DPDK-dev Archive on lore.kernel.org
 help / color / mirror / Atom feed
From: Rahul Bhansali <rbhansali@marvell.com>
To: <dev@dpdk.org>, Nithin Dabilpuram <ndabilpuram@marvell.com>,
	Kiran Kumar K <kirankumark@marvell.com>,
	Sunil Kumar Kori <skori@marvell.com>,
	Satha Rao <skoteshwar@marvell.com>,
	Harman Kalra <hkalra@marvell.com>
Cc: <jerinj@marvell.com>,
	Rakesh Kudurumalla <rkudurumalla@marvell.com>, <stable@dpdk.org>
Subject: [PATCH 14/14] net/cnxk: fix custom inbound SA condition check
Date: Thu, 17 Sep 2026 12:40:16 +0530	[thread overview]
Message-ID: <20260917071016.2366467-14-rbhansali@marvell.com> (raw)
In-Reply-To: <20260917071016.2366467-1-rbhansali@marvell.com>

From: Rakesh Kudurumalla <rkudurumalla@marvell.com>

Custom inbound SA condition should be check when inbound SA create
and destroy.

Fixes: 7eaa499dd0c2 ("net/cnxk: support CN20K inline IPsec session")
Cc: stable@dpdk.org

Signed-off-by: Rakesh Kudurumalla <rkudurumalla@marvell.com>
---
 drivers/net/cnxk/cn20k_ethdev_sec.c | 8 ++++----
 1 file changed, 4 insertions(+), 4 deletions(-)

diff --git a/drivers/net/cnxk/cn20k_ethdev_sec.c b/drivers/net/cnxk/cn20k_ethdev_sec.c
index b365426065..f648340445 100644
--- a/drivers/net/cnxk/cn20k_ethdev_sec.c
+++ b/drivers/net/cnxk/cn20k_ethdev_sec.c
@@ -805,9 +805,6 @@ cn20k_eth_sec_session_create(void *device, struct rte_security_session_conf *con
 	if (conf->protocol != RTE_SECURITY_PROTOCOL_IPSEC)
 		return -ENOTSUP;
 
-	if (nix->custom_inb_sa)
-		return -ENOTSUP;
-
 	if (rte_security_dynfield_register() < 0)
 		return -ENOTSUP;
 
@@ -832,6 +829,9 @@ cn20k_eth_sec_session_create(void *device, struct rte_security_session_conf *con
 	ipsec = &conf->ipsec;
 	crypto = conf->crypto_xform;
 
+	if (nix->custom_inb_sa && ipsec->direction == RTE_SECURITY_IPSEC_SA_DIR_INGRESS)
+		return -ENOTSUP;
+
 	rc = cnxk_ipsec_xform_verify(ipsec, crypto);
 	if (rc) {
 		plt_err("Crypto xform verify failed, rc=%d", rc);
@@ -1083,7 +1083,7 @@ cn20k_eth_sec_session_destroy(void *device, struct rte_security_session *sess)
 	eth_sec = cnxk_eth_sec_sess_get_by_sess(dev, sess);
 	if (!eth_sec)
 		return -ENOENT;
-	if (dev->nix.custom_inb_sa)
+	if (dev->nix.custom_inb_sa && eth_sec->inb)
 		return -ENOTSUP;
 
 	lock = eth_sec->inb ? &dev->inb.lock : &dev->outb.lock;
-- 
2.34.1


  parent reply	other threads:[~2026-09-17  7:15 UTC|newest]

Thread overview: 25+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-17  7:10 [PATCH 01/14] net/cnxk: fix packet length handling Rahul Bhansali
2026-09-17  7:10 ` [PATCH 02/14] common/cnxk: disable CPT drop error in CQ Rahul Bhansali
2026-09-17 16:14   ` Stephen Hemminger
2026-09-17  7:10 ` [PATCH 03/14] common/cnxk: fix NIX QINT count reset Rahul Bhansali
2026-09-17 16:14   ` Stephen Hemminger
2026-09-17  7:10 ` [PATCH 04/14] common/cnxk: update channel mask for cn20k Rahul Bhansali
2026-09-17  7:10 ` [PATCH 05/14] common/cnxk: update macro " Rahul Bhansali
2026-09-17  7:10 ` [PATCH 06/14] common/cnxk: fix null deref and irq ack in CPT CQ handler Rahul Bhansali
2026-09-17 16:15   ` Stephen Hemminger
2026-09-17  7:10 ` [PATCH 07/14] common/cnxk: derive mbuf from CPT CQ in inline IRQ path Rahul Bhansali
2026-09-17 16:15   ` Stephen Hemminger
2026-09-17  7:10 ` [PATCH 08/14] net/cnxk: resolve mbuf from CPT CQ format in SSO work cb Rahul Bhansali
2026-09-17 16:16   ` Stephen Hemminger
2026-09-17  7:10 ` [PATCH 09/14] common/cnxk: update bpid config for cn20k Rahul Bhansali
2026-09-17 16:16   ` Stephen Hemminger
2026-09-17  7:10 ` [PATCH 10/14] net/cnxk: add MSNS inb SA and CN20K CPT result struct Rahul Bhansali
2026-09-17 16:16   ` Stephen Hemminger
2026-09-17  7:10 ` [PATCH 11/14] common/cnxk: fix CPT CQ base address calculation Rahul Bhansali
2026-09-17  7:10 ` [PATCH 12/14] common/cnxk: update mode param for link speed Rahul Bhansali
2026-09-17 16:17   ` Stephen Hemminger
2026-09-17  7:10 ` [PATCH 13/14] common/cnxk: support for cn20k legacy msns mode Rahul Bhansali
2026-09-17 16:18   ` Stephen Hemminger
2026-09-17  7:10 ` Rahul Bhansali [this message]
2026-09-17 16:12 ` [PATCH 01/14] net/cnxk: fix packet length handling Stephen Hemminger
2026-09-17 16:29 ` Stephen Hemminger

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260917071016.2366467-14-rbhansali@marvell.com \
    --to=rbhansali@marvell.com \
    --cc=dev@dpdk.org \
    --cc=hkalra@marvell.com \
    --cc=jerinj@marvell.com \
    --cc=kirankumark@marvell.com \
    --cc=ndabilpuram@marvell.com \
    --cc=rkudurumalla@marvell.com \
    --cc=skori@marvell.com \
    --cc=skoteshwar@marvell.com \
    --cc=stable@dpdk.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox