]> git.ipfire.org Git - thirdparty/iproute2.git/commitdiff
devlink: Support setting port function ipsec_crypto cap
authorDima Chumak <dchumak@nvidia.com>
Mon, 2 Oct 2023 10:43:48 +0000 (13:43 +0300)
committerDavid Ahern <dsahern@kernel.org>
Wed, 4 Oct 2023 15:23:03 +0000 (09:23 -0600)
Support port function commands to enable / disable IPsec crypto
offloads, this is used to control the port IPsec device capabilities.

When IPsec crypto capability is disabled for a function of the port
(default), function cannot offload IPsec operation. When enabled, IPsec
operation can be offloaded by the function of the port.

Enabling IPsec crypto offloads lets the kernel to delegate XFRM state
processing and encrypt/decrypt operation to the device hardware.

Example of a PCI VF port which supports IPsec crypto offloads:

$ devlink port show pci/0000:06:00.0/1
    pci/0000:06:00.0/1: type eth netdev enp6s0pf0vf0 flavour pcivf pfnum 0 vfnum 0
function:
hw_addr 00:00:00:00:00:00 roce enable ipsec_crypto disable

$ devlink port function set pci/0000:06:00.0/1 ipsec_crypto enable

$ devlink port show pci/0000:06:00.0/1
    pci/0000:06:00.0/1: type eth netdev enp6s0pf0vf0 flavour pcivf pfnum 0 vfnum 0
function:
hw_addr 00:00:00:00:00:00 roce enable ipsec_crypto enable

Signed-off-by: Dima Chumak <dchumak@nvidia.com>
Reviewed-by: Jiri Pirko <jiri@nvidia.com>
Signed-off-by: Tariq Toukan <tariqt@nvidia.com>
Signed-off-by: David Ahern <dsahern@kernel.org>
devlink/devlink.c
man/man8/devlink-port.8

index d1795f616ca06cc5034bcbb028381fc781341bc1..7852a47fc98a92ba6c107abbeb7ce4e412b29256 100644 (file)
@@ -2271,6 +2271,18 @@ static int dl_argv_parse(struct dl *dl, uint64_t o_required,
                        if (mig)
                                opts->port_fn_caps.value |= DEVLINK_PORT_FN_CAP_MIGRATABLE;
                        o_found |= DL_OPT_PORT_FN_CAPS;
+               } else if (dl_argv_match(dl, "ipsec_crypto") &&
+                          (o_all & DL_OPT_PORT_FN_CAPS)) {
+                       bool ipsec_crypto;
+
+                       dl_arg_inc(dl);
+                       err = dl_argv_bool(dl, &ipsec_crypto);
+                       if (err)
+                               return err;
+                       opts->port_fn_caps.selector |= DEVLINK_PORT_FN_CAP_IPSEC_CRYPTO;
+                       if (ipsec_crypto)
+                               opts->port_fn_caps.value |= DEVLINK_PORT_FN_CAP_IPSEC_CRYPTO;
+                       o_found |= DL_OPT_PORT_FN_CAPS;
                } else {
                        pr_err("Unknown option \"%s\"\n", dl_argv(dl));
                        return -EINVAL;
@@ -4644,6 +4656,7 @@ static void cmd_port_help(void)
        pr_err("       devlink port unsplit DEV/PORT_INDEX\n");
        pr_err("       devlink port function set DEV/PORT_INDEX [ hw_addr ADDR ] [ state { active | inactive } ]\n");
        pr_err("                      [ roce { enable | disable } ] [ migratable { enable | disable } ]\n");
+       pr_err("                      [ ipsec_crypto { enable | disable } ]\n");
        pr_err("       devlink port function rate { help | show | add | del | set }\n");
        pr_err("       devlink port param set DEV/PORT_INDEX name PARAMETER value VALUE cmode { permanent | driverinit | runtime }\n");
        pr_err("       devlink port param show [DEV/PORT_INDEX name PARAMETER]\n");
@@ -4769,6 +4782,10 @@ static void pr_out_port_function(struct dl *dl, struct nlattr **tb_port)
                        print_string(PRINT_ANY, "migratable", " migratable %s",
                                     port_fn_caps->value & DEVLINK_PORT_FN_CAP_MIGRATABLE ?
                                     "enable" : "disable");
+               if (port_fn_caps->selector & DEVLINK_PORT_FN_CAP_IPSEC_CRYPTO)
+                       print_string(PRINT_ANY, "ipsec_crypto", " ipsec_crypto %s",
+                                    port_fn_caps->value & DEVLINK_PORT_FN_CAP_IPSEC_CRYPTO ?
+                                    "enable" : "disable");
        }
 
        if (!dl->json_output)
@@ -4960,6 +4977,7 @@ static void cmd_port_function_help(void)
 {
        pr_err("Usage: devlink port function set DEV/PORT_INDEX [ hw_addr ADDR ] [ state { active | inactive } ]\n");
        pr_err("                      [ roce { enable | disable } ] [ migratable { enable | disable } ]\n");
+       pr_err("                      [ ipsec_crypto { enable | disable } ]\n");
        pr_err("       devlink port function rate { help | show | add | del | set }\n");
 }
 
index 56049f7349a88890f291c7d2e5f88f3c805a59ef..534d2cbe8fa9398c8553ac7bb0212792f246fe8b 100644 (file)
@@ -77,6 +77,9 @@ devlink-port \- devlink port configuration
 .RI "[ "
 .BR migratable " { " enable " | " disable " }"
 .RI "]"
+.RI "[ "
+.BR ipsec_crypto " { " enable " | " disable " }"
+.RI "]"
 
 .ti -8
 .BR "devlink port function rate "
@@ -222,6 +225,11 @@ Set the RoCE capability of the function.
 .BR migratable " { " enable " | " disable  " } "
 Set the migratable capability of the function.
 
+.TP
+.BR ipsec_crypto " { " enable " | " disable  " } "
+Set the IPsec crypto offload capability of the function. Controls XFRM state
+crypto operation (Encrypt/Decrypt) offload.
+
 .ti -8
 .SS devlink port del - delete a devlink port
 .PP
@@ -351,6 +359,11 @@ devlink port function set pci/0000:01:00.0/1 migratable enable
 This will enable the migratable functionality of the function.
 .RE
 .PP
+devlink port function set pci/0000:01:00.0/1 ipsec_crypto enable
+.RS 4
+This will enable the IPsec crypto offload functionality of the function.
+.RE
+.PP
 devlink port function set pci/0000:01:00.0/1 hw_addr 00:00:00:11:22:33 state active
 .RS 4
 Configure hardware address and also active the function. When a function is