From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pl1-f178.google.com (mail-pl1-f178.google.com [209.85.214.178]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E3536371CEC for ; Wed, 20 May 2026 08:10:26 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.178 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779264628; cv=none; b=KX/foO/T16Vk3Sp+EUmZesX8nL+vNGnXcWwtmGzNjlnm/Rm3lrQvq+lxv6miit2DqQRVX9BwsTst6tAh3Sdfi/kPwLibjumvvUQ2wlCiJ0wPc9awq2cbHeilExxd5X9pYSTAytWuxi0LEatps25OpC4oCAzYxdAKIFJSKnNoPQM= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779264628; c=relaxed/simple; bh=ysrlFQYbnqdUZbioXLpDwJFsDqDNBDcsFeVNdyXQbLU=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=KhBq2Q90DcZukrypVdtctgpCrAeffng4qYJTW2Wtaf/dk7ENL/U5UZpwNX436jx1TH9Nno3xChNUFTFE6Y5fC9K235mGjx2KgU/iEmovgMI6Fb39UOp2pcPf0uG4GTLR3FYrBuGNxvJx5CkmxShRKdmGdGrlOHnmKtqZdS0Z6z4= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=lIt2rD2G; arc=none smtp.client-ip=209.85.214.178 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="lIt2rD2G" Received: by mail-pl1-f178.google.com with SMTP id d9443c01a7336-2b4583f0a1aso29063025ad.3 for ; Wed, 20 May 2026 01:10:26 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1779264626; x=1779869426; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to; bh=zT9gW4My9WtjCFzxGL2IvZPJb7xvVTH1VSTzTxzzIek=; b=lIt2rD2GFOU9KCfnOhLc8kCfVdqHqy897uq07T0pdkItlRh6Zp93x4pdjtYwfLatGa cdu2lYEkFpFwMt0KoU8Xs2lOnWL+yBvxReCY3SqJ0ktwORroO+A7dXt58ovVgLVrHW9x 8EQgFIP+kk1Z1k4n41vvL8q/xtYG0ZbGoYeEU8Eir66fqQPEBNV7b6jRmRv0ttp7kJ4K gkW24LiNseka3sr6EI5wQcJMlDXIhtOB3IZXPAyjWdyKVAw0T6iJHsIQd3urOKPnmBX6 zwYHRpVgIHaADaZLQ5jkQ8X69yNS4CpD0iY3Bw2FH9FN4mumcSQ0qXY3CwJwe+XZB10w BXvA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1779264626; x=1779869426; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=zT9gW4My9WtjCFzxGL2IvZPJb7xvVTH1VSTzTxzzIek=; b=geuz+zSl3Y3bcXrFFMKPZMSkxu/pQXxzRcaDZEC3dHR8O5iXfklwCjfOMC8TgRSajp MDB+YRaz4KGmBbCXoLy0Iv9uGbuLg1aR8N5iIuY8KQaWT9D5fOnSH+9o8CuaVAu256Vj cXqWHjYav7i6ToMQFq9AaZWrmchGspc+m9O9jZVCbcuZ5f8v9TQdb9810pO2VA2XFzK3 6kfKU825kyXKo9Fi5LuSPST9hiTriO830rfaz2VOQH1CosASGi0ue48MLaYxQ9YBuwNe lK+Cexb7o9J83sojkjEi44wFfRUPIN6PLTyY73fPijhwf32o+fINZWmT71q83b38bZKH yWrg== X-Forwarded-Encrypted: i=1; AFNElJ8uW1WGIQYQIak1turDO+W7XR8HXND/QM1fuvHBfZB3LJ1Qe07UhQ1gIJjGX1iu8evJPa5r2rORpdgEVEs=@vger.kernel.org X-Gm-Message-State: AOJu0Yx/Ahj4/a7FqxZRiemDo0AgEHPzcifyVA4YdhbeOZ3qa2cr8Va9 JWl/k6sneKdPrL1JbasEs2wdO3lpb0FFJdFSkWW+i3gJPX/1OqF5XDz+ X-Gm-Gg: Acq92OGzw0bbfxmGyAqz399QQULffSYjlgAOy2RMVq0kuJ5DGOV4ZayowPEdsRWI7zS F+8LPPOmj/GjkMJNTDQwaYneQha/StQpjTLT1uNfPVFkKjVPfUUD9Cb2i/dWbobj0K1LLqYiHgc fxnCVaPod8CI2BQWW2p/XwfOd1yJCoGrsCtZDkoRp3NS/iXNf7E7h4MSAYh1kHj19upaDgjWdkS q1+htPL4aTzNofLzHikGsoGuF69mJMS7N2eM71CZuq/DNsO+4wsuRqWTstd5s/0syqHGdSpiNLe Vx2eRevQRDOsu/w6Ub3QcwYteGlpPMKUCnYnt8Bp2kSApOP+NeeQNUWw3hb4tm98QFET8L0AW23 Z0+Qxepo1o6tod1PLyocERdOJxBj0Nd+YVNgauneLsZ7gkwFUmqMGmSZVbappVZrC11WIZdkPSP cJj7ffZhiZWOTA0bSjjl81 X-Received: by 2002:a17:902:d2cf:b0:2ba:6bd7:8f00 with SMTP id d9443c01a7336-2bd7e78228cmr241655625ad.5.1779264626117; Wed, 20 May 2026 01:10:26 -0700 (PDT) Received: from mincom1 ([14.67.155.25]) by smtp.gmail.com with ESMTPSA id d9443c01a7336-2bd5d116287sm211632735ad.68.2026.05.20.01.10.23 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 20 May 2026 01:10:25 -0700 (PDT) From: Jihong Min To: netdev@vger.kernel.org Cc: Jay Vosburgh , Andrew Lunn , "David S. Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Simon Horman , Steffen Klassert , Herbert Xu , linux-kernel@vger.kernel.org, Jihong Min Subject: [PATCH RFC net-next 0/4] bonding: support LAG IPsec offload with replicated SAs Date: Wed, 20 May 2026 17:10:00 +0900 Message-ID: <20260520081004.2232091-1-hurryman2212@gmail.com> X-Mailer: git-send-email 2.53.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit This RFC adds a bonding model for IPsec/XFRM hardware offload on 802.3ad and balance-xor LAG devices when the transmit hash policy is layer3+4. This is an intentional scope limit rather than a hard limit, as this is the configuration I can test with my gear. The main idea is to leave the existing upstream single-lower-device XFRM offload path for active-backup intentionally untouched, while adding a replicated state model for LAG. For LAG bonds, the bonding driver installs the same XFRM state on every eligible running slave and stores the per-slave hardware handles in bonding-private state. Lower drivers that support this model can then resolve the handle for the concrete lower netdev used by the datapath. LAG IPsec features are user controlled. Newly eligible LAG bonds start with the ESP/XFRM features disabled, but advertise supported mutable features when all running eligible slaves can support them. Users can then opt in with ethtool. Feature enable is propagated to the lower devices and rolled back if a lower device cannot enable the requested features. The series also handles LAG membership and eligibility changes by adding replicated SAs to newly usable slaves, removing the departing lower instance on down/remove, and flushing bond-owned XFRM offload state when the bond leaves the supported mode or hash-policy configuration. This series does not convert any physical NIC driver. A lower driver must explicitly opt in to the replicated-upper-device model before it can use these bond-owned states in its datapath. For example, a driver such as mlx5 would opt in by marking its xfrmdev_ops and by resolving datapath handles through the helper: static const struct xfrmdev_ops mlx5e_ipsec_xfrmdev_ops = { ... .xdo_dev_state_lower_handle = NULL, .flags = XFRMDEV_OPS_F_LOWER_HANDLE, }; handle = xfrm_dev_state_lower_handle(x, netdev); if (!handle) goto drop; sa_entry = (struct mlx5e_ipsec_sa_entry *)handle; Jihong Min (4): xfrm: add a lower-device offload handle resolver bonding: replicate XFRM offload state across LAG slaves bonding: expose user-controlled IPsec features for LAG bonding: handle replicated IPsec SAs across LAG changes drivers/net/bonding/bond_main.c | 855 ++++++++++++++++++++++++++++- drivers/net/bonding/bond_options.c | 59 +- include/linux/netdevice.h | 27 + include/net/bonding.h | 29 +- include/net/xfrm.h | 48 +- net/xfrm/xfrm_state.c | 1 + 6 files changed, 1000 insertions(+), 19 deletions(-) base-commit: 27fa82620cbaa89a7fc11ac3057701d598813e87 -- 2.53.0