diff options
author | Neale Ranns <nranns@cisco.com> | 2020-04-30 13:30:57 +0000 |
---|---|---|
committer | Dave Wallace <dwallacelf@gmail.com> | 2020-05-07 01:00:15 +0000 |
commit | 08f8d3dfeaddb16980c77281586caaf476723dfb (patch) | |
tree | 12b288bad1f191644c0d787c56abb829bdf70d7d | |
parent | 9b5d0b7108451d7c81bad113503d00f46b3bb1ea (diff) |
ipsec: Add/Del SA not MP safe
Type: fix
some crytto engines store key data indexed by SA index. Creating new SAs
means this store reallocs with packets inflight; bad stuff ensues.
Signed-off-by: Neale Ranns <nranns@cisco.com>
Change-Id: Ia23c3a59e2d05fb006bdbd9922d01ee192e22853
-rw-r--r-- | src/vnet/ipsec/ipsec_api.c | 7 |
1 files changed, 0 insertions, 7 deletions
diff --git a/src/vnet/ipsec/ipsec_api.c b/src/vnet/ipsec/ipsec_api.c index 4252acd2688..b86de045fc9 100644 --- a/src/vnet/ipsec/ipsec_api.c +++ b/src/vnet/ipsec/ipsec_api.c @@ -991,13 +991,6 @@ ipsec_api_hookup (vlib_main_t * vm) #undef _ /* - * Adding and deleting SAs is MP safe since when they are added/delete - * no traffic is using them - */ - am->is_mp_safe[VL_API_IPSEC_SAD_ENTRY_ADD_DEL] = 1; - am->is_mp_safe[VL_API_IPSEC_SAD_ENTRY_ADD_DEL_REPLY] = 1; - - /* * Set up the (msg_name, crc, message-id) table */ setup_message_id_table (am); |