diff options
author | Benedict Wong <benedictwong@google.com> | 2023-05-10 01:14:14 +0000 |
---|---|---|
committer | Steffen Klassert <steffen.klassert@secunet.com> | 2023-05-10 07:56:05 +0200 |
commit | 8680407b6f8f5fba59e8f1d63c869abc280f04df (patch) | |
tree | 348112beaab4cedb426f37f881971c848c8016e5 /scripts/gdb | |
parent | cf3128a7aca55b2eefb68281d44749c683bdc96f (diff) |
xfrm: Check if_id in inbound policy/secpath match
This change ensures that if configured in the policy, the if_id set in
the policy and secpath states match during the inbound policy check.
Without this, there is potential for ambiguity where entries in the
secpath differing by only the if_id could be mismatched.
Notably, this is checked in the outbound direction when resolving
templates to SAs, but not on the inbound path when matching SAs and
policies.
Test: Tested against Android kernel unit tests & CTS
Signed-off-by: Benedict Wong <benedictwong@google.com>
Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
Diffstat (limited to 'scripts/gdb')
0 files changed, 0 insertions, 0 deletions