Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 483576 - net-misc/openswan-2.6.39: regressions
Summary: net-misc/openswan-2.6.39: regressions
Status: RESOLVED WONTFIX
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: Current packages (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Mike Gilbert
URL:
Whiteboard:
Keywords:
Depends on:
Blocks: CVE-2013-2053
  Show dependency tree
 
Reported: 2013-09-04 10:34 UTC by Jeremy Olexa (darkside) (RETIRED)
Modified: 2015-04-26 12:58 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments
log file diff (diff.txt,8.14 KB, text/plain)
2013-09-04 20:10 UTC, Jeremy Olexa (darkside) (RETIRED)
Details

Note You need to log in before you can comment on or make changes to this bug.
Description Jeremy Olexa (darkside) (RETIRED) archtester gentoo-dev Security 2013-09-04 10:34:30 UTC
Excuse the poor title, just researching now why this "STABLE" upgrade broke my VPN. The tip of the iceberg alone is hardcoded paths in verify.

% grep sbin/ss openswan-2.6.39/image/usr/libexec/ipsec/verify 
                p = subprocess.Popen(["/usr/sbin/ss", "-n", "-l", "-u", "sport = :500"], stdout=subprocess.PIPE, stderr=subprocess.PIPE) 
<snip>

(Ditto the 'ip' command)

See also: http://comments.gmane.org/gmane.network.openswan.user/21974

I cannot find a fix for my other issues so I will have to downgrade the version for now
Comment 1 Mike Gilbert gentoo-dev 2013-09-04 16:23:57 UTC
Sorry about that; I should have told ago to hold off on security bug 483204 to give it some time in ~arch.

I'll try to patch this /usr/bin/ss issue soon. If you are having other issues, please provide whatever information you can.
Comment 2 Agostino Sarubbo gentoo-dev 2013-09-04 18:13:03 UTC
I didn't notice it launching only the bin. Apologize for the issue.
Comment 3 Jeremy Olexa (darkside) (RETIRED) archtester gentoo-dev Security 2013-09-04 20:10:06 UTC
Created attachment 357854 [details]
log file diff

(In reply to Mike Gilbert from comment #1)

> I'll try to patch this /usr/bin/ss issue soon. If you are having other
> issues, please provide whatever information you can.

Hesitant to make this a troubleshooting forum (I hate that myself) but here is the log file diff between working and not (.38 vs .39)
Comment 4 Mike Gilbert gentoo-dev 2013-09-04 21:02:13 UTC
(In reply to Jeremy Olexa (darkside) from comment #3)
> Hesitant to make this a troubleshooting forum (I hate that myself) but here
> is the log file diff between working and not (.38 vs .39)

Right. I'll have a look at the log later, but I'm probably not going to be able to provide much insight. I just figured it would be a good idea to at least document it.

I'm personally not having any issues with my limited use case (a PSK L2TP VPN to a Windows server).
Comment 5 Jeremy Olexa (darkside) (RETIRED) archtester gentoo-dev Security 2013-09-04 23:45:16 UTC
Yea, basically when I start XL2TPD with debugging and have openswan (ipsec) 2.6.38 running, when the client connects I'll see Xl2TPD doing stuff. With openswan-2.6.39 running, there is nothing in the XL2TPD messages (literally nothing). So, something is obviously happening in that handoff area (or even before). Unfortunately, this is one of those pieces of software that I have running and have little working knowledge of...
Comment 6 Stefano 2013-12-25 15:53:03 UTC
Hi, I am having the same bug posted by Jeremy here (openswan does not hand the connection over to xl2tpd). Wanted to be safe, so I've also tried xl2tpd 1.3.2, unfortunately without luck. Does anyone have more insights on this?
Comment 7 Stefano 2013-12-25 17:10:25 UTC
Ok, weird, same setup for server and client, needed to change "leftprotoport=17/1701" to "leftprotoport=17/%any" to make it working...
Comment 8 Jeremy Olexa (darkside) (RETIRED) archtester gentoo-dev Security 2014-01-05 01:32:40 UTC
(In reply to Stefano from comment #7)
> Ok, weird, same setup for server and client, needed to change
> "leftprotoport=17/1701" to "leftprotoport=17/%any" to make it working...

Confirmed. Thanks for the tip.
Comment 9 Pacho Ramos gentoo-dev 2015-04-26 12:58:07 UTC
removed