[][kernel][mt7988][crypto][Change xfrm policy check for IPsec decryption path]

[Description]
Change xfrm policy check.
Strongswan will install in, out, and fwd three xfrm policies for
IPsec tunnel mode while installing in and out two xfrm policies for
transport mode. With HW offload, in and fwd policy check can't pass
since sec path length is 0. So if the matched policy is packet
offload and direction is in or fwd, pass the check directly.

[Release-log]
N/A


Change-Id: I90db73d7cca5371d9805d56281ef7cc07f3ddf46
Reviewed-on: https://gerrit.mediatek.inc/c/openwrt/feeds/mtk_openwrt_feeds/+/8276271
1 file changed