On 22.12.2021. 14:52, Alexander Bluhm wrote:
> Hi,
> 
> IPsec is not MP safe yet.  To allow forwarding in parallel without
> dirty hacks, it is better to protect IPsec input and output with
> kernel lock.  We do not loose much as crypto needs the kernel lock
> anyway.  From here we can refine the lock later.
> 
> Note that there is no kernel lock in the SPD lockup path.  I want
> to keep that lock free to allow fast forwarding with non IPsec
> traffic.
> 
> There are still some races in special cases, but in general it works
> with parallel IP input.
> 
> ok?

Hi,

i'm trying to panic sasyncd setup with this and parallel forwarding diff
and i just can't :)


Reply via email to