Skip to content

linux-cp: fix interface ipip parser in xfrm-nl plugin - #49

Closed
like-a-bus wants to merge 1 commit into
MarvellEmbeddedProcessors:stable/2502from
like-a-bus:upstream-pr/ipip-parser-fix
Closed

like-a-bus wants to merge 1 commit into
MarvellEmbeddedProcessors:stable/2502from
like-a-bus:upstream-pr/ipip-parser-fix

Conversation

@like-a-bus

Copy link
Copy Markdown

The interface type parser in lcp_xfrm_itf_pair_config() only handled 'interface ipsec' and silently ignored 'interface ipip', causing the plugin to always create ipsec-itf even when ipip was requested in startup.conf.

Additionally, the original parser used 'unformat ... %s' which returns a vec without null-terminator, making clib_strcmp() comparisons unreliable.

This patch replaces the parser with direct unformat literals for both ipsec and ipip variants. This fixes the missing ipip handling and removes the vec/cstring ambiguity. Unused 'tunnel_name' variable is also dropped.

Tested with strongSwan 5.9.13 + linux-xfrm-nl in route-based mode. IPIP tunnel is correctly created on NEWSA notification and IPsec encryption verified via packet trace (esp4-encrypt-tun node) and pcap capture on the WAN interface.

The interface type parser in lcp_xfrm_itf_pair_config() only handled
'interface ipsec' and silently ignored 'interface ipip', causing the
plugin to always create ipsec-itf even when ipip was requested in
startup.conf.

Additionally, the original parser used 'unformat ... %s' which returns
a vec without null-terminator, making clib_strcmp() comparisons
unreliable.

This patch replaces the parser with direct unformat literals for both
ipsec and ipip variants. This fixes the missing ipip handling and
removes the vec/cstring ambiguity. Unused 'tunnel_name' variable is
also dropped.

Tested with strongSwan 5.9.13 + linux-xfrm-nl in route-based mode.
IPIP tunnel is correctly created on NEWSA notification and IPsec
encryption verified via packet trace (esp4-encrypt-tun node) and pcap
capture on the WAN interface.
@github-actions

github-actions Bot commented Sep 7, 2026

Copy link
Copy Markdown

Thank you so much for your interest! VPP takes patches at https://gerrit.fd.io/
git clone https://gerrit.fd.io/r/vpp
Using git review to contribute patches is recommended

@github-actions github-actions Bot closed this Sep 7, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant