Re: [PATCH ipsec-next] Clear secpath on loopback_xmit

2018-10-07 Thread Steffen Klassert
On Fri, Oct 05, 2018 at 11:23:28AM -0700, Benedict Wong wrote: > This patch clears the skb->sp when transmitted over loopback. This > ensures that the loopback-ed packet does not have any secpath > information from the outbound transforms. > > At present, this causes XFRM tunnel mode packets to be

[PATCH ipsec-next] Clear secpath on loopback_xmit

2018-10-05 Thread Benedict Wong
This patch clears the skb->sp when transmitted over loopback. This ensures that the loopback-ed packet does not have any secpath information from the outbound transforms. At present, this causes XFRM tunnel mode packets to be dropped with XFRMINNOPOLS, due to the outbound state being in the secpat