[Swan-dev] KLIPS crashes after kernel update

David McCullough ucdevel at gmail.com
Tue Nov 5 01:16:59 EET 2013

Paul Wouters wrote the following:
> On Mon, 4 Nov 2013, Roel van Meer wrote:
> >Thomas Geulig writes:
> >
> >>Am Montag, 4. November 2013, 13:00:54 schrieb Roel van Meer:
> >>>Nice! I arrived at the same solution, but missed the fact that
> >>>when calling __ip_select_ident() directly we no longer need the series
> >>>of kernel version checks, so my version is a lot more complicated..
> >>>
> >>>One improvement would be that we don't need the if() in the wrapper.
> >>>The caller sets frag_off to 0 so it will not match anyway.
> >>
> >>I've missed that frag_off is always 0.
> >>
> >>So the patch is really simple.
> >
> >I can confirm that this patch works correctly with kernel 3.4.67
> >and 3.10.17 and that it fixes the checksum errors I saw without
> >it.
> Thanks for the patch and testing. I'll coordinate with David to get this
> merged in.

I am a little confused that the ipsec_param2.h patches provided here look
to apply to an ipsec_param2.h that is nothing like the one in my openswan
2.6.37,  looks like a lot of this ident stuff may have been handled in the
older version.

I haven't looked at libreswan,  but I have been using it with klips and
interoperating with other systems,  at least I thought I was ;-)

I'll check this out but probably not till later in the week at the earliest.


David McCullough,  davidm at spottygum.com,   Ph: 0410 560 763

More information about the Swan-dev mailing list