Hi Paul, Thanks for your contributions! I am back from vacations and had a look. I put my comments in gerrit but let me restate my main concerns here: 1) I am not sure we want to keep it as a separate plugin in its current form: it already requires significant "iptfs-awareness" in the core, so it might just be better to acknowledge that it is part of our core IPsec stack (of course the bulk can still be kept nicely isolated in its own file(s)) 2) I think we need to think a bit more about the vnet buffer metadata and flags and how to minimize it. I know it is not easy, but it is a scarce resource
Let's see how we can tackle it. ben ________________________________________ From: [email protected] <[email protected]> on behalf of G. Paul Ziemba <[email protected]> Sent: Thursday, August 13, 2026 18:01 To: [email protected] Subject: [vpp-dev] Please review: ipsec RFC 9347 Not sure who is in the office in August - could someone please look at https://gerrit.fd.io/r/c/vpp/+/46461 This commit is the first of three IPTFS commits. It comprises the changes to vnet/ipsec to work with the IPTFS plugin: > 1. Changes to vnet/ipsec to support IPTFS, consisting of: > a. registration/callback mechanism by which a TFS plugin > can register its entry points > b. updates to the ipsec api to support TFS parameters > c. updates to SA addition and format to call into the TFS plugin > d. updates to esp encode/decode related to the additional > next-protocol value The remaining IPTFS commits are: > 2. A new iptfs plugin, which implements all of the timing, > encoding, and decoding for the RFC 9347 format. > 3. Unit tests that exercise the TFS-specific parts of the API > and the encoding/decoding path of TFS. Thanks! ~!paul
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#27136): https://lists.fd.io/g/vpp-dev/message/27136 Mute This Topic: https://lists.fd.io/mt/120736004/21656 Group Owner: [email protected] Unsubscribe: https://lists.fd.io/g/vpp-dev/leave/14379924/21656/631435203/xyzzy [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
