]> git.droids-corp.org - dpdk.git/commitdiff
ipsec: fix NAT-T ports and length
authorRadu Nicolau <radu.nicolau@intel.com>
Wed, 25 May 2022 13:59:10 +0000 (14:59 +0100)
committerAkhil Goyal <gakhil@marvell.com>
Tue, 21 Jun 2022 18:04:49 +0000 (20:04 +0200)
Fix the UDP header fields, wrong byte order used for src and dst port
and wrong offset used when updating UDP datagram length.

Fixes: 01eef5907fc3 ("ipsec: support NAT-T")
Cc: stable@dpdk.org
Signed-off-by: Radu Nicolau <radu.nicolau@intel.com>
Acked-by: Fan Zhang <roy.fan.zhang@intel.com>
lib/ipsec/esp_outb.c
lib/ipsec/sa.c

index 6925bb994510448856237bb5cab9a6fc6c2f18f4..5a5429a12b824d0100f96d4b8f44232fbf55ab09 100644 (file)
@@ -196,7 +196,7 @@ outb_tun_pkt_prepare(struct rte_ipsec_sa *sa, rte_be64_t sqc,
        /* if UDP encap is enabled update the dgram_len */
        if (sa->type & RTE_IPSEC_SATP_NATT_ENABLE) {
                struct rte_udp_hdr *udph = (struct rte_udp_hdr *)
-                               (ph - sizeof(struct rte_udp_hdr));
+                       (ph + sa->hdr_len - sizeof(struct rte_udp_hdr));
                udph->dgram_len = rte_cpu_to_be_16(mb->pkt_len - sqh_len -
                                sa->hdr_l3_off - sa->hdr_len);
        }
index 1b673b6a187f4659e5ba8b129a35a2f60b68e50e..59a547637dfd29f8f16ac36deb681af537e9f716 100644 (file)
@@ -364,8 +364,8 @@ esp_outb_tun_init(struct rte_ipsec_sa *sa, const struct rte_ipsec_sa_prm *prm)
                struct rte_udp_hdr *udph = (struct rte_udp_hdr *)
                                &sa->hdr[prm->tun.hdr_len];
                sa->hdr_len += sizeof(struct rte_udp_hdr);
-               udph->src_port = prm->ipsec_xform.udp.sport;
-               udph->dst_port = prm->ipsec_xform.udp.dport;
+               udph->src_port = rte_cpu_to_be_16(prm->ipsec_xform.udp.sport);
+               udph->dst_port = rte_cpu_to_be_16(prm->ipsec_xform.udp.dport);
                udph->dgram_cksum = 0;
        }