<feed xmlns='http://www.w3.org/2005/Atom'>
<title>src-test2/sys/netkey, branch releng/4.8</title>
<subtitle>FreeBSD source tree</subtitle>
<id>https://cgit-dev.freebsd.org/src-test2/atom?h=releng%2F4.8</id>
<link rel='self' href='https://cgit-dev.freebsd.org/src-test2/atom?h=releng%2F4.8'/>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/src-test2/'/>
<updated>2003-01-11T19:10:59Z</updated>
<entry>
<title>MFC: "struct route" is not sufficient.  NetBSD PR 18751</title>
<updated>2003-01-11T19:10:59Z</updated>
<author>
<name>Hajimu UMEMOTO</name>
<email>ume@FreeBSD.org</email>
</author>
<published>2003-01-11T19:10:59Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/src-test2/commit/?id=64380b27e06ecca817b3a2ac7c5815dc892fac38'/>
<id>urn:sha1:64380b27e06ecca817b3a2ac7c5815dc892fac38</id>
<content type='text'>
	sys/netinet6/esp_rijndael.c:	1.2
	sys/netinet6/ipcomp_core.c:	1.5
	sys/netkey/keydb.h:		1.8
	sys/netkey/keysock.c:		1.18
</content>
</entry>
<entry>
<title>MFC 1.43:</title>
<updated>2002-07-24T18:17:40Z</updated>
<author>
<name>Hajimu UMEMOTO</name>
<email>ume@FreeBSD.org</email>
</author>
<published>2002-07-24T18:17:40Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/src-test2/commit/?id=3f7a65b366774b0b73be7314e7221af6fbaf3c72'/>
<id>urn:sha1:3f7a65b366774b0b73be7314e7221af6fbaf3c72</id>
<content type='text'>
  - fixed the order of searching SA table for packets.
  - comment about deletion of SA that has not been used by reaching
    soft lifetime.
</content>
</entry>
<entry>
<title>MFC:</title>
<updated>2002-04-28T05:40:29Z</updated>
<author>
<name>SUZUKI Shinsuke</name>
<email>suz@FreeBSD.org</email>
</author>
<published>2002-04-28T05:40:29Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/src-test2/commit/?id=16d053fe829126730a609c1b1052cebdba21ea30'/>
<id>urn:sha1:16d053fe829126730a609c1b1052cebdba21ea30</id>
<content type='text'>
	just merged cosmetic changes from KAME to ease sync between KAME
	and FreeBSD.  (based on freebsd4-snap-20020128)
</content>
</entry>
<entry>
<title>MFC 1.39, 1.40:</title>
<updated>2002-03-08T09:22:49Z</updated>
<author>
<name>Hajimu UMEMOTO</name>
<email>ume@FreeBSD.org</email>
</author>
<published>2002-03-08T09:22:49Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/src-test2/commit/?id=17144e57963d4a0f5e0842ce002cd8b3fdc5eb0b'/>
<id>urn:sha1:17144e57963d4a0f5e0842ce002cd8b3fdc5eb0b</id>
<content type='text'>
  - (when new sa is preferred than old sa)
    even if we fail to send pfkey message, remove the old sa.
  - missing splx
</content>
</entry>
<entry>
<title>MFC: Newer SA is prefered for a out-bound packet than old one</title>
<updated>2001-12-12T15:27:45Z</updated>
<author>
<name>Hajimu UMEMOTO</name>
<email>ume@FreeBSD.org</email>
</author>
<published>2001-12-12T15:27:45Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/src-test2/commit/?id=79de2ed034f486cf874d5f37e8e81c114f06b98b'/>
<id>urn:sha1:79de2ed034f486cf874d5f37e8e81c114f06b98b</id>
<content type='text'>
when net.key.prefered_oldsa is set to zero.

	sys/netkey/key.c:	1.36
	sys/netkey/key_var.h:	1.6
</content>
</entry>
<entry>
<title>MFC:</title>
<updated>2001-11-20T12:26:13Z</updated>
<author>
<name>Hajimu UMEMOTO</name>
<email>ume@FreeBSD.org</email>
</author>
<published>2001-11-20T12:26:13Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/src-test2/commit/?id=40b804bf899fda2aeba0358a7687f4c2c3b9c97c'/>
<id>urn:sha1:40b804bf899fda2aeba0358a7687f4c2c3b9c97c</id>
<content type='text'>
  - net.inet.ipsec.esp_auth hasn't been there
  - nuke all debug printfs, which are unneeded by now.
  - get rid of #ifdef IPSEC_DEBUG in headers
  - now that key_debug_level is always defined, there's no need for
    #ifdef IPSEC_DEBUG around sysctl MIB code (net.key.debug).
  - switch all debug printf() to ipseclog().
  - When there is no suitable inbound policy for the packet of the ipsec
    tunnel mode, the kernel never decapsulate the tunneled packet
    as the ipsec tunnel mode even when the system wide policy is "none".
    Then the kernel leaves the generic tunnel module to process this
    packet.  If there is no rule of the generic tunnel, the packet
    is rejected and the statistics will be counted up.

	sys/netinet6/ipsec.c:	1.14
	sys/netkey/key.c:	1.32-1.35
	sys/netkey/key_debug.c:	1.16
	sys/netkey/key_debug.h:	1.8
	sys/netkey/key_var.h:	1.5
	sys/netkey/keysock.c:	1.8
</content>
</entry>
<entry>
<title>MFC 1.31: Fixed the value of the prefixlen in the sadb_address structure.</title>
<updated>2001-10-29T19:30:35Z</updated>
<author>
<name>Hajimu UMEMOTO</name>
<email>ume@FreeBSD.org</email>
</author>
<published>2001-10-29T19:30:35Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/src-test2/commit/?id=fc0f0e763ebba1e32d121c95e233bcfee161f264'/>
<id>urn:sha1:fc0f0e763ebba1e32d121c95e233bcfee161f264</id>
<content type='text'>
When pfkey message relative to SA is sent, the prefixlen was incorrect.
</content>
</entry>
<entry>
<title>MFC: printed current sequence number of the SA.  accordingly, changed</title>
<updated>2001-10-24T19:49:16Z</updated>
<author>
<name>Hajimu UMEMOTO</name>
<email>ume@FreeBSD.org</email>
</author>
<published>2001-10-24T19:49:16Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/src-test2/commit/?id=24f02893ff982d7a81f48d347d88b4fcafcc165d'/>
<id>urn:sha1:24f02893ff982d7a81f48d347d88b4fcafcc165d</id>
<content type='text'>
into sadb_x_sa2_sequence from sadb_x_sa2_reserved3 in the sadb_x_sa2
structure.  Also the output of setkey is changed.  sequence number
of the sadb is replaced to the end of the output.

	lib/libipsec/pfkey_dump.c:	1.4
	sys/net/pfkeyv2.h:		1.7
	sys/netkey/key.c:		1.29
	sys/netkey/key_debug.c:		1.15
	usr.sbin/setkey/scriptdump.pl:	1.4
</content>
</entry>
<entry>
<title>MFC 1.26-1.28:</title>
<updated>2001-10-24T19:42:39Z</updated>
<author>
<name>Hajimu UMEMOTO</name>
<email>ume@FreeBSD.org</email>
</author>
<published>2001-10-24T19:42:39Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/src-test2/commit/?id=034d77fe8c873251113d7f76c50f8e57dee81339'/>
<id>urn:sha1:034d77fe8c873251113d7f76c50f8e57dee81339</id>
<content type='text'>
  - merged key_cmpsaidx_*.
  - fixed to make a response in key_spdadd().  reported by &lt;R.P.Koster@kpn.com&gt;
  - do not play too much trick with evaluation order.  from netbsd
</content>
</entry>
<entry>
<title>MFC 1.30: The behavior of SPDUPDATE has been changed.</title>
<updated>2001-10-24T19:28:01Z</updated>
<author>
<name>Hajimu UMEMOTO</name>
<email>ume@FreeBSD.org</email>
</author>
<published>2001-10-24T19:28:01Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/src-test2/commit/?id=9d9cca471a6842133e95cbe616c17592194c3036'/>
<id>urn:sha1:9d9cca471a6842133e95cbe616c17592194c3036</id>
<content type='text'>
SPDUPDATE doesn't depend on whether there is a SP or not.
This change makes `generate_policy on' of racoon work.
</content>
</entry>
</feed>
