(racoon 734) Re: racoon + Cisco VPN Client

Aidas Kasparas <[email protected]> Tue, 14 Sep 2004 18:10:10 +0300
Newsgroups gmane.network.ipv6.kame.racoon
Message-ID <[email protected]>
Richard,

	It "return res;", therefore contents of local variable will be copied 
into expression from which this function will be called.

	There would be a problem, if code would read "return &res;"

Richard Whalen wrote:
> I have been working on merging these changes with changes to allow Racoon to
> be used with MultiNet on VMS, and came across the following in isakmp.c that
> is questionable:
> 
> /*
>  * set values into allocated buffer of isakmp header for phase 1
>  */
> struct isakmp_construct
> set_isakmp_header(vbuf, iph1)
> 	vchar_t *vbuf;
> 	struct ph1handle *iph1;
> {
> 	struct isakmp *isakmp;
> 	struct isakmp_construct res;
> 
> 	res.buff=NULL;
> 	res.np=NULL;
> 
> 	if (vbuf->l < sizeof(*isakmp))
> 		return res;
> 
> 	isakmp = (struct isakmp *)vbuf->v;
> 	memcpy(&isakmp->i_ck, &iph1->index.i_ck, sizeof(cookie_t));
> 	memcpy(&isakmp->r_ck, &iph1->index.r_ck, sizeof(cookie_t));
> 	isakmp->np = ISAKMP_NPTYPE_NONE ;
> 	isakmp->v = iph1->version;
> 	isakmp->etype = iph1->etype;
> 	isakmp->flags = iph1->flags;
> 	isakmp->msgid = iph1->msgid;
> 	isakmp->len = htonl(vbuf->l);
> 
> 	res.np=&(isakmp->np);
> 	res.buff=vbuf->v + sizeof(*isakmp);
> 
> 	return res;
> }
> 
> 
> Notice that res is declared as a (stack) local variable, and is returned as
> the value of the function.  This will lead to corruption.
> 
> -----Original Message-----
> From: Shoichi Sakane [mailto:[email protected]]
> Sent: Friday, September 10, 2004 2:58 AM
> To: [email protected]
> Cc: [email protected]; [email protected];
> [email protected]
> Subject: (racoon 723) Re: racoon + Cisco VPN Client
> 
> 
> umm, i forgot to attach the patch to the previous mail. 
> 
> 
>>>>Newer racoon + hybrid auth support can be found here:
>>>> http://ftp.espci.fr/shadow/manu/racoon-20040828.tgz
>>
>>>>Anyone can tell me if this is going to be integrated in KAME repository
>>>>one day?
>>
>>>>We had no environment to test these features.
>>>>Have you verified if any trouble exists with the additional changes?
>>>>if you have, we'll commit the code to racoon CVS tree.
>>
>>>I used the code and had no problem with it. It works and I'm not aware 
>>>of any problem it introduces, but I cannot swear it does't break
> 
> something 
> 
>>>else. Given the nature of the changes, there are little chances it could
> 
> 
>>>breaks something, though.
>>
>>i made the patch for the current racoon in the repository
>>to support the features.  i attached it to this mail.
>>could anyone apply it and check if the features would be enable ?
>>to enable the features, use --enable-hybrid option when you
>>run the configure command.
>>
>>	% patch -p1 < racoon-hybrid.patch
>>	% ./configure --enable-hybrid
>>	% make
>>
>>if the patch will work fine, i will commit it soon.