Thread (8 messages) 8 messages, 4 authors, 2020-08-03

Re: [PATCH net-next v2] xfrm: introduce oseq-may-wrap flag

From: Steffen Klassert <steffen.klassert@secunet.com>
Date: 2020-06-26 05:25:01
Also in: lkml

On Sat, May 30, 2020 at 02:39:12PM +0200, Petr Vaněk wrote:
RFC 4303 in section 3.3.3 suggests to disable anti-replay for manually
distributed ICVs in which case the sender does not need to monitor or
reset the counter. However, the sender still increments the counter and
when it reaches the maximum value, the counter rolls over back to zero.

This patch introduces new extra_flag XFRM_SA_XFLAG_OSEQ_MAY_WRAP which
allows sequence number to cycle in outbound packets if set. This flag is
used only in legacy and bmp code, because esn should not be negotiated
if anti-replay is disabled (see note in 3.3.3 section).

Signed-off-by: Petr Vaněk <redacted>
Now applied to ipsec-next, thanks a lot!
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help