From de3407d02868da17b84be20a37bee2f9d4b5ad99 Mon Sep 17 00:00:00 2001 From: ume Date: Tue, 3 Feb 2004 18:20:55 +0000 Subject: pass pcb rather than so. it is expected that per socket policy works again. --- sys/netinet/raw_ip.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) (limited to 'sys/netinet/raw_ip.c') diff --git a/sys/netinet/raw_ip.c b/sys/netinet/raw_ip.c index bd65e81..eff86d3 100644 --- a/sys/netinet/raw_ip.c +++ b/sys/netinet/raw_ip.c @@ -147,7 +147,7 @@ raw_append(struct inpcb *last, struct ip *ip, struct mbuf *n) #ifdef IPSEC /* check AH/ESP integrity. */ - if (ipsec4_in_reject_so(n, last->inp_socket)) { + if (ipsec4_in_reject(n, last)) { policyfail = 1; ipsecstat.in_polvio++; /* do not inject data to pcb */ -- cgit v1.1