From: "David S. Miller" <davem@redhat.com>
To: kunihiro@ipinfusion.com
Cc: Kazunori.Miyazawa@jp.yokogawa.com, netdev@oss.sgi.com,
usagi-core@linux-ipv6.org, kuznet@ms2.inr.ac.ru
Subject: Re: [PATCH] IPv6 IPsec support
Date: Tue, 18 Feb 2003 23:02:11 -0800 (PST) [thread overview]
Message-ID: <20030218.230211.89243941.davem@redhat.com> (raw)
In-Reply-To: <87znos3j8s.wl@ipinfusion.com>
From: Kunihiro Ishiguro <kunihiro@ipinfusion.com>
Date: Tue, 18 Feb 2003 21:57:39 -0800
I think no need of broadcasting my comments to kernel ML, so I took it
of from CC:. netdev guys will be interested in right? So I kept it.
Yes, this is fine.
1. Do we really need to remove AH header from skb?
In case of IPv4 we modify iph->protocol for further processing thus AH
header is removed. But in case of IPv6, we just simply authenticate
the packet then process next header. So do we really need to remove
AH header in IPv6? Remaining AH header does not harm...
This is an interesting topic.
Actually, there is no reason to prefer one way or another.
Remember, if anyone else is interested in SKB contents (such as
tcpdump), that entity has clone of skb and can still see full
contents.
2. Easy kmalloc()...
It seems there are some easy kmalloc(). Yes I'm stingy with memory.
It is another fun topic.
These are great long term improvements. But for now, please consider
something important when evaluating "overhead". This is the fact that
we are performing full encryption or hash function. Such operation is
quite massively more expensive than kmalloc here and there.
Some day we will have hw acceleration support both at IPSEC and at
crypto library level. At that time cost analysis will change.
Well, I'll find more. Maybe we should be offline and come up with a
single patch.
I would ask that Alexey and myself stay on the CC: list.
It would not hurt to keep netdev as well, perhaps we can
breed some new experts in our ipsec code :-)
next prev parent reply other threads:[~2003-02-19 7:02 UTC|newest]
Thread overview: 24+ messages / expand[flat|nested] mbox.gz Atom feed top
2003-02-19 4:48 [PATCH] IPv6 IPsec support Kazunori MIyazawa
2003-02-19 4:50 ` David S. Miller
2003-02-19 5:10 ` Kunihiro Ishiguro
2003-02-19 5:17 ` Mitsuru KANDA / 神田 充
2003-02-19 5:58 ` Kazunori Miyazawa
2003-02-19 5:30 ` YOSHIFUJI Hideaki / 吉藤英明
2003-02-19 5:57 ` Kunihiro Ishiguro
2003-02-19 7:02 ` David S. Miller [this message]
2003-02-19 9:13 ` Kunihiro Ishiguro
2003-02-19 7:13 ` David S. Miller
2003-02-19 7:33 ` David S. Miller
2003-02-19 14:39 ` (usagi-core 11926) " Kazunori MIyazawa
2003-02-19 21:27 ` David S. Miller
2003-02-19 16:56 ` Mitsuru KANDA / 神田 充
2003-02-19 21:43 ` David S. Miller
2003-02-19 23:10 ` Kunihiro Ishiguro
2003-02-20 0:37 ` David S. Miller
-- strict thread matches above, loose matches on Subject: below --
2003-02-22 11:26 [PATCH] IPv6 IPSEC support Kazunori Miyazawa
2003-02-22 11:13 ` David S. Miller
2003-02-22 12:15 ` Kazunori Miyazawa
2003-02-22 12:49 ` YOSHIFUJI Hideaki / 吉藤英明
2003-02-22 23:47 ` David S. Miller
2003-02-23 0:44 ` YOSHIFUJI Hideaki / 吉藤英明
2003-02-23 15:35 ` Kazunori Miyazawa
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20030218.230211.89243941.davem@redhat.com \
--to=davem@redhat.com \
--cc=Kazunori.Miyazawa@jp.yokogawa.com \
--cc=kunihiro@ipinfusion.com \
--cc=kuznet@ms2.inr.ac.ru \
--cc=netdev@oss.sgi.com \
--cc=usagi-core@linux-ipv6.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).