[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <aYRNpFgo7ikv5F8V@secunet.com>
Date: Thu, 5 Feb 2026 08:58:28 +0100
From: Steffen Klassert <steffen.klassert@...unet.com>
To: Tariq Toukan <tariqt@...dia.com>
CC: Eric Dumazet <edumazet@...gle.com>, Jakub Kicinski <kuba@...nel.org>,
Paolo Abeni <pabeni@...hat.com>, Andrew Lunn <andrew+netdev@...n.ch>, "David
S. Miller" <davem@...emloft.net>, Herbert Xu <herbert@...dor.apana.org.au>,
<netdev@...r.kernel.org>, <linux-kernel@...r.kernel.org>, Mark Bloch
<mbloch@...dia.com>, Gal Pressman <gal@...dia.com>, Moshe Shemesh
<moshe@...dia.com>, Jianbo Liu <jianbol@...dia.com>, Cosmin Ratiu
<cratiu@...dia.com>, Alexandre Cassen <acassen@...p.free.fr>, Leon Romanovsky
<leonro@...dia.com>
Subject: Re: [PATCH net] xfrm: skip templates check for packet offload tunnel
mode
On Tue, Jan 27, 2026 at 02:49:23PM +0200, Tariq Toukan wrote:
> From: Leon Romanovsky <leonro@...dia.com>
>
> In packet offload, hardware is responsible to check templates. The
> result of its operation is forwarded through secpath by relevant
> drivers. That secpath is actually removed in __xfrm_policy_check2().
>
> In case packet is forwarded, this secpath is reset in RX, but pushed
> again to TX where policy is rechecked again against dummy secpath
> in xfrm_policy_ok().
>
> Such situation causes to unexpected XfrmInTmplMismatch increase.
>
> As a solution, simply skip template mismatch check.
>
> Fixes: 600258d555f0 ("xfrm: delete intermediate secpath entry in packet offload mode")
> Signed-off-by: Leon Romanovsky <leonro@...dia.com>
> Reviewed-by: Jianbo Liu <jianbol@...dia.com>
> Reviewed-by: Cosmin Ratiu <cratiu@...dia.com>
> Signed-off-by: Tariq Toukan <tariqt@...dia.com>
Applied, thanks everyone!
Powered by blists - more mailing lists