xfrm: Restrict extended sequence numbers to esp
authorSteffen Klassert <steffen.klassert@secunet.com>
Mon, 28 Mar 2011 19:48:09 +0000 (19:48 +0000)
committerDavid S. Miller <davem@davemloft.net>
Tue, 29 Mar 2011 06:34:53 +0000 (23:34 -0700)
The IPsec extended sequence numbers are fully implemented just for
esp. So restrict the usage to esp until other protocols have
support too.

Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
Acked-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: David S. Miller <davem@davemloft.net>
net/xfrm/xfrm_user.c

index ccc4c0c..3d15d3e 100644 (file)
@@ -127,6 +127,9 @@ static inline int verify_replay(struct xfrm_usersa_info *p,
        if (!rt)
                return 0;
 
+       if (p->id.proto != IPPROTO_ESP)
+               return -EINVAL;
+
        if (p->replay_window != 0)
                return -EINVAL;