FreeBSD src
Go to file
John Baldwin a8280123e4 KTLS: Add a new recrypt operation to the software backend.
When using NIC TLS RX, packets that are dropped and retransmitted are
not decrypted by the NIC but are passed along as-is.  As a result, a
received TLS record might contain a mix of encrypted and decrypted
data.  If this occurs, the already-decrypted data needs to be
re-encrypted so that the resulting record can then be decrypted
normally.

Add support for this for sessions using AES-GCM with TLS 1.2 or TLS
1.3.  For the recrypt operation, allocate a temporary buffer and
encrypt the the payload portion of the TLS record with AES-CTR with an
initial IV constructed from the AES-GCM nonce.  Then fixup the
original mbuf chain by copying the results from the temporary buffer
back into the original mbufs for any mbufs containing decrypted data.

Once it has been recrypted, the mbuf chain can then be decrypted via
the normal software decryption path.

Co-authored by:	Hans Petter Selasky <hselasky@FreeBSD.org>
Reviewed by:	hselasky
Sponsored by:	Netflix
Differential Revision:	https://reviews.freebsd.org/D35012
2022-04-22 15:52:50 -07:00
.cirrus-ci Cirrus-CI: add some timing info on pkg install failure 2021-08-04 15:02:00 -04:00
.github GitHub: Add libefivar's path to CODEOWNERS 2022-02-27 09:11:39 -07:00
bin pax(1): Remove a few double words in source code comments 2022-04-09 14:27:39 +02:00
cddl ctf: Link CTF toolchain man pages to ctf.5 2022-04-21 11:20:28 -04:00
contrib Merge bmake-20220418 2022-04-22 13:42:11 -07:00
crypto ssh: remove duplicate setting of MAIL env var 2022-04-19 10:30:52 -04:00
etc bintrans: move files to a new directory 2022-04-18 10:53:11 +02:00
gnu libdialog: Bump shared library version to 10. 2021-10-27 09:30:24 -07:00
include vendor/bc: import version 5.2.4 2022-04-17 13:20:54 +02:00
kerberos5 pkgbase: Create a FreeBSD-kerberos package 2021-09-07 10:23:14 +02:00
lib pf: Add per-rule timestamps for rule and eth_rule 2022-04-22 19:53:20 +02:00
libexec libexec/rc.d/hostapd: Down/up interface when interface is specified 2022-04-22 09:15:49 -07:00
release release/rc.local: Replace dialog with bsddialog 2022-03-29 15:21:02 +02:00
rescue rescue: Link with -lncursesw instead of -lncursesw_real. 2022-02-11 13:58:59 -08:00
sbin pf: Add per-rule timestamps for rule and eth_rule 2022-04-22 19:53:20 +02:00
secure ssh: update to OpenSSH v8.9p1 2022-04-13 16:00:56 -04:00
share locales: Update to CLDR 41.0 and Unicode 14.0 2022-04-21 14:16:40 +02:00
stand stand: zfs: handle holes at the tail end correctly 2022-04-21 14:57:24 -05:00
sys KTLS: Add a new recrypt operation to the software backend. 2022-04-22 15:52:50 -07:00
targets bintrans: move files to a new directory 2022-04-18 10:53:11 +02:00
tests Have posixshm_test ask the kernel for the page size 2022-04-20 14:44:52 +01:00
tools stress2: Added a syzkaller reproducer 2022-04-22 06:20:14 +02:00
usr.bin Merge bmake-20220418 2022-04-22 13:42:11 -07:00
usr.sbin freebsd-update.8: Note availability of updates for ALPHA, BETA, and RC 2022-04-22 14:37:14 +02:00
.arcconfig Remove history.immutable from .arcconfig 2021-04-13 12:36:25 +01:00
.arclint arc lint: ignore /tests/ in chmod 2017-12-19 03:38:06 +00:00
.cirrus.yml Cirrus-CI: add a manual amd64-gcc9 build and smoketest job 2022-02-15 12:55:14 -05:00
.clang-format clang-format: Add bitset loop macros 2021-09-21 12:08:01 -04:00
.gitattributes Add a basic clang-format configuration file 2019-06-07 15:23:52 +00:00
.gitignore Vendor import of BearSSL at 2022-04-18 hash d40d23b 2022-04-18 11:05:13 -07:00
COPYRIGHT Welcome 2022, update copyrights. 2022-01-01 09:49:49 -07:00
LOCKS LOCKS: update current locks 2018-06-09 03:08:04 +00:00
MAINTAINERS Remove myself from bhyve maintenance; ENOTIME. 2021-11-19 07:09:30 +10:00
Makefile cleankernel: A target to delete the kernel compile file 2022-02-11 12:51:24 -07:00
Makefile.inc1 bintrans: move files to a new directory 2022-04-18 10:53:11 +02:00
Makefile.libcompat Makefile.libcompat: Sort 2022-02-02 14:34:29 -07:00
Makefile.sys.inc AUTO_OBJ: For all top-level targets enforce using an OBJDIR. 2017-12-05 21:29:47 +00:00
ObsoleteFiles.inc bintrans: move files to a new directory 2022-04-18 10:53:11 +02:00
README.md README.md: update gnu directory description 2021-12-17 08:45:31 -05:00
RELNOTES RELNOTES: Add an entry for boottrace(4) 2022-03-29 13:35:14 +02:00
UPDATING UPDATING: Fix a few typos 2022-04-10 10:11:17 +02:00

FreeBSD Source:

This is the top level of the FreeBSD source directory.

FreeBSD is an operating system used to power modern servers, desktops, and embedded platforms. A large community has continually developed it for more than thirty years. Its advanced networking, security, and storage features have made FreeBSD the platform of choice for many of the busiest web sites and most pervasive embedded networking and storage devices.

For copyright information, please see the file COPYRIGHT in this directory. Additional copyright information also exists for some sources in this tree - please see the specific source directories for more information.

The Makefile in this directory supports a number of targets for building components (or all) of the FreeBSD source tree. See build(7), config(8), FreeBSD handbook on building userland, and Handbook for kernels for more information, including setting make(1) variables.

Source Roadmap:

Directory Description
bin System/user commands.
cddl Various commands and libraries under the Common Development and Distribution License.
contrib Packages contributed by 3rd parties.
crypto Cryptography stuff (see crypto/README).
etc Template files for /etc.
gnu Commands and libraries under the GNU General Public License (GPL) or Lesser General Public License (LGPL). Please see gnu/COPYING and gnu/COPYING.LIB for more information.
include System include files.
kerberos5 Kerberos5 (Heimdal) package.
lib System libraries.
libexec System daemons.
release Release building Makefile & associated tools.
rescue Build system for statically linked /rescue utilities.
sbin System commands.
secure Cryptographic libraries and commands.
share Shared resources.
stand Boot loader sources.
sys Kernel sources.
sys/arch/conf Kernel configuration files. GENERIC is the configuration used in release builds. NOTES contains documentation of all possible entries.
tests Regression tests which can be run by Kyua. See tests/README for additional information.
tools Utilities for regression testing and miscellaneous tasks.
usr.bin User commands.
usr.sbin System administration commands.

For information on synchronizing your source tree with one or more of the FreeBSD Project's development branches, please see FreeBSD Handbook.