[PATCH net-next v2 0/7] psp: support rekeying psp protected tcp connections
From: Daniel Zahka
Date: Fri Oct 09 2026 - 16:47:24 EST
The PSP architecture spec states the need for rekeying connections in
the event of a device key rotation. After a device key rotation has
occurred, a new rx derived key needs to be generated and sent out to the
other end of the connection sometime before the next device key rotation
occurs.
Because PSP connections involve two different keys at each endpoint,
one for decrypting ingress traffic, and one for encrypting egress
traffic, there are two types of rekeying events that need to be
supported. From the perspective of one endpoint of the connection:
1. rx rekey: we need to allocate a new spi + decryption key pair to
provide to our peer.
2. tx rekey: our peer has provided us with a new spi + encryption key
pair which we should use for encrypting traffic immediately.
In the case of rx rekeying, there is a period where it makes sense to
accept packets authenticated from either the previous or current spi. To
deal with that, we allow a psp_assoc to remember the last spi that was
valid on a socket due to a rekey. If authentication state does not match
the most recent assoc, the stored state from the previous assoc will be
tried.
In the case of tx rekeying, as soon as we install the new tx key, we
have no use for the previous one, and it can be disposed of immediately.
The only catch is in the case where hw uses a key handle in tx
descriptor state, as opposed to inlining the key directly. In this
case, psp core needs to be sure that any of these unaccounted for
references to key state are gone by the time it tries to sync a deleted
key to hw.
To deal with this race condition, we introduce a different path to key
deletion for psp_assocs removed from the socket during a tx rekey. psp
core will use bql byte counters filled out by the driver to determine a
conservative grace period where key handles can be disposed of.
Lastly, some test cases for rekeying are included that go through key
rotations and rekeying.
There are some packetdrill tests that are queued for upstreaming [1].
[1]: https://github.com/danieldzahka/packetdrill/commits/psp-rekey/
Signed-off-by: Daniel Zahka <daniel.zahka@xxxxxxxxx>
Changes in v2:
- psp: support rx rekey operation
- copy old rx state by value instead of pointer to prev
- place non-datapath fields at end of struct psp_assoc
- disallow rx rekey when socket is not in full psp state, or
dev/version doesn't match
- require the new rx spi to have the opposite phase bit from the
previous one
- psp: support tx rekey operation
- place new assoc on pas->assocs list instead of psd->active_assocs
- disallow tx rekey when socket is not in full psp state
- document rekeying in psp.rst
- reject tx rekey on SADB devices until deferred tx key deletion
lands
- psp: defer tx key deletions for SADB drivers
- replaces "psp: add driver api for deferred tx key deletion"
- use bql byte counters instead of driver callback for grace periods
- only defer tx key deletion when socket outlives psp_assoc
- document driver requirements in psp.rst
- allow tx rekey on SADB devices
- psp: add core tracked stat for outstanding tx keys
- replaces "psp: add core tracked stats for deferred key deletion"
- drop grace-periods stat
- rename tx-key-cnt to tx-key-count, only report it for SADB drivers
- warn about outstanding tx keys in psp_dev_unregister()
- selftests: drv-net: psp: factor out psp connection setup
- split psp_responder conn_setup_psp() into rx_assoc() and tx_assoc()
- drop Reviewed-by from Willem due to psp_responder changes
- selftests: drv-net: psp: add rekey tests
- add tests for rekeys rejected due to psp state and version
mismatch
- add test for rx rekey rejected without a device key rotation
- add rx-assoc, tx-assoc, and key-rotate rpcs to psp_responder
- selftests: drv-net: psp: add a tx rekey drain test for SADB drivers
- new patch
- mlx5: psp: implement deferred tx key deletion
- dropped, bql based grace periods need no driver callback
- Link to v1: https://lore.kernel.org/r/20260204-psp-v1-0-5f034e2dfa36@xxxxxxxxx
---
Daniel Zahka (7):
psp: support rx rekey operation
psp: support tx rekey operation
psp: defer tx key deletions for SADB drivers
psp: add core tracked stat for outstanding tx keys
selftests: drv-net: psp: factor out psp connection setup
selftests: drv-net: psp: add rekey tests
selftests: drv-net: psp: add a tx rekey drain test for SADB drivers
Documentation/netlink/specs/psp.yaml | 8 +
Documentation/networking/psp.rst | 64 +++-
include/net/psp/functions.h | 10 +-
include/net/psp/types.h | 34 +++
include/uapi/linux/psp.h | 1 +
net/psp/Kconfig | 1 +
net/psp/Makefile | 2 +-
net/psp/psp.h | 8 +-
net/psp/psp_deferred_del.c | 231 +++++++++++++++
net/psp/psp_main.c | 25 +-
net/psp/psp_nl.c | 4 +
net/psp/psp_sock.c | 113 ++++++-
tools/testing/selftests/drivers/net/psp.py | 325 ++++++++++++++++++++-
.../testing/selftests/drivers/net/psp_responder.c | 198 +++++++++++--
14 files changed, 970 insertions(+), 54 deletions(-)
---
base-commit: d8674294aefef02266c4d47ad10131f1bffbe534
change-id: 20260202-psp-3c8e2f65c5c4
Best regards,
--
Daniel Zahka <daniel.zahka@xxxxxxxxx>