Patch Detail
get:
Show a patch.
patch:
Update a patch.
put:
Update a patch.
GET /api/patches/105173/?format=api
http://patches.dpdk.org/api/patches/105173/?format=api", "web_url": "http://patches.dpdk.org/project/dpdk/patch/1639676975-1316-9-git-send-email-anoobj@marvell.com/", "project": { "id": 1, "url": "http://patches.dpdk.org/api/projects/1/?format=api", "name": "DPDK", "link_name": "dpdk", "list_id": "dev.dpdk.org", "list_email": "dev@dpdk.org", "web_url": "http://core.dpdk.org", "scm_url": "git://dpdk.org/dpdk", "webscm_url": "http://git.dpdk.org/dpdk", "list_archive_url": "https://inbox.dpdk.org/dev", "list_archive_url_format": "https://inbox.dpdk.org/dev/{}", "commit_url_format": "" }, "msgid": "<1639676975-1316-9-git-send-email-anoobj@marvell.com>", "list_archive_url": "https://inbox.dpdk.org/dev/1639676975-1316-9-git-send-email-anoobj@marvell.com", "date": "2021-12-16T17:49:14", "name": "[v2,08/29] crypto/cnxk: add lookaside IPsec AES-CBC-HMAC-SHA256 support", "commit_ref": null, "pull_url": null, "state": "superseded", "archived": true, "hash": "df89265b0494ee87a5ed3a7ed9d227b1d9877995", "submitter": { "id": 1205, "url": "http://patches.dpdk.org/api/people/1205/?format=api", "name": "Anoob Joseph", "email": "anoobj@marvell.com" }, "delegate": null, "mbox": "http://patches.dpdk.org/project/dpdk/patch/1639676975-1316-9-git-send-email-anoobj@marvell.com/mbox/", "series": [ { "id": 20957, "url": "http://patches.dpdk.org/api/series/20957/?format=api", "web_url": "http://patches.dpdk.org/project/dpdk/list/?series=20957", "date": "2021-12-16T17:49:06", "name": "New features and improvements in cnxk crypto PMD", "version": 2, "mbox": "http://patches.dpdk.org/series/20957/mbox/" } ], "comments": "http://patches.dpdk.org/api/patches/105173/comments/", "check": "success", "checks": "http://patches.dpdk.org/api/patches/105173/checks/", "tags": {}, "related": [], "headers": { "Return-Path": "<dev-bounces@dpdk.org>", "X-Original-To": "patchwork@inbox.dpdk.org", "Delivered-To": "patchwork@inbox.dpdk.org", "Received": [ "from mails.dpdk.org (mails.dpdk.org [217.70.189.124])\n\tby inbox.dpdk.org (Postfix) with ESMTP id 4372FA0032;\n\tThu, 16 Dec 2021 18:53:13 +0100 (CET)", "from [217.70.189.124] (localhost [127.0.0.1])\n\tby mails.dpdk.org (Postfix) with ESMTP id 224BF40685;\n\tThu, 16 Dec 2021 18:53:13 +0100 (CET)", "from mx0b-0016f401.pphosted.com (mx0a-0016f401.pphosted.com\n [67.231.148.174])\n by mails.dpdk.org (Postfix) with ESMTP id 05BBB4014F\n for <dev@dpdk.org>; Thu, 16 Dec 2021 18:53:10 +0100 (CET)", "from pps.filterd (m0045849.ppops.net [127.0.0.1])\n by mx0a-0016f401.pphosted.com (8.16.1.2/8.16.1.2) with ESMTP id\n 1BGBdfP3030228\n for <dev@dpdk.org>; Thu, 16 Dec 2021 09:53:10 -0800", "from dc5-exch01.marvell.com ([199.233.59.181])\n by mx0a-0016f401.pphosted.com (PPS) with ESMTPS id 3d04s71p0u-1\n (version=TLSv1.2 cipher=ECDHE-RSA-AES256-SHA384 bits=256 verify=NOT)\n for <dev@dpdk.org>; Thu, 16 Dec 2021 09:53:10 -0800", "from DC5-EXCH02.marvell.com (10.69.176.39) by DC5-EXCH01.marvell.com\n (10.69.176.38) with Microsoft SMTP Server (TLS) id 15.0.1497.2;\n Thu, 16 Dec 2021 09:53:08 -0800", "from maili.marvell.com (10.69.176.80) by DC5-EXCH02.marvell.com\n (10.69.176.39) with Microsoft SMTP Server id 15.0.1497.18 via Frontend\n Transport; Thu, 16 Dec 2021 09:53:08 -0800", "from HY-LT1002.marvell.com (HY-LT1002.marvell.com [10.28.176.218])\n by maili.marvell.com (Postfix) with ESMTP id 8CC463F7048;\n Thu, 16 Dec 2021 09:53:06 -0800 (PST)" ], "DKIM-Signature": "v=1; a=rsa-sha256; c=relaxed/relaxed; d=marvell.com;\n h=from : to : cc :\n subject : date : message-id : in-reply-to : references : mime-version :\n content-transfer-encoding : content-type; s=pfpt0220;\n bh=hFRU9uGReaCSleoUtV9VgPXn7pJOUCpkGQy9cqO/XyM=;\n b=GsMlrhfVkup/Jd/dYYlR4jdSexLXx2dQeVzylM25y6DT6Mo+tUbOVd55cMDYskJ1qZPD\n TnJqnX0F6YnEOEHheKHlkCtKAd/GDaXSP9iNnQnQjcIRBD7sgHmfv2FJYhWO1yP0Hnb4\n HoZW0nSoqxlwdnfz3NcggOHw7BFxwJfbLmMfmQsKuFfu7caE3SEgbt+KW7sT9J5mOPiO\n N5nwm3X9keFynjvlyQm1mRyLgDFYWDkbUQGufI+9SagEhddDtzWsffJj6taWhy59P+mH\n UasDazq6CxSkUnbPQ7HDH7TpONQqHfUEvKqpOMnq2mIbGNvHYbUpnrk3QsN73sAzNjUe UQ==", "From": "Anoob Joseph <anoobj@marvell.com>", "To": "Akhil Goyal <gakhil@marvell.com>, Jerin Jacob <jerinj@marvell.com>", "CC": "Tejasree Kondoj <ktejasree@marvell.com>, Archana Muniganti\n <marchana@marvell.com>, <dev@dpdk.org>", "Subject": "[PATCH v2 08/29] crypto/cnxk: add lookaside IPsec AES-CBC-HMAC-SHA256\n support", "Date": "Thu, 16 Dec 2021 23:19:14 +0530", "Message-ID": "<1639676975-1316-9-git-send-email-anoobj@marvell.com>", "X-Mailer": "git-send-email 2.7.4", "In-Reply-To": "<1639676975-1316-1-git-send-email-anoobj@marvell.com>", "References": "<1638859858-734-1-git-send-email-anoobj@marvell.com>\n <1639676975-1316-1-git-send-email-anoobj@marvell.com>", "MIME-Version": "1.0", "Content-Transfer-Encoding": "8bit", "Content-Type": "text/plain", "X-Proofpoint-GUID": "giJrLEI3Hnam-rhxnbxE4hbbCob-ZMzS", "X-Proofpoint-ORIG-GUID": "giJrLEI3Hnam-rhxnbxE4hbbCob-ZMzS", "X-Proofpoint-Virus-Version": "vendor=baseguard\n engine=ICAP:2.0.205,Aquarius:18.0.790,Hydra:6.0.425,FMLib:17.11.62.513\n definitions=2021-12-16_06,2021-12-16_01,2021-12-02_01", "X-BeenThere": "dev@dpdk.org", "X-Mailman-Version": "2.1.29", "Precedence": "list", "List-Id": "DPDK patches and discussions <dev.dpdk.org>", "List-Unsubscribe": "<https://mails.dpdk.org/options/dev>,\n <mailto:dev-request@dpdk.org?subject=unsubscribe>", "List-Archive": "<http://mails.dpdk.org/archives/dev/>", "List-Post": "<mailto:dev@dpdk.org>", "List-Help": "<mailto:dev-request@dpdk.org?subject=help>", "List-Subscribe": "<https://mails.dpdk.org/listinfo/dev>,\n <mailto:dev-request@dpdk.org?subject=subscribe>", "Errors-To": "dev-bounces@dpdk.org" }, "content": "From: Tejasree Kondoj <ktejasree@marvell.com>\n\nAdding AES-CBC-HMAC-SHA256 support to lookaside IPsec PMD.\n\nSigned-off-by: Tejasree Kondoj <ktejasree@marvell.com>\n---\n doc/guides/cryptodevs/cnxk.rst | 39 +++++++++++++++++++----\n doc/guides/rel_notes/release_22_03.rst | 4 +++\n drivers/common/cnxk/cnxk_security.c | 14 ++++++++\n drivers/crypto/cnxk/cn10k_ipsec.c | 3 ++\n drivers/crypto/cnxk/cnxk_cryptodev_capabilities.c | 20 ++++++++++++\n drivers/crypto/cnxk/cnxk_ipsec.h | 3 +-\n 6 files changed, 75 insertions(+), 8 deletions(-)", "diff": "diff --git a/doc/guides/cryptodevs/cnxk.rst b/doc/guides/cryptodevs/cnxk.rst\nindex 23cc823..8c4c4ea 100644\n--- a/doc/guides/cryptodevs/cnxk.rst\n+++ b/doc/guides/cryptodevs/cnxk.rst\n@@ -246,14 +246,27 @@ CN9XX Features supported\n * IPv4\n * IPv6\n * ESP\n+* ESN\n+* Anti-replay\n * Tunnel mode\n * Transport mode(IPv4)\n * UDP Encapsulation\n+\n+AEAD algorithms\n++++++++++++++++\n+\n * AES-128/192/256-GCM\n-* AES-128/192/256-CBC-SHA1-HMAC\n-* AES-128/192/256-CBC-SHA256-128-HMAC\n-* ESN\n-* Anti-replay\n+\n+Cipher algorithms\n++++++++++++++++++\n+\n+* AES-128/192/256-CBC\n+\n+Auth algorithms\n++++++++++++++++\n+\n+* SHA1-HMAC\n+* SHA256-128-HMAC\n \n CN10XX Features supported\n ~~~~~~~~~~~~~~~~~~~~~~~~~\n@@ -263,6 +276,20 @@ CN10XX Features supported\n * Tunnel mode\n * Transport mode\n * UDP Encapsulation\n+\n+AEAD algorithms\n++++++++++++++++\n+\n * AES-128/192/256-GCM\n-* AES-128/192/256-CBC-NULL\n-* AES-128/192/256-CBC-SHA1-HMAC\n+\n+Cipher algorithms\n++++++++++++++++++\n+\n+* AES-128/192/256-CBC\n+\n+Auth algorithms\n++++++++++++++++\n+\n+* NULL\n+* SHA1-HMAC\n+* SHA256-128-HMAC\ndiff --git a/doc/guides/rel_notes/release_22_03.rst b/doc/guides/rel_notes/release_22_03.rst\nindex 6d99d1e..1639b0e 100644\n--- a/doc/guides/rel_notes/release_22_03.rst\n+++ b/doc/guides/rel_notes/release_22_03.rst\n@@ -55,6 +55,10 @@ New Features\n Also, make sure to start the actual text at the margin.\n =======================================================\n \n+* **Updated Marvell cnxk crypto PMD.**\n+\n+ * Added SHA256-HMAC support in lookaside protocol (IPsec) for CN10K.\n+\n \n Removed Items\n -------------\ndiff --git a/drivers/common/cnxk/cnxk_security.c b/drivers/common/cnxk/cnxk_security.c\nindex 787138b..f39bc1e 100644\n--- a/drivers/common/cnxk/cnxk_security.c\n+++ b/drivers/common/cnxk/cnxk_security.c\n@@ -32,6 +32,10 @@ ipsec_hmac_opad_ipad_gen(struct rte_crypto_sym_xform *auth_xform,\n \t\troc_hash_sha1_gen(opad, (uint32_t *)&hmac_opad_ipad[0]);\n \t\troc_hash_sha1_gen(ipad, (uint32_t *)&hmac_opad_ipad[24]);\n \t\tbreak;\n+\tcase RTE_CRYPTO_AUTH_SHA256_HMAC:\n+\t\troc_hash_sha256_gen(opad, (uint32_t *)&hmac_opad_ipad[0]);\n+\t\troc_hash_sha256_gen(ipad, (uint32_t *)&hmac_opad_ipad[64]);\n+\t\tbreak;\n \tdefault:\n \t\tbreak;\n \t}\n@@ -129,6 +133,16 @@ ot_ipsec_sa_common_param_fill(union roc_ot_ipsec_sa_word2 *w2,\n \t\t\t i++)\n \t\t\t\ttmp_key[i] = rte_be_to_cpu_64(tmp_key[i]);\n \t\t\tbreak;\n+\t\tcase RTE_CRYPTO_AUTH_SHA256_HMAC:\n+\t\t\tw2->s.auth_type = ROC_IE_OT_SA_AUTH_SHA2_256;\n+\t\t\tipsec_hmac_opad_ipad_gen(auth_xfrm, hmac_opad_ipad);\n+\n+\t\t\ttmp_key = (uint64_t *)hmac_opad_ipad;\n+\t\t\tfor (i = 0; i < (int)(ROC_CTX_MAX_OPAD_IPAD_LEN /\n+\t\t\t\t\t sizeof(uint64_t));\n+\t\t\t i++)\n+\t\t\t\ttmp_key[i] = rte_be_to_cpu_64(tmp_key[i]);\n+\t\t\tbreak;\n \t\tdefault:\n \t\t\treturn -ENOTSUP;\n \t\t}\ndiff --git a/drivers/crypto/cnxk/cn10k_ipsec.c b/drivers/crypto/cnxk/cn10k_ipsec.c\nindex 27df1dc..93eab1b 100644\n--- a/drivers/crypto/cnxk/cn10k_ipsec.c\n+++ b/drivers/crypto/cnxk/cn10k_ipsec.c\n@@ -65,6 +65,9 @@ cn10k_ipsec_outb_sa_create(struct roc_cpt *roc_cpt,\n \t\tif (crypto_xfrm->type == RTE_CRYPTO_SYM_XFORM_AEAD) {\n \t\t\tsa->iv_offset = crypto_xfrm->aead.iv.offset;\n \t\t\tsa->iv_length = crypto_xfrm->aead.iv.length;\n+\t\t} else {\n+\t\t\tsa->iv_offset = crypto_xfrm->cipher.iv.offset;\n+\t\t\tsa->iv_length = crypto_xfrm->cipher.iv.length;\n \t\t}\n \t}\n #else\ndiff --git a/drivers/crypto/cnxk/cnxk_cryptodev_capabilities.c b/drivers/crypto/cnxk/cnxk_cryptodev_capabilities.c\nindex 59b63ed..7d22626 100644\n--- a/drivers/crypto/cnxk/cnxk_cryptodev_capabilities.c\n+++ b/drivers/crypto/cnxk/cnxk_cryptodev_capabilities.c\n@@ -797,6 +797,26 @@ static const struct rte_cryptodev_capabilities sec_caps_sha1_sha2[] = {\n \t\t\t}, }\n \t\t}, }\n \t},\n+\t{\t/* SHA256 HMAC */\n+\t\t.op = RTE_CRYPTO_OP_TYPE_SYMMETRIC,\n+\t\t{.sym = {\n+\t\t\t.xform_type = RTE_CRYPTO_SYM_XFORM_AUTH,\n+\t\t\t{.auth = {\n+\t\t\t\t.algo = RTE_CRYPTO_AUTH_SHA256_HMAC,\n+\t\t\t\t.block_size = 64,\n+\t\t\t\t.key_size = {\n+\t\t\t\t\t.min = 1,\n+\t\t\t\t\t.max = 1024,\n+\t\t\t\t\t.increment = 1\n+\t\t\t\t},\n+\t\t\t\t.digest_size = {\n+\t\t\t\t\t.min = 16,\n+\t\t\t\t\t.max = 16,\n+\t\t\t\t\t.increment = 0\n+\t\t\t\t},\n+\t\t\t}, }\n+\t\t}, }\n+\t},\n };\n \n static const struct rte_security_capability sec_caps_templ[] = {\ndiff --git a/drivers/crypto/cnxk/cnxk_ipsec.h b/drivers/crypto/cnxk/cnxk_ipsec.h\nindex dddb414..f4a1012 100644\n--- a/drivers/crypto/cnxk/cnxk_ipsec.h\n+++ b/drivers/crypto/cnxk/cnxk_ipsec.h\n@@ -46,8 +46,7 @@ ipsec_xform_auth_verify(struct rte_crypto_sym_xform *crypto_xform)\n \tif (crypto_xform->auth.algo == RTE_CRYPTO_AUTH_SHA1_HMAC) {\n \t\tif (keylen >= 20 && keylen <= 64)\n \t\t\treturn 0;\n-\t} else if (roc_model_is_cn9k() &&\n-\t\t (crypto_xform->auth.algo == RTE_CRYPTO_AUTH_SHA256_HMAC)) {\n+\t} else if (crypto_xform->auth.algo == RTE_CRYPTO_AUTH_SHA256_HMAC) {\n \t\tif (keylen >= 32 && keylen <= 64)\n \t\t\treturn 0;\n \t}\n", "prefixes": [ "v2", "08/29" ] }{ "id": 105173, "url": "