Home | History | Annotate | Line # | Download | only in ipsec
t_ipsec_misc.sh revision 1.21
      1  1.21  ozaki #	$NetBSD: t_ipsec_misc.sh,v 1.21 2017/11/09 04:50:37 ozaki-r Exp $
      2   1.1  ozaki #
      3   1.1  ozaki # Copyright (c) 2017 Internet Initiative Japan Inc.
      4   1.1  ozaki # All rights reserved.
      5   1.1  ozaki #
      6   1.1  ozaki # Redistribution and use in source and binary forms, with or without
      7   1.1  ozaki # modification, are permitted provided that the following conditions
      8   1.1  ozaki # are met:
      9   1.1  ozaki # 1. Redistributions of source code must retain the above copyright
     10   1.1  ozaki #    notice, this list of conditions and the following disclaimer.
     11   1.1  ozaki # 2. Redistributions in binary form must reproduce the above copyright
     12   1.1  ozaki #    notice, this list of conditions and the following disclaimer in the
     13   1.1  ozaki #    documentation and/or other materials provided with the distribution.
     14   1.1  ozaki #
     15   1.1  ozaki # THIS SOFTWARE IS PROVIDED BY THE NETBSD FOUNDATION, INC. AND CONTRIBUTORS
     16   1.1  ozaki # ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED
     17   1.1  ozaki # TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
     18   1.1  ozaki # PURPOSE ARE DISCLAIMED.  IN NO EVENT SHALL THE FOUNDATION OR CONTRIBUTORS
     19   1.1  ozaki # BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
     20   1.1  ozaki # CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
     21   1.1  ozaki # SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
     22   1.1  ozaki # INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
     23   1.1  ozaki # CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
     24   1.1  ozaki # ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
     25   1.1  ozaki # POSSIBILITY OF SUCH DAMAGE.
     26   1.1  ozaki #
     27   1.1  ozaki 
     28   1.1  ozaki SOCK_LOCAL=unix://ipsec_local
     29   1.1  ozaki SOCK_PEER=unix://ipsec_peer
     30   1.1  ozaki BUS=./bus_ipsec
     31   1.1  ozaki 
     32   1.4  ozaki DEBUG=${DEBUG:-true}
     33   1.1  ozaki 
     34   1.1  ozaki setup_sasp()
     35   1.1  ozaki {
     36   1.1  ozaki 	local proto=$1
     37   1.1  ozaki 	local algo_args="$2"
     38   1.1  ozaki 	local ip_local=$3
     39   1.1  ozaki 	local ip_peer=$4
     40   1.1  ozaki 	local lifetime=$5
     41   1.8  ozaki 	local update=$6
     42   1.1  ozaki 	local tmpfile=./tmp
     43   1.8  ozaki 	local extra=
     44   1.8  ozaki 
     45   1.8  ozaki 	if [ "$update" = sa ]; then
     46   1.8  ozaki 		extra="update $ip_local $ip_peer $proto 10000 $algo_args;
     47   1.8  ozaki 		       update $ip_peer $ip_local $proto 10001 $algo_args;"
     48   1.8  ozaki 	elif [ "$update" = sp ]; then
     49   1.8  ozaki 		extra="spdupdate $ip_local $ip_peer any -P out ipsec $proto/transport//require;"
     50   1.8  ozaki 	fi
     51   1.1  ozaki 
     52   1.1  ozaki 	export RUMP_SERVER=$SOCK_LOCAL
     53   1.1  ozaki 	cat > $tmpfile <<-EOF
     54   1.1  ozaki 	add $ip_local $ip_peer $proto 10000 -lh $lifetime -ls $lifetime $algo_args;
     55   1.1  ozaki 	add $ip_peer $ip_local $proto 10001 -lh $lifetime -ls $lifetime $algo_args;
     56   1.1  ozaki 	spdadd $ip_local $ip_peer any -P out ipsec $proto/transport//require;
     57   1.8  ozaki 	$extra
     58   1.1  ozaki 	EOF
     59   1.1  ozaki 	$DEBUG && cat $tmpfile
     60   1.1  ozaki 	atf_check -s exit:0 -o empty $HIJACKING setkey -c < $tmpfile
     61   1.3  ozaki 	# XXX it can be expired if $lifetime is very short
     62   1.3  ozaki 	#check_sa_entries $SOCK_LOCAL $ip_local $ip_peer
     63   1.1  ozaki 
     64   1.8  ozaki 	if [ "$update" = sp ]; then
     65   1.8  ozaki 		extra="spdupdate $ip_peer $ip_local any -P out ipsec $proto/transport//require;"
     66   1.8  ozaki 	fi
     67   1.8  ozaki 
     68   1.1  ozaki 	export RUMP_SERVER=$SOCK_PEER
     69   1.1  ozaki 	cat > $tmpfile <<-EOF
     70   1.1  ozaki 	add $ip_local $ip_peer $proto 10000 -lh $lifetime -ls $lifetime $algo_args;
     71   1.1  ozaki 	add $ip_peer $ip_local $proto 10001 -lh $lifetime -ls $lifetime $algo_args;
     72   1.1  ozaki 	spdadd $ip_peer $ip_local any -P out ipsec $proto/transport//require;
     73   1.8  ozaki 	$extra
     74   1.1  ozaki 	EOF
     75   1.1  ozaki 	$DEBUG && cat $tmpfile
     76   1.1  ozaki 	atf_check -s exit:0 -o empty $HIJACKING setkey -c < $tmpfile
     77   1.3  ozaki 	# XXX it can be expired if $lifetime is very short
     78   1.3  ozaki 	#check_sa_entries $SOCK_PEER $ip_local $ip_peer
     79   1.1  ozaki }
     80   1.1  ozaki 
     81   1.1  ozaki test_ipsec4_lifetime()
     82   1.1  ozaki {
     83   1.1  ozaki 	local proto=$1
     84   1.1  ozaki 	local algo=$2
     85   1.1  ozaki 	local ip_local=10.0.0.1
     86   1.1  ozaki 	local ip_peer=10.0.0.2
     87   1.1  ozaki 	local outfile=./out
     88   1.1  ozaki 	local proto_cap=$(echo $proto | tr 'a-z' 'A-Z')
     89   1.1  ozaki 	local algo_args="$(generate_algo_args $proto $algo)"
     90   1.1  ozaki 	local lifetime=3
     91  1.21  ozaki 	local buffertime=2
     92   1.1  ozaki 
     93   1.1  ozaki 	rump_server_crypto_start $SOCK_LOCAL netipsec
     94   1.1  ozaki 	rump_server_crypto_start $SOCK_PEER netipsec
     95   1.1  ozaki 	rump_server_add_iface $SOCK_LOCAL shmif0 $BUS
     96   1.1  ozaki 	rump_server_add_iface $SOCK_PEER shmif0 $BUS
     97   1.1  ozaki 
     98   1.1  ozaki 	export RUMP_SERVER=$SOCK_LOCAL
     99   1.1  ozaki 	atf_check -s exit:0 rump.sysctl -q -w net.inet.ip.dad_count=0
    100   1.1  ozaki 	atf_check -s exit:0 rump.ifconfig shmif0 $ip_local/24
    101   1.1  ozaki 	#atf_check -s exit:0 -o ignore rump.sysctl -w net.key.debug=0xff
    102   1.1  ozaki 
    103   1.1  ozaki 	export RUMP_SERVER=$SOCK_PEER
    104   1.1  ozaki 	atf_check -s exit:0 rump.sysctl -q -w net.inet.ip.dad_count=0
    105   1.1  ozaki 	atf_check -s exit:0 rump.ifconfig shmif0 $ip_peer/24
    106   1.1  ozaki 	#atf_check -s exit:0 -o ignore rump.sysctl -w net.key.debug=0xff
    107   1.1  ozaki 
    108   1.1  ozaki 	extract_new_packets $BUS > $outfile
    109   1.1  ozaki 
    110   1.1  ozaki 	export RUMP_SERVER=$SOCK_LOCAL
    111   1.1  ozaki 	atf_check -s exit:0 -o ignore rump.ping -c 1 -n -w 3 $ip_peer
    112   1.1  ozaki 
    113   1.1  ozaki 	extract_new_packets $BUS > $outfile
    114   1.1  ozaki 	atf_check -s exit:0 -o match:"$ip_local > $ip_peer: ICMP echo request" \
    115   1.1  ozaki 	    cat $outfile
    116   1.1  ozaki 	atf_check -s exit:0 -o match:"$ip_peer > $ip_local: ICMP echo reply" \
    117   1.1  ozaki 	    cat $outfile
    118   1.1  ozaki 
    119   1.1  ozaki 	# Set up SAs with lifetime 1 sec.
    120   1.1  ozaki 	setup_sasp $proto "$algo_args" $ip_local $ip_peer 1
    121   1.1  ozaki 
    122   1.1  ozaki 	# Wait for the SAs to be expired
    123  1.21  ozaki 	atf_check -s exit:0 sleep $((1 + $buffertime))
    124   1.1  ozaki 
    125   1.1  ozaki 	# Check the SAs have been expired
    126   1.1  ozaki 	export RUMP_SERVER=$SOCK_LOCAL
    127   1.1  ozaki 	$DEBUG && $HIJACKING setkey -D
    128   1.1  ozaki 	atf_check -s exit:0 -o match:'No SAD entries.' $HIJACKING setkey -D
    129   1.1  ozaki 	export RUMP_SERVER=$SOCK_PEER
    130   1.1  ozaki 	$DEBUG && $HIJACKING setkey -D
    131   1.1  ozaki 	atf_check -s exit:0 -o match:'No SAD entries.' $HIJACKING setkey -D
    132   1.1  ozaki 
    133   1.1  ozaki 	# Clean up SPs
    134   1.1  ozaki 	export RUMP_SERVER=$SOCK_LOCAL
    135   1.1  ozaki 	atf_check -s exit:0 -o empty $HIJACKING setkey -F -P
    136   1.1  ozaki 	export RUMP_SERVER=$SOCK_PEER
    137   1.1  ozaki 	atf_check -s exit:0 -o empty $HIJACKING setkey -F -P
    138   1.1  ozaki 
    139   1.1  ozaki 	# Set up SAs with lifetime with $lifetime
    140   1.1  ozaki 	setup_sasp $proto "$algo_args" $ip_local $ip_peer $lifetime
    141   1.1  ozaki 
    142   1.1  ozaki 	# Use the SAs; this will create a reference from an SP to an SA
    143   1.1  ozaki 	export RUMP_SERVER=$SOCK_LOCAL
    144   1.1  ozaki 	atf_check -s exit:0 -o ignore rump.ping -c 1 -n -w 3 $ip_peer
    145   1.1  ozaki 
    146   1.1  ozaki 	extract_new_packets $BUS > $outfile
    147   1.1  ozaki 	atf_check -s exit:0 -o match:"$ip_local > $ip_peer: $proto_cap" \
    148   1.1  ozaki 	    cat $outfile
    149   1.1  ozaki 	atf_check -s exit:0 -o match:"$ip_peer > $ip_local: $proto_cap" \
    150   1.1  ozaki 	    cat $outfile
    151   1.1  ozaki 
    152  1.21  ozaki 	atf_check -s exit:0 sleep $((lifetime + $buffertime))
    153   1.1  ozaki 
    154   1.1  ozaki 	export RUMP_SERVER=$SOCK_LOCAL
    155   1.1  ozaki 	$DEBUG && $HIJACKING setkey -D
    156  1.15  ozaki 	atf_check -s exit:0 -o match:'No SAD entries.' $HIJACKING setkey -D -a
    157   1.1  ozaki 
    158   1.1  ozaki 	export RUMP_SERVER=$SOCK_PEER
    159   1.1  ozaki 	$DEBUG && $HIJACKING setkey -D
    160  1.15  ozaki 	atf_check -s exit:0 -o match:'No SAD entries.' $HIJACKING setkey -D -a
    161   1.1  ozaki 
    162   1.1  ozaki 	export RUMP_SERVER=$SOCK_LOCAL
    163   1.1  ozaki 	atf_check -s not-exit:0 -o match:'0 packets received' \
    164   1.1  ozaki 	    rump.ping -c 1 -n -w 1 $ip_peer
    165   1.1  ozaki 
    166   1.1  ozaki 	test_flush_entries $SOCK_LOCAL
    167   1.1  ozaki 	test_flush_entries $SOCK_PEER
    168   1.1  ozaki }
    169   1.1  ozaki 
    170   1.1  ozaki test_ipsec6_lifetime()
    171   1.1  ozaki {
    172   1.1  ozaki 	local proto=$1
    173   1.1  ozaki 	local algo=$2
    174   1.1  ozaki 	local ip_local=fd00::1
    175   1.1  ozaki 	local ip_peer=fd00::2
    176   1.1  ozaki 	local outfile=./out
    177   1.1  ozaki 	local proto_cap=$(echo $proto | tr 'a-z' 'A-Z')
    178   1.1  ozaki 	local algo_args="$(generate_algo_args $proto $algo)"
    179   1.1  ozaki 	local lifetime=3
    180  1.21  ozaki 	local buffertime=2
    181   1.1  ozaki 
    182   1.1  ozaki 	rump_server_crypto_start $SOCK_LOCAL netinet6 netipsec
    183   1.1  ozaki 	rump_server_crypto_start $SOCK_PEER netinet6 netipsec
    184   1.1  ozaki 	rump_server_add_iface $SOCK_LOCAL shmif0 $BUS
    185   1.1  ozaki 	rump_server_add_iface $SOCK_PEER shmif0 $BUS
    186   1.1  ozaki 
    187   1.1  ozaki 	export RUMP_SERVER=$SOCK_LOCAL
    188   1.1  ozaki 	atf_check -s exit:0 rump.sysctl -q -w net.inet6.ip6.dad_count=0
    189   1.1  ozaki 	atf_check -s exit:0 rump.ifconfig shmif0 inet6 $ip_local
    190   1.1  ozaki 
    191   1.1  ozaki 	export RUMP_SERVER=$SOCK_PEER
    192   1.1  ozaki 	atf_check -s exit:0 rump.sysctl -q -w net.inet6.ip6.dad_count=0
    193   1.1  ozaki 	atf_check -s exit:0 rump.ifconfig shmif0 inet6 $ip_peer
    194   1.1  ozaki 
    195   1.1  ozaki 	extract_new_packets $BUS > $outfile
    196   1.1  ozaki 
    197   1.1  ozaki 	export RUMP_SERVER=$SOCK_LOCAL
    198   1.1  ozaki 	atf_check -s exit:0 -o ignore rump.ping6 -c 1 -n -X 3 $ip_peer
    199   1.1  ozaki 
    200   1.1  ozaki 	extract_new_packets $BUS > $outfile
    201   1.1  ozaki 	atf_check -s exit:0 -o match:"$ip_local > $ip_peer: ICMP6, echo request" \
    202   1.1  ozaki 	    cat $outfile
    203   1.1  ozaki 	atf_check -s exit:0 -o match:"$ip_peer > $ip_local: ICMP6, echo reply" \
    204   1.1  ozaki 	    cat $outfile
    205   1.1  ozaki 
    206   1.1  ozaki 	# Set up SAs with lifetime 1 sec.
    207   1.1  ozaki 	setup_sasp $proto "$algo_args" $ip_local $ip_peer 1
    208   1.1  ozaki 
    209   1.1  ozaki 	# Wait for the SAs to be expired
    210  1.21  ozaki 	atf_check -s exit:0 sleep $((1 + $buffertime))
    211   1.1  ozaki 
    212   1.1  ozaki 	# Check the SAs have been expired
    213   1.1  ozaki 	export RUMP_SERVER=$SOCK_LOCAL
    214   1.1  ozaki 	$DEBUG && $HIJACKING setkey -D
    215   1.1  ozaki 	atf_check -s exit:0 -o match:'No SAD entries.' $HIJACKING setkey -D
    216   1.1  ozaki 	export RUMP_SERVER=$SOCK_PEER
    217   1.1  ozaki 	$DEBUG && $HIJACKING setkey -D
    218   1.1  ozaki 	atf_check -s exit:0 -o match:'No SAD entries.' $HIJACKING setkey -D
    219   1.1  ozaki 
    220   1.1  ozaki 	# Clean up SPs
    221   1.1  ozaki 	export RUMP_SERVER=$SOCK_LOCAL
    222   1.1  ozaki 	atf_check -s exit:0 -o empty $HIJACKING setkey -F -P
    223   1.1  ozaki 	export RUMP_SERVER=$SOCK_PEER
    224   1.1  ozaki 	atf_check -s exit:0 -o empty $HIJACKING setkey -F -P
    225   1.1  ozaki 
    226   1.1  ozaki 	# Set up SAs with lifetime with $lifetime
    227   1.1  ozaki 	setup_sasp $proto "$algo_args" $ip_local $ip_peer $lifetime
    228   1.1  ozaki 
    229   1.1  ozaki 	# Use the SAs; this will create a reference from an SP to an SA
    230   1.1  ozaki 	export RUMP_SERVER=$SOCK_LOCAL
    231   1.1  ozaki 	atf_check -s exit:0 -o ignore rump.ping6 -c 1 -n -X 3 $ip_peer
    232   1.1  ozaki 
    233   1.1  ozaki 	extract_new_packets $BUS > $outfile
    234   1.1  ozaki 	atf_check -s exit:0 -o match:"$ip_local > $ip_peer: $proto_cap" \
    235   1.1  ozaki 	    cat $outfile
    236   1.1  ozaki 	atf_check -s exit:0 -o match:"$ip_peer > $ip_local: $proto_cap" \
    237   1.1  ozaki 	    cat $outfile
    238   1.1  ozaki 
    239  1.21  ozaki 	atf_check -s exit:0 sleep $((lifetime + $buffertime))
    240   1.1  ozaki 
    241   1.1  ozaki 	export RUMP_SERVER=$SOCK_LOCAL
    242   1.1  ozaki 	$DEBUG && $HIJACKING setkey -D
    243  1.15  ozaki 	atf_check -s exit:0 -o match:'No SAD entries.' $HIJACKING setkey -D -a
    244   1.1  ozaki 
    245   1.1  ozaki 	export RUMP_SERVER=$SOCK_PEER
    246   1.1  ozaki 	$DEBUG && $HIJACKING setkey -D
    247  1.15  ozaki 	atf_check -s exit:0 -o match:'No SAD entries.' $HIJACKING setkey -D -a
    248   1.1  ozaki 
    249   1.1  ozaki 	export RUMP_SERVER=$SOCK_LOCAL
    250   1.1  ozaki 	atf_check -s not-exit:0 -o match:'0 packets received' \
    251   1.1  ozaki 	    rump.ping6 -c 1 -n -X 1 $ip_peer
    252   1.1  ozaki 
    253   1.1  ozaki 	test_flush_entries $SOCK_LOCAL
    254   1.1  ozaki 	test_flush_entries $SOCK_PEER
    255   1.1  ozaki }
    256   1.1  ozaki 
    257   1.1  ozaki test_lifetime_common()
    258   1.1  ozaki {
    259   1.1  ozaki 	local ipproto=$1
    260   1.1  ozaki 	local proto=$2
    261   1.1  ozaki 	local algo=$3
    262   1.1  ozaki 
    263   1.1  ozaki 	if [ $ipproto = ipv4 ]; then
    264   1.1  ozaki 		test_ipsec4_lifetime $proto $algo
    265   1.1  ozaki 	else
    266   1.1  ozaki 		test_ipsec6_lifetime $proto $algo
    267   1.1  ozaki 	fi
    268   1.1  ozaki }
    269   1.1  ozaki 
    270   1.1  ozaki add_test_lifetime()
    271   1.1  ozaki {
    272   1.1  ozaki 	local ipproto=$1
    273   1.1  ozaki 	local proto=$2
    274   1.1  ozaki 	local algo=$3
    275   1.1  ozaki 	local _algo=$(echo $algo | sed 's/-//g')
    276   1.1  ozaki 	local name= desc=
    277   1.1  ozaki 
    278   1.1  ozaki 	name="ipsec_lifetime_${ipproto}_${proto}_${_algo}"
    279   1.1  ozaki 	desc="Tests of lifetime of IPsec ($ipproto) with $proto ($algo)"
    280   1.1  ozaki 
    281   1.1  ozaki 	atf_test_case ${name} cleanup
    282  1.18  ozaki 	eval "
    283  1.18  ozaki 	    ${name}_head() {
    284  1.18  ozaki 	        atf_set descr \"$desc\"
    285  1.18  ozaki 	        atf_set require.progs rump_server setkey
    286  1.18  ozaki 	    }
    287  1.18  ozaki 	    ${name}_body() {
    288  1.18  ozaki 	        test_lifetime_common $ipproto $proto $algo
    289  1.18  ozaki 	        rump_server_destroy_ifaces
    290  1.18  ozaki 	    }
    291  1.18  ozaki 	    ${name}_cleanup() {
    292  1.18  ozaki 	        \$DEBUG && dump
    293  1.18  ozaki 	        cleanup
    294  1.18  ozaki 	    }
    295   1.1  ozaki 	"
    296   1.1  ozaki 	atf_add_test_case ${name}
    297   1.1  ozaki }
    298   1.1  ozaki 
    299   1.8  ozaki test_update()
    300   1.8  ozaki {
    301   1.8  ozaki 	local proto=$1
    302   1.8  ozaki 	local algo=$2
    303   1.8  ozaki 	local update=$3
    304   1.8  ozaki 	local ip_local=10.0.0.1
    305   1.8  ozaki 	local ip_peer=10.0.0.2
    306   1.8  ozaki 	local algo_args="$(generate_algo_args $proto $algo)"
    307   1.8  ozaki 	local proto_cap=$(echo $proto | tr 'a-z' 'A-Z')
    308   1.8  ozaki 	local outfile=./out
    309   1.8  ozaki 
    310   1.8  ozaki 	rump_server_crypto_start $SOCK_LOCAL netipsec
    311   1.8  ozaki 	rump_server_crypto_start $SOCK_PEER netipsec
    312   1.8  ozaki 	rump_server_add_iface $SOCK_LOCAL shmif0 $BUS
    313   1.8  ozaki 	rump_server_add_iface $SOCK_PEER shmif0 $BUS
    314   1.8  ozaki 
    315   1.8  ozaki 	export RUMP_SERVER=$SOCK_LOCAL
    316   1.8  ozaki 	atf_check -s exit:0 rump.sysctl -q -w net.inet.ip.dad_count=0
    317   1.8  ozaki 	atf_check -s exit:0 rump.ifconfig shmif0 $ip_local/24
    318   1.8  ozaki 
    319   1.8  ozaki 	export RUMP_SERVER=$SOCK_PEER
    320   1.8  ozaki 	atf_check -s exit:0 rump.sysctl -q -w net.inet.ip.dad_count=0
    321   1.8  ozaki 	atf_check -s exit:0 rump.ifconfig shmif0 $ip_peer/24
    322   1.8  ozaki 
    323   1.8  ozaki 	setup_sasp $proto "$algo_args" $ip_local $ip_peer 100 $update
    324   1.8  ozaki 
    325   1.8  ozaki 	extract_new_packets $BUS > $outfile
    326   1.8  ozaki 
    327   1.8  ozaki 	export RUMP_SERVER=$SOCK_LOCAL
    328   1.8  ozaki 	atf_check -s exit:0 -o ignore rump.ping -c 1 -n -w 3 $ip_peer
    329   1.8  ozaki 
    330   1.8  ozaki 	extract_new_packets $BUS > $outfile
    331   1.8  ozaki 	atf_check -s exit:0 -o match:"$ip_local > $ip_peer: $proto_cap" \
    332   1.8  ozaki 	    cat $outfile
    333   1.8  ozaki 	atf_check -s exit:0 -o match:"$ip_peer > $ip_local: $proto_cap" \
    334   1.8  ozaki 	    cat $outfile
    335   1.8  ozaki }
    336   1.8  ozaki 
    337   1.8  ozaki add_test_update()
    338   1.8  ozaki {
    339   1.8  ozaki 	local proto=$1
    340   1.8  ozaki 	local algo=$2
    341   1.8  ozaki 	local update=$3
    342   1.8  ozaki 	local _update=$(echo $update |tr 'a-z' 'A-Z')
    343   1.8  ozaki 	local _algo=$(echo $algo | sed 's/-//g')
    344   1.8  ozaki 	local name= desc=
    345   1.8  ozaki 
    346   1.8  ozaki 	desc="Tests trying to udpate $_update of $proto ($algo)"
    347   1.8  ozaki 	name="ipsec_update_${update}_${proto}_${_algo}"
    348   1.8  ozaki 
    349   1.8  ozaki 	atf_test_case ${name} cleanup
    350  1.18  ozaki 	eval "
    351  1.18  ozaki 	    ${name}_head() {
    352  1.18  ozaki 	        atf_set descr \"$desc\"
    353  1.18  ozaki 	        atf_set require.progs rump_server setkey
    354  1.18  ozaki 	    }
    355  1.18  ozaki 	    ${name}_body() {
    356  1.18  ozaki 	        test_update $proto $algo $update
    357  1.18  ozaki 	        rump_server_destroy_ifaces
    358  1.18  ozaki 	    }
    359  1.18  ozaki 	    ${name}_cleanup() {
    360  1.18  ozaki 	        \$DEBUG && dump
    361  1.18  ozaki 	        cleanup
    362  1.18  ozaki 	    }
    363   1.8  ozaki 	"
    364   1.8  ozaki 	atf_add_test_case ${name}
    365   1.8  ozaki }
    366   1.8  ozaki 
    367   1.9  ozaki add_sa()
    368   1.9  ozaki {
    369   1.9  ozaki 	local proto=$1
    370   1.9  ozaki 	local algo_args="$2"
    371   1.9  ozaki 	local ip_local=$3
    372   1.9  ozaki 	local ip_peer=$4
    373   1.9  ozaki 	local lifetime=$5
    374   1.9  ozaki 	local spi=$6
    375   1.9  ozaki 	local tmpfile=./tmp
    376   1.9  ozaki 	local extra=
    377   1.9  ozaki 
    378   1.9  ozaki 	export RUMP_SERVER=$SOCK_LOCAL
    379   1.9  ozaki 	cat > $tmpfile <<-EOF
    380   1.9  ozaki 	add $ip_local $ip_peer $proto $((spi)) -lh $lifetime -ls $lifetime $algo_args;
    381   1.9  ozaki 	add $ip_peer $ip_local $proto $((spi + 1)) -lh $lifetime -ls $lifetime $algo_args;
    382   1.9  ozaki 	$extra
    383   1.9  ozaki 	EOF
    384   1.9  ozaki 	$DEBUG && cat $tmpfile
    385   1.9  ozaki 	atf_check -s exit:0 -o empty $HIJACKING setkey -c < $tmpfile
    386   1.9  ozaki 	$DEBUG && $HIJACKING setkey -D
    387   1.9  ozaki 	# XXX it can be expired if $lifetime is very short
    388   1.9  ozaki 	#check_sa_entries $SOCK_LOCAL $ip_local $ip_peer
    389   1.9  ozaki 
    390   1.9  ozaki 	export RUMP_SERVER=$SOCK_PEER
    391   1.9  ozaki 	cat > $tmpfile <<-EOF
    392   1.9  ozaki 	add $ip_local $ip_peer $proto $((spi)) -lh $lifetime -ls $lifetime $algo_args;
    393   1.9  ozaki 	add $ip_peer $ip_local $proto $((spi + 1)) -lh $lifetime -ls $lifetime $algo_args;
    394   1.9  ozaki 	$extra
    395   1.9  ozaki 	EOF
    396   1.9  ozaki 	$DEBUG && cat $tmpfile
    397   1.9  ozaki 	atf_check -s exit:0 -o empty $HIJACKING setkey -c < $tmpfile
    398   1.9  ozaki 	$DEBUG && $HIJACKING setkey -D
    399   1.9  ozaki 	# XXX it can be expired if $lifetime is very short
    400   1.9  ozaki 	#check_sa_entries $SOCK_PEER $ip_local $ip_peer
    401   1.9  ozaki }
    402   1.9  ozaki 
    403  1.13  ozaki delete_sa()
    404  1.13  ozaki {
    405  1.13  ozaki 	local proto=$1
    406  1.13  ozaki 	local ip_local=$2
    407  1.13  ozaki 	local ip_peer=$3
    408  1.13  ozaki 	local spi=$4
    409  1.13  ozaki 	local tmpfile=./tmp
    410  1.13  ozaki 	local extra=
    411  1.13  ozaki 
    412  1.13  ozaki 	export RUMP_SERVER=$SOCK_LOCAL
    413  1.13  ozaki 	cat > $tmpfile <<-EOF
    414  1.13  ozaki 	delete $ip_local $ip_peer $proto $((spi));
    415  1.13  ozaki 	delete $ip_peer $ip_local $proto $((spi + 1));
    416  1.13  ozaki 	EOF
    417  1.13  ozaki 	$DEBUG && cat $tmpfile
    418  1.13  ozaki 	atf_check -s exit:0 -o empty $HIJACKING setkey -c < $tmpfile
    419  1.13  ozaki 	$DEBUG && $HIJACKING setkey -D
    420  1.13  ozaki 
    421  1.13  ozaki 	export RUMP_SERVER=$SOCK_PEER
    422  1.13  ozaki 	cat > $tmpfile <<-EOF
    423  1.13  ozaki 	delete $ip_local $ip_peer $proto $((spi));
    424  1.13  ozaki 	delete $ip_peer $ip_local $proto $((spi + 1));
    425  1.13  ozaki 	EOF
    426  1.13  ozaki 	$DEBUG && cat $tmpfile
    427  1.13  ozaki 	atf_check -s exit:0 -o empty $HIJACKING setkey -c < $tmpfile
    428  1.13  ozaki 	$DEBUG && $HIJACKING setkey -D
    429  1.13  ozaki }
    430  1.13  ozaki 
    431   1.9  ozaki check_packet_spi()
    432   1.9  ozaki {
    433   1.9  ozaki 	local outfile=$1
    434   1.9  ozaki 	local ip_local=$2
    435   1.9  ozaki 	local ip_peer=$3
    436   1.9  ozaki 	local proto=$4
    437   1.9  ozaki 	local spi=$5
    438   1.9  ozaki 	local spistr=
    439   1.9  ozaki 
    440   1.9  ozaki 	$DEBUG && cat $outfile
    441   1.9  ozaki 	spistr=$(printf "%08x" $spi)
    442   1.9  ozaki 	atf_check -s exit:0 \
    443   1.9  ozaki 	    -o match:"$ip_local > $ip_peer: $proto_cap\(spi=0x$spistr," \
    444   1.9  ozaki 	    cat $outfile
    445   1.9  ozaki 	spistr=$(printf "%08x" $((spi + 1)))
    446   1.9  ozaki 	atf_check -s exit:0 \
    447   1.9  ozaki 	    -o match:"$ip_peer > $ip_local: $proto_cap\(spi=0x$spistr," \
    448   1.9  ozaki 	    cat $outfile
    449   1.9  ozaki }
    450   1.9  ozaki 
    451  1.12  ozaki wait_sa_disappeared()
    452  1.12  ozaki {
    453  1.12  ozaki 	local spi=$1
    454  1.12  ozaki 	local i=
    455  1.12  ozaki 
    456  1.12  ozaki 	export RUMP_SERVER=$SOCK_LOCAL
    457  1.12  ozaki 	for i in $(seq 1 10); do
    458  1.12  ozaki 		$HIJACKING setkey -D |grep -q "spi=$spi"
    459  1.12  ozaki 		[ $? != 0 ] && break
    460  1.12  ozaki 		sleep 1
    461  1.12  ozaki 	done
    462  1.12  ozaki 	if [ $i -eq 10 ]; then
    463  1.12  ozaki 		atf_fail "SA (spi=$spi) didn't disappear in 10s"
    464  1.12  ozaki 	fi
    465  1.12  ozaki 	export RUMP_SERVER=$SOCK_PEER
    466  1.12  ozaki 	for i in $(seq 1 10); do
    467  1.12  ozaki 		$HIJACKING setkey -D |grep -q "spi=$spi"
    468  1.12  ozaki 		[ $? != 0 ] && break
    469  1.12  ozaki 		sleep 1
    470  1.12  ozaki 	done
    471  1.12  ozaki 	if [ $i -eq 10 ]; then
    472  1.12  ozaki 		atf_fail "SA (spi=$spi) didn't disappear in 10s"
    473  1.12  ozaki 	fi
    474  1.12  ozaki }
    475  1.12  ozaki 
    476   1.9  ozaki test_spi()
    477   1.9  ozaki {
    478   1.9  ozaki 	local proto=$1
    479   1.9  ozaki 	local algo=$2
    480  1.10  ozaki 	local preferred=$3
    481  1.13  ozaki 	local method=$4
    482   1.9  ozaki 	local ip_local=10.0.0.1
    483   1.9  ozaki 	local ip_peer=10.0.0.2
    484   1.9  ozaki 	local algo_args="$(generate_algo_args $proto $algo)"
    485   1.9  ozaki 	local proto_cap=$(echo $proto | tr 'a-z' 'A-Z')
    486   1.9  ozaki 	local outfile=./out
    487   1.9  ozaki 	local spistr=
    488  1.14  ozaki 	local longtime= shorttime=
    489  1.14  ozaki 
    490  1.16  ozaki 	if [ $method = timeout -a $preferred = new ]; then
    491  1.16  ozaki 		skip_if_qemu
    492  1.16  ozaki 	fi
    493  1.16  ozaki 
    494  1.14  ozaki 	if [ $method = delete ]; then
    495  1.14  ozaki 		shorttime=100
    496  1.14  ozaki 		longtime=100
    497  1.14  ozaki 	else
    498  1.14  ozaki 		shorttime=3
    499  1.14  ozaki 		longtime=6
    500  1.14  ozaki 	fi
    501   1.9  ozaki 
    502   1.9  ozaki 	rump_server_crypto_start $SOCK_LOCAL netipsec
    503   1.9  ozaki 	rump_server_crypto_start $SOCK_PEER netipsec
    504   1.9  ozaki 	rump_server_add_iface $SOCK_LOCAL shmif0 $BUS
    505   1.9  ozaki 	rump_server_add_iface $SOCK_PEER shmif0 $BUS
    506   1.9  ozaki 
    507   1.9  ozaki 	export RUMP_SERVER=$SOCK_LOCAL
    508   1.9  ozaki 	atf_check -s exit:0 rump.sysctl -q -w net.inet.ip.dad_count=0
    509   1.9  ozaki 	atf_check -s exit:0 rump.ifconfig shmif0 $ip_local/24
    510   1.9  ozaki 	if [ $preferred = old ]; then
    511   1.9  ozaki 		atf_check -s exit:0 rump.sysctl -q -w net.key.prefered_oldsa=1
    512   1.9  ozaki 	fi
    513   1.9  ozaki 
    514   1.9  ozaki 	export RUMP_SERVER=$SOCK_PEER
    515   1.9  ozaki 	atf_check -s exit:0 rump.sysctl -q -w net.inet.ip.dad_count=0
    516   1.9  ozaki 	atf_check -s exit:0 rump.ifconfig shmif0 $ip_peer/24
    517   1.9  ozaki 	if [ $preferred = old ]; then
    518   1.9  ozaki 		atf_check -s exit:0 rump.sysctl -q -w net.key.prefered_oldsa=1
    519   1.9  ozaki 	fi
    520   1.9  ozaki 
    521   1.9  ozaki 	setup_sasp $proto "$algo_args" $ip_local $ip_peer 100
    522   1.9  ozaki 
    523   1.9  ozaki 	extract_new_packets $BUS > $outfile
    524   1.9  ozaki 
    525   1.9  ozaki 	export RUMP_SERVER=$SOCK_LOCAL
    526   1.9  ozaki 	atf_check -s exit:0 -o ignore rump.ping -c 1 -n -w 3 $ip_peer
    527   1.9  ozaki 	extract_new_packets $BUS > $outfile
    528   1.9  ozaki 	check_packet_spi $outfile $ip_local $ip_peer $proto_cap 10000
    529   1.9  ozaki 
    530   1.9  ozaki 	# Add a new SA with a different SPI
    531  1.14  ozaki 	add_sa $proto "$algo_args" $ip_local $ip_peer $longtime 10010
    532   1.9  ozaki 
    533   1.9  ozaki 	export RUMP_SERVER=$SOCK_LOCAL
    534   1.9  ozaki 	atf_check -s exit:0 -o ignore rump.ping -c 1 -n -w 3 $ip_peer
    535   1.9  ozaki 	extract_new_packets $BUS > $outfile
    536   1.9  ozaki 	if [ $preferred = old ]; then
    537   1.9  ozaki 		check_packet_spi $outfile $ip_local $ip_peer $proto_cap 10000
    538   1.9  ozaki 	else
    539   1.9  ozaki 		# The new SA is preferred
    540   1.9  ozaki 		check_packet_spi $outfile $ip_local $ip_peer $proto_cap 10010
    541   1.9  ozaki 	fi
    542   1.9  ozaki 
    543   1.9  ozaki 	# Add another SA with a different SPI
    544  1.14  ozaki 	add_sa $proto "$algo_args" $ip_local $ip_peer $shorttime 10020
    545   1.9  ozaki 
    546   1.9  ozaki 	export RUMP_SERVER=$SOCK_LOCAL
    547   1.9  ozaki 	atf_check -s exit:0 -o ignore rump.ping -c 1 -n -w 3 $ip_peer
    548   1.9  ozaki 	extract_new_packets $BUS > $outfile
    549   1.9  ozaki 	if [ $preferred = old ]; then
    550   1.9  ozaki 		check_packet_spi $outfile $ip_local $ip_peer $proto_cap 10000
    551   1.9  ozaki 	else
    552   1.9  ozaki 		# The newest SA is preferred
    553   1.9  ozaki 		check_packet_spi $outfile $ip_local $ip_peer $proto_cap 10020
    554   1.9  ozaki 	fi
    555   1.9  ozaki 
    556  1.13  ozaki 	if [ $method = delete ]; then
    557  1.13  ozaki 		delete_sa $proto $ip_local $ip_peer 10020
    558  1.13  ozaki 	else
    559  1.13  ozaki 		wait_sa_disappeared 10020
    560  1.13  ozaki 	fi
    561   1.9  ozaki 
    562   1.9  ozaki 	export RUMP_SERVER=$SOCK_LOCAL
    563   1.9  ozaki 	atf_check -s exit:0 -o ignore rump.ping -c 1 -n -w 3 $ip_peer
    564   1.9  ozaki 	extract_new_packets $BUS > $outfile
    565   1.9  ozaki 	if [ $preferred = old ]; then
    566   1.9  ozaki 		check_packet_spi $outfile $ip_local $ip_peer $proto_cap 10000
    567   1.9  ozaki 	else
    568   1.9  ozaki 		# The newest one is removed and the second one is used
    569   1.9  ozaki 		check_packet_spi $outfile $ip_local $ip_peer $proto_cap 10010
    570   1.9  ozaki 	fi
    571   1.9  ozaki 
    572  1.13  ozaki 	if [ $method = delete ]; then
    573  1.13  ozaki 		delete_sa $proto $ip_local $ip_peer 10010
    574  1.13  ozaki 	else
    575  1.13  ozaki 		wait_sa_disappeared 10010
    576  1.13  ozaki 	fi
    577   1.9  ozaki 
    578   1.9  ozaki 	export RUMP_SERVER=$SOCK_LOCAL
    579   1.9  ozaki 	atf_check -s exit:0 -o ignore rump.ping -c 1 -n -w 3 $ip_peer
    580   1.9  ozaki 	extract_new_packets $BUS > $outfile
    581   1.9  ozaki 	if [ $preferred = old ]; then
    582   1.9  ozaki 		check_packet_spi $outfile $ip_local $ip_peer $proto_cap 10000
    583   1.9  ozaki 	else
    584   1.9  ozaki 		# The second one is removed and the original one is used
    585   1.9  ozaki 		check_packet_spi $outfile $ip_local $ip_peer $proto_cap 10000
    586   1.9  ozaki 	fi
    587   1.9  ozaki }
    588   1.9  ozaki 
    589   1.9  ozaki add_test_spi()
    590   1.9  ozaki {
    591   1.9  ozaki 	local proto=$1
    592   1.9  ozaki 	local algo=$2
    593   1.9  ozaki 	local preferred=$3
    594  1.13  ozaki 	local method=$4
    595   1.9  ozaki 	local _algo=$(echo $algo | sed 's/-//g')
    596   1.9  ozaki 	local name= desc=
    597   1.9  ozaki 
    598  1.13  ozaki 	desc="Tests SAs with different SPIs of $proto ($algo) ($preferred SA preferred) ($method)"
    599  1.13  ozaki 	name="ipsec_spi_${proto}_${_algo}_preferred_${preferred}_${method}"
    600   1.9  ozaki 
    601   1.9  ozaki 	atf_test_case ${name} cleanup
    602  1.18  ozaki 	eval "
    603  1.18  ozaki 	    ${name}_head() {
    604  1.18  ozaki 	        atf_set descr \"$desc\"
    605  1.18  ozaki 	        atf_set require.progs rump_server setkey
    606  1.18  ozaki 	    }
    607  1.18  ozaki 	    ${name}_body() {
    608  1.18  ozaki 	        test_spi $proto $algo $preferred $method
    609  1.18  ozaki 	        rump_server_destroy_ifaces
    610  1.18  ozaki 	    }
    611  1.18  ozaki 	    ${name}_cleanup() {
    612  1.18  ozaki 	        \$DEBUG && dump
    613  1.18  ozaki 	        cleanup
    614  1.18  ozaki 	    }
    615   1.9  ozaki 	"
    616   1.9  ozaki 	atf_add_test_case ${name}
    617   1.9  ozaki }
    618   1.9  ozaki 
    619  1.17  ozaki setup_sp()
    620  1.17  ozaki {
    621  1.17  ozaki 	local proto=$1
    622  1.17  ozaki 	local algo_args="$2"
    623  1.17  ozaki 	local ip_local=$3
    624  1.17  ozaki 	local ip_peer=$4
    625  1.17  ozaki 	local tmpfile=./tmp
    626  1.17  ozaki 
    627  1.17  ozaki 	export RUMP_SERVER=$SOCK_LOCAL
    628  1.17  ozaki 	cat > $tmpfile <<-EOF
    629  1.17  ozaki 	spdadd $ip_local $ip_peer any -P out ipsec $proto/transport//require;
    630  1.19  ozaki 	spdadd $ip_peer $ip_local any -P in ipsec $proto/transport//require;
    631  1.17  ozaki 	EOF
    632  1.17  ozaki 	$DEBUG && cat $tmpfile
    633  1.17  ozaki 	atf_check -s exit:0 -o empty $HIJACKING setkey -c < $tmpfile
    634  1.17  ozaki 	check_sp_entries $SOCK_LOCAL $ip_local $ip_peer
    635  1.17  ozaki 
    636  1.17  ozaki 	export RUMP_SERVER=$SOCK_PEER
    637  1.17  ozaki 	cat > $tmpfile <<-EOF
    638  1.17  ozaki 	spdadd $ip_peer $ip_local any -P out ipsec $proto/transport//require;
    639  1.19  ozaki 	spdadd $ip_local $ip_peer any -P in ipsec $proto/transport//require;
    640  1.17  ozaki 	EOF
    641  1.17  ozaki 	$DEBUG && cat $tmpfile
    642  1.17  ozaki 	atf_check -s exit:0 -o empty $HIJACKING setkey -c < $tmpfile
    643  1.17  ozaki 	check_sp_entries $SOCK_PEER $ip_peer $ip_local
    644  1.17  ozaki }
    645  1.17  ozaki 
    646  1.17  ozaki test_nosa()
    647  1.17  ozaki {
    648  1.17  ozaki 	local proto=$1
    649  1.17  ozaki 	local algo=$2
    650  1.17  ozaki 	local update=$3
    651  1.17  ozaki 	local ip_local=10.0.0.1
    652  1.17  ozaki 	local ip_peer=10.0.0.2
    653  1.17  ozaki 	local algo_args="$(generate_algo_args $proto $algo)"
    654  1.17  ozaki 	local proto_cap=$(echo $proto | tr 'a-z' 'A-Z')
    655  1.17  ozaki 	local outfile=./out
    656  1.17  ozaki 
    657  1.17  ozaki 	rump_server_crypto_start $SOCK_LOCAL netipsec
    658  1.17  ozaki 	rump_server_crypto_start $SOCK_PEER netipsec
    659  1.17  ozaki 	rump_server_add_iface $SOCK_LOCAL shmif0 $BUS
    660  1.17  ozaki 	rump_server_add_iface $SOCK_PEER shmif0 $BUS
    661  1.17  ozaki 
    662  1.17  ozaki 	export RUMP_SERVER=$SOCK_LOCAL
    663  1.17  ozaki 	atf_check -s exit:0 rump.sysctl -q -w net.inet.ip.dad_count=0
    664  1.17  ozaki 	atf_check -s exit:0 rump.ifconfig shmif0 $ip_local/24
    665  1.17  ozaki 
    666  1.17  ozaki 	export RUMP_SERVER=$SOCK_PEER
    667  1.17  ozaki 	atf_check -s exit:0 rump.sysctl -q -w net.inet.ip.dad_count=0
    668  1.17  ozaki 	atf_check -s exit:0 rump.ifconfig shmif0 $ip_peer/24
    669  1.17  ozaki 
    670  1.17  ozaki 	setup_sp $proto "$algo_args" $ip_local $ip_peer
    671  1.17  ozaki 
    672  1.17  ozaki 	extract_new_packets $BUS > $outfile
    673  1.17  ozaki 
    674  1.17  ozaki 	export RUMP_SERVER=$SOCK_LOCAL
    675  1.17  ozaki 	# It doesn't work because there is no SA
    676  1.17  ozaki 	atf_check -s not-exit:0 -o ignore rump.ping -c 1 -n -w 3 $ip_peer
    677  1.17  ozaki }
    678  1.17  ozaki 
    679  1.17  ozaki add_test_nosa()
    680  1.17  ozaki {
    681  1.17  ozaki 	local proto=$1
    682  1.17  ozaki 	local algo=$2
    683  1.17  ozaki 	local _algo=$(echo $algo | sed 's/-//g')
    684  1.17  ozaki 	local name= desc=
    685  1.17  ozaki 
    686  1.17  ozaki 	desc="Tests SPs with no relevant SAs with $proto ($algo)"
    687  1.17  ozaki 	name="ipsec_nosa_${proto}_${_algo}"
    688  1.17  ozaki 
    689  1.17  ozaki 	atf_test_case ${name} cleanup
    690  1.18  ozaki 	eval "
    691  1.18  ozaki 	    ${name}_head() {
    692  1.18  ozaki 	        atf_set descr \"$desc\"
    693  1.18  ozaki 	        atf_set require.progs rump_server setkey
    694  1.18  ozaki 	    }
    695  1.18  ozaki 	    ${name}_body() {
    696  1.18  ozaki 	        test_nosa $proto $algo
    697  1.18  ozaki 	        rump_server_destroy_ifaces
    698  1.18  ozaki 	    }
    699  1.18  ozaki 	    ${name}_cleanup() {
    700  1.18  ozaki 	        \$DEBUG && dump
    701  1.18  ozaki 	        cleanup
    702  1.18  ozaki 	    }
    703  1.17  ozaki 	"
    704  1.17  ozaki 	atf_add_test_case ${name}
    705  1.17  ozaki }
    706  1.17  ozaki 
    707  1.20  ozaki test_multiple_sa()
    708  1.20  ozaki {
    709  1.20  ozaki 	local proto=$1
    710  1.20  ozaki 	local algo=$2
    711  1.20  ozaki 	local update=$3
    712  1.20  ozaki 	local ip_local=10.0.0.1
    713  1.20  ozaki 	local ip_peer=10.0.0.2
    714  1.20  ozaki 	local ip_peer2=10.0.0.3
    715  1.20  ozaki 	local algo_args="$(generate_algo_args $proto $algo)"
    716  1.20  ozaki 	local proto_cap=$(echo $proto | tr 'a-z' 'A-Z')
    717  1.20  ozaki 	local outfile=./out
    718  1.20  ozaki 
    719  1.20  ozaki 	rump_server_crypto_start $SOCK_LOCAL netipsec
    720  1.20  ozaki 	rump_server_crypto_start $SOCK_PEER netipsec
    721  1.20  ozaki 	rump_server_add_iface $SOCK_LOCAL shmif0 $BUS
    722  1.20  ozaki 	rump_server_add_iface $SOCK_PEER shmif0 $BUS
    723  1.20  ozaki 
    724  1.20  ozaki 	export RUMP_SERVER=$SOCK_LOCAL
    725  1.20  ozaki 	atf_check -s exit:0 rump.sysctl -q -w net.inet.ip.dad_count=0
    726  1.20  ozaki 	atf_check -s exit:0 rump.ifconfig shmif0 $ip_local/24
    727  1.20  ozaki 
    728  1.20  ozaki 	export RUMP_SERVER=$SOCK_PEER
    729  1.20  ozaki 	atf_check -s exit:0 rump.sysctl -q -w net.inet.ip.dad_count=0
    730  1.20  ozaki 	atf_check -s exit:0 rump.ifconfig shmif0 $ip_peer/24
    731  1.20  ozaki 	atf_check -s exit:0 rump.ifconfig shmif0 $ip_peer2/24 alias
    732  1.20  ozaki 
    733  1.20  ozaki 	setup_sp $proto "$algo_args" "$ip_local" "0.0.0.0/0"
    734  1.20  ozaki 
    735  1.20  ozaki 	extract_new_packets $BUS > $outfile
    736  1.20  ozaki 
    737  1.20  ozaki 	export RUMP_SERVER=$SOCK_LOCAL
    738  1.20  ozaki 	# There is no SA, so ping should fail
    739  1.20  ozaki 	atf_check -s not-exit:0 -o ignore rump.ping -c 1 -n -w 3 $ip_peer
    740  1.20  ozaki 	atf_check -s not-exit:0 -o ignore rump.ping -c 1 -n -w 3 $ip_peer2
    741  1.20  ozaki 
    742  1.20  ozaki 	add_sa $proto "$algo_args" $ip_local $ip_peer 100 10000
    743  1.20  ozaki 
    744  1.20  ozaki 	export RUMP_SERVER=$SOCK_LOCAL
    745  1.20  ozaki 	# There is only an SA for $ip_peer, so ping to $ip_peer2 should fail
    746  1.20  ozaki 	atf_check -s exit:0 -o ignore rump.ping -c 1 -n -w 3 $ip_peer
    747  1.20  ozaki 	atf_check -s not-exit:0 -o ignore rump.ping -c 1 -n -w 3 $ip_peer2
    748  1.20  ozaki 
    749  1.20  ozaki 	add_sa $proto "$algo_args" $ip_local $ip_peer2 100 10010
    750  1.20  ozaki 
    751  1.20  ozaki 	export RUMP_SERVER=$SOCK_LOCAL
    752  1.20  ozaki 	atf_check -s exit:0 -o ignore rump.ping -c 1 -n -w 3 $ip_peer
    753  1.20  ozaki 	atf_check -s exit:0 -o ignore rump.ping -c 1 -n -w 3 $ip_peer2
    754  1.20  ozaki 
    755  1.20  ozaki 	export RUMP_SERVER=$SOCK_LOCAL
    756  1.20  ozaki 	atf_check -s exit:0 -o match:"$proto/transport//require" \
    757  1.20  ozaki 	    $HIJACKING setkey -D -P
    758  1.20  ozaki 	# Check if the policy isn't modified accidentally
    759  1.20  ozaki 	atf_check -s exit:0 -o not-match:"$proto/transport/.+\-.+/require" \
    760  1.20  ozaki 	    $HIJACKING setkey -D -P
    761  1.20  ozaki 	export RUMP_SERVER=$SOCK_PEER
    762  1.20  ozaki 	atf_check -s exit:0 -o match:"$proto/transport//require" \
    763  1.20  ozaki 	    $HIJACKING setkey -D -P
    764  1.20  ozaki 	# Check if the policy isn't modified accidentally
    765  1.20  ozaki 	atf_check -s exit:0 -o not-match:"$proto/transport/.+\-.+/require" \
    766  1.20  ozaki 	    $HIJACKING setkey -D -P
    767  1.20  ozaki }
    768  1.20  ozaki 
    769  1.20  ozaki add_test_multiple_sa()
    770  1.20  ozaki {
    771  1.20  ozaki 	local proto=$1
    772  1.20  ozaki 	local algo=$2
    773  1.20  ozaki 	local _algo=$(echo $algo | sed 's/-//g')
    774  1.20  ozaki 	local name= desc=
    775  1.20  ozaki 
    776  1.20  ozaki 	desc="Tests multiple SAs with $proto ($algo)"
    777  1.20  ozaki 	name="ipsec_multiple_sa_${proto}_${_algo}"
    778  1.20  ozaki 
    779  1.20  ozaki 	atf_test_case ${name} cleanup
    780  1.20  ozaki 	eval "
    781  1.20  ozaki 	    ${name}_head() {
    782  1.20  ozaki 	        atf_set descr \"$desc\"
    783  1.20  ozaki 	        atf_set require.progs rump_server setkey
    784  1.20  ozaki 	    }
    785  1.20  ozaki 	    ${name}_body() {
    786  1.20  ozaki 	        test_multiple_sa $proto $algo
    787  1.20  ozaki 	        rump_server_destroy_ifaces
    788  1.20  ozaki 	    }
    789  1.20  ozaki 	    ${name}_cleanup() {
    790  1.20  ozaki 	        \$DEBUG && dump
    791  1.20  ozaki 	        cleanup
    792  1.20  ozaki 	    }
    793  1.20  ozaki 	"
    794  1.20  ozaki 	atf_add_test_case ${name}
    795  1.20  ozaki }
    796  1.20  ozaki 
    797   1.1  ozaki atf_init_test_cases()
    798   1.1  ozaki {
    799   1.1  ozaki 	local algo=
    800   1.1  ozaki 
    801   1.1  ozaki 	for algo in $ESP_ENCRYPTION_ALGORITHMS_MINIMUM; do
    802   1.1  ozaki 		add_test_lifetime ipv4 esp $algo
    803   1.1  ozaki 		add_test_lifetime ipv6 esp $algo
    804   1.8  ozaki 		add_test_update esp $algo sa
    805   1.8  ozaki 		add_test_update esp $algo sp
    806  1.13  ozaki 		add_test_spi esp $algo new delete
    807  1.13  ozaki 		add_test_spi esp $algo old delete
    808  1.13  ozaki 		add_test_spi esp $algo new timeout
    809  1.13  ozaki 		add_test_spi esp $algo old timeout
    810  1.17  ozaki 		add_test_nosa esp $algo
    811  1.20  ozaki 		add_test_multiple_sa esp $algo
    812   1.1  ozaki 	done
    813   1.1  ozaki 	for algo in $AH_AUTHENTICATION_ALGORITHMS_MINIMUM; do
    814   1.1  ozaki 		add_test_lifetime ipv4 ah $algo
    815   1.1  ozaki 		add_test_lifetime ipv6 ah $algo
    816   1.8  ozaki 		add_test_update ah $algo sa
    817   1.8  ozaki 		add_test_update ah $algo sp
    818  1.13  ozaki 		add_test_spi ah $algo new delete
    819  1.13  ozaki 		add_test_spi ah $algo old delete
    820  1.13  ozaki 		add_test_spi ah $algo new timeout
    821  1.13  ozaki 		add_test_spi ah $algo old timeout
    822  1.17  ozaki 		add_test_nosa ah $algo
    823  1.20  ozaki 		add_test_multiple_sa ah $algo
    824   1.1  ozaki 	done
    825   1.1  ozaki }
    826