From: Antony Antony <antony@phenome.org>
To: Eyal Birger <eyal.birger@gmail.com>
Cc: steffen.klassert@secunet.com, herbert@gondor.apana.org.au,
davem@davemloft.net, edumazet@google.com, kuba@kernel.org,
dsahern@kernel.org, pabeni@redhat.com, netdev@vger.kernel.org,
devel@linux-ipsec.org
Subject: Re: [devel-ipsec] [PATCH ipsec, v2 0/2] xfrm: respect ip proto rules criteria in xfrm dst lookups
Date: Mon, 2 Sep 2024 15:52:21 +0200 [thread overview]
Message-ID: <ZtXDFWpPVdlNE8NP@Antony2201.local> (raw)
In-Reply-To: <20240902110719.502566-1-eyal.birger@gmail.com>
On Mon, Sep 02, 2024 at 04:07:17AM -0700, Eyal Birger via Devel wrote:
> This series fixes the route lookup when done for xfrm to regard
> L4 criteria specified in ip rules.
Hi Eyal,
This isn't a review of the patch set, instead curiosity about use cases.
This sounds interesting. Would you like to elaborate on the use cases
supported in this patch? From what I understand so far, it seems related to
'ip rule', but I'm wondering about possible use cases: inner packet routing
rule of tunnel? May be you could explain it at the IPsec coffee hour or
share some use case or test script.
Is this only for route based IPsec, i.e. with xfrmi interface, or also for a
policy based without route use cases. In the later case there were
discussions why do we need a route for the inner packet.
-antony
>
> The first patch is a minor refactor to allow passing more parameters
> to dst lookup functions.
> The second patch actually passes L4 information to these lookup functions.
>
> Signed-off-by: Eyal Birger <eyal.birger@gmail.com>
>
> ---
>
> v2: fix first patch based on reviews from Steffen Klassert and
> Simon Horman
>
> Eyal Birger (2):
> xfrm: extract dst lookup parameters into a struct
> xfrm: respect ip protocols rules criteria when performing dst lookups
>
> include/net/xfrm.h | 28 ++++++++++++-----------
> net/ipv4/xfrm4_policy.c | 40 +++++++++++++++------------------
> net/ipv6/xfrm6_policy.c | 31 +++++++++++++-------------
> net/xfrm/xfrm_device.c | 11 ++++++---
> net/xfrm/xfrm_policy.c | 49 +++++++++++++++++++++++++++++++----------
> 5 files changed, 94 insertions(+), 65 deletions(-)
>
> --
> 2.34.1
>
> --
> Devel mailing list
> Devel@linux-ipsec.org
> https://linux-ipsec.org/mailman/listinfo/devel
next prev parent reply other threads:[~2024-09-02 13:52 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2024-09-02 11:07 [PATCH ipsec,v2 0/2] xfrm: respect ip proto rules criteria in xfrm dst lookups Eyal Birger
2024-09-02 11:07 ` [PATCH ipsec,v2 1/2] xfrm: extract dst lookup parameters into a struct Eyal Birger
2024-09-02 11:07 ` [PATCH ipsec,v2 2/2] xfrm: respect ip protocols rules criteria when performing dst lookups Eyal Birger
2024-09-02 13:52 ` Antony Antony [this message]
2024-09-02 20:39 ` [devel-ipsec] [PATCH ipsec, v2 0/2] xfrm: respect ip proto rules criteria in xfrm " Antony Antony
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=ZtXDFWpPVdlNE8NP@Antony2201.local \
--to=antony@phenome.org \
--cc=davem@davemloft.net \
--cc=devel@linux-ipsec.org \
--cc=dsahern@kernel.org \
--cc=edumazet@google.com \
--cc=eyal.birger@gmail.com \
--cc=herbert@gondor.apana.org.au \
--cc=kuba@kernel.org \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=steffen.klassert@secunet.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.