Installing an IPsec SA using old algorithm names (.compat) does not work if the algorithm is not already loaded. When not using the PF_KEY interface, algorithms are not preloaded in xfrm_probe_algs() and installing a IPsec SA fails.
Signed-off-by: Martin Willi <[EMAIL PROTECTED]> --- a/net/xfrm/xfrm_algo.c 2006-12-22 16:43:31.000000000 +0100 +++ b/net/xfrm/xfrm_algo.c 2006-12-22 16:58:19.000000000 +0100 @@ -399,7 +399,8 @@ static struct xfrm_algo_desc *xfrm_get_b if (!probe) break; - status = crypto_has_alg(name, type, mask | CRYPTO_ALG_ASYNC); + status = crypto_has_alg(list[i].name, type, + mask | CRYPTO_ALG_ASYNC); if (!status) break; - To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to [EMAIL PROTECTED] More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/