From: Brian B. <bbu...@qu...> - 2005-09-08 15:04:42
|
This was a define that I had added a while back when policy priority support was added to the linux kernel and setkey. The policy priority support allows insertion at an arbitrary location in the policy list, rather than only at the end. HAVE_PFKEY_POLICY_PRIORITY gets set by configure if the sadb_x_policy_priority member of struct sadb_x_policy is present. I don't remember the exact linux kernel version in which this support was added, but I can go back and find it if you need it. Yes, I believe you are right that it is not supported on any of the *BSD stacks, unless such support has been added recently. Brian VANHULLEBUS Yvan wrote: >Hi all. > >Why and where this flag can be defined when compiling racoon ? > >Is it really used somewhere ? > > >I know that this is at least NOT used on FreeBSD (and I guess on any >KAME based stack), and some insertions takes really lots of time when >the SPD become heavy (more than 1000 entries), without #ifdef >HAVE_PFKEY_POLICY_PRIORITY. > > >Unless someone can explain me why this is needed, I'll set up some >code in #ifdef HAVE_PFKEY_POLICY_PRIORITY soon, to avoid lots of >useless CPU usage ! > > > >Yvan. > > >------------------------------------------------------- >SF.Net email is Sponsored by the Better Software Conference & EXPO >September 19-22, 2005 * San Francisco, CA * Development Lifecycle Practices >Agile & Plan-Driven Development * Managing Projects & Teams * Testing & QA >Security * Process Improvement & Measurement * http://www.sqe.com/bsce5sf >_______________________________________________ >Ipsec-tools-devel mailing list >Ips...@li... >https://lists.sourceforge.net/lists/listinfo/ipsec-tools-devel > > |