xfrm_user_policy() is called from ip_setsockopt with enabled BHs, so it needs to protect against them when grabbing xfrm_km_lock.