From aa5f64a665d55026c030c7f62087ee73425c10b6 Mon Sep 17 00:00:00 2001 From: like-a-bus <32065497+like-a-bus@users.noreply.github.com> Date: Mon, 7 Sep 2026 10:26:28 +0300 Subject: [PATCH] linux-cp: fix interface ipip parser in xfrm-nl plugin The interface type parser in lcp_xfrm_itf_pair_config() only handled 'interface ipsec' and silently ignored 'interface ipip', causing the plugin to always create ipsec-itf even when ipip was requested in startup.conf. Additionally, the original parser used 'unformat ... %s' which returns a vec without null-terminator, making clib_strcmp() comparisons unreliable. This patch replaces the parser with direct unformat literals for both ipsec and ipip variants. This fixes the missing ipip handling and removes the vec/cstring ambiguity. Unused 'tunnel_name' variable is also dropped. Tested with strongSwan 5.9.13 + linux-xfrm-nl in route-based mode. IPIP tunnel is correctly created on NEWSA notification and IPsec encryption verified via packet trace (esp4-encrypt-tun node) and pcap capture on the WAN interface. --- src/plugins/linux-cp/lcp_xfrm_nl.c | 12 ++++-------- 1 file changed, 4 insertions(+), 8 deletions(-) diff --git a/src/plugins/linux-cp/lcp_xfrm_nl.c b/src/plugins/linux-cp/lcp_xfrm_nl.c index 3eb0ab536..ee9aa6623 100644 --- a/src/plugins/linux-cp/lcp_xfrm_nl.c +++ b/src/plugins/linux-cp/lcp_xfrm_nl.c @@ -530,7 +530,6 @@ static clib_error_t * lcp_xfrm_itf_pair_config (vlib_main_t *vm, unformat_input_t *input) { u32 buf_size, batch_size, batch_delay_ms; - char *tunnel_name = NULL; while (unformat_check_input (input) != UNFORMAT_END_OF_INPUT) { @@ -542,13 +541,10 @@ lcp_xfrm_itf_pair_config (vlib_main_t *vm, unformat_input_t *input) lcp_xfrm_nl_set_batch_size (batch_size); else if (unformat (input, "nl-batch-delay-ms %u", &batch_delay_ms)) lcp_xfrm_nl_set_batch_delay (batch_delay_ms); - else if (unformat (input, "interface %s", tunnel_name)) - { - if (!clib_strcmp (tunnel_name, "ipsec")) - nm->interface_type = NL_INTERFACE_TYPE_IPSEC; - - vec_free (tunnel_name); - } + else if (unformat (input, "interface ipsec")) + nm->interface_type = NL_INTERFACE_TYPE_IPSEC; + else if (unformat (input, "interface ipip")) + nm->interface_type = NL_INTERFACE_TYPE_IPIP; else return clib_error_return (0, "invalid netlink option: %U", format_unformat_error, input);