mirror of
https://github.com/strongswan/strongswan.git
synced 2025-10-10 00:00:19 -04:00
child-sa: Remove policies before states to avoid acquire events for untrapped policies
This commit is contained in:
parent
c5f4e7c69e
commit
46188b0eb0
@ -1114,22 +1114,6 @@ METHOD(child_sa_t, destroy, void,
|
|||||||
|
|
||||||
set_state(this, CHILD_DESTROYING);
|
set_state(this, CHILD_DESTROYING);
|
||||||
|
|
||||||
/* delete SAs in the kernel, if they are set up */
|
|
||||||
if (this->my_spi)
|
|
||||||
{
|
|
||||||
hydra->kernel_interface->del_sa(hydra->kernel_interface,
|
|
||||||
this->other_addr, this->my_addr, this->my_spi,
|
|
||||||
proto_ike2ip(this->protocol), this->my_cpi,
|
|
||||||
this->mark_in);
|
|
||||||
}
|
|
||||||
if (this->other_spi)
|
|
||||||
{
|
|
||||||
hydra->kernel_interface->del_sa(hydra->kernel_interface,
|
|
||||||
this->my_addr, this->other_addr, this->other_spi,
|
|
||||||
proto_ike2ip(this->protocol), this->other_cpi,
|
|
||||||
this->mark_out);
|
|
||||||
}
|
|
||||||
|
|
||||||
if (this->config->install_policy(this->config))
|
if (this->config->install_policy(this->config))
|
||||||
{
|
{
|
||||||
/* delete all policies in the kernel */
|
/* delete all policies in the kernel */
|
||||||
@ -1146,6 +1130,22 @@ METHOD(child_sa_t, destroy, void,
|
|||||||
enumerator->destroy(enumerator);
|
enumerator->destroy(enumerator);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/* delete SAs in the kernel, if they are set up */
|
||||||
|
if (this->my_spi)
|
||||||
|
{
|
||||||
|
hydra->kernel_interface->del_sa(hydra->kernel_interface,
|
||||||
|
this->other_addr, this->my_addr, this->my_spi,
|
||||||
|
proto_ike2ip(this->protocol), this->my_cpi,
|
||||||
|
this->mark_in);
|
||||||
|
}
|
||||||
|
if (this->other_spi)
|
||||||
|
{
|
||||||
|
hydra->kernel_interface->del_sa(hydra->kernel_interface,
|
||||||
|
this->my_addr, this->other_addr, this->other_spi,
|
||||||
|
proto_ike2ip(this->protocol), this->other_cpi,
|
||||||
|
this->mark_out);
|
||||||
|
}
|
||||||
|
|
||||||
if (this->reqid_allocated)
|
if (this->reqid_allocated)
|
||||||
{
|
{
|
||||||
if (hydra->kernel_interface->release_reqid(hydra->kernel_interface,
|
if (hydra->kernel_interface->release_reqid(hydra->kernel_interface,
|
||||||
|
Loading…
x
Reference in New Issue
Block a user