On Fri, 28 Feb 2020, Antony Antony wrote:

As I said, I see no difference running 3.29, 3.30 or git master.

I am pretty sure I saw the regression with 3.30. If you show your full test

I got something mixed up. I now see proper differences.

It looks like we might not be using in_struct() for reading traffic
selectors, or we are using one that doesn't handle v4 and v6 being
different. Ideally, this should fail at in_struct(), so we can
reject the entire packet witn INVALID_SYNTAX - which is what
strongswan correctly does.

Paul
_______________________________________________
Swan-dev mailing list
[email protected]
https://lists.libreswan.org/mailman/listinfo/swan-dev

Reply via email to