Page MenuHomeFreeBSD

Add ESP dummy frames support
ClosedPublic

Authored by aurelien.cazuc.external_stormshield.eu on Tue, Nov 26, 9:45 AM.

Details

Summary

This patch provides support of dummy frames as specified by RFC 4303
Packets with IPPROTO_NONE are silently dropped just before ipsecX_common_input_cb

Test Plan

In manual testing, when generating packets with IPPROTO_NONE as next_header, packets are correctly dropped

Diff Detail

Repository
rS FreeBSD src repository
Lint
Automatic diff as part of commit; lint not applicable.
Unit
Automatic diff as part of commit; unit tests not applicable.

Event Timeline

ae added inline comments.Tue, Nov 26, 3:51 PM
sys/netipsec/xform_esp.c
625 ↗(On Diff #64882)

This indentation does not conform to style(9). I think you can just use

if (lastthree[2] == IPPROTO_NONE)
      goto bad;

the error variable should already be zero.

ae accepted this revision.Wed, Nov 27, 12:45 AM
This revision is now accepted and ready to land.Wed, Nov 27, 12:45 AM

Hi @ae ,

Would you prefer commit it yourself or let fabient commit it ?
If you commit it yourself, please mention Stormshield as sponsor.

Thanks

This revision was automatically updated to reflect the committed changes.