->sk); + if (ctx->nk == NULL) { + uma_zfree(V_pf_state_key_z, ctx->sk); + ctx->sk = NULL; + return (PFRES_MEMORY); + } + } } switch (nat_action) { @@ -1339,7 +1347,8 @@ out: reason = PFRES_MAX; notrans: uma_zfree(V_pf_state_key_z, ctx->nk); - uma_zfree(V_pf_state_key_z, ctx->sk); + if (ctx->nk != ctx->sk) + uma_zfree(V_pf_state_key_z, ctx->sk); ctx->sk = ctx->nk = NULL; return (reason);