New commits:
commit 6fa0c0eaf5a0802d4c121b3cd48f632ca65b98e3
Author: Andrew Cagney <>
Date:   Fri Feb 9 12:46:09 2018 -0500

    ikev2: pass struct ike_sa to ikev2_decrypt_msg()
    - switch to ike->sa.st_original_role when selecting crypt keys
      (don't trust MD's .original_role)
    - find/fix use of child SA's .st_oakley.ta_encrypt when testing
      for AEAD
    - when no keys, PEXPECT_LOG() and return STF_FATAL
      (rather than STF_FAIL), to get this far in things are pretty
      messed up.

