netdev
[Top] [All Lists]

Re: [IPSEC] Find larval SAs by sequence number

To: Herbert Xu <herbert@xxxxxxxxxxxxxxxxxxx>
Subject: Re: [IPSEC] Find larval SAs by sequence number
From: "David S. Miller" <davem@xxxxxxxxxxxxx>
Date: Fri, 10 Sep 2004 14:53:50 -0700
Cc: kuznet@xxxxxxxxxxxxx, jmorris@xxxxxxxxxx, netdev@xxxxxxxxxxx
In-reply-to: <20040909121332.GA31902@gondor.apana.org.au>
References: <20040909121332.GA31902@gondor.apana.org.au>
Sender: netdev-bounce@xxxxxxxxxxx
On Thu, 9 Sep 2004 22:13:32 +1000
Herbert Xu <herbert@xxxxxxxxxxxxxxxxxxx> wrote:

> When larval states are generated along with ACQUIRE messages, we should
> use the sequence to find the corresponding larval state when creating
> states with ADD_SA or ALLOC_SPI.
> 
> If we don't do that, then it may take down an unrelated larval state
> with the same parameters (think different TCP sessions).  This not only
> leaves behind a larval state that shouldn't be there, it may also cause
> another ACQUIRE message to be sent unnecessarily.

Looks good, applied.

<Prev in Thread] Current Thread [Next in Thread>