Re: [PATCH v4 net-next 19/19] net/mlx5e: Kconfig, mutually exclude compilation of TLS and IPsec accel
From: Boris Pismenny <hidden>
Date: 2018-07-13 20:20:46
On 7/12/2018 8:44 PM, David Miller wrote:
From: Boris Pismenny <redacted> Date: Thu, 12 Jul 2018 22:25:57 +0300quoted
We currently have no devices that support both TLS and IPsec using the accel framework, and the current code does not support both IPsec and TLS. This patch prevents such combinations. Signed-off-by: Boris Pismenny <redacted> --- drivers/net/ethernet/mellanox/mlx5/core/Kconfig | 1 + 1 file changed, 1 insertion(+)diff --git a/drivers/net/ethernet/mellanox/mlx5/core/Kconfig b/drivers/net/ethernet/mellanox/mlx5/core/Kconfig index 2545296..d3e8c70 100644 --- a/drivers/net/ethernet/mellanox/mlx5/core/Kconfig +++ b/drivers/net/ethernet/mellanox/mlx5/core/Kconfig@@ -93,6 +93,7 @@ config MLX5_EN_TLS depends on TLS_DEVICE depends on TLS=y || MLX5_CORE=m depends on MLX5_ACCEL + depends on !MLX5_EN_IPSEC default nYou absolutely cannot do this. You are forcing a distribution to pick one offload or the other at build time, that's insane. Please find a way to support both offloads in the driver. It is absolutely valid for a distribution to ship the driver in a state that supports both offloads and you must therefore support this properly. Thank you.
Thanks Dave. We currently have no devices that support both TLS and IPsec using the accel framework, and the current code does not support both IPsec and TLS. The purpose of this patch was to prevent such cases using Kconfig. Looking a bit more carefully at the code. We don't need this patch, because we still don't have a deviceID for both TLS and IPsec, so the problematic flow cannot happen. So we've just been over zealous here. I'll remove this patch and send a v5.