Benoit and Fan, thanks for your review comments. I think I have addressed almost all of them - new patchset is doing the CI dance now.
What is the correct protocol for marking gerrit comments as "done"? Should I mark them done after submitting updated code, or does the original commenter do that? I reworked the buffer metadata usage a bit so that this change no longer consumes a vnet flag. I haven't yet shifted the code that is currently in plugins/iptfs to be in, for example, vnet/ipsec/iptfs. Should we resolve any issues with the current change set first? Should I plan to incorporate the (approximately 20) files of plugins/iptfs into vnet/ipsec/iptfs as part of this existing gerrit change, or as a separate gerrit change? thanks, ~!paul [email protected] ("Benoit Ganne (bganne) via lists.fd.io") writes: >--r2AfvxxR4H750F9LXHl8 >Content-Language: en-US >Content-Type: text/plain; charset="us-ascii" >Content-Transfer-Encoding: quoted-printable >Hi Paul, >Thanks for your contributions! I am back from vacations and had a look. I p= >ut my comments in gerrit but let me restate my main concerns here: > 1) I am not sure we want to keep it as a separate plugin in its current fo= >rm: it already requires significant "iptfs-awareness" in the core, so it mi= >ght just be better to acknowledge that it is part of our core IPsec stack (= >of course the bulk can still be kept nicely isolated in its own file(s)) > 2) I think we need to think a bit more about the vnet buffer metadata and = >flags and how to minimize it. I know it is not easy, but it is a scarce res= >ource >Let's see how we can tackle it. >ben >________________________________________ >From: [email protected] <[email protected]> on behalf of G. Paul Ziemba= > <[email protected]> >Sent: Thursday, August 13, 2026 18:01 >To: [email protected] >Subject: [vpp-dev] Please review: ipsec RFC 9347 >Not sure who is in the office in August - could someone please >look at https://gerrit.fd.io/r/c/vpp/+/46461 >This commit is the first of three IPTFS commits. It comprises the >changes to vnet/ipsec to work with the IPTFS plugin: >> 1. Changes to vnet/ipsec to support IPTFS, consisting of: >> a. registration/callback mechanism by which a TFS plugin >> can register its entry points >> b. updates to the ipsec api to support TFS parameters >> c. updates to SA addition and format to call into the TFS plugin >> d. updates to esp encode/decode related to the additional >> next-protocol value >The remaining IPTFS commits are: >> 2. A new iptfs plugin, which implements all of the timing, >> encoding, and decoding for the RFC 9347 format. >> 3. Unit tests that exercise the TFS-specific parts of the API >> and the encoding/decoding path of TFS. >Thanks! > ~!paul >--r2AfvxxR4H750F9LXHl8 >Content-Type: text/plain; charset="utf-8" >Content-Transfer-Encoding: quoted-printable >Content-Disposition: inline >-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D- >Links: You receive all messages sent to this group. >View/Reply Online (#27136): https://lists.fd.io/g/vpp-dev/message/27136 >Mute This Topic: https://lists.fd.io/mt/120736004/1754028 >Group Owner: [email protected] >Unsubscribe: https://lists.fd.io/g/vpp-dev/leave/3836542/1754028/1506166748= >/xyzzy [[email protected]] >-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D- >--r2AfvxxR4H750F9LXHl8--
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#27142): https://lists.fd.io/g/vpp-dev/message/27142 Mute This Topic: https://lists.fd.io/mt/120736004/21656 Group Owner: [email protected] Unsubscribe: https://lists.fd.io/g/vpp-dev/leave/14379924/21656/631435203/xyzzy [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
