Re: fix for PR#177 (lots of mayhem in 2.00pre6)
Sam Sgro <[email protected]>
| Newsgroups | gmane.network.freeswan.devel |
|---|---|
| Message-ID | <[email protected]> |
On Thu, 6 Feb 2003, D. Hugh Redelmeier wrote: > I've checked a bunch of fixes into HEAD. They are all in > programs/pluto, and they are the only changes to this directory. MCR, > could you pull them up to 2.00pre-whatever? > > What is changed? > - various bad things centred around eclipsed connections. > + infinite CPU-eating loop > + assertion failure > + needlessly conflicting eroutes > - Be more careful to select narrowest suitable connection for OE. > - On assertion failure, dump --status to log. > - On assertion failures due to unexpected value in a switch, log the value. > > Real world testing would be good. Perhaps before pulling them up, > perhaps not. I'm running a slightly earlier version with success. > > I've created a new omnibus test, pluto-unit-02. It doesn't work. The > underlying tests run in my world, not yet in UML. I think that the > problem is that they require a bunch of DNS records that are not > available in UML. > > Michael, could you make these records available to east, running > alone? This may require adding a command to start named in the > pluto-unit-02 test script. I've enclosed the BIND control files I > use. > > The TESTLIST entry for this test is currently commented out. > > Hugh Redelmeier > [email protected] voice: +1 416 482-8253 > > > ================ extract from named.conf ================ > // forward for FreeS/WAN testing: > zone "example.com" { > type master; > file "test.zone"; > }; > > // reverse for FreeS/WAN testing: > zone "7.95.127.in-addr.arpa" IN { > type master; > file "test.rev.zone"; > allow-update { none; }; > }; > ================ test.zone ================ > ; example.com zone for FreeS/WAN testing > ; This file belongs in /var/named/test.zone > ; RCSID $Id: $ > > ; add to /etc/named.conf: > > ;;;// forward for FreeS/WAN testing: > ;;;zone "example.com" { > ;;; type master; > ;;; file "test.zone"; > ;;;}; > > $TTL 8h > $ORIGIN example.com. > > @ 3D IN SOA localhost. root.localhost. ( > ; serial > ; YYYYMMDDnn > 2002021801 > 12H ; refresh > 30M ; retry > 5w6d16h ; expiry > 3D ) ; minimum > > IN NS localhost. > > west IN A 127.95.7.1 > IN KEY 0x4200 4 1 AQOFtqrs57eghHmYREoCu1iGn4kXd+a6yT7wCFUk54d9i08mR4h5uFKPhc9fq78XNqz1AhrBH3SRcWAfJ8DaeGvZ0ZvCrTQZn+RJzX1FQ4fjuGBO0eup2XUMsYDw01PFzQ9O4qlwly6niOcMTxvbWgGcl+3DYfRvHgxet8kNtfqzHQ== > IN TXT "X-IPsec-Server(10)[email protected] AQOFtqrs57eghHmYREoCu1iGn4kXd+a6yT7wCFUk54d9i08mR4h5uFKPhc9fq78XNqz1AhrBH3SRcWAfJ8DaeGvZ0ZvCrTQZn+RJzX1FQ4fjuGBO0eup2XUMsYDw01PFzQ9O4qlwly6niOcMTxvbWgGcl+3DYfRvHgxet8kNtfqzHQ==" > > east IN A 127.95.7.2 > IN KEY 0x4200 4 1 AQNWmttqbM8nIypsHEULynOagFyV1MQ+/1yF5sa32abxBb2fimah7NsHM9l/KpNo7RGtiP0L6triedsZ0xz1Maa4DPnZlrtexu5uIH+FH34SUr7Xe2RcHnLVOznHMzacgcjrOUvV/nA9OEGvm7vRsMAWm/VjNuNugogFreiYEpFMQQ== > IN TXT "X-IPsec-Server(10)[email protected] AQNWmttqbM8nIypsHEULynOagFyV1MQ+/1yF5sa32abxBb2fimah7NsHM9l/KpNo7RGtiP0L6triedsZ0xz1Maa4DPnZlrtexu5uIH+FH34SUr7Xe2RcHnLVOznHMzacgcjrOUvV/nA9OEGvm7vRsMAWm/VjNuNugogFreiYEpFMQQ==" > > north IN A 127.95.7.3 > IN KEY 0x4200 4 1 AQN4JFU9gRnG336z1n1cV2LA6ACi1TjXfv3pvl6DRqa6uqBFM9RO4oArPc6FsBkBwEmMr8cpeFn4mVaepVe63qnvmQbGXVcRwhx0a509M824HjnyM04Xpoh2UuP/Mhnkm1cynunRuyGqXaZhlj4s+GbcOxPXhopz94wer+Qs/qvGqw== > IN TXT "X-IPsec-Server(10)[email protected] AQN4JFU9gRnG336z1n1cV2LA6ACi1TjXfv3pvl6DRqa6uqBFM9RO4oArPc6FsBkBwEmMr8cpeFn4mVaepVe63qnvmQbGXVcRwhx0a509M824HjnyM04Xpoh2UuP/Mhnkm1cynunRuyGqXaZhlj4s+GbcOxPXhopz94wer+Qs/qvGqw==" > > south IN A 127.95.7.4 > IN KEY 0x4200 4 1 AQOKe6+kbDtp4PB8NZshjCBw8z5wuGCAddokgSDATW47tNmQhUvzlnT1ia1ZsyiRFph1LJkz+A0bkbOhPr1vWUJHK6/s+Y8Rf7GSZC0Fi5Fr4DgpWwswzFaLl4baRfeu8z4k147dtSoG4K/6UfQ+IbqML5lwm92uRqONszbn/PDDPQ== > IN TXT "X-IPsec-Server(10)[email protected] AQOKe6+kbDtp4PB8NZshjCBw8z5wuGCAddokgSDATW47tNmQhUvzlnT1ia1ZsyiRFph1LJkz+A0bkbOhPr1vWUJHK6/s+Y8Rf7GSZC0Fi5Fr4DgpWwswzFaLl4baRfeu8z4k147dtSoG4K/6UfQ+IbqML5lwm92uRqONszbn/PDDPQ==" > > victoria IN A 127.95.7.10 > vancouver IN A 127.95.7.11 > truro IN A 127.95.7.21 > antigonish IN A 127.95.7.22 > ================ test.rev.zone ================ > ; example.com reverse zone for FreeS/WAN testing > ; This file belongs in /var/named/test.rev.zone > ; RCSID $Id: $ > > ; add to /etc/named.conf: > > ;;;// reverse for FreeS/WAN testing: > ;;;zone "7.95.127.in-addr.arpa" IN { > ;;; type master; > ;;; file "test.rev.zone"; > ;;; allow-update { none; }; > ;;;}; > > $TTL 86400 > $ORIGIN 7.95.127.in-addr.arpa. > > @ IN SOA localhost. root.localhost. ( > 2002021802 ; Serial > 28800 ; Refresh > 14400 ; Retry > 3600000 ; Expire > 86400 ) ; Minimum > IN NS localhost. > > ; these are IPsec hosts > > 1 IN PTR west.example.com. > IN KEY 0x4200 4 1 AQOOyFBeFFr9CWXgn1aOEvTr98HG4inSckTXlyYi5x85G+Q1+PZ/roqB3OtnRS2XbXFb3n92QjZMJ403wQUwMAt6uzXzXDle5VvFn7cVXq3ch0jqQUxIFcdIIFR2wtkxvAr20xSOHNF/ozmKVZLkrHLu4RvVCCbSNa5toqLXblkcOQ== > IN TXT "X-IPsec-Server(10)=127.95.7.1 AQOOyFBeFFr9CWXgn1aOEvTr98HG4inSckTXlyYi5x85G+Q1+PZ/roqB3OtnRS2XbXFb3n92QjZMJ403wQUwMAt6uzXzXDle5VvFn7cVXq3ch0jqQUxIFcdIIFR2wtkxvAr20xSOHNF/ozmKVZLkrHLu4RvVCCbSNa5toqLXblkcOQ==" > 2 IN PTR east.example.com. > IN KEY 0x4200 4 1 AQOeSJscIy2XZHfs+PODDqdgJR2FmdfRNqzURVL5q2fesMHmibMLPM5cTPx2HvYKBX3YyB+BdHoojmFNixV+RTrKyyN0Og4PYwhdw0FUApDvOg7KYe1CeLUeTAUzT5Pq7MdclRW5bYY84hXSfKgaPwPTwuiLKEnVdbhGgwxqwfQ6ow== > IN TXT "X-IPsec-Server(10)=127.95.7.2 AQOeSJscIy2XZHfs+PODDqdgJR2FmdfRNqzURVL5q2fesMHmibMLPM5cTPx2HvYKBX3YyB+BdHoojmFNixV+RTrKyyN0Og4PYwhdw0FUApDvOg7KYe1CeLUeTAUzT5Pq7MdclRW5bYY84hXSfKgaPwPTwuiLKEnVdbhGgwxqwfQ6ow==" > 3 IN PTR north.example.com. > IN KEY 0x4200 4 1 AQN4JFU9gRnG336z1n1cV2LA6ACi1TjXfv3pvl6DRqa6uqBFM9RO4oArPc6FsBkBwEmMr8cpeFn4mVaepVe63qnvmQbGXVcRwhx0a509M824HjnyM04Xpoh2UuP/Mhnkm1cynunRuyGqXaZhlj4s+GbcOxPXhopz94wer+Qs/qvGqw== > IN TXT "X-IPsec-Server(10)=127.95.7.3 AQN4JFU9gRnG336z1n1cV2LA6ACi1TjXfv3pvl6DRqa6uqBFM9RO4oArPc6FsBkBwEmMr8cpeFn4mVaepVe63qnvmQbGXVcRwhx0a509M824HjnyM04Xpoh2UuP/Mhnkm1cynunRuyGqXaZhlj4s+GbcOxPXhopz94wer+Qs/qvGqw==" > 4 IN PTR south.example.com. > IN KEY 0x4200 4 1 AQOKe6+kbDtp4PB8NZshjCBw8z5wuGCAddokgSDATW47tNmQhUvzlnT1ia1ZsyiRFph1LJkz+A0bkbOhPr1vWUJHK6/s+Y8Rf7GSZC0Fi5Fr4DgpWwswzFaLl4baRfeu8z4k147dtSoG4K/6UfQ+IbqML5lwm92uRqONszbn/PDDPQ== > IN TXT "X-IPsec-Server(10)=127.95.7.4 AQOKe6+kbDtp4PB8NZshjCBw8z5wuGCAddokgSDATW47tNmQhUvzlnT1ia1ZsyiRFph1LJkz+A0bkbOhPr1vWUJHK6/s+Y8Rf7GSZC0Fi5Fr4DgpWwswzFaLl4baRfeu8z4k147dtSoG4K/6UfQ+IbqML5lwm92uRqONszbn/PDDPQ==" > > ; these are IPsec clients > > 10 IN PTR victoria.example.com. > IN TXT "X-IPsec-Server(10)=127.95.7.1 AQOOyFBeFFr9CWXgn1aOEvTr98HG4inSckTXlyYi5x85G+Q1+PZ/roqB3OtnRS2XbXFb3n92QjZMJ403wQUwMAt6uzXzXDle5VvFn7cVXq3ch0jqQUxIFcdIIFR2wtkxvAr20xSOHNF/ozmKVZLkrHLu4RvVCCbSNa5toqLXblkcOQ==" > 11 IN PTR vancouver.example.com. > IN TXT "X-IPsec-Server(10)=127.95.7.1 AQOOyFBeFFr9CWXgn1aOEvTr98HG4inSckTXlyYi5x85G+Q1+PZ/roqB3OtnRS2XbXFb3n92QjZMJ403wQUwMAt6uzXzXDle5VvFn7cVXq3ch0jqQUxIFcdIIFR2wtkxvAr20xSOHNF/ozmKVZLkrHLu4RvVCCbSNa5toqLXblkcOQ==" > > 21 IN PTR truro.example.com. > IN TXT "X-IPsec-Server(10)=127.95.7.2 AQOeSJscIy2XZHfs+PODDqdgJR2FmdfRNqzURVL5q2fesMHmibMLPM5cTPx2HvYKBX3YyB+BdHoojmFNixV+RTrKyyN0Og4PYwhdw0FUApDvOg7KYe1CeLUeTAUzT5Pq7MdclRW5bYY84hXSfKgaPwPTwuiLKEnVdbhGgwxqwfQ6ow==" > 22 IN PTR antigonish.example.com. > IN TXT "X-IPsec-Server(10)=127.95.7.2 AQOeSJscIy2XZHfs+PODDqdgJR2FmdfRNqzURVL5q2fesMHmibMLPM5cTPx2HvYKBX3YyB+BdHoojmFNixV+RTrKyyN0Og4PYwhdw0FUApDvOg7KYe1CeLUeTAUzT5Pq7MdclRW5bYY84hXSfKgaPwPTwuiLKEnVdbhGgwxqwfQ6ow==" > ================ end ================ > | -----END PGP SIGNED MESSAGE----- > -- Sam Sgro [email protected]