netdev
[Top] [All Lists]

[XFRM] Allow transport SAs even when there is no policy

To: Patrick McHardy <kaber@xxxxxxxxx>
Subject: [XFRM] Allow transport SAs even when there is no policy
From: Herbert Xu <herbert@xxxxxxxxxxxxxxxxxxx>
Date: Tue, 19 Oct 2004 07:43:26 +1000
Cc: "David S. Miller" <davem@xxxxxxxxxx>, netdev@xxxxxxxxxxx, ipsec-tools-devel@xxxxxxxxxxxxxxxxxxxxx
In-reply-to: <417428CF.2050802@xxxxxxxxx>
References: <4172943B.8050904@xxxxxxxxx> <20041017212317.GA28615@xxxxxxxxxxxxxxxxxxx> <4172F1AB.4020305@xxxxxxxxx> <20041017231258.GA29294@xxxxxxxxxxxxxxxxxxx> <417428CF.2050802@xxxxxxxxx>
Sender: netdev-bounce@xxxxxxxxxxx
User-agent: Mutt/1.5.6+20040722i
On Mon, Oct 18, 2004 at 10:34:23PM +0200, Patrick McHardy wrote:
> 
> > More importantly that it'll stick out like a sore thumb in terms of
> >
> > its semantics.
> 
> __xfrm_policy_check already rejects packets without a matching policy
> and skb->sp set, but it is skipped while the policy list is empty.
> What, from a semantics point of view, would be wrong with making
> xfrm_policy_check behave the same way ?

Good catch.  That was a bug introduced by yours truly :)

What I meant to say is all packets with tunnel mode SAs should be
rejected since we don't allow optional tunnel transforms for security
reasons.

This patch fixes it.

Signed-off-by: Herbert Xu <herbert@xxxxxxxxxxxxxxxxxxx>

Thanks,
-- 
Visit Openswan at http://www.openswan.org/
Email: Herbert Xu ~{PmV>HI~} <herbert@xxxxxxxxxxxxxxxxxxx>
Home Page: http://gondor.apana.org.au/~herbert/
PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt

Attachment: p
Description: Text document

<Prev in Thread] Current Thread [Next in Thread>