RE: [PATCH RFC v4 0/4] introduce IPsec Operation in virtio-net
Srujana Challa <[email protected]>
| Newsgroups | dev.linux.lists.virtio-comment |
|---|---|
| Message-ID | <DS0PR18MB5368A12195BBB0B27AB86E1DA0BB2@DS0PR18MB5368.namprd18.prod.outlook.com> |
> > From: Srujana Challa <[email protected]> > > Sent: Wednesday, April 16, 2025 11:54 AM > > To: Sebastian Mauritsson <[email protected]>; virtio- > > [email protected] > > Cc: [email protected]; [email protected]; [email protected]; > > [email protected]; Satananda Burla <[email protected]>; Nithin Kumar > > Dabilpuram <[email protected]>; Jerin Jacob > > <[email protected]>; Shiva Shankar Kommula <[email protected]> > > Subject: RE: [PATCH RFC v4 0/4] introduce IPsec Operation in > > virtio-net > > > > > What are your thoughts on handling MTU and fragmentation for ESP > packets? > > We do not plan to include post IPsec fragmentation support in this > > series. For this series, the driver or SW stack must pre-fragment the > > packet and ensure that IPsec operations do not increase the payload size > beyond the MTU limit. > > Thanks. > Hi, thanks! Is the plan to use ICMP PMTU messages for this? (as requested by > RFC4303, section 3.3.4 and further described in RFC4301, section 8.2.1) The software stack needs to ensure packets are not larger than the PMTU before sending them to the device. The IPsec offload being proposed for virtio is in agreement with RFC 4303 and 4301 since the linux xfrm framework checks the packet size against the PMTU and sends ICMP messages to the upper layer if fragmentation is needed, using the xfrm4/6_tunnel_check_size function. So device does not expect to see clear text packets larger than PMTU. The current virtio_net device IPsec offload series does not provide pre/post fragmentation support. The stack is responsible for providing the right clear text size packet taking account tunnel and encryption expansion. Thanks. > > > Br, Sebastian > > > > > > > -----Original Message----- > > > > From: Srujana Challa <[email protected]> > > > > Sent: Tuesday, April 8, 2025 9:39 AM > > > > To: [email protected] > > > > Cc: [email protected]; [email protected]; [email protected]; > > > > [email protected]; [email protected]; [email protected]; > > > > [email protected]; [email protected]; [email protected] > > > > Subject: [PATCH RFC v4 0/4] introduce IPsec Operation in > > > > virtio-net > > > > > > > > This series enhances virtio-net by adding support for IPsec Operation. > > > > These patches aim to extend the capabilities of virtio-net, > > > > enabling it to handle IPsec operations efficiently. This enables > > > > the offloading of IPsec processing, both before transmission and > > > > after reception, thereby > > > providing inline offload capabilities. > > > > > > > > It is using new virtio basic facilities of capability and resource > > > > objects. Below is a summary of the changes introduced: > > > > > > > > Patch1: > > > > This patch introduces the foundational support for IPsec within > > > > the virtio-net framework, outlining the necessary capabilities and > > > > resource objects for IPsec operations. > > > > > > > > Patch2: > > > > This patch introduces a new selector and action necessary for > > > > IPsec processing, leveraging flow filter actions. > > > > > > > > Patch3: > > > > This patch introduces new fields in "struct virtio_net_hdr" to to > > > > support IPsec functionality. > > > > > > > > Patch4: > > > > This patch specifies the requirements for both the device and the > > > > driver to support IPsec operations. > > > > > > > > These enhancements are for providing support for IPsec within the > > > > virtio-net device/driver, improving security and performance for > > > > virtualized > > > environments. > > > > We believe these additions will significantly benefit users who > > > > rely on virtio-net for secure data transmission. > > > > > > > > This series references the Virtio-crypto IPsec service operation > > > > capabilities and resource objects data structures, and > > > > cryptographic algorithm definitions to avoid duplication, however > > > > the admin command type vaule differs between Virtio- > > > > > > s/vaule/value > > > > > > > crypto and Virtio-net. > > > > > > > > depends-on: > > > > https://urldefense.proofpoint.com/v2/url?u=https-3A__linkprotect.c > > > > ud > > <https://urldefense.proofpoint.com/v2/url?u=https-3A__linkprotect.cud > > >> > > as > > > > vc.com_url-3Fa-3Dhttps-253a-252f-252flore.kernel.org-252fvirtio-2D > > > > &d > > > > =D > > > > > > > > wIFAg&c=nKjWec2b6R0mOyPaz7xtfQ&r=Fj4OoD5hcKFpANhTWdwQzjT1Jpf7 > > > veC5263T4 > > > > > > > > 7JVpnc&m=qeQ38ckg9CV9XYjq6lTO4eCSj2UOI2n9yYpqZ1ewZAKpY1TyMPV > > > aJGLt5om7E > > > > 1Sa&s=8nGd-AWtrIkGAFVwTmI1rh_DI8dDa_hbo1yqv3-rtAY&e= > > > > comment%2f20250408073512.1783641-1- > > > > schalla%40marvell.com%2f&c=E,1,e0H1NG0bgoOXDTjdINyck8EsQo3iJ- > > > > tOYQYWPMPDLpAxlyZwIxfhnnCkTJgZnA1Z3hM5a4BE-Q- > > > > aIqKCN_jJEHcOnI4Pr5y352wXPV7C9l1z0jpIhulo&typo=1 > > > > depends-on: > > > > https://urldefense.proofpoint.com/v2/url?u=https-3A__linkprotect.c > > > > ud > > <https://urldefense.proofpoint.com/v2/url?u=https-3A__linkprotect.cud > > >> > > as > > > > vc.com_url-3Fa-3Dhttps-253a-252f-252flore.kernel.org-252fvirtio-2D > > > > &d > > > > =D > > > > > > > > wIFAg&c=nKjWec2b6R0mOyPaz7xtfQ&r=Fj4OoD5hcKFpANhTWdwQzjT1Jpf7 > > > veC5263T4 > > > > > > > > 7JVpnc&m=qeQ38ckg9CV9XYjq6lTO4eCSj2UOI2n9yYpqZ1ewZAKpY1TyMPV > > > aJGLt5om7E > > > > 1Sa&s=8nGd-AWtrIkGAFVwTmI1rh_DI8dDa_hbo1yqv3-rtAY&e= > > > > comment%2f20250401195655.486230-1- > > > > > > > > kshankar%40marvell.com%2f&c=E,1,tgp7wHeyHqHljo04DHTnSkhMKJrH1lvo > > > v- > > > > UKPod_ljd0NrIUOs5U-TVPYMaxypakYomt95- > > > > VpcgsrIk36jjnojbPeIkCkUz2Hx40fKBQH_nfQSLy&typo=1 > > > > > > > > v2: > > > > - Addressed the review comments from Parav Pandit. > > > > v3: > > > > - Introduced VIRTIO_NET_HDR_F_SECURITY_SA_SOFT_EXPIRY_WARN > flag in > > > the > > > > virtio_net_hdr:flags. > > > > - Addressed the review comments from Parav Pandit. > > > > v4: > > > > - Rebased this series on VIRTIO_NET_F_OUT_NET_HEADER patch. > > > > > > > > Srujana Challa (4): > > > > virtio-net: Add IPsec operation, capabilities and resource objects > > > > virtio-net: Add new flow filter selector and action for IPsec > > > > virtio-net: extend virtio_net_hdr for IPsec support > > > > virtio-net: Add IPsec operation device and driver requirements > > > > > > > > device-types/net/description.tex | 206 > +++++++++++++++++++++++- > > > > device-types/net/device-conformance.tex | 1 + > > > > device-types/net/driver-conformance.tex | 1 + > > > > 3 files changed, 203 insertions(+), 5 deletions(-) > > > > > > > > -- > > > > 2.25.1 > > > > > > > > > > Disclaimer: This email and any files transmitted with it may contain > > > confidential information intended for the addressee(s) only. The > > > information is not to be surrendered or copied to unauthorized > > > persons. If you have received this communication in error, please > > > notify the sender immediately and delete this e-mail from your system. > Disclaimer: This email and any files transmitted with it may contain confidential > information intended for the addressee(s) only. The information is not to be > surrendered or copied to unauthorized persons. If you have received this > communication in error, please notify the sender immediately and delete this > e-mail from your system.