Update an in-kernel tdb. Silently fail if no tdb is found. */
| 1263 | #if defined(IPSEC) |
| 1264 | /* Update an in-kernel tdb. Silently fail if no tdb is found. */ |
| 1265 | static void |
| 1266 | pfsync_update_net_tdb(struct pfsync_tdb *pt) |
| 1267 | { |
| 1268 | struct tdb *tdb; |
| 1269 | int s; |
| 1270 | |
| 1271 | /* check for invalid values */ |
| 1272 | if (ntohl(pt->spi) <= SPI_RESERVED_MAX || |
| 1273 | (pt->dst.sa.sa_family != AF_INET && |
| 1274 | pt->dst.sa.sa_family != AF_INET6)) |
| 1275 | goto bad; |
| 1276 | |
| 1277 | tdb = gettdb(pt->spi, &pt->dst, pt->sproto); |
| 1278 | if (tdb) { |
| 1279 | pt->rpl = ntohl(pt->rpl); |
| 1280 | pt->cur_bytes = (unsigned long long)be64toh(pt->cur_bytes); |
| 1281 | |
| 1282 | /* Neither replay nor byte counter should ever decrease. */ |
| 1283 | if (pt->rpl < tdb->tdb_rpl || |
| 1284 | pt->cur_bytes < tdb->tdb_cur_bytes) { |
| 1285 | goto bad; |
| 1286 | } |
| 1287 | |
| 1288 | tdb->tdb_rpl = pt->rpl; |
| 1289 | tdb->tdb_cur_bytes = pt->cur_bytes; |
| 1290 | } |
| 1291 | return; |
| 1292 | |
| 1293 | bad: |
| 1294 | if (V_pf_status.debug >= PF_DEBUG_MISC) |
| 1295 | printf("pfsync_insert: PFSYNC_ACT_TDB_UPD: " |
| 1296 | "invalid value\n"); |
| 1297 | V_pfsyncstats.pfsyncs_badstate++; |
| 1298 | return; |
| 1299 | } |
| 1300 | #endif |
| 1301 | |
| 1302 | static int |
no test coverage detected