From: Tariq Toukan <tariqt@nvidia.com>
To: Eric Dumazet <edumazet@google.com>,
Jakub Kicinski <kuba@kernel.org>, Paolo Abeni <pabeni@redhat.com>,
Andrew Lunn <andrew+netdev@lunn.ch>,
"David S. Miller" <davem@davemloft.net>
Cc: Saeed Mahameed <saeedm@nvidia.com>,
Leon Romanovsky <leon@kernel.org>,
Tariq Toukan <tariqt@nvidia.com>, Mark Bloch <mbloch@nvidia.com>,
<netdev@vger.kernel.org>, <linux-rdma@vger.kernel.org>,
<linux-kernel@vger.kernel.org>, Gal Pressman <gal@nvidia.com>,
Moshe Shemesh <moshe@nvidia.com>,
Breno Leitao <leitao@debian.org>,
Alexandre Cassen <acassen@corp.free.fr>,
Jianbo Liu <jianbol@nvidia.com>
Subject: [PATCH net 6/9] net/mlx5e: Use ip6_dst_lookup instead of ipv6_dst_lookup_flow for MAC init
Date: Tue, 9 Dec 2025 14:56:14 +0200 [thread overview]
Message-ID: <1765284977-1363052-7-git-send-email-tariqt@nvidia.com> (raw)
In-Reply-To: <1765284977-1363052-1-git-send-email-tariqt@nvidia.com>
From: Jianbo Liu <jianbol@nvidia.com>
Replace ipv6_stub->ipv6_dst_lookup_flow() with ip6_dst_lookup() in
mlx5e_ipsec_init_macs() since IPsec transformations are not needed
during Security Association setup - only basic routing information is
required for nexthop MAC address resolution.
This resolves an issue where XfrmOutNoStates error counter would be
incremented when xfrm policy is configured before xfrm state, as the
IPsec-aware routing function would attempt policy checks during SA
initialization.
Fixes: 71670f766b8f ("net/mlx5e: Support routed networks during IPsec MACs initialization")
Signed-off-by: Jianbo Liu <jianbol@nvidia.com>
Reviewed-by: Leon Romanovsky <leonro@nvidia.com>
Signed-off-by: Tariq Toukan <tariqt@nvidia.com>
---
drivers/net/ethernet/mellanox/mlx5/core/en_accel/ipsec.c | 5 ++---
1 file changed, 2 insertions(+), 3 deletions(-)
diff --git a/drivers/net/ethernet/mellanox/mlx5/core/en_accel/ipsec.c b/drivers/net/ethernet/mellanox/mlx5/core/en_accel/ipsec.c
index 35d9530037a6..6c79b9cea2ef 100644
--- a/drivers/net/ethernet/mellanox/mlx5/core/en_accel/ipsec.c
+++ b/drivers/net/ethernet/mellanox/mlx5/core/en_accel/ipsec.c
@@ -342,9 +342,8 @@ static void mlx5e_ipsec_init_macs(struct mlx5e_ipsec_sa_entry *sa_entry,
rt_dst_entry = &rt->dst;
break;
case AF_INET6:
- rt_dst_entry = ipv6_stub->ipv6_dst_lookup_flow(
- dev_net(netdev), NULL, &fl6, NULL);
- if (IS_ERR(rt_dst_entry))
+ if (!IS_ENABLED(CONFIG_IPV6) ||
+ ip6_dst_lookup(dev_net(netdev), NULL, &rt_dst_entry, &fl6))
goto neigh;
break;
default:
--
2.31.1
next prev parent reply other threads:[~2025-12-09 12:57 UTC|newest]
Thread overview: 11+ messages / expand[flat|nested] mbox.gz Atom feed top
2025-12-09 12:56 [PATCH net 0/9] mlx5 misc fixes 2025-12-09 Tariq Toukan
2025-12-09 12:56 ` [PATCH net 1/9] net/mlx5: fw reset, clear reset requested on drain_fw_reset Tariq Toukan
2025-12-09 12:56 ` [PATCH net 2/9] net/mlx5: Drain firmware reset in shutdown callback Tariq Toukan
2025-12-09 12:56 ` [PATCH net 3/9] net/mlx5: fw_tracer, Validate format string parameters Tariq Toukan
2025-12-09 12:56 ` [PATCH net 4/9] net/mlx5: fw_tracer, Handle escaped percent properly Tariq Toukan
2025-12-09 12:56 ` [PATCH net 5/9] net/mlx5: Serialize firmware reset with devlink Tariq Toukan
2025-12-09 12:56 ` Tariq Toukan [this message]
2025-12-09 12:56 ` [PATCH net 7/9] net/mlx5e: Trigger neighbor resolution for unresolved destinations Tariq Toukan
2025-12-09 12:56 ` [PATCH net 8/9] net/mlx5e: Do not update BQL of old txqs during channel reconfiguration Tariq Toukan
2025-12-09 12:56 ` [PATCH net 9/9] net/mlx5e: Don't include PSP in the hard MTU calculations Tariq Toukan
2025-12-18 13:00 ` [PATCH net 0/9] mlx5 misc fixes 2025-12-09 patchwork-bot+netdevbpf
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1765284977-1363052-7-git-send-email-tariqt@nvidia.com \
--to=tariqt@nvidia.com \
--cc=acassen@corp.free.fr \
--cc=andrew+netdev@lunn.ch \
--cc=davem@davemloft.net \
--cc=edumazet@google.com \
--cc=gal@nvidia.com \
--cc=jianbol@nvidia.com \
--cc=kuba@kernel.org \
--cc=leitao@debian.org \
--cc=leon@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-rdma@vger.kernel.org \
--cc=mbloch@nvidia.com \
--cc=moshe@nvidia.com \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=saeedm@nvidia.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®