crypto/dpaax_sec: support HFN override
authorAkhil Goyal <akhil.goyal@nxp.com>
Mon, 30 Sep 2019 14:40:44 +0000 (20:10 +0530)
committerAkhil Goyal <akhil.goyal@nxp.com>
Wed, 9 Oct 2019 09:50:12 +0000 (11:50 +0200)
Per packet HFN override is supported in NXP PMDs
(dpaa2_sec and dpaa_sec). DPOVRD register can be
updated with the per packet value if it is enabled
in session configuration. The value is read from
the IV offset.

Signed-off-by: Akhil Goyal <akhil.goyal@nxp.com>
drivers/crypto/dpaa2_sec/dpaa2_sec_dpseci.c
drivers/crypto/dpaa2_sec/dpaa2_sec_priv.h
drivers/crypto/dpaa_sec/dpaa_sec.c
drivers/crypto/dpaa_sec/dpaa_sec.h

index 75a4fe0..7946abf 100644 (file)
@@ -125,14 +125,16 @@ build_proto_compound_fd(dpaa2_sec_session *sess,
        DPAA2_SET_FD_LEN(fd, ip_fle->length);
        DPAA2_SET_FLE_FIN(ip_fle);
 
-#ifdef ENABLE_HFN_OVERRIDE
+       /* In case of PDCP, per packet HFN is stored in
+        * mbuf priv after sym_op.
+        */
        if (sess->ctxt_type == DPAA2_SEC_PDCP && sess->pdcp.hfn_ovd) {
+               uint32_t hfn_ovd = *((uint8_t *)op + sess->pdcp.hfn_ovd_offset);
                /*enable HFN override override */
-               DPAA2_SET_FLE_INTERNAL_JD(ip_fle, sess->pdcp.hfn_ovd);
-               DPAA2_SET_FLE_INTERNAL_JD(op_fle, sess->pdcp.hfn_ovd);
-               DPAA2_SET_FD_INTERNAL_JD(fd, sess->pdcp.hfn_ovd);
+               DPAA2_SET_FLE_INTERNAL_JD(ip_fle, hfn_ovd);
+               DPAA2_SET_FLE_INTERNAL_JD(op_fle, hfn_ovd);
+               DPAA2_SET_FD_INTERNAL_JD(fd, hfn_ovd);
        }
-#endif
 
        return 0;
 
@@ -2664,11 +2666,11 @@ dpaa2_sec_set_pdcp_session(struct rte_cryptodev *dev,
        session->pdcp.bearer = pdcp_xform->bearer;
        session->pdcp.pkt_dir = pdcp_xform->pkt_dir;
        session->pdcp.sn_size = pdcp_xform->sn_size;
-#ifdef ENABLE_HFN_OVERRIDE
-       session->pdcp.hfn_ovd = pdcp_xform->hfn_ovd;
-#endif
        session->pdcp.hfn = pdcp_xform->hfn;
        session->pdcp.hfn_threshold = pdcp_xform->hfn_threshold;
+       session->pdcp.hfn_ovd = pdcp_xform->hfn_ovrd;
+       /* hfv ovd offset location is stored in iv.offset value*/
+       session->pdcp.hfn_ovd_offset = cipher_xform->iv.offset;
 
        cipherdata.key = (size_t)session->cipher_key.data;
        cipherdata.keylen = session->cipher_key.length;
index a05deae..afd98b2 100644 (file)
@@ -147,9 +147,12 @@ struct dpaa2_pdcp_ctxt {
        int8_t bearer;  /*!< PDCP bearer ID */
        int8_t pkt_dir;/*!< PDCP Frame Direction 0:UL 1:DL*/
        int8_t hfn_ovd;/*!< Overwrite HFN per packet*/
+       uint8_t sn_size;        /*!< Sequence number size, 5/7/12/15/18 */
+       uint32_t hfn_ovd_offset;/*!< offset from rte_crypto_op at which
+                                * per packet hfn is stored
+                                */
        uint32_t hfn;   /*!< Hyper Frame Number */
        uint32_t hfn_threshold; /*!< HFN Threashold for key renegotiation */
-       uint8_t sn_size;        /*!< Sequence number size, 7/12/15 */
 };
 
 typedef struct dpaa2_sec_session_entry {
index 059d440..24ec7a3 100644 (file)
@@ -1754,6 +1754,20 @@ dpaa_sec_enqueue_burst(void *qp, struct rte_crypto_op **ops,
                        if (auth_only_len)
                                fd->cmd = 0x80000000 | auth_only_len;
 
+                       /* In case of PDCP, per packet HFN is stored in
+                        * mbuf priv after sym_op.
+                        */
+                       if (is_proto_pdcp(ses) && ses->pdcp.hfn_ovd) {
+                               fd->cmd = 0x80000000 |
+                                       *((uint32_t *)((uint8_t *)op +
+                                       ses->pdcp.hfn_ovd_offset));
+                               DPAA_SEC_DP_DEBUG("Per packet HFN: %x, ovd:%u,%u\n",
+                                       *((uint32_t *)((uint8_t *)op +
+                                       ses->pdcp.hfn_ovd_offset)),
+                                       ses->pdcp.hfn_ovd,
+                                       is_proto_pdcp(ses));
+                       }
+
                }
 send_pkts:
                loop = 0;
@@ -2411,11 +2425,10 @@ dpaa_sec_set_pdcp_session(struct rte_cryptodev *dev,
        session->pdcp.bearer = pdcp_xform->bearer;
        session->pdcp.pkt_dir = pdcp_xform->pkt_dir;
        session->pdcp.sn_size = pdcp_xform->sn_size;
-#ifdef ENABLE_HFN_OVERRIDE
-       session->pdcp.hfn_ovd = pdcp_xform->hfn_ovd;
-#endif
        session->pdcp.hfn = pdcp_xform->hfn;
        session->pdcp.hfn_threshold = pdcp_xform->hfn_threshold;
+       session->pdcp.hfn_ovd = pdcp_xform->hfn_ovrd;
+       session->pdcp.hfn_ovd_offset = cipher_xform->iv.offset;
 
        session->ctx_pool = dev_priv->ctx_pool;
        rte_spinlock_lock(&dev_priv->lock);
index 08e7d66..68461ce 100644 (file)
@@ -103,9 +103,12 @@ struct sec_pdcp_ctxt {
        int8_t bearer;  /*!< PDCP bearer ID */
        int8_t pkt_dir;/*!< PDCP Frame Direction 0:UL 1:DL*/
        int8_t hfn_ovd;/*!< Overwrite HFN per packet*/
+       uint8_t sn_size;        /*!< Sequence number size, 5/7/12/15/18 */
+       uint32_t hfn_ovd_offset;/*!< offset from rte_crypto_op at which
+                                * per packet hfn is stored
+                                */
        uint32_t hfn;   /*!< Hyper Frame Number */
        uint32_t hfn_threshold; /*!< HFN Threashold for key renegotiation */
-       uint8_t sn_size;        /*!< Sequence number size, 7/12/15 */
 };
 
 typedef struct dpaa_sec_session_entry {