[Swan-dev] ikev1 xauth regression

Paul Wouters paul at nohats.ca
Sun Mar 18 23:31:28 UTC 2018


> Date: Sun, 18 Mar 2018 15:58:50
> The regression tests are consistently throwing up this failure:
>
>   http://testing.libreswan.org/results/v3.22-1133-gcc9c2b1-master/xauth-pluto-16/OUTPUT/road.console.diff
>
> Looking through history, it started after these changes:
>
> 2018-03-02 02:20:96015a9pluto: Support for fallback to AUTH_NULL via
> private use notify
> 2018-03-02 02:17:398dd7dpluto: log any ID_NULL identity given then
> forget about it forever
> 2018-03-02 02:13:5d22830libipsecconf: Add support for authby=foo,bar
> 2018-03-02 01:44:3845655testing: test bogus payloads in SA_INIT exchange
> 2018-03-02 01:30:064c0b1retransmits: add --impair delete-on-retransmit
> 2018-03-01 20:48:cc6f7f0packaging: don't use @ @ symbols for ipsec version
> 2018-03-01 19:22:c306de3ikev2: move 'set current state' to before the
> packet decode
>
> I suspect there's timing involved though, locally I'm not seeing this.

I guess I'll git bisect this to find the specific commit. The first two
are only changing IKEv2, and this shows up as an IKEv1 problem, so I'm
a little confused how this happened.

Paul


More information about the Swan-dev mailing list