]> git.droids-corp.org - dpdk.git/commitdiff
test/security: add combined mode inline IPsec cases
authorAkhil Goyal <gakhil@marvell.com>
Tue, 24 May 2022 07:22:12 +0000 (12:52 +0530)
committerAkhil Goyal <gakhil@marvell.com>
Wed, 1 Jun 2022 14:26:34 +0000 (16:26 +0200)
Added combined encap and decap test cases for various algorithm
combinations

Signed-off-by: Akhil Goyal <gakhil@marvell.com>
Acked-by: Fan Zhang <roy.fan.zhang@intel.com>
Acked-by: Anoob Joseph <anoobj@marvell.com>
app/test/test_security_inline_proto.c

index 4a95b25a0b0dc3658ed02b250c393e6db375ce13..a44a4f9b0493fc1af82c79574148c92863f2dd58 100644 (file)
@@ -665,6 +665,92 @@ out:
        return ret;
 }
 
+static int
+test_ipsec_inline_proto_all(const struct ipsec_test_flags *flags)
+{
+       struct ipsec_test_data td_outb;
+       struct ipsec_test_data td_inb;
+       unsigned int i, nb_pkts = 1, pass_cnt = 0, fail_cnt = 0;
+       int ret;
+
+       if (flags->iv_gen || flags->sa_expiry_pkts_soft ||
+                       flags->sa_expiry_pkts_hard)
+               nb_pkts = IPSEC_TEST_PACKETS_MAX;
+
+       for (i = 0; i < RTE_DIM(alg_list); i++) {
+               test_ipsec_td_prepare(alg_list[i].param1,
+                                     alg_list[i].param2,
+                                     flags, &td_outb, 1);
+
+               if (!td_outb.aead) {
+                       enum rte_crypto_cipher_algorithm cipher_alg;
+                       enum rte_crypto_auth_algorithm auth_alg;
+
+                       cipher_alg = td_outb.xform.chain.cipher.cipher.algo;
+                       auth_alg = td_outb.xform.chain.auth.auth.algo;
+
+                       if (td_outb.aes_gmac && cipher_alg != RTE_CRYPTO_CIPHER_NULL)
+                               continue;
+
+                       /* ICV is not applicable for NULL auth */
+                       if (flags->icv_corrupt &&
+                           auth_alg == RTE_CRYPTO_AUTH_NULL)
+                               continue;
+
+                       /* IV is not applicable for NULL cipher */
+                       if (flags->iv_gen &&
+                           cipher_alg == RTE_CRYPTO_CIPHER_NULL)
+                               continue;
+               }
+
+               if (flags->udp_encap)
+                       td_outb.ipsec_xform.options.udp_encap = 1;
+
+               ret = test_ipsec_inline_proto_process(&td_outb, &td_inb, nb_pkts,
+                                               false, flags);
+               if (ret == TEST_SKIPPED)
+                       continue;
+
+               if (ret == TEST_FAILED) {
+                       printf("\n TEST FAILED");
+                       test_ipsec_display_alg(alg_list[i].param1,
+                                              alg_list[i].param2);
+                       fail_cnt++;
+                       continue;
+               }
+
+               test_ipsec_td_update(&td_inb, &td_outb, 1, flags);
+
+               ret = test_ipsec_inline_proto_process(&td_inb, NULL, nb_pkts,
+                                               false, flags);
+               if (ret == TEST_SKIPPED)
+                       continue;
+
+               if (ret == TEST_FAILED) {
+                       printf("\n TEST FAILED");
+                       test_ipsec_display_alg(alg_list[i].param1,
+                                              alg_list[i].param2);
+                       fail_cnt++;
+                       continue;
+               }
+
+               if (flags->display_alg)
+                       test_ipsec_display_alg(alg_list[i].param1,
+                                              alg_list[i].param2);
+
+               pass_cnt++;
+       }
+
+       printf("Tests passed: %d, failed: %d", pass_cnt, fail_cnt);
+       if (fail_cnt > 0)
+               return TEST_FAILED;
+       if (pass_cnt > 0)
+               return TEST_SUCCESS;
+       else
+               return TEST_SKIPPED;
+}
+
+
 static int
 ut_setup_inline_ipsec(void)
 {
@@ -841,6 +927,17 @@ test_ipsec_inline_proto_known_vec_inb(const void *test_data)
        return test_ipsec_inline_proto_process(&td_inb, NULL, 1, false, &flags);
 }
 
+static int
+test_ipsec_inline_proto_display_list(const void *data __rte_unused)
+{
+       struct ipsec_test_flags flags;
+
+       memset(&flags, 0, sizeof(flags));
+
+       flags.display_alg = true;
+
+       return test_ipsec_inline_proto_all(&flags);
+}
 
 static struct unit_test_suite inline_ipsec_testsuite  = {
        .suite_name = "Inline IPsec Ethernet Device Unit Test Suite",
@@ -934,6 +1031,11 @@ static struct unit_test_suite inline_ipsec_testsuite  = {
                        test_ipsec_inline_proto_known_vec_inb,
                        &pkt_null_aes_xcbc),
 
+               TEST_CASE_NAMED_ST(
+                       "Combined test alg list",
+                       ut_setup_inline_ipsec, ut_teardown_inline_ipsec,
+                       test_ipsec_inline_proto_display_list),
+
 
 
                TEST_CASES_END() /**< NULL terminate unit test array */