提交 f4979e26 编写于 作者: L Leon Romanovsky 提交者: Leon Romanovsky

net/mlx5e: Remove ESN callbacks if it is not supported

There is no need in implementation of .xdo_dev_state_advance_esn() and
setting work as it will never be called in packet offload mode.

Link: https://lore.kernel.org/r/2fc9fade32e31f03b100d6086a82ad36269349dc.1680162300.git.leonro@nvidia.comReviewed-by: NRaed Salem <raeds@nvidia.com>
Signed-off-by: NLeon Romanovsky <leonro@nvidia.com>
上级 3e1c957f
...@@ -56,11 +56,6 @@ static bool mlx5e_ipsec_update_esn_state(struct mlx5e_ipsec_sa_entry *sa_entry) ...@@ -56,11 +56,6 @@ static bool mlx5e_ipsec_update_esn_state(struct mlx5e_ipsec_sa_entry *sa_entry)
u32 seq_bottom = 0; u32 seq_bottom = 0;
u8 overlap; u8 overlap;
if (!(sa_entry->x->props.flags & XFRM_STATE_ESN)) {
sa_entry->esn_state.trigger = 0;
return false;
}
replay_esn = sa_entry->x->replay_esn; replay_esn = sa_entry->x->replay_esn;
if (replay_esn->seq >= replay_esn->replay_window) if (replay_esn->seq >= replay_esn->replay_window)
seq_bottom = replay_esn->seq - replay_esn->replay_window + 1; seq_bottom = replay_esn->seq - replay_esn->replay_window + 1;
...@@ -70,7 +65,6 @@ static bool mlx5e_ipsec_update_esn_state(struct mlx5e_ipsec_sa_entry *sa_entry) ...@@ -70,7 +65,6 @@ static bool mlx5e_ipsec_update_esn_state(struct mlx5e_ipsec_sa_entry *sa_entry)
sa_entry->esn_state.esn = xfrm_replay_seqhi(sa_entry->x, sa_entry->esn_state.esn = xfrm_replay_seqhi(sa_entry->x,
htonl(seq_bottom)); htonl(seq_bottom));
sa_entry->esn_state.trigger = 1;
if (unlikely(overlap && seq_bottom < MLX5E_IPSEC_ESN_SCOPE_MID)) { if (unlikely(overlap && seq_bottom < MLX5E_IPSEC_ESN_SCOPE_MID)) {
sa_entry->esn_state.overlap = 0; sa_entry->esn_state.overlap = 0;
return true; return true;
...@@ -229,7 +223,7 @@ void mlx5e_ipsec_build_accel_xfrm_attrs(struct mlx5e_ipsec_sa_entry *sa_entry, ...@@ -229,7 +223,7 @@ void mlx5e_ipsec_build_accel_xfrm_attrs(struct mlx5e_ipsec_sa_entry *sa_entry,
aes_gcm->icv_len = x->aead->alg_icv_len; aes_gcm->icv_len = x->aead->alg_icv_len;
/* esn */ /* esn */
if (sa_entry->esn_state.trigger) { if (x->props.flags & XFRM_STATE_ESN) {
attrs->esn_trigger = true; attrs->esn_trigger = true;
attrs->esn = sa_entry->esn_state.esn; attrs->esn = sa_entry->esn_state.esn;
attrs->esn_overlap = sa_entry->esn_state.overlap; attrs->esn_overlap = sa_entry->esn_state.overlap;
...@@ -394,6 +388,22 @@ static void _update_xfrm_state(struct work_struct *work) ...@@ -394,6 +388,22 @@ static void _update_xfrm_state(struct work_struct *work)
mlx5_accel_esp_modify_xfrm(sa_entry, &modify_work->attrs); mlx5_accel_esp_modify_xfrm(sa_entry, &modify_work->attrs);
} }
static void mlx5e_ipsec_set_esn_ops(struct mlx5e_ipsec_sa_entry *sa_entry)
{
struct xfrm_state *x = sa_entry->x;
if (x->xso.type != XFRM_DEV_OFFLOAD_CRYPTO ||
x->xso.dir != XFRM_DEV_OFFLOAD_OUT)
return;
if (x->props.flags & XFRM_STATE_ESN) {
sa_entry->set_iv_op = mlx5e_ipsec_set_iv_esn;
return;
}
sa_entry->set_iv_op = mlx5e_ipsec_set_iv;
}
static int mlx5e_xfrm_add_state(struct xfrm_state *x, static int mlx5e_xfrm_add_state(struct xfrm_state *x,
struct netlink_ext_ack *extack) struct netlink_ext_ack *extack)
{ {
...@@ -425,7 +435,8 @@ static int mlx5e_xfrm_add_state(struct xfrm_state *x, ...@@ -425,7 +435,8 @@ static int mlx5e_xfrm_add_state(struct xfrm_state *x,
goto err_xfrm; goto err_xfrm;
/* check esn */ /* check esn */
mlx5e_ipsec_update_esn_state(sa_entry); if (x->props.flags & XFRM_STATE_ESN)
mlx5e_ipsec_update_esn_state(sa_entry);
mlx5e_ipsec_build_accel_xfrm_attrs(sa_entry, &sa_entry->attrs); mlx5e_ipsec_build_accel_xfrm_attrs(sa_entry, &sa_entry->attrs);
/* create hw context */ /* create hw context */
...@@ -446,11 +457,17 @@ static int mlx5e_xfrm_add_state(struct xfrm_state *x, ...@@ -446,11 +457,17 @@ static int mlx5e_xfrm_add_state(struct xfrm_state *x,
if (err) if (err)
goto err_add_rule; goto err_add_rule;
if (x->xso.dir == XFRM_DEV_OFFLOAD_OUT) mlx5e_ipsec_set_esn_ops(sa_entry);
sa_entry->set_iv_op = (x->props.flags & XFRM_STATE_ESN) ?
mlx5e_ipsec_set_iv_esn : mlx5e_ipsec_set_iv;
INIT_WORK(&sa_entry->modify_work.work, _update_xfrm_state); switch (x->xso.type) {
case XFRM_DEV_OFFLOAD_CRYPTO:
if (x->props.flags & XFRM_STATE_ESN)
INIT_WORK(&sa_entry->modify_work.work,
_update_xfrm_state);
break;
default:
break;
}
out: out:
x->xso.offload_handle = (unsigned long)sa_entry; x->xso.offload_handle = (unsigned long)sa_entry;
return 0; return 0;
...@@ -485,7 +502,15 @@ static void mlx5e_xfrm_free_state(struct xfrm_state *x) ...@@ -485,7 +502,15 @@ static void mlx5e_xfrm_free_state(struct xfrm_state *x)
if (x->xso.flags & XFRM_DEV_OFFLOAD_FLAG_ACQ) if (x->xso.flags & XFRM_DEV_OFFLOAD_FLAG_ACQ)
goto sa_entry_free; goto sa_entry_free;
cancel_work_sync(&sa_entry->modify_work.work); switch (x->xso.type) {
case XFRM_DEV_OFFLOAD_CRYPTO:
if (x->props.flags & XFRM_STATE_ESN)
cancel_work_sync(&sa_entry->modify_work.work);
break;
default:
break;
}
mlx5e_accel_ipsec_fs_del_rule(sa_entry); mlx5e_accel_ipsec_fs_del_rule(sa_entry);
mlx5_ipsec_free_sa_ctx(sa_entry); mlx5_ipsec_free_sa_ctx(sa_entry);
sa_entry_free: sa_entry_free:
......
...@@ -160,7 +160,6 @@ struct mlx5e_ipsec { ...@@ -160,7 +160,6 @@ struct mlx5e_ipsec {
struct mlx5e_ipsec_esn_state { struct mlx5e_ipsec_esn_state {
u32 esn; u32 esn;
u8 trigger: 1;
u8 overlap: 1; u8 overlap: 1;
}; };
......
...@@ -225,9 +225,6 @@ static int mlx5_modify_ipsec_obj(struct mlx5e_ipsec_sa_entry *sa_entry, ...@@ -225,9 +225,6 @@ static int mlx5_modify_ipsec_obj(struct mlx5e_ipsec_sa_entry *sa_entry,
void *obj; void *obj;
int err; int err;
if (!attrs->esn_trigger)
return 0;
general_obj_types = MLX5_CAP_GEN_64(mdev, general_obj_types); general_obj_types = MLX5_CAP_GEN_64(mdev, general_obj_types);
if (!(general_obj_types & MLX5_HCA_CAP_GENERAL_OBJECT_TYPES_IPSEC)) if (!(general_obj_types & MLX5_HCA_CAP_GENERAL_OBJECT_TYPES_IPSEC))
return -EINVAL; return -EINVAL;
......
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册