From 2096063b0856808326cbd2c1c8a3a786c98ea896 Mon Sep 17 00:00:00 2001 From: Sergio Gonzalez Monroy Date: Thu, 12 Oct 2017 11:43:41 +0100 Subject: dpdk/ipsec: coverity fixes Change-Id: Ica3bc74ffbb1c0df4e198b0abff8df10cdeb2182 Signed-off-by: Sergio Gonzalez Monroy --- src/plugins/dpdk/ipsec/cli.c | 2 +- src/plugins/dpdk/ipsec/esp_decrypt.c | 6 +++--- src/plugins/dpdk/ipsec/esp_encrypt.c | 8 ++++---- 3 files changed, 8 insertions(+), 8 deletions(-) (limited to 'src/plugins/dpdk') diff --git a/src/plugins/dpdk/ipsec/cli.c b/src/plugins/dpdk/ipsec/cli.c index 2dcfe1d5441..ad6025f72ea 100644 --- a/src/plugins/dpdk/ipsec/cli.c +++ b/src/plugins/dpdk/ipsec/cli.c @@ -287,7 +287,7 @@ set_dpdk_crypto_placement_fn (vlib_main_t * vm, crypto_dev_t *dev; u32 thread_idx, i; u16 res_idx, *idx; - u8 dev_idx, auto_en; + u8 dev_idx, auto_en = 0; if (!unformat_user (input, unformat_line_input, line_input)) return clib_error_return (0, "invalid syntax"); diff --git a/src/plugins/dpdk/ipsec/esp_decrypt.c b/src/plugins/dpdk/ipsec/esp_decrypt.c index 90be466efd7..36be24ba430 100644 --- a/src/plugins/dpdk/ipsec/esp_decrypt.c +++ b/src/plugins/dpdk/ipsec/esp_decrypt.c @@ -165,8 +165,6 @@ dpdk_esp_decrypt_node_fn (vlib_main_t * vm, if (sa_index0 != last_sa_index) { - last_sa_index = sa_index0; - sa0 = pool_elt_at_index (im->sad, sa_index0); cipher_alg = vec_elt_at_index (dcm->cipher_algs, sa0->crypto_alg); @@ -207,6 +205,8 @@ dpdk_esp_decrypt_node_fn (vlib_main_t * vm, n_left_to_next -= 1; goto trace; } + + last_sa_index = sa_index0; } /* anti-replay check */ @@ -283,7 +283,7 @@ dpdk_esp_decrypt_node_fn (vlib_main_t * vm, digest = vlib_buffer_get_tail (b0) - trunc_size; - if (cipher_alg->alg == RTE_CRYPTO_CIPHER_AES_CBC) + if (!is_aead && cipher_alg->alg == RTE_CRYPTO_CIPHER_AES_CBC) clib_memcpy(icb, iv, 16); else /* CTR/GCM */ { diff --git a/src/plugins/dpdk/ipsec/esp_encrypt.c b/src/plugins/dpdk/ipsec/esp_encrypt.c index 3ce22843289..a1ef798e070 100644 --- a/src/plugins/dpdk/ipsec/esp_encrypt.c +++ b/src/plugins/dpdk/ipsec/esp_encrypt.c @@ -191,8 +191,6 @@ dpdk_esp_encrypt_node_fn (vlib_main_t * vm, if (sa_index0 != last_sa_index) { - last_sa_index = sa_index0; - sa0 = pool_elt_at_index (im->sad, sa_index0); cipher_alg = @@ -238,6 +236,8 @@ dpdk_esp_encrypt_node_fn (vlib_main_t * vm, n_left_to_next -= 1; goto trace; } + + last_sa_index = sa_index0; } if (PREDICT_FALSE (esp_seq_advance (sa0))) @@ -375,7 +375,7 @@ dpdk_esp_encrypt_node_fn (vlib_main_t * vm, rewrite_len + ip4_header_bytes (&ih0->ip4)); oh0->ip4.protocol = IP_PROTOCOL_IPSEC_ESP; esp0 = - (esp_header_t *) (oh6_0 + ip4_header_bytes (&ih0->ip4)); + (esp_header_t *) (oh0 + ip4_header_bytes (&ih0->ip4)); } esp0->spi = clib_host_to_net_u32 (sa0->spi); esp0->seq = clib_host_to_net_u32 (sa0->seq); @@ -421,7 +421,7 @@ dpdk_esp_encrypt_node_fn (vlib_main_t * vm, u32 *aad = NULL; u8 *digest = vlib_buffer_get_tail (b0) - trunc_size; - if (cipher_alg->alg == RTE_CRYPTO_CIPHER_AES_CBC) + if (!is_aead && cipher_alg->alg == RTE_CRYPTO_CIPHER_AES_CBC) { cipher_off = sizeof (esp_header_t); cipher_len = iv_size + pad_payload_len; -- cgit 1.2.3-korg