On CQE_TLS_OFFLOAD_ERROR the device could not authenticate the record's
payload. Depending on where the failure occurred the bytes may have been
transformed (XORed) or left as wire ciphertext, so set the new
skb->decrypt_failed bit (skb->decrypted stays clear) to let the stack
tell the two cases apart, and fall through to the existing tls_err
accounting.
This is consumed by TLS 1.3 device-offload RX KeyUpdate support in a
following patch: the re-encrypt path undoes the transform on any XORed
frag of a mixed record while software re-authenticates, while a
non-mixed record stays wire ciphertext and is decrypted directly.
Without that consumer the flag is simply ignored.
Signed-off-by: Rishikesh Jethwani <redacted>
---
.../ethernet/mellanox/mlx5/core/en_accel/ktls_rx.c | 13 ++++++++++++-
1 file changed, 12 insertions(+), 1 deletion(-)
diff --git a/drivers/net/ethernet/mellanox/mlx5/core/en_accel/ktls_rx.c b/drivers/net/ethernet/mellanox/mlx5/core/en_accel/ktls_rx.c
index bca45679e201..8ec40f5fd5b5 100644
--- a/drivers/net/ethernet/mellanox/mlx5/core/en_accel/ktls_rx.c
+++ b/drivers/net/ethernet/mellanox/mlx5/core/en_accel/ktls_rx.c
@@ -602,7 +602,18 @@ void mlx5e_ktls_handle_rx_skb(struct mlx5e_rq *rq, struct sk_buff *skb,
stats->tls_resync_req_pkt++;
resync_update_sn(rq, skb);
break;
- default: /* CQE_TLS_OFFLOAD_ERROR: */
+ case CQE_TLS_OFFLOAD_ERROR:
+ /* The device could not authenticate the payload. Depending on
+ * where the failure occurred the bytes may have been transformed
+ * (XORed) or left as wire ciphertext. Flag it so that, during a
+ * TLS 1.3 rekey transition, the re-encrypt path undoes the
+ * transform on any XORed frag of a mixed record while software
+ * re-authenticates; a non-mixed record stays wire ciphertext and
+ * is decrypted directly.
+ */
+ skb->decrypt_failed = 1;
+ fallthrough;
+ default: /* CQE_TLS_OFFLOAD_NOT_DECRYPTED: */
stats->tls_err++;
break;
}
--
2.50.1