Wow, collisions against the best non-cryptographic hash functions that are independent of seed... color me impressed! This does then seem to strongly suggest that a cryptographic hash function is the only way to defend against hash flooding attacks. Props to the SipHash authors, this is some ground-breaking work.
$ time ./citycollisions 1000000 > /dev/null
real 0m0.904s
user 0m0.439s
sys 0m0.008s
$ ./citycollisions 3
128-bit key 741b848b0065aec04bb25b26ca2c3e9
CityHash64( 8e69324ad2a005ff2148534148202020, 16 ) = d3290c3d600b8add
CityHash64( 7ae31886221136ba2148534148202021, 16 ) = d3290c3d600b8add
CityHash64( a9a6b9c6888e94ff2148534148202022, 16 ) = d3290c3d600b8add
$ ./citycollisions 3
128-bit key 5e2a23015c89da98172fbcb77ad98468
CityHash64( 8e69324ad2a005ff2148534148202020, 16 ) = 59d0b041b16594b
CityHash64( 7ae31886221136ba2148534148202021, 16 ) = 59d0b041b16594b
CityHash64( a9a6b9c6888e94ff2148534148202022, 16 ) = 59d0b041b16594b