From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from dpdk.org (dpdk.org [92.243.14.124]) by inbox.dpdk.org (Postfix) with ESMTP id 8D286A04F0 for ; Thu, 19 Dec 2019 15:41:54 +0100 (CET) Received: from [92.243.14.124] (localhost [127.0.0.1]) by dpdk.org (Postfix) with ESMTP id 8122E1C010; Thu, 19 Dec 2019 15:41:54 +0100 (CET) Received: from mail-wr1-f41.google.com (mail-wr1-f41.google.com [209.85.221.41]) by dpdk.org (Postfix) with ESMTP id 81FB41BF70 for ; Thu, 19 Dec 2019 15:41:52 +0100 (CET) Received: by mail-wr1-f41.google.com with SMTP id z7so6191641wrl.13 for ; Thu, 19 Dec 2019 06:41:52 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=from:to:cc:subject:date:message-id:in-reply-to:references :mime-version:content-transfer-encoding; bh=cvVY8PTrB/xnV9s9ATXqhbWxjq6FX8Vcv81UiqIWz5k=; b=q8UfKuppWRrl2D8z+fw6+xxLcG8HlzdSZSfBD9TM7ebSScn9R/mWADupMb2gfneCSY XRvdm08nx+Ta5oTQnaXQ0Fm46ecemtI8A56Cta6GzVy6fW+4hWb4vpPJyD0cyjBhPPJu Vze2u+M1fbJHKij3p8Em97FTPd4DwrXbNPv7m3DzCY6e458Daavu25468o18RH4dJ5p3 WUEUbely16SqhQHckUMYrby/Iyij8VRmi30N/QmIs0eV10KO2nx+AMtkTpJ4YcSqoYPm LSciKkfwYFqFerS1t4N9SeloyG5MqokWFPRqIl+YvR3Hm//TNCTPlxWkz/tJzBkDPqEk AZpw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id:in-reply-to :references:mime-version:content-transfer-encoding; bh=cvVY8PTrB/xnV9s9ATXqhbWxjq6FX8Vcv81UiqIWz5k=; b=RD6zxqHQMZUqlDZ0IYZok5uh8VkgNCyzR9LUHcfPu++QRTFa3I1O5yxLQWX8dfbF2P a1yEMEOXtpSqxKgzGK52Dn4kX3+MfaTTfeAYsMBMVpB7X+L6qcYZRqxQr9DZo+wqP0ML LnnrEOaBy/F0naFm7PIj7XhwTLp3IiTxOpd6v+BDlJgavwg5aoDkq0S7JQKKN9p6Hkqc TWfQuX2JK55wwSuKVYp7+UgxqzLIJEVW+fAPHx2vElPjhvsTZmWEmAIOG7QDeGXyHZzM 4vrl9I0jpMsCz3nYJforVXOpkYSqmi4TDJsNF90C3HHEXblUi7ZgCH2uPBUHYf/muJ1G e3BQ== X-Gm-Message-State: APjAAAW5Tpptb5sku05WJr1dbzR/+Xx+6J7FCmvAQrWhH/R4CJRU9p1z BOxN2oMA1v0sEEAQ1mcIdc4= X-Google-Smtp-Source: APXvYqzJ7pRYQPcMHeZnDTAirrXwWYPSKO0FnBGf229Mwu6IlZAdiyXch5SQAVe7UNATh5LO8T6ptg== X-Received: by 2002:adf:dc8d:: with SMTP id r13mr10255662wrj.357.1576766512223; Thu, 19 Dec 2019 06:41:52 -0800 (PST) Received: from localhost ([88.98.246.218]) by smtp.gmail.com with ESMTPSA id y7sm11036270wmd.1.2019.12.19.06.41.51 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 19 Dec 2019 06:41:51 -0800 (PST) From: luca.boccassi@gmail.com To: Lukasz Bartosik Cc: Anoob Joseph , Akhil Goyal , dpdk stable Date: Thu, 19 Dec 2019 14:34:32 +0000 Message-Id: <20191219143447.21506-125-luca.boccassi@gmail.com> X-Mailer: git-send-email 2.20.1 In-Reply-To: <20191219143447.21506-1-luca.boccassi@gmail.com> References: <20191219143447.21506-1-luca.boccassi@gmail.com> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Subject: [dpdk-stable] patch 'examples/ipsec-secgw: fix default configuration' has been queued to LTS release 17.11.10 X-BeenThere: stable@dpdk.org X-Mailman-Version: 2.1.15 Precedence: list List-Id: patches for DPDK stable branches List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: stable-bounces@dpdk.org Sender: "stable" Hi, FYI, your patch has been queued to LTS release 17.11.10 Note it hasn't been pushed to http://dpdk.org/browse/dpdk-stable yet. It will be pushed if I get no objections before 12/21/19. So please shout if anyone has objections. Also note that after the patch there's a diff of the upstream commit vs the patch applied to the branch. This will indicate if there was any rebasing needed to apply to the stable branch. If there were code changes for rebasing (ie: not only metadata diffs), please double check that the rebase was correctly done. Thanks. Luca Boccassi --- >From c39de520e2d766cd03878b96e440a078ac80ac66 Mon Sep 17 00:00:00 2001 From: Lukasz Bartosik Date: Wed, 6 Nov 2019 16:48:14 +0100 Subject: [PATCH] examples/ipsec-secgw: fix default configuration [ upstream commit 742be57872bed881106ed93f4dadc645d32e1996 ] Update default configuration of ipsec-secgw: 1.In ep0.cfg change SPI value used by two inbound IPv6 security policies from 15 to 115 and 16 to 116 to point to existing inbound SAs. There are no inbound SAs with SPI value 15, 16. - In ep1.cfg change SPI value used by two outbound IPv6 security policies from 15 to 115 and 16 to 116 to point to existing outbound SAs. There are no outbound SAs with SPI value 15, 16. Add missing priority parameter in two inbound IPv4 security policies. Fixes: 60a94afefc84 ("examples/ipsec-secgw: add sample configuration files") Signed-off-by: Lukasz Bartosik Acked-by: Anoob Joseph Acked-by: Akhil Goyal --- examples/ipsec-secgw/ep0.cfg | 8 ++++---- examples/ipsec-secgw/ep1.cfg | 12 ++++++------ 2 files changed, 10 insertions(+), 10 deletions(-) diff --git a/examples/ipsec-secgw/ep0.cfg b/examples/ipsec-secgw/ep0.cfg index 299aa9e061..dfd4aca7d4 100644 --- a/examples/ipsec-secgw/ep0.cfg +++ b/examples/ipsec-secgw/ep0.cfg @@ -49,14 +49,14 @@ sport 0:65535 dport 0:65535 sp ipv6 out esp protect 26 pri 1 dst 0000:0000:0000:0000:bbbb:bbbb:0000:0000/96 \ sport 0:65535 dport 0:65535 -sp ipv6 in esp protect 15 pri 1 dst ffff:0000:0000:0000:5555:5555:0000:0000/96 \ -sport 0:65535 dport 0:65535 -sp ipv6 in esp protect 16 pri 1 dst ffff:0000:0000:0000:6666:6666:0000:0000/96 \ -sport 0:65535 dport 0:65535 sp ipv6 in esp protect 110 pri 1 dst ffff:0000:1111:1111:0000:0000:0000:0000/96 \ sport 0:65535 dport 0:65535 sp ipv6 in esp protect 111 pri 1 dst ffff:0000:1111:1111:1111:1111:0000:0000/96 \ sport 0:65535 dport 0:65535 +sp ipv6 in esp protect 115 pri 1 dst ffff:0000:0000:0000:5555:5555:0000:0000/96 \ +sport 0:65535 dport 0:65535 +sp ipv6 in esp protect 116 pri 1 dst ffff:0000:0000:0000:6666:6666:0000:0000/96 \ +sport 0:65535 dport 0:65535 sp ipv6 in esp protect 125 pri 1 dst ffff:0000:0000:0000:aaaa:aaaa:0000:0000/96 \ sport 0:65535 dport 0:65535 sp ipv6 in esp protect 126 pri 1 dst ffff:0000:0000:0000:bbbb:bbbb:0000:0000/96 \ diff --git a/examples/ipsec-secgw/ep1.cfg b/examples/ipsec-secgw/ep1.cfg index 3f6ff8111b..19bdc68ea2 100644 --- a/examples/ipsec-secgw/ep1.cfg +++ b/examples/ipsec-secgw/ep1.cfg @@ -19,8 +19,8 @@ sp ipv4 in esp protect 15 pri 1 dst 192.168.200.0/24 sport 0:65535 dport 0:65535 sp ipv4 in esp protect 16 pri 1 dst 192.168.201.0/24 sport 0:65535 dport 0:65535 sp ipv4 in esp protect 25 pri 1 dst 192.168.55.0/24 sport 0:65535 dport 0:65535 sp ipv4 in esp protect 26 pri 1 dst 192.168.56.0/24 sport 0:65535 dport 0:65535 -sp ipv4 in esp bypass dst 192.168.240.0/24 sport 0:65535 dport 0:65535 -sp ipv4 in esp bypass dst 192.168.241.0/24 sport 0:65535 dport 0:65535 +sp ipv4 in esp bypass pri 1 dst 192.168.240.0/24 sport 0:65535 dport 0:65535 +sp ipv4 in esp bypass pri 1 dst 192.168.241.0/24 sport 0:65535 dport 0:65535 sp ipv4 out esp protect 105 pri 1 dst 192.168.115.0/24 sport 0:65535 dport 0:65535 sp ipv4 out esp protect 106 pri 1 dst 192.168.116.0/24 sport 0:65535 dport 0:65535 @@ -49,14 +49,14 @@ sport 0:65535 dport 0:65535 sp ipv6 in esp protect 26 pri 1 dst 0000:0000:0000:0000:bbbb:bbbb:0000:0000/96 \ sport 0:65535 dport 0:65535 -sp ipv6 out esp protect 15 pri 1 dst ffff:0000:0000:0000:5555:5555:0000:0000/96 \ -sport 0:65535 dport 0:65535 -sp ipv6 out esp protect 16 pri 1 dst ffff:0000:0000:0000:6666:6666:0000:0000/96 \ -sport 0:65535 dport 0:65535 sp ipv6 out esp protect 110 pri 1 dst ffff:0000:1111:1111:0000:0000:0000:0000/96 \ sport 0:65535 dport 0:65535 sp ipv6 out esp protect 111 pri 1 dst ffff:0000:1111:1111:1111:1111:0000:0000/96 \ sport 0:65535 dport 0:65535 +sp ipv6 out esp protect 115 pri 1 dst ffff:0000:0000:0000:5555:5555:0000:0000/96 \ +sport 0:65535 dport 0:65535 +sp ipv6 out esp protect 116 pri 1 dst ffff:0000:0000:0000:6666:6666:0000:0000/96 \ +sport 0:65535 dport 0:65535 sp ipv6 out esp protect 125 pri 1 dst ffff:0000:0000:0000:aaaa:aaaa:0000:0000/96 \ sport 0:65535 dport 0:65535 sp ipv6 out esp protect 126 pri 1 dst ffff:0000:0000:0000:bbbb:bbbb:0000:0000/96 \ -- 2.20.1 --- Diff of the applied patch vs upstream commit (please double-check if non-empty: --- --- - 2019-12-19 14:32:31.304858886 +0000 +++ 0125-examples-ipsec-secgw-fix-default-configuration.patch 2019-12-19 14:32:26.325302188 +0000 @@ -1,8 +1,10 @@ -From 742be57872bed881106ed93f4dadc645d32e1996 Mon Sep 17 00:00:00 2001 +From c39de520e2d766cd03878b96e440a078ac80ac66 Mon Sep 17 00:00:00 2001 From: Lukasz Bartosik Date: Wed, 6 Nov 2019 16:48:14 +0100 Subject: [PATCH] examples/ipsec-secgw: fix default configuration +[ upstream commit 742be57872bed881106ed93f4dadc645d32e1996 ] + Update default configuration of ipsec-secgw: 1.In ep0.cfg change SPI value used by two inbound IPv6 security policies from 15 to 115 and 16 to 116 to point to existing inbound @@ -13,7 +15,6 @@ priority parameter in two inbound IPv4 security policies. Fixes: 60a94afefc84 ("examples/ipsec-secgw: add sample configuration files") -Cc: stable@dpdk.org Signed-off-by: Lukasz Bartosik Acked-by: Anoob Joseph