Looking only at that diff, the fix is a break.
It inverts the sense of the test so that the authenticator of the packet is used even if the tag is null.
It inverts the sense of the test so that the authenticator of the packet is used even if the tag is null.
In this code, "mtag" is the tag matching PACKET_TAG_IPSEC_IN_CRYPTO_DONE, which the lower-level drivers use to tell the IPSEC code that the NIC already did verification. If the tag isn't there, then you want to do the verification in software, which is what the fixed code does and the broken code didn't do.