From: Anatoly Burakov <anatoly.burakov@intel.com>
To: dev@dpdk.org, Vladimir Medvedkin <vladimir.medvedkin@intel.com>
Subject: [PATCH v1 1/6] net/ixgbe: add key length check in IPsec
Date: Tue, 18 Aug 2026 14:19:27 +0100 [thread overview]
Message-ID: <48a36c08be9e2e5ef8a955847da67ee9e76fda1b.1787059138.git.anatoly.burakov@intel.com> (raw)
In-Reply-To: <cover.1787059137.git.anatoly.burakov@intel.com>
The cryptodev API does not check for user parameters being within the
bounds of what the driver supports. Currently, the only key size supported
by ixgbe is 16 bytes, so that is what we will check for. Add the check.
Signed-off-by: Anatoly Burakov <anatoly.burakov@intel.com>
---
drivers/net/intel/ixgbe/ixgbe_ipsec.c | 6 ++++++
1 file changed, 6 insertions(+)
diff --git a/drivers/net/intel/ixgbe/ixgbe_ipsec.c b/drivers/net/intel/ixgbe/ixgbe_ipsec.c
index bdd34344e8..aaf657af5f 100644
--- a/drivers/net/intel/ixgbe/ixgbe_ipsec.c
+++ b/drivers/net/intel/ixgbe/ixgbe_ipsec.c
@@ -384,6 +384,12 @@ ixgbe_crypto_create_session(void *device,
}
aead_xform = &conf->crypto_xform->aead;
+ /* Only 16-byte keys are supported. */
+ if (aead_xform->key.length != 16) {
+ PMD_DRV_LOG(ERR, "Unsupported key length %u", aead_xform->key.length);
+ return -ENOTSUP;
+ }
+
if (conf->ipsec.direction == RTE_SECURITY_IPSEC_SA_DIR_INGRESS) {
if (dev_conf->rxmode.offloads & RTE_ETH_RX_OFFLOAD_SECURITY) {
ic_session->op = IXGBE_OP_AUTHENTICATED_DECRYPTION;
--
2.52.0
next prev parent reply other threads:[~2026-08-18 13:19 UTC|newest]
Thread overview: 18+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-18 13:19 [PATCH v1 0/6] IXGBE IPsec fixes Anatoly Burakov
2026-08-18 13:19 ` Anatoly Burakov [this message]
2026-08-18 13:19 ` [PATCH v1 2/6] net/ixgbe: remove unnecessary dev pointer Anatoly Burakov
2026-08-18 13:19 ` [PATCH v1 3/6] net/ixgbe: harmonize return values in IPsec Anatoly Burakov
2026-08-18 13:19 ` [PATCH v1 4/6] net/ixgbe: get rid of unnecessary malloc " Anatoly Burakov
2026-08-18 13:19 ` [PATCH v1 5/6] net/ixgbe: fix missing HW write " Anatoly Burakov
2026-08-18 13:19 ` [PATCH v1 6/6] net/ixgbe: refactor IPsec code Anatoly Burakov
2026-08-18 16:14 ` [PATCH v1 0/6] IXGBE IPsec fixes Radu Nicolau
2026-08-19 12:32 ` [PATCH v2 0/7] " Anatoly Burakov
2026-08-19 12:32 ` [PATCH v2 1/7] net/ixgbe: add key length check in IPsec Anatoly Burakov
2026-08-19 12:32 ` [PATCH v2 2/7] net/ixgbe: remove unnecessary dev pointer Anatoly Burakov
2026-08-19 12:32 ` [PATCH v2 3/7] net/ixgbe: harmonize return values in IPsec Anatoly Burakov
2026-08-19 12:32 ` [PATCH v2 4/7] net/ixgbe: get rid of unnecessary malloc " Anatoly Burakov
2026-08-19 12:32 ` [PATCH v2 5/7] net/ixgbe: use correct index variable " Anatoly Burakov
2026-08-19 12:52 ` Bruce Richardson
2026-08-19 12:32 ` [PATCH v2 6/7] net/ixgbe: fix missing HW write " Anatoly Burakov
2026-08-19 12:32 ` [PATCH v2 7/7] net/ixgbe: refactor IPsec code Anatoly Burakov
2026-08-19 14:04 ` [PATCH v2 0/7] IXGBE IPsec fixes Bruce Richardson
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=48a36c08be9e2e5ef8a955847da67ee9e76fda1b.1787059138.git.anatoly.burakov@intel.com \
--to=anatoly.burakov@intel.com \
--cc=dev@dpdk.org \
--cc=vladimir.medvedkin@intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox