diff options
author | Tobias Brunner <tobias@strongswan.org> | 2016-04-06 14:40:28 +0200 |
---|---|---|
committer | Tobias Brunner <tobias@strongswan.org> | 2016-04-15 10:39:00 +0200 |
commit | 869f4e90b1b86e7d25b5624d2906d803327f2a7f (patch) | |
tree | f181222a1573b6cbea67a5699569423b8430f008 /src/libcharon/plugins/kernel_netlink/tests.c | |
parent | ea27163ee122f593374d04eebbc4a9debad59243 (diff) | |
download | strongswan-869f4e90b1b86e7d25b5624d2906d803327f2a7f.tar.bz2 strongswan-869f4e90b1b86e7d25b5624d2906d803327f2a7f.tar.xz |
kernel-netlink: Order policies with equal priorities by their automatic priority
This allows using manual priorities for traps, which have a lower
base priority than the resulting IPsec policies. This could otherwise
be problematic if, for example, swanctl --install/uninstall is used while
an SA is established combined with e.g. IPComp, where the trap policy does
not look the same as the IPsec policy (which is now otherwise often the case
as the reqids stay the same).
It also orders policies by selector size if manual priorities are configured
and narrowing occurs.
Diffstat (limited to 'src/libcharon/plugins/kernel_netlink/tests.c')
0 files changed, 0 insertions, 0 deletions