Commit bcd1f8a4 authored by Steffen Klassert's avatar Steffen Klassert

xfrm: Prepare the GRO codepath for hardware offloading.

On IPsec hardware offloading, we already get a secpath with
valid state attached when the packet enters the GRO handlers.
So check for hardware offload and skip the state lookup in this
case.
Signed-off-by: default avatarSteffen Klassert <steffen.klassert@secunet.com>
parent f1bd7d65
...@@ -43,6 +43,8 @@ static struct sk_buff **esp4_gro_receive(struct sk_buff **head, ...@@ -43,6 +43,8 @@ static struct sk_buff **esp4_gro_receive(struct sk_buff **head,
if ((err = xfrm_parse_spi(skb, IPPROTO_ESP, &spi, &seq)) != 0) if ((err = xfrm_parse_spi(skb, IPPROTO_ESP, &spi, &seq)) != 0)
goto out; goto out;
xo = xfrm_offload(skb);
if (!xo || !(xo->flags & CRYPTO_DONE)) {
err = secpath_set(skb); err = secpath_set(skb);
if (err) if (err)
goto out; goto out;
...@@ -64,6 +66,8 @@ static struct sk_buff **esp4_gro_receive(struct sk_buff **head, ...@@ -64,6 +66,8 @@ static struct sk_buff **esp4_gro_receive(struct sk_buff **head,
xfrm_state_put(x); xfrm_state_put(x);
goto out; goto out;
} }
}
xo->flags |= XFRM_GRO; xo->flags |= XFRM_GRO;
XFRM_TUNNEL_SKB_CB(skb)->tunnel.ip4 = NULL; XFRM_TUNNEL_SKB_CB(skb)->tunnel.ip4 = NULL;
......
...@@ -45,6 +45,8 @@ static struct sk_buff **esp6_gro_receive(struct sk_buff **head, ...@@ -45,6 +45,8 @@ static struct sk_buff **esp6_gro_receive(struct sk_buff **head,
if ((err = xfrm_parse_spi(skb, IPPROTO_ESP, &spi, &seq)) != 0) if ((err = xfrm_parse_spi(skb, IPPROTO_ESP, &spi, &seq)) != 0)
goto out; goto out;
xo = xfrm_offload(skb);
if (!xo || !(xo->flags & CRYPTO_DONE)) {
err = secpath_set(skb); err = secpath_set(skb);
if (err) if (err)
goto out; goto out;
...@@ -66,6 +68,8 @@ static struct sk_buff **esp6_gro_receive(struct sk_buff **head, ...@@ -66,6 +68,8 @@ static struct sk_buff **esp6_gro_receive(struct sk_buff **head,
xfrm_state_put(x); xfrm_state_put(x);
goto out; goto out;
} }
}
xo->flags |= XFRM_GRO; xo->flags |= XFRM_GRO;
XFRM_TUNNEL_SKB_CB(skb)->tunnel.ip6 = NULL; XFRM_TUNNEL_SKB_CB(skb)->tunnel.ip6 = NULL;
......
...@@ -223,11 +223,10 @@ int xfrm_input(struct sk_buff *skb, int nexthdr, __be32 spi, int encap_type) ...@@ -223,11 +223,10 @@ int xfrm_input(struct sk_buff *skb, int nexthdr, __be32 spi, int encap_type)
seq = XFRM_SKB_CB(skb)->seq.input.low; seq = XFRM_SKB_CB(skb)->seq.input.low;
goto resume; goto resume;
} }
/* encap_type < -1 indicates a GRO call. */ /* encap_type < -1 indicates a GRO call. */
encap_type = 0; encap_type = 0;
seq = XFRM_SPI_SKB_CB(skb)->seq; seq = XFRM_SPI_SKB_CB(skb)->seq;
goto lock;
}
if (xo && (xo->flags & CRYPTO_DONE)) { if (xo && (xo->flags & CRYPTO_DONE)) {
crypto_done = true; crypto_done = true;
...@@ -256,6 +255,7 @@ int xfrm_input(struct sk_buff *skb, int nexthdr, __be32 spi, int encap_type) ...@@ -256,6 +255,7 @@ int xfrm_input(struct sk_buff *skb, int nexthdr, __be32 spi, int encap_type)
XFRM_INC_STATS(net, LINUX_MIB_XFRMINHDRERROR); XFRM_INC_STATS(net, LINUX_MIB_XFRMINHDRERROR);
goto drop; goto drop;
} }
}
goto lock; goto lock;
} }
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment