From: Bharat Bhushan <bbhushan2@marvell.com>
To: <netdev@vger.kernel.org>, <linux-kernel@vger.kernel.org>,
<sgoutham@marvell.com>, <gakula@marvell.com>,
<sbhatta@marvell.com>, <hkelam@marvell.com>,
<davem@davemloft.net>, <edumazet@google.com>, <kuba@kernel.org>,
<pabeni@redhat.com>, <jerinj@marvell.com>, <lcherian@marvell.com>,
<richardcochran@gmail.com>
Cc: <bbhushan2@marvell.com>
Subject: [net-next,v4 7/8] cn10k-ipsec: Allow inline ipsec offload for skb with SA
Date: Wed, 12 Jun 2024 19:16:21 +0530 [thread overview]
Message-ID: <20240612134622.2157086-8-bbhushan2@marvell.com> (raw)
In-Reply-To: <20240612134622.2157086-1-bbhushan2@marvell.com>
Allow to use hardware offload for outbound inline ipsec
if security association (SA) is set for a given skb.
Signed-off-by: Bharat Bhushan <bbhushan2@marvell.com>
---
.../ethernet/marvell/octeontx2/nic/cn10k_ipsec.c | 15 +++++++++++++++
1 file changed, 15 insertions(+)
diff --git a/drivers/net/ethernet/marvell/octeontx2/nic/cn10k_ipsec.c b/drivers/net/ethernet/marvell/octeontx2/nic/cn10k_ipsec.c
index 0dc94a39aef3..2f63d91db9ad 100644
--- a/drivers/net/ethernet/marvell/octeontx2/nic/cn10k_ipsec.c
+++ b/drivers/net/ethernet/marvell/octeontx2/nic/cn10k_ipsec.c
@@ -788,9 +788,24 @@ static void cn10k_ipsec_del_state(struct xfrm_state *x)
mutex_unlock(&pf->ipsec.lock);
}
+static bool cn10k_ipsec_offload_ok(struct sk_buff *skb, struct xfrm_state *x)
+{
+ if (x->props.family == AF_INET) {
+ /* Offload with IPv4 options is not supported yet */
+ if (ip_hdr(skb)->ihl > 5)
+ return false;
+ } else {
+ /* Offload with IPv6 extension headers is not support yet */
+ if (ipv6_ext_hdr(ipv6_hdr(skb)->nexthdr))
+ return false;
+ }
+ return true;
+}
+
static const struct xfrmdev_ops cn10k_ipsec_xfrmdev_ops = {
.xdo_dev_state_add = cn10k_ipsec_add_state,
.xdo_dev_state_delete = cn10k_ipsec_del_state,
+ .xdo_dev_offload_ok = cn10k_ipsec_offload_ok,
};
int cn10k_ipsec_ethtool_init(struct net_device *netdev, bool enable)
--
2.34.1
next prev parent reply other threads:[~2024-06-12 13:47 UTC|newest]
Thread overview: 12+ messages / expand[flat|nested] mbox.gz Atom feed top
2024-06-12 13:46 [net-next,v4 0/8] cn10k-ipsec: Add outbound inline ipsec support Bharat Bhushan
2024-06-12 13:46 ` [net-next,v4 1/8] octeontx2-pf: map skb data as device writeable Bharat Bhushan
2024-06-12 13:46 ` [net-next,v4 2/8] octeontx2-pf: Move skb fragment map/unmap to common code Bharat Bhushan
2024-06-12 13:46 ` [net-next,v4 3/8] octeontx2-af: Disable backpressure between CPT and NIX Bharat Bhushan
2024-06-12 13:46 ` [net-next,v4 4/8] cn10k-ipsec: Initialize crypto hardware for outb inline ipsec Bharat Bhushan
2024-06-12 15:45 ` Kalesh Anakkur Purayil
2024-06-13 5:25 ` [EXTERNAL] " Bharat Bhushan
2024-06-12 13:46 ` [net-next,v4 5/8] cn10k-ipsec: Add SA add/delete support " Bharat Bhushan
2024-06-13 18:40 ` Leon Romanovsky
2024-06-12 13:46 ` [net-next,v4 6/8] cn10k-ipsec: Process inline ipsec transmit offload Bharat Bhushan
2024-06-12 13:46 ` Bharat Bhushan [this message]
2024-06-12 13:46 ` [net-next,v4 8/8] cn10k-ipsec: Enable outbound inline ipsec offload Bharat Bhushan
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20240612134622.2157086-8-bbhushan2@marvell.com \
--to=bbhushan2@marvell.com \
--cc=davem@davemloft.net \
--cc=edumazet@google.com \
--cc=gakula@marvell.com \
--cc=hkelam@marvell.com \
--cc=jerinj@marvell.com \
--cc=kuba@kernel.org \
--cc=lcherian@marvell.com \
--cc=linux-kernel@vger.kernel.org \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=richardcochran@gmail.com \
--cc=sbhatta@marvell.com \
--cc=sgoutham@marvell.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.