From b557416532f3db745cb9cceaaf343b4bc5b57003 Mon Sep 17 00:00:00 2001 From: Christophe Gouault Date: Tue, 8 Oct 2013 05:56:54 -0700 Subject: [PATCH] xfrm: enable to set non-wildcard mark 0 on SAs and SPs ip xfrm considers that the user-defined mark is "any" as soon as (mark.v & mark.m == 0), which prevents from specifying non-wildcard marks that include the value 0 (typically 0/0xffffffff). Yet, matching exactly mark 0 is useful for instance to separate vti policies from global policies. Always configure the user mark if mark.m != 0. Signed-off-by: Christophe Gouault --- ip/xfrm_policy.c | 2 +- ip/xfrm_state.c | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/ip/xfrm_policy.c b/ip/xfrm_policy.c index 36e33c982..a8d8b98ba 100644 --- a/ip/xfrm_policy.c +++ b/ip/xfrm_policy.c @@ -373,7 +373,7 @@ static int xfrm_policy_modify(int cmd, unsigned flags, int argc, char **argv) (void *)tmpls_buf, tmpls_len); } - if (mark.m & mark.v) { + if (mark.m) { int r = addattr_l(&req.n, sizeof(req.buf), XFRMA_MARK, (void *)&mark, sizeof(mark)); if (r < 0) { diff --git a/ip/xfrm_state.c b/ip/xfrm_state.c index f4ad4cb15..c4d2bf676 100644 --- a/ip/xfrm_state.c +++ b/ip/xfrm_state.c @@ -528,7 +528,7 @@ static int xfrm_state_modify(int cmd, unsigned flags, int argc, char **argv) exit(1); } - if (mark.m & mark.v) { + if (mark.m) { int r = addattr_l(&req.n, sizeof(req.buf), XFRMA_MARK, (void *)&mark, sizeof(mark)); if (r < 0) { -- 2.47.2