[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-Id: <cover.1652176932.git.leonro@nvidia.com>
Date: Tue, 10 May 2022 13:36:51 +0300
From: Leon Romanovsky <leon@...nel.org>
To: Steffen Klassert <steffen.klassert@...unet.com>
Cc: Leon Romanovsky <leonro@...dia.com>,
"David S . Miller" <davem@...emloft.net>,
Herbert Xu <herbert@...dor.apana.org.au>,
netdev@...r.kernel.org, Raed Salem <raeds@...dia.com>,
ipsec-devel <devel@...ux-ipsec.org>
Subject: [PATCH ipsec-next 0/6] Extend XFRM core to allow full offload configuration
From: Leon Romanovsky <leonro@...dia.com>
The following series extends XFRM core code to handle new type of IPsec
offload - full offload.
In this mode, the HW is going to be responsible for whole data path, so
both policy and state should be offloaded.
The mlx5 part is coming.
Thanks
Leon Romanovsky (6):
xfrm: add new full offload flag
xfrm: allow state full offload mode
xfrm: add an interface to offload policy
xfrm: add TX datapath support for IPsec full offload mode
xfrm: add RX datapath protection for IPsec full offload mode
xfrm: enforce separation between priorities of HW/SW policies
.../inline_crypto/ch_ipsec/chcr_ipsec.c | 4 +
.../net/ethernet/intel/ixgbe/ixgbe_ipsec.c | 5 +
drivers/net/ethernet/intel/ixgbevf/ipsec.c | 5 +
.../mellanox/mlx5/core/en_accel/ipsec.c | 4 +
drivers/net/netdevsim/ipsec.c | 5 +
include/linux/netdevice.h | 3 +
include/net/netns/xfrm.h | 8 +-
include/net/xfrm.h | 102 ++++++++++++----
include/uapi/linux/xfrm.h | 6 +
net/xfrm/xfrm_device.c | 84 ++++++++++++-
net/xfrm/xfrm_output.c | 19 +++
net/xfrm/xfrm_policy.c | 115 ++++++++++++++++++
net/xfrm/xfrm_user.c | 11 ++
13 files changed, 342 insertions(+), 29 deletions(-)
--
2.35.1
Powered by blists - more mailing lists