between SA address pair and SPD filter. for example, the following attempt will return EINVAL: # setkey -c spdadd ::1 ::1 any -P out ipsec esp/tunnel/10.1.1.1-10.1.1.1/use; ^D
sanity check on address family matches between tunnel policy and SPD filter specification. For example, the following returns EINVAL: spdadd ::1 ::1 any -P out ipsec tunnel/10.1.1.1-10.1.1.1/use; XXX more tests - make sure it is not too strict
I've experienced it in the past).