OpenVPN
sid_hash.h
Go to the documentation of this file.
1/*
2 * OpenVPN -- An application to securely tunnel IP networks
3 * over a single TCP/UDP port, with support for SSL/TLS-based
4 * session authentication and key exchange,
5 * packet encryption, packet authentication, and
6 * packet compression.
7 *
8 * Copyright (C) 2026 OpenVPN Inc <sales@openvpn.net>
9 * Copyright (C) 2026 Arne Schwabe <arne@rfc2549.org>
10 *
11 *
12 * This program is free software; you can redistribute it and/or modify
13 * it under the terms of the GNU General Public License version 2
14 * as published by the Free Software Foundation.
15 *
16 * This program is distributed in the hope that it will be useful,
17 * but WITHOUT ANY WARRANTY; without even the implied warranty of
18 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
19 * GNU General Public License for more details.
20 *
21 * You should have received a copy of the GNU General Public License along
22 * with this program; if not, see <https://www.gnu.org/licenses/>.
23 */
24
25#ifndef SID_HASH_H
26#define SID_HASH_H
27
28#include "session_id.h"
29#include "multi.h"
30#include "list.h"
31#include "siphash.h"
32
33inline static void
34multi_hash_sid_add(struct multi_context *m, const struct session_id *sid,
35 struct multi_instance *mi)
36{
37 /* This must only be called if the multi instance is not already present
38 * in the hash table */
40
41 mi->sid_hashed_value = *sid;
42
43 const uint64_t hv = hash_value(m->sid_hash, &mi->sid_hashed_value);
44 struct hash_bucket *bucket = hash_bucket(m->sid_hash, hv);
45 hash_add_fast(m->sid_hash, bucket, &mi->sid_hashed_value, hv, mi);
47}
48
49static inline struct hash_element *
50multi_hash_sid_lookup(struct multi_context *m, const struct session_id *sid)
51{
52 const uint64_t sid_hv = hash_value(m->sid_hash, sid);
53 struct hash_bucket *sid_bucket = hash_bucket(m->sid_hash, sid_hv);
54 struct hash_element *he_sid = hash_lookup_fast(m->sid_hash, sid_bucket, sid, sid_hv);
55 return he_sid;
56}
57
58inline static bool
59multi_hash_sid_remove(struct multi_context *m, const struct session_id *sid)
60{
61 const uint64_t sid_hv = hash_value(m->sid_hash, sid);
62 struct hash_bucket *sid_bucket = hash_bucket(m->sid_hash, sid_hv);
63 struct hash_element *he_sid = hash_lookup_fast(m->sid_hash, sid_bucket, sid, sid_hv);
64 if (he_sid)
65 {
66 struct multi_instance *mi = he_sid->value;
67 ASSERT(hash_remove_fast(m->sid_hash, sid_bucket, sid, sid_hv));
70 return true;
71 }
72 else
73 {
74 return false;
75 }
76}
77
78/* hashing the session. As the struct is just an 8 byte array
79 * hashing is straight forward */
80static inline uint64_t
81session_id_hash_function(const void *key, const uint8_t hash_key[HASH_KEY_LEN])
82{
83 return siphash_hash_func(key, sizeof(struct session_id), hash_key);
84}
85
86/* wrapper for session_id_equal to have the void* arguments that the
87 * hash map requires */
88static inline bool
89session_id_hash_equal(const void *sid1, const void *sid2)
90{
91 return session_id_equal((struct session_id *)sid1, (struct session_id *)sid2);
92}
93
94#endif
bool hash_remove_fast(struct hash *hash, struct hash_bucket *bucket, const void *key, uint64_t hv)
Definition list.c:109
struct hash_element * hash_lookup_fast(struct hash *hash, struct hash_bucket *bucket, const void *key, uint64_t hv)
Definition list.c:81
#define HASH_KEY_LEN
Definition list.h:53
static void hash_add_fast(struct hash *hash, struct hash_bucket *bucket, const void *key, uint64_t hv, void *value)
Definition list.h:149
static struct hash_bucket * hash_bucket(struct hash *hash, uint64_t hv)
Definition list.h:125
static uint64_t hash_value(const struct hash *hash, const void *key)
Definition list.h:107
Header file for server-mode related structures and functions.
static void multi_instance_dec_refcount(struct multi_instance *mi)
Definition multi.h:481
static void multi_instance_inc_refcount(struct multi_instance *mi)
Definition multi.h:475
#define CLEAR(x)
Definition basic.h:32
#define ASSERT(x)
Definition error.h:221
static bool session_id_equal(const struct session_id *sid1, const struct session_id *sid2)
Definition session_id.h:47
static bool session_id_defined(const struct session_id *sid1)
Definition session_id.h:53
static uint64_t session_id_hash_function(const void *key, const uint8_t hash_key[HASH_KEY_LEN])
Definition sid_hash.h:81
static bool session_id_hash_equal(const void *sid1, const void *sid2)
Definition sid_hash.h:89
static void multi_hash_sid_add(struct multi_context *m, const struct session_id *sid, struct multi_instance *mi)
Definition sid_hash.h:34
static bool multi_hash_sid_remove(struct multi_context *m, const struct session_id *sid)
Definition sid_hash.h:59
static struct hash_element * multi_hash_sid_lookup(struct multi_context *m, const struct session_id *sid)
Definition sid_hash.h:50
uint64_t siphash_hash_func(const uint8_t *k, uint32_t length, const uint8_t hash_key[SIPHASH_KEY_SIZE])
Wrapper of the siphash function to be able to use it in the hash map.
Definition siphash.c:37
void * value
Definition list.h:41
Container for unidirectional cipher and HMAC key material.
Definition crypto.h:152
Main OpenVPN server state structure.
Definition multi.h:170
struct hash * sid_hash
TLS sessions indexed by the peer's session id.
Definition multi.h:181
Server-mode state structure for one single VPN tunnel.
Definition multi.h:102
struct session_id sid_hashed_value
If this is multi_instance is hashed in the sid lookup table the session id here is a non-null session...
Definition multi.h:141