From 00a442068d353fd60cbd743f2dfb42ee7407d267 Mon Sep 17 00:00:00 2001 From: Neale Ranns Date: Thu, 21 Mar 2019 16:36:28 +0000 Subject: IPSEC: test for packet drop on sequence number wrap Change-Id: Id546c56a4904d13d4278055f3c5a5e4548e2efd0 Signed-off-by: Neale Ranns --- src/plugins/unittest/CMakeLists.txt | 1 + src/plugins/unittest/ipsec_test.c | 75 +++++++++++++++++++++++++++++++++++++ 2 files changed, 76 insertions(+) create mode 100644 src/plugins/unittest/ipsec_test.c (limited to 'src/plugins/unittest') diff --git a/src/plugins/unittest/CMakeLists.txt b/src/plugins/unittest/CMakeLists.txt index 81db615da0f..74bcef3c208 100644 --- a/src/plugins/unittest/CMakeLists.txt +++ b/src/plugins/unittest/CMakeLists.txt @@ -21,6 +21,7 @@ add_vpp_plugin(unittest crypto/rfc2202_hmac_md5.c crypto/rfc4231.c fib_test.c + ipsec_test.c interface_test.c mfib_test.c session_test.c diff --git a/src/plugins/unittest/ipsec_test.c b/src/plugins/unittest/ipsec_test.c new file mode 100644 index 00000000000..ec39a2e9042 --- /dev/null +++ b/src/plugins/unittest/ipsec_test.c @@ -0,0 +1,75 @@ +/* + * Copyright (c) 2018 Cisco and/or its affiliates. + * Licensed under the Apache License, Version 2.0 (the "License"); + * you may not use this file except in compliance with the License. + * You may obtain a copy of the License at: + * + * http://www.apache.org/licenses/LICENSE-2.0 + * + * Unless required by applicable law or agreed to in writing, software + * distributed under the License is distributed on an "AS IS" BASIS, + * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + * See the License for the specific language governing permissions and + * limitations under the License. + */ + +#include +#include + +static clib_error_t * +test_ipsec_command_fn (vlib_main_t * vm, + unformat_input_t * input, vlib_cli_command_t * cmd) +{ + u64 seq_num; + u32 sa_id; + + sa_id = ~0; + seq_num = 0; + + while (unformat_check_input (input) != UNFORMAT_END_OF_INPUT) + { + if (unformat (input, "sa %d", &sa_id)) + ; + else if (unformat (input, "seq 0x%llx", &seq_num)) + ; + else + break; + } + + if (~0 != sa_id) + { + ipsec_main_t *im = &ipsec_main; + ipsec_sa_t *sa; + u32 sa_index; + + sa_index = ipsec_get_sa_index_by_sa_id (sa_id); + sa = pool_elt_at_index (im->sad, sa_index); + + sa->seq = seq_num & 0xffffffff; + sa->seq_hi = seq_num >> 32; + } + else + { + return clib_error_return (0, "unknown SA `%U'", + format_unformat_error, input); + } + + return (NULL); +} + +/* *INDENT-OFF* */ +VLIB_CLI_COMMAND (test_ipsec_command, static) = +{ + .path = "test ipsec", + .short_help = "test ipsec sa seq-num ", + .function = test_ipsec_command_fn, +}; +/* *INDENT-ON* */ + +/* + * fd.io coding-style-patch-verification: ON + * + * Local Variables: + * eval: (c-set-style "gnu") + * End: + */ -- cgit 1.2.3-korg