From patchwork Tue Oct 24 11:00:06 2017 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Github ODP bot X-Patchwork-Id: 116942 Delivered-To: patch@linaro.org Received: by 10.140.22.164 with SMTP id 33csp5665522qgn; Tue, 24 Oct 2017 04:02:51 -0700 (PDT) X-Google-Smtp-Source: ABhQp+SkB0+K6FKQxVKCYKByan+h7vzMbYLnFLzvxIFDzfJKxsFYi9jtsYp5qFH07vgTw8+fOO+H X-Received: by 10.55.215.22 with SMTP id m22mr23392697qki.64.1508842970570; Tue, 24 Oct 2017 04:02:50 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1508842970; cv=none; d=google.com; s=arc-20160816; b=PE/qSB274dQdwNGJUK0rJt3bfElCptjAb1XST/JN1/2ipZnuRrE6o7nc/W/AHI2gCV VARPHbNqoM2iDrZWc5v3/Qc/jP56QQvkW8GhWBn76e0JDDW/IQiBzOuQidW66pM+Srfn Eet3rU48AaL3srXRsWyvTYNsnwCxsI+R903IiQusGHEl13rF7s+F63vy9SFMf2yr6gDW xeGH0RFWKgqCUi1+Fpl6WGDe+KCx823g10UFDQnAGLTDALO1Nm7eC9BtlsPcBBGs5mDy Up0DRSYU7+TbeivdbYKK6DAWv3R19SxzB9ygOx3mMR4p9DtneyYNu9oiiVYZqnZDis71 uuzA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=sender:errors-to:list-subscribe:list-help:list-post:list-archive :list-unsubscribe:list-id:precedence:subject:github-pr-num :references:in-reply-to:message-id:date:to:from:delivered-to :arc-authentication-results; bh=nUWKwN4Q6BMv5yZneGyCzn3Xy6tq7H1t0LOzqKd+OKE=; b=HwBzc5lX88rXST/HBZ93pAvMG4X54T1UAwZCOEqxJOROxZbQuiNuSEg/HdJ6GcKEqL JaJBSDpvGgFlyKM9Ecc9MTdHb3z9mejfEBI0b/cDT2vWEoWYWRXmmLSCuGjZLUoCfTt9 Moq/Hc6v/2OTuPxiOKohvExy0LHafojSlv1P9Ic5+E168+wjI0Wo63Om2ZeweIHew/GY 55ZZd7kY9aZA8ZRg0gyHBXL9zCpYdjo66g0A3vrtIbRJ2Aqr3WL90mxOYgLO6o83wDLQ FC8tu2OSS127cf5xOqR9sx5POufFLZU4iBYRVhyy0yGtwXtG8in9Q3UoEyv7NH6dzV5K 0wgA== ARC-Authentication-Results: i=1; mx.google.com; spf=pass (google.com: domain of lng-odp-bounces@lists.linaro.org designates 54.197.127.237 as permitted sender) smtp.mailfrom=lng-odp-bounces@lists.linaro.org; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=yandex.ru Return-Path: Received: from lists.linaro.org (ec2-54-197-127-237.compute-1.amazonaws.com. [54.197.127.237]) by mx.google.com with ESMTP id q1si16167qkq.313.2017.10.24.04.02.50; Tue, 24 Oct 2017 04:02:50 -0700 (PDT) Received-SPF: pass (google.com: domain of lng-odp-bounces@lists.linaro.org designates 54.197.127.237 as permitted sender) client-ip=54.197.127.237; Authentication-Results: mx.google.com; spf=pass (google.com: domain of lng-odp-bounces@lists.linaro.org designates 54.197.127.237 as permitted sender) smtp.mailfrom=lng-odp-bounces@lists.linaro.org; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=yandex.ru Received: by lists.linaro.org (Postfix, from userid 109) id 1A358628DE; Tue, 24 Oct 2017 11:02:50 +0000 (UTC) X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on ip-10-142-244-252 X-Spam-Level: X-Spam-Status: No, score=-2.6 required=5.0 tests=BAYES_00,FREEMAIL_FROM, RCVD_IN_DNSWL_LOW,RCVD_IN_MSPIKE_H3,RCVD_IN_MSPIKE_WL,URIBL_BLOCKED autolearn=disabled version=3.4.0 Received: from [127.0.0.1] (localhost [127.0.0.1]) by lists.linaro.org (Postfix) with ESMTP id CB4B5628C4; Tue, 24 Oct 2017 11:00:56 +0000 (UTC) X-Original-To: lng-odp@lists.linaro.org Delivered-To: lng-odp@lists.linaro.org Received: by lists.linaro.org (Postfix, from userid 109) id 3C846628AC; Tue, 24 Oct 2017 11:00:38 +0000 (UTC) Received: from forward103p.mail.yandex.net (forward103p.mail.yandex.net [77.88.28.106]) by lists.linaro.org (Postfix) with ESMTPS id 867EB6204C for ; Tue, 24 Oct 2017 11:00:33 +0000 (UTC) Received: from mxback18j.mail.yandex.net (mxback18j.mail.yandex.net [IPv6:2a02:6b8:0:1619::94]) by forward103p.mail.yandex.net (Yandex) with ESMTP id 167A62184FEF for ; Tue, 24 Oct 2017 14:00:32 +0300 (MSK) Received: from smtp1p.mail.yandex.net (smtp1p.mail.yandex.net [2a02:6b8:0:1472:2741:0:8b6:6]) by mxback18j.mail.yandex.net (nwsmtp/Yandex) with ESMTP id MwcW0nBA56-0VXSH71N; Tue, 24 Oct 2017 14:00:32 +0300 Received: by smtp1p.mail.yandex.net (nwsmtp/Yandex) with ESMTPSA id hdAvnRHsih-0VPSgk7p; Tue, 24 Oct 2017 14:00:31 +0300 (using TLSv1.2 with cipher ECDHE-RSA-AES128-SHA256 (128/128 bits)) (Client certificate not present) From: Github ODP bot To: lng-odp@lists.linaro.org Date: Tue, 24 Oct 2017 14:00:06 +0300 Message-Id: <1508842806-17934-4-git-send-email-odpbot@yandex.ru> X-Mailer: git-send-email 1.9.1 In-Reply-To: <1508842806-17934-1-git-send-email-odpbot@yandex.ru> References: <1508842806-17934-1-git-send-email-odpbot@yandex.ru> Github-pr-num: 256 Subject: [lng-odp] [PATCH API-NEXT v1 3/3] linux-gen: implement odp_ipsec_sa_disable() changes X-BeenThere: lng-odp@lists.linaro.org X-Mailman-Version: 2.1.16 Precedence: list List-Id: "The OpenDataPlane \(ODP\) List" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: lng-odp-bounces@lists.linaro.org Sender: "lng-odp" From: Dmitry Eremin-Solenikov Signed-off-by: Dmitry Eremin-Solenikov --- /** Email created from pull request 256 (lumag:ipsec_sa_disable_v2) ** https://github.com/Linaro/odp/pull/256 ** Patch: https://github.com/Linaro/odp/pull/256.patch ** Base sha: 825f75ed8644ef57c5648961e7982daf13cd9375 ** Merge commit sha: 1bab6bb255422c8eb061c6482397eb498fc7b1cc **/ .../linux-generic/include/odp_ipsec_internal.h | 20 +++++++- platform/linux-generic/odp_ipsec.c | 18 ++++---- platform/linux-generic/odp_ipsec_events.c | 54 +++++++++++++++++++++- platform/linux-generic/odp_ipsec_sad.c | 16 ++----- 4 files changed, 84 insertions(+), 24 deletions(-) diff --git a/platform/linux-generic/include/odp_ipsec_internal.h b/platform/linux-generic/include/odp_ipsec_internal.h index 1340ca7bd..09a7ac126 100644 --- a/platform/linux-generic/include/odp_ipsec_internal.h +++ b/platform/linux-generic/include/odp_ipsec_internal.h @@ -74,9 +74,20 @@ void _odp_ipsec_status_free(ipsec_status_t status); int _odp_ipsec_status_send(odp_queue_t queue, odp_ipsec_status_id_t id, odp_ipsec_sa_t sa, - int result, odp_ipsec_warn_t warn); +/** + * @internal Send SA_DISABLED event + * + * Sends the packet notifying application that SA finished all processing and + * is now disabled. + * + * @param queue destination queue + * @param sa SA respective to the operation + */ +int _odp_ipsec_sa_disabled_send(odp_queue_t queue, + odp_ipsec_sa_t sa); + #define IPSEC_MAX_IV_LEN 32 /**< Maximum IV length in bytes */ #define IPSEC_MAX_SALT_LEN 4 /**< Maximum salt length in bytes */ @@ -191,6 +202,13 @@ int _odp_ipsec_sa_update_stats(ipsec_sa_t *ipsec_sa, uint32_t len, int _odp_ipsec_try_inline(odp_packet_t pkt); /** + * Return IPsec result instance connected to the IPsec packet + * + * @param packet packet of ODP_EVENT_PACKET_IPSEC subtype + */ +odp_ipsec_packet_result_t *_odp_ipsec_pkt_result(odp_packet_t packet); + +/** * @} */ diff --git a/platform/linux-generic/odp_ipsec.c b/platform/linux-generic/odp_ipsec.c index e57736c2a..e9bf88c17 100644 --- a/platform/linux-generic/odp_ipsec.c +++ b/platform/linux-generic/odp_ipsec.c @@ -93,7 +93,7 @@ int odp_ipsec_config(const odp_ipsec_config_t *config) return 0; } -static odp_ipsec_packet_result_t *ipsec_pkt_result(odp_packet_t packet) +odp_ipsec_packet_result_t *_odp_ipsec_pkt_result(odp_packet_t packet) { ODP_ASSERT(ODP_EVENT_PACKET_IPSEC == odp_event_subtype(odp_packet_to_event(packet))); @@ -902,7 +902,7 @@ int odp_ipsec_in(const odp_packet_t pkt_in[], int num_in, _odp_buffer_event_subtype_set(packet_to_buffer(pkt), ODP_EVENT_PACKET_IPSEC); - result = ipsec_pkt_result(pkt); + result = _odp_ipsec_pkt_result(pkt); memset(result, 0, sizeof(*result)); result->status = status; if (NULL != ipsec_sa) @@ -966,7 +966,7 @@ int odp_ipsec_out(const odp_packet_t pkt_in[], int num_in, _odp_buffer_event_subtype_set(packet_to_buffer(pkt), ODP_EVENT_PACKET_IPSEC); - result = ipsec_pkt_result(pkt); + result = _odp_ipsec_pkt_result(pkt); memset(result, 0, sizeof(*result)); result->status = status; result->sa = ipsec_sa->ipsec_sa_hdl; @@ -1014,7 +1014,7 @@ int odp_ipsec_in_enq(const odp_packet_t pkt_in[], int num_in, _odp_buffer_event_subtype_set(packet_to_buffer(pkt), ODP_EVENT_PACKET_IPSEC); - result = ipsec_pkt_result(pkt); + result = _odp_ipsec_pkt_result(pkt); memset(result, 0, sizeof(*result)); result->status = status; if (NULL != ipsec_sa) { @@ -1075,7 +1075,7 @@ int odp_ipsec_out_enq(const odp_packet_t pkt_in[], int num_in, _odp_buffer_event_subtype_set(packet_to_buffer(pkt), ODP_EVENT_PACKET_IPSEC); - result = ipsec_pkt_result(pkt); + result = _odp_ipsec_pkt_result(pkt); memset(result, 0, sizeof(*result)); result->status = status; result->sa = ipsec_sa->ipsec_sa_hdl; @@ -1115,7 +1115,7 @@ int _odp_ipsec_try_inline(odp_packet_t pkt) _odp_buffer_event_subtype_set(packet_to_buffer(pkt), ODP_EVENT_PACKET_IPSEC); - result = ipsec_pkt_result(pkt); + result = _odp_ipsec_pkt_result(pkt); memset(result, 0, sizeof(*result)); result->status = status; result->sa = ipsec_sa->ipsec_sa_hdl; @@ -1192,7 +1192,7 @@ int odp_ipsec_out_inline(const odp_packet_t pkt_in[], int num_in, _odp_buffer_event_subtype_set(packet_to_buffer(pkt), ODP_EVENT_PACKET_IPSEC); - result = ipsec_pkt_result(pkt); + result = _odp_ipsec_pkt_result(pkt); memset(result, 0, sizeof(*result)); result->sa = ipsec_sa->ipsec_sa_hdl; result->status = status; @@ -1217,7 +1217,7 @@ int odp_ipsec_out_inline(const odp_packet_t pkt_in[], int num_in, buf = packet_to_buffer(pkt); _odp_buffer_event_subtype_set(buf, ODP_EVENT_PACKET_IPSEC); - result = ipsec_pkt_result(pkt); + result = _odp_ipsec_pkt_result(pkt); memset(result, 0, sizeof(*result)); result->sa = ipsec_sa->ipsec_sa_hdl; result->status = status; @@ -1246,7 +1246,7 @@ int odp_ipsec_result(odp_ipsec_packet_result_t *result, odp_packet_t packet) ODP_ASSERT(result != NULL); - res = ipsec_pkt_result(packet); + res = _odp_ipsec_pkt_result(packet); /* FIXME: maybe postprocess here, setting alg error in case of crypto * error instead of processing packet fully in ipsec_in/out_single */ diff --git a/platform/linux-generic/odp_ipsec_events.c b/platform/linux-generic/odp_ipsec_events.c index 3a7ebd6e8..3a3a9f5f5 100644 --- a/platform/linux-generic/odp_ipsec_events.c +++ b/platform/linux-generic/odp_ipsec_events.c @@ -6,6 +6,8 @@ #include "config.h" +#include + #include #include @@ -13,6 +15,8 @@ #include #include #include +#include +#include #include typedef struct { @@ -23,6 +27,7 @@ typedef struct { } ipsec_status_hdr_t; static odp_pool_t ipsec_status_pool = ODP_POOL_INVALID; +static odp_pool_t ipsec_sa_disabled_pool = ODP_POOL_INVALID; #define IPSEC_EVENTS_POOL_BUF_COUNT 1024 @@ -43,8 +48,24 @@ int _odp_ipsec_events_init_global(void) goto err_status; } + odp_pool_param_init(¶m); + + param.pkt.seg_len = 16; + param.pkt.len = 16; + param.pkt.num = ODP_CONFIG_IPSEC_SAS; + param.type = ODP_POOL_PACKET; + + ipsec_sa_disabled_pool = odp_pool_create("ipsec_sa_disabled_pool", + ¶m); + if (ODP_POOL_INVALID == ipsec_sa_disabled_pool) { + ODP_ERR("Error: sa_disabled pool create failed.\n"); + goto err_sa_disabled; + } + return 0; +err_sa_disabled: + odp_pool_destroy(ipsec_status_pool); err_status: return -1; } @@ -54,6 +75,12 @@ int _odp_ipsec_events_term_global(void) int ret = 0; int rc = 0; + ret = odp_pool_destroy(ipsec_sa_disabled_pool); + if (ret < 0) { + ODP_ERR("sa_disabled pool destroy failed"); + rc = -1; + } + ret = odp_pool_destroy(ipsec_status_pool); if (ret < 0) { ODP_ERR("status pool destroy failed"); @@ -112,7 +139,6 @@ void _odp_ipsec_status_free(ipsec_status_t status) int _odp_ipsec_status_send(odp_queue_t queue, odp_ipsec_status_id_t id, odp_ipsec_sa_t sa, - int result, odp_ipsec_warn_t warn) { ipsec_status_t ipsec_ev = odp_ipsec_status_alloc(); @@ -125,7 +151,6 @@ int _odp_ipsec_status_send(odp_queue_t queue, status_hdr->status.id = id; status_hdr->status.sa = sa; - status_hdr->status.result = result; status_hdr->status.warn = warn; if (odp_queue_enq(queue, ipsec_status_to_event(ipsec_ev))) { @@ -154,3 +179,28 @@ int odp_ipsec_status(odp_ipsec_status_t *status, odp_event_t event) return 0; } + +int _odp_ipsec_sa_disabled_send(odp_queue_t queue, + odp_ipsec_sa_t sa) +{ + odp_packet_t packet; + odp_ipsec_packet_result_t *result; + + ODP_ASSERT(ODP_POOL_INVALID != ipsec_sa_disabled_pool); + packet = odp_packet_alloc(ipsec_sa_disabled_pool, 0); + ODP_ASSERT(ODP_PACKET_INVALID != packet); + + _odp_buffer_event_subtype_set(packet_to_buffer(packet), + ODP_EVENT_PACKET_IPSEC); + result = _odp_ipsec_pkt_result(packet); + memset(result, 0, sizeof(*result)); + result->status.error.sa_disabled = 1; + result->sa = sa; + + if (odp_queue_enq(queue, odp_ipsec_packet_to_event(packet))) { + odp_packet_free(packet); + return -1; + } + + return 0; +} diff --git a/platform/linux-generic/odp_ipsec_sad.c b/platform/linux-generic/odp_ipsec_sad.c index f0b5b9e4a..a1eff8849 100644 --- a/platform/linux-generic/odp_ipsec_sad.c +++ b/platform/linux-generic/odp_ipsec_sad.c @@ -171,7 +171,6 @@ void _odp_ipsec_sa_unuse(ipsec_sa_t *ipsec_sa) { odp_queue_t queue; odp_ipsec_sa_t sa; - odp_ipsec_warn_t warn = { .all = 0 }; ODP_ASSERT(NULL != ipsec_sa); @@ -179,9 +178,7 @@ void _odp_ipsec_sa_unuse(ipsec_sa_t *ipsec_sa) sa = ipsec_sa->ipsec_sa_hdl; if (ipsec_sa_unlock(ipsec_sa) && ODP_QUEUE_INVALID != queue) - _odp_ipsec_status_send(queue, - ODP_IPSEC_STATUS_SA_DISABLE, - sa, 0, warn); + _odp_ipsec_sa_disabled_send(queue, sa); } void odp_ipsec_sa_param_init(odp_ipsec_sa_param_t *param) @@ -370,17 +367,12 @@ int odp_ipsec_sa_disable(odp_ipsec_sa_t sa) } if (ODP_QUEUE_INVALID != ipsec_sa->queue) { - odp_ipsec_warn_t warn = { .all = 0 }; - /* - * If there were not active state when we disabled SA, - * send the event. + * If there was no active state when we disabled SA, send the + * event. Otherwise it will be sent by _odp_ipsec_sa_unuse(). */ if (0 == state) - _odp_ipsec_status_send(ipsec_sa->queue, - ODP_IPSEC_STATUS_SA_DISABLE, - ipsec_sa->ipsec_sa_hdl, - 0, warn); + _odp_ipsec_sa_disabled_send(ipsec_sa->queue, sa); return 0; }