| Venkat Yekkirala | b6340fc | 2006-07-24 23:28:37 -0700 | [diff] [blame] | 1 | flowi structure: | 
|  | 2 |  | 
|  | 3 | The secid member in the flow structure is used in LSMs (e.g. SELinux) to indicate | 
|  | 4 | the label of the flow. This label of the flow is currently used in selecting | 
|  | 5 | matching labeled xfrm(s). | 
|  | 6 |  | 
|  | 7 | If this is an outbound flow, the label is derived from the socket, if any, or | 
|  | 8 | the incoming packet this flow is being generated as a response to (e.g. tcp | 
|  | 9 | resets, timewait ack, etc.). It is also conceivable that the label could be | 
|  | 10 | derived from other sources such as process context, device, etc., in special | 
|  | 11 | cases, as may be appropriate. | 
|  | 12 |  | 
|  | 13 | If this is an inbound flow, the label is derived from the IPSec security | 
|  | 14 | associations, if any, used by the packet. |