git: a01d6ba04ab6 - main - security/strongswan: Disable loading of kernel-libipsec plugin
- Go to: [ bottom of page ] [ top of archives ] [ this month ]
Date: Sat, 12 Sep 2026 16:23:50 UTC
The branch main has been updated by vvd:
URL: https://cgit.FreeBSD.org/ports/commit/?id=a01d6ba04ab6d6a51aafe15f788f72be55ccc68d
commit a01d6ba04ab6d6a51aafe15f788f72be55ccc68d
Author: Oleksandr Kryvulia <o.kryvulia@flex-it.com.ua>
AuthorDate: 2026-09-12 16:20:04 +0000
Commit: Vladimir Druzenko <vvd@FreeBSD.org>
CommitDate: 2026-09-12 16:20:04 +0000
security/strongswan: Disable loading of kernel-libipsec plugin
115e0906c85a enables building with KERNELLIBIPSEC option by default.
This changes loading order of plugins and brokes some existing
configurations.
PR: 298098 295828
Approved by: blanket (fix runtime)
Sponsored by: FLEX-IT LLC
Sponsored by: UNIS Labs (vvd, commit patch)
---
security/strongswan/Makefile | 2 +-
.../strongswan/files/patch-conf_plugins_kernel-libipsec.conf | 11 +++++++++++
2 files changed, 12 insertions(+), 1 deletion(-)
diff --git a/security/strongswan/Makefile b/security/strongswan/Makefile
index c4bf35c51dfc..79050297e177 100644
--- a/security/strongswan/Makefile
+++ b/security/strongswan/Makefile
@@ -1,6 +1,6 @@
PORTNAME= strongswan
DISTVERSION= 6.0.7
-PORTREVISION= 1
+PORTREVISION= 2
CATEGORIES= security net-vpn
MASTER_SITES= https://download.strongswan.org/ \
https://download2.strongswan.org/
diff --git a/security/strongswan/files/patch-conf_plugins_kernel-libipsec.conf b/security/strongswan/files/patch-conf_plugins_kernel-libipsec.conf
new file mode 100644
index 000000000000..bf97951c4550
--- /dev/null
+++ b/security/strongswan/files/patch-conf_plugins_kernel-libipsec.conf
@@ -0,0 +1,11 @@
+--- conf/plugins/kernel-libipsec.conf.orig 2026-09-08 11:32:49 UTC
++++ conf/plugins/kernel-libipsec.conf
+@@ -8,7 +8,7 @@ kernel-libipsec {
+
+ # Whether to load the plugin. Can also be an integer to increase the
+ # priority of this plugin.
+- load = yes
++ load = no
+
+ # Whether to send and receive ESP packets without UDP encapsulation if
+ # supported on this platform and no NAT is detected.