untrusted comment: verify with openbsd-79-base.pub RWTSdNN9A3yvWA/CUDa/m73lAuSx2ibwUme5+Dyu0DjLpBbNyzPFc47iq+CgJBdZDf3HgQLZmUGKZ8zV1g4KPKnTlEYGihDWNQY= OpenBSD 7.9 errata 031, October 7, 2026: isakmpd(8) contains numerous bugs, which are fixed. Some debugging and logging features have been deleted to allow the use of pledge(2) and unveil(2) to constrain escalation for undiscovered bugs. Apply by doing: signify -Vep /etc/signify/openbsd-79-base.pub -x 031_isakmpd.patch.sig \ -m - | (cd /usr/src && patch -p0) And then rebuild and install isakpmd: cd /usr/src/sbin/isakmpd make obj make make install Index: sbin/isakmpd/conf.c =================================================================== RCS file: /cvs/src/sbin/isakmpd/conf.c,v diff -u -p -u -r1.108 conf.c --- sbin/isakmpd/conf.c 30 Apr 2025 03:53:21 -0000 1.108 +++ sbin/isakmpd/conf.c 1 Oct 2026 21:09:20 -0000 @@ -613,10 +613,10 @@ conf_reinit(void) size_t sz; char *new_conf_addr = 0; - fd = monitor_open(conf_path, O_RDONLY, 0); + fd = monitor_open(conf_path, O_RDONLY); if (fd == -1 || check_file_secrecy_fd(fd, conf_path, &sz) == -1) { if (fd == -1 && errno != ENOENT) - log_error("conf_reinit: open(\"%s\", O_RDONLY, 0) " + log_error("conf_reinit: open(\"%s\", O_RDONLY) " "failed", conf_path); if (fd != -1) close(fd); @@ -945,97 +945,4 @@ conf_end(int transaction, int commit) } } return 0; -} - -/* - * Dump running configuration upon SIGUSR1. - * Configuration is "stored in reverse order", so reverse it again. - */ -struct dumper { - char *s, *v; - struct dumper *next; -}; - -static void -conf_report_dump(struct dumper *node) -{ - /* Recursive, cleanup when we're done. */ - - if (node->next) - conf_report_dump(node->next); - - if (node->v) - LOG_DBG((LOG_REPORT, 0, "%s=\t%s", node->s, node->v)); - else if (node->s) { - LOG_DBG((LOG_REPORT, 0, "%s", node->s)); - if (strlen(node->s) > 0) - free(node->s); - } - free(node); -} - -void -conf_report(void) -{ - struct conf_binding *cb, *last = 0; - unsigned int i; - char *current_section = NULL; - struct dumper *dumper, *dnode; - - dumper = dnode = calloc(1, sizeof *dumper); - if (!dumper) - goto mem_fail; - - LOG_DBG((LOG_REPORT, 0, "conf_report: dumping running configuration")); - - for (i = 0; i < sizeof conf_bindings / sizeof conf_bindings[0]; i++) - for (cb = LIST_FIRST(&conf_bindings[i]); cb; - cb = LIST_NEXT(cb, link)) { - if (!cb->is_default) { - /* Dump this entry. */ - if (!current_section || strcmp(cb->section, - current_section)) { - if (current_section) { - if (asprintf(&dnode->s, "[%s]", - current_section) == -1) - goto mem_fail; - dnode->next = calloc(1, - sizeof(struct dumper)); - dnode = dnode->next; - if (!dnode) - goto mem_fail; - - dnode->s = ""; - dnode->next = calloc(1, - sizeof(struct dumper)); - dnode = dnode->next; - if (!dnode) - goto mem_fail; - } - current_section = cb->section; - } - dnode->s = cb->tag; - dnode->v = cb->value; - dnode->next = calloc(1, sizeof(struct dumper)); - dnode = dnode->next; - if (!dnode) - goto mem_fail; - last = cb; - } - } - - if (last) - if (asprintf(&dnode->s, "[%s]", last->section) == -1) - goto mem_fail; - conf_report_dump(dumper); - - return; - -mem_fail: - log_error("conf_report: malloc/calloc failed"); - while ((dnode = dumper) != 0) { - dumper = dumper->next; - free(dnode->s); - free(dnode); - } } Index: sbin/isakmpd/conf.h =================================================================== RCS file: /cvs/src/sbin/isakmpd/conf.h,v diff -u -p -u -r1.34 conf.h --- sbin/isakmpd/conf.h 30 Aug 2006 16:56:56 -0000 1.34 +++ sbin/isakmpd/conf.h 1 Oct 2026 21:09:20 -0000 @@ -100,6 +100,5 @@ extern void conf_reinit(void); extern int conf_remove(int, char *, char *); extern int conf_remove_section(int, char *); extern int conf_set(int, char *, char *, char *, int, int); -extern void conf_report(void); #endif /* _CONF_H_ */ Index: sbin/isakmpd/connection.c =================================================================== RCS file: /cvs/src/sbin/isakmpd/connection.c,v diff -u -p -u -r1.41 connection.c --- sbin/isakmpd/connection.c 15 Jan 2018 09:54:48 -0000 1.41 +++ sbin/isakmpd/connection.c 1 Oct 2026 21:09:20 -0000 @@ -400,30 +400,6 @@ connection_passive_teardown(char *name) free(conn); } -void -connection_report(void) -{ - struct connection *conn; - struct timespec now; - struct connection_passive *pconn; - struct doi *doi = doi_lookup(ISAKMP_DOI_ISAKMP); - - clock_gettime(CLOCK_MONOTONIC, &now); - for (conn = TAILQ_FIRST(&connections); conn; - conn = TAILQ_NEXT(conn, link)) - LOG_DBG((LOG_REPORT, 0, - "connection_report: connection %s next check %lld seconds", - (conn->name ? conn->name : ""), - (long long)(conn->ev->expiration.tv_sec - now.tv_sec))); - for (pconn = TAILQ_FIRST(&connections_passive); pconn; - pconn = TAILQ_NEXT(pconn, link)) - LOG_DBG((LOG_REPORT, 0, - "connection_report: passive connection %s %s", pconn->name, - doi->decode_ids("local_id: %s, remote_id: %s", - pconn->local_id, pconn->local_sz, - pconn->remote_id, pconn->remote_sz, 1))); -} - /* Reinitialize all connections (SIGHUP handling). */ void connection_reinit(void) Index: sbin/isakmpd/connection.h =================================================================== RCS file: /cvs/src/sbin/isakmpd/connection.h,v diff -u -p -u -r1.5 connection.h --- sbin/isakmpd/connection.h 15 Apr 2004 18:39:25 -0000 1.5 +++ sbin/isakmpd/connection.h 1 Oct 2026 21:09:20 -0000 @@ -43,7 +43,6 @@ extern int connection_exist(char *) extern void connection_init(void); extern char *connection_passive_lookup_by_ids(u_int8_t *, u_int8_t *); extern void connection_reinit(void); -extern void connection_report(void); extern int connection_setup(char *); extern int connection_record_passive(char *); extern void connection_teardown(char *); Index: sbin/isakmpd/exchange.c =================================================================== RCS file: /cvs/src/sbin/isakmpd/exchange.c,v diff -u -p -u -r1.142 exchange.c --- sbin/isakmpd/exchange.c 15 Jan 2018 09:54:48 -0000 1.142 +++ sbin/isakmpd/exchange.c 1 Oct 2026 21:09:20 -0000 @@ -73,7 +73,6 @@ */ #define MAX_BUCKET_BITS 16 -static void exchange_dump(char *, struct exchange *); static void exchange_free_aux(void *); static struct exchange *exchange_lookup_active(char *, int); @@ -807,7 +806,6 @@ exchange_establish_p1(struct transport * exchange_add_finalization(exchange, finalize, arg); cookie_gen(t, exchange, exchange->cookies, ISAKMP_HDR_ICOOKIE_LEN); exchange_enter(exchange); - exchange_dump("exchange_establish_p1", exchange); msg = message_alloc(t, 0, ISAKMP_HDR_SZ); if (!msg) { @@ -923,7 +921,6 @@ exchange_establish_p2(struct sa *isakmp_ if (isakmp_sa->flags & SA_FLAG_NAT_T_KEEPALIVE) exchange->flags |= EXCHANGE_FLAG_NAT_T_KEEPALIVE; exchange_enter(exchange); - exchange_dump("exchange_establish_p2", exchange); /* * Do not create SA's for informational exchanges. @@ -1091,7 +1088,6 @@ exchange_setup_p1(struct message *msg, u ISAKMP_HDR_ICOOKIE_LEN, ISAKMP_HDR_RCOOKIE_LEN); GET_ISAKMP_HDR_ICOOKIE(msg->iov[0].iov_base, exchange->cookies); exchange_enter(exchange); - exchange_dump("exchange_setup_p1", exchange); return exchange; } @@ -1114,66 +1110,9 @@ exchange_setup_p2(struct message *msg, u if (msg->isakmp_sa && (msg->isakmp_sa->flags & SA_FLAG_NAT_T_KEEPALIVE)) exchange->flags |= EXCHANGE_FLAG_NAT_T_KEEPALIVE; exchange_enter(exchange); - exchange_dump("exchange_setup_p2", exchange); return exchange; } -/* Dump interesting data about an exchange. */ -static void -exchange_dump_real(char *header, struct exchange *exchange, int class, - int level) -{ - struct sa *sa; - char buf[LOG_SIZE]; - /* Don't risk overflowing the final log buffer. */ - size_t bufsize_max = LOG_SIZE - strlen(header) - 32; - - LOG_DBG((class, level, - "%s: %p %s %s policy %s phase %d doi %d exchange %d step %d", - header, exchange, exchange->name ? exchange->name : "", - exchange->policy ? exchange->policy : "", - exchange->initiator ? "initiator" : "responder", exchange->phase, - exchange->doi->id, exchange->type, exchange->step)); - LOG_DBG((class, level, "%s: icookie %08x%08x rcookie %08x%08x", header, - decode_32(exchange->cookies), decode_32(exchange->cookies + 4), - decode_32(exchange->cookies + 8), - decode_32(exchange->cookies + 12))); - - /* Include phase 2 SA list for this exchange */ - if (exchange->phase == 2) { - snprintf(buf, bufsize_max, "sa_list "); - for (sa = TAILQ_FIRST(&exchange->sa_list); - sa && strlen(buf) < bufsize_max; sa = TAILQ_NEXT(sa, next)) - snprintf(buf + strlen(buf), bufsize_max - strlen(buf), - "%p ", sa); - if (sa) - strlcat(buf, "...", bufsize_max); - } else - buf[0] = '\0'; - - LOG_DBG((class, level, "%s: msgid %08x %s", header, - decode_32(exchange->message_id), buf)); -} - -static void -exchange_dump(char *header, struct exchange *exchange) -{ - exchange_dump_real(header, exchange, LOG_EXCHANGE, 10); -} - -void -exchange_report(void) -{ - struct exchange *exchange; - int i; - - for (i = 0; i <= bucket_mask; i++) - for (exchange = LIST_FIRST(&exchange_tab[i]); exchange; - exchange = LIST_NEXT(exchange, link)) - exchange_dump_real("exchange_report", exchange, - LOG_REPORT, 0); -} - /* * Release all resources this exchange is using *except* for the "death" * event. When removing an exchange from the expiration handler that event @@ -1317,8 +1256,6 @@ exchange_finalize(struct message *msg) int i; char *id_doi, *id_trp; - exchange_dump("exchange_finalize", exchange); - /* Copy the ID from phase 1 to exchange or phase 2 SA. */ if (msg->isakmp_sa) { if (exchange->id_i && exchange->id_r) { @@ -1457,12 +1394,6 @@ exchange_finalize(struct message *msg) exchange->finalize(exchange, exchange->finalize_arg, 0); exchange->finalize = 0; - /* - * There is no reason to keep the SAs connected to us anymore, in fact - * it can hurt us if we have short lifetimes on the SAs and we try - * to call exchange_report, where the SA list will be walked and - * references to freed SAs can occur. - */ while (TAILQ_FIRST(&exchange->sa_list)) { sa = TAILQ_FIRST(&exchange->sa_list); Index: sbin/isakmpd/exchange.h =================================================================== RCS file: /cvs/src/sbin/isakmpd/exchange.h,v diff -u -p -u -r1.37 exchange.h --- sbin/isakmpd/exchange.h 15 Jan 2018 09:54:48 -0000 1.37 +++ sbin/isakmpd/exchange.h 1 Oct 2026 21:09:20 -0000 @@ -242,7 +242,6 @@ extern void exchange_init(void); extern struct exchange *exchange_lookup(u_int8_t *, int); extern struct exchange *exchange_lookup_by_name(char *, int); extern struct exchange *exchange_lookup_from_icookie(u_int8_t *); -extern void exchange_report(void); extern void exchange_run(struct message *); extern int exchange_save_nonce(struct message *); extern int exchange_save_certreq(struct message *); Index: sbin/isakmpd/field.c =================================================================== RCS file: /cvs/src/sbin/isakmpd/field.c,v diff -u -p -u -r1.22 field.c --- sbin/isakmpd/field.c 2 Apr 2017 21:23:44 -0000 1.22 +++ sbin/isakmpd/field.c 1 Oct 2026 21:09:20 -0000 @@ -39,32 +39,6 @@ #include "log.h" #include "util.h" -static char *field_debug_raw(u_int8_t *, size_t, struct constant_map **); -static char *field_debug_num(u_int8_t *, size_t, struct constant_map **); -static char *field_debug_mask(u_int8_t *, size_t, struct constant_map **); -static char *field_debug_ign(u_int8_t *, size_t, struct constant_map **); -static char *field_debug_cst(u_int8_t *, size_t, struct constant_map **); - -/* Contents must match the enum in struct field. */ -static char *(*decode_field[]) (u_int8_t *, size_t, - struct constant_map **) = { - field_debug_raw, - field_debug_num, - field_debug_mask, - field_debug_ign, - field_debug_cst -}; - -/* - * Return a string showing the hexadecimal contents of the LEN-sized buffer - * BUF. MAPS should be zero and is only here because the API requires it. - */ -static char * -field_debug_raw(u_int8_t *buf, size_t len, struct constant_map **maps) -{ - return raw2hex(buf, len); -} - /* * Convert the unsigned LEN-sized number at BUF of network byteorder to a * 32-bit unsigned integer of host byteorder pointed to by VAL. @@ -86,112 +60,6 @@ extract_val(u_int8_t *buf, size_t len, u return -1; } return 0; -} - -/* - * Return a textual representation of the unsigned number pointed to by BUF - * which is LEN octets long. MAPS should be zero and is only here because - * the API requires it. - */ -static char * -field_debug_num(u_int8_t *buf, size_t len, struct constant_map **maps) -{ - char *retval; - u_int32_t val; - - if (extract_val(buf, len, &val)) - return NULL; - if (asprintf(&retval, "%u", val) == -1) - return NULL; - return retval; -} - -/* - * Return the symbolic names of the flags pointed to by BUF which is LEN - * octets long, using the constant maps MAPS. - */ -static char * -field_debug_mask(u_int8_t *buf, size_t len, struct constant_map **maps) -{ - u_int32_t val; - u_int32_t bit; - char *retval, *new_buf, *name; - size_t buf_sz; - - if (extract_val(buf, len, &val)) - return NULL; - - /* Size for brackets, two spaces and a NUL terminator. */ - buf_sz = 4; - retval = malloc(buf_sz); - if (!retval) - return NULL; - - strlcpy(retval, "[ ", buf_sz); - for (bit = 1; bit; bit <<= 1) { - if (val & bit) { - name = constant_name_maps(maps, bit); - buf_sz += strlen(name) + 1; - new_buf = realloc(retval, buf_sz); - if (!new_buf) { - free(retval); - return NULL; - } - retval = new_buf; - strlcat(retval, name, buf_sz); - strlcat(retval, " ", buf_sz); - } - } - strlcat(retval, "]", buf_sz); - return retval; -} - -/* - * Just a dummy needed to skip the unused LEN sized space at BUF. MAPS - * should be zero and is only here because the API requires it. - */ -static char * -field_debug_ign(u_int8_t *buf, size_t len, struct constant_map **maps) -{ - return NULL; -} - -/* - * Return the symbolic name of a constant pointed to by BUF which is LEN - * octets long, using the constant maps MAPS. - */ -static char * -field_debug_cst(u_int8_t *buf, size_t len, struct constant_map **maps) -{ - u_int32_t val; - - if (extract_val(buf, len, &val)) - return NULL; - - return strdup(constant_name_maps(maps, val)); -} - -/* Pretty-print a field from BUF as described by F. */ -void -field_dump_field(struct field *f, u_int8_t *buf) -{ - char *value; - - value = decode_field[(int) f->type] (buf + f->offset, f->len, f->maps); - if (value) { - LOG_DBG((LOG_MESSAGE, 70, "%s: %s", f->name, value)); - free(value); - } -} - -/* Pretty-print all the fields of BUF as described in FIELDS. */ -void -field_dump_payload(struct field *fields, u_int8_t *buf) -{ - struct field *field; - - for (field = fields; field->name; field++) - field_dump_field(field, buf); } /* Return the numeric value of the field F of BUF. */ Index: sbin/isakmpd/field.h =================================================================== RCS file: /cvs/src/sbin/isakmpd/field.h,v diff -u -p -u -r1.6 field.h --- sbin/isakmpd/field.h 23 May 2004 18:17:55 -0000 1.6 +++ sbin/isakmpd/field.h 1 Oct 2026 21:09:20 -0000 @@ -44,8 +44,6 @@ struct field { struct constant_map **maps; }; -extern void field_dump_field(struct field *, u_int8_t *); -extern void field_dump_payload(struct field *, u_int8_t *); extern u_int32_t field_get_num(struct field *, u_int8_t *); extern void field_get_raw(struct field *, u_int8_t *, u_int8_t *); extern void field_set_num(struct field *, u_int8_t *, u_int32_t); Index: sbin/isakmpd/ike_auth.c =================================================================== RCS file: /cvs/src/sbin/isakmpd/ike_auth.c,v diff -u -p -u -r1.118 ike_auth.c --- sbin/isakmpd/ike_auth.c 7 Jul 2020 17:33:40 -0000 1.118 +++ sbin/isakmpd/ike_auth.c 1 Oct 2026 21:09:20 -0000 @@ -195,7 +195,7 @@ ike_auth_get_key(int type, char *id, cha } keyfile = privkeyfile; - fd = monitor_open(keyfile, O_RDONLY, 0); + fd = monitor_open(keyfile, O_RDONLY); if (fd < 0) { free(keyfile); goto ignorekeynote; @@ -275,7 +275,7 @@ ignorekeynote: local_id); keyfile = privkeyfile; - fd = monitor_open(keyfile, O_RDONLY, 0); + fd = monitor_open(keyfile, O_RDONLY); if (fd == -1 && errno != ENOENT) { log_print("ike_auth_get_key: failed opening " "\"%s\"", keyfile); @@ -290,7 +290,7 @@ ignorekeynote: keyfile = conf_get_str("X509-certificates", "Private-key"); - fd = monitor_open(keyfile, O_RDONLY, 0); + fd = monitor_open(keyfile, O_RDONLY); if (fd == -1) { log_print("ike_auth_get_key: failed opening " "\"%s\"", keyfile); @@ -1115,6 +1115,7 @@ get_raw_key_from_file(int type, u_int8_t char filename[FILENAME_MAX]; char *fstr; FILE *keyfp; + int keyfd; if (type != IKE_AUTH_RSA_SIG) { /* XXX More types? */ LOG_DBG((LOG_NEGOTIATION, 20, "get_raw_key_from_file: " @@ -1141,8 +1142,11 @@ get_raw_key_from_file(int type, u_int8_t free(fstr); /* If the file does not exist, fail silently. */ - keyfp = monitor_fopen(filename, "r"); - if (keyfp) { + keyfd = monitor_open(filename, O_RDONLY); + if (keyfd != -1) { + keyfp = fdopen(keyfd, "r"); + if (keyfp == NULL) + return -1; *rsa = PEM_read_RSA_PUBKEY(keyfp, NULL, NULL, NULL); if (!*rsa) { rewind(keyfp); @@ -1153,7 +1157,7 @@ get_raw_key_from_file(int type, u_int8_t "public key %s", filename); fclose(keyfp); } else if (errno != ENOENT) { - log_error("get_raw_key_from_file: monitor_fopen " + log_error("get_raw_key_from_file: monitor_open " "(\"%s\", \"r\") failed", filename); return -1; } else Index: sbin/isakmpd/ike_quick_mode.c =================================================================== RCS file: /cvs/src/sbin/isakmpd/ike_quick_mode.c,v diff -u -p -u -r1.115 ike_quick_mode.c --- sbin/isakmpd/ike_quick_mode.c 31 Mar 2023 20:16:55 -0000 1.115 +++ sbin/isakmpd/ike_quick_mode.c 2 Oct 2026 22:10:00 -0000 @@ -1052,6 +1052,13 @@ initiator_recv_HASH_SA_NONCE(struct mess size_t rest_len; struct sockaddr *src, *dst; + if (hash == NULL || GET_ISAKMP_GEN_LENGTH(hashp->p) != + ISAKMP_HASH_SZ + hash->hashsize) { + message_drop(msg, ISAKMP_NOTIFY_INVALID_HASH_INFORMATION, 0, 1, + 0); + return -1; + } + /* Allocate the prf and start calculating our HASH(1). XXX Share? */ LOG_DBG_BUF((LOG_NEGOTIATION, 90, "initiator_recv_HASH_SA_NONCE: " "SKEYID_a", (u_int8_t *)isa->skeyid_a, isa->skeyid_len)); @@ -1490,6 +1497,7 @@ responder_recv_HASH_SA_NONCE(struct mess struct sa *sa; struct sa *isakmp_sa = msg->isakmp_sa; struct ipsec_sa *isa = isakmp_sa->data; + struct hash *hashfunc = hash_get(isa->hash); struct exchange *exchange = msg->exchange; struct ipsec_exch *ie = exchange->data; struct prf *prf; @@ -1513,6 +1521,12 @@ responder_recv_HASH_SA_NONCE(struct mess goto cleanup; } hash_len = GET_ISAKMP_GEN_LENGTH(hash); + if (hashfunc == NULL || hash_len != + ISAKMP_HASH_SZ + hashfunc->hashsize) { + message_drop(msg, ISAKMP_NOTIFY_INVALID_HASH_INFORMATION, 0, 1, + 0); + goto cleanup; + } my_hash = malloc(hash_len - ISAKMP_GEN_SZ); if (!my_hash) { log_error("responder_recv_HASH_SA_NONCE: malloc (%lu) failed", @@ -1958,6 +1972,7 @@ responder_recv_HASH(struct message *msg) struct exchange *exchange = msg->exchange; struct sa *isakmp_sa = msg->isakmp_sa; struct ipsec_sa *isa = isakmp_sa->data; + struct hash *hashfunc = hash_get(isa->hash); struct prf *prf; u_int8_t *hash, *my_hash = 0; size_t hash_len; @@ -1968,6 +1983,12 @@ responder_recv_HASH(struct message *msg) hash = hashp->p; hashp->flags |= PL_MARK; hash_len = GET_ISAKMP_GEN_LENGTH(hash); + if (hashfunc == NULL || hash_len != + ISAKMP_HASH_SZ + hashfunc->hashsize) { + message_drop(msg, ISAKMP_NOTIFY_INVALID_HASH_INFORMATION, 0, 1, + 0); + goto cleanup; + } my_hash = malloc(hash_len - ISAKMP_GEN_SZ); if (!my_hash) { log_error("responder_recv_HASH: malloc (%lu) failed", Index: sbin/isakmpd/ipsec.c =================================================================== RCS file: /cvs/src/sbin/isakmpd/ipsec.c,v diff -u -p -u -r1.155 ipsec.c --- sbin/isakmpd/ipsec.c 30 Apr 2025 03:53:21 -0000 1.155 +++ sbin/isakmpd/ipsec.c 1 Oct 2026 21:09:20 -0000 @@ -597,7 +597,7 @@ ipsec_set_network(u_int8_t *src_id, u_in } if (((proto = TAILQ_FIRST(&sa->protos)) != NULL) && - ((iproto = proto->data) != NULL) && + ((iproto = proto->data) != NULL) && (iproto->encap_mode == IPSEC_ENCAP_UDP_ENCAP_TRANSPORT || iproto->encap_mode == IPSEC_ENCAP_UDP_ENCAP_TRANSPORT_DRAFT)) { /* Index: sbin/isakmpd/isakmpd.8 =================================================================== RCS file: /cvs/src/sbin/isakmpd/isakmpd.8,v diff -u -p -u -r1.123 isakmpd.8 --- sbin/isakmpd/isakmpd.8 30 Aug 2019 17:51:47 -0000 1.123 +++ sbin/isakmpd/isakmpd.8 1 Oct 2026 21:09:20 -0000 @@ -42,11 +42,9 @@ .Op Fl c Ar config-file .Op Fl D Ar class Ns = Ns Ar level .Op Fl f Ar fifo -.Op Fl i Ar pid-file .Op Fl l Ar packetlog-file .Op Fl N Ar udpencap-port .Op Fl p Ar listen-port -.Op Fl R Ar report-file .Sh DESCRIPTION The .Nm @@ -219,15 +217,6 @@ If the path given is a dash .Pq Sq \&- , .Nm will listen to stdin instead. -.It Fl i Ar pid-file -By default the PID of the daemon process will be written to -.Pa /var/run/isakmpd.pid . -This path can be overridden by specifying another one as the argument to the -.Fl i -option. -Note that only paths beginning with -.Pa /var/run -are allowed. .It Fl K When this option is given, .Nm @@ -239,24 +228,6 @@ arranged by other programs like .Xr ipsecctl 8 or .Xr bgpd 8 . -.It Fl L -Enable IKE packet capture. -When this option is given, -.Nm -will write an unencrypted copy of the negotiation packets it -is sending and receiving to the file -.Pa /var/run/isakmpd.pcap , -which can later be read by -.Xr tcpdump 8 -and other utilities using -.Xr pcap_open_offline 3 . -.It Fl l Ar packetlog-file -As option -.Fl L -above, but capture to a specified file. -Note that only paths beginning with -.Pa /var/run -are allowed. .It Fl N Ar udpencap-port The .Fl N @@ -272,20 +243,6 @@ SAs in the IPsec stack. The .Fl p option specifies the listen port the daemon will bind to. -.It Fl R Ar report-file -When you signal -.Nm -a -.Dv SIGUSR1 , -it will report its internal state to a report file, normally -.Pa /var/run/isakmpd.report , -but this can be changed by feeding -the file name as an argument to the -.Fl R -flag. -Note that only paths beginning with -.Pa /var/run -are allowed. .It Fl S This option is used for setups using .Xr sasyncd 8 @@ -356,12 +313,6 @@ NOTE: Sending a .Dv SIGHUP or an "R" through the FIFO will void any updates done to the configuration. -.Pp -.It Ic C get Oo Ar section Oc : Ns Ar tag -Get the configuration value of the specified section and tag. -The result is stored in -.Pa /var/run/isakmpd.result . -.Pp .It Ic c Ar name Start the named connection, if stopped or inactive. .Pp @@ -399,22 +350,6 @@ to active or passive mode. In passive mode no packets are sent to peers. .Pp .It Ic p on Ns Op = Ns Ar path -.It Ic p off -Enable or disable cleartext IKE packet capture. -When enabling, optionally specify which file -.Nm -should capture the packets to -(the default is -.Pa /var/run/isakmpd.pcap ) . -Note that only paths beginning with -.Pa /var/run -are allowed. -.Pp -.It Ic Q -Cleanly shutdown the daemon, as when sent a -.Dv SIGTERM -signal. -.Pp .It Ic R Reinitialize .Nm isakmpd , @@ -434,11 +369,6 @@ Same as when sent a .Dv SIGUSR1 signal. .Pp -.It Ic S -Report information on all known SAs to the -.Pa /var/run/isakmpd.result -file. -.Pp .It Ic T Tear down all active quick mode connections. .Pp @@ -729,26 +659,10 @@ The directory in which trusted public ke The keys must be named in the fashion described above. .It Pa /var/run/isakmpd.fifo The FIFO used to manually control -.Nm isakmpd . -.It Pa /var/run/isakmpd.pcap -The default IKE packet capture file. -.It Pa /var/run/isakmpd.pid -The PID of the current daemon. -.It Pa /var/run/isakmpd.report -The report file written when -.Dv SIGUSR1 -is received. -.It Pa /var/run/isakmpd.result -The report file written when the -.Sq S -or -.Sq "C get" -command is issued in the command FIFO. .El .Sh SEE ALSO .Xr openssl 1 , .Xr getnameinfo 3 , -.Xr pcap_open_offline 3 , .Xr ipsec 4 , .Xr ipsec.conf 5 , .Xr isakmpd.conf 5 , @@ -756,7 +670,6 @@ command is issued in the command FIFO. .Xr iked 8 , .Xr sasyncd 8 , .Xr ssl 8 , -.Xr tcpdump 8 .Sh STANDARDS .Rs .%A D. Piper Index: sbin/isakmpd/isakmpd.c =================================================================== RCS file: /cvs/src/sbin/isakmpd/isakmpd.c,v diff -u -p -u -r1.109 isakmpd.c --- sbin/isakmpd/isakmpd.c 8 Mar 2023 04:43:06 -0000 1.109 +++ sbin/isakmpd/isakmpd.c 1 Oct 2026 21:09:20 -0000 @@ -90,7 +90,6 @@ volatile sig_atomic_t sighupped = 0; * via the -R parameter. */ volatile sig_atomic_t sigusr1ed = 0; -static char *report_file = "/var/run/isakmpd.report"; /* * If we receive a TERM signal, perform a "clean shutdown" of the daemon. @@ -100,13 +99,6 @@ static char *report_file = "/var/run/ volatile sig_atomic_t sigtermed = 0; void daemon_shutdown_now(int); void set_slave_signals(void); -void sanitise_stdfd(void); - -/* The default path of the PID file. */ -char *pid_file = "/var/run/isakmpd.pid"; - -/* The path of the IKE packet capture log file. */ -static char *pcap_file = 0; static void usage(void) @@ -114,9 +106,8 @@ usage(void) extern char *__progname; fprintf(stderr, - "usage: %s [-46adKLnSTv] [-c config-file] [-D class=level] [-f fifo]\n" - " [-i pid-file] [-l packetlog-file] [-N udpencap-port]\n" - " [-p listen-port] [-R report-file]\n", + "usage: %s [-46adKnSTv] [-c config-file] [-D class=level] [-f fifo]\n" + " [-N udpencap-port] [-p listen-port]\n", __progname); exit(1); } @@ -126,9 +117,8 @@ parse_args(int argc, char *argv[]) { int ch; int cls, level; - int do_packetlog = 0; - while ((ch = getopt(argc, argv, "46ac:dD:f:i:KnN:p:Ll:R:STv")) != -1) { + while ((ch = getopt(argc, argv, "46ac:dD:f:KnN:p:STv")) != -1) { switch (ch) { case '4': bind_family |= BIND_FAMILY_INET4; @@ -167,10 +157,6 @@ parse_args(int argc, char *argv[]) ui_fifo = optarg; break; - case 'i': - pid_file = optarg; - break; - case 'K': ignore_policy++; break; @@ -187,18 +173,6 @@ parse_args(int argc, char *argv[]) udp_default_port = optarg; break; - case 'l': - pcap_file = optarg; - /* FALLTHROUGH */ - - case 'L': - do_packetlog++; - break; - - case 'R': - report_file = optarg; - break; - case 'S': delete_sas = 0; ui_daemon_passive = 1; @@ -219,11 +193,8 @@ parse_args(int argc, char *argv[]) argc -= optind; argv += optind; - if (argc > 0) + if (argc > 0) usage(); - - if (do_packetlog && !pcap_file) - pcap_file = PCAP_FILE_DEFAULT; } static void @@ -232,29 +203,6 @@ sighup(int sig) sighupped = 1; } -/* Report internal state on SIGUSR1. */ -static void -report(void) -{ - FILE *rfp, *old; - mode_t old_umask; - - old_umask = umask(S_IRWXG | S_IRWXO); - rfp = monitor_fopen(report_file, "w"); - umask(old_umask); - - if (!rfp) { - log_error("report: fopen (\"%s\", \"w\") failed", report_file); - return; - } - /* Divert the log channel to the report file during the report. */ - old = log_current(); - log_to(rfp); - ui_report("r"); - log_to(old); - fclose(rfp); -} - static void sigusr1(int sig) { @@ -296,6 +244,7 @@ set_slave_signals(void) signal(SIGUSR1, sigusr1); } +/* XXX reverse signal race */ static void daemon_shutdown(void) { @@ -327,61 +276,18 @@ daemon_shutdown(void) * the DELETE notifications have been sent, we can shutdown. */ - log_packet_stop(); log_print("isakmpd: exit"); exit(0); } } -/* Called on SIGTERM, SIGINT or by ui_shutdown_daemon(). */ +/* Called on SIGTERM or SIGINT */ void daemon_shutdown_now(int sig) { sigtermed = 1; } -/* Write pid file. */ -static void -write_pid_file(void) -{ - FILE *fp; - - unlink(pid_file); - - fp = fopen(pid_file, "w"); - if (fp != NULL) { - if (fprintf(fp, "%ld\n", (long) getpid()) < 0) - log_error("write_pid_file: failed to write PID to " - "\"%.100s\"", pid_file); - fclose(fp); - } else - log_fatal("write_pid_file: fopen (\"%.100s\", \"w\") failed", - pid_file); -} - -void -sanitise_stdfd(void) -{ - int nullfd, dupfd; - - if ((nullfd = dupfd = open(_PATH_DEVNULL, O_RDWR)) == -1) { - fprintf(stderr, "Couldn't open /dev/null: %s\n", - strerror(errno)); - exit(1); - } - while (++dupfd <= STDERR_FILENO) { - /* Only populate closed fds */ - if (fcntl(dupfd, F_GETFL) == -1 && errno == EBADF) { - if (dup2(nullfd, dupfd) == -1) { - fprintf(stderr, "dup2: %s\n", strerror(errno)); - exit(1); - } - } - } - if (nullfd > STDERR_FILENO) - close(nullfd); -} - int main(int argc, char *argv[]) { @@ -390,14 +296,6 @@ main(int argc, char *argv[]) size_t mask_size; struct timespec ts, *timeout; - closefrom(STDERR_FILENO + 1); - - /* - * Make sure init() won't alloc fd 0, 1 or 2, as daemon() will close - * them. - */ - sanitise_stdfd(); - /* Log cmd line parsing and initialization errors to stderr. */ log_to(stderr); parse_args(argc, argv); @@ -420,8 +318,6 @@ main(int argc, char *argv[]) /* Set timezone before priv'separation */ tzset(); - write_pid_file(); - if (monitor_init(debug)) { /* The parent, with privileges enters infinite monitor loop. */ monitor_loop(debug); @@ -431,10 +327,6 @@ main(int argc, char *argv[]) init(); - /* If we wanted IKE packet capture to file, initialize it now. */ - if (pcap_file != 0) - log_packet_init(pcap_file); - /* Allocate the file descriptor sets just big enough. */ n = getdtablesize(); mask_size = howmany(n, NFDBITS) * sizeof(fd_mask); @@ -460,7 +352,6 @@ main(int argc, char *argv[]) if (sigusr1ed) { sigusr1ed = 0; log_print("SIGUSR1 received"); - report(); } /* * and if someone set 'sigtermed' (SIGTERM, SIGINT or via the Index: sbin/isakmpd/log.c =================================================================== RCS file: /cvs/src/sbin/isakmpd/log.c,v diff -u -p -u -r1.65 log.c --- sbin/isakmpd/log.c 28 Apr 2024 16:43:42 -0000 1.65 +++ sbin/isakmpd/log.c 1 Oct 2026 21:09:20 -0000 @@ -42,8 +42,6 @@ #include #include -#include - #include #include #include @@ -65,32 +63,6 @@ static FILE *log_output; int verbose_logging = 0; static int log_level[LOG_ENDCLASS]; -#define TCPDUMP_MAGIC 0xa1b2c3d4 -#define SNAPLEN (64 * 1024) - -struct packhdr { - struct pcap_pkthdr pcap;/* pcap file packet header */ - u_int32_t sa_family; /* address family */ - union { - struct ip ip4; /* IPv4 header (w/o options) */ - struct ip6_hdr ip6; /* IPv6 header */ - } ip; -}; - -struct isakmp_hdr { - u_int8_t icookie[8], rcookie[8]; - u_int8_t next, ver, type, flags; - u_int32_t msgid, len; -}; - -static char *pcaplog_file = NULL; -static FILE *packet_log; -static u_int8_t *packet_buf = NULL; - -static int udp_cksum(struct packhdr *, const struct udphdr *, - u_int16_t *); -static u_int16_t in_cksum(const u_int16_t *, int); - void log_init(int debug) { @@ -381,316 +353,4 @@ log_fatalx(const char *fmt, ...) _log_print(0, LOG_CRIT, fmt, ap, LOG_PRINT, 0); va_end(ap); monitor_exit(1); -} - -void -log_packet_init(char *newname) -{ - struct pcap_file_header sf_hdr; - struct stat st; - mode_t old_umask; - char *mode; - - /* Allocate packet buffer first time through. */ - if (!packet_buf) - packet_buf = malloc(SNAPLEN); - - if (!packet_buf) { - log_error("log_packet_init: malloc (%d) failed", SNAPLEN); - return; - } - if (pcaplog_file && strcmp(pcaplog_file, PCAP_FILE_DEFAULT) != 0) - free(pcaplog_file); - - pcaplog_file = strdup(newname); - if (!pcaplog_file) { - log_error("log_packet_init: strdup (\"%s\") failed", newname); - return; - } - /* Does the file already exist? XXX lstat() or stat()? */ - /* XXX This is a fstat! */ - if (monitor_stat(pcaplog_file, &st) == 0) { - /* Sanity checks. */ - if (!S_ISREG(st.st_mode)) { - log_print("log_packet_init: existing capture file is " - "not a regular file"); - return; - } - if ((st.st_mode & (S_IRWXG | S_IRWXO)) != 0) { - log_print("log_packet_init: existing capture " - "file has bad modes"); - return; - } - /* - * XXX It would be nice to check if it actually is a pcap - * file... - */ - - mode = "a"; - } else - mode = "w"; - - old_umask = umask(S_IRWXG | S_IRWXO); - packet_log = monitor_fopen(pcaplog_file, mode); - umask(old_umask); - - if (!packet_log) { - log_error("log_packet_init: fopen (\"%s\", \"%s\") failed", - pcaplog_file, mode); - return; - } - log_print("log_packet_init: " - "starting IKE packet capture to file \"%s\"", pcaplog_file); - - /* If this is a new file, we need to write a PCAP header to it. */ - if (*mode == 'w') { - sf_hdr.magic = TCPDUMP_MAGIC; - sf_hdr.version_major = PCAP_VERSION_MAJOR; - sf_hdr.version_minor = PCAP_VERSION_MINOR; - sf_hdr.thiszone = 0; - sf_hdr.snaplen = SNAPLEN; - sf_hdr.sigfigs = 0; - sf_hdr.linktype = DLT_LOOP; - - fwrite((char *) &sf_hdr, sizeof sf_hdr, 1, packet_log); - fflush(packet_log); - } -} - -void -log_packet_restart(char *newname) -{ - if (packet_log) { - log_print("log_packet_restart: capture already active on " - "file \"%s\"", pcaplog_file); - return; - } - if (newname) - log_packet_init(newname); - else if (!pcaplog_file) - log_packet_init(PCAP_FILE_DEFAULT); - else - log_packet_init(pcaplog_file); -} - -void -log_packet_stop(void) -{ - /* Stop capture. */ - if (packet_log) { - fclose(packet_log); - log_print("log_packet_stop: stopped capture"); - } - packet_log = 0; -} - -void -log_packet_iov(struct sockaddr *src, struct sockaddr *dst, struct iovec *iov, - int iovcnt) -{ - struct isakmp_hdr *isakmphdr; - struct packhdr hdr; - struct udphdr udp; - struct timeval tv; - int off, datalen, hdrlen, i, add_espmarker = 0; - const u_int32_t espmarker = 0; - - for (i = 0, datalen = 0; i < iovcnt; i++) - datalen += iov[i].iov_len; - - if (!packet_log || datalen > SNAPLEN) - return; - - /* copy packet into buffer */ - for (i = 0, off = 0; i < iovcnt; i++) { - memcpy(packet_buf + off, iov[i].iov_base, iov[i].iov_len); - off += iov[i].iov_len; - } - - bzero(&hdr, sizeof hdr); - bzero(&udp, sizeof udp); - - /* isakmp - turn off the encryption bit in the isakmp hdr */ - isakmphdr = (struct isakmp_hdr *) packet_buf; - isakmphdr->flags &= ~(ISAKMP_FLAGS_ENC); - - /* udp */ - udp.uh_sport = sockaddr_port(src); - udp.uh_dport = sockaddr_port(dst); - datalen += sizeof udp; - if (ntohs(udp.uh_sport) == 4500 || - ntohs(udp.uh_dport) == 4500) { /* XXX Quick and dirty */ - add_espmarker = 1; - datalen += sizeof espmarker; - } - udp.uh_ulen = htons(datalen); - - /* ip */ - hdr.sa_family = htonl(src->sa_family); - switch (src->sa_family) { - default: - /* Assume IPv4. XXX Can 'default' ever happen here? */ - hdr.sa_family = htonl(AF_INET); - hdr.ip.ip4.ip_src.s_addr = 0x02020202; - hdr.ip.ip4.ip_dst.s_addr = 0x01010101; - /* The rest of the setup is common to AF_INET. */ - goto setup_ip4; - - case AF_INET: - hdr.ip.ip4.ip_src.s_addr = - ((struct sockaddr_in *)src)->sin_addr.s_addr; - hdr.ip.ip4.ip_dst.s_addr = - ((struct sockaddr_in *)dst)->sin_addr.s_addr; - -setup_ip4: - hdrlen = sizeof hdr.ip.ip4; - hdr.ip.ip4.ip_v = 0x4; - hdr.ip.ip4.ip_hl = 0x5; - hdr.ip.ip4.ip_p = IPPROTO_UDP; - hdr.ip.ip4.ip_len = htons(datalen + hdrlen); - /* Let's use the IP ID as a "packet counter". */ - i = ntohs(hdr.ip.ip4.ip_id) + 1; - hdr.ip.ip4.ip_id = htons(i); - /* Calculate IP header checksum. */ - hdr.ip.ip4.ip_sum = in_cksum((u_int16_t *) & hdr.ip.ip4, - hdr.ip.ip4.ip_hl << 2); - break; - - case AF_INET6: - hdrlen = sizeof(hdr.ip.ip6); - hdr.ip.ip6.ip6_vfc = IPV6_VERSION; - hdr.ip.ip6.ip6_nxt = IPPROTO_UDP; - hdr.ip.ip6.ip6_plen = udp.uh_ulen; - memcpy(&hdr.ip.ip6.ip6_src, - &((struct sockaddr_in6 *)src)->sin6_addr, - sizeof hdr.ip.ip6.ip6_src); - memcpy(&hdr.ip.ip6.ip6_dst, - &((struct sockaddr_in6 *)dst)->sin6_addr, - sizeof hdr.ip.ip6.ip6_dst); - break; - } - - /* Calculate UDP checksum. */ - udp.uh_sum = udp_cksum(&hdr, &udp, (u_int16_t *) packet_buf); - hdrlen += sizeof hdr.sa_family; - - /* pcap file packet header */ - gettimeofday(&tv, 0); - hdr.pcap.ts.tv_sec = tv.tv_sec; - hdr.pcap.ts.tv_usec = tv.tv_usec; - hdr.pcap.caplen = datalen + hdrlen; - hdr.pcap.len = datalen + hdrlen; - - hdrlen += sizeof(struct pcap_pkthdr); - datalen -= sizeof(struct udphdr); - - /* Write to pcap file. */ - fwrite(&hdr, hdrlen, 1, packet_log); /* pcap + IP */ - fwrite(&udp, sizeof(struct udphdr), 1, packet_log); /* UDP */ - if (add_espmarker) { - fwrite(&espmarker, sizeof espmarker, 1, packet_log); - datalen -= sizeof espmarker; - } - fwrite(packet_buf, datalen, 1, packet_log); /* IKE-data */ - fflush(packet_log); -} - -/* Copied from tcpdump/print-udp.c, mostly rewritten. */ -static int -udp_cksum(struct packhdr *hdr, const struct udphdr *u, u_int16_t *d) -{ - struct ip *ip4; - struct ip6_hdr *ip6; - int i, hdrlen, tlen = ntohs(u->uh_ulen) - sizeof(struct udphdr); - - union phu { - struct ip4pseudo { - struct in_addr src; - struct in_addr dst; - u_int8_t z; - u_int8_t proto; - u_int16_t len; - } ip4p; - struct ip6pseudo { - struct in6_addr src; - struct in6_addr dst; - u_int32_t plen; - u_int16_t z0; - u_int8_t z1; - u_int8_t nxt; - } ip6p; - u_int16_t pa[20]; - } phu; - const u_int16_t *sp; - u_int32_t sum; - - /* Setup pseudoheader. */ - bzero(phu.pa, sizeof phu); - switch (ntohl(hdr->sa_family)) { - case AF_INET: - ip4 = &hdr->ip.ip4; - memcpy(&phu.ip4p.src, &ip4->ip_src, sizeof(struct in_addr)); - memcpy(&phu.ip4p.dst, &ip4->ip_dst, sizeof(struct in_addr)); - phu.ip4p.proto = ip4->ip_p; - phu.ip4p.len = u->uh_ulen; - hdrlen = sizeof phu.ip4p; - break; - - case AF_INET6: - ip6 = &hdr->ip.ip6; - memcpy(&phu.ip6p.src, &ip6->ip6_src, sizeof(phu.ip6p.src)); - memcpy(&phu.ip6p.dst, &ip6->ip6_dst, sizeof(phu.ip6p.dst)); - phu.ip6p.plen = u->uh_ulen; - phu.ip6p.nxt = ip6->ip6_nxt; - hdrlen = sizeof phu.ip6p; - break; - - default: - return 0; - } - - /* IPv6 wants a 0xFFFF checksum "on error", not 0x0. */ - if (tlen < 0) - return (ntohl(hdr->sa_family) == AF_INET ? 0 : 0xFFFF); - - sum = 0; - for (i = 0; i < hdrlen; i += 2) - sum += phu.pa[i / 2]; - - sp = (const u_int16_t *)u; - for (i = 0; i < (int)sizeof(struct udphdr); i += 2) - sum += *sp++; - - sp = d; - for (i = 0; i < (tlen & ~1); i += 2) - sum += *sp++; - - if (tlen & 1) - sum += htons((*(const char *)sp) << 8); - - while (sum > 0xffff) - sum = (sum & 0xffff) + (sum >> 16); - sum = ~sum & 0xffff; - - return sum; -} - -/* Copied from tcpdump/print-ip.c, modified. */ -static u_int16_t -in_cksum(const u_int16_t *w, int len) -{ - int nleft = len, sum = 0; - u_int16_t answer; - - while (nleft > 1) { - sum += *w++; - nleft -= 2; - } - if (nleft == 1) - sum += htons(*(const u_char *)w << 8); - - sum = (sum >> 16) + (sum & 0xffff); /* add hi 16 to low 16 */ - sum += (sum >> 16); /* add carry */ - answer = ~sum; /* truncate to 16 bits */ - return answer; } Index: sbin/isakmpd/log.h =================================================================== RCS file: /cvs/src/sbin/isakmpd/log.h,v diff -u -p -u -r1.25 log.h --- sbin/isakmpd/log.h 22 Dec 2008 14:30:04 -0000 1.25 +++ sbin/isakmpd/log.h 1 Oct 2026 21:09:20 -0000 @@ -70,13 +70,6 @@ extern void log_debug_buf(int, int, extern void log_debug_cmd(int, int); extern void log_debug_toggle(void); -#define PCAP_FILE_DEFAULT "/var/run/isakmpd.pcap" -extern void log_packet_init(char *); -extern void log_packet_iov(struct sockaddr *, struct sockaddr *, - struct iovec *, int); -extern void log_packet_restart(char *); -extern void log_packet_stop(void); - extern FILE *log_current(void); extern void log_error(const char *,...) __attribute__((__format__(__printf__, 1, 2))); Index: sbin/isakmpd/message.c =================================================================== RCS file: /cvs/src/sbin/isakmpd/message.c,v diff -u -p -u -r1.129 message.c --- sbin/isakmpd/message.c 4 Apr 2016 17:35:07 -0000 1.129 +++ sbin/isakmpd/message.c 2 Oct 2026 22:10:00 -0000 @@ -73,7 +73,6 @@ static int message_index_payload(struct u_int8_t ,u_int8_t *); static int message_parse_transform(struct message *, struct payload *, u_int8_t, u_int8_t *); -static struct field *message_get_field(u_int8_t); static int message_validate_payload(struct message *, struct payload *, u_int8_t); static u_int16_t message_payload_sz(u_int8_t); @@ -94,8 +93,6 @@ static int message_validate_sig(str static int message_validate_transform(struct message *, struct payload *); static int message_validate_vendor(struct message *, struct payload *); -static void message_packet_log(struct message *); - /* * Fields used for checking monotonic increasing of proposal and transform * numbers. @@ -376,56 +373,6 @@ message_parse_transform(struct message * return 0; } -static struct field * -message_get_field(u_int8_t payload) -{ - switch (payload) { - case ISAKMP_PAYLOAD_SA: - return isakmp_sa_fld; - case ISAKMP_PAYLOAD_PROPOSAL: - return isakmp_prop_fld; - case ISAKMP_PAYLOAD_TRANSFORM: - return isakmp_transform_fld; - case ISAKMP_PAYLOAD_KEY_EXCH: - return isakmp_ke_fld; - case ISAKMP_PAYLOAD_ID: - return isakmp_id_fld; - case ISAKMP_PAYLOAD_CERT: - return isakmp_cert_fld; - case ISAKMP_PAYLOAD_CERT_REQ: - return isakmp_certreq_fld; - case ISAKMP_PAYLOAD_HASH: - return isakmp_hash_fld; - case ISAKMP_PAYLOAD_SIG: - return isakmp_sig_fld; - case ISAKMP_PAYLOAD_NONCE: - return isakmp_nonce_fld; - case ISAKMP_PAYLOAD_NOTIFY: - return isakmp_notify_fld; - case ISAKMP_PAYLOAD_DELETE: - return isakmp_delete_fld; - case ISAKMP_PAYLOAD_VENDOR: - return isakmp_vendor_fld; - case ISAKMP_PAYLOAD_ATTRIBUTE: - return isakmp_attribute_fld; - case ISAKMP_PAYLOAD_NAT_D: - case ISAKMP_PAYLOAD_NAT_D_DRAFT: - return isakmp_nat_d_fld; - case ISAKMP_PAYLOAD_NAT_OA: - case ISAKMP_PAYLOAD_NAT_OA_DRAFT: - return isakmp_nat_oa_fld; - /* Not yet supported and any other unknown payloads. */ - case ISAKMP_PAYLOAD_SAK: - case ISAKMP_PAYLOAD_SAT: - case ISAKMP_PAYLOAD_KD: - case ISAKMP_PAYLOAD_SEQ: - case ISAKMP_PAYLOAD_POP: - default: - break; - } - return NULL; -} - static int message_validate_payload(struct message *m, struct payload *p, u_int8_t payload) { @@ -719,6 +666,9 @@ message_validate_hash(struct message *ms hash = hash_get(isa->hash); if (hash == NULL) goto invalid; + if (GET_ISAKMP_GEN_LENGTH(hashp->p) != + ISAKMP_HASH_SZ + hash->hashsize) + goto invalid; /* If no SKEYID_a, we can not do anything (should not happen). */ if (!isa->skeyid_a) @@ -1214,15 +1164,12 @@ message_validate_payloads(struct message { int i; struct payload *p; - struct field *f; for (i = ISAKMP_PAYLOAD_SA; i < ISAKMP_PAYLOAD_MAX; i++) TAILQ_FOREACH(p, &msg->payload[i], link) { LOG_DBG((LOG_MESSAGE, 60, "message_validate_payloads: " "payload %s at %p of message %p", constant_name(isakmp_payload_cst, i), p->p, msg)); - if ((f = message_get_field(i)) != NULL) - field_dump_payload(f, p->p); if (message_validate_payload(msg, p, i)) return -1; } @@ -1253,8 +1200,6 @@ message_recv(struct message *msg) message_drop(msg, 0, 0, 1, 1); return -1; } - /* Possibly dump a raw hex image of the message to the log channel. */ - message_dump_raw("message_recv", msg, LOG_MESSAGE); /* * If the responder cookie is zero, this is a request to setup an @@ -1434,9 +1379,6 @@ message_recv(struct message *msg) msg->orig = buf; msg->orig_sz = sz; - /* IKE packet capture */ - message_packet_log(msg); - /* * Check the overall payload structure at the same time as indexing * them by type. @@ -1547,8 +1489,6 @@ message_send(struct message *msg) timer_remove_event(msg->retrans); msg->retrans = 0; } - /* IKE packet capture */ - message_packet_log(msg); /* * If the ISAKMP SA has set up encryption, encrypt the message. @@ -1574,7 +1514,6 @@ message_send(struct message *msg) GET_ISAKMP_HDR_FLAGS(msg->iov[0].iov_base) | ISAKMP_FLAGS_COMMIT); - message_dump_raw("message_send", msg, LOG_MESSAGE); msg->flags |= MSG_IN_TRANSIT; exchange->in_transit = msg; @@ -1912,61 +1851,6 @@ message_drop(struct message *msg, int no incoming); if (clean) message_free(msg); -} - -/* - * If the user demands debug printouts, printout MSG with as much detail - * as we can without resorting to per-payload handling. - */ -void -message_dump_raw(char *header, struct message *msg, int class) -{ - u_int32_t i, j, k = 0; - char buf[80], *p = buf; - - LOG_DBG((class, 70, "%s: message %p", header, msg)); - field_dump_payload(isakmp_hdr_fld, msg->iov[0].iov_base); - for (i = 0; i < msg->iovlen; i++) - for (j = 0; j < msg->iov[i].iov_len; j++) { - snprintf(p, sizeof buf - (int) (p - buf), "%02x", - ((u_int8_t *) msg->iov[i].iov_base)[j]); - p += strlen(p); - if (++k % 32 == 0) { - *p = '\0'; - LOG_DBG((class, 70, "%s: %s", header, buf)); - p = buf; - } else if (k % 4 == 0) - *p++ = ' '; - } - *p = '\0'; - if (p != buf) - LOG_DBG((class, 70, "%s: %s", header, buf)); -} - -static void -message_packet_log(struct message *msg) -{ - struct sockaddr *src, *dst; - struct transport *t = msg->transport; - - /* Don't log retransmissions. Redundant for incoming packets... */ - if (msg->xmits > 0) - return; - - if (msg->exchange && msg->exchange->flags & EXCHANGE_FLAG_NAT_T_ENABLE) - t = ((struct virtual_transport *)msg->transport)->encap; - - /* Figure out direction. */ - if (msg->exchange && - msg->exchange->initiator ^ (msg->exchange->step % 2)) { - t->vtbl->get_src(t, &src); - t->vtbl->get_dst(t, &dst); - } else { - t->vtbl->get_src(t, &dst); - t->vtbl->get_dst(t, &src); - } - - log_packet_iov(src, dst, msg->iov, msg->iovlen); } /* Index: sbin/isakmpd/message.h =================================================================== RCS file: /cvs/src/sbin/isakmpd/message.h,v diff -u -p -u -r1.30 message.h --- sbin/isakmpd/message.h 21 May 2024 05:00:47 -0000 1.30 +++ sbin/isakmpd/message.h 1 Oct 2026 21:09:20 -0000 @@ -180,7 +180,6 @@ extern struct message *message_alloc(str extern struct message *message_alloc_reply(struct message *); extern u_int8_t *message_copy(struct message *, size_t, size_t *); extern void message_drop(struct message *, int, struct proto *, int, int); -extern void message_dump_raw(char *, struct message *, int); extern void message_free(struct message *); extern int message_negotiate_sa(struct message *, int (*)(struct exchange *, struct sa *, struct sa *)); Index: sbin/isakmpd/monitor.c =================================================================== RCS file: /cvs/src/sbin/isakmpd/monitor.c,v diff -u -p -u -r1.83 monitor.c --- sbin/isakmpd/monitor.c 8 Feb 2023 08:03:11 -0000 1.83 +++ sbin/isakmpd/monitor.c 1 Oct 2026 21:09:20 -0000 @@ -58,8 +58,6 @@ struct monitor_state { char root[PATH_MAX]; } m_state; -extern char *pid_file; - extern void set_slave_signals(void); /* Private functions. */ @@ -71,7 +69,6 @@ static void m_priv_setsockopt(void); static void m_priv_req_readdir(void); static void m_priv_bind(void); static void m_priv_pfkey_open(void); -static int m_priv_local_sanitize_path(const char *, size_t, int); static int m_priv_check_sockopt(int, int); static int m_priv_check_bind(const struct sockaddr *, socklen_t); @@ -101,45 +98,45 @@ monitor_init(int debug) strlcpy(m_state.root, pw->pw_dir, sizeof m_state.root); set_monitor_signals(); - m_state.pid = fork(); - if (m_state.pid == -1) + switch ((m_state.pid = fork())) { + case -1: log_fatal("monitor_init: fork of unprivileged child failed"); - if (m_state.pid == 0) { + break; + case 0: /* The child process drops privileges. */ set_slave_signals(); if (chroot(pw->pw_dir) != 0 || chdir("/") != 0) - log_fatal("monitor_init: chroot failed"); + log_fatal("monitor_init: chroot in child failed"); if (setgroups(1, &pw->pw_gid) == -1 || setresgid(pw->pw_gid, pw->pw_gid, pw->pw_gid) || setresuid(pw->pw_uid, pw->pw_uid, pw->pw_uid)) log_fatal("monitor_init: can't drop privileges"); + if (pledge("stdio sendfd route recvfd inet", NULL) == -1) + log_fatal("monitor_init: pledge in child failed"); + m_state.s = p[0]; close(p[1]); LOG_DBG((LOG_MISC, 10, "monitor_init: privileges dropped for child process")); - } else { + break; + default: /* Privileged monitor. */ setproctitle("monitor [priv]"); + if (unveil(ISAKMPD_ROOT, "r") == -1) + log_fatal("monitor_init: unveil %s", ISAKMPD_ROOT); + if (unveil(NULL, NULL) == -1) + log_fatal("monitor_init: unveil"); + m_state.s = p[1]; close(p[0]); + break; } - - /* With "-dd", stop and wait here. For gdb "attach" etc. */ - if (debug > 1) { - log_print("monitor_init: stopped %s PID %d fd %d%s", - m_state.pid ? "priv" : "child", getpid(), m_state.s, - m_state.pid ? ", waiting for SIGCONT" : ""); - kill(getpid(), SIGSTOP); /* Wait here for SIGCONT. */ - if (m_state.pid) - kill(m_state.pid, SIGCONT); /* Continue child. */ - } - return m_state.pid; } @@ -161,7 +158,6 @@ monitor_exit(int code) /* Remove FIFO and pid files. */ unlink(ui_fifo); - unlink(pid_file); } close(m_state.s); @@ -195,27 +191,19 @@ monitor_pf_key_v2_open(void) } int -monitor_open(const char *path, int flags, mode_t mode) +monitor_open(const char *path, int flags) { size_t len; int fd, err, cmd; - char pathreal[PATH_MAX]; - - if (path[0] == '/') - strlcpy(pathreal, path, sizeof pathreal); - else - snprintf(pathreal, sizeof pathreal, "%s/%s", m_state.root, - path); cmd = MONITOR_GET_FD; must_write(&cmd, sizeof cmd); - len = strlen(pathreal); + len = strlen(path); must_write(&len, sizeof len); - must_write(&pathreal, len); + must_write(path, len); must_write(&flags, sizeof flags); - must_write(&mode, sizeof mode); must_read(&err, sizeof err); if (err != 0) { @@ -232,71 +220,6 @@ monitor_open(const char *path, int flags return fd; } -FILE * -monitor_fopen(const char *path, const char *mode) -{ - FILE *fp; - int fd, flags = 0, saved_errno; - mode_t mask, cur_umask; - - /* Only the child process is supposed to run this. */ - if (m_state.pid) - log_fatal("[priv] bad call to monitor_fopen"); - - switch (mode[0]) { - case 'r': - flags = (mode[1] == '+' ? O_RDWR : O_RDONLY); - break; - case 'w': - flags = (mode[1] == '+' ? O_RDWR : O_WRONLY) | O_CREAT | - O_TRUNC; - break; - case 'a': - flags = (mode[1] == '+' ? O_RDWR : O_WRONLY) | O_CREAT | - O_APPEND; - break; - default: - log_fatal("monitor_fopen: bad call"); - } - - cur_umask = umask(0); - (void)umask(cur_umask); - mask = S_IRUSR | S_IWUSR | S_IRGRP | S_IWGRP | S_IROTH | S_IWOTH; - mask &= ~cur_umask; - - fd = monitor_open(path, flags, mask); - if (fd < 0) - return NULL; - - /* Got the fd, attach a FILE * to it. */ - fp = fdopen(fd, mode); - if (!fp) { - log_error("monitor_fopen: fdopen() failed"); - saved_errno = errno; - close(fd); - errno = saved_errno; - return NULL; - } - return fp; -} - -int -monitor_stat(const char *path, struct stat *sb) -{ - int fd, r, saved_errno; - - /* O_NONBLOCK is needed for stat'ing fifos. */ - fd = monitor_open(path, O_RDONLY | O_NONBLOCK, 0); - if (fd < 0) - return -1; - - r = fstat(fd, sb); - saved_errno = errno; - close(fd); - errno = saved_errno; - return r; -} - int monitor_setsockopt(int s, int level, int optname, const void *optval, socklen_t optlen) @@ -422,7 +345,7 @@ sig_pass_to_chld(int sig) void monitor_loop(int debug) { - int msgcode; + int msgcode, init_done = 0; if (!debug) log_to(0); @@ -438,6 +361,8 @@ monitor_loop(int debug) case MONITOR_PFKEY_OPEN: LOG_DBG((LOG_MISC, 80, "monitor_loop: MONITOR_PFKEY_OPEN")); + if (init_done) + log_fatal("monitor_loop: not allowed"); m_priv_pfkey_open(); break; @@ -462,15 +387,13 @@ monitor_loop(int debug) case MONITOR_INIT_DONE: LOG_DBG((LOG_MISC, 80, "monitor_loop: MONITOR_INIT_DONE")); - break; - - case MONITOR_SHUTDOWN: - LOG_DBG((LOG_MISC, 80, - "monitor_loop: MONITOR_SHUTDOWN")); + if (init_done) + log_fatal("monitor_loop: not allowed"); + init_done = 1; break; default: - log_print("monitor_loop: got unknown code %d", + log_error("monitor_loop: got unknown code %d", msgcode); } } @@ -504,10 +427,10 @@ static void m_priv_getfd(void) { char path[PATH_MAX]; + struct stat sb; size_t len; - int v, flags, ret; + int fd, flags; int err = 0; - mode_t mode; must_read(&len, sizeof len); if (len == 0 || len >= sizeof path) @@ -519,25 +442,26 @@ m_priv_getfd(void) log_fatal("m_priv_getfd: invalid pathname"); must_read(&flags, sizeof flags); - must_read(&mode, sizeof mode); + if (flags != O_RDONLY) + log_fatal("m_priv_getfd: invalid open flags"); - if ((ret = m_priv_local_sanitize_path(path, sizeof path, flags)) - != 0) { - if (errno != ENOENT) - log_print("m_priv_getfd: illegal path \"%s\"", path); + flags |= O_NOFOLLOW; + if ((fd = open(path, flags)) == -1) err = errno; - v = -1; - } else { - if ((v = open(path, flags, mode)) == -1) - err = errno; + + if (fd != -1 && (fstat(fd, &sb) == -1 || S_ISREG(sb.st_mode) == 0)) { + log_error("m_priv_getfd: not an actual file %s", path); + close(fd); + fd = -1; + err = EPERM; } must_write(&err, sizeof err); - if (v != -1) { - if (mm_send_fd(m_state.s, v) == -1) + if (fd != -1) { + if (mm_send_fd(m_state.s, fd) == -1) log_error("m_priv_getfd: sending fd failed"); - close(v); + close(fd); } } @@ -687,55 +611,6 @@ must_write(const void *buf, size_t n) } } -/* Check that path/mode is permitted. */ -static int -m_priv_local_sanitize_path(const char *path, size_t pmax, int flags) -{ - char new_path[PATH_MAX], var_run[PATH_MAX], *enddir; - - /* - * We only permit paths starting with - * /etc/isakmpd/ (read only) - * /var/run/ (rw) - */ - - if (realpath(path, new_path) == NULL) { - if (errno != ENOENT) - return 1; - /* - * It is ok if the directory exists, - * but the file should be created. - */ - if (strlcpy(new_path, path, sizeof(new_path)) >= - sizeof(new_path)) - return 1; - enddir = strrchr(new_path, '/'); - if (enddir == NULL || enddir[1] == '\0') - return 1; - enddir[1] = '\0'; - if (realpath(new_path, new_path) == NULL) { - errno = ENOENT; - return 1; - } - enddir = strrchr(path, '/'); - strlcat(new_path, enddir, sizeof(new_path)); - } - - if (realpath("/var/run/", var_run) == NULL) - return 1; - strlcat(var_run, "/", sizeof(var_run)); - - if (strncmp(var_run, new_path, strlen(var_run)) == 0) - return 0; - - if (strncmp(ISAKMPD_ROOT, new_path, strlen(ISAKMPD_ROOT)) == 0 && - (flags & O_ACCMODE) == O_RDONLY) - return 0; - - errno = EACCES; - return 1; -} - /* Check setsockopt */ static int m_priv_check_sockopt(int level, int name) @@ -823,24 +698,21 @@ static void m_priv_req_readdir(void) { size_t len; - char path[PATH_MAX]; + char dirpath[PATH_MAX], filepath[PATH_MAX]; DIR *dp; struct dirent *file; struct stat sb; - int off, size, fd, ret, serrno; + int fd, ret, serrno; must_read(&len, sizeof len); - if (len == 0 || len >= sizeof path) + if (len == 0 || len >= sizeof dirpath) log_fatal("m_priv_req_readdir: invalid pathname length"); - must_read(path, len); - path[len] = '\0'; - if (strlen(path) != len) + must_read(dirpath, len); + dirpath[len] = '\0'; + if (strlen(dirpath) != len) log_fatal("m_priv_req_readdir: invalid pathname"); - off = strlen(path); - size = sizeof path - off; - - if ((dp = opendir(path)) == NULL) { + if ((dp = opendir(dirpath)) == NULL) { serrno = errno; ret = -1; must_write(&ret, sizeof ret); @@ -853,26 +725,31 @@ m_priv_req_readdir(void) must_write(&ret, sizeof ret); while ((file = readdir(dp)) != NULL) { - strlcpy(path + off, file->d_name, size); - - if (m_priv_local_sanitize_path(path, sizeof path, O_RDONLY) - != 0) + if (strcmp(file->d_name, ".") == 0 || + strcmp(file->d_name, "..") == 0) continue; - fd = open(path, O_RDONLY); + fd = openat(dirfd(dp), file->d_name, O_RDONLY|O_NOFOLLOW); if (fd == -1) { log_error("m_priv_req_readdir: open " - "(\"%s\", O_RDONLY, 0) failed", path); + "(\"%s\", O_RDONLY) failed", dirpath); + close(fd); continue; } - if ((fstat(fd, &sb) == -1) || - !(S_ISREG(sb.st_mode) || S_ISLNK(sb.st_mode))) { + if (fstat(fd, &sb) == -1 || S_ISREG(sb.st_mode) == 0) { + close(fd); + fd = -1; + continue; + } + + if ((len = snprintf(filepath, sizeof filepath, + "%s/%s", dirpath, file->d_name)) >= sizeof(filepath)) { + /* Long filenames are silently skipped */ close(fd); continue; } - len = strlen(path); must_write(&len, sizeof len); - must_write(path, len); + must_write(filepath, len); mm_send_fd(m_state.s, fd); close(fd); Index: sbin/isakmpd/monitor.h =================================================================== RCS file: /cvs/src/sbin/isakmpd/monitor.h,v diff -u -p -u -r1.19 monitor.h --- sbin/isakmpd/monitor.h 22 Dec 2008 14:30:04 -0000 1.19 +++ sbin/isakmpd/monitor.h 1 Oct 2026 21:09:20 -0000 @@ -40,9 +40,7 @@ enum monitor_reqtypes { MONITOR_SETSOCKOPT, MONITOR_BIND, MONITOR_REQ_READDIR, - MONITOR_MKFIFO, - MONITOR_INIT_DONE, - MONITOR_SHUTDOWN + MONITOR_INIT_DONE }; pid_t monitor_init(int); @@ -51,9 +49,7 @@ void monitor_loop(int); int mm_send_fd(int, int); int mm_receive_fd(int); -FILE *monitor_fopen(const char *, const char *); -int monitor_open(const char *, int, mode_t); -int monitor_stat(const char *, struct stat *); +int monitor_open(const char *, int); int monitor_setsockopt(int, int, int, const void *, socklen_t); int monitor_bind(int, const struct sockaddr *, socklen_t); int monitor_req_readdir(const char *); Index: sbin/isakmpd/pf_key_v2.c =================================================================== RCS file: /cvs/src/sbin/isakmpd/pf_key_v2.c,v diff -u -p -u -r1.205 pf_key_v2.c --- sbin/isakmpd/pf_key_v2.c 7 Aug 2023 04:01:30 -0000 1.205 +++ sbin/isakmpd/pf_key_v2.c 1 Oct 2026 21:09:20 -0000 @@ -892,6 +892,7 @@ pf_key_v2_set_spi(struct sa *sa, struct char *addr_str, *s; char iface_str[32]; + bzero(&iface_str, sizeof(iface_str)); msg.sadb_msg_type = incoming ? SADB_UPDATE : SADB_ADD; switch (proto->proto) { case IPSEC_PROTO_IPSEC_ESP: @@ -3102,7 +3103,7 @@ pf_key_v2_acquire(struct pf_key_v2_msg * goto fail; } } - } else + } else pf_key_v2_conf_refinc(af, configname); /* Set the ISAKMP-peer section. */ Index: sbin/isakmpd/policy.c =================================================================== RCS file: /cvs/src/sbin/isakmpd/policy.c,v diff -u -p -u -r1.103 policy.c --- sbin/isakmpd/policy.c 28 Apr 2024 16:43:42 -0000 1.103 +++ sbin/isakmpd/policy.c 1 Oct 2026 21:09:20 -0000 @@ -1943,7 +1943,7 @@ policy_init(void) policy_file = CONF_DFLT_POLICY_FILE; /* Open policy file. */ - fd = monitor_open(policy_file, O_RDONLY, 0); + fd = monitor_open(policy_file, O_RDONLY); if (fd == -1) log_fatal("policy_init: open (\"%s\", O_RDONLY) failed", policy_file); @@ -2159,6 +2159,14 @@ keynote_cert_obtain(u_int8_t *id, size_t case IPSEC_ID_FQDN: case IPSEC_ID_USER_FQDN: + /* The ID becomes exactly one pathname component. */ + if (id_len == 0 || memchr(id, '\0', id_len) != NULL || + memchr(id, '/', id_len) != NULL || + (id_len == 1 && id[0] == '.') || + (id_len == 2 && memcmp(id, "..", 2) == 0)) { + log_print("keynote_cert_obtain: invalid textual ID"); + return 0; + } file = calloc(len + id_len, sizeof(char)); if (file == NULL) { log_error("keynote_cert_obtain: " @@ -2176,7 +2184,7 @@ keynote_cert_obtain(u_int8_t *id, size_t return 0; } - fd = monitor_open(file, O_RDONLY, 0); + fd = monitor_open(file, O_RDONLY); if (fd < 0) { LOG_DBG((LOG_POLICY, 30, "keynote_cert_obtain: " "failed to open \"%s\"", file)); @@ -2206,8 +2214,8 @@ keynote_cert_obtain(u_int8_t *id, size_t LOG_DBG((LOG_POLICY, 30, "keynote_cert_obtain: " "failed to read %lu bytes from \"%s\"", (unsigned long)size, file)); - free(cert); - cert = NULL; + free(*cert); + *cert = NULL; free(file); close(fd); return 0; Index: sbin/isakmpd/sa.c =================================================================== RCS file: /cvs/src/sbin/isakmpd/sa.c,v diff -u -p -u -r1.125 sa.c --- sbin/isakmpd/sa.c 28 Jan 2022 05:24:15 -0000 1.125 +++ sbin/isakmpd/sa.c 1 Oct 2026 21:09:20 -0000 @@ -207,7 +207,7 @@ _net_addrcmp(struct sockaddr *sa1, struc case AF_INET6: if (((struct sockaddr_in6 *)sa1)->sin6_scope_id != ((struct sockaddr_in6 *)sa2)->sin6_scope_id) - return (((struct sockaddr_in6 *)sa1)->sin6_scope_id < + return (((struct sockaddr_in6 *)sa1)->sin6_scope_id < ((struct sockaddr_in6 *)sa2)->sin6_scope_id) ? -1 : 1; return memcmp(&((struct sockaddr_in6 *)sa1)->sin6_addr, @@ -454,346 +454,6 @@ sa_create(struct exchange *exchange, str return 0; } -/* - * Dump the internal state of SA to the report channel, with HEADER - * prepended to each line. - */ -void -sa_dump(int cls, int level, char *header, struct sa *sa) -{ - struct proto *proto; - char spi_header[80]; - int i; - - LOG_DBG((cls, level, "%s: %p %s phase %d doi %d flags 0x%x", header, - sa, sa->name ? sa->name : "", sa->phase, sa->doi->id, - sa->flags)); - LOG_DBG((cls, level, "%s: icookie %08x%08x rcookie %08x%08x", header, - decode_32(sa->cookies), decode_32(sa->cookies + 4), - decode_32(sa->cookies + 8), decode_32(sa->cookies + 12))); - LOG_DBG((cls, level, "%s: msgid %08x refcnt %d", header, - decode_32(sa->message_id), sa->refcnt)); - LOG_DBG((cls, level, "%s: life secs %llu kb %llu", header, sa->seconds, - sa->kilobytes)); - for (proto = TAILQ_FIRST(&sa->protos); proto; - proto = TAILQ_NEXT(proto, link)) { - LOG_DBG((cls, level, "%s: suite %d proto %d", header, - proto->no, proto->proto)); - LOG_DBG((cls, level, - "%s: spi_sz[0] %d spi[0] %p spi_sz[1] %d spi[1] %p", - header, proto->spi_sz[0], proto->spi[0], proto->spi_sz[1], - proto->spi[1])); - LOG_DBG((cls, level, "%s: %s, %s", header, - !sa->doi ? "" : - sa->doi->decode_ids("initiator id: %s, responder id: %s", - sa->id_i, sa->id_i_len, - sa->id_r, sa->id_r_len, 0), - !sa->transport ? "" : - sa->transport->vtbl->decode_ids(sa->transport))); - for (i = 0; i < 2; i++) - if (proto->spi[i]) { - snprintf(spi_header, sizeof spi_header, - "%s: spi[%d]", header, i); - LOG_DBG_BUF((cls, level, spi_header, - proto->spi[i], proto->spi_sz[i])); - } - } -} - -/* - * Display the SA's two SPI values. - */ -static void -report_spi(FILE *fd, const u_int8_t *buf, size_t sz, int spi) -{ -#define SBUFSZ (2 * 32 + 9) - char s[SBUFSZ]; - size_t i, j; - - for (i = j = 0; i < sz;) { - snprintf(s + j, sizeof s - j, "%02x", buf[i++]); - j += strlen(s + j); - if (i % 4 == 0) { - if (i % 32 == 0) { - s[j] = '\0'; - fprintf(fd, "%s", s); - j = 0; - } else - s[j++] = ' '; - } - } - - if (j) { - s[j] = '\0'; - fprintf(fd, "SPI %d: %s\n", spi, s); - } -} - -/* - * Display the transform names to file. - * Structure is taken from pf_key_v2.c, pf_key_v2_set_spi. - * Transform names are taken from /usr/src/sys/crypto/xform.c. - */ -static void -report_proto(FILE *fd, struct proto *proto) -{ - struct ipsec_proto *iproto; - int keylen, hashlen; - - switch (proto->proto) { - case IPSEC_PROTO_IPSEC_ESP: - keylen = ipsec_esp_enckeylength(proto); - hashlen = ipsec_esp_authkeylength(proto); - fprintf(fd, "Transform: IPsec ESP\n"); - fprintf(fd, "Encryption key length: %d\n", keylen); - fprintf(fd, "Authentication key length: %d\n", hashlen); - - fprintf(fd, "Encryption algorithm: "); - switch (proto->id) { - case IPSEC_ESP_3DES: - fprintf(fd, "3DES\n"); - break; - - case IPSEC_ESP_AES: - fprintf(fd, "AES (CBC)\n"); - break; - - case IPSEC_ESP_AES_CTR: - fprintf(fd, "AES (CTR)\n"); - break; - - case IPSEC_ESP_AES_GCM_16: - fprintf(fd, "AES (GCM)\n"); - break; - - case IPSEC_ESP_AES_GMAC: - fprintf(fd, "AES (GMAC)\n"); - break; - - case IPSEC_ESP_CAST: - fprintf(fd, "Cast-128\n"); - break; - - case IPSEC_ESP_BLOWFISH: - fprintf(fd, "Blowfish\n"); - break; - - default: - fprintf(fd, "unknown (%d)\n", proto->id); - } - - fprintf(fd, "Authentication algorithm: "); - - if (!proto->data) { - fprintf(fd, "none\n"); - break; - } - iproto = proto->data; - - switch (iproto->auth) { - case IPSEC_AUTH_HMAC_MD5: - fprintf(fd, "HMAC-MD5\n"); - break; - - case IPSEC_AUTH_HMAC_SHA: - fprintf(fd, "HMAC-SHA1\n"); - break; - - case IPSEC_AUTH_HMAC_RIPEMD: - fprintf(fd, "HMAC-RIPEMD-160\n"); - break; - - case IPSEC_AUTH_HMAC_SHA2_256: - fprintf(fd, "HMAC-SHA2-256\n"); - break; - - case IPSEC_AUTH_HMAC_SHA2_384: - fprintf(fd, "HMAC-SHA2-384\n"); - break; - - case IPSEC_AUTH_HMAC_SHA2_512: - fprintf(fd, "HMAC-SHA2-512\n"); - break; - - case IPSEC_AUTH_DES_MAC: - case IPSEC_AUTH_KPDK: - /* XXX We should be supporting KPDK */ - fprintf(fd, "unknown (%d)", iproto->auth); - break; - - default: - fprintf(fd, "none\n"); - } - break; - - case IPSEC_PROTO_IPSEC_AH: - hashlen = ipsec_ah_keylength(proto); - fprintf(fd, "Transform: IPsec AH\n"); - fprintf(fd, "Encryption not used.\n"); - fprintf(fd, "Authentication key length: %d\n", hashlen); - - fprintf(fd, "Authentication algorithm: "); - switch (proto->id) { - case IPSEC_AH_MD5: - fprintf(fd, "HMAC-MD5\n"); - break; - - case IPSEC_AH_SHA: - fprintf(fd, "HMAC-SHA1\n"); - break; - - case IPSEC_AH_RIPEMD: - fprintf(fd, "HMAC-RIPEMD-160\n"); - break; - - case IPSEC_AH_SHA2_256: - fprintf(fd, "HMAC-SHA2-256\n"); - break; - - case IPSEC_AH_SHA2_384: - fprintf(fd, "HMAC-SHA2-384\n"); - break; - - case IPSEC_AH_SHA2_512: - fprintf(fd, "HMAC-SHA2-512\n"); - break; - - default: - fprintf(fd, "unknown (%d)", proto->id); - } - break; - - default: - fprintf(fd, "report_proto: invalid proto %d\n", proto->proto); - } -} - -/* - * Display SA lifetimes. - */ -static void -report_lifetimes(FILE *fd, struct sa *sa) -{ - long timeout; - - if (sa->seconds) - fprintf(fd, "Lifetime: %llu seconds\n", sa->seconds); - - if (sa->soft_death) { - timeout = get_timeout(&sa->soft_death->expiration); - if (timeout < 0) - fprintf(fd, "\n"); - else - fprintf(fd, "Soft timeout in %ld seconds\n", timeout); - } - - if (sa->death) { - timeout = get_timeout(&sa->death->expiration); - if (timeout < 0) - fprintf(fd, "No hard timeout>\n"); - else - fprintf(fd, "Hard timeout in %ld seconds\n", timeout); - } - - if (sa->kilobytes) - fprintf(fd, "Lifetime: %llu kilobytes\n", sa->kilobytes); -} - -/* - * Print phase 1 specific information. - */ -static void -report_phase1(FILE *fd, struct sa *sa) -{ - /* Cookies. */ - fprintf(fd, "icookie %08x%08x rcookie %08x%08x\n", - decode_32(sa->cookies), decode_32(sa->cookies + 4), - decode_32(sa->cookies + 8), decode_32(sa->cookies + 12)); -} - -/* - * Print phase 2 specific information. - */ -static void -report_phase2(FILE *fd, struct sa *sa) -{ - struct proto *proto; - int i; - - /* Transform information. */ - for (proto = TAILQ_FIRST(&sa->protos); proto; - proto = TAILQ_NEXT(proto, link)) { - - /* SPI values. */ - for (i = 0; i < 2; i++) - if (proto->spi[i]) - report_spi(fd, proto->spi[i], - proto->spi_sz[i], i); - else - fprintf(fd, "SPI %d not defined.\n", i); - - /* Proto values. */ - report_proto(fd, proto); - } -} - -/* Report all the SAs to the report channel. */ -void -sa_report(void) -{ - struct sa *sa; - int i; - - for (i = 0; i <= bucket_mask; i++) - for (sa = LIST_FIRST(&sa_tab[i]); sa; sa = LIST_NEXT(sa, link)) - sa_dump(LOG_REPORT, 0, "sa_report", sa); -} - -/* - * Print an SA's connection details to file SA_FILE. - */ -static void -sa_dump_all(FILE *fd, struct sa *sa) -{ - /* SA name and phase. */ - fprintf(fd, "SA name: %s", sa->name ? sa->name : ""); - fprintf(fd, " (Phase %d%s)\n", sa->phase, sa->phase == 1 ? - (sa->initiator ? "/Initiator" : "/Responder") : ""); - - /* Source and destination IPs. */ - fprintf(fd, "%s", sa->transport == NULL ? "" : - sa->transport->vtbl->decode_ids(sa->transport)); - fprintf(fd, "\n"); - - /* Lifetimes */ - report_lifetimes(fd, sa); - - fprintf(fd, "Flags 0x%08x\n", sa->flags); - - if (sa->phase == 1) - report_phase1(fd, sa); - else if (sa->phase == 2) - report_phase2(fd, sa); - else { - /* Should not happen, but... */ - fprintf(fd, "\n"); - } - - /* SA separator. */ - fprintf(fd, "\n"); -} - -/* Report info of all SAs to file 'fd'. */ -void -sa_report_all(FILE *fd) -{ - struct sa *sa; - int i; - - for (i = 0; i <= bucket_mask; i++) - for (sa = LIST_FIRST(&sa_tab[i]); sa; sa = LIST_NEXT(sa, link)) - sa_dump_all(fd, sa); -} /* Free the protocol structure pointed to by PROTO. */ void Index: sbin/isakmpd/sa.h =================================================================== RCS file: /cvs/src/sbin/isakmpd/sa.h,v diff -u -p -u -r1.55 sa.h --- sbin/isakmpd/sa.h 7 Aug 2023 04:01:30 -0000 1.55 +++ sbin/isakmpd/sa.h 1 Oct 2026 21:09:20 -0000 @@ -275,9 +275,6 @@ extern void sa_replace(struct sa *, extern void sa_reference(struct sa *); extern void sa_release(struct sa *); extern void sa_remove(struct sa *); -extern void sa_report(void); -extern void sa_dump(int, int, char *, struct sa *); -extern void sa_report_all(FILE *); extern int sa_setup_expirations(struct sa *); /* Index: sbin/isakmpd/timer.c =================================================================== RCS file: /cvs/src/sbin/isakmpd/timer.c,v diff -u -p -u -r1.18 timer.c --- sbin/isakmpd/timer.c 5 Dec 2017 20:31:45 -0000 1.18 +++ sbin/isakmpd/timer.c 1 Oct 2026 21:09:20 -0000 @@ -123,18 +123,3 @@ timer_remove_event(struct event *ev) TAILQ_REMOVE(&events, ev, link); free(ev); } - -void -timer_report(void) -{ - struct event *ev; - struct timespec now; - - clock_gettime(CLOCK_MONOTONIC, &now); - - for (ev = TAILQ_FIRST(&events); ev; ev = TAILQ_NEXT(ev, link)) - LOG_DBG((LOG_REPORT, 0, - "timer_report: event %s(%p) scheduled in %d seconds", - (ev->name ? ev->name : ""), ev, - (int) (ev->expiration.tv_sec - now.tv_sec))); -} Index: sbin/isakmpd/timer.h =================================================================== RCS file: /cvs/src/sbin/isakmpd/timer.h,v diff -u -p -u -r1.9 timer.h --- sbin/isakmpd/timer.h 5 Dec 2017 20:31:45 -0000 1.9 +++ sbin/isakmpd/timer.h 1 Oct 2026 21:09:20 -0000 @@ -50,6 +50,5 @@ extern void timer_handle_expirations extern struct event *timer_add_event(char *, void (*) (void *), void *, struct timespec *); extern void timer_remove_event(struct event *); -extern void timer_report(void); #endif /* _TIMER_H_ */ Index: sbin/isakmpd/transport.c =================================================================== RCS file: /cvs/src/sbin/isakmpd/transport.c,v diff -u -p -u -r1.39 transport.c --- sbin/isakmpd/transport.c 28 Jan 2021 01:18:44 -0000 1.39 +++ sbin/isakmpd/transport.c 1 Oct 2026 21:09:20 -0000 @@ -117,41 +117,6 @@ transport_release(struct transport *t) t->vtbl->remove(t); } -void -transport_report(void) -{ - struct virtual_transport *v; - struct transport *t; - struct message *msg; - - for (t = LIST_FIRST(&transport_list); t; t = LIST_NEXT(t, link)) { - LOG_DBG((LOG_REPORT, 0, - "transport_report: transport %p flags %x refcnt %d", t, - t->flags, t->refcnt)); - - /* XXX Report sth on the virtual transport? */ - t->vtbl->report(t); - - /* - * This is the reason message_dump_raw lives outside - * message.c. - */ - v = (struct virtual_transport *)t->virtual; - if ((v->encap_is_active && v->encap == t) || - (!v->encap_is_active && v->main == t)) { - for (msg = TAILQ_FIRST(&t->virtual->prio_sendq); msg; - msg = TAILQ_NEXT(msg, link)) - message_dump_raw("udp_report(prio)", msg, - LOG_REPORT); - - for (msg = TAILQ_FIRST(&t->virtual->sendq); msg; - msg = TAILQ_NEXT(msg, link)) - message_dump_raw("udp_report", msg, - LOG_REPORT); - } - } -} - int transport_prio_sendqs_empty(void) { Index: sbin/isakmpd/transport.h =================================================================== RCS file: /cvs/src/sbin/isakmpd/transport.h,v diff -u -p -u -r1.24 transport.h --- sbin/isakmpd/transport.h 28 Jan 2022 05:24:15 -0000 1.24 +++ sbin/isakmpd/transport.h 1 Oct 2026 21:09:20 -0000 @@ -67,9 +67,6 @@ struct transport_vtbl { /* Remove a transport instance of this method. */ void (*remove) (struct transport *); - /* Report status of given transport */ - void (*report) (struct transport *); - /* Let the given transport set its bit in the fd_set passed in. */ int (*fd_set) (struct transport *, fd_set *, int); @@ -155,7 +152,6 @@ extern int transport_prio_sendqs_em extern void transport_reference(struct transport *); extern void transport_reinit(void); extern void transport_release(struct transport *); -extern void transport_report(void); extern void transport_send_messages(fd_set *); extern void transport_setup(struct transport *, int); #endif /* _TRANSPORT_H_ */ Index: sbin/isakmpd/udp.c =================================================================== RCS file: /cvs/src/sbin/isakmpd/udp.c,v diff -u -p -u -r1.95 udp.c --- sbin/isakmpd/udp.c 22 Jul 2008 09:45:56 -0000 1.95 +++ sbin/isakmpd/udp.c 1 Oct 2026 21:09:20 -0000 @@ -73,7 +73,6 @@ char *udp_decode_ids(struct transport void udp_remove(struct transport *); static struct transport *udp_create(char *); -static void udp_report(struct transport *); static void udp_handle_message(struct transport *); static struct transport *udp_make(struct sockaddr *); static int udp_send_message(struct message *, struct transport *); @@ -83,7 +82,6 @@ static struct transport_vtbl udp_transpo udp_create, 0, udp_remove, - udp_report, udp_fd_set, udp_fd_isset, udp_handle_message, @@ -151,7 +149,7 @@ udp_make(struct sockaddr *laddr) * make sure it is entirely reuseable with SO_REUSEPORT. */ on = 1; - if (setsockopt(s, SOL_SOCKET, + if (monitor_setsockopt(s, SOL_SOCKET, wildcardaddress ? SO_REUSEPORT : SO_REUSEADDR, (void *)&on, sizeof on) == -1) { log_error("udp_make: setsockopt (%d, %d, %d, %p, %lu)", s, @@ -372,29 +370,6 @@ udp_remove(struct transport *t) LOG_DBG((LOG_TRANSPORT, 90, "udp_remove: removed transport %p", t)); free(t); -} - -/* Report transport-method specifics of the T transport. */ -void -udp_report(struct transport *t) -{ - struct udp_transport *u = (struct udp_transport *)t; - char *src = NULL, *dst = NULL; - in_port_t sport, dport; - - if (sockaddr2text(u->src, &src, 0)) - return; - sport = sockaddr_port(u->src); - - if (!u->dst || sockaddr2text(u->dst, &dst, 0)) - dst = 0; - dport = dst ? sockaddr_port(u->dst) : 0; - - LOG_DBG((LOG_REPORT, 0, "udp_report: fd %d src %s:%u dst %s:%u", u->s, - src, ntohs(sport), dst ? dst : "", ntohs(dport))); - - free(dst); - free(src); } /* Index: sbin/isakmpd/udp_encap.c =================================================================== RCS file: /cvs/src/sbin/isakmpd/udp_encap.c,v diff -u -p -u -r1.24 udp_encap.c --- sbin/isakmpd/udp_encap.c 16 Jan 2022 14:30:11 -0000 1.24 +++ sbin/isakmpd/udp_encap.c 1 Oct 2026 21:09:20 -0000 @@ -70,7 +70,6 @@ char *udp_decode_ids(struct transport void udp_remove(struct transport *); static struct transport *udp_encap_create(char *); -static void udp_encap_report(struct transport *); static void udp_encap_handle_message(struct transport *); static struct transport *udp_encap_make(struct sockaddr *); static int udp_encap_send_message(struct message *, @@ -81,7 +80,6 @@ static struct transport_vtbl udp_encap_t udp_encap_create, 0, udp_remove, - udp_encap_report, udp_fd_set, udp_fd_isset, udp_encap_handle_message, @@ -150,7 +148,7 @@ udp_encap_make(struct sockaddr *laddr) * SO_REUSEPORT. */ on = 1; - if (setsockopt(s, SOL_SOCKET, + if (monitor_setsockopt(s, SOL_SOCKET, wildcardaddress ? SO_REUSEPORT : SO_REUSEADDR, (void *)&on, sizeof on) == -1) { log_error("udp_encap_make: setsockopt (%d, %d, %d, %p, %lu)", @@ -312,29 +310,6 @@ ret: conf_free_list(addr_list); free(dst); return rv; -} - -/* Report transport-method specifics of the T transport. */ -void -udp_encap_report(struct transport *t) -{ - struct udp_transport *u = (struct udp_transport *)t; - char *src = NULL, *dst = NULL; - in_port_t sport, dport; - - if (sockaddr2text(u->src, &src, 0)) - return; - sport = sockaddr_port(u->src); - - if (!u->dst || sockaddr2text(u->dst, &dst, 0)) - dst = 0; - dport = dst ? sockaddr_port(u->dst) : 0; - - LOG_DBG ((LOG_REPORT, 0, "udp_encap_report: fd %d src %s:%u dst %s:%u", - u->s, src, ntohs(sport), dst ? dst : "*", ntohs(dport))); - - free(dst); - free(src); } /* Index: sbin/isakmpd/ui.c =================================================================== RCS file: /cvs/src/sbin/isakmpd/ui.c,v diff -u -p -u -r1.58 ui.c --- sbin/isakmpd/ui.c 24 Oct 2021 21:24:21 -0000 1.58 +++ sbin/isakmpd/ui.c 1 Oct 2026 21:09:20 -0000 @@ -60,11 +60,6 @@ /* from isakmpd.c */ void daemon_shutdown_now(int); -/* Report all SA configuration information. */ -void ui_report_sa(char *); - -static FILE *ui_open_result(void); - char *ui_fifo = FIFO; int ui_socket; struct event *ui_cr_event = NULL; @@ -224,25 +219,10 @@ ui_config(char *cmd) char subcmd[201], section[201], tag[201], value[201], tmp[201]; char *v, *nv; int trans = 0, items, skip = 0, ret; - FILE *fp; if (sscanf(cmd, "C %200s", subcmd) != 1) goto fail; - if (strcasecmp(subcmd, "get") == 0) { - if (sscanf(cmd, "C %*s [%200[^]]]:%200s", section, tag) != 2) - goto fail; - v = conf_get_str(section, tag); - fp = ui_open_result(); - if (fp) { - if (v) - fprintf(fp, "%s\n", v); - fclose(fp); - } - LOG_DBG((LOG_UI, 30, "ui_config: \"%s\"", cmd)); - return; - } - trans = conf_begin(); if (strcasecmp(subcmd, "set") == 0) { items = sscanf(cmd, "C %*s [%200[^]]]:%200[^=]=%200s %200s", @@ -413,67 +393,6 @@ ui_debug(char *cmd) } static void -ui_packetlog(char *cmd) -{ - char subcmd[201]; - - if (sscanf(cmd, "p %200s", subcmd) != 1) - goto fail; - - if (strncasecmp(subcmd, "on=", 3) == 0) { - /* Start capture to a new file. */ - if (subcmd[strlen(subcmd) - 1] == '\n') - subcmd[strlen(subcmd) - 1] = 0; - log_packet_restart(subcmd + 3); - } else if (strcasecmp(subcmd, "on") == 0) - log_packet_restart(NULL); - else if (strcasecmp(subcmd, "off") == 0) - log_packet_stop(); - return; - -fail: - log_print("ui_packetlog: command \"%s\" malformed", cmd); -} - -static void -ui_shutdown_daemon(char *cmd) -{ - if (strlen(cmd) == 1) { - log_print("ui_shutdown_daemon: received shutdown command"); - daemon_shutdown_now(0); - } else - log_print("ui_shutdown_daemon: command \"%s\" malformed", cmd); -} - -/* Report SAs and ongoing exchanges. */ -void -ui_report(char *cmd) -{ - /* XXX Skip 'cmd' as arg? */ - sa_report(); - exchange_report(); - transport_report(); - connection_report(); - timer_report(); - conf_report(); -} - -/* Report all SA configuration information. */ -void -ui_report_sa(char *cmd) -{ - FILE *fp = ui_open_result(); - - /* Skip 'cmd' as arg? */ - if (!fp) - return; - - sa_report_all(fp); - - fclose(fp); -} - -static void ui_setmode(char *cmd) { char arg[11]; @@ -481,19 +400,19 @@ ui_setmode(char *cmd) if (sscanf(cmd, "M %10s", arg) != 1) goto fail; if (strncmp(arg, "active", 6) == 0) { - if (ui_daemon_passive) + if (ui_daemon_passive) LOG_DBG((LOG_UI, 20, "ui_setmode: switching to active mode")); ui_daemon_passive = 0; } else if (strncmp(arg, "passive", 7) == 0) { - if (!ui_daemon_passive) + if (!ui_daemon_passive) LOG_DBG((LOG_UI, 20, "ui_setmode: switching to passive mode")); ui_daemon_passive = 1; } else goto fail; return; - + fail: log_print("ui_setmode: command \"%s\" malformed", cmd); } @@ -528,26 +447,10 @@ ui_handle_command(char *line) ui_setmode(line); break; - case 'p': - ui_packetlog(line); - break; - - case 'Q': - ui_shutdown_daemon(line); - break; - case 'R': reinit(); break; - case 'S': - ui_report_sa(line); - break; - - case 'r': - ui_report(line); - break; - case 't': ui_teardown(line); break; @@ -628,14 +531,4 @@ ui_handler(void) } p++; } -} - -static FILE * -ui_open_result(void) -{ - FILE *fp = monitor_fopen(RESULT_FILE, "w"); - - if (!fp) - log_error("ui_open_result: fopen() failed"); - return fp; } Index: sbin/isakmpd/ui.h =================================================================== RCS file: /cvs/src/sbin/isakmpd/ui.h,v diff -u -p -u -r1.8 ui.h --- sbin/isakmpd/ui.h 1 Sep 2006 00:24:06 -0000 1.8 +++ sbin/isakmpd/ui.h 1 Oct 2026 21:09:20 -0000 @@ -33,7 +33,6 @@ #define _UI_H_ #define FIFO "/var/run/isakmpd.fifo" -#define RESULT_FILE "/var/run/isakmpd.result" extern char *ui_fifo; extern int ui_socket; @@ -41,6 +40,5 @@ extern int ui_daemon_passive; extern void ui_handler(void); extern void ui_init(void); -extern void ui_report(char *); #endif /* _UI_H_ */ Index: sbin/isakmpd/util.c =================================================================== RCS file: /cvs/src/sbin/isakmpd/util.c,v diff -u -p -u -r1.72 util.c --- sbin/isakmpd/util.c 28 Jun 2019 13:32:44 -0000 1.72 +++ sbin/isakmpd/util.c 1 Oct 2026 21:09:20 -0000 @@ -52,12 +52,6 @@ #include "util.h" /* - * Set if -N is given, allowing name lookups to be done, possibly stalling - * the daemon for quite a while. - */ -int allow_name_lookups = 0; - -/* * XXX These might be turned into inlines or macros, maybe even * machine-dependent ones, for performance reasons. */ @@ -206,8 +200,7 @@ text2sockaddr(char *address, char *port, pid_t pid; bzero(&hints, sizeof hints); - if (!allow_name_lookups) - hints.ai_flags = AI_NUMERICHOST; + hints.ai_flags = AI_NUMERICHOST; hints.ai_family = PF_UNSPEC; hints.ai_socktype = SOCK_DGRAM; hints.ai_protocol = IPPROTO_UDP; @@ -356,7 +349,7 @@ sockaddr2text(struct sockaddr *sa, char long val; if (getnameinfo(sa, SA_LEN(sa), buf, sizeof buf, 0, 0, - allow_name_lookups ? 0 : NI_NUMERICHOST)) + NI_NUMERICHOST)) return -1; if (zflag == 0) { Index: sbin/isakmpd/util.h =================================================================== RCS file: /cvs/src/sbin/isakmpd/util.h,v diff -u -p -u -r1.33 util.h --- sbin/isakmpd/util.h 5 Dec 2017 20:31:45 -0000 1.33 +++ sbin/isakmpd/util.h 1 Oct 2026 21:09:20 -0000 @@ -49,7 +49,7 @@ extern u_int32_t decode_32(u_int8_t *); extern void encode_16(u_int8_t *, u_int16_t); extern void encode_32(u_int8_t *, u_int32_t); extern int hex2raw(char *, u_int8_t *, size_t); -extern char *raw2hex(u_int8_t *, size_t); +extern char *raw2hex(u_int8_t *, size_t); extern int sockaddr2text(struct sockaddr *, char **, int); extern u_int8_t *sockaddr_addrdata(struct sockaddr *); extern int sockaddr_addrlen(struct sockaddr *); Index: sbin/isakmpd/virtual.c =================================================================== RCS file: /cvs/src/sbin/isakmpd/virtual.c,v diff -u -p -u -r1.33 virtual.c --- sbin/isakmpd/virtual.c 28 Jun 2019 13:32:44 -0000 1.33 +++ sbin/isakmpd/virtual.c 1 Oct 2026 21:09:20 -0000 @@ -66,7 +66,6 @@ static void virtual_get_src(struct tra static void virtual_handle_message(struct transport *); static void virtual_reinit(void); static void virtual_remove(struct transport *); -static void virtual_report(struct transport *); static int virtual_send_message(struct message *, struct transport *); @@ -75,7 +74,6 @@ static struct transport_vtbl virtual_tra virtual_create, virtual_reinit, virtual_remove, - virtual_report, 0, 0, virtual_handle_message, @@ -630,11 +628,6 @@ virtual_remove(struct transport *t) LOG_DBG((LOG_TRANSPORT, 90, "virtual_remove: removed %p", v)); free(t); -} - -static void -virtual_report(struct transport *t) -{ } static void