#include <linux/in6.h>
 #endif
 
-#define DUMMY_MARK 0
-
 static inline int aead_len(struct xfrm_algo_aead *alg)
 {
        return sizeof(*alg) + ((alg->alg_key_len + 7) / 8);
        if (err)
                goto error;
 
+       xfrm_mark_get(attrs, &xp->mark);
+
        return xp;
  error:
        *errp = err;
                goto nlmsg_failure;
        if (copy_to_user_policy_type(xp->type, skb) < 0)
                goto nlmsg_failure;
+       if (xfrm_mark_put(skb, &xp->mark))
+               goto nla_put_failure;
 
        nlmsg_end(skb, nlh);
        return 0;
 
+nla_put_failure:
 nlmsg_failure:
        nlmsg_cancel(skb, nlh);
        return -EMSGSIZE;
        int err;
        struct km_event c;
        int delete;
+       struct xfrm_mark m;
+       u32 mark = xfrm_mark_get(attrs, &m);
 
        p = nlmsg_data(nlh);
        delete = nlh->nlmsg_type == XFRM_MSG_DELPOLICY;
                return err;
 
        if (p->index)
-               xp = xfrm_policy_byid(net, DUMMY_MARK, type, p->dir, p->index, delete, &err);
+               xp = xfrm_policy_byid(net, mark, type, p->dir, p->index, delete, &err);
        else {
                struct nlattr *rt = attrs[XFRMA_SEC_CTX];
                struct xfrm_sec_ctx *ctx;
                        if (err)
                                return err;
                }
-               xp = xfrm_policy_bysel_ctx(net, DUMMY_MARK, type, p->dir, &p->sel,
+               xp = xfrm_policy_bysel_ctx(net, mark, type, p->dir, &p->sel,
                                           ctx, delete, &err);
                security_xfrm_policy_free(ctx);
        }
        struct xfrm_userpolicy_info *p = &up->pol;
        u8 type = XFRM_POLICY_TYPE_MAIN;
        int err = -ENOENT;
+       struct xfrm_mark m;
+       u32 mark = xfrm_mark_get(attrs, &m);
 
        err = copy_from_user_policy_type(&type, attrs);
        if (err)
                return err;
 
        if (p->index)
-               xp = xfrm_policy_byid(net, DUMMY_MARK, type, p->dir, p->index, 0, &err);
+               xp = xfrm_policy_byid(net, mark, type, p->dir, p->index, 0, &err);
        else {
                struct nlattr *rt = attrs[XFRMA_SEC_CTX];
                struct xfrm_sec_ctx *ctx;
                        if (err)
                                return err;
                }
-               xp = xfrm_policy_bysel_ctx(net, DUMMY_MARK, type, p->dir,
+               xp = xfrm_policy_bysel_ctx(net, mark, type, p->dir,
                                           &p->sel, ctx, 0, &err);
                security_xfrm_policy_free(ctx);
        }
                goto nlmsg_failure;
        if (copy_to_user_policy_type(xp->type, skb) < 0)
                goto nlmsg_failure;
+       if (xfrm_mark_put(skb, &xp->mark))
+               goto nla_put_failure;
 
        return nlmsg_end(skb, nlh);
 
+nla_put_failure:
 nlmsg_failure:
        nlmsg_cancel(skb, nlh);
        return -EMSGSIZE;
        return NLMSG_ALIGN(sizeof(struct xfrm_user_polexpire))
               + nla_total_size(sizeof(struct xfrm_user_tmpl) * xp->xfrm_nr)
               + nla_total_size(xfrm_user_sec_ctx_size(xp->security))
+              + nla_total_size(sizeof(struct xfrm_mark))
               + userpolicy_type_attrsize();
 }
 
                goto nlmsg_failure;
        if (copy_to_user_policy_type(xp->type, skb) < 0)
                goto nlmsg_failure;
+       if (xfrm_mark_put(skb, &xp->mark))
+               goto nla_put_failure;
        upe->hard = !!hard;
 
        return nlmsg_end(skb, nlh);
 
+nla_put_failure:
 nlmsg_failure:
        nlmsg_cancel(skb, nlh);
        return -EMSGSIZE;
                headlen = sizeof(*id);
        }
        len += userpolicy_type_attrsize();
+       len += nla_total_size(sizeof(struct xfrm_mark));
        len += NLMSG_ALIGN(headlen);
 
        skb = nlmsg_new(len, GFP_ATOMIC);
        if (copy_to_user_policy_type(xp->type, skb) < 0)
                goto nlmsg_failure;
 
+       if (xfrm_mark_put(skb, &xp->mark))
+               goto nla_put_failure;
+
        nlmsg_end(skb, nlh);
 
        return nlmsg_multicast(net->xfrm.nlsk, skb, 0, XFRMNLGRP_POLICY, GFP_ATOMIC);
 
+nla_put_failure:
 nlmsg_failure:
        kfree_skb(skb);
        return -1;