1. 11 Jul, 2011 2 commits
    • David Ward's avatar
      xfrm: Update documentation · cbec0219
      David Ward authored
      The ip(8) man page and the "ip xfrm [ XFRM-OBJECT ] help" command output
      are updated to include missing options, fix errors, and improve grammar.
      There are no functional changes made.
      
      The documentation for the ip command has many different meanings for the
      same formatting symbols (which really needs to be fixed). This patch makes
      consistent use of brackets [ ] to indicate optional parameters, pipes | to
      mean "OR", braces { } to group things together, and dashes - instead of
      underscores _ inside of parameter names. The parameters are listed in the
      order in which they are parsed in the source code.
      
      There are several parameters and options that are still not mentioned or
      need to be described more thoroughly in the "COMMAND SYNTAX" section of
      the ip(8) man page. I would appreciate help from the developers with this.
      Signed-off-by: default avatarDavid Ward <david.ward@ll.mit.edu>
      cbec0219
    • Gilles Espinasse's avatar
      iproute2: fix minor typo in comments · 4f69c63a
      Gilles Espinasse authored
      Signed-off-by: default avatarGilles Espinasse <g.esp@free.fr>
      4f69c63a
  2. 29 Jun, 2011 5 commits
  3. 20 Jun, 2011 5 commits
  4. 19 May, 2011 1 commit
  5. 12 May, 2011 1 commit
    • Eric Dumazet's avatar
      ip: Support IFLA_TXQLEN in ip link command · f78e316f
      Eric Dumazet authored
      Eric Dumazet a écrit :
      > We currently use an expensive ioctl() to get device txqueuelen, while
      > rtnetlink gave it to us for free. This patch speeds up ip link operation
      > when many devices are registered.
      >
      
      Here is a 2nd version od this patch, not displaying "qlen 0" useless info
      
      [PATCH iproute2] ip: Support IFLA_TXQLEN in ip link show command
      
      We currently use an expensive ioctl() to get device txqueuelen, while
      rtnetlink gave it to us for free. This patch speeds up ip link operation
      when many devices are registered.
      Signed-off-by: default avatarEric Dumazet <eric.dumazet@gmail.com>
      f78e316f
  6. 26 Apr, 2011 1 commit
  7. 12 Apr, 2011 16 commits
  8. 17 Mar, 2011 9 commits
    • Stephen Hemminger's avatar
      v2.6.38.1 · 77d1e6ab
      Stephen Hemminger authored
      77d1e6ab
    • Nicolas Dichtel's avatar
      iproute2: allow to specify truncation bits on auth algo · aba38344
      Nicolas Dichtel authored
      Hi,
      
      here is a patch against iproute2 to allow user to set a state with a specific
      auth length.
      
      Example:
      $ ip xfrm state add src 10.16.0.72 dst 10.16.0.121 proto ah spi 0x10000000
      auth-trunc "sha256" "azertyuiopqsdfghjklmwxcvbn123456" 96 mode tunnel
      $ ip xfrm state
      src 10.16.0.72 dst 10.16.0.121
               proto ah spi 0x10000000 reqid 0 mode tunnel
               replay-window 0
               auth-trunc hmac(sha256)
      0x617a6572747975696f707173646667686a6b6c6d77786376626e313233343536 96
               sel src 0.0.0.0/0 dst 0.0.0.0/0
      
      Regards,
      Nicolas
      
      >From 522ed7348cdf3b6f501af2a5a5d989de1696565a Mon Sep 17 00:00:00 2001
      From: Nicolas Dichtel <nicolas.dichtel@6wind.com>
      Date: Thu, 23 Dec 2010 06:48:12 -0500
      Subject: [PATCH] iproute2: allow to specify truncation bits on auth algo
      
      Attribute XFRMA_ALG_AUTH_TRUNC can be used to specify
      truncation bits, so we add a new algo type: auth-trunc.
      Signed-off-by: default avatarNicolas Dichtel <nicolas.dichtel@6wind.com>
      aba38344
    • Vlad Dogaru's avatar
      iproute2: fix man page whitespace · 2c19bf6a
      Vlad Dogaru authored
      Signed-off-by: default avatarVlad Dogaru <ddvlad@rosedu.org>
      2c19bf6a
    • Gerrit Renker's avatar
      iproute: rename 'get_jiffies' since it uses msecs · db6b0cfa
      Gerrit Renker authored
      The get_jiffies() function retrieves rtt-type values in units of
      milliseconds. This patch updates the function name accordingly,
      following the pattern given by dst_metric() <=> dst_metric_rtt().
      db6b0cfa
    • Gerrit Renker's avatar
      iproute: fix unit conversion of rtt/rttvar/rto_min · fca1dae8
      Gerrit Renker authored
      Since July 2008 (2.6.27, c1e20f7c8b9), the kernel stores the values for
      RTAX_{RTT{,VAR},RTO_MIN} in milliseconds. When using a kernel > 2.6.27 with
      the current iproute2, conversion of these values is broken in either way.
      
      This patch
       * updates the code to pass and retrieve milliseconds;
       * since values < 1msec would be rounded up, also drops the usec/nsec variants;
       * since there is no way to query kernel HZ, also drops the jiffies variant.
      
      Arguments such as
      	rtt		3.23sec
      	rto_min		0xff
      	rto_min		0.200s
      	rttvar		25ms
      now all work as expected when reading back previously set values.
      fca1dae8
    • Gerrit Renker's avatar
      utils: get_jiffies always uses base=0 · 897fb84f
      Gerrit Renker authored
      get_jiffies() is in all places called in the same manner, with base=0;
      simplify argument list by putting the constant value into the function.
      897fb84f
    • Joy Latten's avatar
      xfrm security context support · 4bb75da2
      Joy Latten authored
      Adds security context support to ip xfrm state.
      Signed-off-by: default avatarJoy Latten <latten@austin.ibm.com>
      4bb75da2
    • Joy Latten's avatar
      xfrm security context support · e5055b59
      Joy Latten authored
      Adds security context support to ip xfrm policy.
      Signed-off-by: default avatarJoy Latten <latten@austin.ibm.com>
      e5055b59
    • Joy Latten's avatar
      xfrm security context support · 2c319e1a
      Joy Latten authored
      In the Linux kernel, ipsec policy and SAs can include a
      security context to support MAC networking. This feature
      is often referred to as "labeled ipsec".
      
      This patchset adds security context support into ip xfrm
      such that a security context can be included when
      add/delete/display SAs and policies with the ip command.
      The user provides the security context when adding
      SAs and policies. If a policy or SA contains a security
      context, the changes allow the security context to be displayed.
      
      For example,
      ip xfrm state
      src 10.1.1.6 dst 10.1.1.2
      	proto esp spi 0x00000301 reqid 0 mode transport
      	replay-window 0
      	auth hmac(digest_null) 0x3078
      	enc cbc(des3_ede) 0x6970763672656164796c6f676f33646573636263696e3031
      	security context root:system_r:unconfined_t:s0
      
      Please  let me know if all is ok with the patchset.
      Thanks!!
      
      regards,
      Joy
      Signed-off-by: default avatarJoy Latten <latten@austin.ibm.com>
      2c319e1a