Commit | Line | Data |
---|---|---|
b6340fcd VY |
1 | flowi structure: |
2 | ||
3 | The secid member in the flow structure is used in LSMs (e.g. SELinux) to indicate | |
4 | the label of the flow. This label of the flow is currently used in selecting | |
5 | matching labeled xfrm(s). | |
6 | ||
7 | If this is an outbound flow, the label is derived from the socket, if any, or | |
8 | the incoming packet this flow is being generated as a response to (e.g. tcp | |
9 | resets, timewait ack, etc.). It is also conceivable that the label could be | |
10 | derived from other sources such as process context, device, etc., in special | |
11 | cases, as may be appropriate. | |
12 | ||
13 | If this is an inbound flow, the label is derived from the IPSec security | |
14 | associations, if any, used by the packet. |