From owner-freebsd-bugs@FreeBSD.ORG Tue Aug 12 05:20:01 2008 Return-Path: Delivered-To: freebsd-bugs@hub.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id B6B961065676 for ; Tue, 12 Aug 2008 05:20:01 +0000 (UTC) (envelope-from gnats@FreeBSD.org) Received: from freefall.freebsd.org (freefall.freebsd.org [IPv6:2001:4f8:fff6::28]) by mx1.freebsd.org (Postfix) with ESMTP id 8E9FE8FC0C for ; Tue, 12 Aug 2008 05:20:01 +0000 (UTC) (envelope-from gnats@FreeBSD.org) Received: from freefall.freebsd.org (gnats@localhost [127.0.0.1]) by freefall.freebsd.org (8.14.2/8.14.2) with ESMTP id m7C5K1AY055022 for ; Tue, 12 Aug 2008 05:20:01 GMT (envelope-from gnats@freefall.freebsd.org) Received: (from gnats@localhost) by freefall.freebsd.org (8.14.2/8.14.1/Submit) id m7C5K1RL055021; Tue, 12 Aug 2008 05:20:01 GMT (envelope-from gnats) Resent-Date: Tue, 12 Aug 2008 05:20:01 GMT Resent-Message-Id: <200808120520.m7C5K1RL055021@freefall.freebsd.org> Resent-From: FreeBSD-gnats-submit@FreeBSD.org (GNATS Filer) Resent-To: freebsd-bugs@FreeBSD.org Resent-Reply-To: FreeBSD-gnats-submit@FreeBSD.org, "Eugene M. Zheganin" Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 851EF1065675 for ; Tue, 12 Aug 2008 05:14:07 +0000 (UTC) (envelope-from nobody@FreeBSD.org) Received: from www.freebsd.org (www.freebsd.org [IPv6:2001:4f8:fff6::21]) by mx1.freebsd.org (Postfix) with ESMTP id 6F9118FC1D for ; Tue, 12 Aug 2008 05:14:07 +0000 (UTC) (envelope-from nobody@FreeBSD.org) Received: from www.freebsd.org (localhost [127.0.0.1]) by www.freebsd.org (8.14.2/8.14.2) with ESMTP id m7C5E6ZM001557 for ; Tue, 12 Aug 2008 05:14:06 GMT (envelope-from nobody@www.freebsd.org) Received: (from nobody@localhost) by www.freebsd.org (8.14.2/8.14.1/Submit) id m7C5E6gb001556; Tue, 12 Aug 2008 05:14:06 GMT (envelope-from nobody) Message-Id: <200808120514.m7C5E6gb001556@www.freebsd.org> Date: Tue, 12 Aug 2008 05:14:06 GMT From: "Eugene M. Zheganin" To: freebsd-gnats-submit@FreeBSD.org X-Send-Pr-Version: www-3.1 Cc: Subject: bin/126468: some ipsec configurations make FreeBSD panic X-BeenThere: freebsd-bugs@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Bug reports List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 12 Aug 2008 05:20:01 -0000 >Number: 126468 >Category: bin >Synopsis: some ipsec configurations make FreeBSD panic >Confidential: no >Severity: serious >Priority: medium >Responsible: freebsd-bugs >State: open >Quarter: >Keywords: >Date-Required: >Class: sw-bug >Submitter-Id: current-users >Arrival-Date: Tue Aug 12 05:20:01 UTC 2008 >Closed-Date: >Last-Modified: >Originator: Eugene M. Zheganin >Release: 7.0-RELEASE-p3 >Organization: Norma JSC. >Environment: FreeBSD izh.norma.com. 7.0-RELEASE-p3 FreeBSD 7.0-RELEASE-p3 #5: Mon Aug 11 18:41:13 YEKST 2008 emz@ravenholm.hq.norma.perm.ru:/usr/obj/usr/src/sys/IZH i386 >Description: The ipsec.conf below makes FreeBSD panic immidiately after setkey -f ipsec.conf. This ipsec.conf was reported to be working on 6.2-RELEASE and on all releases since 4.7-RELEASE. Problem appeared after an upgrade to 7.0-RELEASE. The problem is repeatable on 2 FreeBSD machines, one of those machines is running a clean install of FreeBSD 7.0-RELEASE-p3. The file is also available at http://zhegan.in/unix/ipsec.conf . ===Cut=== flush; spdflush; spdadd 212.33.248.82 212.33.248.81 ipencap -P out ipsec esp/tunnel/212.33.248.82-212.33.248.81/require ah/transport/212.33.248.82-212.33.248.81/require; spdadd 212.33.248.81 212.33.248.82 ipencap -P in ipsec esp/tunnel/212.33.248.81-212.33.248.82/require ah/transport/212.33.248.81-212.33.248.82/require; spdadd 192.168.251.5 192.168.251.2 ipencap -P out ipsec esp/tunnel/192.168.251.5-192.168.251.2/require ah/transport/192.168.251.5-192.168.251.2/require; spdadd 192.168.251.2 192.168.251.5 ipencap -P in ipsec esp/tunnel/192.168.251.2-192.168.251.5/require ah/transport/192.168.251.2-192.168.251.5/require; add 212.33.248.81 212.33.248.82 esp 0x10007 -m tunnel -E 3des-cbc "Somepeoplesaymylovecanno" -A hmac-md5 "Pleasebelievemem"; add 212.33.248.81 212.33.248.82 ah 0x10008 -m transport -A keyed-md5 "Yourloveformehas"; add 212.33.248.82 212.33.248.81 esp 0x10005 -m tunnel -E 3des-cbc "ButnowIvegottoknowyatell" -A hmac-md5 "TellmewhoamItobl"; add 212.33.248.82 212.33.248.81 ah 0x10006 -m transport -A keyed-md5 "Iwasbornwithouty"; add 192.168.251.5 192.168.251.2 esp 0x10052 -m tunnel -E 3des-cbc "DrutfomgooxkeabTevutOcks" -A hmac-md5 "onghojdiodhovtev"; add 192.168.251.5 192.168.251.2 ah 0x10053 -m transport -A keyed-md5 "saidIltUxOpZeeld"; add 192.168.251.2 192.168.251.5 esp 0x10054 -m tunnel -E 3des-cbc "DrutfomgooxkeabTevutOcks" -A hmac-md5 "MesbemusnEbMifAv"; add 192.168.251.2 192.168.251.5 ah 0x10055 -m transport -A keyed-md5 "toojijbishriRiwi"; ===Cut=== >How-To-Repeat: Get a FreeBSD, get an IPSEC-enabled kernel. Try to setkey -f with a proposed configuration inside the . >Fix: >Release-Note: >Audit-Trail: >Unformatted: