From: David S. Miller Date: Fri, 22 Sep 2006 22:17:35 +0000 (-0700) Subject: [IPSEC] esp: Defer output IV initialization to first use. X-Git-Tag: v2.6.19-rc1~1272^2~130 X-Git-Url: http://git.openpandora.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=e4bec827feda76d5e7417a2696a75424834d564f;p=pandora-kernel.git [IPSEC] esp: Defer output IV initialization to first use. First of all, if the xfrm_state only gets used for input packets this entropy is a complete waste. Secondly, it is often the case that a configuration loads many rules (perhaps even dynamically) and they don't all necessarily ever get used. This get_random_bytes() call was showing up in the profiles for xfrm_state inserts which is how I noticed this. Signed-off-by: David S. Miller --- Reading git-diff-tree failed