* [PATCH 0/6] DPAA2 SEC related changes
@ 2026-08-10 11:29 Gagandeep Singh
2026-08-10 11:29 ` [PATCH 1/6] crypto/dpaa2_sec: fix buffer overflow in GCM decrypt Gagandeep Singh
` (6 more replies)
0 siblings, 7 replies; 26+ messages in thread
From: Gagandeep Singh @ 2026-08-10 11:29 UTC (permalink / raw)
To: dev, gakhil; +Cc: hemant.agrawal
This series include bug fixes, enhancement and AES-GMAC support
Gagandeep Singh (6):
crypto/dpaa2_sec: fix buffer overflow in GCM decrypt
crypto/dpaa2_sec: fix FLE pool leak on sec FD build failure
crypto/dpaa2_sec: support AES-GMAC
crypto/dpaa2_sec: increase ivsize range for AES-CTR
crypto/dpaa2_sec: add missing ECN capability
crypto/dpaa2_sec: add support for env variables
drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c | 50 ++++++++++++++++++---
drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h | 45 ++++++++++++++++---
lib/cryptodev/rte_crypto_sym.h | 2 +
3 files changed, 86 insertions(+), 11 deletions(-)
--
2.25.1
^ permalink raw reply [flat|nested] 26+ messages in thread
* [PATCH 1/6] crypto/dpaa2_sec: fix buffer overflow in GCM decrypt
2026-08-10 11:29 [PATCH 0/6] DPAA2 SEC related changes Gagandeep Singh
@ 2026-08-10 11:29 ` Gagandeep Singh
2026-08-10 11:29 ` [PATCH 2/6] crypto/dpaa2_sec: fix FLE pool leak on sec FD build failure Gagandeep Singh
` (5 subsequent siblings)
6 siblings, 0 replies; 26+ messages in thread
From: Gagandeep Singh @ 2026-08-10 11:29 UTC (permalink / raw)
To: dev, gakhil; +Cc: hemant.agrawal, stable, Gagandeep Singh
In build_authenc_gcm_fd, when both AAD (auth_only_len > 0) and decrypt
direction are active, the SGE layout occupies 8 entries plus 16 bytes of
old_icv storage at index 8. The FLE pool buffer was only 256 bytes
(8 x 32), causing old_icv to be written one entry past the end of the
allocated buffer. The resulting virtual address was not mapped by the
IOMMU, so DPAA2_VADDR_TO_IOVA returned 0 and the SEC engine received
iova=0x00000000 as the ICV buffer address, triggering an SMMU
translation fault (FSR=0x402 TF).
Additionally, the upfront bpid/IVP initialization only covered sge+3,
leaving sge+4 (the input data SGE when AAD is present) without a valid
bpid or IVP assignment.
Increase FLE_POOL_BUF_SIZE from 256 to 288 (9 x 32 bytes) to
accommodate the full layout, and extend the bpid/IVP initialization
to cover sge+4 in both branches of build_authenc_gcm_fd.
Fixes: 13273250ee ("crypto/dpaa2_sec: support AES-GCM and CTR")
Cc: stable@dpdk.org
Signed-off-by: Gagandeep Singh <g.singh@nxp.com>
---
drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c | 2 ++
drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h | 2 +-
2 files changed, 3 insertions(+), 1 deletion(-)
diff --git a/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c b/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c
index 3d980d096f..2a015a3d82 100644
--- a/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c
+++ b/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c
@@ -569,6 +569,7 @@ build_authenc_gcm_fd(dpaa2_sec_session *sess,
DPAA2_SET_FLE_BPID(sge + 1, bpid);
DPAA2_SET_FLE_BPID(sge + 2, bpid);
DPAA2_SET_FLE_BPID(sge + 3, bpid);
+ DPAA2_SET_FLE_BPID(sge + 4, bpid);
} else {
DPAA2_SET_FD_IVP(fd);
DPAA2_SET_FLE_IVP(fle);
@@ -577,6 +578,7 @@ build_authenc_gcm_fd(dpaa2_sec_session *sess,
DPAA2_SET_FLE_IVP((sge + 1));
DPAA2_SET_FLE_IVP((sge + 2));
DPAA2_SET_FLE_IVP((sge + 3));
+ DPAA2_SET_FLE_IVP((sge + 4));
}
/* Save the shared descriptor */
diff --git a/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h b/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h
index 755c8e9cc3..ff32f3d860 100644
--- a/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h
+++ b/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h
@@ -17,7 +17,7 @@ extern uint8_t cryptodev_driver_id;
/* FLE_POOL_NUM_BUFS is set as per the ipsec-secgw application */
#define FLE_POOL_NUM_BUFS 32000
-#define FLE_POOL_BUF_SIZE 256
+#define FLE_POOL_BUF_SIZE 288
#define FLE_POOL_CACHE_SIZE 512
#define FLE_SG_MEM_SIZE(num) (FLE_POOL_BUF_SIZE + ((num) * 32))
--
2.25.1
^ permalink raw reply related [flat|nested] 26+ messages in thread
* [PATCH 2/6] crypto/dpaa2_sec: fix FLE pool leak on sec FD build failure
2026-08-10 11:29 [PATCH 0/6] DPAA2 SEC related changes Gagandeep Singh
2026-08-10 11:29 ` [PATCH 1/6] crypto/dpaa2_sec: fix buffer overflow in GCM decrypt Gagandeep Singh
@ 2026-08-10 11:29 ` Gagandeep Singh
2026-08-10 11:29 ` [PATCH 3/6] crypto/dpaa2_sec: support AES-GMAC Gagandeep Singh
` (4 subsequent siblings)
6 siblings, 0 replies; 26+ messages in thread
From: Gagandeep Singh @ 2026-08-10 11:29 UTC (permalink / raw)
To: dev, gakhil; +Cc: hemant.agrawal, stable, Gagandeep Singh
When build_sec_fd fails at index loop inside the enqueue burst loops,
the previously built FD entries (indices 0..loop-1) were never freed.
The cleanup loop iterated in the wrong direction, starting at the
failed index and going up to frames_to_send, which are entries that
were never built. This caused silent FLE pool exhaustion, after which
every subsequent build_sec_fd returned -ENOMEM, enqueue_burst
returned 0 indefinitely, and the crypto-perf test hung.
Fix both dpaa2_sec_enqueue_burst and dpaa2_sec_enqueue_burst_ordered
by clamping frames_to_send to loop + 1 and iterating from 0 to
free all allocated FLE buffers including the failed entry.
Fixes: 623326dded ("crypto/dpaa2_sec: introduce poll mode driver")
Cc: stable@dpdk.org
Signed-off-by: Gagandeep Singh <g.singh@nxp.com>
---
drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c | 6 ++++++
1 file changed, 6 insertions(+)
diff --git a/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c b/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c
index 2a015a3d82..15152cc5a1 100644
--- a/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c
+++ b/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c
@@ -1550,6 +1550,9 @@ dpaa2_sec_enqueue_burst(void *qp, struct rte_crypto_op **ops,
ret = build_sec_fd(*ops, &fd_arr[loop], bpid, dpaa2_qp);
if (ret) {
DPAA2_SEC_DP_DEBUG("FD build failed");
+ frames_to_send = loop + 1;
+ for (loop = 0; loop < frames_to_send; loop++)
+ free_fle(&fd_arr[loop], dpaa2_qp);
goto skip_tx;
}
ops++;
@@ -1909,6 +1912,9 @@ dpaa2_sec_enqueue_burst_ordered(void *qp, struct rte_crypto_op **ops,
ret = build_sec_fd(*ops, &fd_arr[loop], bpid, dpaa2_qp);
if (ret) {
DPAA2_SEC_DP_DEBUG("FD build failed");
+ frames_to_send = loop + 1;
+ for (loop = 0; loop < frames_to_send; loop++)
+ free_fle(&fd_arr[loop], dpaa2_qp);
goto skip_tx;
}
ops++;
--
2.25.1
^ permalink raw reply related [flat|nested] 26+ messages in thread
* [PATCH 3/6] crypto/dpaa2_sec: support AES-GMAC
2026-08-10 11:29 [PATCH 0/6] DPAA2 SEC related changes Gagandeep Singh
2026-08-10 11:29 ` [PATCH 1/6] crypto/dpaa2_sec: fix buffer overflow in GCM decrypt Gagandeep Singh
2026-08-10 11:29 ` [PATCH 2/6] crypto/dpaa2_sec: fix FLE pool leak on sec FD build failure Gagandeep Singh
@ 2026-08-10 11:29 ` Gagandeep Singh
2026-08-10 11:29 ` [PATCH 4/6] crypto/dpaa2_sec: increase ivsize range for AES-CTR Gagandeep Singh
` (3 subsequent siblings)
6 siblings, 0 replies; 26+ messages in thread
From: Gagandeep Singh @ 2026-08-10 11:29 UTC (permalink / raw)
To: dev, gakhil; +Cc: hemant.agrawal, Gagandeep Singh
Add AES-GMAC as a supported AEAD algorithm for IPsec protocol
offload. AES-GMAC provides NULL encryption with GMAC authentication
and maps to OP_PCL_IPSEC_AES_NULL_WITH_GMAC in the SEC protocol
control word.
When AES_GMAC is specified as an AUTH (non-AEAD) algorithm, return
-ENOTSUP with an informative message directing the user to the AEAD
path.
Add RTE_CRYPTO_AEAD_AES_GMAC to the AEAD algorithm enum and expose
the capability in dpaa2_sec_capabilities.
Signed-off-by: Gagandeep Singh <g.singh@nxp.com>
---
drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c | 15 +++++++++-
drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h | 33 ++++++++++++++++++++-
lib/cryptodev/rte_crypto_sym.h | 2 ++
3 files changed, 48 insertions(+), 2 deletions(-)
diff --git a/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c b/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c
index 15152cc5a1..0e4e67aa07 100644
--- a/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c
+++ b/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c
@@ -1,7 +1,7 @@
/* SPDX-License-Identifier: BSD-3-Clause
*
* Copyright (c) 2016 Freescale Semiconductor, Inc. All rights reserved.
- * Copyright 2016-2025 NXP
+ * Copyright 2016-2026 NXP
*
*/
@@ -2975,6 +2975,13 @@ dpaa2_sec_ipsec_aead_init(struct rte_crypto_aead_xform *aead_xform,
aeaddata->algmode = OP_ALG_AAI_CCM;
session->aead_alg = RTE_CRYPTO_AEAD_AES_CCM;
break;
+ case RTE_CRYPTO_AEAD_AES_GMAC:
+ /**
+ * AES-GMAC is an AEAD algo with NULL encryption and GMAC
+ * authentication.
+ */
+ aeaddata->algtype = OP_PCL_IPSEC_AES_NULL_WITH_GMAC;
+ break;
default:
DPAA2_SEC_ERR("Crypto: Undefined AEAD specified %u",
aead_xform->algo);
@@ -3046,6 +3053,10 @@ dpaa2_sec_ipsec_proto_init(struct rte_crypto_cipher_xform *cipher_xform,
authdata->algtype = OP_PCL_IPSEC_HMAC_MD5_96;
authdata->algmode = OP_ALG_AAI_HMAC;
break;
+ case RTE_CRYPTO_AUTH_AES_GMAC:
+ DPAA2_SEC_ERR(
+ "AES_GMAC is supported as AEAD algo for IPSEC proto only");
+ return -ENOTSUP;
case RTE_CRYPTO_AUTH_SHA224_HMAC:
authdata->algmode = OP_ALG_AAI_HMAC;
if (session->digest_length == 6)
@@ -3217,6 +3228,7 @@ dpaa2_sec_set_ipsec_session(struct rte_cryptodev *dev,
case OP_PCL_IPSEC_AES_GCM8:
case OP_PCL_IPSEC_AES_GCM12:
case OP_PCL_IPSEC_AES_GCM16:
+ case OP_PCL_IPSEC_AES_NULL_WITH_GMAC:
memcpy(encap_pdb.gcm.salt,
(uint8_t *)&(ipsec_xform->salt), 4);
break;
@@ -3357,6 +3369,7 @@ dpaa2_sec_set_ipsec_session(struct rte_cryptodev *dev,
case OP_PCL_IPSEC_AES_GCM8:
case OP_PCL_IPSEC_AES_GCM12:
case OP_PCL_IPSEC_AES_GCM16:
+ case OP_PCL_IPSEC_AES_NULL_WITH_GMAC:
memcpy(decap_pdb.gcm.salt,
(uint8_t *)&(ipsec_xform->salt), 4);
break;
diff --git a/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h b/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h
index ff32f3d860..1824cc4a60 100644
--- a/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h
+++ b/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h
@@ -1,7 +1,7 @@
/* SPDX-License-Identifier: BSD-3-Clause
*
* Copyright (c) 2016 Freescale Semiconductor, Inc. All rights reserved.
- * Copyright 2016,2020-2024 NXP
+ * Copyright 2016,2020-2026 NXP
*
*/
@@ -762,6 +762,37 @@ static const struct rte_cryptodev_capabilities dpaa2_sec_capabilities[] = {
}, }
}, }
},
+ { /* AES GMAC (AEAD) */
+ .op = RTE_CRYPTO_OP_TYPE_SYMMETRIC,
+ {.sym = {
+ .xform_type = RTE_CRYPTO_SYM_XFORM_AEAD,
+ {.aead = {
+ .algo = RTE_CRYPTO_AEAD_AES_GMAC,
+ .block_size = 16,
+ .key_size = {
+ .min = 16,
+ .max = 32,
+ .increment = 8
+ },
+ .digest_size = {
+ .min = 16,
+ .max = 16,
+ .increment = 0
+ },
+ .aad_size = {
+ .min = 0,
+ .max = 65535,
+ .increment = 1
+ },
+ .iv_size = {
+ .min = 12,
+ .max = 16,
+ .increment = 4
+ }
+ }, }
+ }, }
+ },
+
RTE_CRYPTODEV_END_OF_CAPABILITIES_LIST()
};
diff --git a/lib/cryptodev/rte_crypto_sym.h b/lib/cryptodev/rte_crypto_sym.h
index 630fd153bd..f65db616a0 100644
--- a/lib/cryptodev/rte_crypto_sym.h
+++ b/lib/cryptodev/rte_crypto_sym.h
@@ -508,6 +508,8 @@ enum rte_crypto_aead_algorithm {
/**< AES algorithm in NCA5 mode */
RTE_CRYPTO_AEAD_ZUC_NCA6,
/**< ZUC-256 algorithm in NCA6 mode */
+ RTE_CRYPTO_AEAD_AES_GMAC,
+ /**< AES algorithm in GMAC mode. */
};
/** Symmetric AEAD Operations */
--
2.25.1
^ permalink raw reply related [flat|nested] 26+ messages in thread
* [PATCH 4/6] crypto/dpaa2_sec: increase ivsize range for AES-CTR
2026-08-10 11:29 [PATCH 0/6] DPAA2 SEC related changes Gagandeep Singh
` (2 preceding siblings ...)
2026-08-10 11:29 ` [PATCH 3/6] crypto/dpaa2_sec: support AES-GMAC Gagandeep Singh
@ 2026-08-10 11:29 ` Gagandeep Singh
2026-08-10 11:29 ` [PATCH 5/6] crypto/dpaa2_sec: add missing ECN capability Gagandeep Singh
` (2 subsequent siblings)
6 siblings, 0 replies; 26+ messages in thread
From: Gagandeep Singh @ 2026-08-10 11:29 UTC (permalink / raw)
To: dev, gakhil; +Cc: hemant.agrawal
Widen the AES-CTR IV size range from the fixed 16-byte value to
[12, 16] with a 4-byte increment. This allows 96-bit IVs (the
standard NIST SP 800-38A recommendation) in addition to 128-bit
IVs, aligning with common usage and test-vector expectations.
The change applies to both dpaa2_sec_capabilities and
dpaa2_pdcp_capabilities.
Signed-off-by: Hemant Agrawal <hemant.agrawal@nxp.com>
---
drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h | 8 ++++----
1 file changed, 4 insertions(+), 4 deletions(-)
diff --git a/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h b/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h
index 1824cc4a60..7e18e83858 100644
--- a/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h
+++ b/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h
@@ -625,9 +625,9 @@ static const struct rte_cryptodev_capabilities dpaa2_sec_capabilities[] = {
.increment = 8
},
.iv_size = {
- .min = 16,
+ .min = 12,
.max = 16,
- .increment = 0
+ .increment = 4
},
}, }
}, }
@@ -855,9 +855,9 @@ static const struct rte_cryptodev_capabilities dpaa2_pdcp_capabilities[] = {
.increment = 8
},
.iv_size = {
- .min = 16,
+ .min = 12,
.max = 16,
- .increment = 0
+ .increment = 4
}
}, }
}, }
--
2.25.1
^ permalink raw reply related [flat|nested] 26+ messages in thread
* [PATCH 5/6] crypto/dpaa2_sec: add missing ECN capability
2026-08-10 11:29 [PATCH 0/6] DPAA2 SEC related changes Gagandeep Singh
` (3 preceding siblings ...)
2026-08-10 11:29 ` [PATCH 4/6] crypto/dpaa2_sec: increase ivsize range for AES-CTR Gagandeep Singh
@ 2026-08-10 11:29 ` Gagandeep Singh
2026-08-10 11:29 ` [PATCH 6/6] crypto/dpaa2_sec: add support for env variables Gagandeep Singh
2026-09-30 7:08 ` [PATCH v2 0/6] DPAA2 SEC related changes Gagandeep Singh
6 siblings, 0 replies; 26+ messages in thread
From: Gagandeep Singh @ 2026-08-10 11:29 UTC (permalink / raw)
To: dev, gakhil; +Cc: hemant.agrawal, Gagandeep Singh
Set the .ecn = 1 flag in both tunnel-mode security capability
entries to advertise that the driver supports ECN (Explicit
Congestion Notification) copying during IPsec encap/decap.
Signed-off-by: Gagandeep Singh <g.singh@nxp.com>
---
drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h | 2 ++
1 file changed, 2 insertions(+)
diff --git a/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h b/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h
index 7e18e83858..16b8273a79 100644
--- a/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h
+++ b/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h
@@ -1004,6 +1004,7 @@ static const struct rte_security_capability dpaa2_sec_security_cap[] = {
.copy_df = 1,
.copy_dscp = 1,
.dec_ttl = 1,
+ .ecn = 1,
.esn = 1,
},
.replay_win_sz_max = 1024
@@ -1023,6 +1024,7 @@ static const struct rte_security_capability dpaa2_sec_security_cap[] = {
.copy_df = 1,
.copy_dscp = 1,
.dec_ttl = 1,
+ .ecn = 1,
.esn = 1,
},
.replay_win_sz_max = 1024
--
2.25.1
^ permalink raw reply related [flat|nested] 26+ messages in thread
* [PATCH 6/6] crypto/dpaa2_sec: add support for env variables
2026-08-10 11:29 [PATCH 0/6] DPAA2 SEC related changes Gagandeep Singh
` (4 preceding siblings ...)
2026-08-10 11:29 ` [PATCH 5/6] crypto/dpaa2_sec: add missing ECN capability Gagandeep Singh
@ 2026-08-10 11:29 ` Gagandeep Singh
2026-08-10 15:16 ` Stephen Hemminger
2026-09-30 7:08 ` [PATCH v2 0/6] DPAA2 SEC related changes Gagandeep Singh
6 siblings, 1 reply; 26+ messages in thread
From: Gagandeep Singh @ 2026-08-10 11:29 UTC (permalink / raw)
To: dev, gakhil; +Cc: hemant.agrawal, Gagandeep Singh
Allow driver configuration via environment variables as a fallback
when devargs are not provided. After processing devargs (or when
devargs are absent), check DRIVER_STRICT_ORDER and DRIVER_DUMP_MODE
environment variables to set en_loose_ordered and dpaa2_sec_dp_dump.
This lets users configure the driver without modifying EAL arguments,
useful in environments where command-line access is restricted.
Signed-off-by: Gagandeep Singh <g.singh@nxp.com>
---
drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c | 27 ++++++++++++++++++---
1 file changed, 23 insertions(+), 4 deletions(-)
diff --git a/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c b/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c
index 0e4e67aa07..c54960820c 100644
--- a/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c
+++ b/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c
@@ -4379,25 +4379,44 @@ check_devargs_handler(const char *key, const char *value,
static void
dpaa2_sec_get_devargs(struct rte_cryptodev *cryptodev, const char *key)
{
+ struct dpaa2_sec_dev_private *internals;
struct rte_kvargs *kvlist;
struct rte_devargs *devargs;
+ int ret;
+ char *env;
+
+ internals = cryptodev->data->dev_private;
devargs = cryptodev->device->devargs;
if (!devargs)
- return;
+ goto env_set;
kvlist = rte_kvargs_parse(devargs->args, NULL);
if (!kvlist)
- return;
+ goto env_set;
if (!rte_kvargs_count(kvlist, key)) {
rte_kvargs_free(kvlist);
- return;
+ goto env_set;
}
- rte_kvargs_process(kvlist, key,
+ ret = rte_kvargs_process(kvlist, key,
check_devargs_handler, (void *)cryptodev);
rte_kvargs_free(kvlist);
+ if (!ret)
+ return;
+
+env_set:
+ env = getenv(DRIVER_STRICT_ORDER);
+ if (env)
+ internals->en_loose_ordered = !atoi(env);
+
+ env = getenv(DRIVER_DUMP_MODE);
+ if (env) {
+ dpaa2_sec_dp_dump = atoi(env);
+ if (dpaa2_sec_dp_dump > DPAA2_SEC_DP_FULL_DUMP)
+ dpaa2_sec_dp_dump = DPAA2_SEC_DP_FULL_DUMP;
+ }
}
static int
--
2.25.1
^ permalink raw reply related [flat|nested] 26+ messages in thread
* Re: [PATCH 6/6] crypto/dpaa2_sec: add support for env variables
2026-08-10 11:29 ` [PATCH 6/6] crypto/dpaa2_sec: add support for env variables Gagandeep Singh
@ 2026-08-10 15:16 ` Stephen Hemminger
2026-08-11 7:50 ` Gagandeep Singh
0 siblings, 1 reply; 26+ messages in thread
From: Stephen Hemminger @ 2026-08-10 15:16 UTC (permalink / raw)
To: Gagandeep Singh; +Cc: dev, gakhil, hemant.agrawal
On Mon, 10 Aug 2026 16:59:51 +0530
Gagandeep Singh <g.singh@nxp.com> wrote:
> Allow driver configuration via environment variables as a fallback
> when devargs are not provided. After processing devargs (or when
> devargs are absent), check DRIVER_STRICT_ORDER and DRIVER_DUMP_MODE
> environment variables to set en_loose_ordered and dpaa2_sec_dp_dump.
>
> This lets users configure the driver without modifying EAL arguments,
> useful in environments where command-line access is restricted.
>
> Signed-off-by: Gagandeep Singh <g.singh@nxp.com>
No. This is bad precedent. DPDK has a method for configuration.
Adding AdHoc environment variables creates chaos.
^ permalink raw reply [flat|nested] 26+ messages in thread
* RE: [PATCH 6/6] crypto/dpaa2_sec: add support for env variables
2026-08-10 15:16 ` Stephen Hemminger
@ 2026-08-11 7:50 ` Gagandeep Singh
0 siblings, 0 replies; 26+ messages in thread
From: Gagandeep Singh @ 2026-08-11 7:50 UTC (permalink / raw)
To: Stephen Hemminger; +Cc: dev@dpdk.org, gakhil@marvell.com, Hemant Agrawal
Hi,
> -----Original Message-----
> From: Stephen Hemminger <stephen@networkplumber.org>
> Sent: Monday, August 10, 2026 8:46 PM
> To: Gagandeep Singh <G.Singh@nxp.com>
> Cc: dev@dpdk.org; gakhil@marvell.com; Hemant Agrawal
> <hemant.agrawal@nxp.com>
> Subject: Re: [PATCH 6/6] crypto/dpaa2_sec: add support for env variables
>
> On Mon, 10 Aug 2026 16:59:51 +0530
> Gagandeep Singh <g.singh@nxp.com> wrote:
>
> > Allow driver configuration via environment variables as a fallback
> > when devargs are not provided. After processing devargs (or when
> > devargs are absent), check DRIVER_STRICT_ORDER and
> DRIVER_DUMP_MODE
> > environment variables to set en_loose_ordered and dpaa2_sec_dp_dump.
> >
> > This lets users configure the driver without modifying EAL arguments,
> > useful in environments where command-line access is restricted.
> >
> > Signed-off-by: Gagandeep Singh <g.singh@nxp.com>
>
> No. This is bad precedent. DPDK has a method for configuration.
> Adding AdHoc environment variables creates chaos.
I understand the concern. The devargs are already presents. The motivation was mainly customer support. In many deployments,
users cannot easily modify EAL/devargs but can set environment variables without the need to update and recompile
their binaries, making it easier to enable temporary debugging in the field.
^ permalink raw reply [flat|nested] 26+ messages in thread
* [PATCH v2 0/6] DPAA2 SEC related changes
2026-08-10 11:29 [PATCH 0/6] DPAA2 SEC related changes Gagandeep Singh
` (5 preceding siblings ...)
2026-08-10 11:29 ` [PATCH 6/6] crypto/dpaa2_sec: add support for env variables Gagandeep Singh
@ 2026-09-30 7:08 ` Gagandeep Singh
2026-09-30 7:08 ` [PATCH v2 1/6] crypto/dpaa2_sec: fix buffer overflow in GCM decrypt Gagandeep Singh
` (6 more replies)
6 siblings, 7 replies; 26+ messages in thread
From: Gagandeep Singh @ 2026-09-30 7:08 UTC (permalink / raw)
To: dev, gakhil; +Cc: hemant.agrawal
V2-changes:
- Support AES-GMAC as AUTH algorithm instead of as AEAD.
This series include bug fixes, enhancement and AES-GMAC support
Gagandeep Singh (6):
crypto/dpaa2_sec: fix buffer overflow in GCM decrypt
crypto/dpaa2_sec: fix FLE pool leak on sec FD build failure
crypto/dpaa2_sec: increase ivsize range for AES-CTR
crypto/dpaa2_sec: add missing ECN capability
crypto/dpaa2_sec: add support for env variables
crypto/dpaa2_sec: support AES-GMAC
doc/guides/cryptodevs/dpaa2_sec.rst | 13 +++-
doc/guides/cryptodevs/features/dpaa2_sec.ini | 3 +
drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c | 78 ++++++++++++++++++--
drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h | 40 ++++++++--
4 files changed, 122 insertions(+), 12 deletions(-)
--
2.25.1
^ permalink raw reply [flat|nested] 26+ messages in thread
* [PATCH v2 1/6] crypto/dpaa2_sec: fix buffer overflow in GCM decrypt
2026-09-30 7:08 ` [PATCH v2 0/6] DPAA2 SEC related changes Gagandeep Singh
@ 2026-09-30 7:08 ` Gagandeep Singh
2026-09-30 7:08 ` [PATCH v2 2/6] crypto/dpaa2_sec: fix FLE pool leak on sec FD build failure Gagandeep Singh
` (5 subsequent siblings)
6 siblings, 0 replies; 26+ messages in thread
From: Gagandeep Singh @ 2026-09-30 7:08 UTC (permalink / raw)
To: dev, gakhil; +Cc: hemant.agrawal, stable, Gagandeep Singh
In build_authenc_gcm_fd, when both AAD (auth_only_len > 0) and decrypt
direction are active, the SGE layout occupies 8 entries plus 16 bytes of
old_icv storage at index 8. The FLE pool buffer was only 256 bytes
(8 x 32), causing old_icv to be written one entry past the end of the
allocated buffer. The resulting virtual address was not mapped by the
IOMMU, so DPAA2_VADDR_TO_IOVA returned 0 and the SEC engine received
iova=0x00000000 as the ICV buffer address, triggering an SMMU
translation fault (FSR=0x402 TF).
Additionally, the upfront bpid/IVP initialization only covered sge+3,
leaving sge+4 (the input data SGE when AAD is present) without a valid
bpid or IVP assignment.
Increase FLE_POOL_BUF_SIZE from 256 to 288 (9 x 32 bytes) to
accommodate the full layout, and extend the bpid/IVP initialization
to cover sge+4 in both branches of build_authenc_gcm_fd.
Fixes: 13273250eec5 ("crypto/dpaa2_sec: support AES-GCM and CTR")
Cc: stable@dpdk.org
Signed-off-by: Gagandeep Singh <g.singh@nxp.com>
---
drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c | 2 ++
drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h | 2 +-
2 files changed, 3 insertions(+), 1 deletion(-)
diff --git a/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c b/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c
index 3d980d096f..2a015a3d82 100644
--- a/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c
+++ b/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c
@@ -569,6 +569,7 @@ build_authenc_gcm_fd(dpaa2_sec_session *sess,
DPAA2_SET_FLE_BPID(sge + 1, bpid);
DPAA2_SET_FLE_BPID(sge + 2, bpid);
DPAA2_SET_FLE_BPID(sge + 3, bpid);
+ DPAA2_SET_FLE_BPID(sge + 4, bpid);
} else {
DPAA2_SET_FD_IVP(fd);
DPAA2_SET_FLE_IVP(fle);
@@ -577,6 +578,7 @@ build_authenc_gcm_fd(dpaa2_sec_session *sess,
DPAA2_SET_FLE_IVP((sge + 1));
DPAA2_SET_FLE_IVP((sge + 2));
DPAA2_SET_FLE_IVP((sge + 3));
+ DPAA2_SET_FLE_IVP((sge + 4));
}
/* Save the shared descriptor */
diff --git a/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h b/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h
index 755c8e9cc3..ff32f3d860 100644
--- a/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h
+++ b/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h
@@ -17,7 +17,7 @@ extern uint8_t cryptodev_driver_id;
/* FLE_POOL_NUM_BUFS is set as per the ipsec-secgw application */
#define FLE_POOL_NUM_BUFS 32000
-#define FLE_POOL_BUF_SIZE 256
+#define FLE_POOL_BUF_SIZE 288
#define FLE_POOL_CACHE_SIZE 512
#define FLE_SG_MEM_SIZE(num) (FLE_POOL_BUF_SIZE + ((num) * 32))
--
2.25.1
^ permalink raw reply related [flat|nested] 26+ messages in thread
* [PATCH v2 2/6] crypto/dpaa2_sec: fix FLE pool leak on sec FD build failure
2026-09-30 7:08 ` [PATCH v2 0/6] DPAA2 SEC related changes Gagandeep Singh
2026-09-30 7:08 ` [PATCH v2 1/6] crypto/dpaa2_sec: fix buffer overflow in GCM decrypt Gagandeep Singh
@ 2026-09-30 7:08 ` Gagandeep Singh
2026-09-30 7:08 ` [PATCH v2 3/6] crypto/dpaa2_sec: increase ivsize range for AES-CTR Gagandeep Singh
` (4 subsequent siblings)
6 siblings, 0 replies; 26+ messages in thread
From: Gagandeep Singh @ 2026-09-30 7:08 UTC (permalink / raw)
To: dev, gakhil; +Cc: hemant.agrawal, stable, Gagandeep Singh
When build_sec_fd fails at index loop inside the enqueue burst loops,
the previously built FD entries (indices 0..loop-1) were never freed.
The cleanup loop iterated in the wrong direction, starting at the
failed index and going up to frames_to_send, which are entries that
were never built. This caused silent FLE pool exhaustion, after which
every subsequent build_sec_fd returned -ENOMEM, enqueue_burst
returned 0 indefinitely, and the crypto-perf test hung.
Fix both dpaa2_sec_enqueue_burst and dpaa2_sec_enqueue_burst_ordered
by clamping frames_to_send to loop + 1 and iterating from 0 to
free all allocated FLE buffers including the failed entry.
Fixes: 623326dded3a ("crypto/dpaa2_sec: introduce poll mode driver")
Cc: stable@dpdk.org
Signed-off-by: Gagandeep Singh <g.singh@nxp.com>
---
drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c | 6 ++++++
1 file changed, 6 insertions(+)
diff --git a/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c b/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c
index 2a015a3d82..15152cc5a1 100644
--- a/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c
+++ b/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c
@@ -1550,6 +1550,9 @@ dpaa2_sec_enqueue_burst(void *qp, struct rte_crypto_op **ops,
ret = build_sec_fd(*ops, &fd_arr[loop], bpid, dpaa2_qp);
if (ret) {
DPAA2_SEC_DP_DEBUG("FD build failed");
+ frames_to_send = loop + 1;
+ for (loop = 0; loop < frames_to_send; loop++)
+ free_fle(&fd_arr[loop], dpaa2_qp);
goto skip_tx;
}
ops++;
@@ -1909,6 +1912,9 @@ dpaa2_sec_enqueue_burst_ordered(void *qp, struct rte_crypto_op **ops,
ret = build_sec_fd(*ops, &fd_arr[loop], bpid, dpaa2_qp);
if (ret) {
DPAA2_SEC_DP_DEBUG("FD build failed");
+ frames_to_send = loop + 1;
+ for (loop = 0; loop < frames_to_send; loop++)
+ free_fle(&fd_arr[loop], dpaa2_qp);
goto skip_tx;
}
ops++;
--
2.25.1
^ permalink raw reply related [flat|nested] 26+ messages in thread
* [PATCH v2 3/6] crypto/dpaa2_sec: increase ivsize range for AES-CTR
2026-09-30 7:08 ` [PATCH v2 0/6] DPAA2 SEC related changes Gagandeep Singh
2026-09-30 7:08 ` [PATCH v2 1/6] crypto/dpaa2_sec: fix buffer overflow in GCM decrypt Gagandeep Singh
2026-09-30 7:08 ` [PATCH v2 2/6] crypto/dpaa2_sec: fix FLE pool leak on sec FD build failure Gagandeep Singh
@ 2026-09-30 7:08 ` Gagandeep Singh
2026-09-30 7:08 ` [PATCH v2 4/6] crypto/dpaa2_sec: add missing ECN capability Gagandeep Singh
` (3 subsequent siblings)
6 siblings, 0 replies; 26+ messages in thread
From: Gagandeep Singh @ 2026-09-30 7:08 UTC (permalink / raw)
To: dev, gakhil; +Cc: hemant.agrawal, Gagandeep Singh
Widen the AES-CTR IV size range from the fixed 16-byte value to
[12, 16] with a 4-byte increment. This allows 96-bit IVs (the
standard NIST SP 800-38A recommendation) in addition to 128-bit
IVs, aligning with common usage and test-vector expectations.
The change applies to both dpaa2_sec_capabilities and
dpaa2_pdcp_capabilities.
Signed-off-by: Hemant Agrawal <hemant.agrawal@nxp.com>
Signed-off-by: Gagandeep Singh <g.singh@nxp.com>
---
drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h | 8 ++++----
1 file changed, 4 insertions(+), 4 deletions(-)
diff --git a/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h b/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h
index ff32f3d860..b9a6440f78 100644
--- a/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h
+++ b/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h
@@ -625,9 +625,9 @@ static const struct rte_cryptodev_capabilities dpaa2_sec_capabilities[] = {
.increment = 8
},
.iv_size = {
- .min = 16,
+ .min = 12,
.max = 16,
- .increment = 0
+ .increment = 4
},
}, }
}, }
@@ -824,9 +824,9 @@ static const struct rte_cryptodev_capabilities dpaa2_pdcp_capabilities[] = {
.increment = 8
},
.iv_size = {
- .min = 16,
+ .min = 12,
.max = 16,
- .increment = 0
+ .increment = 4
}
}, }
}, }
--
2.25.1
^ permalink raw reply related [flat|nested] 26+ messages in thread
* [PATCH v2 4/6] crypto/dpaa2_sec: add missing ECN capability
2026-09-30 7:08 ` [PATCH v2 0/6] DPAA2 SEC related changes Gagandeep Singh
` (2 preceding siblings ...)
2026-09-30 7:08 ` [PATCH v2 3/6] crypto/dpaa2_sec: increase ivsize range for AES-CTR Gagandeep Singh
@ 2026-09-30 7:08 ` Gagandeep Singh
2026-09-30 7:08 ` [PATCH v2 5/6] crypto/dpaa2_sec: add support for env variables Gagandeep Singh
` (2 subsequent siblings)
6 siblings, 0 replies; 26+ messages in thread
From: Gagandeep Singh @ 2026-09-30 7:08 UTC (permalink / raw)
To: dev, gakhil; +Cc: hemant.agrawal, Gagandeep Singh
Set the .ecn = 1 flag in both tunnel-mode security capability
entries to advertise that the driver supports ECN (Explicit
Congestion Notification) copying during IPsec encap/decap.
Signed-off-by: Gagandeep Singh <g.singh@nxp.com>
---
drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h | 2 ++
1 file changed, 2 insertions(+)
diff --git a/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h b/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h
index b9a6440f78..94ba321c72 100644
--- a/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h
+++ b/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h
@@ -973,6 +973,7 @@ static const struct rte_security_capability dpaa2_sec_security_cap[] = {
.copy_df = 1,
.copy_dscp = 1,
.dec_ttl = 1,
+ .ecn = 1,
.esn = 1,
},
.replay_win_sz_max = 1024
@@ -992,6 +993,7 @@ static const struct rte_security_capability dpaa2_sec_security_cap[] = {
.copy_df = 1,
.copy_dscp = 1,
.dec_ttl = 1,
+ .ecn = 1,
.esn = 1,
},
.replay_win_sz_max = 1024
--
2.25.1
^ permalink raw reply related [flat|nested] 26+ messages in thread
* [PATCH v2 5/6] crypto/dpaa2_sec: add support for env variables
2026-09-30 7:08 ` [PATCH v2 0/6] DPAA2 SEC related changes Gagandeep Singh
` (3 preceding siblings ...)
2026-09-30 7:08 ` [PATCH v2 4/6] crypto/dpaa2_sec: add missing ECN capability Gagandeep Singh
@ 2026-09-30 7:08 ` Gagandeep Singh
2026-10-05 18:37 ` [EXTERNAL] " Akhil Goyal
2026-09-30 7:08 ` [PATCH v2 6/6] crypto/dpaa2_sec: support AES-GMAC Gagandeep Singh
2026-10-06 11:43 ` [PATCH v3 0/6] DPAA2 SEC related changes Gagandeep Singh
6 siblings, 1 reply; 26+ messages in thread
From: Gagandeep Singh @ 2026-09-30 7:08 UTC (permalink / raw)
To: dev, gakhil; +Cc: hemant.agrawal, Gagandeep Singh
Allow driver configuration via environment variables as a fallback
when devargs are not provided. After processing devargs (or when
devargs are absent), check DRIVER_STRICT_ORDER and DRIVER_DUMP_MODE
environment variables to set en_loose_ordered and dpaa2_sec_dp_dump.
This lets users configure the driver without modifying EAL arguments,
useful in environments where command-line access is restricted.
Signed-off-by: Gagandeep Singh <g.singh@nxp.com>
---
doc/guides/cryptodevs/dpaa2_sec.rst | 12 ++++++++-
drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c | 27 ++++++++++++++++++---
2 files changed, 34 insertions(+), 5 deletions(-)
diff --git a/doc/guides/cryptodevs/dpaa2_sec.rst b/doc/guides/cryptodevs/dpaa2_sec.rst
index f95c6282bb..925d3371bf 100644
--- a/doc/guides/cryptodevs/dpaa2_sec.rst
+++ b/doc/guides/cryptodevs/dpaa2_sec.rst
@@ -1,5 +1,5 @@
.. SPDX-License-Identifier: BSD-3-Clause
- Copyright 2016 NXP
+ Copyright 2016,2026 NXP
@@ -188,9 +188,19 @@ along with other useful debugging information like session, queue, descriptor
data.
e.g. ``fslmc:dpseci.1,drv_dump_mode=1``
+Alternatively, set the environment variable ``drv_dump_mode`` to the desired
+mode value. The environment variable is used as a fallback when the devarg is
+not provided, which is useful in production environments where modifying EAL
+command-line arguments is not practical.
+e.g. ``export drv_dump_mode=1``
+
Enable strict ordering
----------------------
Use dev arg option ``drv_strict_order=1`` to enable strict ordering.
By default, loose ordering is set for ordered schedule type event.
e.g. ``fslmc:dpseci.1,drv_strict_order=1``
+
+Alternatively, set the environment variable ``drv_strict_order=1`` to enable
+strict ordering without modifying EAL arguments.
+e.g. ``export drv_strict_order=1``
diff --git a/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c b/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c
index 15152cc5a1..0ff54fb644 100644
--- a/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c
+++ b/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c
@@ -4366,25 +4366,44 @@ check_devargs_handler(const char *key, const char *value,
static void
dpaa2_sec_get_devargs(struct rte_cryptodev *cryptodev, const char *key)
{
+ struct dpaa2_sec_dev_private *internals;
struct rte_kvargs *kvlist;
struct rte_devargs *devargs;
+ int ret;
+ char *env;
+
+ internals = cryptodev->data->dev_private;
devargs = cryptodev->device->devargs;
if (!devargs)
- return;
+ goto env_set;
kvlist = rte_kvargs_parse(devargs->args, NULL);
if (!kvlist)
- return;
+ goto env_set;
if (!rte_kvargs_count(kvlist, key)) {
rte_kvargs_free(kvlist);
- return;
+ goto env_set;
}
- rte_kvargs_process(kvlist, key,
+ ret = rte_kvargs_process(kvlist, key,
check_devargs_handler, (void *)cryptodev);
rte_kvargs_free(kvlist);
+ if (!ret)
+ return;
+
+env_set:
+ env = getenv(DRIVER_STRICT_ORDER);
+ if (env)
+ internals->en_loose_ordered = !atoi(env);
+
+ env = getenv(DRIVER_DUMP_MODE);
+ if (env) {
+ dpaa2_sec_dp_dump = atoi(env);
+ if (dpaa2_sec_dp_dump > DPAA2_SEC_DP_FULL_DUMP)
+ dpaa2_sec_dp_dump = DPAA2_SEC_DP_FULL_DUMP;
+ }
}
static int
--
2.25.1
^ permalink raw reply related [flat|nested] 26+ messages in thread
* [PATCH v2 6/6] crypto/dpaa2_sec: support AES-GMAC
2026-09-30 7:08 ` [PATCH v2 0/6] DPAA2 SEC related changes Gagandeep Singh
` (4 preceding siblings ...)
2026-09-30 7:08 ` [PATCH v2 5/6] crypto/dpaa2_sec: add support for env variables Gagandeep Singh
@ 2026-09-30 7:08 ` Gagandeep Singh
2026-10-05 18:14 ` [EXTERNAL] " Akhil Goyal
2026-10-06 11:43 ` [PATCH v3 0/6] DPAA2 SEC related changes Gagandeep Singh
6 siblings, 1 reply; 26+ messages in thread
From: Gagandeep Singh @ 2026-09-30 7:08 UTC (permalink / raw)
To: dev, gakhil; +Cc: hemant.agrawal, Gagandeep Singh
Add AES-GMAC (RTE_CRYPTO_AUTH_AES_GMAC) support to the dpaa2_sec driver
for both symmetric auth-only and IPsec lookaside protocol paths.
For the auth-only path, AES-GMAC uses the GCM shared descriptor
(cnstr_shdsc_gcm_encap/decap) with per-packet IV and data supplied
via sym_op->auth.{iv,data,digest}.
For the IPsec lookaside protocol path, AES-GMAC maps to
OP_PCL_IPSEC_AES_NULL_WITH_GMAC. The SEC hardware protocol word
treats this as a cipher type, so the GMAC key and algtype are placed
in cipherdata rather than authdata. This is handled in
dpaa2_sec_ipsec_proto_init() by overriding cipherdata with the auth
key and setting authdata algtype to HMAC_NULL.
Also add AES-GMAC to dpaa2_sec_capabilities[] as an AUTH xform.
Signed-off-by: Gagandeep Singh <g.singh@nxp.com>
---
doc/guides/cryptodevs/dpaa2_sec.rst | 1 +
doc/guides/cryptodevs/features/dpaa2_sec.ini | 3 ++
drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c | 43 +++++++++++++++++++-
drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h | 28 ++++++++++++-
4 files changed, 73 insertions(+), 2 deletions(-)
diff --git a/doc/guides/cryptodevs/dpaa2_sec.rst b/doc/guides/cryptodevs/dpaa2_sec.rst
index 925d3371bf..d9a661c272 100644
--- a/doc/guides/cryptodevs/dpaa2_sec.rst
+++ b/doc/guides/cryptodevs/dpaa2_sec.rst
@@ -125,6 +125,7 @@ Hash algorithms:
* ``RTE_CRYPTO_AUTH_MD5_HMAC``
* ``RTE_CRYPTO_AUTH_AES_XCBC_MAC``
* ``RTE_CRYPTO_AUTH_AES_CMAC``
+* ``RTE_CRYPTO_AUTH_AES_GMAC``
AEAD algorithms:
diff --git a/doc/guides/cryptodevs/features/dpaa2_sec.ini b/doc/guides/cryptodevs/features/dpaa2_sec.ini
index a280c7b51b..49434739f0 100644
--- a/doc/guides/cryptodevs/features/dpaa2_sec.ini
+++ b/doc/guides/cryptodevs/features/dpaa2_sec.ini
@@ -48,6 +48,9 @@ SHA384 HMAC = Y
SHA512 = Y
SHA512 HMAC = Y
SNOW3G UIA2 = Y
+AES GMAC (128) = Y
+AES GMAC (192) = Y
+AES GMAC (256) = Y
AES XCBC MAC = Y
ZUC EIA3 = Y
AES CMAC (128) = Y
diff --git a/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c b/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c
index 0ff54fb644..8e271a3b50 100644
--- a/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c
+++ b/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c
@@ -1,7 +1,7 @@
/* SPDX-License-Identifier: BSD-3-Clause
*
* Copyright (c) 2016 Freescale Semiconductor, Inc. All rights reserved.
- * Copyright 2016-2025 NXP
+ * Copyright 2016-2026 NXP
*
*/
@@ -2483,6 +2483,30 @@ dpaa2_sec_auth_init(struct rte_crypto_sym_xform *xform,
!session->dir,
session->digest_length);
break;
+ case RTE_CRYPTO_AUTH_AES_GMAC:
+ /* AES-GMAC is an authentication-only operation using the
+ * GCM algorithm with a zero-length payload. The IV is
+ * passed per-packet via the auth xform iv field, and the
+ * data to authenticate is in sym_op->auth.data.
+ */
+ session->iv.offset = xform->auth.iv.offset;
+ session->iv.length = xform->auth.iv.length;
+ session->auth_alg = RTE_CRYPTO_AUTH_AES_GMAC;
+ authdata.algtype = OP_ALG_ALGSEL_AES;
+ authdata.algmode = OP_ALG_AAI_GCM;
+ if (session->dir == DIR_ENC)
+ bufsize = cnstr_shdsc_gcm_encap(
+ priv->flc_desc[DESC_INITFINAL].desc,
+ 1, 0, SHR_NEVER, &authdata,
+ session->iv.length,
+ session->digest_length);
+ else
+ bufsize = cnstr_shdsc_gcm_decap(
+ priv->flc_desc[DESC_INITFINAL].desc,
+ 1, 0, SHR_NEVER, &authdata,
+ session->iv.length,
+ session->digest_length);
+ break;
default:
DPAA2_SEC_ERR("Crypto: Unsupported Auth alg %s (%u)",
rte_cryptodev_get_auth_algo_string(xform->auth.algo),
@@ -3046,6 +3070,18 @@ dpaa2_sec_ipsec_proto_init(struct rte_crypto_cipher_xform *cipher_xform,
authdata->algtype = OP_PCL_IPSEC_HMAC_MD5_96;
authdata->algmode = OP_ALG_AAI_HMAC;
break;
+ case RTE_CRYPTO_AUTH_AES_GMAC:
+ /* AES-GMAC uses OP_PCL_IPSEC_AES_NULL_WITH_GMAC which is
+ * treated as a cipher type in the SEC protocol word.
+ * Place the GMAC key in cipherdata and set authdata to NULL.
+ */
+ cipherdata->key = (size_t)session->auth_key.data;
+ cipherdata->keylen = session->auth_key.length;
+ cipherdata->key_enc_flags = 0;
+ cipherdata->key_type = RTA_DATA_IMM;
+ cipherdata->algtype = OP_PCL_IPSEC_AES_NULL_WITH_GMAC;
+ authdata->algtype = OP_PCL_IPSEC_HMAC_NULL;
+ return 0;
case RTE_CRYPTO_AUTH_SHA224_HMAC:
authdata->algmode = OP_ALG_AAI_HMAC;
if (session->digest_length == 6)
@@ -3142,6 +3178,9 @@ dpaa2_sec_set_ipsec_session(struct rte_cryptodev *dev,
PMD_INIT_FUNC_TRACE();
+ memset(&authdata, 0, sizeof(authdata));
+ memset(&cipherdata, 0, sizeof(cipherdata));
+
RTE_SET_USED(dev);
/** Make FLC address to align with stashing, low 6 bits are used
@@ -3217,6 +3256,7 @@ dpaa2_sec_set_ipsec_session(struct rte_cryptodev *dev,
case OP_PCL_IPSEC_AES_GCM8:
case OP_PCL_IPSEC_AES_GCM12:
case OP_PCL_IPSEC_AES_GCM16:
+ case OP_PCL_IPSEC_AES_NULL_WITH_GMAC:
memcpy(encap_pdb.gcm.salt,
(uint8_t *)&(ipsec_xform->salt), 4);
break;
@@ -3357,6 +3397,7 @@ dpaa2_sec_set_ipsec_session(struct rte_cryptodev *dev,
case OP_PCL_IPSEC_AES_GCM8:
case OP_PCL_IPSEC_AES_GCM12:
case OP_PCL_IPSEC_AES_GCM16:
+ case OP_PCL_IPSEC_AES_NULL_WITH_GMAC:
memcpy(decap_pdb.gcm.salt,
(uint8_t *)&(ipsec_xform->salt), 4);
break;
diff --git a/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h b/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h
index 94ba321c72..913c91ebc2 100644
--- a/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h
+++ b/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h
@@ -1,7 +1,7 @@
/* SPDX-License-Identifier: BSD-3-Clause
*
* Copyright (c) 2016 Freescale Semiconductor, Inc. All rights reserved.
- * Copyright 2016,2020-2024 NXP
+ * Copyright 2016,2020-2026 NXP
*
*/
@@ -528,6 +528,32 @@ static const struct rte_cryptodev_capabilities dpaa2_sec_capabilities[] = {
}, }
}, }
},
+ { /* AES GMAC */
+ .op = RTE_CRYPTO_OP_TYPE_SYMMETRIC,
+ {.sym = {
+ .xform_type = RTE_CRYPTO_SYM_XFORM_AUTH,
+ {.auth = {
+ .algo = RTE_CRYPTO_AUTH_AES_GMAC,
+ .block_size = 16,
+ .key_size = {
+ .min = 16,
+ .max = 32,
+ .increment = 8
+ },
+ .digest_size = {
+ .min = 8,
+ .max = 16,
+ .increment = 4
+ },
+ .aad_size = { 0 },
+ .iv_size = {
+ .min = 12,
+ .max = 12,
+ .increment = 0
+ },
+ }, }
+ }, }
+ },
{ /* AES XCBC HMAC */
.op = RTE_CRYPTO_OP_TYPE_SYMMETRIC,
{.sym = {
--
2.25.1
^ permalink raw reply related [flat|nested] 26+ messages in thread
* RE: [EXTERNAL] [PATCH v2 6/6] crypto/dpaa2_sec: support AES-GMAC
2026-09-30 7:08 ` [PATCH v2 6/6] crypto/dpaa2_sec: support AES-GMAC Gagandeep Singh
@ 2026-10-05 18:14 ` Akhil Goyal
0 siblings, 0 replies; 26+ messages in thread
From: Akhil Goyal @ 2026-10-05 18:14 UTC (permalink / raw)
To: Gagandeep Singh, dev@dpdk.org; +Cc: hemant.agrawal@nxp.com
> Add AES-GMAC (RTE_CRYPTO_AUTH_AES_GMAC) support to the dpaa2_sec
> driver
> for both symmetric auth-only and IPsec lookaside protocol paths.
>
> For the auth-only path, AES-GMAC uses the GCM shared descriptor
> (cnstr_shdsc_gcm_encap/decap) with per-packet IV and data supplied
> via sym_op->auth.{iv,data,digest}.
>
> For the IPsec lookaside protocol path, AES-GMAC maps to
> OP_PCL_IPSEC_AES_NULL_WITH_GMAC. The SEC hardware protocol word
> treats this as a cipher type, so the GMAC key and algtype are placed
> in cipherdata rather than authdata. This is handled in
> dpaa2_sec_ipsec_proto_init() by overriding cipherdata with the auth
> key and setting authdata algtype to HMAC_NULL.
>
> Also add AES-GMAC to dpaa2_sec_capabilities[] as an AUTH xform.
>
> Signed-off-by: Gagandeep Singh <g.singh@nxp.com>
> ---
> doc/guides/cryptodevs/dpaa2_sec.rst | 1 +
> doc/guides/cryptodevs/features/dpaa2_sec.ini | 3 ++
> drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c | 43 +++++++++++++++++++-
> drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h | 28 ++++++++++++-
> 4 files changed, 73 insertions(+), 2 deletions(-)
>
> diff --git a/doc/guides/cryptodevs/dpaa2_sec.rst
> b/doc/guides/cryptodevs/dpaa2_sec.rst
> index 925d3371bf..d9a661c272 100644
> --- a/doc/guides/cryptodevs/dpaa2_sec.rst
> +++ b/doc/guides/cryptodevs/dpaa2_sec.rst
> @@ -125,6 +125,7 @@ Hash algorithms:
> * ``RTE_CRYPTO_AUTH_MD5_HMAC``
> * ``RTE_CRYPTO_AUTH_AES_XCBC_MAC``
> * ``RTE_CRYPTO_AUTH_AES_CMAC``
> +* ``RTE_CRYPTO_AUTH_AES_GMAC``
>
> AEAD algorithms:
>
> diff --git a/doc/guides/cryptodevs/features/dpaa2_sec.ini
> b/doc/guides/cryptodevs/features/dpaa2_sec.ini
> index a280c7b51b..49434739f0 100644
> --- a/doc/guides/cryptodevs/features/dpaa2_sec.ini
> +++ b/doc/guides/cryptodevs/features/dpaa2_sec.ini
> @@ -48,6 +48,9 @@ SHA384 HMAC = Y
> SHA512 = Y
> SHA512 HMAC = Y
> SNOW3G UIA2 = Y
> +AES GMAC (128) = Y
> +AES GMAC (192) = Y
> +AES GMAC (256) = Y
> AES XCBC MAC = Y
> ZUC EIA3 = Y
> AES CMAC (128) = Y
Please fix
Warning generate_overview_table(): Unknown feature 'AES GMAC (128)' in 'dpaa2_sec.ini'
^ permalink raw reply [flat|nested] 26+ messages in thread
* RE: [EXTERNAL] [PATCH v2 5/6] crypto/dpaa2_sec: add support for env variables
2026-09-30 7:08 ` [PATCH v2 5/6] crypto/dpaa2_sec: add support for env variables Gagandeep Singh
@ 2026-10-05 18:37 ` Akhil Goyal
2026-10-06 4:15 ` Gagandeep Singh
0 siblings, 1 reply; 26+ messages in thread
From: Akhil Goyal @ 2026-10-05 18:37 UTC (permalink / raw)
To: Gagandeep Singh, dev@dpdk.org; +Cc: hemant.agrawal@nxp.com, Stephen Hemminger
> Allow driver configuration via environment variables as a fallback
> when devargs are not provided. After processing devargs (or when
> devargs are absent), check DRIVER_STRICT_ORDER and DRIVER_DUMP_MODE
> environment variables to set en_loose_ordered and dpaa2_sec_dp_dump.
>
> This lets users configure the driver without modifying EAL arguments,
> useful in environments where command-line access is restricted.
>
> Signed-off-by: Gagandeep Singh <g.singh@nxp.com>
> ---
> doc/guides/cryptodevs/dpaa2_sec.rst | 12 ++++++++-
> drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c | 27 ++++++++++++++++++---
> 2 files changed, 34 insertions(+), 5 deletions(-)
>
> diff --git a/doc/guides/cryptodevs/dpaa2_sec.rst
> b/doc/guides/cryptodevs/dpaa2_sec.rst
> index f95c6282bb..925d3371bf 100644
> --- a/doc/guides/cryptodevs/dpaa2_sec.rst
> +++ b/doc/guides/cryptodevs/dpaa2_sec.rst
> @@ -1,5 +1,5 @@
> .. SPDX-License-Identifier: BSD-3-Clause
> - Copyright 2016 NXP
> + Copyright 2016,2026 NXP
>
>
>
> @@ -188,9 +188,19 @@ along with other useful debugging information like
> session, queue, descriptor
> data.
> e.g. ``fslmc:dpseci.1,drv_dump_mode=1``
>
> +Alternatively, set the environment variable ``drv_dump_mode`` to the desired
> +mode value. The environment variable is used as a fallback when the devarg is
> +not provided, which is useful in production environments where modifying EAL
> +command-line arguments is not practical.
> +e.g. ``export drv_dump_mode=1``
> +
I think Stephen has pointed out that this is bad precedent.
DPDK has already a way to configure to avoid env variables.
It is not clear why we need this?
While there is a way to set env variable, but cannot change command line args?
Is this a debug thing?
^ permalink raw reply [flat|nested] 26+ messages in thread
* RE: [EXTERNAL] [PATCH v2 5/6] crypto/dpaa2_sec: add support for env variables
2026-10-05 18:37 ` [EXTERNAL] " Akhil Goyal
@ 2026-10-06 4:15 ` Gagandeep Singh
0 siblings, 0 replies; 26+ messages in thread
From: Gagandeep Singh @ 2026-10-06 4:15 UTC (permalink / raw)
To: Akhil Goyal, dev@dpdk.org; +Cc: Hemant Agrawal, Stephen Hemminger
Hi,
NXP Confidential
> -----Original Message-----
> From: Akhil Goyal <gakhil@marvell.com>
> Sent: Tuesday, October 6, 2026 12:08 AM
> To: Gagandeep Singh <G.Singh@nxp.com>; dev@dpdk.org
> Cc: Hemant Agrawal <hemant.agrawal@nxp.com>; Stephen Hemminger
> <stephen@networkplumber.org>
> Subject: RE: [EXTERNAL] [PATCH v2 5/6] crypto/dpaa2_sec: add support for env
> variables
>
> > Allow driver configuration via environment variables as a fallback
> > when devargs are not provided. After processing devargs (or when
> > devargs are absent), check DRIVER_STRICT_ORDER and DRIVER_DUMP_MODE
> > environment variables to set en_loose_ordered and dpaa2_sec_dp_dump.
> >
> > This lets users configure the driver without modifying EAL arguments,
> > useful in environments where command-line access is restricted.
> >
> > Signed-off-by: Gagandeep Singh <g.singh@nxp.com>
> > ---
> > doc/guides/cryptodevs/dpaa2_sec.rst | 12 ++++++++-
> > drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c | 27
> > ++++++++++++++++++---
> > 2 files changed, 34 insertions(+), 5 deletions(-)
> >
> > diff --git a/doc/guides/cryptodevs/dpaa2_sec.rst
> > b/doc/guides/cryptodevs/dpaa2_sec.rst
> > index f95c6282bb..925d3371bf 100644
> > --- a/doc/guides/cryptodevs/dpaa2_sec.rst
> > +++ b/doc/guides/cryptodevs/dpaa2_sec.rst
> > @@ -1,5 +1,5 @@
> > .. SPDX-License-Identifier: BSD-3-Clause
> > - Copyright 2016 NXP
> > + Copyright 2016,2026 NXP
> >
> >
> >
> > @@ -188,9 +188,19 @@ along with other useful debugging information
> > like session, queue, descriptor data.
> > e.g. ``fslmc:dpseci.1,drv_dump_mode=1``
> >
> > +Alternatively, set the environment variable ``drv_dump_mode`` to the
> > +desired mode value. The environment variable is used as a fallback
> > +when the devarg is not provided, which is useful in production
> > +environments where modifying EAL command-line arguments is not practical.
> > +e.g. ``export drv_dump_mode=1``
> > +
>
> I think Stephen has pointed out that this is bad precedent.
> DPDK has already a way to configure to avoid env variables.
> It is not clear why we need this?
> While there is a way to set env variable, but cannot change command line args?
> Is this a debug thing?
This is mainly intended for debug/diagnostic use. Many of our customers do not expose DPDK command-line arguments and instead use a fixed set of EAL parameters built into the application or deployment framework. In such cases, an environment variable provides a simple way to enable temporary diagnostics in the fields.
That said, I understand the concern about introducing an alternative configuration mechanism. If the preference is to keep configuration strictly through devargs, I can remove this patch.
^ permalink raw reply [flat|nested] 26+ messages in thread
* [PATCH v3 0/6] DPAA2 SEC related changes
2026-09-30 7:08 ` [PATCH v2 0/6] DPAA2 SEC related changes Gagandeep Singh
` (5 preceding siblings ...)
2026-09-30 7:08 ` [PATCH v2 6/6] crypto/dpaa2_sec: support AES-GMAC Gagandeep Singh
@ 2026-10-06 11:43 ` Gagandeep Singh
2026-10-06 11:43 ` [PATCH v3 1/6] crypto/dpaa2_sec: fix buffer overflow in GCM decrypt Gagandeep Singh
` (5 more replies)
6 siblings, 6 replies; 26+ messages in thread
From: Gagandeep Singh @ 2026-10-06 11:43 UTC (permalink / raw)
To: dev, gakhil; +Cc: hemant.agrawal
V3-changes:
- updated dpaa3_sec.ini with correct feature name.
V2-changes:
- Support AES-GMAC as AUTH algorithm instead of as AEAD.
This series include bug fixes, enhancement and AES-GMAC support
Gagandeep Singh (6):
crypto/dpaa2_sec: fix buffer overflow in GCM decrypt
crypto/dpaa2_sec: fix FLE pool leak on sec FD build failure
crypto/dpaa2_sec: increase ivsize range for AES-CTR
crypto/dpaa2_sec: add missing ECN capability
crypto/dpaa2_sec: add support for env variables
crypto/dpaa2_sec: support AES-GMAC
doc/guides/cryptodevs/dpaa2_sec.rst | 13 +++-
doc/guides/cryptodevs/features/dpaa2_sec.ini | 1 +
drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c | 78 ++++++++++++++++++--
drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h | 40 ++++++++--
4 files changed, 120 insertions(+), 12 deletions(-)
--
2.25.1
^ permalink raw reply [flat|nested] 26+ messages in thread
* [PATCH v3 1/6] crypto/dpaa2_sec: fix buffer overflow in GCM decrypt
2026-10-06 11:43 ` [PATCH v3 0/6] DPAA2 SEC related changes Gagandeep Singh
@ 2026-10-06 11:43 ` Gagandeep Singh
2026-10-06 11:43 ` [PATCH v3 2/6] crypto/dpaa2_sec: fix FLE pool leak on sec FD build failure Gagandeep Singh
` (4 subsequent siblings)
5 siblings, 0 replies; 26+ messages in thread
From: Gagandeep Singh @ 2026-10-06 11:43 UTC (permalink / raw)
To: dev, gakhil; +Cc: hemant.agrawal, stable, Gagandeep Singh
In build_authenc_gcm_fd, when both AAD (auth_only_len > 0) and decrypt
direction are active, the SGE layout occupies 8 entries plus 16 bytes of
old_icv storage at index 8. The FLE pool buffer was only 256 bytes
(8 x 32), causing old_icv to be written one entry past the end of the
allocated buffer. The resulting virtual address was not mapped by the
IOMMU, so DPAA2_VADDR_TO_IOVA returned 0 and the SEC engine received
iova=0x00000000 as the ICV buffer address, triggering an SMMU
translation fault (FSR=0x402 TF).
Additionally, the upfront bpid/IVP initialization only covered sge+3,
leaving sge+4 (the input data SGE when AAD is present) without a valid
bpid or IVP assignment.
Increase FLE_POOL_BUF_SIZE from 256 to 288 (9 x 32 bytes) to
accommodate the full layout, and extend the bpid/IVP initialization
to cover sge+4 in both branches of build_authenc_gcm_fd.
Fixes: 13273250eec5 ("crypto/dpaa2_sec: support AES-GCM and CTR")
Cc: stable@dpdk.org
Signed-off-by: Gagandeep Singh <g.singh@nxp.com>
---
drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c | 2 ++
drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h | 2 +-
2 files changed, 3 insertions(+), 1 deletion(-)
diff --git a/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c b/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c
index 3d980d096f..2a015a3d82 100644
--- a/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c
+++ b/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c
@@ -569,6 +569,7 @@ build_authenc_gcm_fd(dpaa2_sec_session *sess,
DPAA2_SET_FLE_BPID(sge + 1, bpid);
DPAA2_SET_FLE_BPID(sge + 2, bpid);
DPAA2_SET_FLE_BPID(sge + 3, bpid);
+ DPAA2_SET_FLE_BPID(sge + 4, bpid);
} else {
DPAA2_SET_FD_IVP(fd);
DPAA2_SET_FLE_IVP(fle);
@@ -577,6 +578,7 @@ build_authenc_gcm_fd(dpaa2_sec_session *sess,
DPAA2_SET_FLE_IVP((sge + 1));
DPAA2_SET_FLE_IVP((sge + 2));
DPAA2_SET_FLE_IVP((sge + 3));
+ DPAA2_SET_FLE_IVP((sge + 4));
}
/* Save the shared descriptor */
diff --git a/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h b/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h
index 755c8e9cc3..ff32f3d860 100644
--- a/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h
+++ b/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h
@@ -17,7 +17,7 @@ extern uint8_t cryptodev_driver_id;
/* FLE_POOL_NUM_BUFS is set as per the ipsec-secgw application */
#define FLE_POOL_NUM_BUFS 32000
-#define FLE_POOL_BUF_SIZE 256
+#define FLE_POOL_BUF_SIZE 288
#define FLE_POOL_CACHE_SIZE 512
#define FLE_SG_MEM_SIZE(num) (FLE_POOL_BUF_SIZE + ((num) * 32))
--
2.25.1
^ permalink raw reply related [flat|nested] 26+ messages in thread
* [PATCH v3 2/6] crypto/dpaa2_sec: fix FLE pool leak on sec FD build failure
2026-10-06 11:43 ` [PATCH v3 0/6] DPAA2 SEC related changes Gagandeep Singh
2026-10-06 11:43 ` [PATCH v3 1/6] crypto/dpaa2_sec: fix buffer overflow in GCM decrypt Gagandeep Singh
@ 2026-10-06 11:43 ` Gagandeep Singh
2026-10-06 11:43 ` [PATCH v3 3/6] crypto/dpaa2_sec: increase ivsize range for AES-CTR Gagandeep Singh
` (3 subsequent siblings)
5 siblings, 0 replies; 26+ messages in thread
From: Gagandeep Singh @ 2026-10-06 11:43 UTC (permalink / raw)
To: dev, gakhil; +Cc: hemant.agrawal, stable, Gagandeep Singh
When build_sec_fd fails at index loop inside the enqueue burst loops,
the previously built FD entries (indices 0..loop-1) were never freed.
The cleanup loop iterated in the wrong direction, starting at the
failed index and going up to frames_to_send, which are entries that
were never built. This caused silent FLE pool exhaustion, after which
every subsequent build_sec_fd returned -ENOMEM, enqueue_burst
returned 0 indefinitely, and the crypto-perf test hung.
Fix both dpaa2_sec_enqueue_burst and dpaa2_sec_enqueue_burst_ordered
by clamping frames_to_send to loop + 1 and iterating from 0 to
free all allocated FLE buffers including the failed entry.
Fixes: 623326dded3a ("crypto/dpaa2_sec: introduce poll mode driver")
Cc: stable@dpdk.org
Signed-off-by: Gagandeep Singh <g.singh@nxp.com>
---
drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c | 6 ++++++
1 file changed, 6 insertions(+)
diff --git a/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c b/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c
index 2a015a3d82..15152cc5a1 100644
--- a/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c
+++ b/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c
@@ -1550,6 +1550,9 @@ dpaa2_sec_enqueue_burst(void *qp, struct rte_crypto_op **ops,
ret = build_sec_fd(*ops, &fd_arr[loop], bpid, dpaa2_qp);
if (ret) {
DPAA2_SEC_DP_DEBUG("FD build failed");
+ frames_to_send = loop + 1;
+ for (loop = 0; loop < frames_to_send; loop++)
+ free_fle(&fd_arr[loop], dpaa2_qp);
goto skip_tx;
}
ops++;
@@ -1909,6 +1912,9 @@ dpaa2_sec_enqueue_burst_ordered(void *qp, struct rte_crypto_op **ops,
ret = build_sec_fd(*ops, &fd_arr[loop], bpid, dpaa2_qp);
if (ret) {
DPAA2_SEC_DP_DEBUG("FD build failed");
+ frames_to_send = loop + 1;
+ for (loop = 0; loop < frames_to_send; loop++)
+ free_fle(&fd_arr[loop], dpaa2_qp);
goto skip_tx;
}
ops++;
--
2.25.1
^ permalink raw reply related [flat|nested] 26+ messages in thread
* [PATCH v3 3/6] crypto/dpaa2_sec: increase ivsize range for AES-CTR
2026-10-06 11:43 ` [PATCH v3 0/6] DPAA2 SEC related changes Gagandeep Singh
2026-10-06 11:43 ` [PATCH v3 1/6] crypto/dpaa2_sec: fix buffer overflow in GCM decrypt Gagandeep Singh
2026-10-06 11:43 ` [PATCH v3 2/6] crypto/dpaa2_sec: fix FLE pool leak on sec FD build failure Gagandeep Singh
@ 2026-10-06 11:43 ` Gagandeep Singh
2026-10-06 11:43 ` [PATCH v3 4/6] crypto/dpaa2_sec: add missing ECN capability Gagandeep Singh
` (2 subsequent siblings)
5 siblings, 0 replies; 26+ messages in thread
From: Gagandeep Singh @ 2026-10-06 11:43 UTC (permalink / raw)
To: dev, gakhil; +Cc: hemant.agrawal, Gagandeep Singh
Widen the AES-CTR IV size range from the fixed 16-byte value to
[12, 16] with a 4-byte increment. This allows 96-bit IVs (the
standard NIST SP 800-38A recommendation) in addition to 128-bit
IVs, aligning with common usage and test-vector expectations.
The change applies to both dpaa2_sec_capabilities and
dpaa2_pdcp_capabilities.
Signed-off-by: Hemant Agrawal <hemant.agrawal@nxp.com>
Signed-off-by: Gagandeep Singh <g.singh@nxp.com>
---
drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h | 8 ++++----
1 file changed, 4 insertions(+), 4 deletions(-)
diff --git a/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h b/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h
index ff32f3d860..b9a6440f78 100644
--- a/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h
+++ b/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h
@@ -625,9 +625,9 @@ static const struct rte_cryptodev_capabilities dpaa2_sec_capabilities[] = {
.increment = 8
},
.iv_size = {
- .min = 16,
+ .min = 12,
.max = 16,
- .increment = 0
+ .increment = 4
},
}, }
}, }
@@ -824,9 +824,9 @@ static const struct rte_cryptodev_capabilities dpaa2_pdcp_capabilities[] = {
.increment = 8
},
.iv_size = {
- .min = 16,
+ .min = 12,
.max = 16,
- .increment = 0
+ .increment = 4
}
}, }
}, }
--
2.25.1
^ permalink raw reply related [flat|nested] 26+ messages in thread
* [PATCH v3 4/6] crypto/dpaa2_sec: add missing ECN capability
2026-10-06 11:43 ` [PATCH v3 0/6] DPAA2 SEC related changes Gagandeep Singh
` (2 preceding siblings ...)
2026-10-06 11:43 ` [PATCH v3 3/6] crypto/dpaa2_sec: increase ivsize range for AES-CTR Gagandeep Singh
@ 2026-10-06 11:43 ` Gagandeep Singh
2026-10-06 11:43 ` [PATCH v3 5/6] crypto/dpaa2_sec: add support for env variables Gagandeep Singh
2026-10-06 11:43 ` [PATCH v3 6/6] crypto/dpaa2_sec: support AES-GMAC Gagandeep Singh
5 siblings, 0 replies; 26+ messages in thread
From: Gagandeep Singh @ 2026-10-06 11:43 UTC (permalink / raw)
To: dev, gakhil; +Cc: hemant.agrawal, Gagandeep Singh
Set the .ecn = 1 flag in both tunnel-mode security capability
entries to advertise that the driver supports ECN (Explicit
Congestion Notification) copying during IPsec encap/decap.
Signed-off-by: Gagandeep Singh <g.singh@nxp.com>
---
drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h | 2 ++
1 file changed, 2 insertions(+)
diff --git a/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h b/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h
index b9a6440f78..94ba321c72 100644
--- a/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h
+++ b/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h
@@ -973,6 +973,7 @@ static const struct rte_security_capability dpaa2_sec_security_cap[] = {
.copy_df = 1,
.copy_dscp = 1,
.dec_ttl = 1,
+ .ecn = 1,
.esn = 1,
},
.replay_win_sz_max = 1024
@@ -992,6 +993,7 @@ static const struct rte_security_capability dpaa2_sec_security_cap[] = {
.copy_df = 1,
.copy_dscp = 1,
.dec_ttl = 1,
+ .ecn = 1,
.esn = 1,
},
.replay_win_sz_max = 1024
--
2.25.1
^ permalink raw reply related [flat|nested] 26+ messages in thread
* [PATCH v3 5/6] crypto/dpaa2_sec: add support for env variables
2026-10-06 11:43 ` [PATCH v3 0/6] DPAA2 SEC related changes Gagandeep Singh
` (3 preceding siblings ...)
2026-10-06 11:43 ` [PATCH v3 4/6] crypto/dpaa2_sec: add missing ECN capability Gagandeep Singh
@ 2026-10-06 11:43 ` Gagandeep Singh
2026-10-06 11:43 ` [PATCH v3 6/6] crypto/dpaa2_sec: support AES-GMAC Gagandeep Singh
5 siblings, 0 replies; 26+ messages in thread
From: Gagandeep Singh @ 2026-10-06 11:43 UTC (permalink / raw)
To: dev, gakhil; +Cc: hemant.agrawal, Gagandeep Singh
Allow driver configuration via environment variables as a fallback
when devargs are not provided. After processing devargs (or when
devargs are absent), check DRIVER_STRICT_ORDER and DRIVER_DUMP_MODE
environment variables to set en_loose_ordered and dpaa2_sec_dp_dump.
This lets users configure the driver without modifying EAL arguments,
useful in environments where command-line access is restricted.
Signed-off-by: Gagandeep Singh <g.singh@nxp.com>
---
doc/guides/cryptodevs/dpaa2_sec.rst | 12 ++++++++-
drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c | 27 ++++++++++++++++++---
2 files changed, 34 insertions(+), 5 deletions(-)
diff --git a/doc/guides/cryptodevs/dpaa2_sec.rst b/doc/guides/cryptodevs/dpaa2_sec.rst
index f95c6282bb..925d3371bf 100644
--- a/doc/guides/cryptodevs/dpaa2_sec.rst
+++ b/doc/guides/cryptodevs/dpaa2_sec.rst
@@ -1,5 +1,5 @@
.. SPDX-License-Identifier: BSD-3-Clause
- Copyright 2016 NXP
+ Copyright 2016,2026 NXP
@@ -188,9 +188,19 @@ along with other useful debugging information like session, queue, descriptor
data.
e.g. ``fslmc:dpseci.1,drv_dump_mode=1``
+Alternatively, set the environment variable ``drv_dump_mode`` to the desired
+mode value. The environment variable is used as a fallback when the devarg is
+not provided, which is useful in production environments where modifying EAL
+command-line arguments is not practical.
+e.g. ``export drv_dump_mode=1``
+
Enable strict ordering
----------------------
Use dev arg option ``drv_strict_order=1`` to enable strict ordering.
By default, loose ordering is set for ordered schedule type event.
e.g. ``fslmc:dpseci.1,drv_strict_order=1``
+
+Alternatively, set the environment variable ``drv_strict_order=1`` to enable
+strict ordering without modifying EAL arguments.
+e.g. ``export drv_strict_order=1``
diff --git a/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c b/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c
index 15152cc5a1..0ff54fb644 100644
--- a/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c
+++ b/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c
@@ -4366,25 +4366,44 @@ check_devargs_handler(const char *key, const char *value,
static void
dpaa2_sec_get_devargs(struct rte_cryptodev *cryptodev, const char *key)
{
+ struct dpaa2_sec_dev_private *internals;
struct rte_kvargs *kvlist;
struct rte_devargs *devargs;
+ int ret;
+ char *env;
+
+ internals = cryptodev->data->dev_private;
devargs = cryptodev->device->devargs;
if (!devargs)
- return;
+ goto env_set;
kvlist = rte_kvargs_parse(devargs->args, NULL);
if (!kvlist)
- return;
+ goto env_set;
if (!rte_kvargs_count(kvlist, key)) {
rte_kvargs_free(kvlist);
- return;
+ goto env_set;
}
- rte_kvargs_process(kvlist, key,
+ ret = rte_kvargs_process(kvlist, key,
check_devargs_handler, (void *)cryptodev);
rte_kvargs_free(kvlist);
+ if (!ret)
+ return;
+
+env_set:
+ env = getenv(DRIVER_STRICT_ORDER);
+ if (env)
+ internals->en_loose_ordered = !atoi(env);
+
+ env = getenv(DRIVER_DUMP_MODE);
+ if (env) {
+ dpaa2_sec_dp_dump = atoi(env);
+ if (dpaa2_sec_dp_dump > DPAA2_SEC_DP_FULL_DUMP)
+ dpaa2_sec_dp_dump = DPAA2_SEC_DP_FULL_DUMP;
+ }
}
static int
--
2.25.1
^ permalink raw reply related [flat|nested] 26+ messages in thread
* [PATCH v3 6/6] crypto/dpaa2_sec: support AES-GMAC
2026-10-06 11:43 ` [PATCH v3 0/6] DPAA2 SEC related changes Gagandeep Singh
` (4 preceding siblings ...)
2026-10-06 11:43 ` [PATCH v3 5/6] crypto/dpaa2_sec: add support for env variables Gagandeep Singh
@ 2026-10-06 11:43 ` Gagandeep Singh
5 siblings, 0 replies; 26+ messages in thread
From: Gagandeep Singh @ 2026-10-06 11:43 UTC (permalink / raw)
To: dev, gakhil; +Cc: hemant.agrawal, Gagandeep Singh
Add AES-GMAC (RTE_CRYPTO_AUTH_AES_GMAC) support to the dpaa2_sec driver
for both symmetric auth-only and IPsec lookaside protocol paths.
For the auth-only path, AES-GMAC uses the GCM shared descriptor
(cnstr_shdsc_gcm_encap/decap) with per-packet IV and data supplied
via sym_op->auth.{iv,data,digest}.
For the IPsec lookaside protocol path, AES-GMAC maps to
OP_PCL_IPSEC_AES_NULL_WITH_GMAC. The SEC hardware protocol word
treats this as a cipher type, so the GMAC key and algtype are placed
in cipherdata rather than authdata. This is handled in
dpaa2_sec_ipsec_proto_init() by overriding cipherdata with the auth
key and setting authdata algtype to HMAC_NULL.
Also add AES-GMAC to dpaa2_sec_capabilities[] as an AUTH xform.
Signed-off-by: Gagandeep Singh <g.singh@nxp.com>
---
doc/guides/cryptodevs/dpaa2_sec.rst | 1 +
doc/guides/cryptodevs/features/dpaa2_sec.ini | 1 +
drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c | 43 +++++++++++++++++++-
drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h | 28 ++++++++++++-
4 files changed, 71 insertions(+), 2 deletions(-)
diff --git a/doc/guides/cryptodevs/dpaa2_sec.rst b/doc/guides/cryptodevs/dpaa2_sec.rst
index 925d3371bf..d9a661c272 100644
--- a/doc/guides/cryptodevs/dpaa2_sec.rst
+++ b/doc/guides/cryptodevs/dpaa2_sec.rst
@@ -125,6 +125,7 @@ Hash algorithms:
* ``RTE_CRYPTO_AUTH_MD5_HMAC``
* ``RTE_CRYPTO_AUTH_AES_XCBC_MAC``
* ``RTE_CRYPTO_AUTH_AES_CMAC``
+* ``RTE_CRYPTO_AUTH_AES_GMAC``
AEAD algorithms:
diff --git a/doc/guides/cryptodevs/features/dpaa2_sec.ini b/doc/guides/cryptodevs/features/dpaa2_sec.ini
index a280c7b51b..c6e7f22a87 100644
--- a/doc/guides/cryptodevs/features/dpaa2_sec.ini
+++ b/doc/guides/cryptodevs/features/dpaa2_sec.ini
@@ -48,6 +48,7 @@ SHA384 HMAC = Y
SHA512 = Y
SHA512 HMAC = Y
SNOW3G UIA2 = Y
+AES GMAC = Y
AES XCBC MAC = Y
ZUC EIA3 = Y
AES CMAC (128) = Y
diff --git a/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c b/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c
index 0ff54fb644..8e271a3b50 100644
--- a/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c
+++ b/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c
@@ -1,7 +1,7 @@
/* SPDX-License-Identifier: BSD-3-Clause
*
* Copyright (c) 2016 Freescale Semiconductor, Inc. All rights reserved.
- * Copyright 2016-2025 NXP
+ * Copyright 2016-2026 NXP
*
*/
@@ -2483,6 +2483,30 @@ dpaa2_sec_auth_init(struct rte_crypto_sym_xform *xform,
!session->dir,
session->digest_length);
break;
+ case RTE_CRYPTO_AUTH_AES_GMAC:
+ /* AES-GMAC is an authentication-only operation using the
+ * GCM algorithm with a zero-length payload. The IV is
+ * passed per-packet via the auth xform iv field, and the
+ * data to authenticate is in sym_op->auth.data.
+ */
+ session->iv.offset = xform->auth.iv.offset;
+ session->iv.length = xform->auth.iv.length;
+ session->auth_alg = RTE_CRYPTO_AUTH_AES_GMAC;
+ authdata.algtype = OP_ALG_ALGSEL_AES;
+ authdata.algmode = OP_ALG_AAI_GCM;
+ if (session->dir == DIR_ENC)
+ bufsize = cnstr_shdsc_gcm_encap(
+ priv->flc_desc[DESC_INITFINAL].desc,
+ 1, 0, SHR_NEVER, &authdata,
+ session->iv.length,
+ session->digest_length);
+ else
+ bufsize = cnstr_shdsc_gcm_decap(
+ priv->flc_desc[DESC_INITFINAL].desc,
+ 1, 0, SHR_NEVER, &authdata,
+ session->iv.length,
+ session->digest_length);
+ break;
default:
DPAA2_SEC_ERR("Crypto: Unsupported Auth alg %s (%u)",
rte_cryptodev_get_auth_algo_string(xform->auth.algo),
@@ -3046,6 +3070,18 @@ dpaa2_sec_ipsec_proto_init(struct rte_crypto_cipher_xform *cipher_xform,
authdata->algtype = OP_PCL_IPSEC_HMAC_MD5_96;
authdata->algmode = OP_ALG_AAI_HMAC;
break;
+ case RTE_CRYPTO_AUTH_AES_GMAC:
+ /* AES-GMAC uses OP_PCL_IPSEC_AES_NULL_WITH_GMAC which is
+ * treated as a cipher type in the SEC protocol word.
+ * Place the GMAC key in cipherdata and set authdata to NULL.
+ */
+ cipherdata->key = (size_t)session->auth_key.data;
+ cipherdata->keylen = session->auth_key.length;
+ cipherdata->key_enc_flags = 0;
+ cipherdata->key_type = RTA_DATA_IMM;
+ cipherdata->algtype = OP_PCL_IPSEC_AES_NULL_WITH_GMAC;
+ authdata->algtype = OP_PCL_IPSEC_HMAC_NULL;
+ return 0;
case RTE_CRYPTO_AUTH_SHA224_HMAC:
authdata->algmode = OP_ALG_AAI_HMAC;
if (session->digest_length == 6)
@@ -3142,6 +3178,9 @@ dpaa2_sec_set_ipsec_session(struct rte_cryptodev *dev,
PMD_INIT_FUNC_TRACE();
+ memset(&authdata, 0, sizeof(authdata));
+ memset(&cipherdata, 0, sizeof(cipherdata));
+
RTE_SET_USED(dev);
/** Make FLC address to align with stashing, low 6 bits are used
@@ -3217,6 +3256,7 @@ dpaa2_sec_set_ipsec_session(struct rte_cryptodev *dev,
case OP_PCL_IPSEC_AES_GCM8:
case OP_PCL_IPSEC_AES_GCM12:
case OP_PCL_IPSEC_AES_GCM16:
+ case OP_PCL_IPSEC_AES_NULL_WITH_GMAC:
memcpy(encap_pdb.gcm.salt,
(uint8_t *)&(ipsec_xform->salt), 4);
break;
@@ -3357,6 +3397,7 @@ dpaa2_sec_set_ipsec_session(struct rte_cryptodev *dev,
case OP_PCL_IPSEC_AES_GCM8:
case OP_PCL_IPSEC_AES_GCM12:
case OP_PCL_IPSEC_AES_GCM16:
+ case OP_PCL_IPSEC_AES_NULL_WITH_GMAC:
memcpy(decap_pdb.gcm.salt,
(uint8_t *)&(ipsec_xform->salt), 4);
break;
diff --git a/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h b/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h
index 94ba321c72..913c91ebc2 100644
--- a/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h
+++ b/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h
@@ -1,7 +1,7 @@
/* SPDX-License-Identifier: BSD-3-Clause
*
* Copyright (c) 2016 Freescale Semiconductor, Inc. All rights reserved.
- * Copyright 2016,2020-2024 NXP
+ * Copyright 2016,2020-2026 NXP
*
*/
@@ -528,6 +528,32 @@ static const struct rte_cryptodev_capabilities dpaa2_sec_capabilities[] = {
}, }
}, }
},
+ { /* AES GMAC */
+ .op = RTE_CRYPTO_OP_TYPE_SYMMETRIC,
+ {.sym = {
+ .xform_type = RTE_CRYPTO_SYM_XFORM_AUTH,
+ {.auth = {
+ .algo = RTE_CRYPTO_AUTH_AES_GMAC,
+ .block_size = 16,
+ .key_size = {
+ .min = 16,
+ .max = 32,
+ .increment = 8
+ },
+ .digest_size = {
+ .min = 8,
+ .max = 16,
+ .increment = 4
+ },
+ .aad_size = { 0 },
+ .iv_size = {
+ .min = 12,
+ .max = 12,
+ .increment = 0
+ },
+ }, }
+ }, }
+ },
{ /* AES XCBC HMAC */
.op = RTE_CRYPTO_OP_TYPE_SYMMETRIC,
{.sym = {
--
2.25.1
^ permalink raw reply related [flat|nested] 26+ messages in thread
end of thread, other threads:[~2026-10-06 11:44 UTC | newest]
Thread overview: 26+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-10 11:29 [PATCH 0/6] DPAA2 SEC related changes Gagandeep Singh
2026-08-10 11:29 ` [PATCH 1/6] crypto/dpaa2_sec: fix buffer overflow in GCM decrypt Gagandeep Singh
2026-08-10 11:29 ` [PATCH 2/6] crypto/dpaa2_sec: fix FLE pool leak on sec FD build failure Gagandeep Singh
2026-08-10 11:29 ` [PATCH 3/6] crypto/dpaa2_sec: support AES-GMAC Gagandeep Singh
2026-08-10 11:29 ` [PATCH 4/6] crypto/dpaa2_sec: increase ivsize range for AES-CTR Gagandeep Singh
2026-08-10 11:29 ` [PATCH 5/6] crypto/dpaa2_sec: add missing ECN capability Gagandeep Singh
2026-08-10 11:29 ` [PATCH 6/6] crypto/dpaa2_sec: add support for env variables Gagandeep Singh
2026-08-10 15:16 ` Stephen Hemminger
2026-08-11 7:50 ` Gagandeep Singh
2026-09-30 7:08 ` [PATCH v2 0/6] DPAA2 SEC related changes Gagandeep Singh
2026-09-30 7:08 ` [PATCH v2 1/6] crypto/dpaa2_sec: fix buffer overflow in GCM decrypt Gagandeep Singh
2026-09-30 7:08 ` [PATCH v2 2/6] crypto/dpaa2_sec: fix FLE pool leak on sec FD build failure Gagandeep Singh
2026-09-30 7:08 ` [PATCH v2 3/6] crypto/dpaa2_sec: increase ivsize range for AES-CTR Gagandeep Singh
2026-09-30 7:08 ` [PATCH v2 4/6] crypto/dpaa2_sec: add missing ECN capability Gagandeep Singh
2026-09-30 7:08 ` [PATCH v2 5/6] crypto/dpaa2_sec: add support for env variables Gagandeep Singh
2026-10-05 18:37 ` [EXTERNAL] " Akhil Goyal
2026-10-06 4:15 ` Gagandeep Singh
2026-09-30 7:08 ` [PATCH v2 6/6] crypto/dpaa2_sec: support AES-GMAC Gagandeep Singh
2026-10-05 18:14 ` [EXTERNAL] " Akhil Goyal
2026-10-06 11:43 ` [PATCH v3 0/6] DPAA2 SEC related changes Gagandeep Singh
2026-10-06 11:43 ` [PATCH v3 1/6] crypto/dpaa2_sec: fix buffer overflow in GCM decrypt Gagandeep Singh
2026-10-06 11:43 ` [PATCH v3 2/6] crypto/dpaa2_sec: fix FLE pool leak on sec FD build failure Gagandeep Singh
2026-10-06 11:43 ` [PATCH v3 3/6] crypto/dpaa2_sec: increase ivsize range for AES-CTR Gagandeep Singh
2026-10-06 11:43 ` [PATCH v3 4/6] crypto/dpaa2_sec: add missing ECN capability Gagandeep Singh
2026-10-06 11:43 ` [PATCH v3 5/6] crypto/dpaa2_sec: add support for env variables Gagandeep Singh
2026-10-06 11:43 ` [PATCH v3 6/6] crypto/dpaa2_sec: support AES-GMAC Gagandeep Singh
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox