[PATCH net-next v2 4/7] psp: add core tracked stat for outstanding tx keys

From: Daniel Zahka

Date: Fri Oct 09 2026 - 16:50:01 EST


It is useful to keep track of tx_key_cnt: the number of outstanding tx
keys from the hw's perspective. Userspace can monitor this to
determine if there is a key leak (leak in the sense that some device
resource like an SADB entry has been leaked, not that the crypto key
has been exposed).

It also may be of interest to userspace if a device is approaching its
SADB capacity.

Only report this stat to userspace if the driver uses an SADB.

Signed-off-by: Daniel Zahka <daniel.zahka@xxxxxxxxx>
---
Documentation/netlink/specs/psp.yaml | 8 ++++++++
include/net/psp/types.h | 2 ++
include/uapi/linux/psp.h | 1 +
net/psp/psp_main.c | 3 +++
net/psp/psp_nl.c | 4 ++++
net/psp/psp_sock.c | 6 +++++-
6 files changed, 23 insertions(+), 1 deletion(-)

diff --git a/Documentation/netlink/specs/psp.yaml b/Documentation/netlink/specs/psp.yaml
index f3266763c325..d14c11d09891 100644
--- a/Documentation/netlink/specs/psp.yaml
+++ b/Documentation/netlink/specs/psp.yaml
@@ -190,6 +190,13 @@ attribute-sets:
doc: |
Number of PSP packets for transmission with errors.
Device statistic (from the PSP spec).
+ -
+ name: tx-key-count
+ type: uint
+ doc: |
+ Current number of Tx keys installed on the device.
+ Only visible if the driver stores keys on device.
+ Kernel statistic.

operations:
list:
@@ -316,6 +323,7 @@ operations:
- tx-packets
- tx-bytes
- tx-error
+ - tx-key-count
pre: psp-device-get-locked
post: psp-device-unlock
dump:
diff --git a/include/net/psp/types.h b/include/net/psp/types.h
index 8ffc566cec2a..970801cb6502 100644
--- a/include/net/psp/types.h
+++ b/include/net/psp/types.h
@@ -90,6 +90,7 @@ struct psp_assoc_dev {
* @stats: statistics maintained by the core
* @stats.rotations: See stats attr key-rotations
* @stats.stales: See stats attr stale-events
+ * @stats.tx_key_cnt: See stats attr tx-key-count
*
* @rcu: RCU head for freeing the structure
*/
@@ -125,6 +126,7 @@ struct psp_dev {
struct {
unsigned long rotations;
unsigned long stales;
+ unsigned long tx_key_cnt;
} stats;

struct rcu_head rcu;
diff --git a/include/uapi/linux/psp.h b/include/uapi/linux/psp.h
index 1c8899cd4da5..21810e8a7229 100644
--- a/include/uapi/linux/psp.h
+++ b/include/uapi/linux/psp.h
@@ -69,6 +69,7 @@ enum {
PSP_A_STATS_TX_PACKETS,
PSP_A_STATS_TX_BYTES,
PSP_A_STATS_TX_ERROR,
+ PSP_A_STATS_TX_KEY_COUNT,

__PSP_A_STATS_MAX,
PSP_A_STATS_MAX = (__PSP_A_STATS_MAX - 1)
diff --git a/net/psp/psp_main.c b/net/psp/psp_main.c
index e118b8019e7e..9f256157d88b 100644
--- a/net/psp/psp_main.c
+++ b/net/psp/psp_main.c
@@ -169,6 +169,9 @@ void psp_dev_unregister(struct psp_dev *psd)
list_del(&pas->assocs_list);
}

+ WARN(psd->stats.tx_key_cnt, "psp: %s: %lu Tx keys still installed\n",
+ netdev_name(psd->main_netdev), psd->stats.tx_key_cnt);
+
list_for_each_entry_safe(entry, entry_tmp, &psd->assoc_dev_list,
dev_list) {
list_del(&entry->dev_list);
diff --git a/net/psp/psp_nl.c b/net/psp/psp_nl.c
index cdfc2d72fb39..494022ab5a71 100644
--- a/net/psp/psp_nl.c
+++ b/net/psp/psp_nl.c
@@ -934,6 +934,10 @@ psp_nl_stats_fill(struct psp_dev *psd, struct sk_buff *rsp,
nla_put_uint(rsp, PSP_A_STATS_TX_ERROR, stats.tx_error))
goto err_cancel_msg;

+ if (psp_dev_has_sadb(psd) &&
+ nla_put_uint(rsp, PSP_A_STATS_TX_KEY_COUNT, psd->stats.tx_key_cnt))
+ goto err_cancel_msg;
+
genlmsg_end(rsp, hdr);
return 0;

diff --git a/net/psp/psp_sock.c b/net/psp/psp_sock.c
index d21f7afd830a..c458bc551b4b 100644
--- a/net/psp/psp_sock.c
+++ b/net/psp/psp_sock.c
@@ -94,9 +94,11 @@ static int psp_dev_tx_key_add(struct psp_dev *psd, struct psp_assoc *pas,

memcpy(&dummy->tx, key, sizeof(*key));
err = psd->ops->tx_key_add(psd, dummy, extack);
- if (!err)
+ if (!err) {
+ psd->stats.tx_key_cnt++;
memcpy(pas->drv_data, dummy->drv_data,
psd->caps->assoc_drv_spc);
+ }

kfree(dummy);
return err;
@@ -105,6 +107,8 @@ static int psp_dev_tx_key_add(struct psp_dev *psd, struct psp_assoc *pas,
void psp_dev_tx_key_del(struct psp_dev *psd, struct psp_assoc *pas)
{
psd->ops->tx_key_del(psd, pas);
+ if (!WARN_ON_ONCE(!psd->stats.tx_key_cnt))
+ psd->stats.tx_key_cnt--;
}

static void psp_assoc_free(struct work_struct *work)

--
2.52.0