Skip to content

fix(ipsec): reconcile owned connections after local endpoint changes - #25

Closed
chen21019 wants to merge 2 commits into
mainfrom
verification/ipsec-vxlan-overlay-network-0.14.38-local-endpoint
Closed

chen21019 wants to merge 2 commits into
mainfrom
verification/ipsec-vxlan-overlay-network-0.14.38-local-endpoint

Conversation

@chen21019

Copy link
Copy Markdown

Repair

Bind the IPsec connection cache to the local Agent address and the complete effective IKE configuration. Update the cache only after a successful load; discovered connection names are not ownership evidence.

After connections, policies and routes succeed, retire only the exact previously owned local-endpoint IKE ID. Preserve foreign or ambiguous associations, explicit identities, crypto settings, firewall backend selection and plugin ownership boundaries.

Verification

Targeted connection tests (8 tests plus 9 negative subcases) and a Linux cross-build passed with the existing Go 1.26.6 toolchain. Four real-Git history contract tests passed. Security and CodeQL gates on the candidate SHA are pending; both will be rerun against the final merged SHA before the separate numeric v0.14.38 release. No published digest or live endpoint-change acceptance is claimed here.

The release history gate now permits normal reviewed PR merges while retaining clean-tree, reviewed-ancestor, nonempty-delta and exact-SHA checks. Its regression test runs inside the Security gate.

@chen21019
chen21019 requested a review from a team as a code owner October 5, 2026 04:19
@chen21019

Copy link
Copy Markdown
Author

Superseded by signed-source PR #26, now normally merged as c143e9a. The reviewed tree is unchanged. Same-commit main Security and CodeQL gates 37266561280 / 37266569003 passed. Release v0.14.38 is in progress; this closure does not claim deployed acceptance.

@chen21019 chen21019 closed this Oct 5, 2026
@chen21019
chen21019 deleted the verification/ipsec-vxlan-overlay-network-0.14.38-local-endpoint branch October 5, 2026 05:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant