Commit a718759e5a for strongswan.org
commit a718759e5a2de5aba8c8da985c773a2ab9cff186
Author: Duc Anh Luu <luuducanh05051995@gmail.com>
Date: Tue Oct 6 00:05:56 2026 +0700
message: Log the limit if a fragmented message is too large
When the reassembled size of a fragmented IKE message exceeds max_packet,
the message is dropped and only "fragmented IKE message is too large" is
logged. With post-quantum signatures (e.g. ML-DSA-87 certificates, which
result in IKE_AUTH messages of about 12.5 kB) this limit is easily reached
with the default of 10000 bytes. Change the wording to make the
connection to the max_packet option clearer and log the configured limit.
Closes strongswan/strongswan#3162
diff --git a/src/libcharon/encoding/message.c b/src/libcharon/encoding/message.c
index 3037788bc5..7d1d461192 100644
--- a/src/libcharon/encoding/message.c
+++ b/src/libcharon/encoding/message.c
@@ -2943,7 +2943,8 @@ static status_t add_fragment(private_message_t *this, uint16_t num,
this->frag->len += data.len;
if (this->frag->len > this->frag->max_packet)
{
- DBG1(DBG_ENC, "fragmented IKE message is too large");
+ DBG1(DBG_ENC, "fragmented IKE message exceeds the maximum packet "
+ "size of %zu bytes", this->frag->max_packet);
reset_defrag(this);
return FAILED;
}