| 143 | } |
| 144 | |
| 145 | int |
| 146 | esp_inbound_post(struct rte_mbuf *m, struct ipsec_sa *sa, |
| 147 | struct rte_crypto_op *cop) |
| 148 | { |
| 149 | struct ip *ip4, *ip; |
| 150 | struct ip6_hdr *ip6; |
| 151 | uint8_t *nexthdr, *pad_len; |
| 152 | uint8_t *padding; |
| 153 | uint16_t i; |
| 154 | struct rte_ipsec_session *ips; |
| 155 | |
| 156 | RTE_ASSERT(m != NULL); |
| 157 | RTE_ASSERT(sa != NULL); |
| 158 | RTE_ASSERT(cop != NULL); |
| 159 | |
| 160 | ips = ipsec_get_primary_session(sa); |
| 161 | |
| 162 | if ((ips->type == RTE_SECURITY_ACTION_TYPE_INLINE_PROTOCOL) || |
| 163 | (ips->type == RTE_SECURITY_ACTION_TYPE_INLINE_CRYPTO)) { |
| 164 | if (m->ol_flags & RTE_MBUF_F_RX_SEC_OFFLOAD) { |
| 165 | if (m->ol_flags & RTE_MBUF_F_RX_SEC_OFFLOAD_FAILED) |
| 166 | cop->status = RTE_CRYPTO_OP_STATUS_ERROR; |
| 167 | else |
| 168 | cop->status = RTE_CRYPTO_OP_STATUS_SUCCESS; |
| 169 | } else |
| 170 | cop->status = RTE_CRYPTO_OP_STATUS_NOT_PROCESSED; |
| 171 | } |
| 172 | |
| 173 | if (cop->status != RTE_CRYPTO_OP_STATUS_SUCCESS) { |
| 174 | RTE_LOG(ERR, IPSEC_ESP, "%s() failed crypto op\n", __func__); |
| 175 | return -1; |
| 176 | } |
| 177 | |
| 178 | if (ips->type == RTE_SECURITY_ACTION_TYPE_INLINE_CRYPTO && |
| 179 | ips->security.ol_flags & RTE_SECURITY_RX_HW_TRAILER_OFFLOAD) { |
| 180 | nexthdr = &m->inner_esp_next_proto; |
| 181 | } else { |
| 182 | nexthdr = rte_pktmbuf_mtod_offset(m, uint8_t*, |
| 183 | rte_pktmbuf_pkt_len(m) - sa->digest_len - 1); |
| 184 | pad_len = nexthdr - 1; |
| 185 | |
| 186 | padding = pad_len - *pad_len; |
| 187 | for (i = 0; i < *pad_len; i++) { |
| 188 | if (padding[i] != i + 1) { |
| 189 | RTE_LOG(ERR, IPSEC_ESP, "invalid padding\n"); |
| 190 | return -EINVAL; |
| 191 | } |
| 192 | } |
| 193 | |
| 194 | if (rte_pktmbuf_trim(m, *pad_len + 2 + sa->digest_len)) { |
| 195 | RTE_LOG(ERR, IPSEC_ESP, |
| 196 | "failed to remove pad_len + digest\n"); |
| 197 | return -EINVAL; |
| 198 | } |
| 199 | } |
| 200 | |
| 201 | if (unlikely(IS_TRANSPORT(sa->flags))) { |
| 202 | ip = rte_pktmbuf_mtod(m, struct ip *); |
nothing calls this directly
no test coverage detected