On Fri, 4 Jan 2008, Paul Moore wrote: > I believe that if we simplify the problem to just IPsec causing multiple > hits on the postroute hook we have a simple solution. The fix is to > only apply the new egress access checks when skb->dst->xfrm == NULL. Sounds good. -- James Morris <jmorris@xxxxxxxxx> -- This message was distributed to subscribers of the selinux mailing list. If you no longer wish to subscribe, send mail to majordomo@xxxxxxxxxxxxx with the words "unsubscribe selinux" without quotes as the message.