mbox series

pull request (net-next): ipsec-next 2017-12-15

Message ID 20171215121952.20745-1-steffen.klassert@secunet.com
State Accepted, archived
Delegated to: David Miller
Headers show
Series pull request (net-next): ipsec-next 2017-12-15 | expand

Pull-request

git://git.kernel.org/pub/scm/linux/kernel/git/klassert/ipsec-next.git master

Message

Steffen Klassert Dec. 15, 2017, 12:19 p.m. UTC
1) Currently we can add or update socket policies, but
   not clear them. Support clearing of socket policies
   too. From Lorenzo Colitti.

2) Add documentation for the xfrm device offload api.
   From Shannon Nelson.

3) Fix IPsec extended sequence numbers (ESN) for
   IPsec offloading. From Yossef Efraim.

4) xfrm_dev_state_add function returns success even for
   unsupported options, fix this to fail in such cases.
   From Yossef Efraim.

5) Remove a redundant xfrm_state assignment.
   From Aviv Heller.

Please pull or let me know if there are problems.

Thanks!

The following changes since commit b9151761021e25c024a6670df4e7c43ffbab0e1d:

  Merge tag 'nfsd-4.15-1' of git://linux-nfs.org/~bfields/linux (2017-11-29 14:49:26 -0800)

are available in the git repository at:

  git://git.kernel.org/pub/scm/linux/kernel/git/klassert/ipsec-next.git master

for you to fetch changes up to 9b7e14dba0c087e950fc024b486e8f729c1ee672:

  xfrm: Remove redundant state assignment in xfrm_input() (2017-12-01 07:41:48 +0100)

----------------------------------------------------------------
Aviv Heller (1):
      xfrm: Remove redundant state assignment in xfrm_input()

Lorenzo Colitti (1):
      net: xfrm: allow clearing socket xfrm policies.

Shannon Nelson (1):
      xfrm: add documentation for xfrm device offload api

Yossef Efraim (2):
      xfrm: Fix xfrm_replay_overflow_offload_esn
      xfrm: Fix xfrm_dev_state_add to fail for unsupported HW SA option

 Documentation/networking/00-INDEX        |   2 +
 Documentation/networking/xfrm_device.txt | 132 +++++++++++++++++++++++++++++++
 net/xfrm/xfrm_device.c                   |   2 +-
 net/xfrm/xfrm_input.c                    |   1 -
 net/xfrm/xfrm_policy.c                   |   2 +-
 net/xfrm/xfrm_replay.c                   |   3 +-
 net/xfrm/xfrm_state.c                    |   7 ++
 7 files changed, 144 insertions(+), 5 deletions(-)
 create mode 100644 Documentation/networking/xfrm_device.txt

Comments

David Miller Dec. 15, 2017, 4:10 p.m. UTC | #1
From: Steffen Klassert <steffen.klassert@secunet.com>
Date: Fri, 15 Dec 2017 13:19:47 +0100

> 1) Currently we can add or update socket policies, but
>    not clear them. Support clearing of socket policies
>    too. From Lorenzo Colitti.
> 
> 2) Add documentation for the xfrm device offload api.
>    From Shannon Nelson.
> 
> 3) Fix IPsec extended sequence numbers (ESN) for
>    IPsec offloading. From Yossef Efraim.
> 
> 4) xfrm_dev_state_add function returns success even for
>    unsupported options, fix this to fail in such cases.
>    From Yossef Efraim.
> 
> 5) Remove a redundant xfrm_state assignment.
>    From Aviv Heller.
> 
> Please pull or let me know if there are problems.

Pulled, thank you Steffen.