Extend the notdef #ifdef to cover the packet copy as there is no point in doing that if we're not doing the rest of the work.
Submitted by: thompsa MFC after: 1 week
This commit is contained in:
parent
3b72821f02
commit
79bc655b50
@ -321,6 +321,7 @@ ipsec4_common_input_cb(struct mbuf *m, struct secasvar *sav,
|
|||||||
}
|
}
|
||||||
prot = ip->ip_p;
|
prot = ip->ip_p;
|
||||||
|
|
||||||
|
#ifdef notyet
|
||||||
/* IP-in-IP encapsulation */
|
/* IP-in-IP encapsulation */
|
||||||
if (prot == IPPROTO_IPIP) {
|
if (prot == IPPROTO_IPIP) {
|
||||||
struct ip ipn;
|
struct ip ipn;
|
||||||
@ -336,7 +337,6 @@ ipsec4_common_input_cb(struct mbuf *m, struct secasvar *sav,
|
|||||||
m_copydata(m, ip->ip_hl << 2, sizeof(struct ip),
|
m_copydata(m, ip->ip_hl << 2, sizeof(struct ip),
|
||||||
(caddr_t) &ipn);
|
(caddr_t) &ipn);
|
||||||
|
|
||||||
#ifdef notyet
|
|
||||||
/* XXX PROXY address isn't recorded in SAH */
|
/* XXX PROXY address isn't recorded in SAH */
|
||||||
/*
|
/*
|
||||||
* Check that the inner source address is the same as
|
* Check that the inner source address is the same as
|
||||||
@ -364,7 +364,6 @@ ipsec4_common_input_cb(struct mbuf *m, struct secasvar *sav,
|
|||||||
error = EACCES;
|
error = EACCES;
|
||||||
goto bad;
|
goto bad;
|
||||||
}
|
}
|
||||||
#endif /*XXX*/
|
|
||||||
}
|
}
|
||||||
#if INET6
|
#if INET6
|
||||||
/* IPv6-in-IP encapsulation. */
|
/* IPv6-in-IP encapsulation. */
|
||||||
@ -382,7 +381,6 @@ ipsec4_common_input_cb(struct mbuf *m, struct secasvar *sav,
|
|||||||
m_copydata(m, ip->ip_hl << 2, sizeof(struct ip6_hdr),
|
m_copydata(m, ip->ip_hl << 2, sizeof(struct ip6_hdr),
|
||||||
(caddr_t) &ip6n);
|
(caddr_t) &ip6n);
|
||||||
|
|
||||||
#ifdef notyet
|
|
||||||
/*
|
/*
|
||||||
* Check that the inner source address is the same as
|
* Check that the inner source address is the same as
|
||||||
* the proxy address, if available.
|
* the proxy address, if available.
|
||||||
@ -408,9 +406,9 @@ ipsec4_common_input_cb(struct mbuf *m, struct secasvar *sav,
|
|||||||
error = EACCES;
|
error = EACCES;
|
||||||
goto bad;
|
goto bad;
|
||||||
}
|
}
|
||||||
#endif /*XXX*/
|
|
||||||
}
|
}
|
||||||
#endif /* INET6 */
|
#endif /* INET6 */
|
||||||
|
#endif /*XXX*/
|
||||||
|
|
||||||
/*
|
/*
|
||||||
* Record what we've done to the packet (under what SA it was
|
* Record what we've done to the packet (under what SA it was
|
||||||
@ -572,6 +570,7 @@ ipsec6_common_input_cb(struct mbuf *m, struct secasvar *sav, int skip, int proto
|
|||||||
/* Save protocol */
|
/* Save protocol */
|
||||||
m_copydata(m, protoff, 1, (unsigned char *) &prot);
|
m_copydata(m, protoff, 1, (unsigned char *) &prot);
|
||||||
|
|
||||||
|
#ifdef notyet
|
||||||
#ifdef INET
|
#ifdef INET
|
||||||
/* IP-in-IP encapsulation */
|
/* IP-in-IP encapsulation */
|
||||||
if (prot == IPPROTO_IPIP) {
|
if (prot == IPPROTO_IPIP) {
|
||||||
@ -587,7 +586,6 @@ ipsec6_common_input_cb(struct mbuf *m, struct secasvar *sav, int skip, int proto
|
|||||||
/* ipn will now contain the inner IPv4 header */
|
/* ipn will now contain the inner IPv4 header */
|
||||||
m_copydata(m, skip, sizeof(struct ip), (caddr_t) &ipn);
|
m_copydata(m, skip, sizeof(struct ip), (caddr_t) &ipn);
|
||||||
|
|
||||||
#ifdef notyet
|
|
||||||
/*
|
/*
|
||||||
* Check that the inner source address is the same as
|
* Check that the inner source address is the same as
|
||||||
* the proxy address, if available.
|
* the proxy address, if available.
|
||||||
@ -611,7 +609,6 @@ ipsec6_common_input_cb(struct mbuf *m, struct secasvar *sav, int skip, int proto
|
|||||||
error = EACCES;
|
error = EACCES;
|
||||||
goto bad;
|
goto bad;
|
||||||
}
|
}
|
||||||
#endif /*XXX*/
|
|
||||||
}
|
}
|
||||||
#endif /* INET */
|
#endif /* INET */
|
||||||
|
|
||||||
@ -630,7 +627,6 @@ ipsec6_common_input_cb(struct mbuf *m, struct secasvar *sav, int skip, int proto
|
|||||||
m_copydata(m, skip, sizeof(struct ip6_hdr),
|
m_copydata(m, skip, sizeof(struct ip6_hdr),
|
||||||
(caddr_t) &ip6n);
|
(caddr_t) &ip6n);
|
||||||
|
|
||||||
#ifdef notyet
|
|
||||||
/*
|
/*
|
||||||
* Check that the inner source address is the same as
|
* Check that the inner source address is the same as
|
||||||
* the proxy address, if available.
|
* the proxy address, if available.
|
||||||
@ -655,8 +651,8 @@ ipsec6_common_input_cb(struct mbuf *m, struct secasvar *sav, int skip, int proto
|
|||||||
error = EACCES;
|
error = EACCES;
|
||||||
goto bad;
|
goto bad;
|
||||||
}
|
}
|
||||||
#endif /*XXX*/
|
|
||||||
}
|
}
|
||||||
|
#endif /*XXX*/
|
||||||
|
|
||||||
/*
|
/*
|
||||||
* Record what we've done to the packet (under what SA it was
|
* Record what we've done to the packet (under what SA it was
|
||||||
|
Loading…
x
Reference in New Issue
Block a user