IPv6-in-IP encapsulation. */
| 344 | #ifdef INET6 |
| 345 | /* IPv6-in-IP encapsulation. */ |
| 346 | else if (prot == IPPROTO_IPV6 && |
| 347 | saidx->mode != IPSEC_MODE_TRANSPORT) { |
| 348 | if (m->m_pkthdr.len - skip < sizeof(struct ip6_hdr)) { |
| 349 | IPSEC_ISTAT(sproto, hdrops); |
| 350 | error = EINVAL; |
| 351 | goto bad; |
| 352 | } |
| 353 | /* enc0: strip IPv4 header, keep IPv6 header only */ |
| 354 | m_striphdr(m, 0, ip->ip_hl << 2); |
| 355 | } |
| 356 | #endif /* INET6 */ |
| 357 | else if (prot != IPPROTO_IPV6 && saidx->mode == IPSEC_MODE_ANY) { |
| 358 | /* |
nothing calls this directly
no test coverage detected