diff options
| author | Christian Hopps <chopps@labn.net> | 2024-11-14 02:07:02 -0500 |
|---|---|---|
| committer | Steffen Klassert <steffen.klassert@secunet.com> | 2024-12-05 10:01:28 +0100 |
| commit | d1716d5a44c37e5743bf6ea4e5cdbdab37727f27 (patch) | |
| tree | f0acee1586e60852300c49b1eb16577a89ea01d9 /net/netfilter/nft_xfrm.c | |
| parent | xfrm: add mode_cbs module functionality (diff) | |
| download | linux-d1716d5a44c37e5743bf6ea4e5cdbdab37727f27.tar.gz linux-d1716d5a44c37e5743bf6ea4e5cdbdab37727f27.zip | |
xfrm: add generic iptfs defines and functionality
Define `XFRM_MODE_IPTFS` and `IPSEC_MODE_IPTFS` constants, and add these to
switch case and conditionals adjacent with the existing TUNNEL modes.
Signed-off-by: Christian Hopps <chopps@labn.net>
Tested-by: Antony Antony <antony.antony@secunet.com>
Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
Diffstat (limited to 'net/netfilter/nft_xfrm.c')
| -rw-r--r-- | net/netfilter/nft_xfrm.c | 3 |
1 files changed, 2 insertions, 1 deletions
diff --git a/net/netfilter/nft_xfrm.c b/net/netfilter/nft_xfrm.c index 8a07b46cc8fb..3210cfc966ab 100644 --- a/net/netfilter/nft_xfrm.c +++ b/net/netfilter/nft_xfrm.c @@ -112,7 +112,8 @@ static bool xfrm_state_addr_ok(enum nft_xfrm_keys k, u8 family, u8 mode) return true; } - return mode == XFRM_MODE_BEET || mode == XFRM_MODE_TUNNEL; + return mode == XFRM_MODE_BEET || mode == XFRM_MODE_TUNNEL || + mode == XFRM_MODE_IPTFS; } static void nft_xfrm_state_get_key(const struct nft_xfrm *priv, |
