1 /* SPDX-License-Identifier: BSD-3-Clause
2 * Copyright(c) 2010-2017 Intel Corporation
8 #include <rte_security.h>
10 #define IPSRXIDX_RX_EN 0x00000001
11 #define IPSRXIDX_TABLE_IP 0x00000002
12 #define IPSRXIDX_TABLE_SPI 0x00000004
13 #define IPSRXIDX_TABLE_KEY 0x00000006
14 #define IPSRXIDX_WRITE 0x80000000
15 #define IPSRXIDX_READ 0x40000000
16 #define IPSRXMOD_VALID 0x00000001
17 #define IPSRXMOD_PROTO 0x00000004
18 #define IPSRXMOD_DECRYPT 0x00000008
19 #define IPSRXMOD_IPV6 0x00000010
20 #define IXGBE_ADVTXD_POPTS_IPSEC 0x00000400
21 #define IXGBE_ADVTXD_TUCMD_IPSEC_TYPE_ESP 0x00002000
22 #define IXGBE_ADVTXD_TUCMD_IPSEC_ENCRYPT_EN 0x00004000
23 #define IXGBE_RXDADV_IPSEC_STATUS_SECP 0x00020000
24 #define IXGBE_RXDADV_IPSEC_ERROR_BIT_MASK 0x18000000
25 #define IXGBE_RXDADV_IPSEC_ERROR_INVALID_PROTOCOL 0x08000000
26 #define IXGBE_RXDADV_IPSEC_ERROR_INVALID_LENGTH 0x10000000
27 #define IXGBE_RXDADV_IPSEC_ERROR_AUTHENTICATION_FAILED 0x18000000
29 #define IPSEC_MAX_RX_IP_COUNT 128
30 #define IPSEC_MAX_SA_COUNT 1024
32 #define ESP_ICV_SIZE 16
33 #define ESP_TRAILER_SIZE 2
35 enum ixgbe_operation {
36 IXGBE_OP_AUTHENTICATED_ENCRYPTION,
37 IXGBE_OP_AUTHENTICATED_DECRYPTION
46 * Generic IP address structure
47 * TODO: Find better location for this rte_net.h possibly.
54 /**< IP Address Type - IPv4/IPv6 */
62 /** inline crypto crypto private session structure */
63 struct ixgbe_crypto_session {
64 enum ixgbe_operation op;
72 struct rte_eth_dev *dev;
73 } __rte_cache_aligned;
75 struct ixgbe_crypto_rx_ip_table {
79 struct ixgbe_crypto_rx_sa_table {
86 struct ixgbe_crypto_tx_sa_table {
91 union ixgbe_crypto_tx_desc_md {
94 /**< SA table index */
96 /**< ICV and ESP trailer length */
98 /**< enable encryption */
104 struct ixgbe_crypto_rx_ip_table rx_ip_tbl[IPSEC_MAX_RX_IP_COUNT];
105 struct ixgbe_crypto_rx_sa_table rx_sa_tbl[IPSEC_MAX_SA_COUNT];
106 struct ixgbe_crypto_tx_sa_table tx_sa_tbl[IPSEC_MAX_SA_COUNT];
110 int ixgbe_ipsec_ctx_create(struct rte_eth_dev *dev);
111 int ixgbe_crypto_enable_ipsec(struct rte_eth_dev *dev);
112 int ixgbe_crypto_add_ingress_sa_from_flow(const void *sess,
118 #endif /*IXGBE_IPSEC_H_*/