Hi Anatoly,
one comment inline
On 10/9/2026 11:59 AM, Anatoly Burakov wrote:
Use the new flow graph API and common flow engine infrastructure to
implement flow parser for security filter. As a result, flow item checks
have become more stringent:
- Mask is now explicitly validated to not have unsupported items in it,
when previously they were ignored
- Mask is also validated to mask src/dst addresses, as otherwise it is
inconsistent with rte_flow API
- The security engine was only looking for IPv4/IPv6 pattern items and
completely ignored both prefix and suffix. This logic has been replaced
by allowing [ETH]/IP/[UDP|ESP] patterns, as is used in ipsec-gw app
Previously, security parser was a special case, now it is a first class
citizen. All decryption SA tracking has been moved into the engine, as the
engine is now the authoritative source of new Rx flows and the state of
the Rx SA table (the Tx SA table is still up to IPsec code to manage).
Because IPsec code does not manage the Rx SA table now, a synchronization
mechanism is needed to prevent IPsec code from deallocating a security
session when it is still referenced by security flows, so the security
session is now atomically refcounted. For Tx, the refcount is effectively
a noop, whereas for Rx it is now managed by rte_flow security engine.
Signed-off-by: Anatoly Burakov <[email protected]>
---
<snip>
static inline void
ixgbe_crypto_write_rx_ip(struct ixgbe_hw *hw, uint32_t idx,
const struct ipaddr *ip, bool enable)
@@ -137,195 +131,165 @@ ixgbe_crypto_clear_ipsec_tables(struct rte_eth_dev *dev)
ixgbe_crypto_write_tx_key(hw, i, key, 0, false);
}
- memset(priv->rx_ip_tbl, 0, sizeof(priv->rx_ip_tbl));
- memset(priv->rx_sa_tbl, 0, sizeof(priv->rx_sa_tbl));
- memset(priv->tx_sa_tbl, 0, sizeof(priv->tx_sa_tbl));
+ *priv->tx_sa_tbl = (struct ixgbe_crypto_tx_sa_table){0};
tx_sa_tbl is an array of 1024 elements. Do we really need to cleanup
only the first one?
+}
+
<snip>
--
Regards,
Vladimir