diff options
author | Paul Moore <pmoore@redhat.com> | 2013-05-29 09:36:25 +0200 |
---|---|---|
committer | David S. Miller <davem@davemloft.net> | 2013-06-01 02:30:07 +0200 |
commit | e4c1721642bbd42d8142f4811cde0588c28db51d (patch) | |
tree | 8f7750f6065dcb5d2bd727174fb9f4e3cd8fccf3 /net/xfrm/xfrm_user.c | |
parent | udp6: Fix udp fragmentation for tunnel traffic. (diff) | |
download | linux-e4c1721642bbd42d8142f4811cde0588c28db51d.tar.xz linux-e4c1721642bbd42d8142f4811cde0588c28db51d.zip |
xfrm: force a garbage collection after deleting a policy
In some cases after deleting a policy from the SPD the policy would
remain in the dst/flow/route cache for an extended period of time
which caused problems for SELinux as its dynamic network access
controls key off of the number of XFRM policy and state entries.
This patch corrects this problem by forcing a XFRM garbage collection
whenever a policy is sucessfully removed.
Reported-by: Ondrej Moris <omoris@redhat.com>
Signed-off-by: Paul Moore <pmoore@redhat.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Diffstat (limited to 'net/xfrm/xfrm_user.c')
-rw-r--r-- | net/xfrm/xfrm_user.c | 2 |
1 files changed, 2 insertions, 0 deletions
diff --git a/net/xfrm/xfrm_user.c b/net/xfrm/xfrm_user.c index aa778748c565..3f565e495ac6 100644 --- a/net/xfrm/xfrm_user.c +++ b/net/xfrm/xfrm_user.c @@ -1681,6 +1681,8 @@ static int xfrm_get_policy(struct sk_buff *skb, struct nlmsghdr *nlh, out: xfrm_pol_put(xp); + if (delete && err == 0) + xfrm_garbage_collect(net); return err; } |