Add address family independed function ipsec_checkpolicy().
It takes security policy as argument and returns policy decision:
NULL and *error == 0 means "no IPsec processig required"; NULL and *error != -EINVAL means "packet should be discarded"; not NULL means "packet should be handled by IPsec".