Thread (29 messages) 29 messages, 2 authors, 9d ago
COOLING9d

Revision v17 of 2 in this series.

Revisions (2)
  1. v16 [diff vs current]
  2. v17 current

[PATCH net-next v17 10/15] net/mlx5e: flag TLS RX records that failed device decryption

From: Rishikesh Jethwani <hidden>
Date: 2026-09-17 22:45:28
Subsystem: mellanox ethernet driver (mlx5e), mellanox ethernet innova drivers, mellanox mlx5 core vpi driver, networking drivers, the rest · Maintainers: Saeed Mahameed, Tariq Toukan, Mark Bloch, Leon Romanovsky, Andrew Lunn, "David S. Miller", Eric Dumazet, Jakub Kicinski, Paolo Abeni, Linus Torvalds

On CQE_TLS_OFFLOAD_ERROR the device could not authenticate the record's
payload. Depending on where the failure occurred the bytes may have been
transformed (XORed) or left as wire ciphertext, so set the new
skb->decrypt_failed bit (skb->decrypted stays clear) to let the stack
tell the two cases apart, and fall through to the existing tls_err
accounting.

This is consumed by TLS 1.3 device-offload RX KeyUpdate support in a
following patch: the re-encrypt path undoes the transform on any XORed
frag of a mixed record while software re-authenticates, while a
non-mixed record stays wire ciphertext and is decrypted directly.
Without that consumer the flag is simply ignored.

Signed-off-by: Rishikesh Jethwani <redacted>
---
 .../ethernet/mellanox/mlx5/core/en_accel/ktls_rx.c  | 13 ++++++++++++-
 1 file changed, 12 insertions(+), 1 deletion(-)
diff --git a/drivers/net/ethernet/mellanox/mlx5/core/en_accel/ktls_rx.c b/drivers/net/ethernet/mellanox/mlx5/core/en_accel/ktls_rx.c
index bca45679e201..8ec40f5fd5b5 100644
--- a/drivers/net/ethernet/mellanox/mlx5/core/en_accel/ktls_rx.c
+++ b/drivers/net/ethernet/mellanox/mlx5/core/en_accel/ktls_rx.c
@@ -602,7 +602,18 @@ void mlx5e_ktls_handle_rx_skb(struct mlx5e_rq *rq, struct sk_buff *skb,
 		stats->tls_resync_req_pkt++;
 		resync_update_sn(rq, skb);
 		break;
-	default: /* CQE_TLS_OFFLOAD_ERROR: */
+	case CQE_TLS_OFFLOAD_ERROR:
+		/* The device could not authenticate the payload. Depending on
+		 * where the failure occurred the bytes may have been transformed
+		 * (XORed) or left as wire ciphertext. Flag it so that, during a
+		 * TLS 1.3 rekey transition, the re-encrypt path undoes the
+		 * transform on any XORed frag of a mixed record while software
+		 * re-authenticates; a non-mixed record stays wire ciphertext and
+		 * is decrypted directly.
+		 */
+		skb->decrypt_failed = 1;
+		fallthrough;
+	default: /* CQE_TLS_OFFLOAD_NOT_DECRYPTED: */
 		stats->tls_err++;
 		break;
 	}
-- 
2.50.1
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help