From mboxrd@z Thu Jan  1 00:00:00 1970
Return-Path: <konstantin.ananyev@intel.com>
Received: from mga18.intel.com (mga18.intel.com [134.134.136.126])
 by dpdk.org (Postfix) with ESMTP id 2272F292D
 for <dev@dpdk.org>; Fri, 22 Feb 2019 13:38:07 +0100 (CET)
X-Amp-Result: SKIPPED(no attachment in message)
X-Amp-File-Uploaded: False
Received: from fmsmga007.fm.intel.com ([10.253.24.52])
 by orsmga106.jf.intel.com with ESMTP/TLS/DHE-RSA-AES256-GCM-SHA384;
 22 Feb 2019 04:38:06 -0800
X-ExtLoop1: 1
X-IronPort-AV: E=Sophos;i="5.58,399,1544515200"; d="scan'208";a="124401641"
Received: from irsmsx101.ger.corp.intel.com ([163.33.3.153])
 by fmsmga007.fm.intel.com with ESMTP; 22 Feb 2019 04:38:06 -0800
Received: from irsmsx105.ger.corp.intel.com ([169.254.7.72]) by
 IRSMSX101.ger.corp.intel.com ([169.254.1.185]) with mapi id 14.03.0415.000;
 Fri, 22 Feb 2019 12:38:05 +0000
From: "Ananyev, Konstantin" <konstantin.ananyev@intel.com>
To: "Zhang, Roy Fan" <roy.fan.zhang@intel.com>, "dev@dpdk.org" <dev@dpdk.org>
CC: "akhil.goyal@nxp.com" <akhil.goyal@nxp.com>
Thread-Topic: [PATCH v2 3/4] ipsec: add 3DES-CBC algorithm support
Thread-Index: AQHUyGiHg6Vu0IzzLkmbeSWd45LD5aXrxaDA
Date: Fri, 22 Feb 2019 12:38:04 +0000
Message-ID: <2601191342CEEE43887BDE71AB977258012413C292@irsmsx105.ger.corp.intel.com>
References: <20190218163254.56905-1-roy.fan.zhang@intel.com>
 <20190219153236.84537-1-roy.fan.zhang@intel.com>
 <20190219153236.84537-4-roy.fan.zhang@intel.com>
In-Reply-To: <20190219153236.84537-4-roy.fan.zhang@intel.com>
Accept-Language: en-IE, en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-titus-metadata-40: eyJDYXRlZ29yeUxhYmVscyI6IiIsIk1ldGFkYXRhIjp7Im5zIjoiaHR0cDpcL1wvd3d3LnRpdHVzLmNvbVwvbnNcL0ludGVsMyIsImlkIjoiMDM3OWQ0ZGQtNzU2ZC00ZGM3LWE2MGUtNWY2YjllOTc3NTkwIiwicHJvcHMiOlt7Im4iOiJDVFBDbGFzc2lmaWNhdGlvbiIsInZhbHMiOlt7InZhbHVlIjoiQ1RQX05UIn1dfV19LCJTdWJqZWN0TGFiZWxzIjpbXSwiVE1DVmVyc2lvbiI6IjE3LjEwLjE4MDQuNDkiLCJUcnVzdGVkTGFiZWxIYXNoIjoiNDVZUGdTSnVpS3p0UTZveUtCcDViMXJHU1o4SW5wZlI4a2tVREVpUnZUSjNcL0g2S0tmdHBoeURKRUFpaDYzeEEifQ==
x-ctpclassification: CTP_NT
dlp-product: dlpe-windows
dlp-version: 11.0.400.15
dlp-reaction: no-action
x-originating-ip: [163.33.239.181]
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Subject: Re: [dpdk-dev] [PATCH v2 3/4] ipsec: add 3DES-CBC algorithm support
X-BeenThere: dev@dpdk.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: DPDK patches and discussions <dev.dpdk.org>
List-Unsubscribe: <https://mails.dpdk.org/options/dev>,
 <mailto:dev-request@dpdk.org?subject=unsubscribe>
List-Archive: <http://mails.dpdk.org/archives/dev/>
List-Post: <mailto:dev@dpdk.org>
List-Help: <mailto:dev-request@dpdk.org?subject=help>
List-Subscribe: <https://mails.dpdk.org/listinfo/dev>,
 <mailto:dev-request@dpdk.org?subject=subscribe>
X-List-Received-Date: Fri, 22 Feb 2019 12:38:08 -0000

> This patch adds triple-des CBC mode cipher algorithm to ipsec
> library.
>=20
> Signed-off-by: Fan Zhang <roy.fan.zhang@intel.com>
> ---
>  lib/librte_ipsec/sa.c | 10 ++++++++++
>  lib/librte_ipsec/sa.h |  6 ++++++
>  2 files changed, 16 insertions(+)
>=20
> diff --git a/lib/librte_ipsec/sa.c b/lib/librte_ipsec/sa.c
> index e34dd320a..5c59c4b67 100644
> --- a/lib/librte_ipsec/sa.c
> +++ b/lib/librte_ipsec/sa.c
> @@ -307,6 +307,13 @@ esp_sa_init(struct rte_ipsec_sa *sa, const struct rt=
e_ipsec_sa_prm *prm,
>  			sa->algo_type =3D ALGO_TYPE_AES_CTR;
>  			break;
>=20
> +		case RTE_CRYPTO_CIPHER_3DES_CBC:
> +			/* RFC 1851 */
> +			sa->pad_align =3D IPSEC_PAD_3DES_CBC;
> +			sa->iv_len =3D IPSEC_3DES_IV_SIZE;
> +			sa->algo_type =3D ALGO_TYPE_3DES;
> +			break;
> +
>  		default:
>  			return -EINVAL;
>  		}
> @@ -512,6 +519,8 @@ esp_outb_cop_prepare(struct rte_crypto_op *cop,
>  			sa->iv_ofs);
>  		aes_ctr_cnt_blk_fill(ctr, ivp[0], sa->salt);
>  		break;
> +	case ALGO_TYPE_3DES:
> +		/* Cipher-Auth (3DES-CBC *) case */
>  	case ALGO_TYPE_NULL:
>  		/* NULL case */
>  		sop->cipher.data.offset =3D sa->ctp.cipher.offset + hlen;
> @@ -873,6 +882,7 @@ esp_inb_tun_cop_prepare(struct rte_crypto_op *cop,
>  		aead_gcm_iv_fill(gcm, ivp[0], sa->salt);
>  		break;
>  	case ALGO_TYPE_AES_CBC:
> +	case ALGO_TYPE_3DES:
>  		sop->cipher.data.offset =3D pofs + sa->ctp.cipher.offset;
>  		sop->cipher.data.length =3D clen;
>  		sop->auth.data.offset =3D pofs + sa->ctp.auth.offset;
> diff --git a/lib/librte_ipsec/sa.h b/lib/librte_ipsec/sa.h
> index 12c061ee6..8398748d1 100644
> --- a/lib/librte_ipsec/sa.h
> +++ b/lib/librte_ipsec/sa.h
> @@ -14,6 +14,7 @@
>  /* padding alignment for different algorithms */
>  enum {
>  	IPSEC_PAD_DEFAULT =3D 4,
> +	IPSEC_PAD_3DES_CBC =3D IPSEC_PAD_DEFAULT,
>  	IPSEC_PAD_AES_CBC =3D IPSEC_MAX_IV_SIZE,
>  	IPSEC_PAD_AES_CTR =3D IPSEC_PAD_DEFAULT,
>  	IPSEC_PAD_AES_GCM =3D IPSEC_PAD_DEFAULT,
> @@ -24,6 +25,10 @@ enum {
>  enum {
>  	IPSEC_IV_SIZE_DEFAULT =3D IPSEC_MAX_IV_SIZE,
>  	IPSEC_AES_CTR_IV_SIZE =3D sizeof(uint64_t),
> +	/* TripleDES supports IV size of 32bits or 64bits but he library

Typo: 's/ he / the /'

> +	 * only supports 64bits.
> +	 */
> +	IPSEC_3DES_IV_SIZE =3D sizeof(uint64_t),
>  };
>=20
>  /* these definitions probably has to be in rte_crypto_sym.h */
> @@ -57,6 +62,7 @@ struct replay_sqn {
>  /*IPSEC SA supported algorithms */
>  enum sa_algo_type	{
>  	ALGO_TYPE_NULL =3D 0,
> +	ALGO_TYPE_3DES,
>  	ALGO_TYPE_AES_CBC,
>  	ALGO_TYPE_AES_CTR,
>  	ALGO_TYPE_AES_GCM,
> --

Acked-by: Konstantin Ananyev <konstantin.ananyev@intel.com>

> 2.14.5