From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from dpdk.org (dpdk.org [92.243.14.124]) by inbox.dpdk.org (Postfix) with ESMTP id D8F3EA0487 for ; Mon, 29 Jul 2019 13:38:22 +0200 (CEST) Received: from [92.243.14.124] (localhost [127.0.0.1]) by dpdk.org (Postfix) with ESMTP id 519451BF24; Mon, 29 Jul 2019 13:38:21 +0200 (CEST) Received: from mx0b-0016f401.pphosted.com (mx0b-0016f401.pphosted.com [67.231.156.173]) by dpdk.org (Postfix) with ESMTP id 6D0FD1BF23 for ; Mon, 29 Jul 2019 13:38:20 +0200 (CEST) Received: from pps.filterd (m0045851.ppops.net [127.0.0.1]) by mx0b-0016f401.pphosted.com (8.16.0.42/8.16.0.42) with SMTP id x6TBUpGS005404; Mon, 29 Jul 2019 04:38:19 -0700 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=marvell.com; h=from : to : cc : subject : date : message-id : references : in-reply-to : content-type : mime-version; s=pfpt0818; bh=FpNgV0AkDxUHZHx+E8dZBTYCWPHK1iKoWpRvnZ4bzdU=; b=fF6j2UYPU0A6sTo/nm5uaMtD/7KkszcUQvELeNdZk4KRLP4mx8N8Rw89OKxkcaPlRJ/A E+bU5wLCUuSCKGWUmNbxbnVj1N/3uK9drmwfPwFuXCHuiEJLvmZBcSI3RT5RoVEF+RwN oNRTzqxxScHpvdnbLN1dDV2Vu6IFudOVVryVyL7b8t2pTM2Er3T4Bk89snTI5zxGz28p zkpT/Hp5lLpOf7d2GsoOKG6RfgP3PaZgsX4PZ/0cHqSoEtDXi8MctwTwEQezxWYQ/Zep evGfYWp0u+DyeZnLB/hhc1YJTxVP58crufPjwn3eju8FP7RigKGcNPZOJxj3SpA0Qdea gA== Received: from sc-exch01.marvell.com ([199.233.58.181]) by mx0b-0016f401.pphosted.com with ESMTP id 2u0p4kxyk2-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-SHA384 bits=256 verify=NOT); Mon, 29 Jul 2019 04:38:19 -0700 Received: from SC-EXCH02.marvell.com (10.93.176.82) by SC-EXCH01.marvell.com (10.93.176.81) with Microsoft SMTP Server (TLS) id 15.0.1367.3; Mon, 29 Jul 2019 04:38:16 -0700 Received: from NAM03-CO1-obe.outbound.protection.outlook.com (104.47.40.56) by SC-EXCH02.marvell.com (10.93.176.82) with Microsoft SMTP Server (TLS) id 15.0.1367.3 via Frontend Transport; Mon, 29 Jul 2019 04:38:16 -0700 ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=G3ClfTQ6BmUubplg4QHaQW9GKSjEssUsMSqKFvaJMzCBYn7wXjnqhiOtDQQRAHSvRW1LW/XVKMoQk3Dc5tAKZA9BZqXLoqq0PqdjLOf5l3b10d1Zzi4QdvDJKkiZuMJTOTXmF/xyTUKoR1rjL0+h29uYfazaJQKUN8YB3Kygxgv9crwCt8PBSgERBHgOzD9uJtSeWsW5WRnTECVqIh1Kd3vwY948wYvl83MDOguCSpjAszyxQfd8oPWlLnDIKmYDM6mz+v68XmxFXuLP1Z+nyiFX+uj7XCQkO5hfCBzCIibpDF4j7y4dYTjrYa+oL3Ro8BJ5ilkpQyrK1WsjVvmkxQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=FpNgV0AkDxUHZHx+E8dZBTYCWPHK1iKoWpRvnZ4bzdU=; b=HVaLI4x5jq8tdASG1ZLCZmOg2mWZvWMmqilV37DzxOih7iEuN+6ABSotN+n/zjxpoSIfP1D9DBv6WNL0miLAzHuvrJnakjBk0mliWBx7fb7fKbOsIITlp9eLfRHh0ejWlFdnjB8G/3v0Nq6do4t1qvMzju4VkPSMDHwhTLrutygFn9pMozVp3dv9fIl2HoaXx/XFQHdQjX3bTUOWb+F7ll99LomRG+/ceptDcWnJaYdmza4gM9XHRS2QVKBUhHFp7D9Dh/nw0pNDwORHUFUF/+3VmCTFG6XDaWxM9KZWLOr2I9u4cT9UfppdGoMDJNw640U+AW9H/0zReOGMYJ72eQ== ARC-Authentication-Results: i=1; mx.microsoft.com 1;spf=pass smtp.mailfrom=marvell.com;dmarc=pass action=none header.from=marvell.com;dkim=pass header.d=marvell.com;arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=marvell.onmicrosoft.com; s=selector2-marvell-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=FpNgV0AkDxUHZHx+E8dZBTYCWPHK1iKoWpRvnZ4bzdU=; b=eSWi6SjpNfEjs7+rKStox9IXbApWN88pYpeTYsJFeASMGd9/z1/lY+VwKfsAyQQU1VnruI8G2+vv1uZIMrt3LxUTTb0XT5AtUMkKbyeyapwtOtHOgN2vHbTLte3s1Se6aMl5w2cUUeIUwDJ463EXRfRwD1OhLzJfj2wyzUWcdyM= Received: from MN2PR18MB2542.namprd18.prod.outlook.com (20.179.82.221) by MN2PR18MB3069.namprd18.prod.outlook.com (20.178.255.161) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2115.10; Mon, 29 Jul 2019 11:38:11 +0000 Received: from MN2PR18MB2542.namprd18.prod.outlook.com ([fe80::74b0:9895:ebeb:2e03]) by MN2PR18MB2542.namprd18.prod.outlook.com ([fe80::74b0:9895:ebeb:2e03%3]) with mapi id 15.20.2115.005; Mon, 29 Jul 2019 11:38:11 +0000 From: Ayuj Verma To: "Kusztal, ArkadiuszX" , Shally Verma , Anoob Joseph , "akhil.goyal@nxp.com" CC: Sunila Sahu , Kanaka Durga Kotamarthy , "dev@dpdk.org" , "Trahe, Fiona" Thread-Topic: [PATCH v1 0/2] declare crypto asym xform immutable Thread-Index: AQHVQf0Voz5AKR080U2fA9qunr53mKbZdj1+gAFFAYCAABJ3AIAAFSsAgAAWigCAAGzMAIAGFy2P Date: Mon, 29 Jul 2019 11:38:10 +0000 Message-ID: References: <1563958317-480-1-git-send-email-ayverma@marvell.com> , <06EE24DD0B19E248B53F6DC8657831551B282E1B@hasmsx109.ger.corp.intel.com> In-Reply-To: <06EE24DD0B19E248B53F6DC8657831551B282E1B@hasmsx109.ger.corp.intel.com> Accept-Language: en-IN, en-US Content-Language: en-IN X-MS-Has-Attach: X-MS-TNEF-Correlator: x-originating-ip: [14.140.231.66] x-ms-publictraffictype: Email x-ms-office365-filtering-correlation-id: 1e6d1838-090b-443b-930d-08d714193c10 x-microsoft-antispam: BCL:0; PCL:0; RULEID:(2390118)(7020095)(4652040)(8989299)(4534185)(7168020)(4627221)(201703031133081)(201702281549075)(8990200)(5600148)(711020)(4605104)(1401327)(2017052603328)(7193020); SRVR:MN2PR18MB3069; x-ms-traffictypediagnostic: MN2PR18MB3069: x-microsoft-antispam-prvs: x-ms-oob-tlc-oobclassifiers: OLM:10000; x-forefront-prvs: 01136D2D90 x-forefront-antispam-report: SFV:NSPM; SFS:(10009020)(4636009)(366004)(39850400004)(136003)(396003)(376002)(346002)(189003)(199004)(53754006)(30864003)(99286004)(54906003)(110136005)(52536014)(64756008)(7736002)(11346002)(71190400001)(71200400001)(316002)(5660300002)(66476007)(33656002)(102836004)(55236004)(561944003)(26005)(66556008)(53546011)(6506007)(66446008)(76116006)(66946007)(186003)(7696005)(446003)(76176011)(74316002)(486006)(256004)(2906002)(476003)(68736007)(14444005)(25786009)(478600001)(8676002)(2501003)(53936002)(54896002)(4326008)(55016002)(19627405001)(3846002)(6116002)(6606003)(86362001)(8936002)(66066001)(14454004)(229853002)(6436002)(81166006)(81156014)(6246003)(9686003)(236005); DIR:OUT; SFP:1101; SCL:1; SRVR:MN2PR18MB3069; H:MN2PR18MB2542.namprd18.prod.outlook.com; FPR:; SPF:None; LANG:en; PTR:InfoNoRecords; MX:1; A:1; received-spf: None (protection.outlook.com: marvell.com does not designate permitted sender hosts) x-ms-exchange-senderadcheck: 1 x-microsoft-antispam-message-info: DTIttbMZ1B2QcvFraL946SwzMBk4btMyapouUzQedlrJFBtozuWV5O7cxPiWAY9jaACNQYlTVYstySEVFUMjb9IwJLdFfYVvJE6ICahxmG8NR08Rs2ILMJaCLy5VYOkoatr6CGFQGaGFI+K4u2eK6U8vBmtzq4ljoZ2ZS+SDZW8Qpftxxmj+mBiKviK9fBGBwFCnQEG0nU24dZDG17nkvi7qYNjrDYetbuyAloXrctW+ziQassOKN1jIR4c9Uk0+Yt5trgb+C8IE8P5CFfg7xR0iXr6jHu+Sf7L0rUSH4VUGP6QQyAfjhICGB1FF34WOcNVNqlnMucWnzA+3Uo/Efvbo/bbejKn06CvxZ04EyR71o3rWNA/FV3sdwEaCOE92OqD1RWDNUUMWyDUQKhHn50CqsXrYPIE8DorC4PKy2/c= MIME-Version: 1.0 X-MS-Exchange-CrossTenant-Network-Message-Id: 1e6d1838-090b-443b-930d-08d714193c10 X-MS-Exchange-CrossTenant-originalarrivaltime: 29 Jul 2019 11:38:10.9402 (UTC) X-MS-Exchange-CrossTenant-fromentityheader: Hosted X-MS-Exchange-CrossTenant-id: 70e1fb47-1155-421d-87fc-2e58f638b6e0 X-MS-Exchange-CrossTenant-mailboxtype: HOSTED X-MS-Exchange-CrossTenant-userprincipalname: ayverma@marvell.com X-MS-Exchange-Transport-CrossTenantHeadersStamped: MN2PR18MB3069 X-OriginatorOrg: marvell.com X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10434:5.22.84,1.0.8 definitions=2019-07-29_05:2019-07-29,2019-07-29 signatures=0 Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable X-Content-Filtered-By: Mailman/MimeDel 2.1.15 Subject: Re: [dpdk-dev] [PATCH v1 0/2] declare crypto asym xform immutable X-BeenThere: dev@dpdk.org X-Mailman-Version: 2.1.15 Precedence: list List-Id: DPDK patches and discussions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: dev-bounces@dpdk.org Sender: "dev" ________________________________ From: Kusztal, ArkadiuszX Sent: 25 July 2019 19:57 To: Shally Verma ; Anoob Joseph ; = Ayuj Verma ; akhil.goyal@nxp.com Cc: Sunila Sahu ; Kanaka Durga Kotamarthy ; dev@dpdk.org ; Trahe, Fiona Subject: RE: [PATCH v1 0/2] declare crypto asym xform immutable Hi All, > > > I believe there are couple of issues with this patch. > > > > > > Are these experimental APIs? I believe they were made stable this > > > release and I'm not sure if it is a right practice to edit an API > > > without deprecation notice after it is made stable. Especially now > > > that RC2 is done. @Akhil, what is your take on this? > > > [Shally] These are experimental still, hence no deprecation notice. > > > We checked about it with Fiona, Akhil before. > > > > [Anoob] In the patch, the edited APIs doesn't have experimental tag. I > > leave it to Akhil's judgement on this. > > > > > > > > I think, the approach here is wrong. If the lifetime of the session > > > is expected to be only few packets, then session-less (which I > > > believe is in the pipeline) would make more sense. > > > [Shally] See my response further below on this. > > > > > > If the lifetime of the session is expected to be more than that, > > > then having this feature/limitation would make application more > > > complicated. Also, since one asymmetric session can hold both public > > > & private keys, the implicit assumption would be, the session can be > > > used for multiple kinds of operations. This change is in > > > contradiction with > > that. > > > [Shally] Why the contradiction here? There's no change in session > > > usage from current version. Currently too, once keys are set on > > > asymmetric session, they are used with multiple operations using > > > that sessions, example - once RSA xform is set with keys, then one > > > can perform sign/verify/enc/dec. So, I don't see any change in that > > > notion with this proposal. All we are changing is, PMD which does > > > not need to store keys in specific format (like openssl PMD), can > > > just hold app buffer pointer till session-lifetime (eventually > > > giving same effect as sessionless). It will help such PMDs to > > > optimize their session setup time by > > avoiding unnecessary memcpy of keys buffers. > > > > [Anoob] Contradiction is in the sense of what is a session. Here we > > are saying one session can have SIGN & VERIFY, but the lifetime of > > the session is assumed to be "short". > [Shally] No. we only said, Session will only have keys (which is in xform= ) with > which SIGN & VERIFY will be performed during enqueue. > As long as there're operations to be performed using data set in session, > session data should not be manipulated. [AK] - we need to keep in mind that if we will copy user private key inside= our internal structs, It will be stored in two places in the same time, making it more vulnerable= , that's why I have asked about session lifetime. At least we could inform user of this when PMD copy data internally. Of course usually this data need to be copied anyway for op lifetime (becau= se of some padding/alignement requirements hw may have). > > > > > > > > > But my major concern is how this can lead to accidental errors. > > > Making the argument as const will mean the API won't edit its > > > contents. But if there is a pointer in that (key happens to be a > > > pointer inside the xform), having const for xform will not help. > > > This is my understanding. Please correct me if I'm wrong. > > > [Shally] This spec says " xform and its buffers remain constant" . > > > So, intention is to state to apps that buffer passed to xform should > > > be const in nature and that they should not modify it. > > > > [Anoob] The current change could break existing applications. And the > > compiler will not be able to detect it. > > > [Shally] Application would need to be changed to make sure this criteria = is > met. We took care to check same in asym unit test app while proposing > change. > > > > > > > Also, I could have the xform allocated from stack (non const, > > > regular local > > > variable) and then call the session_init. Would compiler throw an > > > issue in that case? I doubt so. > > > > > > void abc(const int t) > > > { > > > printf("%d\n", t); > > > } > > > > > > void main() > > > { > > > int t =3D 0; > > > abc(t); > > > t =3D 2; > > > abc(t); > > > } > > > > > > To summarize, if this assumption is accepted, then compiler will not > > > be able to ensure it. And to properly use it, application will have > > > to be drafted differently. And when similar effect can be achieved > > > by having session-less, this seems redundant. > > > [Shally] Compiler may or may not warn on typecast error here. > > > > [Anoob] May or may not be? > > > [Shally] Yes. Depending on compiler version type or optimization level. > Havent given try to all. [AK] Integers conversions are not good example as integers in C are governe= d by different rules than pointers. In terms of this - struct rte_crypto_asym_xform *xforms, + const struct rte_crypto_asym_xform *xforms, No compiler should complain about that as per spec: for any qualifier q, a = pointer to a non-q-qualified type may be converted to a pointer to the q-qualified version of the type. We of course expect user will not change this data when there are still ops= to be enqueued with this xform. [Ayuj] Yes, also can't do below : const struct rte_crypto_asym_xform *xform; struct rte_crypto_modex_xform *xfrm =3D &(xform->= modex); it should needs to be const for both which will ensure its sanity= : const struct rte_crypto_asym_xform *xform; const struct rte_crypto_modex_xform *xfrm =3D &(x= form->modex); > > > > That's why > > > spec and documentation are put in place to ensure that application > > > don't reuse them or destroy them once "xform and its buffers" are > > > set on > > session. > > > And, same will need to be documented about xform for session-less > > > usage as well. > > > > [Anoob] Can you describe how this is required in session-less? > > > [Shally] We don't know how every PMD might use them. So, it is safe to ma= rk > xform and buffers immutable there too. > So this is my thought but I have asked from POC for sessionless, as it is > proposal by Arek, am yet to get more feedback on that. > > > > Even there, we would ensure that application do not re-use or modify > > > xform and its buffers until dequeue happen. So, practically I see, > > > application would have to take of these cases in session-less as well= . > > > > > > Since in session-based case, xform are set on it than ops, so we're > > > moving same definition on session. So for PMDs which support > > > sessions-based implementations ( like ours) , believe it completely > > > make sense to enable sessions to have sessionless effect. If we > > > don't change spec to enable optimization, then we're making > > > 1-approach slower than other. PMDs can adopt any approach more > suitable to them. > > > But spec could be made flexible to allow them to experiment with > > > both approaches for performance. Else , PMDs will be forced to > > > experiment around sessionless which may be eventually be an > > > unnecessary overhead > > for them. > > > > [Anoob] I get your intention on avoiding the memcpys. But the current > > changes would make the spec more prone to errors. And if we think we > > should improve the key handling done in both session & session-less, I > > would suggest not to rush with this change. We can keep the API > > experimental and continue improving it to fix this issue for all PMDs m= ore > cleanly. > > > [Shally] There's no rush. It is up and open for feedback. > This change has an intent to optimize session setup time and since xform > data is not supposed to change once it is set on session. Only change > proposed is, why not just use app buffers instead of redundant copy of sa= me > into PMD buffer. > if you see better suggestions , please provide. > > > > > > > Thanks > > > Shally > > > > > > So this change is NACK from my side. > > > > > > Thanks, > > > Anoob > > > > > > From: Ayuj Verma > > > Sent: Wednesday, July 24, 2019 2:23 PM > > > To: mailto:akhil.goyal@nxp.com > > > Cc: mailto:arkadiuszx.kusztal@intel.com; Shally Verma > > > ; Sunila Sahu > > > ; Kanaka Durga Kotamarthy > > > ; Anoob > > Joseph > > > ; mailto:dev@dpdk.org; Fiona Trahe > > > > > > Subject: Re: [PATCH v1 0/2] declare crypto asym xform immutable > > > > > > +Fiona. > > > ________________________________________ > > > From: Ayuj Verma > > > Sent: 24 July 2019 14:21:55 > > > To: mailto:akhil.goyal@nxp.com > > > Cc: mailto:arkadiuszx.kusztal@intel.com > > > ; Shally Verma > > > ; Sunila Sahu > > > ; Kanaka Durga Kotamarthy > > > ; Anoob > > Joseph > > > ; mailto:dev@dpdk.org > > > ; Ayuj Verma > > > Subject: [PATCH v1 0/2] declare crypto asym xform immutable > > > > > > Mark asym xform as immutable till lifetime of session. It will save > > > session setup time for PMDs, which doesn't require any manipulation > > > of xform data, by directly using these buffers. > > > > > > * Updated xform type in session init/configure > > > API as constant. > > > * Updated doc with proper transform description. > > > * Updated openssl PMD with above changes. > > > > > > Ayuj Verma (2): > > > lib/crypto: declare crypto asym xform immutable > > > crypto/openssl: mark asym xform constant > > > > > > doc/guides/prog_guide/cryptodev_lib.rst | 10 ++++++++++ > > > drivers/crypto/openssl/rte_openssl_pmd_ops.c | 8 ++++---- > > > lib/librte_cryptodev/rte_cryptodev.c | 2 +- > > > lib/librte_cryptodev/rte_cryptodev.h | 2 +- > > > lib/librte_cryptodev/rte_cryptodev_pmd.h | 2 +- > > > 5 files changed, 17 insertions(+), 7 deletions(-) > > > > > > -- > > > 1.8.3.1