+* security: ``rte_security_set_pkt_metadata`` and ``rte_security_get_userdata``
+ routines used by inline outbound and inline inbound security processing were
+ made inline and enhanced to do simple 64-bit set/get for PMDs that do not
+ have much processing in PMD specific callbacks but just 64-bit set/get.
+ This avoids a per packet function pointer jump overhead for such PMDs.
+
+* security: A new option ``iv_gen_disable`` was added in structure
+ ``rte_security_ipsec_sa_options`` to disable IV generation inside PMD,
+ so that application can provide its own IV and test known test vectors.
+
+* security: A new option ``tunnel_hdr_verify`` was added in structure
+ ``rte_security_ipsec_sa_options`` to indicate whether outer header
+ verification need to be done as part of inbound IPsec processing.
+
+* security: A new option ``udp_ports_verify`` was added in structure
+ ``rte_security_ipsec_sa_options`` to indicate whether UDP ports
+ verification need to be done as part of inbound IPsec processing.
+
+* security: A new structure ``rte_security_ipsec_lifetime`` was added to
+ replace ``esn_soft_limit`` in IPsec configuration structure
+ ``rte_security_ipsec_xform`` to allow applications to configure SA soft
+ and hard expiry limits. Limits can be either in number of packets or bytes.
+
+* bbdev: Added capability related to more comprehensive CRC options,
+ shifting values of the ``enum rte_bbdev_op_ldpcdec_flag_bitmasks``.
+