netdev.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
From: Saeed Mahameed <saeed@kernel.org>
To: "David S. Miller" <davem@davemloft.net>,
	Jakub Kicinski <kuba@kernel.org>, Paolo Abeni <pabeni@redhat.com>,
	Eric Dumazet <edumazet@google.com>
Cc: Saeed Mahameed <saeedm@nvidia.com>,
	netdev@vger.kernel.org, Tariq Toukan <tariqt@nvidia.com>,
	Leon Romanovsky <leonro@nvidia.com>
Subject: [net-next V2 04/15] net/mlx5e: Ensure that IPsec sequence packet number starts from 1
Date: Fri, 20 Oct 2023 23:46:09 -0700	[thread overview]
Message-ID: <20231021064620.87397-5-saeed@kernel.org> (raw)
In-Reply-To: <20231021064620.87397-1-saeed@kernel.org>

From: Leon Romanovsky <leonro@nvidia.com>

According to RFC4303, section "3.3.3. Sequence Number Generation",
the first packet sent using a given SA will contain a sequence
number of 1.

However if user didn't set seq/oseq, the HW used zero as first sequence
packet number. Such misconfiguration causes to drop of first packet
if replay window protection was enabled in SA.

To fix it, set sequence number to be at least 1.

Fixes: 7db21ef4566e ("net/mlx5e: Set IPsec replay sequence numbers")
Signed-off-by: Leon Romanovsky <leonro@nvidia.com>
Signed-off-by: Saeed Mahameed <saeedm@nvidia.com>
---
 drivers/net/ethernet/mellanox/mlx5/core/en_accel/ipsec.c | 9 ++++++++-
 1 file changed, 8 insertions(+), 1 deletion(-)

diff --git a/drivers/net/ethernet/mellanox/mlx5/core/en_accel/ipsec.c b/drivers/net/ethernet/mellanox/mlx5/core/en_accel/ipsec.c
index ddd2230f04aa..bf88232a2fc2 100644
--- a/drivers/net/ethernet/mellanox/mlx5/core/en_accel/ipsec.c
+++ b/drivers/net/ethernet/mellanox/mlx5/core/en_accel/ipsec.c
@@ -121,7 +121,14 @@ static bool mlx5e_ipsec_update_esn_state(struct mlx5e_ipsec_sa_entry *sa_entry)
 	if (x->xso.type == XFRM_DEV_OFFLOAD_CRYPTO)
 		esn_msb = xfrm_replay_seqhi(x, htonl(seq_bottom));
 
-	sa_entry->esn_state.esn = esn;
+	if (sa_entry->esn_state.esn_msb)
+		sa_entry->esn_state.esn = esn;
+	else
+		/* According to RFC4303, section "3.3.3. Sequence Number Generation",
+		 * the first packet sent using a given SA will contain a sequence
+		 * number of 1.
+		 */
+		sa_entry->esn_state.esn = max_t(u32, esn, 1);
 	sa_entry->esn_state.esn_msb = esn_msb;
 
 	if (unlikely(overlap && seq_bottom < MLX5E_IPSEC_ESN_SCOPE_MID)) {
-- 
2.41.0


  parent reply	other threads:[~2023-10-21  6:46 UTC|newest]

Thread overview: 26+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2023-10-21  6:46 [pull request][net-next V2 00/15] mlx5 updates 2023-10-19 Saeed Mahameed
2023-10-21  6:46 ` [net-next V2 01/15] xfrm: generalize xdo_dev_state_update_curlft to allow statistics update Saeed Mahameed
2023-10-21  6:46 ` [net-next V2 02/15] xfrm: get global statistics from the offloaded device Saeed Mahameed
2023-10-21  6:46 ` [net-next V2 03/15] net/mlx5e: Honor user choice of IPsec replay window size Saeed Mahameed
2023-10-21  6:46 ` Saeed Mahameed [this message]
2023-10-21  6:46 ` [net-next V2 05/15] net/mlx5e: Unify esw and normal IPsec status table creation/destruction Saeed Mahameed
2023-10-21  6:46 ` [net-next V2 06/15] net/mlx5e: Remove exposure of IPsec RX flow steering struct Saeed Mahameed
2023-10-21  6:46 ` [net-next V2 07/15] net/mlx5e: Add IPsec and ASO syndromes check in HW Saeed Mahameed
2023-10-21  6:46 ` [net-next V2 08/15] net/mlx5e: Connect mlx5 IPsec statistics with XFRM core Saeed Mahameed
2023-10-21  6:46 ` [net-next V2 09/15] net/mlx5e: Delete obsolete IPsec code Saeed Mahameed
2023-10-21  6:46 ` [net-next V2 10/15] net/mlx5: Increase size of irq name buffer Saeed Mahameed
2023-10-21  6:46 ` [net-next V2 11/15] net/mlx5e: Reduce the size of icosq_str Saeed Mahameed
2023-10-21  6:46 ` [net-next V2 12/15] net/mlx5e: Check return value of snprintf writing to fw_version buffer Saeed Mahameed
2023-10-21  6:46 ` [net-next V2 13/15] net/mlx5e: Check return value of snprintf writing to fw_version buffer for representors Saeed Mahameed
2023-10-21  6:46 ` [net-next V2 14/15] net/mlx5: print change on SW reset semaphore returns busy Saeed Mahameed
2023-10-21  6:46 ` [net-next V2 15/15] net/mlx5: Allow sync reset flow when BF MGT interface device is present Saeed Mahameed
2023-10-25  1:02 ` [pull request][net-next V2 00/15] mlx5 updates 2023-10-19 Jakub Kicinski
2023-10-25  8:52   ` Leon Romanovsky
2023-10-26  1:25     ` Jakub Kicinski
2023-10-26  7:29       ` Leon Romanovsky
2023-10-26 22:26   ` Saeed Mahameed
2023-10-26 22:46     ` Jakub Kicinski
2023-10-27  0:44       ` Saeed Mahameed
2023-10-27 10:08         ` Leon Romanovsky
2023-10-27 22:02 ` Saeed Mahameed
2023-10-29  7:44   ` Leon Romanovsky

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20231021064620.87397-5-saeed@kernel.org \
    --to=saeed@kernel.org \
    --cc=davem@davemloft.net \
    --cc=edumazet@google.com \
    --cc=kuba@kernel.org \
    --cc=leonro@nvidia.com \
    --cc=netdev@vger.kernel.org \
    --cc=pabeni@redhat.com \
    --cc=saeedm@nvidia.com \
    --cc=tariqt@nvidia.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).