From 2b608e5a45f1984a73316754c01af51cb1f9fd29 Mon Sep 17 00:00:00 2001 From: Patrick McHardy Date: Wed, 20 Oct 2004 07:47:54 -0700 Subject: [PATCH] [XFRM]: Apply policy checks to packets with a secpath when the policy list is empty Signed-off-by: Patrick McHardy Signed-off-by: David S. Miller --- include/net/xfrm.h | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/include/net/xfrm.h b/include/net/xfrm.h index b5c9b1028583c..2c89b019388a8 100644 --- a/include/net/xfrm.h +++ b/include/net/xfrm.h @@ -601,7 +601,7 @@ static inline int xfrm_policy_check(struct sock *sk, int dir, struct sk_buff *sk if (sk && sk->sk_policy[XFRM_POLICY_IN]) return __xfrm_policy_check(sk, dir, skb, family); - return !xfrm_policy_list[dir] || + return (!xfrm_policy_list[dir] && !skb->sp) || (skb->dst->flags & DST_NOPOLICY) || __xfrm_policy_check(sk, dir, skb, family); } -- 2.53.0