From 75467f60a3d14f08f86f2b353298d2826382ff23 Mon Sep 17 00:00:00 2001 From: Linus Torvalds Date: Fri, 25 Sep 2026 15:55:03 -0700 Subject: Merge tag 'ipe-pr-20260925' of git://git.kernel.org/pub/scm/linux/kernel/git/wufan/ipe Pull IPE fixes from Fan Wu: "Two fixes for use-after-free issues found by recent LLM-assisted code analysis. - move successful policy load auditing under the new policy directory's inode lock, preventing a concurrent policy deletion from freeing the policy while it is still being audited - protect the dm-verity root hash with RCU, preventing policy evaluation from racing with root hash replacement during preresume" * tag 'ipe-pr-20260925' of git://git.kernel.org/pub/scm/linux/kernel/git/wufan/ipe: ipe: protect the dm-verity root hash with RCU ipe: fix use-after-free when auditing a newly loaded policy --- include/net/ipcomp.h | 21 +++++++++++++++++++++ 1 file changed, 21 insertions(+) create mode 100644 include/net/ipcomp.h (limited to 'include/net/ipcomp.h') diff --git a/include/net/ipcomp.h b/include/net/ipcomp.h new file mode 100644 index 000000000..51401f01e --- /dev/null +++ b/include/net/ipcomp.h @@ -0,0 +1,21 @@ +/* SPDX-License-Identifier: GPL-2.0 */ +#ifndef _NET_IPCOMP_H +#define _NET_IPCOMP_H + +#include + +struct ip_comp_hdr; +struct netlink_ext_ack; +struct xfrm_state; + +int ipcomp_input(struct xfrm_state *x, struct sk_buff *skb); +int ipcomp_output(struct xfrm_state *x, struct sk_buff *skb); +void ipcomp_destroy(struct xfrm_state *x); +int ipcomp_init_state(struct xfrm_state *x, struct netlink_ext_ack *extack); + +static inline struct ip_comp_hdr *ip_comp_hdr(const struct sk_buff *skb) +{ + return (struct ip_comp_hdr *)skb_transport_header(skb); +} + +#endif -- cgit v1.3.1