On Thu, Jul 19, 2018 at 07:07:47PM -0700, Nathan Harold wrote: > Allow attaching an SA to an xfrm interface id after > the creation of the SA, so that tasks such as keying > which must be done as the SA is created, can remain > separate from the decision on how to route traffic > from an SA. This permits SA creation to be decomposed > in to three separate steps: > 1) allocation of a SPI > 2) algorithm and key negotiation > 3) insertion into the data path > > Signed-off-by: Nathan Harold <nhar...@google.com>
Applied to ipsec-next, thanks Nathan!