From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from dpdk.org (dpdk.org [92.243.14.124]) by inbox.dpdk.org (Postfix) with ESMTP id 55E34A0553; Mon, 17 Feb 2020 15:11:21 +0100 (CET) Received: from [92.243.14.124] (localhost [127.0.0.1]) by dpdk.org (Postfix) with ESMTP id 2E6D81DA9F; Mon, 17 Feb 2020 15:11:20 +0100 (CET) Received: from git-send-mailer.rdmz.labs.mlnx (unknown [37.142.13.130]) by dpdk.org (Postfix) with ESMTP id 67A871D6F5; Mon, 17 Feb 2020 15:11:18 +0100 (CET) From: Bing Zhao To: orika@mellanox.com, viacheslavo@mellanox.com Cc: rasland@mellanox.com, matan@mellanox.com, dev@dpdk.org, jackmin@mellanox.com, stable@dpdk.org Date: Mon, 17 Feb 2020 22:10:55 +0800 Message-Id: <1581948655-2491-1-git-send-email-bingz@mellanox.com> X-Mailer: git-send-email 1.8.3.1 Subject: [dpdk-dev] [PATCH] net/mlx5: fix the matching for ICMP fragments X-BeenThere: dev@dpdk.org X-Mailman-Version: 2.1.15 Precedence: list List-Id: DPDK patches and discussions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: dev-bounces@dpdk.org Sender: "dev" The hardware can recognize and mark the layer 4 protocol type for TCP, UDP and IPSec non-fragmented packets. For all the fragmented packets, L4 type will be considered as None. This can be used when creating a flow with L4 matching, then hops number will be reduced and a better performance could be gained. But for ICMP packets, it cannot be recognized correctly because it is not a L4 protocol in the stack, even if the packet format is similar. All the fragmented and non-fragmented ICMP will have the None L4 type. Fragmented packets with incomplete headers could not hit the flow, even for the first fragment. Because then it will make it complex to defragment for both HW and SW. For other types, the implicit rules could be used directly and all the fragments will miss the flow. For ICMP packets, this should be done explicitly because all packets have None type. The first fragment will still hit the flow if there is no explicit rule. All ICMP fragments will still hit the rules like ETH, ETH + IP, and ETH + IP + "ICMP protocol" only since they are wildcard rules, and there is no next layer protocol specified field in such rules. Fixes: d53aa89aea91 ("net/mlx5: support matching on ICMP/ICMP6") Cc: jackmin@mellanox.com Cc: stable@dpdk.org Signed-off-by: Bing Zhao --- drivers/net/mlx5/mlx5_flow_dv.c | 12 ++++++++++++ 1 file changed, 12 insertions(+) diff --git a/drivers/net/mlx5/mlx5_flow_dv.c b/drivers/net/mlx5/mlx5_flow_dv.c index a9bb0b4..0e31c69 100644 --- a/drivers/net/mlx5/mlx5_flow_dv.c +++ b/drivers/net/mlx5/mlx5_flow_dv.c @@ -6403,6 +6403,12 @@ struct field_modify_info modify_tcp[] = { return; if (!icmp6_m) icmp6_m = &rte_flow_item_icmp6_mask; + /* + * Force flow only to match the non-fragmented IPv6 ICMPv6 packets. + * If only the protocol is specified, no need to match the frag. + */ + MLX5_SET(fte_match_set_lyr_2_4, headers_m, frag, 1); + MLX5_SET(fte_match_set_lyr_2_4, headers_v, frag, 0); MLX5_SET(fte_match_set_misc3, misc3_m, icmpv6_type, icmp6_m->type); MLX5_SET(fte_match_set_misc3, misc3_v, icmpv6_type, icmp6_v->type & icmp6_m->type); @@ -6450,6 +6456,12 @@ struct field_modify_info modify_tcp[] = { return; if (!icmp_m) icmp_m = &rte_flow_item_icmp_mask; + /* + * Force flow only to match the non-fragmented IPv4 ICMP packets. + * If only the protocol is specified, no need to match the frag. + */ + MLX5_SET(fte_match_set_lyr_2_4, headers_m, frag, 1); + MLX5_SET(fte_match_set_lyr_2_4, headers_v, frag, 0); MLX5_SET(fte_match_set_misc3, misc3_m, icmp_type, icmp_m->hdr.icmp_type); MLX5_SET(fte_match_set_misc3, misc3_v, icmp_type, -- 1.8.3.1