Thread (1 message) 1 message, 1 author, 2025-06-12

Re: [EXTERNAL] Re: [PATCH] xfrm: Duplicate SPI Handling – IPsec-v3 Compliance Concern

From: Steffen Klassert <steffen.klassert@secunet.com>
Date: 2025-06-12 05:02:27

On Wed, Jun 11, 2025 at 11:39:59AM +0000, Aakash Kumar Shankarappa wrote:
Hi Steffen,
Thanks for the review.
Agreed. As per the RFC, for unicast traffic, the packet is looked up in the SAD based on the SPI and optionally the protocol.
Since the protocol is optional and no existing lookup incorporates spi + protocol , I used the closest available function — xfrm_state_lookup_byspi(). If you agree, I can add a new lookup function that matches on both SPI and protocol, as shown below.
Let me know your comment.
Yes, something like this should do it.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help