get:
Show a patch.

patch:
Update a patch.

put:
Update a patch.

GET /api/patches/131908/?format=api
HTTP 200 OK
Allow: GET, PUT, PATCH, HEAD, OPTIONS
Content-Type: application/json
Vary: Accept

{
    "id": 131908,
    "url": "http://patches.dpdk.org/api/patches/131908/?format=api",
    "web_url": "http://patches.dpdk.org/project/dpdk/patch/20230926024959.207098-10-chaoyong.he@corigine.com/",
    "project": {
        "id": 1,
        "url": "http://patches.dpdk.org/api/projects/1/?format=api",
        "name": "DPDK",
        "link_name": "dpdk",
        "list_id": "dev.dpdk.org",
        "list_email": "dev@dpdk.org",
        "web_url": "http://core.dpdk.org",
        "scm_url": "git://dpdk.org/dpdk",
        "webscm_url": "http://git.dpdk.org/dpdk",
        "list_archive_url": "https://inbox.dpdk.org/dev",
        "list_archive_url_format": "https://inbox.dpdk.org/dev/{}",
        "commit_url_format": ""
    },
    "msgid": "<20230926024959.207098-10-chaoyong.he@corigine.com>",
    "list_archive_url": "https://inbox.dpdk.org/dev/20230926024959.207098-10-chaoyong.he@corigine.com",
    "date": "2023-09-26T02:49:58",
    "name": "[v2,09/10] net/nfp: support IPsec Rx and Tx offload",
    "commit_ref": null,
    "pull_url": null,
    "state": "superseded",
    "archived": true,
    "hash": "fd30b28e70b0764e54388e227e68d995636f0e1f",
    "submitter": {
        "id": 2554,
        "url": "http://patches.dpdk.org/api/people/2554/?format=api",
        "name": "Chaoyong He",
        "email": "chaoyong.he@corigine.com"
    },
    "delegate": {
        "id": 319,
        "url": "http://patches.dpdk.org/api/users/319/?format=api",
        "username": "fyigit",
        "first_name": "Ferruh",
        "last_name": "Yigit",
        "email": "ferruh.yigit@amd.com"
    },
    "mbox": "http://patches.dpdk.org/project/dpdk/patch/20230926024959.207098-10-chaoyong.he@corigine.com/mbox/",
    "series": [
        {
            "id": 29622,
            "url": "http://patches.dpdk.org/api/series/29622/?format=api",
            "web_url": "http://patches.dpdk.org/project/dpdk/list/?series=29622",
            "date": "2023-09-26T02:49:49",
            "name": "add the support of ipsec offload",
            "version": 2,
            "mbox": "http://patches.dpdk.org/series/29622/mbox/"
        }
    ],
    "comments": "http://patches.dpdk.org/api/patches/131908/comments/",
    "check": "success",
    "checks": "http://patches.dpdk.org/api/patches/131908/checks/",
    "tags": {},
    "related": [],
    "headers": {
        "Return-Path": "<dev-bounces@dpdk.org>",
        "X-Original-To": "patchwork@inbox.dpdk.org",
        "Delivered-To": "patchwork@inbox.dpdk.org",
        "Received": [
            "from mails.dpdk.org (mails.dpdk.org [217.70.189.124])\n\tby inbox.dpdk.org (Postfix) with ESMTP id E66134263C;\n\tTue, 26 Sep 2023 04:51:43 +0200 (CEST)",
            "from mails.dpdk.org (localhost [127.0.0.1])\n\tby mails.dpdk.org (Postfix) with ESMTP id 7FD8040A73;\n\tTue, 26 Sep 2023 04:50:50 +0200 (CEST)",
            "from NAM10-DM6-obe.outbound.protection.outlook.com\n (mail-dm6nam10on2097.outbound.protection.outlook.com [40.107.93.97])\n by mails.dpdk.org (Postfix) with ESMTP id 088FB406B8\n for <dev@dpdk.org>; Tue, 26 Sep 2023 04:50:49 +0200 (CEST)",
            "from PH0PR13MB5568.namprd13.prod.outlook.com (2603:10b6:510:12b::16)\n by SA3PR13MB6516.namprd13.prod.outlook.com (2603:10b6:806:39c::8)\n with Microsoft SMTP Server (version=TLS1_2,\n cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.6792.27; Tue, 26 Sep\n 2023 02:50:47 +0000",
            "from PH0PR13MB5568.namprd13.prod.outlook.com\n ([fe80::b070:92e1:931e:fee7]) by PH0PR13MB5568.namprd13.prod.outlook.com\n ([fe80::b070:92e1:931e:fee7%4]) with mapi id 15.20.6792.026; Tue, 26 Sep 2023\n 02:50:47 +0000"
        ],
        "ARC-Seal": "i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none;\n b=OWHLV1dHt/6FCTRR0XdfFfHkZyTNPMw7Jq0H6FMG2iherhKZ+HOeOiGn3C3usKI3w8Hf19hnNiYR7bFv2IORvqd3jQ/tJQPqxY3/J6Wferl65KN8ImLPZZQCTY2aGH12N2Lh3M1EZaS+7XWfcRNNLDti1Fx8lo4k/M0t5xBTCzBgXin61r7POnvOp1FL5v3lR9InXsyNtSP/nevJ44DmRjwqomjbVyX2vF8FhR0yyvnO9+nd56bvIU50XFjmEQqlsEL/kzhNXBh1DI4wwzBasAtkDmdgUsP/rDA1oh4HZSah7lxfXV1lYgQf4eAZ4QeDQ6SY5DPtxdufeAyOx3sI1Q==",
        "ARC-Message-Signature": "i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com;\n s=arcselector9901;\n h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1;\n bh=EYRQ9UDYnLsk8jRllKp9kQgg7WUQrpmRy1ztZD/Kplg=;\n b=QaYUSuliiSBdan56SEHrNjXxVVMdEozHODRqL8+UsAmlylLxXUsn4HRoarZqcdDeJhIsTpNlfEPvRJXBKW7WItk5mW/0/2MpaYfDLqzrsQTMibrh/iproV8tAnaIss3nt1eE2MHHOxK/TitN3AIzRtaYskvqzokW74N3olGkng1+2QzMiLQv8iwB14724KbgU4HluKKoX4t1qXIjs6AYwxnL06IR/a4H54KWp9VyL1qTSuEvne/oSx3HXTvQkYTBFG8Nvd1UGv+VqB0T7QUQpNUr7oGYJxf/M+5gsJmz5hI7bfmUUat+g46IvSf3LCc2EzNbrny/Mxq0IhZ62K6QNw==",
        "ARC-Authentication-Results": "i=1; mx.microsoft.com 1; spf=pass\n smtp.mailfrom=corigine.com; dmarc=pass action=none header.from=corigine.com;\n dkim=pass header.d=corigine.com; arc=none",
        "DKIM-Signature": "v=1; a=rsa-sha256; c=relaxed/relaxed;\n d=corigine.onmicrosoft.com; s=selector2-corigine-onmicrosoft-com;\n h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck;\n bh=EYRQ9UDYnLsk8jRllKp9kQgg7WUQrpmRy1ztZD/Kplg=;\n b=lXX6L0/A/bUHaVABdolNPKqmoHUcXW070uQYC4JmEAAkSBlMC3iLAcdVhmITGLb75y+q8fdMY3F5RnZXapHjbYi4GLNwfCiKdh8OicMUOIcmgmW0CCjfK/tpvNXwBw4H0Qu3idYXf2NfVn3IQu5f01Po3J4lV0rRkTHO1lJhhyU=",
        "Authentication-Results": "dkim=none (message not signed)\n header.d=none;dmarc=none action=none header.from=corigine.com;",
        "From": "Chaoyong He <chaoyong.he@corigine.com>",
        "To": "dev@dpdk.org",
        "Cc": "oss-drivers@corigine.com, Shihong Wang <shihong.wang@corigine.com>,\n Chang Miao <chang.miao@corigine.com>,\n Chaoyong He <chaoyong.he@corigine.com>",
        "Subject": "[PATCH v2 09/10] net/nfp: support IPsec Rx and Tx offload",
        "Date": "Tue, 26 Sep 2023 10:49:58 +0800",
        "Message-Id": "<20230926024959.207098-10-chaoyong.he@corigine.com>",
        "X-Mailer": "git-send-email 2.39.1",
        "In-Reply-To": "<20230926024959.207098-1-chaoyong.he@corigine.com>",
        "References": "<20230925060644.1458598-1-chaoyong.he@corigine.com>\n <20230926024959.207098-1-chaoyong.he@corigine.com>",
        "Content-Transfer-Encoding": "8bit",
        "Content-Type": "text/plain",
        "X-ClientProxiedBy": "BYAPR05CA0020.namprd05.prod.outlook.com\n (2603:10b6:a03:c0::33) To PH0PR13MB5568.namprd13.prod.outlook.com\n (2603:10b6:510:12b::16)",
        "MIME-Version": "1.0",
        "X-MS-PublicTrafficType": "Email",
        "X-MS-TrafficTypeDiagnostic": "PH0PR13MB5568:EE_|SA3PR13MB6516:EE_",
        "X-MS-Office365-Filtering-Correlation-Id": "f4c1183a-3fc1-47b0-b25f-08dbbe3b629b",
        "X-MS-Exchange-SenderADCheck": "1",
        "X-MS-Exchange-AntiSpam-Relay": "0",
        "X-Microsoft-Antispam": "BCL:0;",
        "X-Microsoft-Antispam-Message-Info": "\n yUH6/FQFL/fxQUbgeFdPDBcvS3XQxA+CTwml7nIh+Wa1ntZEovlTfrcl37798qKcrfc/pXWUB8KVW1Hpe3GNgQIWvhOmxi4T4zgteNEKkkap3T7y2z2qmni3BXF7NuCuCqNTKYiToHWNCYxl6ytmmgpA/TijIt3WX+n5wqwP8hBa88/hqxaMhkbpFOQHY3ewMwvpcVDpw7dC11mZpabV1iTw8rzHyMFDENhtpz5y1yI9bG5S4j7J7ylknpcH7u2bfiSFIEgEXAHPoAkmOXcNt8jrVLMh/IDZoIUbgsJzZXJJPg06rumOVrfeboJDgm/Zpdsf3E/rXnPO82FPrwpfDRkv77jf9G22Vla3rM5/1hEhHdzJNHOMt82IotLxg+NuwMkUK6Jl3hOu7CqYx2/yNuH4Z/emrUB77kwQolX24LVY+Oa4+L9iMTBmOoQWZvy9oKzXJcJyy+VFmN7fi9CNGEpS9Ne92MRRW/qcH1W98Fv08cIefxuWmbgPaX8QzHREA+AceqA0z7PGQi4c8c3doDyE1hdAL+H/QoRcR2vk7BeByiRHfMrBZFXY1sBRWxYCNnH3n/uK6af5fAOww0O6t/o6QPnE/tWTG1Q4VuqHF7mMuFfwX9O47W9GLWtguK/elymktfyCyKxQC8a/z6Yt2dRCsodOGZacNwoWMZSaAco=",
        "X-Forefront-Antispam-Report": "CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:;\n IPV:NLI; SFV:NSPM; H:PH0PR13MB5568.namprd13.prod.outlook.com; PTR:; CAT:NONE;\n SFS:(13230031)(39830400003)(136003)(366004)(346002)(396003)(376002)(230922051799003)(1800799009)(451199024)(186009)(4326008)(83380400001)(2616005)(6486002)(6506007)(52116002)(478600001)(6666004)(86362001)(36756003)(38100700002)(1076003)(30864003)(26005)(66476007)(8936002)(66556008)(6916009)(6512007)(2906002)(38350700002)(66946007)(41300700001)(107886003)(316002)(44832011)(8676002)(5660300002)(54906003);\n DIR:OUT; SFP:1102;",
        "X-MS-Exchange-AntiSpam-MessageData-ChunkCount": "1",
        "X-MS-Exchange-AntiSpam-MessageData-0": "\n 9xPu9GWCT1DlDlc3SXkEWpfzz6T9HPbn6SBCqns9oQtissreXLX6b8bAqsfO7NCfVg+yT7q422/5+NMpG/orXjHaXhg0Fr2sgvTCaTx6yB9Q9dTTescpAHxNGlSqd2OXauBUNi6nrSAzAAGcEeoaA0Bjr8JNa7T9jIV8RgOSG54y6RBj9e5TifRhChfe4uvLVyTQ43BPrzlX2SvOJTjljTewn+kyK5ux+D2Ukqg7wxR3EZ0ELUK0ONrC0TZE2KEoHfAyqU2a24McAd77cPNIE5+yd1scznpqlG5d80JaXGIWuOBAeaiATMCN2YlLlBG5P3LAqIWVgeGykKme2oWRZ6rFH34FQBv6rSCmbUCirQtzlfVP4Jsabb/RC4bCU9Gm7cRGJu06BDFd0Gmd0ZJrkLOHlVg+L7odFb46kggAgkI+A0cgNax8vO4bzy9mn1SfOEFfQ7fg3JJhRyDHkmxyh5EawYleDdFZVzmDkN9LaAP+ksb2ii+inPdHexVQnsky81la2Rj/7OGz2V4cwhHnrC5u6DMSrrecM/kxTSCrhSexvEXttMCE+wUvC7uL6zHaoPjLsxjbMK8fxAwN3REFpe+gw5yBhThp6nBm5vDgGMbCpGiPqNTgFH+Tukb+Ojfk8VCAj3brooNkGlo54Ql7QgPS6CnhFsSaeMWxcDkpg05RAKHZrWoAz18hqzVWOqLtx80UAY+duWdSRSMO9bhAP33dP8oDL0VzHyX663It8lhB9k1YcR4AVpY7wI206SmuUAHU8DbUNkeDR47N/nKiD4onaN5+sEt2Ctkqb0WG6JcIVSB36S2tLJtCWivbhAUAb9aPNfKQC+eaoSGVh3N6saeRnUybyFudduLkZE+ycI6WXTk+81jcTRuSM3rhR6cGjmv6nq5G38VpVcLjsmhqM4PK+E9qCtpY8lCZ+rqHyuOv0qHIk3BJZFqPc9xxipkNA8dAIxDHA0TfTJb5AOGQ5IhRhke1WdIGReG21afIk7yp4ugt4VrbQAQ3HYakJmz57MKTq3Tl9WkAd6S7z0vC8MQs2TgaVz4+2oB7sBZnCDLPS0R6h9iOntdOXO1sW/DO6zpDrHabt0UNodSevvwgo689qlOYurgHQ06F+YnxnR2qmnHiOUw+ntvGaqcEk0HeJimV/vOjp1xbbjga6AweptZnOVi+/jx6CwkzVJpe7UgtdTO2TE2aTc8c1Qew7BZCpKnz7g6j4dhZJTsd8djdhG6kWo5N1UvVyAP5Wb5K/VzW0aYIEtUsluwkshSPgtGgmM/igN1yGeq2WUGjwOSmuP8Fm2PPqpt8SpYgwcONo8rrLshrO7gxeKN3oPOR9HsvOmX31OFlzTA88wHU+Z/ASDDjCSj9nW8fa0SIczDNjn+jZceQ5BXItXiSFFzN/GjARfAHeBubnQ81KXqasipMaJjfIg55VVapKyFHY6MvQOiqNdPGRMNhNIDqOYDOPzAcH+YLjSF5UtDxkmL9ARRvsxkBproFDzi9/901Jnsa5vTye/Au+GlFKi2DXJd09EgUswyz7FLqgIaJB39wi0fybES3GovyCi+2Jtg5+U/MkPyulOnGpnkY+oXkOv5te39Y2RcXpDwcE/b9WNpoaCDUvA==",
        "X-OriginatorOrg": "corigine.com",
        "X-MS-Exchange-CrossTenant-Network-Message-Id": "\n f4c1183a-3fc1-47b0-b25f-08dbbe3b629b",
        "X-MS-Exchange-CrossTenant-AuthSource": "PH0PR13MB5568.namprd13.prod.outlook.com",
        "X-MS-Exchange-CrossTenant-AuthAs": "Internal",
        "X-MS-Exchange-CrossTenant-OriginalArrivalTime": "26 Sep 2023 02:50:47.2778 (UTC)",
        "X-MS-Exchange-CrossTenant-FromEntityHeader": "Hosted",
        "X-MS-Exchange-CrossTenant-Id": "fe128f2c-073b-4c20-818e-7246a585940c",
        "X-MS-Exchange-CrossTenant-MailboxType": "HOSTED",
        "X-MS-Exchange-CrossTenant-UserPrincipalName": "\n dEyksXrZJZIRtfE+HkoItiknQrgl/EW7fxO5z1JcjdZ81oyu3IykroF/t6UvK12OIf2BrlyoZ6zhHMhaxJLNZzo4BW2V4Cqafp2MsxI3wy8=",
        "X-MS-Exchange-Transport-CrossTenantHeadersStamped": "SA3PR13MB6516",
        "X-BeenThere": "dev@dpdk.org",
        "X-Mailman-Version": "2.1.29",
        "Precedence": "list",
        "List-Id": "DPDK patches and discussions <dev.dpdk.org>",
        "List-Unsubscribe": "<https://mails.dpdk.org/options/dev>,\n <mailto:dev-request@dpdk.org?subject=unsubscribe>",
        "List-Archive": "<http://mails.dpdk.org/archives/dev/>",
        "List-Post": "<mailto:dev@dpdk.org>",
        "List-Help": "<mailto:dev-request@dpdk.org?subject=help>",
        "List-Subscribe": "<https://mails.dpdk.org/listinfo/dev>,\n <mailto:dev-request@dpdk.org?subject=subscribe>",
        "Errors-To": "dev-bounces@dpdk.org"
    },
    "content": "From: Shihong Wang <shihong.wang@corigine.com>\n\nThe Rx path checks the ipsec metadata and base on the\ncrypto status sets ol_flags in the rte_mbuf.\n\nThe Tx path write IPsec message to mbuf metadata based\non mbuf dynamic field.\n\nSigned-off-by: Shihong Wang <shihong.wang@corigine.com>\nSigned-off-by: Chang Miao <chang.miao@corigine.com>\nReviewed-by: Chaoyong He <chaoyong.he@corigine.com>\n---\n doc/guides/nics/nfp.rst            | 31 +++++++++++++\n drivers/net/nfp/nfd3/nfp_nfd3_dp.c | 24 ++++++++++\n drivers/net/nfp/nfdk/nfp_nfdk_dp.c | 24 ++++++++++\n drivers/net/nfp/nfp_ctrl.h         |  1 +\n drivers/net/nfp/nfp_ipsec.c        | 42 +++++++++++++++++\n drivers/net/nfp/nfp_ipsec.h        |  6 +++\n drivers/net/nfp/nfp_rxtx.c         | 74 ++++++++++++++++++++++++++++++\n drivers/net/nfp/nfp_rxtx.h         |  5 ++\n 8 files changed, 207 insertions(+)",
    "diff": "diff --git a/doc/guides/nics/nfp.rst b/doc/guides/nics/nfp.rst\nindex 456a22dcbc..fee1860f4a 100644\n--- a/doc/guides/nics/nfp.rst\n+++ b/doc/guides/nics/nfp.rst\n@@ -348,6 +348,18 @@ Metadata with L2 (1W/4B)\n    The vlan[0] is the innermost VLAN\n    The vlan[1] is the QinQ info\n \n+NFP_NET_META_IPSEC\n+The IPsec type requires 4 bit.\n+The SA index value is 32 bit which need 1 data field.\n+::\n+\n+   ----------------------------------------------------------------\n+      3                   2                   1                   0\n+    1 0 9 8 7 6 5 4 3 2 1 0 9 8 7 6 5 4 3 2 1 0 9 8 7 6 5 4 3 2 1 0\n+   +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+\n+   |                           sa_idx                              |\n+   +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+\n+\n TX\n ~~\n \n@@ -363,3 +375,22 @@ NFP_NET_META_VLAN\n                                    ^                               ^\n                              NOTE: |             TCI               |\n                                    +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+\n+\n+NFP_NET_META_IPSEC\n+The IPsec type requires 12 bit, because it requires three data fields.\n+::\n+\n+   ----------------------------------------------------------------\n+      3                   2                   1                   0\n+    1 0 9 8 7 6 5 4 3 2 1 0 9 8 7 6 5 4 3 2 1 0 9 8 7 6 5 4 3 2 1 0\n+   +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+\n+   |                            sa_idx                             |\n+   +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+\n+   |                     nfp_ipsec_force_seq_low                   |\n+   +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+\n+   |                     nfp_ipsec_force_seq_hi                    |\n+   +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+\n+\n+   The sa_idx is 32 bit which need 1 data field.\n+   The nfp_ipsec_force_seq_low & nfp_ipsec_force_seq_hi is Anti-re-anti-count,\n+   which is 64 bit need two data fields.\ndiff --git a/drivers/net/nfp/nfd3/nfp_nfd3_dp.c b/drivers/net/nfp/nfd3/nfp_nfd3_dp.c\nindex ab0747fc16..64928254d8 100644\n--- a/drivers/net/nfp/nfd3/nfp_nfd3_dp.c\n+++ b/drivers/net/nfp/nfd3/nfp_nfd3_dp.c\n@@ -147,10 +147,13 @@ nfp_net_nfd3_set_meta_data(struct nfp_net_meta_raw *meta_data,\n \tchar *meta;\n \tuint8_t layer = 0;\n \tuint32_t meta_info;\n+\tuint32_t cap_extend;\n \tstruct nfp_net_hw *hw;\n \tuint8_t vlan_layer = 0;\n+\tuint8_t ipsec_layer = 0;\n \n \thw = txq->hw;\n+\tcap_extend = nn_cfg_readl(hw, NFP_NET_CFG_CAP_WORD1);\n \n \tif ((pkt->ol_flags & RTE_MBUF_F_TX_VLAN) != 0 &&\n \t\t\t(hw->ctrl & NFP_NET_CFG_CTRL_TXVLAN_V2) != 0) {\n@@ -160,6 +163,18 @@ nfp_net_nfd3_set_meta_data(struct nfp_net_meta_raw *meta_data,\n \t\tmeta_data->header |= NFP_NET_META_VLAN;\n \t}\n \n+\tif ((pkt->ol_flags & RTE_MBUF_F_TX_SEC_OFFLOAD) != 0 &&\n+\t\t\t(cap_extend & NFP_NET_CFG_CTRL_IPSEC) != 0) {\n+\t\tuint32_t ipsec_type = NFP_NET_META_IPSEC |\n+\t\t\t\tNFP_NET_META_IPSEC << NFP_NET_META_FIELD_SIZE |\n+\t\t\t\tNFP_NET_META_IPSEC << (2 * NFP_NET_META_FIELD_SIZE);\n+\t\tif (meta_data->length == 0)\n+\t\t\tmeta_data->length = NFP_NET_META_FIELD_SIZE;\n+\t\tuint8_t ipsec_offset = meta_data->length - NFP_NET_META_FIELD_SIZE;\n+\t\tmeta_data->header |= (ipsec_type << ipsec_offset);\n+\t\tmeta_data->length += 3 * NFP_NET_META_FIELD_SIZE;\n+\t}\n+\n \tif (meta_data->length == 0)\n \t\treturn;\n \n@@ -180,6 +195,15 @@ nfp_net_nfd3_set_meta_data(struct nfp_net_meta_raw *meta_data,\n \t\t\tnfp_net_set_meta_vlan(meta_data, pkt, layer);\n \t\t\tvlan_layer++;\n \t\t\tbreak;\n+\t\tcase NFP_NET_META_IPSEC:\n+\t\t\tif (ipsec_layer > 2) {\n+\t\t\t\tPMD_DRV_LOG(ERR, \"At most 3 layers of ipsec is supported for now.\");\n+\t\t\t\treturn;\n+\t\t\t}\n+\n+\t\t\tnfp_net_set_meta_ipsec(meta_data, txq, pkt, layer, ipsec_layer);\n+\t\t\tipsec_layer++;\n+\t\t\tbreak;\n \t\tdefault:\n \t\t\tPMD_DRV_LOG(ERR, \"The metadata type not supported\");\n \t\t\treturn;\ndiff --git a/drivers/net/nfp/nfdk/nfp_nfdk_dp.c b/drivers/net/nfp/nfdk/nfp_nfdk_dp.c\nindex a85734f121..d4bd5edb0a 100644\n--- a/drivers/net/nfp/nfdk/nfp_nfdk_dp.c\n+++ b/drivers/net/nfp/nfdk/nfp_nfdk_dp.c\n@@ -177,13 +177,16 @@ nfp_net_nfdk_set_meta_data(struct rte_mbuf *pkt,\n \tchar *meta;\n \tuint8_t layer = 0;\n \tuint32_t meta_type;\n+\tuint32_t cap_extend;\n \tstruct nfp_net_hw *hw;\n \tuint32_t header_offset;\n \tuint8_t vlan_layer = 0;\n+\tuint8_t ipsec_layer = 0;\n \tstruct nfp_net_meta_raw meta_data;\n \n \tmemset(&meta_data, 0, sizeof(meta_data));\n \thw = txq->hw;\n+\tcap_extend = nn_cfg_readl(hw, NFP_NET_CFG_CAP_WORD1);\n \n \tif ((pkt->ol_flags & RTE_MBUF_F_TX_VLAN) != 0 &&\n \t\t\t(hw->ctrl & NFP_NET_CFG_CTRL_TXVLAN_V2) != 0) {\n@@ -193,6 +196,18 @@ nfp_net_nfdk_set_meta_data(struct rte_mbuf *pkt,\n \t\tmeta_data.header |= NFP_NET_META_VLAN;\n \t}\n \n+\tif ((pkt->ol_flags & RTE_MBUF_F_TX_SEC_OFFLOAD) != 0 &&\n+\t\t\t(cap_extend & NFP_NET_CFG_CTRL_IPSEC) != 0) {\n+\t\tuint32_t ipsec_type = NFP_NET_META_IPSEC |\n+\t\t\t\tNFP_NET_META_IPSEC << NFP_NET_META_FIELD_SIZE |\n+\t\t\t\tNFP_NET_META_IPSEC << (2 * NFP_NET_META_FIELD_SIZE);\n+\t\tif (meta_data.length == 0)\n+\t\t\tmeta_data.length = NFP_NET_META_FIELD_SIZE;\n+\t\tuint8_t ipsec_offset = meta_data.length - NFP_NET_META_FIELD_SIZE;\n+\t\tmeta_data.header |= (ipsec_type << ipsec_offset);\n+\t\tmeta_data.length += 3 * NFP_NET_META_FIELD_SIZE;\n+\t}\n+\n \tif (meta_data.length == 0)\n \t\treturn;\n \n@@ -215,6 +230,15 @@ nfp_net_nfdk_set_meta_data(struct rte_mbuf *pkt,\n \t\t\tnfp_net_set_meta_vlan(&meta_data, pkt, layer);\n \t\t\tvlan_layer++;\n \t\t\tbreak;\n+\t\tcase NFP_NET_META_IPSEC:\n+\t\t\tif (ipsec_layer > 2) {\n+\t\t\t\tPMD_DRV_LOG(ERR, \"At most 3 layers of ipsec is supported for now.\");\n+\t\t\t\treturn;\n+\t\t\t}\n+\n+\t\t\tnfp_net_set_meta_ipsec(&meta_data, txq, pkt, layer, ipsec_layer);\n+\t\t\tipsec_layer++;\n+\t\t\tbreak;\n \t\tdefault:\n \t\t\tPMD_DRV_LOG(ERR, \"The metadata type not supported\");\n \t\t\treturn;\ndiff --git a/drivers/net/nfp/nfp_ctrl.h b/drivers/net/nfp/nfp_ctrl.h\nindex 361739a4b9..3488df6ba8 100644\n--- a/drivers/net/nfp/nfp_ctrl.h\n+++ b/drivers/net/nfp/nfp_ctrl.h\n@@ -39,6 +39,7 @@\n #define NFP_NET_META_HASH               1 /* next field carries hash type */\n #define NFP_NET_META_VLAN               4\n #define NFP_NET_META_PORTID             5\n+#define NFP_NET_META_IPSEC              9\n \n #define NFP_META_PORT_ID_CTRL           ~0U\n \ndiff --git a/drivers/net/nfp/nfp_ipsec.c b/drivers/net/nfp/nfp_ipsec.c\nindex 0022532027..8626c6323d 100644\n--- a/drivers/net/nfp/nfp_ipsec.c\n+++ b/drivers/net/nfp/nfp_ipsec.c\n@@ -1153,6 +1153,47 @@ nfp_crypto_update_session(void *device __rte_unused,\n \treturn 0;\n }\n \n+static int\n+nfp_security_set_pkt_metadata(void *device,\n+\t\tstruct rte_security_session *session,\n+\t\tstruct rte_mbuf *m,\n+\t\tvoid *params)\n+{\n+\tint offset;\n+\tuint64_t *sqn;\n+\tstruct nfp_net_hw *hw;\n+\tstruct rte_eth_dev *eth_dev;\n+\tstruct nfp_ipsec_session *priv_session;\n+\n+\tsqn = params;\n+\teth_dev = device;\n+\tpriv_session = SECURITY_GET_SESS_PRIV(session);\n+\thw = NFP_NET_DEV_PRIVATE_TO_HW(eth_dev->data->dev_private);\n+\n+\tif (priv_session->ipsec.direction == RTE_SECURITY_IPSEC_SA_DIR_EGRESS) {\n+\t\tstruct nfp_tx_ipsec_desc_msg *desc_md;\n+\n+\t\toffset = hw->ipsec_data->pkt_dynfield_offset;\n+\t\tdesc_md = RTE_MBUF_DYNFIELD(m, offset, struct nfp_tx_ipsec_desc_msg *);\n+\n+\t\tif (priv_session->msg.ctrl_word.ext_seq != 0 && sqn != NULL) {\n+\t\t\tdesc_md->esn.low = rte_cpu_to_be_32(*sqn);\n+\t\t\tdesc_md->esn.hi = rte_cpu_to_be_32(*sqn >> 32);\n+\t\t} else if (priv_session->msg.ctrl_word.ext_seq != 0) {\n+\t\t\tdesc_md->esn.low = rte_cpu_to_be_32(priv_session->ipsec.esn.low);\n+\t\t\tdesc_md->esn.hi = rte_cpu_to_be_32(priv_session->ipsec.esn.hi);\n+\t\t} else {\n+\t\t\tdesc_md->esn.low = rte_cpu_to_be_32(priv_session->ipsec.esn.value);\n+\t\t\tdesc_md->esn.hi = 0;\n+\t\t}\n+\n+\t\tdesc_md->enc = 1;\n+\t\tdesc_md->sa_idx = rte_cpu_to_be_32(priv_session->sa_index);\n+\t}\n+\n+\treturn 0;\n+}\n+\n /**\n  * Get discards packet statistics for each SA\n  *\n@@ -1247,6 +1288,7 @@ static const struct rte_security_ops nfp_security_ops = {\n \t.session_update = nfp_crypto_update_session,\n \t.session_get_size = nfp_security_session_get_size,\n \t.session_stats_get = nfp_security_session_get_stats,\n+\t.set_pkt_metadata = nfp_security_set_pkt_metadata,\n \t.capabilities_get = nfp_crypto_capabilities_get,\n };\n \ndiff --git a/drivers/net/nfp/nfp_ipsec.h b/drivers/net/nfp/nfp_ipsec.h\nindex 531bc60c5a..cacb05f13e 100644\n--- a/drivers/net/nfp/nfp_ipsec.h\n+++ b/drivers/net/nfp/nfp_ipsec.h\n@@ -163,6 +163,12 @@ struct nfp_net_ipsec_data {\n \tstruct nfp_ipsec_session *sa_entries[NFP_NET_IPSEC_MAX_SA_CNT];\n };\n \n+enum nfp_ipsec_meta_layer {\n+\tNFP_IPSEC_META_SAIDX,       /**< Order of SA index in metadata */\n+\tNFP_IPSEC_META_SEQLOW,      /**< Order of Sequence Number (low 32bits) in metadata */\n+\tNFP_IPSEC_META_SEQHI,       /**< Order of Sequence Number (high 32bits) in metadata */\n+};\n+\n int nfp_ipsec_init(struct rte_eth_dev *dev);\n void nfp_ipsec_uninit(struct rte_eth_dev *dev);\n \ndiff --git a/drivers/net/nfp/nfp_rxtx.c b/drivers/net/nfp/nfp_rxtx.c\nindex e74aba7439..66a5d6cb3a 100644\n--- a/drivers/net/nfp/nfp_rxtx.c\n+++ b/drivers/net/nfp/nfp_rxtx.c\n@@ -8,11 +8,13 @@\n #include \"nfp_rxtx.h\"\n \n #include <ethdev_pci.h>\n+#include <rte_security.h>\n \n #include \"nfd3/nfp_nfd3.h\"\n #include \"nfdk/nfp_nfdk.h\"\n #include \"flower/nfp_flower.h\"\n \n+#include \"nfp_ipsec.h\"\n #include \"nfp_logs.h\"\n \n /* Maximum number of supported VLANs in parsed form packet metadata. */\n@@ -25,8 +27,10 @@\n  * read-only after it have been recorded during parsing by nfp_net_parse_meta().\n  *\n  * @port_id: Port id value\n+ * @sa_idx: IPsec SA index\n  * @hash: RSS hash value\n  * @hash_type: RSS hash type\n+ * @ipsec_type: IPsec type\n  * @vlan_layer: The layers of VLAN info which are passed from nic.\n  *              Only this number of entries of the @vlan array are valid.\n  *\n@@ -44,8 +48,10 @@\n  */\n struct nfp_meta_parsed {\n \tuint32_t port_id;\n+\tuint32_t sa_idx;\n \tuint32_t hash;\n \tuint8_t hash_type;\n+\tuint8_t ipsec_type;\n \tuint8_t vlan_layer;\n \tstruct {\n \t\tuint8_t offload;\n@@ -304,6 +310,10 @@ nfp_net_parse_chained_meta(uint8_t *meta_base,\n \t\t\tmeta->vlan[meta->vlan_layer].tpid = NFP_NET_META_TPID(vlan_info);\n \t\t\t++meta->vlan_layer;\n \t\t\tbreak;\n+\t\tcase NFP_NET_META_IPSEC:\n+\t\t\tmeta->sa_idx = rte_be_to_cpu_32(*(rte_be32_t *)meta_offset);\n+\t\t\tmeta->ipsec_type = meta_info & NFP_NET_META_FIELD_MASK;\n+\t\t\tbreak;\n \t\tdefault:\n \t\t\t/* Unsupported metadata can be a performance issue */\n \t\t\treturn false;\n@@ -429,6 +439,39 @@ nfp_net_parse_meta_qinq(const struct nfp_meta_parsed *meta,\n \tmb->ol_flags |= RTE_MBUF_F_RX_QINQ | RTE_MBUF_F_RX_QINQ_STRIPPED;\n }\n \n+/*\n+ * Set mbuf IPsec Offload features based on metadata info.\n+ *\n+ * The IPsec Offload features is prepended to the mbuf ol_flags.\n+ * Extract and decode metadata info and set the mbuf ol_flags.\n+ */\n+static void\n+nfp_net_parse_meta_ipsec(struct nfp_meta_parsed *meta,\n+\t\tstruct nfp_net_rxq *rxq,\n+\t\tstruct rte_mbuf *mbuf)\n+{\n+\tint offset;\n+\tuint32_t sa_idx;\n+\tstruct nfp_net_hw *hw;\n+\tstruct nfp_tx_ipsec_desc_msg *desc_md;\n+\n+\thw = rxq->hw;\n+\tsa_idx = meta->sa_idx;\n+\n+\tif (meta->ipsec_type != NFP_NET_META_IPSEC)\n+\t\treturn;\n+\n+\tif (sa_idx >= NFP_NET_IPSEC_MAX_SA_CNT) {\n+\t\tmbuf->ol_flags |= RTE_MBUF_F_RX_SEC_OFFLOAD_FAILED;\n+\t} else {\n+\t\tmbuf->ol_flags |= RTE_MBUF_F_RX_SEC_OFFLOAD;\n+\t\toffset = hw->ipsec_data->pkt_dynfield_offset;\n+\t\tdesc_md = RTE_MBUF_DYNFIELD(mbuf, offset, struct nfp_tx_ipsec_desc_msg *);\n+\t\tdesc_md->sa_idx = sa_idx;\n+\t\tdesc_md->enc = 0;\n+\t}\n+}\n+\n /* nfp_net_parse_meta() - Parse the metadata from packet */\n static void\n nfp_net_parse_meta(struct nfp_net_rx_desc *rxds,\n@@ -453,6 +496,7 @@ nfp_net_parse_meta(struct nfp_net_rx_desc *rxds,\n \t\t\tnfp_net_parse_meta_hash(meta, rxq, mb);\n \t\t\tnfp_net_parse_meta_vlan(meta, rxds, rxq, mb);\n \t\t\tnfp_net_parse_meta_qinq(meta, rxq, mb);\n+\t\t\tnfp_net_parse_meta_ipsec(meta, rxq, mb);\n \t\t} else {\n \t\t\tPMD_RX_LOG(DEBUG, \"RX chained metadata format is wrong!\");\n \t\t}\n@@ -1035,6 +1079,36 @@ nfp_net_set_meta_vlan(struct nfp_net_meta_raw *meta_data,\n \tmeta_data->data[layer] = rte_cpu_to_be_32(tpid << 16 | vlan_tci);\n }\n \n+void\n+nfp_net_set_meta_ipsec(struct nfp_net_meta_raw *meta_data,\n+\t\tstruct nfp_net_txq *txq,\n+\t\tstruct rte_mbuf *pkt,\n+\t\tuint8_t layer,\n+\t\tuint8_t ipsec_layer)\n+{\n+\tint offset;\n+\tstruct nfp_net_hw *hw;\n+\tstruct nfp_tx_ipsec_desc_msg *desc_md;\n+\n+\thw = txq->hw;\n+\toffset = hw->ipsec_data->pkt_dynfield_offset;\n+\tdesc_md = RTE_MBUF_DYNFIELD(pkt, offset, struct nfp_tx_ipsec_desc_msg *);\n+\n+\tswitch (ipsec_layer) {\n+\tcase NFP_IPSEC_META_SAIDX:\n+\t\tmeta_data->data[layer] = desc_md->sa_idx;\n+\t\tbreak;\n+\tcase NFP_IPSEC_META_SEQLOW:\n+\t\tmeta_data->data[layer] = desc_md->esn.low;\n+\t\tbreak;\n+\tcase NFP_IPSEC_META_SEQHI:\n+\t\tmeta_data->data[layer] = desc_md->esn.hi;\n+\t\tbreak;\n+\tdefault:\n+\t\tbreak;\n+\t}\n+}\n+\n int\n nfp_net_tx_queue_setup(struct rte_eth_dev *dev,\n \t\tuint16_t queue_idx,\ndiff --git a/drivers/net/nfp/nfp_rxtx.h b/drivers/net/nfp/nfp_rxtx.h\nindex 4e8558074e..3c7138f7d6 100644\n--- a/drivers/net/nfp/nfp_rxtx.h\n+++ b/drivers/net/nfp/nfp_rxtx.h\n@@ -257,5 +257,10 @@ int nfp_net_tx_free_bufs(struct nfp_net_txq *txq);\n void nfp_net_set_meta_vlan(struct nfp_net_meta_raw *meta_data,\n \t\tstruct rte_mbuf *pkt,\n \t\tuint8_t layer);\n+void nfp_net_set_meta_ipsec(struct nfp_net_meta_raw *meta_data,\n+\t\tstruct nfp_net_txq *txq,\n+\t\tstruct rte_mbuf *pkt,\n+\t\tuint8_t layer,\n+\t\tuint8_t ipsec_layer);\n \n #endif /* _NFP_RXTX_H_ */\n",
    "prefixes": [
        "v2",
        "09/10"
    ]
}