Date: Thu, 09 Nov 2000 12:38:42 -0800 From: Lars Eggert <larse@ISI.EDU> To: Hajimu UMEMOTO <ume@mahoroba.org> Cc: casonc@netplex.aussie.org, freebsd-bugs@freebsd.org, freebsd-stable@freebsd.org, xbone@ISI.EDU, itojun@iijlab.net Subject: Re: Bug or feature ? Message-ID: <3A0B0B52.39B7D7CC@isi.edu> References: <005701c04a62$366f7b20$023a1dac@dsat.net.au> <3A0AEF2D.7665487F@isi.edu> <20001110.043514.08324946.ume@mahoroba.org>
next in thread | previous in thread | raw e-mail | index | archive | help
[-- Attachment #1 --] Hajimu UMEMOTO wrote: > larse> A full patch is available from > larse> http://www.kame.net/dev/cvsweb.cgi/kame/kame/sys/netinet6/ipsec.c.diff?r1=1.82&r2=1.83 > > larse> Pending approval, could the fix please be committed to -STABLE? > > This is still work in progress. The commit messages says as below: > > > Log: > > alternative to PR 296. make sure we do not decapsulate IP tunnel packet > > if we got a transport-mode SA. need to do more for "any" SA. > > DO NOT MERGE IT TO *BSD YET. > > There is too few time to be in time to 4.2-RELEASE. So, I'll backout > previous commit, once. Then, I'll commit right fix after 4.2-RELEASE. There is a small bug in KAME when it encouters IPsec transport mode packets that went over an IPIP tunnel. (They are being treated as IPsec tunnel mode packets.) The original bugfix we submitted fixes that, but opened another problem with ANY SAs. (Packets matching ANY SAs where dropped when they should have been treated as tunnel mode packets.) The new bugfix addresses that problem, so it should be committed in our opinion. The fixes uncovered a small design quirk in KAME SA ANY handling. I'm sure this will be fixed in KAME eventually. For now, I see only benefit in applying the new bugfix: It fixes the IPsec/IPIP bug, and restores interoperability with ANY SAs. Itojun, do you agree with this? What problems did you see in merging the bugfix into FreeBSD? Maybe I missed something. Lars -- Lars Eggert <larse@isi.edu> Information Sciences Institute http://www.isi.edu/larse/ University of Southern California [-- Attachment #2 --] 0# *H 010 + 0 *H 00A#0 *H 010 UZA10UWestern Cape10UDurbanville10 U Thawte10UCertificate Services1(0&UPersonal Freemail RSA 1999.9.160 000824203008Z 010824203008Z0T10 UEggert1 0U*Lars10ULars Eggert10 *H larse@isi.edu00 *H 0 \p9 H;vr∩6"C?mxfJf7I[3CF́L I - zHRVA怤2]0-bL)%X>nӅ w0u0*+e!0 00L2uMyffBNUbNJJcdZ2s0U0 larse@isi.edu0U0 0U#0`fUXFa#Ì0 *H _3 F=%nWY-HXD9UOc6ܰwf@uܶNԄR?Pr}E1֮23mFhySwM_h|d yR=$P 00}0 *H 010 UZA10UWestern Cape10U Cape Town10U Thawte Consulting1(0&UCertification Services Division1$0"UThawte Personal Freemail CA1+0) *H personal-freemail@thawte.com0 990916140140Z 010915140140Z010 UZA10UWestern Cape10UDurbanville10 U Thawte10UCertificate Services1(0&UPersonal Freemail RSA 1999.9.1600 *H 0 iZz]!#rLK~r$BRW{azr98e^eyvL>hput ,O 1ArƦ]D.Mօ>lx~@эWs0FO 7050U0 0U#0rIs4Uvr~wƲ0 *H kY1rr`HU{gapm¥7؝(V\uoƑlfq|ko!6- -mƃRt\~ orzg,ks nΝc) ~U100010 UZA10UWestern Cape10UDurbanville10 U Thawte10UCertificate Services1(0&UPersonal Freemail RSA 1999.9.16#0 + 0 *H 1 *H 0 *H 1 001109203842Z0# *H 1,F@>V&{0R *H 1E0C0 *H 0*H 0+0 *H @0 *H (0 *H 'v,ƀO;+m7֝ݻ{Q&|&IÁ"FrE X[N-}/~ +uXH*fUuU6R-u
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?3A0B0B52.39B7D7CC>
