IB/core: IB cache enhancements to support Infiniband security
Cache the subnet prefix and add a function to access it. Enforcing security requires frequent queries of the subnet prefix and the pkeys in the pkey table. Signed-off-by: Daniel Jurgens <danielj@mellanox.com> Reviewed-by: Eli Cohen <eli@mellanox.com> Reviewed-by: Leon Romanovsky <leonro@mellanox.com> Reviewed-by: James Morris <james.l.morris@oracle.com> Acked-by: Doug Ledford <dledford@redhat.com> Signed-off-by: Paul Moore <paul@paul-moore.com>
This commit is contained in:

committed by
Paul Moore

parent
270e857314
commit
883c71feaf
@@ -911,6 +911,26 @@ int ib_get_cached_pkey(struct ib_device *device,
|
|||||||
}
|
}
|
||||||
EXPORT_SYMBOL(ib_get_cached_pkey);
|
EXPORT_SYMBOL(ib_get_cached_pkey);
|
||||||
|
|
||||||
|
int ib_get_cached_subnet_prefix(struct ib_device *device,
|
||||||
|
u8 port_num,
|
||||||
|
u64 *sn_pfx)
|
||||||
|
{
|
||||||
|
unsigned long flags;
|
||||||
|
int p;
|
||||||
|
|
||||||
|
if (port_num < rdma_start_port(device) ||
|
||||||
|
port_num > rdma_end_port(device))
|
||||||
|
return -EINVAL;
|
||||||
|
|
||||||
|
p = port_num - rdma_start_port(device);
|
||||||
|
read_lock_irqsave(&device->cache.lock, flags);
|
||||||
|
*sn_pfx = device->cache.ports[p].subnet_prefix;
|
||||||
|
read_unlock_irqrestore(&device->cache.lock, flags);
|
||||||
|
|
||||||
|
return 0;
|
||||||
|
}
|
||||||
|
EXPORT_SYMBOL(ib_get_cached_subnet_prefix);
|
||||||
|
|
||||||
int ib_find_cached_pkey(struct ib_device *device,
|
int ib_find_cached_pkey(struct ib_device *device,
|
||||||
u8 port_num,
|
u8 port_num,
|
||||||
u16 pkey,
|
u16 pkey,
|
||||||
@@ -1108,6 +1128,8 @@ static void ib_cache_update(struct ib_device *device,
|
|||||||
device->cache.ports[port - rdma_start_port(device)].port_state =
|
device->cache.ports[port - rdma_start_port(device)].port_state =
|
||||||
tprops->state;
|
tprops->state;
|
||||||
|
|
||||||
|
device->cache.ports[port - rdma_start_port(device)].subnet_prefix =
|
||||||
|
tprops->subnet_prefix;
|
||||||
write_unlock_irq(&device->cache.lock);
|
write_unlock_irq(&device->cache.lock);
|
||||||
|
|
||||||
kfree(gid_cache);
|
kfree(gid_cache);
|
||||||
|
@@ -176,4 +176,7 @@ int ib_nl_handle_set_timeout(struct sk_buff *skb,
|
|||||||
int ib_nl_handle_ip_res_resp(struct sk_buff *skb,
|
int ib_nl_handle_ip_res_resp(struct sk_buff *skb,
|
||||||
struct netlink_callback *cb);
|
struct netlink_callback *cb);
|
||||||
|
|
||||||
|
int ib_get_cached_subnet_prefix(struct ib_device *device,
|
||||||
|
u8 port_num,
|
||||||
|
u64 *sn_pfx);
|
||||||
#endif /* _CORE_PRIV_H */
|
#endif /* _CORE_PRIV_H */
|
||||||
|
@@ -1891,6 +1891,7 @@ enum ib_mad_result {
|
|||||||
};
|
};
|
||||||
|
|
||||||
struct ib_port_cache {
|
struct ib_port_cache {
|
||||||
|
u64 subnet_prefix;
|
||||||
struct ib_pkey_cache *pkey;
|
struct ib_pkey_cache *pkey;
|
||||||
struct ib_gid_table *gid;
|
struct ib_gid_table *gid;
|
||||||
u8 lmc;
|
u8 lmc;
|
||||||
|
Reference in New Issue
Block a user