Skip site navigation (1)Skip section navigation (2)
Date:      Thu, 09 Nov 2000 12:38:42 -0800
From:      Lars Eggert <larse@ISI.EDU>
To:        Hajimu UMEMOTO <ume@mahoroba.org>
Cc:        casonc@netplex.aussie.org, freebsd-bugs@freebsd.org, freebsd-stable@freebsd.org, xbone@ISI.EDU, itojun@iijlab.net
Subject:   Re: Bug or feature ?
Message-ID:  <3A0B0B52.39B7D7CC@isi.edu>
References:  <005701c04a62$366f7b20$023a1dac@dsat.net.au> <3A0AEF2D.7665487F@isi.edu> <20001110.043514.08324946.ume@mahoroba.org>

next in thread | previous in thread | raw e-mail | index | archive | help

[-- Attachment #1 --]
Hajimu UMEMOTO wrote:
> larse> A full patch is available from
> larse> http://www.kame.net/dev/cvsweb.cgi/kame/kame/sys/netinet6/ipsec.c.diff?r1=1.82&r2=1.83
> 
> larse> Pending approval, could the fix please be committed to -STABLE?
> 
> This is still work in progress.  The commit messages says as below:
> 
> >  Log:
> >  alternative to PR 296.  make sure we do not decapsulate IP tunnel packet
> >  if we got a transport-mode SA.  need to do more for "any" SA.
> >  DO NOT MERGE IT TO *BSD YET.
> 
> There is too few time to be in time to 4.2-RELEASE.  So, I'll backout
> previous commit, once.  Then, I'll commit right fix after 4.2-RELEASE.

There is a small bug in KAME when it encouters IPsec transport mode packets
that went over an IPIP tunnel. (They are being treated as IPsec tunnel mode
packets.) The original bugfix we submitted fixes that, but opened another
problem with ANY SAs. (Packets matching ANY SAs where dropped when they
should have been treated as tunnel mode packets.) The new bugfix addresses
that problem, so it should be committed in our opinion.

The fixes uncovered a small design quirk in KAME SA ANY handling. I'm sure
this will be fixed in KAME eventually. For now, I see only benefit in
applying the new bugfix: It fixes the IPsec/IPIP bug, and restores
interoperability with ANY SAs.

Itojun, do you agree with this? What problems did you see in merging the
bugfix into FreeBSD? Maybe I missed something.

Lars
-- 
Lars Eggert <larse@isi.edu>                 Information Sciences Institute
http://www.isi.edu/larse/                University of Southern California
[-- Attachment #2 --]
0#	*H
010	+0	*H
00A#0
	*H
010	UZA10UWestern Cape10UDurbanville10
U
Thawte10UCertificate Services1(0&UPersonal Freemail RSA 1999.9.160
000824203008Z
010824203008Z0T10
UEggert1
0U*Lars10ULars Eggert10	*H
	
larse@isi.edu00
	*H
0\p9޻ H;v֐r∩6"C?mxfJf7I[3CF́L	I
-zHRVA怤2]0-bL)%X>nӅw0u0*+e!000L2uMyffBNUbNJJcdZ2s0U0
larse@isi.edu0U00U#0`fUXFa#Ì0
	*H
_3	F=%nWY-HXD9UOc6ܰwf@uܶNԄR?Pr}E1֮23mFhySwM_h|d yR=$P 00}0
	*H
010	UZA10UWestern Cape10U	Cape Town10U
Thawte Consulting1(0&UCertification Services Division1$0"UThawte Personal Freemail CA1+0)	*H
	personal-freemail@thawte.com0
990916140140Z
010915140140Z010	UZA10UWestern Cape10UDurbanville10
U
Thawte10UCertificate Services1(0&UPersonal Freemail RSA 1999.9.1600
	*H
0iZz]!#rLK~r$BRW{azr98e^eyvL>hput,O	1ArƦ]D.Mօ>lx~@эWs0FO7050U00U#0rIs4Uvr~wƲ0
	*H
kY1rr`HU{gapm¥7؝(V\uoƑlfq|ko!6-	-mƃRt\~
orzg,ksnΝc)	~U100010	UZA10UWestern Cape10UDurbanville10
U
Thawte10UCertificate Services1(0&UPersonal Freemail RSA 1999.9.16#0	+0	*H
	1	*H
0	*H
	1
001109203842Z0#	*H
	1,F@>V&{0R	*H
	1E0C0
*H
0*H
0+0
*H
@0
*H
(0
	*H
'v,ƀO;+m7֝ݻ{Q&|&IÁ"Fr෽E	X[N-}/~
+uXH*fUuU6R-u

Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?3A0B0B52.39B7D7CC>