DPDK-dev Archive on lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH 0/6] DPAA2 SEC related changes
@ 2026-08-10 11:29 Gagandeep Singh
  2026-08-10 11:29 ` [PATCH 1/6] crypto/dpaa2_sec: fix buffer overflow in GCM decrypt Gagandeep Singh
                   ` (6 more replies)
  0 siblings, 7 replies; 26+ messages in thread
From: Gagandeep Singh @ 2026-08-10 11:29 UTC (permalink / raw)
  To: dev, gakhil; +Cc: hemant.agrawal

This series include bug fixes, enhancement and AES-GMAC support

Gagandeep Singh (6):
  crypto/dpaa2_sec: fix buffer overflow in GCM decrypt
  crypto/dpaa2_sec: fix FLE pool leak on sec FD build failure
  crypto/dpaa2_sec: support AES-GMAC
  crypto/dpaa2_sec: increase ivsize range for AES-CTR
  crypto/dpaa2_sec: add missing ECN capability
  crypto/dpaa2_sec: add support for env variables

 drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c | 50 ++++++++++++++++++---
 drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h   | 45 ++++++++++++++++---
 lib/cryptodev/rte_crypto_sym.h              |  2 +
 3 files changed, 86 insertions(+), 11 deletions(-)

-- 
2.25.1


^ permalink raw reply	[flat|nested] 26+ messages in thread

* [PATCH 1/6] crypto/dpaa2_sec: fix buffer overflow in GCM decrypt
  2026-08-10 11:29 [PATCH 0/6] DPAA2 SEC related changes Gagandeep Singh
@ 2026-08-10 11:29 ` Gagandeep Singh
  2026-08-10 11:29 ` [PATCH 2/6] crypto/dpaa2_sec: fix FLE pool leak on sec FD build failure Gagandeep Singh
                   ` (5 subsequent siblings)
  6 siblings, 0 replies; 26+ messages in thread
From: Gagandeep Singh @ 2026-08-10 11:29 UTC (permalink / raw)
  To: dev, gakhil; +Cc: hemant.agrawal, stable, Gagandeep Singh

In build_authenc_gcm_fd, when both AAD (auth_only_len > 0) and decrypt
direction are active, the SGE layout occupies 8 entries plus 16 bytes of
old_icv storage at index 8. The FLE pool buffer was only 256 bytes
(8 x 32), causing old_icv to be written one entry past the end of the
allocated buffer. The resulting virtual address was not mapped by the
IOMMU, so DPAA2_VADDR_TO_IOVA returned 0 and the SEC engine received
iova=0x00000000 as the ICV buffer address, triggering an SMMU
translation fault (FSR=0x402 TF).

Additionally, the upfront bpid/IVP initialization only covered sge+3,
leaving sge+4 (the input data SGE when AAD is present) without a valid
bpid or IVP assignment.

Increase FLE_POOL_BUF_SIZE from 256 to 288 (9 x 32 bytes) to
accommodate the full layout, and extend the bpid/IVP initialization
to cover sge+4 in both branches of build_authenc_gcm_fd.

Fixes: 13273250ee ("crypto/dpaa2_sec: support AES-GCM and CTR")
Cc: stable@dpdk.org
Signed-off-by: Gagandeep Singh <g.singh@nxp.com>
---
 drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c | 2 ++
 drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h   | 2 +-
 2 files changed, 3 insertions(+), 1 deletion(-)

diff --git a/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c b/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c
index 3d980d096f..2a015a3d82 100644
--- a/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c
+++ b/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c
@@ -569,6 +569,7 @@ build_authenc_gcm_fd(dpaa2_sec_session *sess,
 		DPAA2_SET_FLE_BPID(sge + 1, bpid);
 		DPAA2_SET_FLE_BPID(sge + 2, bpid);
 		DPAA2_SET_FLE_BPID(sge + 3, bpid);
+		DPAA2_SET_FLE_BPID(sge + 4, bpid);
 	} else {
 		DPAA2_SET_FD_IVP(fd);
 		DPAA2_SET_FLE_IVP(fle);
@@ -577,6 +578,7 @@ build_authenc_gcm_fd(dpaa2_sec_session *sess,
 		DPAA2_SET_FLE_IVP((sge + 1));
 		DPAA2_SET_FLE_IVP((sge + 2));
 		DPAA2_SET_FLE_IVP((sge + 3));
+		DPAA2_SET_FLE_IVP((sge + 4));
 	}
 
 	/* Save the shared descriptor */
diff --git a/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h b/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h
index 755c8e9cc3..ff32f3d860 100644
--- a/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h
+++ b/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h
@@ -17,7 +17,7 @@ extern uint8_t cryptodev_driver_id;
 
 /* FLE_POOL_NUM_BUFS is set as per the ipsec-secgw application */
 #define FLE_POOL_NUM_BUFS	32000
-#define FLE_POOL_BUF_SIZE	256
+#define FLE_POOL_BUF_SIZE	288
 #define FLE_POOL_CACHE_SIZE	512
 #define FLE_SG_MEM_SIZE(num)	(FLE_POOL_BUF_SIZE + ((num) * 32))
 
-- 
2.25.1


^ permalink raw reply related	[flat|nested] 26+ messages in thread

* [PATCH 2/6] crypto/dpaa2_sec: fix FLE pool leak on sec FD build failure
  2026-08-10 11:29 [PATCH 0/6] DPAA2 SEC related changes Gagandeep Singh
  2026-08-10 11:29 ` [PATCH 1/6] crypto/dpaa2_sec: fix buffer overflow in GCM decrypt Gagandeep Singh
@ 2026-08-10 11:29 ` Gagandeep Singh
  2026-08-10 11:29 ` [PATCH 3/6] crypto/dpaa2_sec: support AES-GMAC Gagandeep Singh
                   ` (4 subsequent siblings)
  6 siblings, 0 replies; 26+ messages in thread
From: Gagandeep Singh @ 2026-08-10 11:29 UTC (permalink / raw)
  To: dev, gakhil; +Cc: hemant.agrawal, stable, Gagandeep Singh

When build_sec_fd fails at index loop inside the enqueue burst loops,
the previously built FD entries (indices 0..loop-1) were never freed.
The cleanup loop iterated in the wrong direction, starting at the
failed index and going up to frames_to_send, which are entries that
were never built. This caused silent FLE pool exhaustion, after which
every subsequent build_sec_fd returned -ENOMEM, enqueue_burst
returned 0 indefinitely, and the crypto-perf test hung.

Fix both dpaa2_sec_enqueue_burst and dpaa2_sec_enqueue_burst_ordered
by clamping frames_to_send to loop + 1 and iterating from 0 to
free all allocated FLE buffers including the failed entry.

Fixes: 623326dded ("crypto/dpaa2_sec: introduce poll mode driver")
Cc: stable@dpdk.org
Signed-off-by: Gagandeep Singh <g.singh@nxp.com>
---
 drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c | 6 ++++++
 1 file changed, 6 insertions(+)

diff --git a/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c b/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c
index 2a015a3d82..15152cc5a1 100644
--- a/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c
+++ b/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c
@@ -1550,6 +1550,9 @@ dpaa2_sec_enqueue_burst(void *qp, struct rte_crypto_op **ops,
 			ret = build_sec_fd(*ops, &fd_arr[loop], bpid, dpaa2_qp);
 			if (ret) {
 				DPAA2_SEC_DP_DEBUG("FD build failed");
+				frames_to_send = loop + 1;
+				for (loop = 0; loop < frames_to_send; loop++)
+					free_fle(&fd_arr[loop], dpaa2_qp);
 				goto skip_tx;
 			}
 			ops++;
@@ -1909,6 +1912,9 @@ dpaa2_sec_enqueue_burst_ordered(void *qp, struct rte_crypto_op **ops,
 			ret = build_sec_fd(*ops, &fd_arr[loop], bpid, dpaa2_qp);
 			if (ret) {
 				DPAA2_SEC_DP_DEBUG("FD build failed");
+				frames_to_send = loop + 1;
+				for (loop = 0; loop < frames_to_send; loop++)
+					free_fle(&fd_arr[loop], dpaa2_qp);
 				goto skip_tx;
 			}
 			ops++;
-- 
2.25.1


^ permalink raw reply related	[flat|nested] 26+ messages in thread

* [PATCH 3/6] crypto/dpaa2_sec: support AES-GMAC
  2026-08-10 11:29 [PATCH 0/6] DPAA2 SEC related changes Gagandeep Singh
  2026-08-10 11:29 ` [PATCH 1/6] crypto/dpaa2_sec: fix buffer overflow in GCM decrypt Gagandeep Singh
  2026-08-10 11:29 ` [PATCH 2/6] crypto/dpaa2_sec: fix FLE pool leak on sec FD build failure Gagandeep Singh
@ 2026-08-10 11:29 ` Gagandeep Singh
  2026-08-10 11:29 ` [PATCH 4/6] crypto/dpaa2_sec: increase ivsize range for AES-CTR Gagandeep Singh
                   ` (3 subsequent siblings)
  6 siblings, 0 replies; 26+ messages in thread
From: Gagandeep Singh @ 2026-08-10 11:29 UTC (permalink / raw)
  To: dev, gakhil; +Cc: hemant.agrawal, Gagandeep Singh

Add AES-GMAC as a supported AEAD algorithm for IPsec protocol
offload. AES-GMAC provides NULL encryption with GMAC authentication
and maps to OP_PCL_IPSEC_AES_NULL_WITH_GMAC in the SEC protocol
control word.

When AES_GMAC is specified as an AUTH (non-AEAD) algorithm, return
-ENOTSUP with an informative message directing the user to the AEAD
path.

Add RTE_CRYPTO_AEAD_AES_GMAC to the AEAD algorithm enum and expose
the capability in dpaa2_sec_capabilities.

Signed-off-by: Gagandeep Singh <g.singh@nxp.com>
---
 drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c | 15 +++++++++-
 drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h   | 33 ++++++++++++++++++++-
 lib/cryptodev/rte_crypto_sym.h              |  2 ++
 3 files changed, 48 insertions(+), 2 deletions(-)

diff --git a/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c b/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c
index 15152cc5a1..0e4e67aa07 100644
--- a/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c
+++ b/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c
@@ -1,7 +1,7 @@
 /* SPDX-License-Identifier: BSD-3-Clause
  *
  *   Copyright (c) 2016 Freescale Semiconductor, Inc. All rights reserved.
- *   Copyright 2016-2025 NXP
+ *   Copyright 2016-2026 NXP
  *
  */
 
@@ -2975,6 +2975,13 @@ dpaa2_sec_ipsec_aead_init(struct rte_crypto_aead_xform *aead_xform,
 		aeaddata->algmode = OP_ALG_AAI_CCM;
 		session->aead_alg = RTE_CRYPTO_AEAD_AES_CCM;
 		break;
+	case RTE_CRYPTO_AEAD_AES_GMAC:
+		/**
+		 * AES-GMAC is an AEAD algo with NULL encryption and GMAC
+		 * authentication.
+		 */
+		aeaddata->algtype = OP_PCL_IPSEC_AES_NULL_WITH_GMAC;
+		break;
 	default:
 		DPAA2_SEC_ERR("Crypto: Undefined AEAD specified %u",
 			      aead_xform->algo);
@@ -3046,6 +3053,10 @@ dpaa2_sec_ipsec_proto_init(struct rte_crypto_cipher_xform *cipher_xform,
 		authdata->algtype = OP_PCL_IPSEC_HMAC_MD5_96;
 		authdata->algmode = OP_ALG_AAI_HMAC;
 		break;
+	case RTE_CRYPTO_AUTH_AES_GMAC:
+		DPAA2_SEC_ERR(
+			"AES_GMAC is supported as AEAD algo for IPSEC proto only");
+		return -ENOTSUP;
 	case RTE_CRYPTO_AUTH_SHA224_HMAC:
 		authdata->algmode = OP_ALG_AAI_HMAC;
 		if (session->digest_length == 6)
@@ -3217,6 +3228,7 @@ dpaa2_sec_set_ipsec_session(struct rte_cryptodev *dev,
 		case OP_PCL_IPSEC_AES_GCM8:
 		case OP_PCL_IPSEC_AES_GCM12:
 		case OP_PCL_IPSEC_AES_GCM16:
+		case OP_PCL_IPSEC_AES_NULL_WITH_GMAC:
 			memcpy(encap_pdb.gcm.salt,
 				(uint8_t *)&(ipsec_xform->salt), 4);
 			break;
@@ -3357,6 +3369,7 @@ dpaa2_sec_set_ipsec_session(struct rte_cryptodev *dev,
 		case OP_PCL_IPSEC_AES_GCM8:
 		case OP_PCL_IPSEC_AES_GCM12:
 		case OP_PCL_IPSEC_AES_GCM16:
+		case OP_PCL_IPSEC_AES_NULL_WITH_GMAC:
 			memcpy(decap_pdb.gcm.salt,
 				(uint8_t *)&(ipsec_xform->salt), 4);
 			break;
diff --git a/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h b/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h
index ff32f3d860..1824cc4a60 100644
--- a/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h
+++ b/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h
@@ -1,7 +1,7 @@
 /* SPDX-License-Identifier: BSD-3-Clause
  *
  *   Copyright (c) 2016 Freescale Semiconductor, Inc. All rights reserved.
- *   Copyright 2016,2020-2024 NXP
+ *   Copyright 2016,2020-2026 NXP
  *
  */
 
@@ -762,6 +762,37 @@ static const struct rte_cryptodev_capabilities dpaa2_sec_capabilities[] = {
 			}, }
 		}, }
 	},
+	{	/* AES GMAC (AEAD) */
+		.op = RTE_CRYPTO_OP_TYPE_SYMMETRIC,
+		{.sym = {
+			.xform_type = RTE_CRYPTO_SYM_XFORM_AEAD,
+			{.aead = {
+				.algo = RTE_CRYPTO_AEAD_AES_GMAC,
+				.block_size = 16,
+				.key_size = {
+					.min = 16,
+					.max = 32,
+					.increment = 8
+				},
+				.digest_size = {
+					.min = 16,
+					.max = 16,
+					.increment = 0
+				},
+				.aad_size = {
+					.min = 0,
+					.max = 65535,
+					.increment = 1
+				},
+				.iv_size = {
+					.min = 12,
+					.max = 16,
+					.increment = 4
+				}
+			}, }
+		}, }
+	},
+
 	RTE_CRYPTODEV_END_OF_CAPABILITIES_LIST()
 };
 
diff --git a/lib/cryptodev/rte_crypto_sym.h b/lib/cryptodev/rte_crypto_sym.h
index 630fd153bd..f65db616a0 100644
--- a/lib/cryptodev/rte_crypto_sym.h
+++ b/lib/cryptodev/rte_crypto_sym.h
@@ -508,6 +508,8 @@ enum rte_crypto_aead_algorithm {
 	/**< AES algorithm in NCA5 mode */
 	RTE_CRYPTO_AEAD_ZUC_NCA6,
 	/**< ZUC-256 algorithm in NCA6 mode */
+	RTE_CRYPTO_AEAD_AES_GMAC,
+	/**< AES algorithm in GMAC mode. */
 };
 
 /** Symmetric AEAD Operations */
-- 
2.25.1


^ permalink raw reply related	[flat|nested] 26+ messages in thread

* [PATCH 4/6] crypto/dpaa2_sec: increase ivsize range for AES-CTR
  2026-08-10 11:29 [PATCH 0/6] DPAA2 SEC related changes Gagandeep Singh
                   ` (2 preceding siblings ...)
  2026-08-10 11:29 ` [PATCH 3/6] crypto/dpaa2_sec: support AES-GMAC Gagandeep Singh
@ 2026-08-10 11:29 ` Gagandeep Singh
  2026-08-10 11:29 ` [PATCH 5/6] crypto/dpaa2_sec: add missing ECN capability Gagandeep Singh
                   ` (2 subsequent siblings)
  6 siblings, 0 replies; 26+ messages in thread
From: Gagandeep Singh @ 2026-08-10 11:29 UTC (permalink / raw)
  To: dev, gakhil; +Cc: hemant.agrawal

Widen the AES-CTR IV size range from the fixed 16-byte value to
[12, 16] with a 4-byte increment. This allows 96-bit IVs (the
standard NIST SP 800-38A recommendation) in addition to 128-bit
IVs, aligning with common usage and test-vector expectations.

The change applies to both dpaa2_sec_capabilities and
dpaa2_pdcp_capabilities.

Signed-off-by: Hemant Agrawal <hemant.agrawal@nxp.com>
---
 drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h | 8 ++++----
 1 file changed, 4 insertions(+), 4 deletions(-)

diff --git a/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h b/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h
index 1824cc4a60..7e18e83858 100644
--- a/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h
+++ b/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h
@@ -625,9 +625,9 @@ static const struct rte_cryptodev_capabilities dpaa2_sec_capabilities[] = {
 					.increment = 8
 				},
 				.iv_size = {
-					.min = 16,
+					.min = 12,
 					.max = 16,
-					.increment = 0
+					.increment = 4
 				},
 			}, }
 		}, }
@@ -855,9 +855,9 @@ static const struct rte_cryptodev_capabilities dpaa2_pdcp_capabilities[] = {
 					.increment = 8
 				},
 				.iv_size = {
-					.min = 16,
+					.min = 12,
 					.max = 16,
-					.increment = 0
+					.increment = 4
 				}
 			}, }
 		}, }
-- 
2.25.1


^ permalink raw reply related	[flat|nested] 26+ messages in thread

* [PATCH 5/6] crypto/dpaa2_sec: add missing ECN capability
  2026-08-10 11:29 [PATCH 0/6] DPAA2 SEC related changes Gagandeep Singh
                   ` (3 preceding siblings ...)
  2026-08-10 11:29 ` [PATCH 4/6] crypto/dpaa2_sec: increase ivsize range for AES-CTR Gagandeep Singh
@ 2026-08-10 11:29 ` Gagandeep Singh
  2026-08-10 11:29 ` [PATCH 6/6] crypto/dpaa2_sec: add support for env variables Gagandeep Singh
  2026-09-30  7:08 ` [PATCH v2 0/6] DPAA2 SEC related changes Gagandeep Singh
  6 siblings, 0 replies; 26+ messages in thread
From: Gagandeep Singh @ 2026-08-10 11:29 UTC (permalink / raw)
  To: dev, gakhil; +Cc: hemant.agrawal, Gagandeep Singh

Set the .ecn = 1 flag in both tunnel-mode security capability
entries to advertise that the driver supports ECN (Explicit
Congestion Notification) copying during IPsec encap/decap.

Signed-off-by: Gagandeep Singh <g.singh@nxp.com>
---
 drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h b/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h
index 7e18e83858..16b8273a79 100644
--- a/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h
+++ b/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h
@@ -1004,6 +1004,7 @@ static const struct rte_security_capability dpaa2_sec_security_cap[] = {
 				.copy_df = 1,
 				.copy_dscp = 1,
 				.dec_ttl = 1,
+				.ecn = 1,
 				.esn = 1,
 			},
 			.replay_win_sz_max = 1024
@@ -1023,6 +1024,7 @@ static const struct rte_security_capability dpaa2_sec_security_cap[] = {
 				.copy_df = 1,
 				.copy_dscp = 1,
 				.dec_ttl = 1,
+				.ecn = 1,
 				.esn = 1,
 			},
 			.replay_win_sz_max = 1024
-- 
2.25.1


^ permalink raw reply related	[flat|nested] 26+ messages in thread

* [PATCH 6/6] crypto/dpaa2_sec: add support for env variables
  2026-08-10 11:29 [PATCH 0/6] DPAA2 SEC related changes Gagandeep Singh
                   ` (4 preceding siblings ...)
  2026-08-10 11:29 ` [PATCH 5/6] crypto/dpaa2_sec: add missing ECN capability Gagandeep Singh
@ 2026-08-10 11:29 ` Gagandeep Singh
  2026-08-10 15:16   ` Stephen Hemminger
  2026-09-30  7:08 ` [PATCH v2 0/6] DPAA2 SEC related changes Gagandeep Singh
  6 siblings, 1 reply; 26+ messages in thread
From: Gagandeep Singh @ 2026-08-10 11:29 UTC (permalink / raw)
  To: dev, gakhil; +Cc: hemant.agrawal, Gagandeep Singh

Allow driver configuration via environment variables as a fallback
when devargs are not provided. After processing devargs (or when
devargs are absent), check DRIVER_STRICT_ORDER and DRIVER_DUMP_MODE
environment variables to set en_loose_ordered and dpaa2_sec_dp_dump.

This lets users configure the driver without modifying EAL arguments,
useful in environments where command-line access is restricted.

Signed-off-by: Gagandeep Singh <g.singh@nxp.com>
---
 drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c | 27 ++++++++++++++++++---
 1 file changed, 23 insertions(+), 4 deletions(-)

diff --git a/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c b/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c
index 0e4e67aa07..c54960820c 100644
--- a/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c
+++ b/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c
@@ -4379,25 +4379,44 @@ check_devargs_handler(const char *key, const char *value,
 static void
 dpaa2_sec_get_devargs(struct rte_cryptodev *cryptodev, const char *key)
 {
+	struct dpaa2_sec_dev_private *internals;
 	struct rte_kvargs *kvlist;
 	struct rte_devargs *devargs;
+	int ret;
+	char *env;
+
+	internals = cryptodev->data->dev_private;
 
 	devargs = cryptodev->device->devargs;
 	if (!devargs)
-		return;
+		goto env_set;
 
 	kvlist = rte_kvargs_parse(devargs->args, NULL);
 	if (!kvlist)
-		return;
+		goto env_set;
 
 	if (!rte_kvargs_count(kvlist, key)) {
 		rte_kvargs_free(kvlist);
-		return;
+		goto env_set;
 	}
 
-	rte_kvargs_process(kvlist, key,
+	ret = rte_kvargs_process(kvlist, key,
 			check_devargs_handler, (void *)cryptodev);
 	rte_kvargs_free(kvlist);
+	if (!ret)
+		return;
+
+env_set:
+	env = getenv(DRIVER_STRICT_ORDER);
+	if (env)
+		internals->en_loose_ordered = !atoi(env);
+
+	env = getenv(DRIVER_DUMP_MODE);
+	if (env) {
+		dpaa2_sec_dp_dump = atoi(env);
+		if (dpaa2_sec_dp_dump > DPAA2_SEC_DP_FULL_DUMP)
+			dpaa2_sec_dp_dump = DPAA2_SEC_DP_FULL_DUMP;
+	}
 }
 
 static int
-- 
2.25.1


^ permalink raw reply related	[flat|nested] 26+ messages in thread

* Re: [PATCH 6/6] crypto/dpaa2_sec: add support for env variables
  2026-08-10 11:29 ` [PATCH 6/6] crypto/dpaa2_sec: add support for env variables Gagandeep Singh
@ 2026-08-10 15:16   ` Stephen Hemminger
  2026-08-11  7:50     ` Gagandeep Singh
  0 siblings, 1 reply; 26+ messages in thread
From: Stephen Hemminger @ 2026-08-10 15:16 UTC (permalink / raw)
  To: Gagandeep Singh; +Cc: dev, gakhil, hemant.agrawal

On Mon, 10 Aug 2026 16:59:51 +0530
Gagandeep Singh <g.singh@nxp.com> wrote:

> Allow driver configuration via environment variables as a fallback
> when devargs are not provided. After processing devargs (or when
> devargs are absent), check DRIVER_STRICT_ORDER and DRIVER_DUMP_MODE
> environment variables to set en_loose_ordered and dpaa2_sec_dp_dump.
> 
> This lets users configure the driver without modifying EAL arguments,
> useful in environments where command-line access is restricted.
> 
> Signed-off-by: Gagandeep Singh <g.singh@nxp.com>

No. This is bad precedent. DPDK has a method for configuration.
Adding AdHoc environment variables creates chaos.

^ permalink raw reply	[flat|nested] 26+ messages in thread

* RE: [PATCH 6/6] crypto/dpaa2_sec: add support for env variables
  2026-08-10 15:16   ` Stephen Hemminger
@ 2026-08-11  7:50     ` Gagandeep Singh
  0 siblings, 0 replies; 26+ messages in thread
From: Gagandeep Singh @ 2026-08-11  7:50 UTC (permalink / raw)
  To: Stephen Hemminger; +Cc: dev@dpdk.org, gakhil@marvell.com, Hemant Agrawal

Hi,

> -----Original Message-----
> From: Stephen Hemminger <stephen@networkplumber.org>
> Sent: Monday, August 10, 2026 8:46 PM
> To: Gagandeep Singh <G.Singh@nxp.com>
> Cc: dev@dpdk.org; gakhil@marvell.com; Hemant Agrawal
> <hemant.agrawal@nxp.com>
> Subject: Re: [PATCH 6/6] crypto/dpaa2_sec: add support for env variables
> 
> On Mon, 10 Aug 2026 16:59:51 +0530
> Gagandeep Singh <g.singh@nxp.com> wrote:
> 
> > Allow driver configuration via environment variables as a fallback
> > when devargs are not provided. After processing devargs (or when
> > devargs are absent), check DRIVER_STRICT_ORDER and
> DRIVER_DUMP_MODE
> > environment variables to set en_loose_ordered and dpaa2_sec_dp_dump.
> >
> > This lets users configure the driver without modifying EAL arguments,
> > useful in environments where command-line access is restricted.
> >
> > Signed-off-by: Gagandeep Singh <g.singh@nxp.com>
> 
> No. This is bad precedent. DPDK has a method for configuration.
> Adding AdHoc environment variables creates chaos.

I understand the concern. The devargs are already presents. The motivation was mainly customer support. In many deployments,
users cannot easily modify EAL/devargs but can set environment variables without the need to update and recompile
their binaries, making it easier to enable temporary debugging in the field.

^ permalink raw reply	[flat|nested] 26+ messages in thread

* [PATCH v2 0/6] DPAA2 SEC related changes
  2026-08-10 11:29 [PATCH 0/6] DPAA2 SEC related changes Gagandeep Singh
                   ` (5 preceding siblings ...)
  2026-08-10 11:29 ` [PATCH 6/6] crypto/dpaa2_sec: add support for env variables Gagandeep Singh
@ 2026-09-30  7:08 ` Gagandeep Singh
  2026-09-30  7:08   ` [PATCH v2 1/6] crypto/dpaa2_sec: fix buffer overflow in GCM decrypt Gagandeep Singh
                     ` (6 more replies)
  6 siblings, 7 replies; 26+ messages in thread
From: Gagandeep Singh @ 2026-09-30  7:08 UTC (permalink / raw)
  To: dev, gakhil; +Cc: hemant.agrawal

V2-changes:
 - Support AES-GMAC as AUTH algorithm instead of as AEAD.

This series include bug fixes, enhancement and AES-GMAC support

Gagandeep Singh (6):
  crypto/dpaa2_sec: fix buffer overflow in GCM decrypt
  crypto/dpaa2_sec: fix FLE pool leak on sec FD build failure
  crypto/dpaa2_sec: increase ivsize range for AES-CTR
  crypto/dpaa2_sec: add missing ECN capability
  crypto/dpaa2_sec: add support for env variables
  crypto/dpaa2_sec: support AES-GMAC

 doc/guides/cryptodevs/dpaa2_sec.rst          | 13 +++-
 doc/guides/cryptodevs/features/dpaa2_sec.ini |  3 +
 drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c  | 78 ++++++++++++++++++--
 drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h    | 40 ++++++++--
 4 files changed, 122 insertions(+), 12 deletions(-)

-- 
2.25.1


^ permalink raw reply	[flat|nested] 26+ messages in thread

* [PATCH v2 1/6] crypto/dpaa2_sec: fix buffer overflow in GCM decrypt
  2026-09-30  7:08 ` [PATCH v2 0/6] DPAA2 SEC related changes Gagandeep Singh
@ 2026-09-30  7:08   ` Gagandeep Singh
  2026-09-30  7:08   ` [PATCH v2 2/6] crypto/dpaa2_sec: fix FLE pool leak on sec FD build failure Gagandeep Singh
                     ` (5 subsequent siblings)
  6 siblings, 0 replies; 26+ messages in thread
From: Gagandeep Singh @ 2026-09-30  7:08 UTC (permalink / raw)
  To: dev, gakhil; +Cc: hemant.agrawal, stable, Gagandeep Singh

In build_authenc_gcm_fd, when both AAD (auth_only_len > 0) and decrypt
direction are active, the SGE layout occupies 8 entries plus 16 bytes of
old_icv storage at index 8. The FLE pool buffer was only 256 bytes
(8 x 32), causing old_icv to be written one entry past the end of the
allocated buffer. The resulting virtual address was not mapped by the
IOMMU, so DPAA2_VADDR_TO_IOVA returned 0 and the SEC engine received
iova=0x00000000 as the ICV buffer address, triggering an SMMU
translation fault (FSR=0x402 TF).

Additionally, the upfront bpid/IVP initialization only covered sge+3,
leaving sge+4 (the input data SGE when AAD is present) without a valid
bpid or IVP assignment.

Increase FLE_POOL_BUF_SIZE from 256 to 288 (9 x 32 bytes) to
accommodate the full layout, and extend the bpid/IVP initialization
to cover sge+4 in both branches of build_authenc_gcm_fd.

Fixes: 13273250eec5 ("crypto/dpaa2_sec: support AES-GCM and CTR")
Cc: stable@dpdk.org
Signed-off-by: Gagandeep Singh <g.singh@nxp.com>
---
 drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c | 2 ++
 drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h   | 2 +-
 2 files changed, 3 insertions(+), 1 deletion(-)

diff --git a/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c b/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c
index 3d980d096f..2a015a3d82 100644
--- a/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c
+++ b/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c
@@ -569,6 +569,7 @@ build_authenc_gcm_fd(dpaa2_sec_session *sess,
 		DPAA2_SET_FLE_BPID(sge + 1, bpid);
 		DPAA2_SET_FLE_BPID(sge + 2, bpid);
 		DPAA2_SET_FLE_BPID(sge + 3, bpid);
+		DPAA2_SET_FLE_BPID(sge + 4, bpid);
 	} else {
 		DPAA2_SET_FD_IVP(fd);
 		DPAA2_SET_FLE_IVP(fle);
@@ -577,6 +578,7 @@ build_authenc_gcm_fd(dpaa2_sec_session *sess,
 		DPAA2_SET_FLE_IVP((sge + 1));
 		DPAA2_SET_FLE_IVP((sge + 2));
 		DPAA2_SET_FLE_IVP((sge + 3));
+		DPAA2_SET_FLE_IVP((sge + 4));
 	}
 
 	/* Save the shared descriptor */
diff --git a/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h b/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h
index 755c8e9cc3..ff32f3d860 100644
--- a/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h
+++ b/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h
@@ -17,7 +17,7 @@ extern uint8_t cryptodev_driver_id;
 
 /* FLE_POOL_NUM_BUFS is set as per the ipsec-secgw application */
 #define FLE_POOL_NUM_BUFS	32000
-#define FLE_POOL_BUF_SIZE	256
+#define FLE_POOL_BUF_SIZE	288
 #define FLE_POOL_CACHE_SIZE	512
 #define FLE_SG_MEM_SIZE(num)	(FLE_POOL_BUF_SIZE + ((num) * 32))
 
-- 
2.25.1


^ permalink raw reply related	[flat|nested] 26+ messages in thread

* [PATCH v2 2/6] crypto/dpaa2_sec: fix FLE pool leak on sec FD build failure
  2026-09-30  7:08 ` [PATCH v2 0/6] DPAA2 SEC related changes Gagandeep Singh
  2026-09-30  7:08   ` [PATCH v2 1/6] crypto/dpaa2_sec: fix buffer overflow in GCM decrypt Gagandeep Singh
@ 2026-09-30  7:08   ` Gagandeep Singh
  2026-09-30  7:08   ` [PATCH v2 3/6] crypto/dpaa2_sec: increase ivsize range for AES-CTR Gagandeep Singh
                     ` (4 subsequent siblings)
  6 siblings, 0 replies; 26+ messages in thread
From: Gagandeep Singh @ 2026-09-30  7:08 UTC (permalink / raw)
  To: dev, gakhil; +Cc: hemant.agrawal, stable, Gagandeep Singh

When build_sec_fd fails at index loop inside the enqueue burst loops,
the previously built FD entries (indices 0..loop-1) were never freed.
The cleanup loop iterated in the wrong direction, starting at the
failed index and going up to frames_to_send, which are entries that
were never built. This caused silent FLE pool exhaustion, after which
every subsequent build_sec_fd returned -ENOMEM, enqueue_burst
returned 0 indefinitely, and the crypto-perf test hung.

Fix both dpaa2_sec_enqueue_burst and dpaa2_sec_enqueue_burst_ordered
by clamping frames_to_send to loop + 1 and iterating from 0 to
free all allocated FLE buffers including the failed entry.

Fixes: 623326dded3a ("crypto/dpaa2_sec: introduce poll mode driver")
Cc: stable@dpdk.org
Signed-off-by: Gagandeep Singh <g.singh@nxp.com>
---
 drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c | 6 ++++++
 1 file changed, 6 insertions(+)

diff --git a/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c b/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c
index 2a015a3d82..15152cc5a1 100644
--- a/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c
+++ b/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c
@@ -1550,6 +1550,9 @@ dpaa2_sec_enqueue_burst(void *qp, struct rte_crypto_op **ops,
 			ret = build_sec_fd(*ops, &fd_arr[loop], bpid, dpaa2_qp);
 			if (ret) {
 				DPAA2_SEC_DP_DEBUG("FD build failed");
+				frames_to_send = loop + 1;
+				for (loop = 0; loop < frames_to_send; loop++)
+					free_fle(&fd_arr[loop], dpaa2_qp);
 				goto skip_tx;
 			}
 			ops++;
@@ -1909,6 +1912,9 @@ dpaa2_sec_enqueue_burst_ordered(void *qp, struct rte_crypto_op **ops,
 			ret = build_sec_fd(*ops, &fd_arr[loop], bpid, dpaa2_qp);
 			if (ret) {
 				DPAA2_SEC_DP_DEBUG("FD build failed");
+				frames_to_send = loop + 1;
+				for (loop = 0; loop < frames_to_send; loop++)
+					free_fle(&fd_arr[loop], dpaa2_qp);
 				goto skip_tx;
 			}
 			ops++;
-- 
2.25.1


^ permalink raw reply related	[flat|nested] 26+ messages in thread

* [PATCH v2 3/6] crypto/dpaa2_sec: increase ivsize range for AES-CTR
  2026-09-30  7:08 ` [PATCH v2 0/6] DPAA2 SEC related changes Gagandeep Singh
  2026-09-30  7:08   ` [PATCH v2 1/6] crypto/dpaa2_sec: fix buffer overflow in GCM decrypt Gagandeep Singh
  2026-09-30  7:08   ` [PATCH v2 2/6] crypto/dpaa2_sec: fix FLE pool leak on sec FD build failure Gagandeep Singh
@ 2026-09-30  7:08   ` Gagandeep Singh
  2026-09-30  7:08   ` [PATCH v2 4/6] crypto/dpaa2_sec: add missing ECN capability Gagandeep Singh
                     ` (3 subsequent siblings)
  6 siblings, 0 replies; 26+ messages in thread
From: Gagandeep Singh @ 2026-09-30  7:08 UTC (permalink / raw)
  To: dev, gakhil; +Cc: hemant.agrawal, Gagandeep Singh

Widen the AES-CTR IV size range from the fixed 16-byte value to
[12, 16] with a 4-byte increment. This allows 96-bit IVs (the
standard NIST SP 800-38A recommendation) in addition to 128-bit
IVs, aligning with common usage and test-vector expectations.

The change applies to both dpaa2_sec_capabilities and
dpaa2_pdcp_capabilities.

Signed-off-by: Hemant Agrawal <hemant.agrawal@nxp.com>
Signed-off-by: Gagandeep Singh <g.singh@nxp.com>
---
 drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h | 8 ++++----
 1 file changed, 4 insertions(+), 4 deletions(-)

diff --git a/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h b/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h
index ff32f3d860..b9a6440f78 100644
--- a/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h
+++ b/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h
@@ -625,9 +625,9 @@ static const struct rte_cryptodev_capabilities dpaa2_sec_capabilities[] = {
 					.increment = 8
 				},
 				.iv_size = {
-					.min = 16,
+					.min = 12,
 					.max = 16,
-					.increment = 0
+					.increment = 4
 				},
 			}, }
 		}, }
@@ -824,9 +824,9 @@ static const struct rte_cryptodev_capabilities dpaa2_pdcp_capabilities[] = {
 					.increment = 8
 				},
 				.iv_size = {
-					.min = 16,
+					.min = 12,
 					.max = 16,
-					.increment = 0
+					.increment = 4
 				}
 			}, }
 		}, }
-- 
2.25.1


^ permalink raw reply related	[flat|nested] 26+ messages in thread

* [PATCH v2 4/6] crypto/dpaa2_sec: add missing ECN capability
  2026-09-30  7:08 ` [PATCH v2 0/6] DPAA2 SEC related changes Gagandeep Singh
                     ` (2 preceding siblings ...)
  2026-09-30  7:08   ` [PATCH v2 3/6] crypto/dpaa2_sec: increase ivsize range for AES-CTR Gagandeep Singh
@ 2026-09-30  7:08   ` Gagandeep Singh
  2026-09-30  7:08   ` [PATCH v2 5/6] crypto/dpaa2_sec: add support for env variables Gagandeep Singh
                     ` (2 subsequent siblings)
  6 siblings, 0 replies; 26+ messages in thread
From: Gagandeep Singh @ 2026-09-30  7:08 UTC (permalink / raw)
  To: dev, gakhil; +Cc: hemant.agrawal, Gagandeep Singh

Set the .ecn = 1 flag in both tunnel-mode security capability
entries to advertise that the driver supports ECN (Explicit
Congestion Notification) copying during IPsec encap/decap.

Signed-off-by: Gagandeep Singh <g.singh@nxp.com>
---
 drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h b/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h
index b9a6440f78..94ba321c72 100644
--- a/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h
+++ b/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h
@@ -973,6 +973,7 @@ static const struct rte_security_capability dpaa2_sec_security_cap[] = {
 				.copy_df = 1,
 				.copy_dscp = 1,
 				.dec_ttl = 1,
+				.ecn = 1,
 				.esn = 1,
 			},
 			.replay_win_sz_max = 1024
@@ -992,6 +993,7 @@ static const struct rte_security_capability dpaa2_sec_security_cap[] = {
 				.copy_df = 1,
 				.copy_dscp = 1,
 				.dec_ttl = 1,
+				.ecn = 1,
 				.esn = 1,
 			},
 			.replay_win_sz_max = 1024
-- 
2.25.1


^ permalink raw reply related	[flat|nested] 26+ messages in thread

* [PATCH v2 5/6] crypto/dpaa2_sec: add support for env variables
  2026-09-30  7:08 ` [PATCH v2 0/6] DPAA2 SEC related changes Gagandeep Singh
                     ` (3 preceding siblings ...)
  2026-09-30  7:08   ` [PATCH v2 4/6] crypto/dpaa2_sec: add missing ECN capability Gagandeep Singh
@ 2026-09-30  7:08   ` Gagandeep Singh
  2026-10-05 18:37     ` [EXTERNAL] " Akhil Goyal
  2026-09-30  7:08   ` [PATCH v2 6/6] crypto/dpaa2_sec: support AES-GMAC Gagandeep Singh
  2026-10-06 11:43   ` [PATCH v3 0/6] DPAA2 SEC related changes Gagandeep Singh
  6 siblings, 1 reply; 26+ messages in thread
From: Gagandeep Singh @ 2026-09-30  7:08 UTC (permalink / raw)
  To: dev, gakhil; +Cc: hemant.agrawal, Gagandeep Singh

Allow driver configuration via environment variables as a fallback
when devargs are not provided. After processing devargs (or when
devargs are absent), check DRIVER_STRICT_ORDER and DRIVER_DUMP_MODE
environment variables to set en_loose_ordered and dpaa2_sec_dp_dump.

This lets users configure the driver without modifying EAL arguments,
useful in environments where command-line access is restricted.

Signed-off-by: Gagandeep Singh <g.singh@nxp.com>
---
 doc/guides/cryptodevs/dpaa2_sec.rst         | 12 ++++++++-
 drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c | 27 ++++++++++++++++++---
 2 files changed, 34 insertions(+), 5 deletions(-)

diff --git a/doc/guides/cryptodevs/dpaa2_sec.rst b/doc/guides/cryptodevs/dpaa2_sec.rst
index f95c6282bb..925d3371bf 100644
--- a/doc/guides/cryptodevs/dpaa2_sec.rst
+++ b/doc/guides/cryptodevs/dpaa2_sec.rst
@@ -1,5 +1,5 @@
 ..  SPDX-License-Identifier: BSD-3-Clause
-    Copyright 2016 NXP
+    Copyright 2016,2026 NXP
 
 
 
@@ -188,9 +188,19 @@ along with other useful debugging information like session, queue, descriptor
 data.
 e.g. ``fslmc:dpseci.1,drv_dump_mode=1``
 
+Alternatively, set the environment variable ``drv_dump_mode`` to the desired
+mode value. The environment variable is used as a fallback when the devarg is
+not provided, which is useful in production environments where modifying EAL
+command-line arguments is not practical.
+e.g. ``export drv_dump_mode=1``
+
 Enable strict ordering
 ----------------------
 
 Use dev arg option ``drv_strict_order=1`` to enable strict ordering.
 By default, loose ordering is set for ordered schedule type event.
 e.g. ``fslmc:dpseci.1,drv_strict_order=1``
+
+Alternatively, set the environment variable ``drv_strict_order=1`` to enable
+strict ordering without modifying EAL arguments.
+e.g. ``export drv_strict_order=1``
diff --git a/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c b/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c
index 15152cc5a1..0ff54fb644 100644
--- a/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c
+++ b/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c
@@ -4366,25 +4366,44 @@ check_devargs_handler(const char *key, const char *value,
 static void
 dpaa2_sec_get_devargs(struct rte_cryptodev *cryptodev, const char *key)
 {
+	struct dpaa2_sec_dev_private *internals;
 	struct rte_kvargs *kvlist;
 	struct rte_devargs *devargs;
+	int ret;
+	char *env;
+
+	internals = cryptodev->data->dev_private;
 
 	devargs = cryptodev->device->devargs;
 	if (!devargs)
-		return;
+		goto env_set;
 
 	kvlist = rte_kvargs_parse(devargs->args, NULL);
 	if (!kvlist)
-		return;
+		goto env_set;
 
 	if (!rte_kvargs_count(kvlist, key)) {
 		rte_kvargs_free(kvlist);
-		return;
+		goto env_set;
 	}
 
-	rte_kvargs_process(kvlist, key,
+	ret = rte_kvargs_process(kvlist, key,
 			check_devargs_handler, (void *)cryptodev);
 	rte_kvargs_free(kvlist);
+	if (!ret)
+		return;
+
+env_set:
+	env = getenv(DRIVER_STRICT_ORDER);
+	if (env)
+		internals->en_loose_ordered = !atoi(env);
+
+	env = getenv(DRIVER_DUMP_MODE);
+	if (env) {
+		dpaa2_sec_dp_dump = atoi(env);
+		if (dpaa2_sec_dp_dump > DPAA2_SEC_DP_FULL_DUMP)
+			dpaa2_sec_dp_dump = DPAA2_SEC_DP_FULL_DUMP;
+	}
 }
 
 static int
-- 
2.25.1


^ permalink raw reply related	[flat|nested] 26+ messages in thread

* [PATCH v2 6/6] crypto/dpaa2_sec: support AES-GMAC
  2026-09-30  7:08 ` [PATCH v2 0/6] DPAA2 SEC related changes Gagandeep Singh
                     ` (4 preceding siblings ...)
  2026-09-30  7:08   ` [PATCH v2 5/6] crypto/dpaa2_sec: add support for env variables Gagandeep Singh
@ 2026-09-30  7:08   ` Gagandeep Singh
  2026-10-05 18:14     ` [EXTERNAL] " Akhil Goyal
  2026-10-06 11:43   ` [PATCH v3 0/6] DPAA2 SEC related changes Gagandeep Singh
  6 siblings, 1 reply; 26+ messages in thread
From: Gagandeep Singh @ 2026-09-30  7:08 UTC (permalink / raw)
  To: dev, gakhil; +Cc: hemant.agrawal, Gagandeep Singh

Add AES-GMAC (RTE_CRYPTO_AUTH_AES_GMAC) support to the dpaa2_sec driver
for both symmetric auth-only and IPsec lookaside protocol paths.

For the auth-only path, AES-GMAC uses the GCM shared descriptor
(cnstr_shdsc_gcm_encap/decap) with per-packet IV and data supplied
via sym_op->auth.{iv,data,digest}.

For the IPsec lookaside protocol path, AES-GMAC maps to
OP_PCL_IPSEC_AES_NULL_WITH_GMAC.  The SEC hardware protocol word
treats this as a cipher type, so the GMAC key and algtype are placed
in cipherdata rather than authdata.  This is handled in
dpaa2_sec_ipsec_proto_init() by overriding cipherdata with the auth
key and setting authdata algtype to HMAC_NULL.

Also add AES-GMAC to dpaa2_sec_capabilities[] as an AUTH xform.

Signed-off-by: Gagandeep Singh <g.singh@nxp.com>
---
 doc/guides/cryptodevs/dpaa2_sec.rst          |  1 +
 doc/guides/cryptodevs/features/dpaa2_sec.ini |  3 ++
 drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c  | 43 +++++++++++++++++++-
 drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h    | 28 ++++++++++++-
 4 files changed, 73 insertions(+), 2 deletions(-)

diff --git a/doc/guides/cryptodevs/dpaa2_sec.rst b/doc/guides/cryptodevs/dpaa2_sec.rst
index 925d3371bf..d9a661c272 100644
--- a/doc/guides/cryptodevs/dpaa2_sec.rst
+++ b/doc/guides/cryptodevs/dpaa2_sec.rst
@@ -125,6 +125,7 @@ Hash algorithms:
 * ``RTE_CRYPTO_AUTH_MD5_HMAC``
 * ``RTE_CRYPTO_AUTH_AES_XCBC_MAC``
 * ``RTE_CRYPTO_AUTH_AES_CMAC``
+* ``RTE_CRYPTO_AUTH_AES_GMAC``
 
 AEAD algorithms:
 
diff --git a/doc/guides/cryptodevs/features/dpaa2_sec.ini b/doc/guides/cryptodevs/features/dpaa2_sec.ini
index a280c7b51b..49434739f0 100644
--- a/doc/guides/cryptodevs/features/dpaa2_sec.ini
+++ b/doc/guides/cryptodevs/features/dpaa2_sec.ini
@@ -48,6 +48,9 @@ SHA384 HMAC  = Y
 SHA512       = Y
 SHA512 HMAC  = Y
 SNOW3G UIA2  = Y
+AES GMAC (128) = Y
+AES GMAC (192) = Y
+AES GMAC (256) = Y
 AES XCBC MAC = Y
 ZUC EIA3     = Y
 AES CMAC (128) = Y
diff --git a/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c b/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c
index 0ff54fb644..8e271a3b50 100644
--- a/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c
+++ b/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c
@@ -1,7 +1,7 @@
 /* SPDX-License-Identifier: BSD-3-Clause
  *
  *   Copyright (c) 2016 Freescale Semiconductor, Inc. All rights reserved.
- *   Copyright 2016-2025 NXP
+ *   Copyright 2016-2026 NXP
  *
  */
 
@@ -2483,6 +2483,30 @@ dpaa2_sec_auth_init(struct rte_crypto_sym_xform *xform,
 					   !session->dir,
 					   session->digest_length);
 		break;
+	case RTE_CRYPTO_AUTH_AES_GMAC:
+		/* AES-GMAC is an authentication-only operation using the
+		 * GCM algorithm with a zero-length payload.  The IV is
+		 * passed per-packet via the auth xform iv field, and the
+		 * data to authenticate is in sym_op->auth.data.
+		 */
+		session->iv.offset = xform->auth.iv.offset;
+		session->iv.length = xform->auth.iv.length;
+		session->auth_alg = RTE_CRYPTO_AUTH_AES_GMAC;
+		authdata.algtype = OP_ALG_ALGSEL_AES;
+		authdata.algmode = OP_ALG_AAI_GCM;
+		if (session->dir == DIR_ENC)
+			bufsize = cnstr_shdsc_gcm_encap(
+					priv->flc_desc[DESC_INITFINAL].desc,
+					1, 0, SHR_NEVER, &authdata,
+					session->iv.length,
+					session->digest_length);
+		else
+			bufsize = cnstr_shdsc_gcm_decap(
+					priv->flc_desc[DESC_INITFINAL].desc,
+					1, 0, SHR_NEVER, &authdata,
+					session->iv.length,
+					session->digest_length);
+		break;
 	default:
 		DPAA2_SEC_ERR("Crypto: Unsupported Auth alg %s (%u)",
 			rte_cryptodev_get_auth_algo_string(xform->auth.algo),
@@ -3046,6 +3070,18 @@ dpaa2_sec_ipsec_proto_init(struct rte_crypto_cipher_xform *cipher_xform,
 		authdata->algtype = OP_PCL_IPSEC_HMAC_MD5_96;
 		authdata->algmode = OP_ALG_AAI_HMAC;
 		break;
+	case RTE_CRYPTO_AUTH_AES_GMAC:
+		/* AES-GMAC uses OP_PCL_IPSEC_AES_NULL_WITH_GMAC which is
+		 * treated as a cipher type in the SEC protocol word.
+		 * Place the GMAC key in cipherdata and set authdata to NULL.
+		 */
+		cipherdata->key = (size_t)session->auth_key.data;
+		cipherdata->keylen = session->auth_key.length;
+		cipherdata->key_enc_flags = 0;
+		cipherdata->key_type = RTA_DATA_IMM;
+		cipherdata->algtype = OP_PCL_IPSEC_AES_NULL_WITH_GMAC;
+		authdata->algtype = OP_PCL_IPSEC_HMAC_NULL;
+		return 0;
 	case RTE_CRYPTO_AUTH_SHA224_HMAC:
 		authdata->algmode = OP_ALG_AAI_HMAC;
 		if (session->digest_length == 6)
@@ -3142,6 +3178,9 @@ dpaa2_sec_set_ipsec_session(struct rte_cryptodev *dev,
 
 	PMD_INIT_FUNC_TRACE();
 
+	memset(&authdata, 0, sizeof(authdata));
+	memset(&cipherdata, 0, sizeof(cipherdata));
+
 	RTE_SET_USED(dev);
 
 	/** Make FLC address to align with stashing, low 6 bits are used
@@ -3217,6 +3256,7 @@ dpaa2_sec_set_ipsec_session(struct rte_cryptodev *dev,
 		case OP_PCL_IPSEC_AES_GCM8:
 		case OP_PCL_IPSEC_AES_GCM12:
 		case OP_PCL_IPSEC_AES_GCM16:
+		case OP_PCL_IPSEC_AES_NULL_WITH_GMAC:
 			memcpy(encap_pdb.gcm.salt,
 				(uint8_t *)&(ipsec_xform->salt), 4);
 			break;
@@ -3357,6 +3397,7 @@ dpaa2_sec_set_ipsec_session(struct rte_cryptodev *dev,
 		case OP_PCL_IPSEC_AES_GCM8:
 		case OP_PCL_IPSEC_AES_GCM12:
 		case OP_PCL_IPSEC_AES_GCM16:
+		case OP_PCL_IPSEC_AES_NULL_WITH_GMAC:
 			memcpy(decap_pdb.gcm.salt,
 				(uint8_t *)&(ipsec_xform->salt), 4);
 			break;
diff --git a/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h b/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h
index 94ba321c72..913c91ebc2 100644
--- a/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h
+++ b/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h
@@ -1,7 +1,7 @@
 /* SPDX-License-Identifier: BSD-3-Clause
  *
  *   Copyright (c) 2016 Freescale Semiconductor, Inc. All rights reserved.
- *   Copyright 2016,2020-2024 NXP
+ *   Copyright 2016,2020-2026 NXP
  *
  */
 
@@ -528,6 +528,32 @@ static const struct rte_cryptodev_capabilities dpaa2_sec_capabilities[] = {
 			}, }
 		}, }
 	},
+	{	/* AES GMAC */
+		.op = RTE_CRYPTO_OP_TYPE_SYMMETRIC,
+		{.sym = {
+			.xform_type = RTE_CRYPTO_SYM_XFORM_AUTH,
+			{.auth = {
+				.algo = RTE_CRYPTO_AUTH_AES_GMAC,
+				.block_size = 16,
+				.key_size = {
+					.min = 16,
+					.max = 32,
+					.increment = 8
+				},
+				.digest_size = {
+					.min = 8,
+					.max = 16,
+					.increment = 4
+				},
+				.aad_size = { 0 },
+				.iv_size = {
+					.min = 12,
+					.max = 12,
+					.increment = 0
+				},
+			}, }
+		}, }
+	},
 	{	/* AES XCBC HMAC */
 		.op = RTE_CRYPTO_OP_TYPE_SYMMETRIC,
 		{.sym = {
-- 
2.25.1


^ permalink raw reply related	[flat|nested] 26+ messages in thread

* RE: [EXTERNAL] [PATCH v2 6/6] crypto/dpaa2_sec: support AES-GMAC
  2026-09-30  7:08   ` [PATCH v2 6/6] crypto/dpaa2_sec: support AES-GMAC Gagandeep Singh
@ 2026-10-05 18:14     ` Akhil Goyal
  0 siblings, 0 replies; 26+ messages in thread
From: Akhil Goyal @ 2026-10-05 18:14 UTC (permalink / raw)
  To: Gagandeep Singh, dev@dpdk.org; +Cc: hemant.agrawal@nxp.com

> Add AES-GMAC (RTE_CRYPTO_AUTH_AES_GMAC) support to the dpaa2_sec
> driver
> for both symmetric auth-only and IPsec lookaside protocol paths.
> 
> For the auth-only path, AES-GMAC uses the GCM shared descriptor
> (cnstr_shdsc_gcm_encap/decap) with per-packet IV and data supplied
> via sym_op->auth.{iv,data,digest}.
> 
> For the IPsec lookaside protocol path, AES-GMAC maps to
> OP_PCL_IPSEC_AES_NULL_WITH_GMAC.  The SEC hardware protocol word
> treats this as a cipher type, so the GMAC key and algtype are placed
> in cipherdata rather than authdata.  This is handled in
> dpaa2_sec_ipsec_proto_init() by overriding cipherdata with the auth
> key and setting authdata algtype to HMAC_NULL.
> 
> Also add AES-GMAC to dpaa2_sec_capabilities[] as an AUTH xform.
> 
> Signed-off-by: Gagandeep Singh <g.singh@nxp.com>
> ---
>  doc/guides/cryptodevs/dpaa2_sec.rst          |  1 +
>  doc/guides/cryptodevs/features/dpaa2_sec.ini |  3 ++
>  drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c  | 43 +++++++++++++++++++-
>  drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h    | 28 ++++++++++++-
>  4 files changed, 73 insertions(+), 2 deletions(-)
> 
> diff --git a/doc/guides/cryptodevs/dpaa2_sec.rst
> b/doc/guides/cryptodevs/dpaa2_sec.rst
> index 925d3371bf..d9a661c272 100644
> --- a/doc/guides/cryptodevs/dpaa2_sec.rst
> +++ b/doc/guides/cryptodevs/dpaa2_sec.rst
> @@ -125,6 +125,7 @@ Hash algorithms:
>  * ``RTE_CRYPTO_AUTH_MD5_HMAC``
>  * ``RTE_CRYPTO_AUTH_AES_XCBC_MAC``
>  * ``RTE_CRYPTO_AUTH_AES_CMAC``
> +* ``RTE_CRYPTO_AUTH_AES_GMAC``
> 
>  AEAD algorithms:
> 
> diff --git a/doc/guides/cryptodevs/features/dpaa2_sec.ini
> b/doc/guides/cryptodevs/features/dpaa2_sec.ini
> index a280c7b51b..49434739f0 100644
> --- a/doc/guides/cryptodevs/features/dpaa2_sec.ini
> +++ b/doc/guides/cryptodevs/features/dpaa2_sec.ini
> @@ -48,6 +48,9 @@ SHA384 HMAC  = Y
>  SHA512       = Y
>  SHA512 HMAC  = Y
>  SNOW3G UIA2  = Y
> +AES GMAC (128) = Y
> +AES GMAC (192) = Y
> +AES GMAC (256) = Y
>  AES XCBC MAC = Y
>  ZUC EIA3     = Y
>  AES CMAC (128) = Y
Please fix 
Warning generate_overview_table(): Unknown feature 'AES GMAC (128)' in 'dpaa2_sec.ini'

^ permalink raw reply	[flat|nested] 26+ messages in thread

* RE: [EXTERNAL] [PATCH v2 5/6] crypto/dpaa2_sec: add support for env variables
  2026-09-30  7:08   ` [PATCH v2 5/6] crypto/dpaa2_sec: add support for env variables Gagandeep Singh
@ 2026-10-05 18:37     ` Akhil Goyal
  2026-10-06  4:15       ` Gagandeep Singh
  0 siblings, 1 reply; 26+ messages in thread
From: Akhil Goyal @ 2026-10-05 18:37 UTC (permalink / raw)
  To: Gagandeep Singh, dev@dpdk.org; +Cc: hemant.agrawal@nxp.com, Stephen Hemminger

> Allow driver configuration via environment variables as a fallback
> when devargs are not provided. After processing devargs (or when
> devargs are absent), check DRIVER_STRICT_ORDER and DRIVER_DUMP_MODE
> environment variables to set en_loose_ordered and dpaa2_sec_dp_dump.
> 
> This lets users configure the driver without modifying EAL arguments,
> useful in environments where command-line access is restricted.
> 
> Signed-off-by: Gagandeep Singh <g.singh@nxp.com>
> ---
>  doc/guides/cryptodevs/dpaa2_sec.rst         | 12 ++++++++-
>  drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c | 27 ++++++++++++++++++---
>  2 files changed, 34 insertions(+), 5 deletions(-)
> 
> diff --git a/doc/guides/cryptodevs/dpaa2_sec.rst
> b/doc/guides/cryptodevs/dpaa2_sec.rst
> index f95c6282bb..925d3371bf 100644
> --- a/doc/guides/cryptodevs/dpaa2_sec.rst
> +++ b/doc/guides/cryptodevs/dpaa2_sec.rst
> @@ -1,5 +1,5 @@
>  ..  SPDX-License-Identifier: BSD-3-Clause
> -    Copyright 2016 NXP
> +    Copyright 2016,2026 NXP
> 
> 
> 
> @@ -188,9 +188,19 @@ along with other useful debugging information like
> session, queue, descriptor
>  data.
>  e.g. ``fslmc:dpseci.1,drv_dump_mode=1``
> 
> +Alternatively, set the environment variable ``drv_dump_mode`` to the desired
> +mode value. The environment variable is used as a fallback when the devarg is
> +not provided, which is useful in production environments where modifying EAL
> +command-line arguments is not practical.
> +e.g. ``export drv_dump_mode=1``
> +

I think Stephen has pointed out that this is bad precedent.
DPDK has already a way to configure to avoid env variables.
It is not clear why we need this?
While there is a way to set env variable, but cannot change command line args?
Is this a debug thing?


^ permalink raw reply	[flat|nested] 26+ messages in thread

* RE: [EXTERNAL] [PATCH v2 5/6] crypto/dpaa2_sec: add support for env variables
  2026-10-05 18:37     ` [EXTERNAL] " Akhil Goyal
@ 2026-10-06  4:15       ` Gagandeep Singh
  0 siblings, 0 replies; 26+ messages in thread
From: Gagandeep Singh @ 2026-10-06  4:15 UTC (permalink / raw)
  To: Akhil Goyal, dev@dpdk.org; +Cc: Hemant Agrawal, Stephen Hemminger

Hi,


NXP Confidential
> -----Original Message-----
> From: Akhil Goyal <gakhil@marvell.com>
> Sent: Tuesday, October 6, 2026 12:08 AM
> To: Gagandeep Singh <G.Singh@nxp.com>; dev@dpdk.org
> Cc: Hemant Agrawal <hemant.agrawal@nxp.com>; Stephen Hemminger
> <stephen@networkplumber.org>
> Subject: RE: [EXTERNAL] [PATCH v2 5/6] crypto/dpaa2_sec: add support for env
> variables
>
> > Allow driver configuration via environment variables as a fallback
> > when devargs are not provided. After processing devargs (or when
> > devargs are absent), check DRIVER_STRICT_ORDER and DRIVER_DUMP_MODE
> > environment variables to set en_loose_ordered and dpaa2_sec_dp_dump.
> >
> > This lets users configure the driver without modifying EAL arguments,
> > useful in environments where command-line access is restricted.
> >
> > Signed-off-by: Gagandeep Singh <g.singh@nxp.com>
> > ---
> >  doc/guides/cryptodevs/dpaa2_sec.rst         | 12 ++++++++-
> >  drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c | 27
> > ++++++++++++++++++---
> >  2 files changed, 34 insertions(+), 5 deletions(-)
> >
> > diff --git a/doc/guides/cryptodevs/dpaa2_sec.rst
> > b/doc/guides/cryptodevs/dpaa2_sec.rst
> > index f95c6282bb..925d3371bf 100644
> > --- a/doc/guides/cryptodevs/dpaa2_sec.rst
> > +++ b/doc/guides/cryptodevs/dpaa2_sec.rst
> > @@ -1,5 +1,5 @@
> >  ..  SPDX-License-Identifier: BSD-3-Clause
> > -    Copyright 2016 NXP
> > +    Copyright 2016,2026 NXP
> >
> >
> >
> > @@ -188,9 +188,19 @@ along with other useful debugging information
> > like session, queue, descriptor  data.
> >  e.g. ``fslmc:dpseci.1,drv_dump_mode=1``
> >
> > +Alternatively, set the environment variable ``drv_dump_mode`` to the
> > +desired mode value. The environment variable is used as a fallback
> > +when the devarg is not provided, which is useful in production
> > +environments where modifying EAL command-line arguments is not practical.
> > +e.g. ``export drv_dump_mode=1``
> > +
>
> I think Stephen has pointed out that this is bad precedent.
> DPDK has already a way to configure to avoid env variables.
> It is not clear why we need this?
> While there is a way to set env variable, but cannot change command line args?
> Is this a debug thing?

This is mainly intended for debug/diagnostic use. Many of our customers do not expose DPDK command-line arguments and instead use a fixed set of EAL parameters built into the application or deployment framework. In such cases, an environment variable provides a simple way to enable temporary diagnostics in the fields.

That said, I understand the concern about introducing an alternative configuration mechanism. If the preference is to keep configuration strictly through devargs, I can remove this patch.

^ permalink raw reply	[flat|nested] 26+ messages in thread

* [PATCH v3 0/6]  DPAA2 SEC related changes
  2026-09-30  7:08 ` [PATCH v2 0/6] DPAA2 SEC related changes Gagandeep Singh
                     ` (5 preceding siblings ...)
  2026-09-30  7:08   ` [PATCH v2 6/6] crypto/dpaa2_sec: support AES-GMAC Gagandeep Singh
@ 2026-10-06 11:43   ` Gagandeep Singh
  2026-10-06 11:43     ` [PATCH v3 1/6] crypto/dpaa2_sec: fix buffer overflow in GCM decrypt Gagandeep Singh
                       ` (5 more replies)
  6 siblings, 6 replies; 26+ messages in thread
From: Gagandeep Singh @ 2026-10-06 11:43 UTC (permalink / raw)
  To: dev, gakhil; +Cc: hemant.agrawal

V3-changes:
 - updated dpaa3_sec.ini with correct feature name.

V2-changes:
 - Support AES-GMAC as AUTH algorithm instead of as AEAD.

This series include bug fixes, enhancement and AES-GMAC support

Gagandeep Singh (6):
  crypto/dpaa2_sec: fix buffer overflow in GCM decrypt
  crypto/dpaa2_sec: fix FLE pool leak on sec FD build failure
  crypto/dpaa2_sec: increase ivsize range for AES-CTR
  crypto/dpaa2_sec: add missing ECN capability
  crypto/dpaa2_sec: add support for env variables
  crypto/dpaa2_sec: support AES-GMAC

 doc/guides/cryptodevs/dpaa2_sec.rst          | 13 +++-
 doc/guides/cryptodevs/features/dpaa2_sec.ini |  1 +
 drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c  | 78 ++++++++++++++++++--
 drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h    | 40 ++++++++--
 4 files changed, 120 insertions(+), 12 deletions(-)

-- 
2.25.1


^ permalink raw reply	[flat|nested] 26+ messages in thread

* [PATCH v3 1/6] crypto/dpaa2_sec: fix buffer overflow in GCM decrypt
  2026-10-06 11:43   ` [PATCH v3 0/6] DPAA2 SEC related changes Gagandeep Singh
@ 2026-10-06 11:43     ` Gagandeep Singh
  2026-10-06 11:43     ` [PATCH v3 2/6] crypto/dpaa2_sec: fix FLE pool leak on sec FD build failure Gagandeep Singh
                       ` (4 subsequent siblings)
  5 siblings, 0 replies; 26+ messages in thread
From: Gagandeep Singh @ 2026-10-06 11:43 UTC (permalink / raw)
  To: dev, gakhil; +Cc: hemant.agrawal, stable, Gagandeep Singh

In build_authenc_gcm_fd, when both AAD (auth_only_len > 0) and decrypt
direction are active, the SGE layout occupies 8 entries plus 16 bytes of
old_icv storage at index 8. The FLE pool buffer was only 256 bytes
(8 x 32), causing old_icv to be written one entry past the end of the
allocated buffer. The resulting virtual address was not mapped by the
IOMMU, so DPAA2_VADDR_TO_IOVA returned 0 and the SEC engine received
iova=0x00000000 as the ICV buffer address, triggering an SMMU
translation fault (FSR=0x402 TF).

Additionally, the upfront bpid/IVP initialization only covered sge+3,
leaving sge+4 (the input data SGE when AAD is present) without a valid
bpid or IVP assignment.

Increase FLE_POOL_BUF_SIZE from 256 to 288 (9 x 32 bytes) to
accommodate the full layout, and extend the bpid/IVP initialization
to cover sge+4 in both branches of build_authenc_gcm_fd.

Fixes: 13273250eec5 ("crypto/dpaa2_sec: support AES-GCM and CTR")
Cc: stable@dpdk.org
Signed-off-by: Gagandeep Singh <g.singh@nxp.com>
---
 drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c | 2 ++
 drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h   | 2 +-
 2 files changed, 3 insertions(+), 1 deletion(-)

diff --git a/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c b/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c
index 3d980d096f..2a015a3d82 100644
--- a/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c
+++ b/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c
@@ -569,6 +569,7 @@ build_authenc_gcm_fd(dpaa2_sec_session *sess,
 		DPAA2_SET_FLE_BPID(sge + 1, bpid);
 		DPAA2_SET_FLE_BPID(sge + 2, bpid);
 		DPAA2_SET_FLE_BPID(sge + 3, bpid);
+		DPAA2_SET_FLE_BPID(sge + 4, bpid);
 	} else {
 		DPAA2_SET_FD_IVP(fd);
 		DPAA2_SET_FLE_IVP(fle);
@@ -577,6 +578,7 @@ build_authenc_gcm_fd(dpaa2_sec_session *sess,
 		DPAA2_SET_FLE_IVP((sge + 1));
 		DPAA2_SET_FLE_IVP((sge + 2));
 		DPAA2_SET_FLE_IVP((sge + 3));
+		DPAA2_SET_FLE_IVP((sge + 4));
 	}
 
 	/* Save the shared descriptor */
diff --git a/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h b/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h
index 755c8e9cc3..ff32f3d860 100644
--- a/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h
+++ b/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h
@@ -17,7 +17,7 @@ extern uint8_t cryptodev_driver_id;
 
 /* FLE_POOL_NUM_BUFS is set as per the ipsec-secgw application */
 #define FLE_POOL_NUM_BUFS	32000
-#define FLE_POOL_BUF_SIZE	256
+#define FLE_POOL_BUF_SIZE	288
 #define FLE_POOL_CACHE_SIZE	512
 #define FLE_SG_MEM_SIZE(num)	(FLE_POOL_BUF_SIZE + ((num) * 32))
 
-- 
2.25.1


^ permalink raw reply related	[flat|nested] 26+ messages in thread

* [PATCH v3 2/6] crypto/dpaa2_sec: fix FLE pool leak on sec FD build failure
  2026-10-06 11:43   ` [PATCH v3 0/6] DPAA2 SEC related changes Gagandeep Singh
  2026-10-06 11:43     ` [PATCH v3 1/6] crypto/dpaa2_sec: fix buffer overflow in GCM decrypt Gagandeep Singh
@ 2026-10-06 11:43     ` Gagandeep Singh
  2026-10-06 11:43     ` [PATCH v3 3/6] crypto/dpaa2_sec: increase ivsize range for AES-CTR Gagandeep Singh
                       ` (3 subsequent siblings)
  5 siblings, 0 replies; 26+ messages in thread
From: Gagandeep Singh @ 2026-10-06 11:43 UTC (permalink / raw)
  To: dev, gakhil; +Cc: hemant.agrawal, stable, Gagandeep Singh

When build_sec_fd fails at index loop inside the enqueue burst loops,
the previously built FD entries (indices 0..loop-1) were never freed.
The cleanup loop iterated in the wrong direction, starting at the
failed index and going up to frames_to_send, which are entries that
were never built. This caused silent FLE pool exhaustion, after which
every subsequent build_sec_fd returned -ENOMEM, enqueue_burst
returned 0 indefinitely, and the crypto-perf test hung.

Fix both dpaa2_sec_enqueue_burst and dpaa2_sec_enqueue_burst_ordered
by clamping frames_to_send to loop + 1 and iterating from 0 to
free all allocated FLE buffers including the failed entry.

Fixes: 623326dded3a ("crypto/dpaa2_sec: introduce poll mode driver")
Cc: stable@dpdk.org
Signed-off-by: Gagandeep Singh <g.singh@nxp.com>
---
 drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c | 6 ++++++
 1 file changed, 6 insertions(+)

diff --git a/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c b/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c
index 2a015a3d82..15152cc5a1 100644
--- a/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c
+++ b/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c
@@ -1550,6 +1550,9 @@ dpaa2_sec_enqueue_burst(void *qp, struct rte_crypto_op **ops,
 			ret = build_sec_fd(*ops, &fd_arr[loop], bpid, dpaa2_qp);
 			if (ret) {
 				DPAA2_SEC_DP_DEBUG("FD build failed");
+				frames_to_send = loop + 1;
+				for (loop = 0; loop < frames_to_send; loop++)
+					free_fle(&fd_arr[loop], dpaa2_qp);
 				goto skip_tx;
 			}
 			ops++;
@@ -1909,6 +1912,9 @@ dpaa2_sec_enqueue_burst_ordered(void *qp, struct rte_crypto_op **ops,
 			ret = build_sec_fd(*ops, &fd_arr[loop], bpid, dpaa2_qp);
 			if (ret) {
 				DPAA2_SEC_DP_DEBUG("FD build failed");
+				frames_to_send = loop + 1;
+				for (loop = 0; loop < frames_to_send; loop++)
+					free_fle(&fd_arr[loop], dpaa2_qp);
 				goto skip_tx;
 			}
 			ops++;
-- 
2.25.1


^ permalink raw reply related	[flat|nested] 26+ messages in thread

* [PATCH v3 3/6] crypto/dpaa2_sec: increase ivsize range for AES-CTR
  2026-10-06 11:43   ` [PATCH v3 0/6] DPAA2 SEC related changes Gagandeep Singh
  2026-10-06 11:43     ` [PATCH v3 1/6] crypto/dpaa2_sec: fix buffer overflow in GCM decrypt Gagandeep Singh
  2026-10-06 11:43     ` [PATCH v3 2/6] crypto/dpaa2_sec: fix FLE pool leak on sec FD build failure Gagandeep Singh
@ 2026-10-06 11:43     ` Gagandeep Singh
  2026-10-06 11:43     ` [PATCH v3 4/6] crypto/dpaa2_sec: add missing ECN capability Gagandeep Singh
                       ` (2 subsequent siblings)
  5 siblings, 0 replies; 26+ messages in thread
From: Gagandeep Singh @ 2026-10-06 11:43 UTC (permalink / raw)
  To: dev, gakhil; +Cc: hemant.agrawal, Gagandeep Singh

Widen the AES-CTR IV size range from the fixed 16-byte value to
[12, 16] with a 4-byte increment. This allows 96-bit IVs (the
standard NIST SP 800-38A recommendation) in addition to 128-bit
IVs, aligning with common usage and test-vector expectations.

The change applies to both dpaa2_sec_capabilities and
dpaa2_pdcp_capabilities.

Signed-off-by: Hemant Agrawal <hemant.agrawal@nxp.com>
Signed-off-by: Gagandeep Singh <g.singh@nxp.com>
---
 drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h | 8 ++++----
 1 file changed, 4 insertions(+), 4 deletions(-)

diff --git a/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h b/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h
index ff32f3d860..b9a6440f78 100644
--- a/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h
+++ b/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h
@@ -625,9 +625,9 @@ static const struct rte_cryptodev_capabilities dpaa2_sec_capabilities[] = {
 					.increment = 8
 				},
 				.iv_size = {
-					.min = 16,
+					.min = 12,
 					.max = 16,
-					.increment = 0
+					.increment = 4
 				},
 			}, }
 		}, }
@@ -824,9 +824,9 @@ static const struct rte_cryptodev_capabilities dpaa2_pdcp_capabilities[] = {
 					.increment = 8
 				},
 				.iv_size = {
-					.min = 16,
+					.min = 12,
 					.max = 16,
-					.increment = 0
+					.increment = 4
 				}
 			}, }
 		}, }
-- 
2.25.1


^ permalink raw reply related	[flat|nested] 26+ messages in thread

* [PATCH v3 4/6] crypto/dpaa2_sec: add missing ECN capability
  2026-10-06 11:43   ` [PATCH v3 0/6] DPAA2 SEC related changes Gagandeep Singh
                       ` (2 preceding siblings ...)
  2026-10-06 11:43     ` [PATCH v3 3/6] crypto/dpaa2_sec: increase ivsize range for AES-CTR Gagandeep Singh
@ 2026-10-06 11:43     ` Gagandeep Singh
  2026-10-06 11:43     ` [PATCH v3 5/6] crypto/dpaa2_sec: add support for env variables Gagandeep Singh
  2026-10-06 11:43     ` [PATCH v3 6/6] crypto/dpaa2_sec: support AES-GMAC Gagandeep Singh
  5 siblings, 0 replies; 26+ messages in thread
From: Gagandeep Singh @ 2026-10-06 11:43 UTC (permalink / raw)
  To: dev, gakhil; +Cc: hemant.agrawal, Gagandeep Singh

Set the .ecn = 1 flag in both tunnel-mode security capability
entries to advertise that the driver supports ECN (Explicit
Congestion Notification) copying during IPsec encap/decap.

Signed-off-by: Gagandeep Singh <g.singh@nxp.com>
---
 drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h b/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h
index b9a6440f78..94ba321c72 100644
--- a/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h
+++ b/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h
@@ -973,6 +973,7 @@ static const struct rte_security_capability dpaa2_sec_security_cap[] = {
 				.copy_df = 1,
 				.copy_dscp = 1,
 				.dec_ttl = 1,
+				.ecn = 1,
 				.esn = 1,
 			},
 			.replay_win_sz_max = 1024
@@ -992,6 +993,7 @@ static const struct rte_security_capability dpaa2_sec_security_cap[] = {
 				.copy_df = 1,
 				.copy_dscp = 1,
 				.dec_ttl = 1,
+				.ecn = 1,
 				.esn = 1,
 			},
 			.replay_win_sz_max = 1024
-- 
2.25.1


^ permalink raw reply related	[flat|nested] 26+ messages in thread

* [PATCH v3 5/6] crypto/dpaa2_sec: add support for env variables
  2026-10-06 11:43   ` [PATCH v3 0/6] DPAA2 SEC related changes Gagandeep Singh
                       ` (3 preceding siblings ...)
  2026-10-06 11:43     ` [PATCH v3 4/6] crypto/dpaa2_sec: add missing ECN capability Gagandeep Singh
@ 2026-10-06 11:43     ` Gagandeep Singh
  2026-10-06 11:43     ` [PATCH v3 6/6] crypto/dpaa2_sec: support AES-GMAC Gagandeep Singh
  5 siblings, 0 replies; 26+ messages in thread
From: Gagandeep Singh @ 2026-10-06 11:43 UTC (permalink / raw)
  To: dev, gakhil; +Cc: hemant.agrawal, Gagandeep Singh

Allow driver configuration via environment variables as a fallback
when devargs are not provided. After processing devargs (or when
devargs are absent), check DRIVER_STRICT_ORDER and DRIVER_DUMP_MODE
environment variables to set en_loose_ordered and dpaa2_sec_dp_dump.

This lets users configure the driver without modifying EAL arguments,
useful in environments where command-line access is restricted.

Signed-off-by: Gagandeep Singh <g.singh@nxp.com>
---
 doc/guides/cryptodevs/dpaa2_sec.rst         | 12 ++++++++-
 drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c | 27 ++++++++++++++++++---
 2 files changed, 34 insertions(+), 5 deletions(-)

diff --git a/doc/guides/cryptodevs/dpaa2_sec.rst b/doc/guides/cryptodevs/dpaa2_sec.rst
index f95c6282bb..925d3371bf 100644
--- a/doc/guides/cryptodevs/dpaa2_sec.rst
+++ b/doc/guides/cryptodevs/dpaa2_sec.rst
@@ -1,5 +1,5 @@
 ..  SPDX-License-Identifier: BSD-3-Clause
-    Copyright 2016 NXP
+    Copyright 2016,2026 NXP
 
 
 
@@ -188,9 +188,19 @@ along with other useful debugging information like session, queue, descriptor
 data.
 e.g. ``fslmc:dpseci.1,drv_dump_mode=1``
 
+Alternatively, set the environment variable ``drv_dump_mode`` to the desired
+mode value. The environment variable is used as a fallback when the devarg is
+not provided, which is useful in production environments where modifying EAL
+command-line arguments is not practical.
+e.g. ``export drv_dump_mode=1``
+
 Enable strict ordering
 ----------------------
 
 Use dev arg option ``drv_strict_order=1`` to enable strict ordering.
 By default, loose ordering is set for ordered schedule type event.
 e.g. ``fslmc:dpseci.1,drv_strict_order=1``
+
+Alternatively, set the environment variable ``drv_strict_order=1`` to enable
+strict ordering without modifying EAL arguments.
+e.g. ``export drv_strict_order=1``
diff --git a/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c b/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c
index 15152cc5a1..0ff54fb644 100644
--- a/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c
+++ b/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c
@@ -4366,25 +4366,44 @@ check_devargs_handler(const char *key, const char *value,
 static void
 dpaa2_sec_get_devargs(struct rte_cryptodev *cryptodev, const char *key)
 {
+	struct dpaa2_sec_dev_private *internals;
 	struct rte_kvargs *kvlist;
 	struct rte_devargs *devargs;
+	int ret;
+	char *env;
+
+	internals = cryptodev->data->dev_private;
 
 	devargs = cryptodev->device->devargs;
 	if (!devargs)
-		return;
+		goto env_set;
 
 	kvlist = rte_kvargs_parse(devargs->args, NULL);
 	if (!kvlist)
-		return;
+		goto env_set;
 
 	if (!rte_kvargs_count(kvlist, key)) {
 		rte_kvargs_free(kvlist);
-		return;
+		goto env_set;
 	}
 
-	rte_kvargs_process(kvlist, key,
+	ret = rte_kvargs_process(kvlist, key,
 			check_devargs_handler, (void *)cryptodev);
 	rte_kvargs_free(kvlist);
+	if (!ret)
+		return;
+
+env_set:
+	env = getenv(DRIVER_STRICT_ORDER);
+	if (env)
+		internals->en_loose_ordered = !atoi(env);
+
+	env = getenv(DRIVER_DUMP_MODE);
+	if (env) {
+		dpaa2_sec_dp_dump = atoi(env);
+		if (dpaa2_sec_dp_dump > DPAA2_SEC_DP_FULL_DUMP)
+			dpaa2_sec_dp_dump = DPAA2_SEC_DP_FULL_DUMP;
+	}
 }
 
 static int
-- 
2.25.1


^ permalink raw reply related	[flat|nested] 26+ messages in thread

* [PATCH v3 6/6] crypto/dpaa2_sec: support AES-GMAC
  2026-10-06 11:43   ` [PATCH v3 0/6] DPAA2 SEC related changes Gagandeep Singh
                       ` (4 preceding siblings ...)
  2026-10-06 11:43     ` [PATCH v3 5/6] crypto/dpaa2_sec: add support for env variables Gagandeep Singh
@ 2026-10-06 11:43     ` Gagandeep Singh
  5 siblings, 0 replies; 26+ messages in thread
From: Gagandeep Singh @ 2026-10-06 11:43 UTC (permalink / raw)
  To: dev, gakhil; +Cc: hemant.agrawal, Gagandeep Singh

Add AES-GMAC (RTE_CRYPTO_AUTH_AES_GMAC) support to the dpaa2_sec driver
for both symmetric auth-only and IPsec lookaside protocol paths.

For the auth-only path, AES-GMAC uses the GCM shared descriptor
(cnstr_shdsc_gcm_encap/decap) with per-packet IV and data supplied
via sym_op->auth.{iv,data,digest}.

For the IPsec lookaside protocol path, AES-GMAC maps to
OP_PCL_IPSEC_AES_NULL_WITH_GMAC.  The SEC hardware protocol word
treats this as a cipher type, so the GMAC key and algtype are placed
in cipherdata rather than authdata.  This is handled in
dpaa2_sec_ipsec_proto_init() by overriding cipherdata with the auth
key and setting authdata algtype to HMAC_NULL.

Also add AES-GMAC to dpaa2_sec_capabilities[] as an AUTH xform.

Signed-off-by: Gagandeep Singh <g.singh@nxp.com>
---
 doc/guides/cryptodevs/dpaa2_sec.rst          |  1 +
 doc/guides/cryptodevs/features/dpaa2_sec.ini |  1 +
 drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c  | 43 +++++++++++++++++++-
 drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h    | 28 ++++++++++++-
 4 files changed, 71 insertions(+), 2 deletions(-)

diff --git a/doc/guides/cryptodevs/dpaa2_sec.rst b/doc/guides/cryptodevs/dpaa2_sec.rst
index 925d3371bf..d9a661c272 100644
--- a/doc/guides/cryptodevs/dpaa2_sec.rst
+++ b/doc/guides/cryptodevs/dpaa2_sec.rst
@@ -125,6 +125,7 @@ Hash algorithms:
 * ``RTE_CRYPTO_AUTH_MD5_HMAC``
 * ``RTE_CRYPTO_AUTH_AES_XCBC_MAC``
 * ``RTE_CRYPTO_AUTH_AES_CMAC``
+* ``RTE_CRYPTO_AUTH_AES_GMAC``
 
 AEAD algorithms:
 
diff --git a/doc/guides/cryptodevs/features/dpaa2_sec.ini b/doc/guides/cryptodevs/features/dpaa2_sec.ini
index a280c7b51b..c6e7f22a87 100644
--- a/doc/guides/cryptodevs/features/dpaa2_sec.ini
+++ b/doc/guides/cryptodevs/features/dpaa2_sec.ini
@@ -48,6 +48,7 @@ SHA384 HMAC  = Y
 SHA512       = Y
 SHA512 HMAC  = Y
 SNOW3G UIA2  = Y
+AES GMAC     = Y
 AES XCBC MAC = Y
 ZUC EIA3     = Y
 AES CMAC (128) = Y
diff --git a/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c b/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c
index 0ff54fb644..8e271a3b50 100644
--- a/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c
+++ b/drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c
@@ -1,7 +1,7 @@
 /* SPDX-License-Identifier: BSD-3-Clause
  *
  *   Copyright (c) 2016 Freescale Semiconductor, Inc. All rights reserved.
- *   Copyright 2016-2025 NXP
+ *   Copyright 2016-2026 NXP
  *
  */
 
@@ -2483,6 +2483,30 @@ dpaa2_sec_auth_init(struct rte_crypto_sym_xform *xform,
 					   !session->dir,
 					   session->digest_length);
 		break;
+	case RTE_CRYPTO_AUTH_AES_GMAC:
+		/* AES-GMAC is an authentication-only operation using the
+		 * GCM algorithm with a zero-length payload.  The IV is
+		 * passed per-packet via the auth xform iv field, and the
+		 * data to authenticate is in sym_op->auth.data.
+		 */
+		session->iv.offset = xform->auth.iv.offset;
+		session->iv.length = xform->auth.iv.length;
+		session->auth_alg = RTE_CRYPTO_AUTH_AES_GMAC;
+		authdata.algtype = OP_ALG_ALGSEL_AES;
+		authdata.algmode = OP_ALG_AAI_GCM;
+		if (session->dir == DIR_ENC)
+			bufsize = cnstr_shdsc_gcm_encap(
+					priv->flc_desc[DESC_INITFINAL].desc,
+					1, 0, SHR_NEVER, &authdata,
+					session->iv.length,
+					session->digest_length);
+		else
+			bufsize = cnstr_shdsc_gcm_decap(
+					priv->flc_desc[DESC_INITFINAL].desc,
+					1, 0, SHR_NEVER, &authdata,
+					session->iv.length,
+					session->digest_length);
+		break;
 	default:
 		DPAA2_SEC_ERR("Crypto: Unsupported Auth alg %s (%u)",
 			rte_cryptodev_get_auth_algo_string(xform->auth.algo),
@@ -3046,6 +3070,18 @@ dpaa2_sec_ipsec_proto_init(struct rte_crypto_cipher_xform *cipher_xform,
 		authdata->algtype = OP_PCL_IPSEC_HMAC_MD5_96;
 		authdata->algmode = OP_ALG_AAI_HMAC;
 		break;
+	case RTE_CRYPTO_AUTH_AES_GMAC:
+		/* AES-GMAC uses OP_PCL_IPSEC_AES_NULL_WITH_GMAC which is
+		 * treated as a cipher type in the SEC protocol word.
+		 * Place the GMAC key in cipherdata and set authdata to NULL.
+		 */
+		cipherdata->key = (size_t)session->auth_key.data;
+		cipherdata->keylen = session->auth_key.length;
+		cipherdata->key_enc_flags = 0;
+		cipherdata->key_type = RTA_DATA_IMM;
+		cipherdata->algtype = OP_PCL_IPSEC_AES_NULL_WITH_GMAC;
+		authdata->algtype = OP_PCL_IPSEC_HMAC_NULL;
+		return 0;
 	case RTE_CRYPTO_AUTH_SHA224_HMAC:
 		authdata->algmode = OP_ALG_AAI_HMAC;
 		if (session->digest_length == 6)
@@ -3142,6 +3178,9 @@ dpaa2_sec_set_ipsec_session(struct rte_cryptodev *dev,
 
 	PMD_INIT_FUNC_TRACE();
 
+	memset(&authdata, 0, sizeof(authdata));
+	memset(&cipherdata, 0, sizeof(cipherdata));
+
 	RTE_SET_USED(dev);
 
 	/** Make FLC address to align with stashing, low 6 bits are used
@@ -3217,6 +3256,7 @@ dpaa2_sec_set_ipsec_session(struct rte_cryptodev *dev,
 		case OP_PCL_IPSEC_AES_GCM8:
 		case OP_PCL_IPSEC_AES_GCM12:
 		case OP_PCL_IPSEC_AES_GCM16:
+		case OP_PCL_IPSEC_AES_NULL_WITH_GMAC:
 			memcpy(encap_pdb.gcm.salt,
 				(uint8_t *)&(ipsec_xform->salt), 4);
 			break;
@@ -3357,6 +3397,7 @@ dpaa2_sec_set_ipsec_session(struct rte_cryptodev *dev,
 		case OP_PCL_IPSEC_AES_GCM8:
 		case OP_PCL_IPSEC_AES_GCM12:
 		case OP_PCL_IPSEC_AES_GCM16:
+		case OP_PCL_IPSEC_AES_NULL_WITH_GMAC:
 			memcpy(decap_pdb.gcm.salt,
 				(uint8_t *)&(ipsec_xform->salt), 4);
 			break;
diff --git a/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h b/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h
index 94ba321c72..913c91ebc2 100644
--- a/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h
+++ b/drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h
@@ -1,7 +1,7 @@
 /* SPDX-License-Identifier: BSD-3-Clause
  *
  *   Copyright (c) 2016 Freescale Semiconductor, Inc. All rights reserved.
- *   Copyright 2016,2020-2024 NXP
+ *   Copyright 2016,2020-2026 NXP
  *
  */
 
@@ -528,6 +528,32 @@ static const struct rte_cryptodev_capabilities dpaa2_sec_capabilities[] = {
 			}, }
 		}, }
 	},
+	{	/* AES GMAC */
+		.op = RTE_CRYPTO_OP_TYPE_SYMMETRIC,
+		{.sym = {
+			.xform_type = RTE_CRYPTO_SYM_XFORM_AUTH,
+			{.auth = {
+				.algo = RTE_CRYPTO_AUTH_AES_GMAC,
+				.block_size = 16,
+				.key_size = {
+					.min = 16,
+					.max = 32,
+					.increment = 8
+				},
+				.digest_size = {
+					.min = 8,
+					.max = 16,
+					.increment = 4
+				},
+				.aad_size = { 0 },
+				.iv_size = {
+					.min = 12,
+					.max = 12,
+					.increment = 0
+				},
+			}, }
+		}, }
+	},
 	{	/* AES XCBC HMAC */
 		.op = RTE_CRYPTO_OP_TYPE_SYMMETRIC,
 		{.sym = {
-- 
2.25.1


^ permalink raw reply related	[flat|nested] 26+ messages in thread

end of thread, other threads:[~2026-10-06 11:44 UTC | newest]

Thread overview: 26+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-10 11:29 [PATCH 0/6] DPAA2 SEC related changes Gagandeep Singh
2026-08-10 11:29 ` [PATCH 1/6] crypto/dpaa2_sec: fix buffer overflow in GCM decrypt Gagandeep Singh
2026-08-10 11:29 ` [PATCH 2/6] crypto/dpaa2_sec: fix FLE pool leak on sec FD build failure Gagandeep Singh
2026-08-10 11:29 ` [PATCH 3/6] crypto/dpaa2_sec: support AES-GMAC Gagandeep Singh
2026-08-10 11:29 ` [PATCH 4/6] crypto/dpaa2_sec: increase ivsize range for AES-CTR Gagandeep Singh
2026-08-10 11:29 ` [PATCH 5/6] crypto/dpaa2_sec: add missing ECN capability Gagandeep Singh
2026-08-10 11:29 ` [PATCH 6/6] crypto/dpaa2_sec: add support for env variables Gagandeep Singh
2026-08-10 15:16   ` Stephen Hemminger
2026-08-11  7:50     ` Gagandeep Singh
2026-09-30  7:08 ` [PATCH v2 0/6] DPAA2 SEC related changes Gagandeep Singh
2026-09-30  7:08   ` [PATCH v2 1/6] crypto/dpaa2_sec: fix buffer overflow in GCM decrypt Gagandeep Singh
2026-09-30  7:08   ` [PATCH v2 2/6] crypto/dpaa2_sec: fix FLE pool leak on sec FD build failure Gagandeep Singh
2026-09-30  7:08   ` [PATCH v2 3/6] crypto/dpaa2_sec: increase ivsize range for AES-CTR Gagandeep Singh
2026-09-30  7:08   ` [PATCH v2 4/6] crypto/dpaa2_sec: add missing ECN capability Gagandeep Singh
2026-09-30  7:08   ` [PATCH v2 5/6] crypto/dpaa2_sec: add support for env variables Gagandeep Singh
2026-10-05 18:37     ` [EXTERNAL] " Akhil Goyal
2026-10-06  4:15       ` Gagandeep Singh
2026-09-30  7:08   ` [PATCH v2 6/6] crypto/dpaa2_sec: support AES-GMAC Gagandeep Singh
2026-10-05 18:14     ` [EXTERNAL] " Akhil Goyal
2026-10-06 11:43   ` [PATCH v3 0/6] DPAA2 SEC related changes Gagandeep Singh
2026-10-06 11:43     ` [PATCH v3 1/6] crypto/dpaa2_sec: fix buffer overflow in GCM decrypt Gagandeep Singh
2026-10-06 11:43     ` [PATCH v3 2/6] crypto/dpaa2_sec: fix FLE pool leak on sec FD build failure Gagandeep Singh
2026-10-06 11:43     ` [PATCH v3 3/6] crypto/dpaa2_sec: increase ivsize range for AES-CTR Gagandeep Singh
2026-10-06 11:43     ` [PATCH v3 4/6] crypto/dpaa2_sec: add missing ECN capability Gagandeep Singh
2026-10-06 11:43     ` [PATCH v3 5/6] crypto/dpaa2_sec: add support for env variables Gagandeep Singh
2026-10-06 11:43     ` [PATCH v3 6/6] crypto/dpaa2_sec: support AES-GMAC Gagandeep Singh

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox