From: Rahul Bhansali <rbhansali@marvell.com>
To: <dev@dpdk.org>, Nithin Dabilpuram <ndabilpuram@marvell.com>,
Kiran Kumar K <kirankumark@marvell.com>,
Sunil Kumar Kori <skori@marvell.com>,
Satha Rao <skoteshwar@marvell.com>,
Harman Kalra <hkalra@marvell.com>
Cc: <jerinj@marvell.com>,
Rakesh Kudurumalla <rkudurumalla@marvell.com>, <stable@dpdk.org>
Subject: [PATCH 14/14] net/cnxk: fix custom inbound SA condition check
Date: Thu, 17 Sep 2026 12:40:16 +0530 [thread overview]
Message-ID: <20260917071016.2366467-14-rbhansali@marvell.com> (raw)
In-Reply-To: <20260917071016.2366467-1-rbhansali@marvell.com>
From: Rakesh Kudurumalla <rkudurumalla@marvell.com>
Custom inbound SA condition should be check when inbound SA create
and destroy.
Fixes: 7eaa499dd0c2 ("net/cnxk: support CN20K inline IPsec session")
Cc: stable@dpdk.org
Signed-off-by: Rakesh Kudurumalla <rkudurumalla@marvell.com>
---
drivers/net/cnxk/cn20k_ethdev_sec.c | 8 ++++----
1 file changed, 4 insertions(+), 4 deletions(-)
diff --git a/drivers/net/cnxk/cn20k_ethdev_sec.c b/drivers/net/cnxk/cn20k_ethdev_sec.c
index b365426065..f648340445 100644
--- a/drivers/net/cnxk/cn20k_ethdev_sec.c
+++ b/drivers/net/cnxk/cn20k_ethdev_sec.c
@@ -805,9 +805,6 @@ cn20k_eth_sec_session_create(void *device, struct rte_security_session_conf *con
if (conf->protocol != RTE_SECURITY_PROTOCOL_IPSEC)
return -ENOTSUP;
- if (nix->custom_inb_sa)
- return -ENOTSUP;
-
if (rte_security_dynfield_register() < 0)
return -ENOTSUP;
@@ -832,6 +829,9 @@ cn20k_eth_sec_session_create(void *device, struct rte_security_session_conf *con
ipsec = &conf->ipsec;
crypto = conf->crypto_xform;
+ if (nix->custom_inb_sa && ipsec->direction == RTE_SECURITY_IPSEC_SA_DIR_INGRESS)
+ return -ENOTSUP;
+
rc = cnxk_ipsec_xform_verify(ipsec, crypto);
if (rc) {
plt_err("Crypto xform verify failed, rc=%d", rc);
@@ -1083,7 +1083,7 @@ cn20k_eth_sec_session_destroy(void *device, struct rte_security_session *sess)
eth_sec = cnxk_eth_sec_sess_get_by_sess(dev, sess);
if (!eth_sec)
return -ENOENT;
- if (dev->nix.custom_inb_sa)
+ if (dev->nix.custom_inb_sa && eth_sec->inb)
return -ENOTSUP;
lock = eth_sec->inb ? &dev->inb.lock : &dev->outb.lock;
--
2.34.1
next prev parent reply other threads:[~2026-09-17 7:15 UTC|newest]
Thread overview: 25+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-17 7:10 [PATCH 01/14] net/cnxk: fix packet length handling Rahul Bhansali
2026-09-17 7:10 ` [PATCH 02/14] common/cnxk: disable CPT drop error in CQ Rahul Bhansali
2026-09-17 16:14 ` Stephen Hemminger
2026-09-17 7:10 ` [PATCH 03/14] common/cnxk: fix NIX QINT count reset Rahul Bhansali
2026-09-17 16:14 ` Stephen Hemminger
2026-09-17 7:10 ` [PATCH 04/14] common/cnxk: update channel mask for cn20k Rahul Bhansali
2026-09-17 7:10 ` [PATCH 05/14] common/cnxk: update macro " Rahul Bhansali
2026-09-17 7:10 ` [PATCH 06/14] common/cnxk: fix null deref and irq ack in CPT CQ handler Rahul Bhansali
2026-09-17 16:15 ` Stephen Hemminger
2026-09-17 7:10 ` [PATCH 07/14] common/cnxk: derive mbuf from CPT CQ in inline IRQ path Rahul Bhansali
2026-09-17 16:15 ` Stephen Hemminger
2026-09-17 7:10 ` [PATCH 08/14] net/cnxk: resolve mbuf from CPT CQ format in SSO work cb Rahul Bhansali
2026-09-17 16:16 ` Stephen Hemminger
2026-09-17 7:10 ` [PATCH 09/14] common/cnxk: update bpid config for cn20k Rahul Bhansali
2026-09-17 16:16 ` Stephen Hemminger
2026-09-17 7:10 ` [PATCH 10/14] net/cnxk: add MSNS inb SA and CN20K CPT result struct Rahul Bhansali
2026-09-17 16:16 ` Stephen Hemminger
2026-09-17 7:10 ` [PATCH 11/14] common/cnxk: fix CPT CQ base address calculation Rahul Bhansali
2026-09-17 7:10 ` [PATCH 12/14] common/cnxk: update mode param for link speed Rahul Bhansali
2026-09-17 16:17 ` Stephen Hemminger
2026-09-17 7:10 ` [PATCH 13/14] common/cnxk: support for cn20k legacy msns mode Rahul Bhansali
2026-09-17 16:18 ` Stephen Hemminger
2026-09-17 7:10 ` Rahul Bhansali [this message]
2026-09-17 16:12 ` [PATCH 01/14] net/cnxk: fix packet length handling Stephen Hemminger
2026-09-17 16:29 ` Stephen Hemminger
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260917071016.2366467-14-rbhansali@marvell.com \
--to=rbhansali@marvell.com \
--cc=dev@dpdk.org \
--cc=hkalra@marvell.com \
--cc=jerinj@marvell.com \
--cc=kirankumark@marvell.com \
--cc=ndabilpuram@marvell.com \
--cc=rkudurumalla@marvell.com \
--cc=skori@marvell.com \
--cc=skoteshwar@marvell.com \
--cc=stable@dpdk.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox