[dpdk-stable] patch 'examples/ipsec-secgw: fix AES-CTR block size' has been queued to LTS release 17.11.7

Yongseok Koh yskoh at mellanox.com
Tue Jul 23 03:00:08 CEST 2019


Hi,

FYI, your patch has been queued to LTS release 17.11.7

Note it hasn't been pushed to http://dpdk.org/browse/dpdk-stable yet.
It will be pushed if I get no objection by 07/27/19. So please
shout if anyone has objection.

Also note that after the patch there's a diff of the upstream commit vs the
patch applied to the branch. This will indicate if there was any rebasing
needed to apply to the stable branch. If there were code changes for rebasing
(ie: not only metadata diffs), please double check that the rebase was
correctly done.

Thanks.

Yongseok

---
>From 406181af775f015be96d1b2bef1221b29a54900a Mon Sep 17 00:00:00 2001
From: Fan Zhang <roy.fan.zhang at intel.com>
Date: Tue, 5 Mar 2019 14:40:41 +0000
Subject: [PATCH] examples/ipsec-secgw: fix AES-CTR block size

[ upstream commit 8d9a222507b291113e18e6bc46f3196a51fd181d ]

This patch fixes the incorrect block size for AES-CTR in
legacy mode. Originally, wrong block size will cause
esp_inbound() drop AES-CTR encrypted packets if the payload
sizes not equal to multiple times of 16.

Fixes: 4470c22de2e1 ("examples/ipsec-secgw: add AES-CTR")

Signed-off-by: Fan Zhang <roy.fan.zhang at intel.com>
Acked-by: Konstantin Ananyev <konstantin.ananyev at intel.com>
Acked-by: Akhil Goyal <akhil.goyal at nxp.com>
---
 examples/ipsec-secgw/sa.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/examples/ipsec-secgw/sa.c b/examples/ipsec-secgw/sa.c
index b9f4a21149..b51a230a33 100644
--- a/examples/ipsec-secgw/sa.c
+++ b/examples/ipsec-secgw/sa.c
@@ -101,7 +101,7 @@ const struct supported_cipher_algo cipher_algos[] = {
 		.keyword = "aes-128-ctr",
 		.algo = RTE_CRYPTO_CIPHER_AES_CTR,
 		.iv_len = 8,
-		.block_size = 16, /* XXX AESNI MB limition, should be 4 */
+		.block_size = 4,
 		.key_len = 20
 	}
 };
-- 
2.21.0

---
  Diff of the applied patch vs upstream commit (please double-check if non-empty:
---
--- -	2019-07-22 17:55:08.740136911 -0700
+++ 0041-examples-ipsec-secgw-fix-AES-CTR-block-size.patch	2019-07-22 17:55:06.057474000 -0700
@@ -1,15 +1,16 @@
-From 8d9a222507b291113e18e6bc46f3196a51fd181d Mon Sep 17 00:00:00 2001
+From 406181af775f015be96d1b2bef1221b29a54900a Mon Sep 17 00:00:00 2001
 From: Fan Zhang <roy.fan.zhang at intel.com>
 Date: Tue, 5 Mar 2019 14:40:41 +0000
 Subject: [PATCH] examples/ipsec-secgw: fix AES-CTR block size
 
+[ upstream commit 8d9a222507b291113e18e6bc46f3196a51fd181d ]
+
 This patch fixes the incorrect block size for AES-CTR in
 legacy mode. Originally, wrong block size will cause
 esp_inbound() drop AES-CTR encrypted packets if the payload
 sizes not equal to multiple times of 16.
 
 Fixes: 4470c22de2e1 ("examples/ipsec-secgw: add AES-CTR")
-Cc: stable at dpdk.org
 
 Signed-off-by: Fan Zhang <roy.fan.zhang at intel.com>
 Acked-by: Konstantin Ananyev <konstantin.ananyev at intel.com>
@@ -19,18 +20,18 @@
  1 file changed, 1 insertion(+), 1 deletion(-)
 
 diff --git a/examples/ipsec-secgw/sa.c b/examples/ipsec-secgw/sa.c
-index 414fcd26cf..93e3620bcd 100644
+index b9f4a21149..b51a230a33 100644
 --- a/examples/ipsec-secgw/sa.c
 +++ b/examples/ipsec-secgw/sa.c
-@@ -80,7 +80,7 @@ const struct supported_cipher_algo cipher_algos[] = {
+@@ -101,7 +101,7 @@ const struct supported_cipher_algo cipher_algos[] = {
  		.keyword = "aes-128-ctr",
  		.algo = RTE_CRYPTO_CIPHER_AES_CTR,
  		.iv_len = 8,
 -		.block_size = 16, /* XXX AESNI MB limition, should be 4 */
 +		.block_size = 4,
  		.key_len = 20
- 	},
- 	{
+ 	}
+ };
 -- 
 2.21.0
 


More information about the stable mailing list