[IPSEC]: Move all calls to xfrm_audit_state_icvfail to xfrm_input
Let's nip the code duplication in the bud :) Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au> Signed-off-by: David S. Miller <davem@davemloft.net>
此提交包含在:
@@ -179,10 +179,8 @@ static int ah_input(struct xfrm_state *x, struct sk_buff *skb)
|
||||
err = ah_mac_digest(ahp, skb, ah->auth_data);
|
||||
if (err)
|
||||
goto unlock;
|
||||
if (memcmp(ahp->work_icv, auth_data, ahp->icv_trunc_len)) {
|
||||
xfrm_audit_state_icvfail(x, skb, IPPROTO_AH);
|
||||
if (memcmp(ahp->work_icv, auth_data, ahp->icv_trunc_len))
|
||||
err = -EBADMSG;
|
||||
}
|
||||
}
|
||||
unlock:
|
||||
spin_unlock(&x->lock);
|
||||
|
新增問題並參考
封鎖使用者