Re: [PATCH net] neighbour: stop using device addresses in hashes
From: Ido Schimmel
Date: Wed Oct 07 2026 - 04:25:25 EST
On Tue, Oct 06, 2026 at 03:41:18PM -0700, Kyle Zeng wrote:
> RTM_GETNEIGHTBL exposes the live hash multiplier and bucket mask. For
> ARP, that multiplier is applied to the IPv4 key XOR hash32_ptr(dev).
> Since hash32_ptr() merely folds the address, timing chosen-key misses
> through the unprivileged SIOCGARP ioctl can reveal the folded address
> of the loopback net_device. NDISC uses the same address-dependent
> first hash term.
>
> Give each net_device an independent random neighbour hash discriminator
> at allocation time and use it in both protocol hashes. Keep it immutable
> so that lookups, insertion and rehashing agree even if the device's
> ifindex or network namespace changes. This retains the cross-namespace
> hash distribution that motivated using the device pointer, without
> putting a kernel address into the observable hash. A dedicated value
> also avoids making a salt used by unrelated network hashes observable.
>
> The existing NDTA_CONFIG fields and neighbour key comparisons can stay
> unchanged. Update the net_device cacheline documentation and assertions
> for the new read-mostly field.
>
> Fixes: b14f243a42c7 ("net: Dont use ifindices in hash fns")
> Assisted-by: Codex:gpt-6-astra
> Signed-off-by: Kyle Zeng <kylebot@xxxxxxxxxx>
> ---
> Documentation/networking/net_cachelines/net_device.rst | 1 +
> include/linux/netdevice.h | 2 ++
> include/net/arp.h | 3 +--
> include/net/ndisc.h | 3 +--
> net/core/dev.c | 4 +++-
> 5 files changed, 8 insertions(+), 5 deletions(-)
Eric,
Given [1], do you think this should be targeted at net-next?
In net-next the neighbour tables are per-netns, so we can return to
hashing based on the device index instead of its pointer. Something like
[2].
[1] https://lore.kernel.org/netdev/CAL4WiiqWwV+8JaYjsHrWDvoSt8Ng01xs9Orv4xhRpFAvhMnD6w@xxxxxxxxxxxxxx/
[2]
diff --git a/include/net/arp.h b/include/net/arp.h
index e932def63d62..9e583624f5b2 100644
--- a/include/net/arp.h
+++ b/include/net/arp.h
@@ -4,7 +4,6 @@
#define _ARP_H
#include <linux/if_arp.h>
-#include <linux/hash.h>
#include <net/neighbour.h>
static inline struct neigh_table *arp_table(struct net *net)
@@ -15,7 +14,7 @@ static inline struct neigh_table *arp_table(struct net *net)
static inline u32 arp_hashfn(const void *pkey, const struct net_device *dev, u32 *hash_rnd)
{
u32 key = *(const u32 *)pkey;
- u32 val = key ^ hash32_ptr(dev);
+ u32 val = key ^ dev->ifindex;
return val * hash_rnd[0];
}
diff --git a/include/net/ndisc.h b/include/net/ndisc.h
index 96e3bb6e83af..a97be2e69409 100644
--- a/include/net/ndisc.h
+++ b/include/net/ndisc.h
@@ -54,7 +54,6 @@ enum {
#include <linux/types.h>
#include <linux/if_arp.h>
#include <linux/netdevice.h>
-#include <linux/hash.h>
#include <net/neighbour.h>
@@ -355,7 +354,7 @@ static inline u32 ndisc_hashfn(const void *pkey, const struct net_device *dev, _
{
const u32 *p32 = pkey;
- return (((p32[0] ^ hash32_ptr(dev)) * hash_rnd[0]) +
+ return (((p32[0] ^ dev->ifindex) * hash_rnd[0]) +
(p32[1] * hash_rnd[1]) +
(p32[2] * hash_rnd[2]) +
(p32[3] * hash_rnd[3]));