| Age | Commit message (Collapse) | Author |
|
Exercise duplicate transmit SCI rejection using default, explicit and
all-ones SCI requests on the same lower device. Cover an all-ones request
for both the first and second device, and clean up the second device if
a kernel incorrectly accepts the duplicate.
Also verify that an all-ones SCI still resolves to the default when a
different port is already in use, and that deleting the device makes
its SCI available for reuse.
These cases cover the duplicate acceptance flagged by Sashiko during
review of an earlier MACsec initialization fix. The same tests produce
five passes and two failures before the fix, and seven passes after it.
Check local iproute2 MACsec support before running the new tests. Keep
the existing local and remote checks for callers supplying a configuration,
without requiring remote or offload support for the new local tests.
Link: https://lists.openwall.net/netdev/2026/09/16/11
Signed-off-by: Haseeb Malik <haseebulhaq55@gmail.com>
Link: https://patch.msgid.link/20261001-fix-macsec-duplicate-sci-v3-2-0f179fbe1f2d@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
|
|
Add VLAN filter propagation tests through offloaded MACsec devices via
actual traffic.
The tests create MACsec tunnels with matching SAs on both endpoints,
stack VLANs on top, and verify connectivity with ping. Covered:
- Offloaded MACsec with VLAN (filters propagate to HW)
- Software MACsec with VLAN (no HW filter propagation)
- Offload on/off toggle and verifying traffic still works
On netdevsim this makes use of the VLAN filter debugfs file to actually
validate that filters are applied/removed correctly.
On real hardware the traffic should validate actual VLAN filter
propagation.
Signed-off-by: Cosmin Ratiu <cratiu@nvidia.com>
Reviewed-by: Sabrina Dubroca <sd@queasysnail.net>
Link: https://patch.msgid.link/20260408115240.1636047-4-cratiu@nvidia.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
|
|
Move MACsec offload API and ethtool feature tests from
tools/testing/selftests/drivers/net/netdevsim/macsec-offload.sh to
tools/testing/selftests/drivers/net/macsec.py using the NetDrvEnv
framework so tests can run against both netdevsim (default) and real
hardware (NETIF=ethX). As some real hardware requires MACsec to use
encryption, add that to the tests.
Netdevsim-specific limit checks (max SecY, max RX SC) were moved into
separate test cases to avoid failures on real hardware.
Signed-off-by: Cosmin Ratiu <cratiu@nvidia.com>
Reviewed-by: Sabrina Dubroca <sd@queasysnail.net>
Link: https://patch.msgid.link/20260408115240.1636047-2-cratiu@nvidia.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
|