Tobias Brunner
e175abaf89
include: Add XFRM mode and attributes for IP-TFS
2025-05-28 16:37:46 +02:00
Tobias Brunner
aa1322aed5
include: Add XFRM identifiers for per-CPU SAs/acquires
2025-05-28 16:35:26 +02:00
Tobias Brunner
b05628dd2d
include: Update XFRM header for SA direction attribute
2024-08-07 14:41:28 +02:00
Tobias Brunner
e21290ec30
kernel-netlink: Read last use time from SA if possible
...
Since 6.2 the Linux kernel updates the last use time per SA. In
previous releases the attribute was only updated and reported for
specific outbound IPv6 SAs.
Using this reduces the number of kernel queries per CHILD_SA: for DPDs
from two policy queries (IN/FWD) to a single query of the inbound SA,
and for status reports the three policy queries (IN/FWD/OUT) can be
omitted and only the two SAs have to be queried. For NAT keepalives the
number of queries doesn't change but a policy query (OUT) is replaced by
a query for the outbound SA.
While we could use the existence of the attribute as indicator for its
support, we don't know this until we queried an SA. By using a version
check we can announce the feature from the start.
2023-02-22 13:20:10 +01:00
Tobias Brunner
55719d7de5
kernel-netlink: Add support for full packet and policy HW offloading
2023-02-16 13:25:34 +01:00
Josh Soref
b3ab7a48cc
Spelling fixes
...
* accumulating
* acquire
* alignment
* appropriate
* argument
* assign
* attribute
* authenticate
* authentication
* authenticator
* authority
* auxiliary
* brackets
* callback
* camellia
* can't
* cancelability
* certificate
* choinyambuu
* chunk
* collector
* collision
* communicating
* compares
* compatibility
* compressed
* confidentiality
* configuration
* connection
* consistency
* constraint
* construction
* constructor
* database
* decapsulated
* declaration
* decrypt
* derivative
* destination
* destroyed
* details
* devised
* dynamic
* ecapsulation
* encoded
* encoding
* encrypted
* enforcing
* enumerator
* establishment
* excluded
* exclusively
* exited
* expecting
* expire
* extension
* filter
* firewall
* foundation
* fulfillment
* gateways
* hashing
* hashtable
* heartbeats
* identifier
* identifiers
* identities
* identity
* implementers
* indicating
* initialize
* initiate
* initiation
* initiator
* inner
* instantiate
* legitimate
* libraries
* libstrongswan
* logger
* malloc
* manager
* manually
* measurement
* mechanism
* message
* network
* nonexistent
* object
* occurrence
* optional
* outgoing
* packages
* packets
* padding
* particular
* passphrase
* payload
* periodically
* policies
* possible
* previously
* priority
* proposal
* protocol
* provide
* provider
* pseudo
* pseudonym
* public
* qualifier
* quantum
* quintuplets
* reached
* reading
* recommendation to
* recommendation
* recursive
* reestablish
* referencing
* registered
* rekeying
* reliable
* replacing
* representing
* represents
* request
* request
* resolver
* result
* resulting
* resynchronization
* retriable
* revocation
* right
* rollback
* rule
* rules
* runtime
* scenario
* scheduled
* security
* segment
* service
* setting
* signature
* specific
* specified
* speed
* started
* steffen
* strongswan
* subjectaltname
* supported
* threadsafe
* traffic
* tremendously
* treshold
* unique
* uniqueness
* unknown
* until
* upper
* using
* validator
* verification
* version
* version
* warrior
Closes strongswan/strongswan#164 .
2020-02-11 18:23:07 +01:00
Tobias Brunner
d1cd2a0541
include: Add XFRM attribute identifier for interface ID
2019-04-03 12:00:08 +02:00
Tobias Brunner
9cee688f78
kernel-netlink: Add support for setting mark/mask an SA should apply to processed traffic
2018-08-31 12:24:30 +02:00
Tobias Brunner
5bfae68670
include: Update xfrm.h to include hardware offloading extensions
2017-05-23 16:51:02 +02:00
Martin Willi
dbff6373e1
include: Update xfrm.h to Linux v4.3
...
We strip the newly introduced <linux/in6.h> include, as this clashes with the
<netinet/in6.h> include.
2016-09-30 14:51:58 +02:00
Martin Willi
f7925cad04
Updated copy of linux/xfrm.h to 2.6.39, featuring ESN support
2011-04-20 12:26:57 +02:00
Martin Willi
d86bb6ef4d
Implemented Traffic Flow Confidentiality padding in kernel_interface
2010-12-20 09:45:39 +01:00
Andreas Steffen
f031e41bea
upgraded xfrm.h to linux-2.6.34
2010-06-27 11:23:35 +02:00
Martin Willi
2379fdba1e
Updated XFRM linux header, includes specified truncations for auth algos
2009-11-26 10:39:25 +01:00
Andreas Steffen
217d95c82e
upgrade to linux-2.6.28 headers with support for kmaddress struct
2008-10-29 05:32:38 +00:00
Martin Willi
aa9a300677
userland support to process notifies for new NAT mappings detected in UDP encapsulation
2008-10-07 07:55:28 +00:00
Andreas Steffen
eb0cc33886
The XFRM_STATE_AF_UNSPEC flag added to xfrm.h allows IPv4-over-IPv6 and IPv6-over-IPv6 tunnels with the 2.6.26 and later Linux kernels
2008-07-15 15:28:00 +00:00
Tobias Brunner
5a9f62a754
updated xfrm.h to the version from the 2.6.25.4 kernel sources
2008-05-16 13:24:18 +00:00
Andreas Steffen
a26b6acf92
reverted to original header files
2007-04-29 18:19:02 +00:00
Andreas Steffen
5c438b66e2
removed dependencies on linux/types.h
2007-04-27 17:24:20 +00:00
Martin Willi
04a7b6d868
added most problematic linux headers to distribution
...
other/real linux header may be selected using --with-linux-headers=dir
2007-04-19 08:59:36 +00:00