No description
  • C 96.9%
  • Assembly 0.9%
  • Rust 0.6%
  • Shell 0.6%
  • Python 0.5%
  • Other 0.3%
Find a file
Jakub Kicinski 71af6a2ddf mlx5-updates-2023-01-30
Add fast update encryption key
 
 Jianbo Liu Says:
 ================
 
 Data encryption keys (DEKs) are the keys used for data encryption and
 decryption operations. Starting from version 22.33.0783, firmware is
 optimized to accelerate the update of user keys into DEK object in
 hardware. The support for bulk allocation and destruction of DEK
 objects is added, and the bulk allocated DEKs are uninitialized, as
 the bulk creation requires no input key. When offload
 encryption/decryption, user gets one object from a bulk, and updates
 key by a new "modify DEK" command. This command is the same as create
 DEK object, but requires no heavy context memory allocation in
 firmware, which consumes most cpu cycles of the create DEK command.
 
 DEKs are cached internally by the NIC, so invalidating internal NIC
 caches is required before reusing DEKs. The SYNC_CRYPTO command is
 added to support it. DEK object can be reused, the keys in it can be
 updated after this command is executed.
 
 This patchset enhances the key creation and destruction flow, to get
 use of this new feature. Any user, for example, ktls, ipsec and
 macsec, can use it to offload keys. But, only ktls uses it, as others
 don't need many keys, and caching two many DEKs in pool is wasteful.
 
 There are two new data struts added:
     a. DEK pool. One pool is created for each key type. The bulks by
 the type, are placed in the pool's different bulk lists, according to
 the number of available and in_used DEKs in the bulk.
     b. DEK bulk. All DEKs in one bulk allocation are store here. There
 are two bitmaps to indicate the state of each DEK.
 
 New APIs are then added. When user need a DEK object,
     a. Fetch one bulk with avail DEKs, from the partial_list or
 avail_list, otherwise create new one.
     b. Pick one DEK, and set its need_sync and in_used bits to 1.
 Move the bulk to full_list if no more available keys, or put it to
 partial_list if the bulk is newly created.
     c. Update DEK object's key with user key, by the "modify DEK"
 command.
     d. Return DEK struct to user, then it gets the object id and fills
 it into the offload commands.
 When user free a DEK,
     a. Set in_use bit to 0. If all need_sync bits are 1 and all in_use
 bits of this bulk are 0, move it to sync_list.
     b. If the number of DEKs, which are freed by users, is over the
 threshold (128), schedule a workqueue to do the sync process.
 
 For the sync process, the SYNC_CRYPTO command is executed first. Then,
 for each bulks in partial_list, full_list and sync_list, reset
 need_sync bits of the freed DEK objects. If all need_sync bits in one
 bulk are zero, move it to avail_list.
 
 We already supported TIS pool to recycle the TISes. With this series
 and TIS pool, TLS CPS performance is improved greatly.
 And we tested https on the system:
     CPU: dual AMD EPYC 7763 64-Core processors
     RAM: 512G
     DEV: ConnectX-6 DX, with FW ver 22.33.0838 and TLS_OPTIMISE=true
 TLS CPS performance numbers are:
     Before: 11k connections/sec
     After: 101 connections/sec
 
 ================
 -----BEGIN PGP SIGNATURE-----
 
 iQEzBAABCAAdFiEEGhZs6bAKwk/OTgTpSD+KveBX+j4FAmPYho4ACgkQSD+KveBX
 +j4tmQf/UnDnj55lf7zxvDYCgIThSFeqIPCnwnbRRTPB85jsjsBMx+52ugYGJ5kZ
 Mci93QfkDoIEAAamBwj76X3skobmsdKZsOmFyLKpfWBz6K98EZVC7nAPPRO9o80Z
 YGQQAbUn8I/USC0cB2BICCnjkbcpeMUgYYqnLteBsKBiH3IkMoEtkeaWN0M3SHK/
 xKLZwlpX+2gIotr6h2ftd8B8ygL1CSyMTqIp0vrSQY69ucTpgtsbDufODbU58p7n
 JUOVtNM5irwi2QdfSJjPAc1vMkkVJYCGbE1mxMjbKyDOMEnK5vIiMgb7RWRSMbdC
 FzSY0/vQxFoOB21+CeiGN/rPvMnRCA==
 =/Cb4
 -----END PGP SIGNATURE-----

Merge tag 'mlx5-updates-2023-01-30' of git://git.kernel.org/pub/scm/linux/kernel/git/saeed/linux

Saeed Mahameed says:

====================
mlx5-updates-2023-01-30

Add fast update encryption key

Jianbo Liu Says:
================

Data encryption keys (DEKs) are the keys used for data encryption and
decryption operations. Starting from version 22.33.0783, firmware is
optimized to accelerate the update of user keys into DEK object in
hardware. The support for bulk allocation and destruction of DEK
objects is added, and the bulk allocated DEKs are uninitialized, as
the bulk creation requires no input key. When offload
encryption/decryption, user gets one object from a bulk, and updates
key by a new "modify DEK" command. This command is the same as create
DEK object, but requires no heavy context memory allocation in
firmware, which consumes most cpu cycles of the create DEK command.

DEKs are cached internally by the NIC, so invalidating internal NIC
caches is required before reusing DEKs. The SYNC_CRYPTO command is
added to support it. DEK object can be reused, the keys in it can be
updated after this command is executed.

This patchset enhances the key creation and destruction flow, to get
use of this new feature. Any user, for example, ktls, ipsec and
macsec, can use it to offload keys. But, only ktls uses it, as others
don't need many keys, and caching two many DEKs in pool is wasteful.

There are two new data struts added:
    a. DEK pool. One pool is created for each key type. The bulks by
the type, are placed in the pool's different bulk lists, according to
the number of available and in_used DEKs in the bulk.
    b. DEK bulk. All DEKs in one bulk allocation are store here. There
are two bitmaps to indicate the state of each DEK.

New APIs are then added. When user need a DEK object,
    a. Fetch one bulk with avail DEKs, from the partial_list or
avail_list, otherwise create new one.
    b. Pick one DEK, and set its need_sync and in_used bits to 1.
Move the bulk to full_list if no more available keys, or put it to
partial_list if the bulk is newly created.
    c. Update DEK object's key with user key, by the "modify DEK"
command.
    d. Return DEK struct to user, then it gets the object id and fills
it into the offload commands.
When user free a DEK,
    a. Set in_use bit to 0. If all need_sync bits are 1 and all in_use
bits of this bulk are 0, move it to sync_list.
    b. If the number of DEKs, which are freed by users, is over the
threshold (128), schedule a workqueue to do the sync process.

For the sync process, the SYNC_CRYPTO command is executed first. Then,
for each bulks in partial_list, full_list and sync_list, reset
need_sync bits of the freed DEK objects. If all need_sync bits in one
bulk are zero, move it to avail_list.

We already supported TIS pool to recycle the TISes. With this series
and TIS pool, TLS CPS performance is improved greatly.
And we tested https on the system:
    CPU: dual AMD EPYC 7763 64-Core processors
    RAM: 512G
    DEV: ConnectX-6 DX, with FW ver 22.33.0838 and TLS_OPTIMISE=true
TLS CPS performance numbers are:
    Before: 11k connections/sec
    After: 101 connections/sec

================

* tag 'mlx5-updates-2023-01-30' of git://git.kernel.org/pub/scm/linux/kernel/git/saeed/linux:
  net/mlx5e: kTLS, Improve connection rate by using fast update encryption key
  net/mlx5: Keep only one bulk of full available DEKs
  net/mlx5: Add async garbage collector for DEK bulk
  net/mlx5: Reuse DEKs after executing SYNC_CRYPTO command
  net/mlx5: Use bulk allocation for fast update encryption key
  net/mlx5: Add bulk allocation and modify_dek operation
  net/mlx5: Add support SYNC_CRYPTO command
  net/mlx5: Add new APIs for fast update encryption key
  net/mlx5: Refactor the encryption key creation
  net/mlx5: Add const to the key pointer of encryption key creation
  net/mlx5: Prepare for fast crypto key update if hardware supports it
  net/mlx5: Change key type to key purpose
  net/mlx5: Add IFC bits and enums for crypto key
  net/mlx5: Add IFC bits for general obj create param
  net/mlx5: Header file for crypto
====================

Link: https://lore.kernel.org/r/20230131031201.35336-1-saeed@kernel.org
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
History 2023-01-31 21:35:34 -08:00
arch sh: checksum: add missing linux/uaccess.h include 2023-01-30 21:04:21 -08:00
block block-6.2-2023-01-20 2023-01-20 12:44:41 -08:00
certs certs: make system keyring depend on built-in x509 parser 2022-09-24 04:31:18 +09:00
crypto wifi: cfg80211: Deduplicate certificate loading 2023-01-19 14:46:45 +01:00
Documentation dt-bindings: net: add amlogic gxl mdio multiplexer 2023-01-31 20:59:07 -08:00
drivers mlx5-updates-2023-01-30 2023-01-31 21:35:34 -08:00
fs Merge git://git.kernel.org/pub/scm/linux/kernel/git/netdev/net 2023-01-27 22:56:18 -08:00
include mlx5-updates-2023-01-30 2023-01-31 21:35:34 -08:00
init bpf-next-for-netdev 2023-01-28 00:00:14 -08:00
io_uring io_uring/poll: don't reissue in case of poll race on multishot request 2023-01-20 15:11:54 -07:00
ipc Non-MM patches for 6.2-rc1. 2022-12-12 17:28:58 -08:00
kernel bpf-next-for-netdev 2023-01-28 00:00:14 -08:00
lib bpf-next-for-netdev 2023-01-28 00:00:14 -08:00
LICENSES LICENSES: Add the copyleft-next-0.3.1 license 2022-11-08 15:44:01 +01:00
mm slab fixes for 6.2-rc5 2023-01-19 12:24:39 -08:00
net devlink: remove devlink features 2023-01-30 08:37:46 +00:00
rust rust: print: avoid evaluating arguments in pr_* macros in unsafe blocks 2023-01-16 00:54:35 +01:00
samples samples/bpf: change _kern suffix to .bpf with BPF test programs 2023-01-15 13:32:45 -08:00
scripts bpf-next-for-netdev 2023-01-28 00:00:14 -08:00
security tomoyo: Update website link 2023-01-13 23:11:38 +09:00
sound treewide: fix up files incorrectly marked executable 2023-01-26 10:05:39 -08:00
tools selftests: net: forwarding: lib: Drop lldpad_app_wait_set(), _del() 2023-01-31 21:02:11 -08:00
usr usr/gen_init_cpio.c: remove unnecessary -1 values from int file 2022-10-03 14:21:44 -07:00
virt VFIO fixes for v6.2-rc6 2023-01-23 11:56:07 -08:00
.clang-format iommufd for 6.2 2022-12-14 09:15:43 -08:00
.cocciconfig scripts: add Linux .cocciconfig for coccinelle 2016-07-22 12:13:39 +02:00
.get_maintainer.ignore get_maintainer: add Alan to .get_maintainer.ignore 2022-08-20 15:17:44 -07:00
.gitattributes .gitattributes: use 'dts' diff driver for dts files 2019-12-04 19:44:11 -08:00
.gitignore .gitignore: ignore *.rpm 2022-12-30 17:22:14 +09:00
.mailmap 21 hotfixes. Thirteen of these address pre-6.1 issues and hence have 2023-01-16 16:36:39 -08:00
.rustfmt.toml rust: add .rustfmt.toml 2022-09-28 09:02:20 +02:00
COPYING COPYING: state that all contributions really are covered by this file 2020-02-10 13:32:20 -08:00
CREDITS MAINTAINERS: Update MPTCP maintainer list and CREDITS 2023-01-23 21:42:13 -08:00
Kbuild Kbuild updates for v6.1 2022-10-10 12:00:45 -07:00
Kconfig kbuild: ensure full rebuild when the compiler is updated 2020-05-12 13:28:33 +09:00
MAINTAINERS net: dsa: ocelot: add external ocelot switch control 2023-01-30 21:07:21 -08:00
Makefile Linux 6.2-rc5 2023-01-21 16:27:01 -08:00
README Drop all 00-INDEX files from Documentation/ 2018-09-09 15:08:58 -06:00

Linux kernel
============

There are several guides for kernel developers and users. These guides can
be rendered in a number of formats, like HTML and PDF. Please read
Documentation/admin-guide/README.rst first.

In order to build the documentation, use ``make htmldocs`` or
``make pdfdocs``.  The formatted documentation can also be read online at:

    https://www.kernel.org/doc/html/latest/

There are various text files in the Documentation/ subdirectory,
several of them using the Restructured Text markup notation.

Please read the Documentation/process/changes.rst file, as it contains the
requirements for building and running the kernel, and information about
the problems which may result by upgrading your kernel.