Moved all kernel plugins to libhydra.
This commit is contained in:
@@ -0,0 +1,16 @@
|
||||
|
||||
INCLUDES = -I$(top_srcdir)/src/libstrongswan -I$(top_srcdir)/src/libhydra
|
||||
|
||||
AM_CFLAGS = -rdynamic
|
||||
|
||||
if MONOLITHIC
|
||||
noinst_LTLIBRARIES = libstrongswan-kernel-klips.la
|
||||
else
|
||||
plugin_LTLIBRARIES = libstrongswan-kernel-klips.la
|
||||
endif
|
||||
|
||||
libstrongswan_kernel_klips_la_SOURCES = \
|
||||
kernel_klips_plugin.h kernel_klips_plugin.c \
|
||||
kernel_klips_ipsec.h kernel_klips_ipsec.c pfkeyv2.h
|
||||
|
||||
libstrongswan_kernel_klips_la_LDFLAGS = -module -avoid-version
|
||||
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,46 @@
|
||||
/*
|
||||
* Copyright (C) 2008 Tobias Brunner
|
||||
* Hochschule fuer Technik Rapperswil
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify it
|
||||
* under the terms of the GNU General Public License as published by the
|
||||
* Free Software Foundation; either version 2 of the License, or (at your
|
||||
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
|
||||
*
|
||||
* This program is distributed in the hope that it will be useful, but
|
||||
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
|
||||
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
||||
* for more details.
|
||||
*/
|
||||
|
||||
/**
|
||||
* @defgroup kernel_klips_ipsec_i kernel_klips_ipsec
|
||||
* @{ @ingroup kernel_klips
|
||||
*/
|
||||
|
||||
#ifndef KERNEL_KLIPS_IPSEC_H_
|
||||
#define KERNEL_KLIPS_IPSEC_H_
|
||||
|
||||
#include <kernel/kernel_ipsec.h>
|
||||
|
||||
typedef struct kernel_klips_ipsec_t kernel_klips_ipsec_t;
|
||||
|
||||
/**
|
||||
* Implementation of the kernel ipsec interface using PF_KEY.
|
||||
*/
|
||||
struct kernel_klips_ipsec_t {
|
||||
|
||||
/**
|
||||
* Implements kernel_ipsec_t interface
|
||||
*/
|
||||
kernel_ipsec_t interface;
|
||||
};
|
||||
|
||||
/**
|
||||
* Create a PF_KEY kernel ipsec interface instance.
|
||||
*
|
||||
* @return kernel_klips_ipsec_t instance
|
||||
*/
|
||||
kernel_klips_ipsec_t *kernel_klips_ipsec_create();
|
||||
|
||||
#endif /** KERNEL_KLIPS_IPSEC_H_ @}*/
|
||||
@@ -0,0 +1,58 @@
|
||||
/*
|
||||
* Copyright (C) 2008 Tobias Brunner
|
||||
* Hochschule fuer Technik Rapperswil
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify it
|
||||
* under the terms of the GNU General Public License as published by the
|
||||
* Free Software Foundation; either version 2 of the License, or (at your
|
||||
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
|
||||
*
|
||||
* This program is distributed in the hope that it will be useful, but
|
||||
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
|
||||
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
||||
* for more details.
|
||||
*/
|
||||
|
||||
|
||||
#include "kernel_klips_plugin.h"
|
||||
|
||||
#include "kernel_klips_ipsec.h"
|
||||
|
||||
#include <hydra.h>
|
||||
|
||||
typedef struct private_kernel_klips_plugin_t private_kernel_klips_plugin_t;
|
||||
|
||||
/**
|
||||
* private data of kernel PF_KEY plugin
|
||||
*/
|
||||
struct private_kernel_klips_plugin_t {
|
||||
/**
|
||||
* implements plugin interface
|
||||
*/
|
||||
kernel_klips_plugin_t public;
|
||||
};
|
||||
|
||||
/**
|
||||
* Implementation of plugin_t.destroy
|
||||
*/
|
||||
static void destroy(private_kernel_klips_plugin_t *this)
|
||||
{
|
||||
hydra->kernel_interface->remove_ipsec_interface(hydra->kernel_interface,
|
||||
(kernel_ipsec_constructor_t)kernel_klips_ipsec_create);
|
||||
free(this);
|
||||
}
|
||||
|
||||
/*
|
||||
* see header file
|
||||
*/
|
||||
plugin_t *kernel_klips_plugin_create()
|
||||
{
|
||||
private_kernel_klips_plugin_t *this = malloc_thing(private_kernel_klips_plugin_t);
|
||||
|
||||
this->public.plugin.destroy = (void(*)(plugin_t*))destroy;
|
||||
|
||||
hydra->kernel_interface->add_ipsec_interface(hydra->kernel_interface,
|
||||
(kernel_ipsec_constructor_t)kernel_klips_ipsec_create);
|
||||
|
||||
return &this->public.plugin;
|
||||
}
|
||||
@@ -0,0 +1,42 @@
|
||||
/*
|
||||
* Copyright (C) 2008 Tobias Brunner
|
||||
* Hochschule fuer Technik Rapperswil
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify it
|
||||
* under the terms of the GNU General Public License as published by the
|
||||
* Free Software Foundation; either version 2 of the License, or (at your
|
||||
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
|
||||
*
|
||||
* This program is distributed in the hope that it will be useful, but
|
||||
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
|
||||
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
||||
* for more details.
|
||||
*/
|
||||
|
||||
/**
|
||||
* @defgroup kernel_klips kernel_klips
|
||||
* @ingroup hplugins
|
||||
*
|
||||
* @defgroup kernel_klips_plugin kernel_klips_plugin
|
||||
* @{ @ingroup kernel_klips
|
||||
*/
|
||||
|
||||
#ifndef KERNEL_KLIPS_PLUGIN_H_
|
||||
#define KERNEL_KLIPS_PLUGIN_H_
|
||||
|
||||
#include <plugins/plugin.h>
|
||||
|
||||
typedef struct kernel_klips_plugin_t kernel_klips_plugin_t;
|
||||
|
||||
/**
|
||||
* PF_KEY kernel interface plugin
|
||||
*/
|
||||
struct kernel_klips_plugin_t {
|
||||
|
||||
/**
|
||||
* implements plugin interface
|
||||
*/
|
||||
plugin_t plugin;
|
||||
};
|
||||
|
||||
#endif /** KERNEL_KLIPS_PLUGIN_H_ @}*/
|
||||
@@ -0,0 +1,322 @@
|
||||
/*
|
||||
RFC 2367 PF_KEY Key Management API July 1998
|
||||
|
||||
|
||||
Appendix D: Sample Header File
|
||||
|
||||
This file defines structures and symbols for the PF_KEY Version 2
|
||||
key management interface. It was written at the U.S. Naval Research
|
||||
Laboratory. This file is in the public domain. The authors ask that
|
||||
you leave this credit intact on any copies of this file.
|
||||
*/
|
||||
#ifndef __PFKEY_V2_H
|
||||
#define __PFKEY_V2_H 1
|
||||
|
||||
#define PF_KEY_V2 2
|
||||
#define PFKEYV2_REVISION 199806L
|
||||
|
||||
#define SADB_RESERVED 0
|
||||
#define SADB_GETSPI 1
|
||||
#define SADB_UPDATE 2
|
||||
#define SADB_ADD 3
|
||||
#define SADB_DELETE 4
|
||||
#define SADB_GET 5
|
||||
#define SADB_ACQUIRE 6
|
||||
#define SADB_REGISTER 7
|
||||
#define SADB_EXPIRE 8
|
||||
#define SADB_FLUSH 9
|
||||
#define SADB_DUMP 10
|
||||
#define SADB_X_PROMISC 11
|
||||
#define SADB_X_PCHANGE 12
|
||||
#define SADB_X_GRPSA 13
|
||||
#define SADB_X_ADDFLOW 14
|
||||
#define SADB_X_DELFLOW 15
|
||||
#define SADB_X_DEBUG 16
|
||||
#define SADB_X_NAT_T_NEW_MAPPING 17
|
||||
#define SADB_MAX 17
|
||||
|
||||
struct sadb_msg {
|
||||
uint8_t sadb_msg_version;
|
||||
uint8_t sadb_msg_type;
|
||||
uint8_t sadb_msg_errno;
|
||||
uint8_t sadb_msg_satype;
|
||||
uint16_t sadb_msg_len;
|
||||
uint16_t sadb_msg_reserved;
|
||||
uint32_t sadb_msg_seq;
|
||||
uint32_t sadb_msg_pid;
|
||||
};
|
||||
|
||||
struct sadb_ext {
|
||||
uint16_t sadb_ext_len;
|
||||
uint16_t sadb_ext_type;
|
||||
};
|
||||
|
||||
struct sadb_sa {
|
||||
uint16_t sadb_sa_len;
|
||||
uint16_t sadb_sa_exttype;
|
||||
uint32_t sadb_sa_spi;
|
||||
uint8_t sadb_sa_replay;
|
||||
uint8_t sadb_sa_state;
|
||||
uint8_t sadb_sa_auth;
|
||||
uint8_t sadb_sa_encrypt;
|
||||
uint32_t sadb_sa_flags;
|
||||
};
|
||||
|
||||
struct sadb_lifetime {
|
||||
uint16_t sadb_lifetime_len;
|
||||
uint16_t sadb_lifetime_exttype;
|
||||
uint32_t sadb_lifetime_allocations;
|
||||
uint64_t sadb_lifetime_bytes;
|
||||
uint64_t sadb_lifetime_addtime;
|
||||
uint64_t sadb_lifetime_usetime;
|
||||
uint32_t sadb_x_lifetime_packets;
|
||||
uint32_t sadb_x_lifetime_reserved;
|
||||
};
|
||||
|
||||
struct sadb_address {
|
||||
uint16_t sadb_address_len;
|
||||
uint16_t sadb_address_exttype;
|
||||
uint8_t sadb_address_proto;
|
||||
uint8_t sadb_address_prefixlen;
|
||||
uint16_t sadb_address_reserved;
|
||||
};
|
||||
|
||||
struct sadb_key {
|
||||
uint16_t sadb_key_len;
|
||||
uint16_t sadb_key_exttype;
|
||||
uint16_t sadb_key_bits;
|
||||
uint16_t sadb_key_reserved;
|
||||
};
|
||||
|
||||
struct sadb_ident {
|
||||
uint16_t sadb_ident_len;
|
||||
uint16_t sadb_ident_exttype;
|
||||
uint16_t sadb_ident_type;
|
||||
uint16_t sadb_ident_reserved;
|
||||
uint64_t sadb_ident_id;
|
||||
};
|
||||
|
||||
struct sadb_sens {
|
||||
uint16_t sadb_sens_len;
|
||||
uint16_t sadb_sens_exttype;
|
||||
uint32_t sadb_sens_dpd;
|
||||
uint8_t sadb_sens_sens_level;
|
||||
uint8_t sadb_sens_sens_len;
|
||||
uint8_t sadb_sens_integ_level;
|
||||
uint8_t sadb_sens_integ_len;
|
||||
uint32_t sadb_sens_reserved;
|
||||
};
|
||||
|
||||
struct sadb_prop {
|
||||
uint16_t sadb_prop_len;
|
||||
uint16_t sadb_prop_exttype;
|
||||
uint8_t sadb_prop_replay;
|
||||
uint8_t sadb_prop_reserved[3];
|
||||
};
|
||||
|
||||
struct sadb_comb {
|
||||
uint8_t sadb_comb_auth;
|
||||
uint8_t sadb_comb_encrypt;
|
||||
uint16_t sadb_comb_flags;
|
||||
uint16_t sadb_comb_auth_minbits;
|
||||
uint16_t sadb_comb_auth_maxbits;
|
||||
uint16_t sadb_comb_encrypt_minbits;
|
||||
uint16_t sadb_comb_encrypt_maxbits;
|
||||
uint32_t sadb_comb_reserved;
|
||||
uint32_t sadb_comb_soft_allocations;
|
||||
uint32_t sadb_comb_hard_allocations;
|
||||
uint64_t sadb_comb_soft_bytes;
|
||||
uint64_t sadb_comb_hard_bytes;
|
||||
uint64_t sadb_comb_soft_addtime;
|
||||
uint64_t sadb_comb_hard_addtime;
|
||||
uint64_t sadb_comb_soft_usetime;
|
||||
uint64_t sadb_comb_hard_usetime;
|
||||
uint32_t sadb_x_comb_soft_packets;
|
||||
uint32_t sadb_x_comb_hard_packets;
|
||||
};
|
||||
|
||||
struct sadb_supported {
|
||||
uint16_t sadb_supported_len;
|
||||
uint16_t sadb_supported_exttype;
|
||||
uint32_t sadb_supported_reserved;
|
||||
};
|
||||
|
||||
struct sadb_alg {
|
||||
uint8_t sadb_alg_id;
|
||||
uint8_t sadb_alg_ivlen;
|
||||
uint16_t sadb_alg_minbits;
|
||||
uint16_t sadb_alg_maxbits;
|
||||
uint16_t sadb_alg_reserved;
|
||||
};
|
||||
|
||||
struct sadb_spirange {
|
||||
uint16_t sadb_spirange_len;
|
||||
uint16_t sadb_spirange_exttype;
|
||||
uint32_t sadb_spirange_min;
|
||||
uint32_t sadb_spirange_max;
|
||||
uint32_t sadb_spirange_reserved;
|
||||
};
|
||||
|
||||
struct sadb_x_kmprivate {
|
||||
uint16_t sadb_x_kmprivate_len;
|
||||
uint16_t sadb_x_kmprivate_exttype;
|
||||
uint32_t sadb_x_kmprivate_reserved;
|
||||
};
|
||||
|
||||
struct sadb_x_satype {
|
||||
uint16_t sadb_x_satype_len;
|
||||
uint16_t sadb_x_satype_exttype;
|
||||
uint8_t sadb_x_satype_satype;
|
||||
uint8_t sadb_x_satype_reserved[3];
|
||||
};
|
||||
|
||||
struct sadb_x_debug {
|
||||
uint16_t sadb_x_debug_len;
|
||||
uint16_t sadb_x_debug_exttype;
|
||||
uint32_t sadb_x_debug_tunnel;
|
||||
uint32_t sadb_x_debug_netlink;
|
||||
uint32_t sadb_x_debug_xform;
|
||||
uint32_t sadb_x_debug_eroute;
|
||||
uint32_t sadb_x_debug_spi;
|
||||
uint32_t sadb_x_debug_radij;
|
||||
uint32_t sadb_x_debug_esp;
|
||||
uint32_t sadb_x_debug_ah;
|
||||
uint32_t sadb_x_debug_rcv;
|
||||
uint32_t sadb_x_debug_pfkey;
|
||||
uint32_t sadb_x_debug_ipcomp;
|
||||
uint32_t sadb_x_debug_verbose;
|
||||
uint8_t sadb_x_debug_reserved[4];
|
||||
};
|
||||
|
||||
struct sadb_x_nat_t_type {
|
||||
uint16_t sadb_x_nat_t_type_len;
|
||||
uint16_t sadb_x_nat_t_type_exttype;
|
||||
uint8_t sadb_x_nat_t_type_type;
|
||||
uint8_t sadb_x_nat_t_type_reserved[3];
|
||||
};
|
||||
struct sadb_x_nat_t_port {
|
||||
uint16_t sadb_x_nat_t_port_len;
|
||||
uint16_t sadb_x_nat_t_port_exttype;
|
||||
uint16_t sadb_x_nat_t_port_port;
|
||||
uint16_t sadb_x_nat_t_port_reserved;
|
||||
};
|
||||
|
||||
/*
|
||||
* A protocol structure for passing through the transport level
|
||||
* protocol. It contains more fields than are actually used/needed
|
||||
* but it is this way to be compatible with the structure used in
|
||||
* OpenBSD (http://www.openbsd.org/cgi-bin/cvsweb/src/sys/net/pfkeyv2.h)
|
||||
*/
|
||||
struct sadb_protocol {
|
||||
uint16_t sadb_protocol_len;
|
||||
uint16_t sadb_protocol_exttype;
|
||||
uint8_t sadb_protocol_proto;
|
||||
uint8_t sadb_protocol_direction;
|
||||
uint8_t sadb_protocol_flags;
|
||||
uint8_t sadb_protocol_reserved2;
|
||||
};
|
||||
|
||||
#define SADB_EXT_RESERVED 0
|
||||
#define SADB_EXT_SA 1
|
||||
#define SADB_EXT_LIFETIME_CURRENT 2
|
||||
#define SADB_EXT_LIFETIME_HARD 3
|
||||
#define SADB_EXT_LIFETIME_SOFT 4
|
||||
#define SADB_EXT_ADDRESS_SRC 5
|
||||
#define SADB_EXT_ADDRESS_DST 6
|
||||
#define SADB_EXT_ADDRESS_PROXY 7
|
||||
#define SADB_EXT_KEY_AUTH 8
|
||||
#define SADB_EXT_KEY_ENCRYPT 9
|
||||
#define SADB_EXT_IDENTITY_SRC 10
|
||||
#define SADB_EXT_IDENTITY_DST 11
|
||||
#define SADB_EXT_SENSITIVITY 12
|
||||
#define SADB_EXT_PROPOSAL 13
|
||||
#define SADB_EXT_SUPPORTED_AUTH 14
|
||||
#define SADB_EXT_SUPPORTED_ENCRYPT 15
|
||||
#define SADB_EXT_SPIRANGE 16
|
||||
#define SADB_X_EXT_KMPRIVATE 17
|
||||
#define SADB_X_EXT_SATYPE2 18
|
||||
#define SADB_X_EXT_SA2 19
|
||||
#define SADB_X_EXT_ADDRESS_DST2 20
|
||||
#define SADB_X_EXT_ADDRESS_SRC_FLOW 21
|
||||
#define SADB_X_EXT_ADDRESS_DST_FLOW 22
|
||||
#define SADB_X_EXT_ADDRESS_SRC_MASK 23
|
||||
#define SADB_X_EXT_ADDRESS_DST_MASK 24
|
||||
#define SADB_X_EXT_DEBUG 25
|
||||
#define SADB_X_EXT_PROTOCOL 26
|
||||
#define SADB_X_EXT_NAT_T_TYPE 27
|
||||
#define SADB_X_EXT_NAT_T_SPORT 28
|
||||
#define SADB_X_EXT_NAT_T_DPORT 29
|
||||
#define SADB_X_EXT_NAT_T_OA 30
|
||||
#define SADB_EXT_MAX 30
|
||||
|
||||
/* SADB_X_DELFLOW required over and above SADB_X_SAFLAGS_CLEARFLOW */
|
||||
#define SADB_X_EXT_ADDRESS_DELFLOW \
|
||||
( (1<<SADB_X_EXT_ADDRESS_SRC_FLOW) \
|
||||
| (1<<SADB_X_EXT_ADDRESS_DST_FLOW) \
|
||||
| (1<<SADB_X_EXT_ADDRESS_SRC_MASK) \
|
||||
| (1<<SADB_X_EXT_ADDRESS_DST_MASK))
|
||||
|
||||
#define SADB_SATYPE_UNSPEC 0
|
||||
#define SADB_SATYPE_AH 2
|
||||
#define SADB_SATYPE_ESP 3
|
||||
#define SADB_SATYPE_RSVP 5
|
||||
#define SADB_SATYPE_OSPFV2 6
|
||||
#define SADB_SATYPE_RIPV2 7
|
||||
#define SADB_SATYPE_MIP 8
|
||||
#define SADB_X_SATYPE_IPIP 9
|
||||
#define SADB_X_SATYPE_COMP 10
|
||||
#define SADB_X_SATYPE_INT 11
|
||||
#define SADB_SATYPE_MAX 11
|
||||
|
||||
#define SADB_SASTATE_LARVAL 0
|
||||
#define SADB_SASTATE_MATURE 1
|
||||
#define SADB_SASTATE_DYING 2
|
||||
#define SADB_SASTATE_DEAD 3
|
||||
#define SADB_SASTATE_MAX 3
|
||||
|
||||
#define SADB_SAFLAGS_PFS 1
|
||||
#define SADB_X_SAFLAGS_REPLACEFLOW 2
|
||||
#define SADB_X_SAFLAGS_CLEARFLOW 4
|
||||
#define SADB_X_SAFLAGS_INFLOW 8
|
||||
|
||||
#define SADB_AALG_NONE 0
|
||||
#define SADB_AALG_MD5HMAC 2
|
||||
#define SADB_AALG_SHA1HMAC 3
|
||||
#define SADB_AALG_SHA256_HMAC 5
|
||||
#define SADB_AALG_SHA384_HMAC 6
|
||||
#define SADB_AALG_SHA512_HMAC 7
|
||||
#define SADB_AALG_RIPEMD160HMAC 8
|
||||
#define SADB_AALG_MAX 15
|
||||
|
||||
#define SADB_EALG_NONE 0
|
||||
#define SADB_EALG_DESCBC 2
|
||||
#define SADB_EALG_3DESCBC 3
|
||||
#define SADB_EALG_BFCBC 7
|
||||
#define SADB_EALG_NULL 11
|
||||
#define SADB_EALG_AESCBC 12
|
||||
#define SADB_EALG_MAX 255
|
||||
|
||||
#define SADB_X_CALG_NONE 0
|
||||
#define SADB_X_CALG_OUI 1
|
||||
#define SADB_X_CALG_DEFLATE 2
|
||||
#define SADB_X_CALG_LZS 3
|
||||
#define SADB_X_CALG_V42BIS 4
|
||||
#define SADB_X_CALG_MAX 4
|
||||
|
||||
#define SADB_X_TALG_NONE 0
|
||||
#define SADB_X_TALG_IPv4_in_IPv4 1
|
||||
#define SADB_X_TALG_IPv6_in_IPv4 2
|
||||
#define SADB_X_TALG_IPv4_in_IPv6 3
|
||||
#define SADB_X_TALG_IPv6_in_IPv6 4
|
||||
#define SADB_X_TALG_MAX 4
|
||||
|
||||
|
||||
#define SADB_IDENTTYPE_RESERVED 0
|
||||
#define SADB_IDENTTYPE_PREFIX 1
|
||||
#define SADB_IDENTTYPE_FQDN 2
|
||||
#define SADB_IDENTTYPE_USERFQDN 3
|
||||
#define SADB_X_IDENTTYPE_CONNECTION 4
|
||||
#define SADB_IDENTTYPE_MAX 4
|
||||
|
||||
#define SADB_KEY_FLAGS_MAX 0
|
||||
#endif /* __PFKEY_V2_H */
|
||||
@@ -0,0 +1,21 @@
|
||||
|
||||
INCLUDES = -I${linux_headers} -I$(top_srcdir)/src/libstrongswan \
|
||||
-I$(top_srcdir)/src/libhydra
|
||||
|
||||
AM_CFLAGS = -rdynamic \
|
||||
-DROUTING_TABLE=${routing_table} \
|
||||
-DROUTING_TABLE_PRIO=${routing_table_prio}
|
||||
|
||||
if MONOLITHIC
|
||||
noinst_LTLIBRARIES = libstrongswan-kernel-netlink.la
|
||||
else
|
||||
plugin_LTLIBRARIES = libstrongswan-kernel-netlink.la
|
||||
endif
|
||||
|
||||
libstrongswan_kernel_netlink_la_SOURCES = \
|
||||
kernel_netlink_plugin.h kernel_netlink_plugin.c \
|
||||
kernel_netlink_ipsec.h kernel_netlink_ipsec.c \
|
||||
kernel_netlink_net.h kernel_netlink_net.c \
|
||||
kernel_netlink_shared.h kernel_netlink_shared.c
|
||||
|
||||
libstrongswan_kernel_netlink_la_LDFLAGS = -module -avoid-version
|
||||
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,46 @@
|
||||
/*
|
||||
* Copyright (C) 2008 Tobias Brunner
|
||||
* Hochschule fuer Technik Rapperswil
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify it
|
||||
* under the terms of the GNU General Public License as published by the
|
||||
* Free Software Foundation; either version 2 of the License, or (at your
|
||||
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
|
||||
*
|
||||
* This program is distributed in the hope that it will be useful, but
|
||||
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
|
||||
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
||||
* for more details.
|
||||
*/
|
||||
|
||||
/**
|
||||
* @defgroup kernel_netlink_ipsec_i kernel_netlink_ipsec
|
||||
* @{ @ingroup kernel_netlink
|
||||
*/
|
||||
|
||||
#ifndef KERNEL_NETLINK_IPSEC_H_
|
||||
#define KERNEL_NETLINK_IPSEC_H_
|
||||
|
||||
#include <kernel/kernel_ipsec.h>
|
||||
|
||||
typedef struct kernel_netlink_ipsec_t kernel_netlink_ipsec_t;
|
||||
|
||||
/**
|
||||
* Implementation of the kernel ipsec interface using Netlink.
|
||||
*/
|
||||
struct kernel_netlink_ipsec_t {
|
||||
|
||||
/**
|
||||
* Implements kernel_ipsec_t interface
|
||||
*/
|
||||
kernel_ipsec_t interface;
|
||||
};
|
||||
|
||||
/**
|
||||
* Create a netlink kernel ipsec interface instance.
|
||||
*
|
||||
* @return kernel_netlink_ipsec_t instance
|
||||
*/
|
||||
kernel_netlink_ipsec_t *kernel_netlink_ipsec_create();
|
||||
|
||||
#endif /** KERNEL_NETLINK_IPSEC_H_ @}*/
|
||||
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,46 @@
|
||||
/*
|
||||
* Copyright (C) 2008 Tobias Brunner
|
||||
* Hochschule fuer Technik Rapperswil
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify it
|
||||
* under the terms of the GNU General Public License as published by the
|
||||
* Free Software Foundation; either version 2 of the License, or (at your
|
||||
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
|
||||
*
|
||||
* This program is distributed in the hope that it will be useful, but
|
||||
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
|
||||
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
||||
* for more details.
|
||||
*/
|
||||
|
||||
/**
|
||||
* @defgroup kernel_netlink_net_i kernel_netlink_net
|
||||
* @{ @ingroup kernel_netlink
|
||||
*/
|
||||
|
||||
#ifndef KERNEL_NETLINK_NET_H_
|
||||
#define KERNEL_NETLINK_NET_H_
|
||||
|
||||
#include <kernel/kernel_net.h>
|
||||
|
||||
typedef struct kernel_netlink_net_t kernel_netlink_net_t;
|
||||
|
||||
/**
|
||||
* Implementation of the kernel network interface using Netlink.
|
||||
*/
|
||||
struct kernel_netlink_net_t {
|
||||
|
||||
/**
|
||||
* Implements kernel_net_t interface
|
||||
*/
|
||||
kernel_net_t interface;
|
||||
};
|
||||
|
||||
/**
|
||||
* Create a netlink kernel network interface instance.
|
||||
*
|
||||
* @return kernel_netlink_net_t instance
|
||||
*/
|
||||
kernel_netlink_net_t *kernel_netlink_net_create();
|
||||
|
||||
#endif /** KERNEL_NETLINK_NET_H_ @}*/
|
||||
@@ -0,0 +1,63 @@
|
||||
/*
|
||||
* Copyright (C) 2008 Tobias Brunner
|
||||
* Hochschule fuer Technik Rapperswil
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify it
|
||||
* under the terms of the GNU General Public License as published by the
|
||||
* Free Software Foundation; either version 2 of the License, or (at your
|
||||
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
|
||||
*
|
||||
* This program is distributed in the hope that it will be useful, but
|
||||
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
|
||||
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
||||
* for more details.
|
||||
*/
|
||||
|
||||
|
||||
#include "kernel_netlink_plugin.h"
|
||||
|
||||
#include "kernel_netlink_ipsec.h"
|
||||
#include "kernel_netlink_net.h"
|
||||
|
||||
#include <hydra.h>
|
||||
|
||||
typedef struct private_kernel_netlink_plugin_t private_kernel_netlink_plugin_t;
|
||||
|
||||
/**
|
||||
* private data of kernel netlink plugin
|
||||
*/
|
||||
struct private_kernel_netlink_plugin_t {
|
||||
/**
|
||||
* implements plugin interface
|
||||
*/
|
||||
kernel_netlink_plugin_t public;
|
||||
};
|
||||
|
||||
/**
|
||||
* Implementation of plugin_t.destroy
|
||||
*/
|
||||
static void destroy(private_kernel_netlink_plugin_t *this)
|
||||
{
|
||||
hydra->kernel_interface->remove_ipsec_interface(hydra->kernel_interface,
|
||||
(kernel_ipsec_constructor_t)kernel_netlink_ipsec_create);
|
||||
hydra->kernel_interface->remove_net_interface(hydra->kernel_interface,
|
||||
(kernel_net_constructor_t)kernel_netlink_net_create);
|
||||
free(this);
|
||||
}
|
||||
|
||||
/*
|
||||
* see header file
|
||||
*/
|
||||
plugin_t *kernel_netlink_plugin_create()
|
||||
{
|
||||
private_kernel_netlink_plugin_t *this = malloc_thing(private_kernel_netlink_plugin_t);
|
||||
|
||||
this->public.plugin.destroy = (void(*)(plugin_t*))destroy;
|
||||
|
||||
hydra->kernel_interface->add_ipsec_interface(hydra->kernel_interface,
|
||||
(kernel_ipsec_constructor_t)kernel_netlink_ipsec_create);
|
||||
hydra->kernel_interface->add_net_interface(hydra->kernel_interface,
|
||||
(kernel_net_constructor_t)kernel_netlink_net_create);
|
||||
|
||||
return &this->public.plugin;
|
||||
}
|
||||
@@ -0,0 +1,42 @@
|
||||
/*
|
||||
* Copyright (C) 2008 Tobias Brunner
|
||||
* Hochschule fuer Technik Rapperswil
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify it
|
||||
* under the terms of the GNU General Public License as published by the
|
||||
* Free Software Foundation; either version 2 of the License, or (at your
|
||||
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
|
||||
*
|
||||
* This program is distributed in the hope that it will be useful, but
|
||||
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
|
||||
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
||||
* for more details.
|
||||
*/
|
||||
|
||||
/**
|
||||
* @defgroup kernel_netlink kernel_netlink
|
||||
* @ingroup hplugins
|
||||
*
|
||||
* @defgroup kernel_netlink_plugin kernel_netlink_plugin
|
||||
* @{ @ingroup kernel_netlink
|
||||
*/
|
||||
|
||||
#ifndef KERNEL_NETLINK_PLUGIN_H_
|
||||
#define KERNEL_NETLINK_PLUGIN_H_
|
||||
|
||||
#include <plugins/plugin.h>
|
||||
|
||||
typedef struct kernel_netlink_plugin_t kernel_netlink_plugin_t;
|
||||
|
||||
/**
|
||||
* netlink kernel interface plugin
|
||||
*/
|
||||
struct kernel_netlink_plugin_t {
|
||||
|
||||
/**
|
||||
* implements plugin interface
|
||||
*/
|
||||
plugin_t plugin;
|
||||
};
|
||||
|
||||
#endif /** KERNEL_NETLINK_PLUGIN_H_ @}*/
|
||||
@@ -0,0 +1,306 @@
|
||||
/*
|
||||
* Copyright (C) 2008 Tobias Brunner
|
||||
* Hochschule fuer Technik Rapperswil
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify it
|
||||
* under the terms of the GNU General Public License as published by the
|
||||
* Free Software Foundation; either version 2 of the License, or (at your
|
||||
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
|
||||
*
|
||||
* This program is distributed in the hope that it will be useful, but
|
||||
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
|
||||
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
||||
* for more details.
|
||||
*/
|
||||
|
||||
#include <sys/socket.h>
|
||||
#include <linux/netlink.h>
|
||||
#include <linux/rtnetlink.h>
|
||||
#include <errno.h>
|
||||
#include <unistd.h>
|
||||
|
||||
#include "kernel_netlink_shared.h"
|
||||
|
||||
#include <debug.h>
|
||||
#include <threading/mutex.h>
|
||||
|
||||
typedef struct private_netlink_socket_t private_netlink_socket_t;
|
||||
|
||||
/**
|
||||
* Private variables and functions of netlink_socket_t class.
|
||||
*/
|
||||
struct private_netlink_socket_t {
|
||||
/**
|
||||
* public part of the netlink_socket_t object.
|
||||
*/
|
||||
netlink_socket_t public;
|
||||
|
||||
/**
|
||||
* mutex to lock access to netlink socket
|
||||
*/
|
||||
mutex_t *mutex;
|
||||
|
||||
/**
|
||||
* current sequence number for netlink request
|
||||
*/
|
||||
int seq;
|
||||
|
||||
/**
|
||||
* netlink socket protocol
|
||||
*/
|
||||
int protocol;
|
||||
|
||||
/**
|
||||
* netlink socket
|
||||
*/
|
||||
int socket;
|
||||
};
|
||||
|
||||
/**
|
||||
* Imported from kernel_netlink_ipsec.c
|
||||
*/
|
||||
extern enum_name_t *xfrm_msg_names;
|
||||
|
||||
/**
|
||||
* Implementation of netlink_socket_t.send
|
||||
*/
|
||||
static status_t netlink_send(private_netlink_socket_t *this, struct nlmsghdr *in,
|
||||
struct nlmsghdr **out, size_t *out_len)
|
||||
{
|
||||
int len, addr_len;
|
||||
struct sockaddr_nl addr;
|
||||
chunk_t result = chunk_empty, tmp;
|
||||
struct nlmsghdr *msg, peek;
|
||||
|
||||
this->mutex->lock(this->mutex);
|
||||
|
||||
in->nlmsg_seq = ++this->seq;
|
||||
in->nlmsg_pid = getpid();
|
||||
|
||||
memset(&addr, 0, sizeof(addr));
|
||||
addr.nl_family = AF_NETLINK;
|
||||
addr.nl_pid = 0;
|
||||
addr.nl_groups = 0;
|
||||
|
||||
if (this->protocol == NETLINK_XFRM)
|
||||
{
|
||||
chunk_t in_chunk = { (u_char*)in, in->nlmsg_len };
|
||||
|
||||
DBG3(DBG_KNL, "sending %N: %B", xfrm_msg_names, in->nlmsg_type, &in_chunk);
|
||||
}
|
||||
|
||||
while (TRUE)
|
||||
{
|
||||
len = sendto(this->socket, in, in->nlmsg_len, 0,
|
||||
(struct sockaddr*)&addr, sizeof(addr));
|
||||
|
||||
if (len != in->nlmsg_len)
|
||||
{
|
||||
if (errno == EINTR)
|
||||
{
|
||||
/* interrupted, try again */
|
||||
continue;
|
||||
}
|
||||
this->mutex->unlock(this->mutex);
|
||||
DBG1(DBG_KNL, "error sending to netlink socket: %s", strerror(errno));
|
||||
return FAILED;
|
||||
}
|
||||
break;
|
||||
}
|
||||
|
||||
while (TRUE)
|
||||
{
|
||||
char buf[4096];
|
||||
tmp.len = sizeof(buf);
|
||||
tmp.ptr = buf;
|
||||
msg = (struct nlmsghdr*)tmp.ptr;
|
||||
|
||||
memset(&addr, 0, sizeof(addr));
|
||||
addr.nl_family = AF_NETLINK;
|
||||
addr.nl_pid = getpid();
|
||||
addr.nl_groups = 0;
|
||||
addr_len = sizeof(addr);
|
||||
|
||||
len = recvfrom(this->socket, tmp.ptr, tmp.len, 0,
|
||||
(struct sockaddr*)&addr, &addr_len);
|
||||
|
||||
if (len < 0)
|
||||
{
|
||||
if (errno == EINTR)
|
||||
{
|
||||
DBG1(DBG_KNL, "got interrupted");
|
||||
/* interrupted, try again */
|
||||
continue;
|
||||
}
|
||||
DBG1(DBG_KNL, "error reading from netlink socket: %s", strerror(errno));
|
||||
this->mutex->unlock(this->mutex);
|
||||
free(result.ptr);
|
||||
return FAILED;
|
||||
}
|
||||
if (!NLMSG_OK(msg, len))
|
||||
{
|
||||
DBG1(DBG_KNL, "received corrupted netlink message");
|
||||
this->mutex->unlock(this->mutex);
|
||||
free(result.ptr);
|
||||
return FAILED;
|
||||
}
|
||||
if (msg->nlmsg_seq != this->seq)
|
||||
{
|
||||
DBG1(DBG_KNL, "received invalid netlink sequence number");
|
||||
if (msg->nlmsg_seq < this->seq)
|
||||
{
|
||||
continue;
|
||||
}
|
||||
this->mutex->unlock(this->mutex);
|
||||
free(result.ptr);
|
||||
return FAILED;
|
||||
}
|
||||
|
||||
tmp.len = len;
|
||||
result.ptr = realloc(result.ptr, result.len + tmp.len);
|
||||
memcpy(result.ptr + result.len, tmp.ptr, tmp.len);
|
||||
result.len += tmp.len;
|
||||
|
||||
/* NLM_F_MULTI flag does not seem to be set correctly, we use sequence
|
||||
* numbers to detect multi header messages */
|
||||
len = recvfrom(this->socket, &peek, sizeof(peek), MSG_PEEK | MSG_DONTWAIT,
|
||||
(struct sockaddr*)&addr, &addr_len);
|
||||
|
||||
if (len == sizeof(peek) && peek.nlmsg_seq == this->seq)
|
||||
{
|
||||
/* seems to be multipart */
|
||||
continue;
|
||||
}
|
||||
break;
|
||||
}
|
||||
|
||||
*out_len = result.len;
|
||||
*out = (struct nlmsghdr*)result.ptr;
|
||||
|
||||
this->mutex->unlock(this->mutex);
|
||||
|
||||
return SUCCESS;
|
||||
}
|
||||
|
||||
/**
|
||||
* Implementation of netlink_socket_t.send_ack.
|
||||
*/
|
||||
static status_t netlink_send_ack(private_netlink_socket_t *this, struct nlmsghdr *in)
|
||||
{
|
||||
struct nlmsghdr *out, *hdr;
|
||||
size_t len;
|
||||
|
||||
if (netlink_send(this, in, &out, &len) != SUCCESS)
|
||||
{
|
||||
return FAILED;
|
||||
}
|
||||
hdr = out;
|
||||
while (NLMSG_OK(hdr, len))
|
||||
{
|
||||
switch (hdr->nlmsg_type)
|
||||
{
|
||||
case NLMSG_ERROR:
|
||||
{
|
||||
struct nlmsgerr* err = (struct nlmsgerr*)NLMSG_DATA(hdr);
|
||||
|
||||
if (err->error)
|
||||
{
|
||||
if (-err->error == EEXIST)
|
||||
{ /* do not report existing routes */
|
||||
free(out);
|
||||
return ALREADY_DONE;
|
||||
}
|
||||
DBG1(DBG_KNL, "received netlink error: %s (%d)",
|
||||
strerror(-err->error), -err->error);
|
||||
free(out);
|
||||
return FAILED;
|
||||
}
|
||||
free(out);
|
||||
return SUCCESS;
|
||||
}
|
||||
default:
|
||||
hdr = NLMSG_NEXT(hdr, len);
|
||||
continue;
|
||||
case NLMSG_DONE:
|
||||
break;
|
||||
}
|
||||
break;
|
||||
}
|
||||
DBG1(DBG_KNL, "netlink request not acknowledged");
|
||||
free(out);
|
||||
return FAILED;
|
||||
}
|
||||
|
||||
/**
|
||||
* Implementation of netlink_socket_t.destroy.
|
||||
*/
|
||||
static void destroy(private_netlink_socket_t *this)
|
||||
{
|
||||
if (this->socket > 0)
|
||||
{
|
||||
close(this->socket);
|
||||
}
|
||||
this->mutex->destroy(this->mutex);
|
||||
free(this);
|
||||
}
|
||||
|
||||
/**
|
||||
* Described in header.
|
||||
*/
|
||||
netlink_socket_t *netlink_socket_create(int protocol)
|
||||
{
|
||||
private_netlink_socket_t *this = malloc_thing(private_netlink_socket_t);
|
||||
struct sockaddr_nl addr;
|
||||
|
||||
/* public functions */
|
||||
this->public.send = (status_t(*)(netlink_socket_t*,struct nlmsghdr*, struct nlmsghdr**, size_t*))netlink_send;
|
||||
this->public.send_ack = (status_t(*)(netlink_socket_t*,struct nlmsghdr*))netlink_send_ack;
|
||||
this->public.destroy = (void(*)(netlink_socket_t*))destroy;
|
||||
|
||||
/* private members */
|
||||
this->seq = 200;
|
||||
this->mutex = mutex_create(MUTEX_TYPE_DEFAULT);
|
||||
|
||||
memset(&addr, 0, sizeof(addr));
|
||||
addr.nl_family = AF_NETLINK;
|
||||
|
||||
this->protocol = protocol;
|
||||
this->socket = socket(AF_NETLINK, SOCK_RAW, protocol);
|
||||
if (this->socket < 0)
|
||||
{
|
||||
DBG1(DBG_KNL, "unable to create netlink socket");
|
||||
destroy(this);
|
||||
return NULL;
|
||||
}
|
||||
|
||||
addr.nl_groups = 0;
|
||||
if (bind(this->socket, (struct sockaddr*)&addr, sizeof(addr)))
|
||||
{
|
||||
DBG1(DBG_KNL, "unable to bind netlink socket");
|
||||
destroy(this);
|
||||
return NULL;
|
||||
}
|
||||
|
||||
return &this->public;
|
||||
}
|
||||
|
||||
/**
|
||||
* Described in header.
|
||||
*/
|
||||
void netlink_add_attribute(struct nlmsghdr *hdr, int rta_type, chunk_t data,
|
||||
size_t buflen)
|
||||
{
|
||||
struct rtattr *rta;
|
||||
|
||||
if (NLMSG_ALIGN(hdr->nlmsg_len) + RTA_ALIGN(data.len) > buflen)
|
||||
{
|
||||
DBG1(DBG_KNL, "unable to add attribute, buffer too small");
|
||||
return;
|
||||
}
|
||||
|
||||
rta = (struct rtattr*)(((char*)hdr) + NLMSG_ALIGN(hdr->nlmsg_len));
|
||||
rta->rta_type = rta_type;
|
||||
rta->rta_len = RTA_LENGTH(data.len);
|
||||
memcpy(RTA_DATA(rta), data.ptr, data.len);
|
||||
hdr->nlmsg_len = NLMSG_ALIGN(hdr->nlmsg_len) + rta->rta_len;
|
||||
}
|
||||
@@ -0,0 +1,77 @@
|
||||
/*
|
||||
* Copyright (C) 2008 Tobias Brunner
|
||||
* Hochschule fuer Technik Rapperswil
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify it
|
||||
* under the terms of the GNU General Public License as published by the
|
||||
* Free Software Foundation; either version 2 of the License, or (at your
|
||||
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
|
||||
*
|
||||
* This program is distributed in the hope that it will be useful, but
|
||||
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
|
||||
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
||||
* for more details.
|
||||
*/
|
||||
|
||||
#ifndef KERNEL_NETLINK_SHARED_H_
|
||||
#define KERNEL_NETLINK_SHARED_H_
|
||||
|
||||
#include <library.h>
|
||||
|
||||
#include <linux/rtnetlink.h>
|
||||
|
||||
/**
|
||||
* General purpose netlink buffer.
|
||||
*
|
||||
* 1024 byte is currently sufficient for all operations. Some platform
|
||||
* require an enforced aligment to four bytes (e.g. ARM).
|
||||
*/
|
||||
typedef u_char netlink_buf_t[1024] __attribute__((aligned(RTA_ALIGNTO)));
|
||||
|
||||
typedef struct netlink_socket_t netlink_socket_t;
|
||||
|
||||
/**
|
||||
* Wrapper around a netlink socket.
|
||||
*/
|
||||
struct netlink_socket_t {
|
||||
|
||||
/**
|
||||
* Send a netlink message and wait for a reply.
|
||||
*
|
||||
* @param in netlink message to send
|
||||
* @param out received netlink message
|
||||
* @param out_len length of the received message
|
||||
*/
|
||||
status_t (*send)(netlink_socket_t *this, struct nlmsghdr *in, struct nlmsghdr **out, size_t *out_len);
|
||||
|
||||
/**
|
||||
* Send a netlink message and wait for its acknowledge.
|
||||
*
|
||||
* @param in netlink message to send
|
||||
*/
|
||||
status_t (*send_ack)(netlink_socket_t *this, struct nlmsghdr *in);
|
||||
|
||||
/**
|
||||
* Destroy the socket.
|
||||
*/
|
||||
void (*destroy)(netlink_socket_t *this);
|
||||
};
|
||||
|
||||
/**
|
||||
* Create a netlink_socket_t object.
|
||||
*
|
||||
* @param protocol protocol type (e.g. NETLINK_XFRM or NETLINK_ROUTE)
|
||||
*/
|
||||
netlink_socket_t *netlink_socket_create(int protocol);
|
||||
|
||||
/**
|
||||
* Creates an rtattr and adds it to the given netlink message.
|
||||
*
|
||||
* @param hdr netlink message
|
||||
* @param rta_type type of the rtattr
|
||||
* @param data data to add to the rtattr
|
||||
* @param buflen length of the netlink message buffer
|
||||
*/
|
||||
void netlink_add_attribute(struct nlmsghdr *hdr, int rta_type, chunk_t data, size_t buflen);
|
||||
|
||||
#endif /* KERNEL_NETLINK_SHARED_H_ */
|
||||
@@ -0,0 +1,17 @@
|
||||
|
||||
INCLUDES = -I${linux_headers} -I$(top_srcdir)/src/libstrongswan \
|
||||
-I$(top_srcdir)/src/libhydra
|
||||
|
||||
AM_CFLAGS = -rdynamic
|
||||
|
||||
if MONOLITHIC
|
||||
noinst_LTLIBRARIES = libstrongswan-kernel-pfkey.la
|
||||
else
|
||||
plugin_LTLIBRARIES = libstrongswan-kernel-pfkey.la
|
||||
endif
|
||||
|
||||
libstrongswan_kernel_pfkey_la_SOURCES = \
|
||||
kernel_pfkey_plugin.h kernel_pfkey_plugin.c \
|
||||
kernel_pfkey_ipsec.h kernel_pfkey_ipsec.c
|
||||
|
||||
libstrongswan_kernel_pfkey_la_LDFLAGS = -module -avoid-version
|
||||
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,46 @@
|
||||
/*
|
||||
* Copyright (C) 2008 Tobias Brunner
|
||||
* Hochschule fuer Technik Rapperswil
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify it
|
||||
* under the terms of the GNU General Public License as published by the
|
||||
* Free Software Foundation; either version 2 of the License, or (at your
|
||||
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
|
||||
*
|
||||
* This program is distributed in the hope that it will be useful, but
|
||||
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
|
||||
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
||||
* for more details.
|
||||
*/
|
||||
|
||||
/**
|
||||
* @defgroup kernel_pfkey_ipsec_i kernel_pfkey_ipsec
|
||||
* @{ @ingroup kernel_pfkey
|
||||
*/
|
||||
|
||||
#ifndef KERNEL_PFKEY_IPSEC_H_
|
||||
#define KERNEL_PFKEY_IPSEC_H_
|
||||
|
||||
#include <kernel/kernel_ipsec.h>
|
||||
|
||||
typedef struct kernel_pfkey_ipsec_t kernel_pfkey_ipsec_t;
|
||||
|
||||
/**
|
||||
* Implementation of the kernel ipsec interface using PF_KEY.
|
||||
*/
|
||||
struct kernel_pfkey_ipsec_t {
|
||||
|
||||
/**
|
||||
* Implements kernel_ipsec_t interface
|
||||
*/
|
||||
kernel_ipsec_t interface;
|
||||
};
|
||||
|
||||
/**
|
||||
* Create a PF_KEY kernel ipsec interface instance.
|
||||
*
|
||||
* @return kernel_pfkey_ipsec_t instance
|
||||
*/
|
||||
kernel_pfkey_ipsec_t *kernel_pfkey_ipsec_create();
|
||||
|
||||
#endif /** KERNEL_PFKEY_IPSEC_H_ @}*/
|
||||
@@ -0,0 +1,58 @@
|
||||
/*
|
||||
* Copyright (C) 2008 Tobias Brunner
|
||||
* Hochschule fuer Technik Rapperswil
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify it
|
||||
* under the terms of the GNU General Public License as published by the
|
||||
* Free Software Foundation; either version 2 of the License, or (at your
|
||||
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
|
||||
*
|
||||
* This program is distributed in the hope that it will be useful, but
|
||||
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
|
||||
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
||||
* for more details.
|
||||
*/
|
||||
|
||||
|
||||
#include "kernel_pfkey_plugin.h"
|
||||
|
||||
#include "kernel_pfkey_ipsec.h"
|
||||
|
||||
#include <hydra.h>
|
||||
|
||||
typedef struct private_kernel_pfkey_plugin_t private_kernel_pfkey_plugin_t;
|
||||
|
||||
/**
|
||||
* private data of kernel PF_KEY plugin
|
||||
*/
|
||||
struct private_kernel_pfkey_plugin_t {
|
||||
/**
|
||||
* implements plugin interface
|
||||
*/
|
||||
kernel_pfkey_plugin_t public;
|
||||
};
|
||||
|
||||
/**
|
||||
* Implementation of plugin_t.destroy
|
||||
*/
|
||||
static void destroy(private_kernel_pfkey_plugin_t *this)
|
||||
{
|
||||
hydra->kernel_interface->remove_ipsec_interface(hydra->kernel_interface,
|
||||
(kernel_ipsec_constructor_t)kernel_pfkey_ipsec_create);
|
||||
free(this);
|
||||
}
|
||||
|
||||
/*
|
||||
* see header file
|
||||
*/
|
||||
plugin_t *kernel_pfkey_plugin_create()
|
||||
{
|
||||
private_kernel_pfkey_plugin_t *this = malloc_thing(private_kernel_pfkey_plugin_t);
|
||||
|
||||
this->public.plugin.destroy = (void(*)(plugin_t*))destroy;
|
||||
|
||||
hydra->kernel_interface->add_ipsec_interface(hydra->kernel_interface,
|
||||
(kernel_ipsec_constructor_t)kernel_pfkey_ipsec_create);
|
||||
|
||||
return &this->public.plugin;
|
||||
}
|
||||
@@ -0,0 +1,42 @@
|
||||
/*
|
||||
* Copyright (C) 2008 Tobias Brunner
|
||||
* Hochschule fuer Technik Rapperswil
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify it
|
||||
* under the terms of the GNU General Public License as published by the
|
||||
* Free Software Foundation; either version 2 of the License, or (at your
|
||||
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
|
||||
*
|
||||
* This program is distributed in the hope that it will be useful, but
|
||||
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
|
||||
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
||||
* for more details.
|
||||
*/
|
||||
|
||||
/**
|
||||
* @defgroup kernel_pfkey kernel_pfkey
|
||||
* @ingroup hplugins
|
||||
*
|
||||
* @defgroup kernel_pfkey_plugin kernel_pfkey_plugin
|
||||
* @{ @ingroup kernel_pfkey
|
||||
*/
|
||||
|
||||
#ifndef KERNEL_PFKEY_PLUGIN_H_
|
||||
#define KERNEL_PFKEY_PLUGIN_H_
|
||||
|
||||
#include <plugins/plugin.h>
|
||||
|
||||
typedef struct kernel_pfkey_plugin_t kernel_pfkey_plugin_t;
|
||||
|
||||
/**
|
||||
* PF_KEY kernel interface plugin
|
||||
*/
|
||||
struct kernel_pfkey_plugin_t {
|
||||
|
||||
/**
|
||||
* implements plugin interface
|
||||
*/
|
||||
plugin_t plugin;
|
||||
};
|
||||
|
||||
#endif /** KERNEL_PFKEY_PLUGIN_H_ @}*/
|
||||
@@ -0,0 +1,17 @@
|
||||
|
||||
INCLUDES = -I${linux_headers} -I$(top_srcdir)/src/libstrongswan \
|
||||
-I$(top_srcdir)/src/libhydra
|
||||
|
||||
AM_CFLAGS = -rdynamic
|
||||
|
||||
if MONOLITHIC
|
||||
noinst_LTLIBRARIES = libstrongswan-kernel-pfroute.la
|
||||
else
|
||||
plugin_LTLIBRARIES = libstrongswan-kernel-pfroute.la
|
||||
endif
|
||||
|
||||
libstrongswan_kernel_pfroute_la_SOURCES = \
|
||||
kernel_pfroute_plugin.h kernel_pfroute_plugin.c \
|
||||
kernel_pfroute_net.h kernel_pfroute_net.c
|
||||
|
||||
libstrongswan_kernel_pfroute_la_LDFLAGS = -module -avoid-version
|
||||
@@ -0,0 +1,742 @@
|
||||
/*
|
||||
* Copyright (C) 2009 Tobias Brunner
|
||||
* Hochschule fuer Technik Rapperswil
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify it
|
||||
* under the terms of the GNU General Public License as published by the
|
||||
* Free Software Foundation; either version 2 of the License, or (at your
|
||||
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
|
||||
*
|
||||
* This program is distributed in the hope that it will be useful, but
|
||||
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
|
||||
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
||||
* for more details.
|
||||
*/
|
||||
|
||||
#include <sys/types.h>
|
||||
#include <sys/socket.h>
|
||||
#include <net/if.h>
|
||||
#include <ifaddrs.h>
|
||||
#include <net/route.h>
|
||||
#include <unistd.h>
|
||||
#include <errno.h>
|
||||
|
||||
#include "kernel_pfroute_net.h"
|
||||
|
||||
#include <hydra.h>
|
||||
#include <debug.h>
|
||||
#include <utils/host.h>
|
||||
#include <threading/thread.h>
|
||||
#include <threading/mutex.h>
|
||||
#include <utils/linked_list.h>
|
||||
#include <processing/jobs/callback_job.h>
|
||||
|
||||
#ifndef HAVE_STRUCT_SOCKADDR_SA_LEN
|
||||
#error Cannot compile this plugin on systems where 'struct sockaddr' has no sa_len member.
|
||||
#endif
|
||||
|
||||
/** delay before firing roam events (ms) */
|
||||
#define ROAM_DELAY 100
|
||||
|
||||
/** buffer size for PF_ROUTE messages */
|
||||
#define PFROUTE_BUFFER_SIZE 4096
|
||||
|
||||
typedef struct addr_entry_t addr_entry_t;
|
||||
|
||||
/**
|
||||
* IP address in an inface_entry_t
|
||||
*/
|
||||
struct addr_entry_t {
|
||||
|
||||
/** The ip address */
|
||||
host_t *ip;
|
||||
|
||||
/** virtual IP managed by us */
|
||||
bool virtual;
|
||||
|
||||
/** Number of times this IP is used, if virtual */
|
||||
u_int refcount;
|
||||
};
|
||||
|
||||
/**
|
||||
* destroy a addr_entry_t object
|
||||
*/
|
||||
static void addr_entry_destroy(addr_entry_t *this)
|
||||
{
|
||||
this->ip->destroy(this->ip);
|
||||
free(this);
|
||||
}
|
||||
|
||||
typedef struct iface_entry_t iface_entry_t;
|
||||
|
||||
/**
|
||||
* A network interface on this system, containing addr_entry_t's
|
||||
*/
|
||||
struct iface_entry_t {
|
||||
|
||||
/** interface index */
|
||||
int ifindex;
|
||||
|
||||
/** name of the interface */
|
||||
char ifname[IFNAMSIZ];
|
||||
|
||||
/** interface flags, as in netdevice(7) SIOCGIFFLAGS */
|
||||
u_int flags;
|
||||
|
||||
/** list of addresses as host_t */
|
||||
linked_list_t *addrs;
|
||||
};
|
||||
|
||||
/**
|
||||
* destroy an interface entry
|
||||
*/
|
||||
static void iface_entry_destroy(iface_entry_t *this)
|
||||
{
|
||||
this->addrs->destroy_function(this->addrs, (void*)addr_entry_destroy);
|
||||
free(this);
|
||||
}
|
||||
|
||||
|
||||
typedef struct private_kernel_pfroute_net_t private_kernel_pfroute_net_t;
|
||||
|
||||
/**
|
||||
* Private variables and functions of kernel_pfroute class.
|
||||
*/
|
||||
struct private_kernel_pfroute_net_t
|
||||
{
|
||||
/**
|
||||
* Public part of the kernel_pfroute_t object.
|
||||
*/
|
||||
kernel_pfroute_net_t public;
|
||||
|
||||
/**
|
||||
* mutex to lock access to various lists
|
||||
*/
|
||||
mutex_t *mutex;
|
||||
|
||||
/**
|
||||
* Cached list of interfaces and their addresses (iface_entry_t)
|
||||
*/
|
||||
linked_list_t *ifaces;
|
||||
|
||||
/**
|
||||
* job receiving PF_ROUTE events
|
||||
*/
|
||||
callback_job_t *job;
|
||||
|
||||
/**
|
||||
* mutex to lock access to the PF_ROUTE socket
|
||||
*/
|
||||
mutex_t *mutex_pfroute;
|
||||
|
||||
/**
|
||||
* PF_ROUTE socket to communicate with the kernel
|
||||
*/
|
||||
int socket;
|
||||
|
||||
/**
|
||||
* PF_ROUTE socket to receive events
|
||||
*/
|
||||
int socket_events;
|
||||
|
||||
/**
|
||||
* sequence number for messages sent to the kernel
|
||||
*/
|
||||
int seq;
|
||||
|
||||
/**
|
||||
* time of last roam event
|
||||
*/
|
||||
timeval_t last_roam;
|
||||
};
|
||||
|
||||
/**
|
||||
* callback function that raises the delayed roam event
|
||||
*/
|
||||
static job_requeue_t roam_event(uintptr_t address)
|
||||
{
|
||||
hydra->kernel_interface->roam(hydra->kernel_interface, address != 0);
|
||||
return JOB_REQUEUE_NONE;
|
||||
}
|
||||
|
||||
/**
|
||||
* fire a roaming event. we delay it for a bit and fire only one event
|
||||
* for multiple calls. otherwise we would create too many events.
|
||||
*/
|
||||
static void fire_roam_event(private_kernel_pfroute_net_t *this, bool address)
|
||||
{
|
||||
timeval_t now;
|
||||
job_t *job;
|
||||
|
||||
time_monotonic(&now);
|
||||
if (timercmp(&now, &this->last_roam, >))
|
||||
{
|
||||
now.tv_usec += ROAM_DELAY * 1000;
|
||||
while (now.tv_usec > 1000000)
|
||||
{
|
||||
now.tv_sec++;
|
||||
now.tv_usec -= 1000000;
|
||||
}
|
||||
this->last_roam = now;
|
||||
|
||||
job = (job_t*)callback_job_create((callback_job_cb_t)roam_event,
|
||||
(void*)(uintptr_t)(address ? 1 : 0),
|
||||
NULL, NULL);
|
||||
hydra->scheduler->schedule_job_ms(hydra->scheduler, job, ROAM_DELAY);
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Process an RTM_*ADDR message from the kernel
|
||||
*/
|
||||
static void process_addr(private_kernel_pfroute_net_t *this,
|
||||
struct rt_msghdr *msg)
|
||||
{
|
||||
struct ifa_msghdr *ifa = (struct ifa_msghdr*)msg;
|
||||
sockaddr_t *sockaddr = (sockaddr_t*)(ifa + 1);
|
||||
host_t *host = NULL;
|
||||
enumerator_t *ifaces, *addrs;
|
||||
iface_entry_t *iface;
|
||||
addr_entry_t *addr;
|
||||
bool found = FALSE, changed = FALSE, roam = FALSE;
|
||||
int i;
|
||||
|
||||
for (i = 1; i < (1 << RTAX_MAX); i <<= 1)
|
||||
{
|
||||
if (ifa->ifam_addrs & i)
|
||||
{
|
||||
if (RTA_IFA & i)
|
||||
{
|
||||
host = host_create_from_sockaddr(sockaddr);
|
||||
break;
|
||||
}
|
||||
sockaddr = (sockaddr_t*)((char*)sockaddr + sockaddr->sa_len);
|
||||
}
|
||||
}
|
||||
|
||||
if (!host)
|
||||
{
|
||||
return;
|
||||
}
|
||||
|
||||
this->mutex->lock(this->mutex);
|
||||
ifaces = this->ifaces->create_enumerator(this->ifaces);
|
||||
while (ifaces->enumerate(ifaces, &iface))
|
||||
{
|
||||
if (iface->ifindex == ifa->ifam_index)
|
||||
{
|
||||
addrs = iface->addrs->create_enumerator(iface->addrs);
|
||||
while (addrs->enumerate(addrs, &addr))
|
||||
{
|
||||
if (host->ip_equals(host, addr->ip))
|
||||
{
|
||||
found = TRUE;
|
||||
if (ifa->ifam_type == RTM_DELADDR)
|
||||
{
|
||||
iface->addrs->remove_at(iface->addrs, addrs);
|
||||
if (!addr->virtual)
|
||||
{
|
||||
changed = TRUE;
|
||||
DBG1(DBG_KNL, "%H disappeared from %s",
|
||||
host, iface->ifname);
|
||||
}
|
||||
addr_entry_destroy(addr);
|
||||
}
|
||||
else if (ifa->ifam_type == RTM_NEWADDR && addr->virtual)
|
||||
{
|
||||
addr->refcount = 1;
|
||||
}
|
||||
}
|
||||
}
|
||||
addrs->destroy(addrs);
|
||||
|
||||
if (!found && ifa->ifam_type == RTM_NEWADDR)
|
||||
{
|
||||
changed = TRUE;
|
||||
addr = malloc_thing(addr_entry_t);
|
||||
addr->ip = host->clone(host);
|
||||
addr->virtual = FALSE;
|
||||
addr->refcount = 1;
|
||||
iface->addrs->insert_last(iface->addrs, addr);
|
||||
DBG1(DBG_KNL, "%H appeared on %s", host, iface->ifname);
|
||||
}
|
||||
|
||||
if (changed && (iface->flags & IFF_UP))
|
||||
{
|
||||
roam = TRUE;
|
||||
}
|
||||
break;
|
||||
}
|
||||
}
|
||||
ifaces->destroy(ifaces);
|
||||
this->mutex->unlock(this->mutex);
|
||||
host->destroy(host);
|
||||
|
||||
if (roam)
|
||||
{
|
||||
fire_roam_event(this, TRUE);
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Process an RTM_IFINFO message from the kernel
|
||||
*/
|
||||
static void process_link(private_kernel_pfroute_net_t *this,
|
||||
struct rt_msghdr *hdr)
|
||||
{
|
||||
struct if_msghdr *msg = (struct if_msghdr*)hdr;
|
||||
enumerator_t *enumerator;
|
||||
iface_entry_t *iface;
|
||||
bool roam = FALSE;
|
||||
|
||||
if (msg->ifm_flags & IFF_LOOPBACK)
|
||||
{ /* ignore loopback interfaces */
|
||||
return;
|
||||
}
|
||||
|
||||
this->mutex->lock(this->mutex);
|
||||
enumerator = this->ifaces->create_enumerator(this->ifaces);
|
||||
while (enumerator->enumerate(enumerator, &iface))
|
||||
{
|
||||
if (iface->ifindex == msg->ifm_index)
|
||||
{
|
||||
if (!(iface->flags & IFF_UP) && (msg->ifm_flags & IFF_UP))
|
||||
{
|
||||
roam = TRUE;
|
||||
DBG1(DBG_KNL, "interface %s activated", iface->ifname);
|
||||
}
|
||||
else if ((iface->flags & IFF_UP) && !(msg->ifm_flags & IFF_UP))
|
||||
{
|
||||
roam = TRUE;
|
||||
DBG1(DBG_KNL, "interface %s deactivated", iface->ifname);
|
||||
}
|
||||
iface->flags = msg->ifm_flags;
|
||||
break;
|
||||
}
|
||||
}
|
||||
enumerator->destroy(enumerator);
|
||||
this->mutex->unlock(this->mutex);
|
||||
|
||||
if (roam)
|
||||
{
|
||||
fire_roam_event(this, TRUE);
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Process an RTM_*ROUTE message from the kernel
|
||||
*/
|
||||
static void process_route(private_kernel_pfroute_net_t *this,
|
||||
struct rt_msghdr *msg)
|
||||
{
|
||||
|
||||
}
|
||||
|
||||
/**
|
||||
* Receives events from kernel
|
||||
*/
|
||||
static job_requeue_t receive_events(private_kernel_pfroute_net_t *this)
|
||||
{
|
||||
unsigned char buf[PFROUTE_BUFFER_SIZE];
|
||||
struct rt_msghdr *msg = (struct rt_msghdr*)buf;
|
||||
int len;
|
||||
bool oldstate;
|
||||
|
||||
oldstate = thread_cancelability(TRUE);
|
||||
len = recvfrom(this->socket_events, buf, sizeof(buf), 0, NULL, 0);
|
||||
thread_cancelability(oldstate);
|
||||
|
||||
if (len < 0)
|
||||
{
|
||||
switch (errno)
|
||||
{
|
||||
case EINTR:
|
||||
/* interrupted, try again */
|
||||
return JOB_REQUEUE_DIRECT;
|
||||
case EAGAIN:
|
||||
/* no data ready, select again */
|
||||
return JOB_REQUEUE_DIRECT;
|
||||
default:
|
||||
DBG1(DBG_KNL, "unable to receive from PF_ROUTE event socket");
|
||||
sleep(1);
|
||||
return JOB_REQUEUE_FAIR;
|
||||
}
|
||||
}
|
||||
|
||||
if (len < sizeof(msg->rtm_msglen) || len < msg->rtm_msglen ||
|
||||
msg->rtm_version != RTM_VERSION)
|
||||
{
|
||||
DBG2(DBG_KNL, "received corrupted PF_ROUTE message");
|
||||
return JOB_REQUEUE_DIRECT;
|
||||
}
|
||||
|
||||
switch (msg->rtm_type)
|
||||
{
|
||||
case RTM_NEWADDR:
|
||||
case RTM_DELADDR:
|
||||
process_addr(this, msg);
|
||||
break;
|
||||
case RTM_IFINFO:
|
||||
/*case RTM_IFANNOUNCE <- what about this*/
|
||||
process_link(this, msg);
|
||||
break;
|
||||
case RTM_ADD:
|
||||
case RTM_DELETE:
|
||||
process_route(this, msg);
|
||||
default:
|
||||
break;
|
||||
}
|
||||
|
||||
return JOB_REQUEUE_DIRECT;
|
||||
}
|
||||
|
||||
|
||||
/** enumerator over addresses */
|
||||
typedef struct {
|
||||
private_kernel_pfroute_net_t* this;
|
||||
/** whether to enumerate down interfaces */
|
||||
bool include_down_ifaces;
|
||||
/** whether to enumerate virtual ip addresses */
|
||||
bool include_virtual_ips;
|
||||
} address_enumerator_t;
|
||||
|
||||
/**
|
||||
* cleanup function for address enumerator
|
||||
*/
|
||||
static void address_enumerator_destroy(address_enumerator_t *data)
|
||||
{
|
||||
data->this->mutex->unlock(data->this->mutex);
|
||||
free(data);
|
||||
}
|
||||
|
||||
/**
|
||||
* filter for addresses
|
||||
*/
|
||||
static bool filter_addresses(address_enumerator_t *data, addr_entry_t** in, host_t** out)
|
||||
{
|
||||
host_t *ip;
|
||||
if (!data->include_virtual_ips && (*in)->virtual)
|
||||
{ /* skip virtual interfaces added by us */
|
||||
return FALSE;
|
||||
}
|
||||
ip = (*in)->ip;
|
||||
if (ip->get_family(ip) == AF_INET6)
|
||||
{
|
||||
struct sockaddr_in6 *sin6 = (struct sockaddr_in6 *)ip->get_sockaddr(ip);
|
||||
if (IN6_IS_ADDR_LINKLOCAL(&sin6->sin6_addr))
|
||||
{ /* skip addresses with a unusable scope */
|
||||
return FALSE;
|
||||
}
|
||||
}
|
||||
*out = ip;
|
||||
return TRUE;
|
||||
}
|
||||
|
||||
/**
|
||||
* enumerator constructor for interfaces
|
||||
*/
|
||||
static enumerator_t *create_iface_enumerator(iface_entry_t *iface, address_enumerator_t *data)
|
||||
{
|
||||
return enumerator_create_filter(iface->addrs->create_enumerator(iface->addrs),
|
||||
(void*)filter_addresses, data, NULL);
|
||||
}
|
||||
|
||||
/**
|
||||
* filter for interfaces
|
||||
*/
|
||||
static bool filter_interfaces(address_enumerator_t *data, iface_entry_t** in, iface_entry_t** out)
|
||||
{
|
||||
if (!data->include_down_ifaces && !((*in)->flags & IFF_UP))
|
||||
{ /* skip interfaces not up */
|
||||
return FALSE;
|
||||
}
|
||||
*out = *in;
|
||||
return TRUE;
|
||||
}
|
||||
|
||||
/**
|
||||
* implementation of kernel_net_t.create_address_enumerator
|
||||
*/
|
||||
static enumerator_t *create_address_enumerator(private_kernel_pfroute_net_t *this,
|
||||
bool include_down_ifaces, bool include_virtual_ips)
|
||||
{
|
||||
address_enumerator_t *data = malloc_thing(address_enumerator_t);
|
||||
data->this = this;
|
||||
data->include_down_ifaces = include_down_ifaces;
|
||||
data->include_virtual_ips = include_virtual_ips;
|
||||
|
||||
this->mutex->lock(this->mutex);
|
||||
return enumerator_create_nested(
|
||||
enumerator_create_filter(this->ifaces->create_enumerator(this->ifaces),
|
||||
(void*)filter_interfaces, data, NULL),
|
||||
(void*)create_iface_enumerator, data, (void*)address_enumerator_destroy);
|
||||
}
|
||||
|
||||
/**
|
||||
* implementation of kernel_net_t.get_interface_name
|
||||
*/
|
||||
static char *get_interface_name(private_kernel_pfroute_net_t *this, host_t* ip)
|
||||
{
|
||||
enumerator_t *ifaces, *addrs;
|
||||
iface_entry_t *iface;
|
||||
addr_entry_t *addr;
|
||||
char *name = NULL;
|
||||
|
||||
DBG2(DBG_KNL, "getting interface name for %H", ip);
|
||||
|
||||
this->mutex->lock(this->mutex);
|
||||
ifaces = this->ifaces->create_enumerator(this->ifaces);
|
||||
while (ifaces->enumerate(ifaces, &iface))
|
||||
{
|
||||
addrs = iface->addrs->create_enumerator(iface->addrs);
|
||||
while (addrs->enumerate(addrs, &addr))
|
||||
{
|
||||
if (ip->ip_equals(ip, addr->ip))
|
||||
{
|
||||
name = strdup(iface->ifname);
|
||||
break;
|
||||
}
|
||||
}
|
||||
addrs->destroy(addrs);
|
||||
if (name)
|
||||
{
|
||||
break;
|
||||
}
|
||||
}
|
||||
ifaces->destroy(ifaces);
|
||||
this->mutex->unlock(this->mutex);
|
||||
|
||||
if (name)
|
||||
{
|
||||
DBG2(DBG_KNL, "%H is on interface %s", ip, name);
|
||||
}
|
||||
else
|
||||
{
|
||||
DBG2(DBG_KNL, "%H is not a local address", ip);
|
||||
}
|
||||
return name;
|
||||
}
|
||||
|
||||
/**
|
||||
* Implementation of kernel_net_t.get_source_addr.
|
||||
*/
|
||||
static host_t* get_source_addr(private_kernel_pfroute_net_t *this,
|
||||
host_t *dest, host_t *src)
|
||||
{
|
||||
return NULL;
|
||||
}
|
||||
|
||||
/**
|
||||
* Implementation of kernel_net_t.get_nexthop.
|
||||
*/
|
||||
static host_t* get_nexthop(private_kernel_pfroute_net_t *this, host_t *dest)
|
||||
{
|
||||
return NULL;
|
||||
}
|
||||
|
||||
/**
|
||||
* Implementation of kernel_net_t.add_ip.
|
||||
*/
|
||||
static status_t add_ip(private_kernel_pfroute_net_t *this,
|
||||
host_t *virtual_ip, host_t *iface_ip)
|
||||
{
|
||||
return FAILED;
|
||||
}
|
||||
|
||||
/**
|
||||
* Implementation of kernel_net_t.del_ip.
|
||||
*/
|
||||
static status_t del_ip(private_kernel_pfroute_net_t *this, host_t *virtual_ip)
|
||||
{
|
||||
return FAILED;
|
||||
}
|
||||
|
||||
/**
|
||||
* Implementation of kernel_net_t.add_route.
|
||||
*/
|
||||
static status_t add_route(private_kernel_pfroute_net_t *this, chunk_t dst_net,
|
||||
u_int8_t prefixlen, host_t *gateway, host_t *src_ip, char *if_name)
|
||||
{
|
||||
return FAILED;
|
||||
}
|
||||
|
||||
/**
|
||||
* Implementation of kernel_net_t.del_route.
|
||||
*/
|
||||
static status_t del_route(private_kernel_pfroute_net_t *this, chunk_t dst_net,
|
||||
u_int8_t prefixlen, host_t *gateway, host_t *src_ip, char *if_name)
|
||||
{
|
||||
return FAILED;
|
||||
}
|
||||
|
||||
/**
|
||||
* Initialize a list of local addresses.
|
||||
*/
|
||||
static status_t init_address_list(private_kernel_pfroute_net_t *this)
|
||||
{
|
||||
struct ifaddrs *ifap, *ifa;
|
||||
iface_entry_t *iface, *current;
|
||||
addr_entry_t *addr;
|
||||
enumerator_t *ifaces, *addrs;
|
||||
|
||||
DBG1(DBG_KNL, "listening on interfaces:");
|
||||
|
||||
if (getifaddrs(&ifap) < 0)
|
||||
{
|
||||
DBG1(DBG_KNL, " failed to get interfaces!");
|
||||
return FAILED;
|
||||
}
|
||||
|
||||
for (ifa = ifap; ifa != NULL; ifa = ifa->ifa_next)
|
||||
{
|
||||
if (ifa->ifa_addr == NULL)
|
||||
{
|
||||
continue;
|
||||
}
|
||||
switch(ifa->ifa_addr->sa_family)
|
||||
{
|
||||
case AF_LINK:
|
||||
case AF_INET:
|
||||
case AF_INET6:
|
||||
{
|
||||
if (ifa->ifa_flags & IFF_LOOPBACK)
|
||||
{ /* ignore loopback interfaces */
|
||||
continue;
|
||||
}
|
||||
|
||||
iface = NULL;
|
||||
ifaces = this->ifaces->create_enumerator(this->ifaces);
|
||||
while (ifaces->enumerate(ifaces, ¤t))
|
||||
{
|
||||
if (streq(current->ifname, ifa->ifa_name))
|
||||
{
|
||||
iface = current;
|
||||
break;
|
||||
}
|
||||
}
|
||||
ifaces->destroy(ifaces);
|
||||
|
||||
if (!iface)
|
||||
{
|
||||
iface = malloc_thing(iface_entry_t);
|
||||
memcpy(iface->ifname, ifa->ifa_name, IFNAMSIZ);
|
||||
iface->ifindex = if_nametoindex(ifa->ifa_name);
|
||||
iface->flags = ifa->ifa_flags;
|
||||
iface->addrs = linked_list_create();
|
||||
this->ifaces->insert_last(this->ifaces, iface);
|
||||
}
|
||||
|
||||
if (ifa->ifa_addr->sa_family != AF_LINK)
|
||||
{
|
||||
addr = malloc_thing(addr_entry_t);
|
||||
addr->ip = host_create_from_sockaddr(ifa->ifa_addr);
|
||||
addr->virtual = FALSE;
|
||||
addr->refcount = 1;
|
||||
iface->addrs->insert_last(iface->addrs, addr);
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
freeifaddrs(ifap);
|
||||
|
||||
ifaces = this->ifaces->create_enumerator(this->ifaces);
|
||||
while (ifaces->enumerate(ifaces, &iface))
|
||||
{
|
||||
if (iface->flags & IFF_UP)
|
||||
{
|
||||
DBG1(DBG_KNL, " %s", iface->ifname);
|
||||
addrs = iface->addrs->create_enumerator(iface->addrs);
|
||||
while (addrs->enumerate(addrs, (void**)&addr))
|
||||
{
|
||||
DBG1(DBG_KNL, " %H", addr->ip);
|
||||
}
|
||||
addrs->destroy(addrs);
|
||||
}
|
||||
}
|
||||
ifaces->destroy(ifaces);
|
||||
|
||||
return SUCCESS;
|
||||
}
|
||||
|
||||
/**
|
||||
* Implementation of kernel_netlink_net_t.destroy.
|
||||
*/
|
||||
static void destroy(private_kernel_pfroute_net_t *this)
|
||||
{
|
||||
if (this->job)
|
||||
{
|
||||
this->job->cancel(this->job);
|
||||
}
|
||||
if (this->socket > 0)
|
||||
{
|
||||
close(this->socket);
|
||||
}
|
||||
if (this->socket_events)
|
||||
{
|
||||
close(this->socket_events);
|
||||
}
|
||||
this->ifaces->destroy_function(this->ifaces, (void*)iface_entry_destroy);
|
||||
this->mutex->destroy(this->mutex);
|
||||
this->mutex_pfroute->destroy(this->mutex_pfroute);
|
||||
free(this);
|
||||
}
|
||||
|
||||
/*
|
||||
* Described in header.
|
||||
*/
|
||||
kernel_pfroute_net_t *kernel_pfroute_net_create()
|
||||
{
|
||||
private_kernel_pfroute_net_t *this = malloc_thing(private_kernel_pfroute_net_t);
|
||||
|
||||
/* public functions */
|
||||
this->public.interface.get_interface = (char*(*)(kernel_net_t*,host_t*))get_interface_name;
|
||||
this->public.interface.create_address_enumerator = (enumerator_t*(*)(kernel_net_t*,bool,bool))create_address_enumerator;
|
||||
this->public.interface.get_source_addr = (host_t*(*)(kernel_net_t*, host_t *dest, host_t *src))get_source_addr;
|
||||
this->public.interface.get_nexthop = (host_t*(*)(kernel_net_t*, host_t *dest))get_nexthop;
|
||||
this->public.interface.add_ip = (status_t(*)(kernel_net_t*,host_t*,host_t*)) add_ip;
|
||||
this->public.interface.del_ip = (status_t(*)(kernel_net_t*,host_t*)) del_ip;
|
||||
this->public.interface.add_route = (status_t(*)(kernel_net_t*,chunk_t,u_int8_t,host_t*,host_t*,char*)) add_route;
|
||||
this->public.interface.del_route = (status_t(*)(kernel_net_t*,chunk_t,u_int8_t,host_t*,host_t*,char*)) del_route;
|
||||
|
||||
this->public.interface.destroy = (void(*)(kernel_net_t*)) destroy;
|
||||
|
||||
/* private members */
|
||||
this->ifaces = linked_list_create();
|
||||
this->mutex = mutex_create(MUTEX_TYPE_DEFAULT);
|
||||
this->mutex_pfroute = mutex_create(MUTEX_TYPE_DEFAULT);
|
||||
|
||||
this->seq = 0;
|
||||
this->socket_events = 0;
|
||||
this->job = NULL;
|
||||
|
||||
/* create a PF_ROUTE socket to communicate with the kernel */
|
||||
this->socket = socket(PF_ROUTE, SOCK_RAW, AF_UNSPEC);
|
||||
if (this->socket < 0)
|
||||
{
|
||||
DBG1(DBG_KNL, "unable to create PF_ROUTE socket");
|
||||
destroy(this);
|
||||
return NULL;
|
||||
}
|
||||
|
||||
/* create a PF_ROUTE socket to receive events */
|
||||
this->socket_events = socket(PF_ROUTE, SOCK_RAW, AF_UNSPEC);
|
||||
if (this->socket_events < 0)
|
||||
{
|
||||
DBG1(DBG_KNL, "unable to create PF_ROUTE event socket");
|
||||
destroy(this);
|
||||
return NULL;
|
||||
}
|
||||
|
||||
this->job = callback_job_create((callback_job_cb_t)receive_events,
|
||||
this, NULL, NULL);
|
||||
hydra->processor->queue_job(hydra->processor, (job_t*)this->job);
|
||||
|
||||
if (init_address_list(this) != SUCCESS)
|
||||
{
|
||||
DBG1(DBG_KNL, "unable to get interface list");
|
||||
destroy(this);
|
||||
return NULL;
|
||||
}
|
||||
|
||||
return &this->public;
|
||||
}
|
||||
@@ -0,0 +1,46 @@
|
||||
/*
|
||||
* Copyright (C) 2009 Tobias Brunner
|
||||
* Hochschule fuer Technik Rapperswil
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify it
|
||||
* under the terms of the GNU General Public License as published by the
|
||||
* Free Software Foundation; either version 2 of the License, or (at your
|
||||
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
|
||||
*
|
||||
* This program is distributed in the hope that it will be useful, but
|
||||
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
|
||||
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
||||
* for more details.
|
||||
*/
|
||||
|
||||
/**
|
||||
* @defgroup kernel_pfroute_net_i kernel_pfroute_net
|
||||
* @{ @ingroup kernel_pfroute
|
||||
*/
|
||||
|
||||
#ifndef KERNEL_PFROUTE_NET_H_
|
||||
#define KERNEL_PFROUTE_NET_H_
|
||||
|
||||
#include <kernel/kernel_net.h>
|
||||
|
||||
typedef struct kernel_pfroute_net_t kernel_pfroute_net_t;
|
||||
|
||||
/**
|
||||
* Implementation of the kernel net interface using PF_ROUTE.
|
||||
*/
|
||||
struct kernel_pfroute_net_t {
|
||||
|
||||
/**
|
||||
* Implements kernel_net_t interface
|
||||
*/
|
||||
kernel_net_t interface;
|
||||
};
|
||||
|
||||
/**
|
||||
* Create a PF_ROUTE kernel net interface instance.
|
||||
*
|
||||
* @return kernel_pfroute_net_t instance
|
||||
*/
|
||||
kernel_pfroute_net_t *kernel_pfroute_net_create();
|
||||
|
||||
#endif /** KERNEL_PFROUTE_NET_H_ @}*/
|
||||
@@ -0,0 +1,58 @@
|
||||
/*
|
||||
* Copyright (C) 2009 Tobias Brunner
|
||||
* Hochschule fuer Technik Rapperswil
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify it
|
||||
* under the terms of the GNU General Public License as published by the
|
||||
* Free Software Foundation; either version 2 of the License, or (at your
|
||||
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
|
||||
*
|
||||
* This program is distributed in the hope that it will be useful, but
|
||||
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
|
||||
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
||||
* for more details.
|
||||
*/
|
||||
|
||||
|
||||
#include "kernel_pfroute_plugin.h"
|
||||
|
||||
#include "kernel_pfroute_net.h"
|
||||
|
||||
#include <hydra.h>
|
||||
|
||||
typedef struct private_kernel_pfroute_plugin_t private_kernel_pfroute_plugin_t;
|
||||
|
||||
/**
|
||||
* private data of kernel PF_ROUTE plugin
|
||||
*/
|
||||
struct private_kernel_pfroute_plugin_t {
|
||||
/**
|
||||
* implements plugin interface
|
||||
*/
|
||||
kernel_pfroute_plugin_t public;
|
||||
};
|
||||
|
||||
/**
|
||||
* Implementation of plugin_t.destroy
|
||||
*/
|
||||
static void destroy(private_kernel_pfroute_plugin_t *this)
|
||||
{
|
||||
hydra->kernel_interface->remove_net_interface(hydra->kernel_interface,
|
||||
(kernel_net_constructor_t)kernel_pfroute_net_create);
|
||||
free(this);
|
||||
}
|
||||
|
||||
/*
|
||||
* see header file
|
||||
*/
|
||||
plugin_t *kernel_pfroute_plugin_create()
|
||||
{
|
||||
private_kernel_pfroute_plugin_t *this = malloc_thing(private_kernel_pfroute_plugin_t);
|
||||
|
||||
this->public.plugin.destroy = (void(*)(plugin_t*))destroy;
|
||||
|
||||
hydra->kernel_interface->add_net_interface(hydra->kernel_interface,
|
||||
(kernel_net_constructor_t)kernel_pfroute_net_create);
|
||||
|
||||
return &this->public.plugin;
|
||||
}
|
||||
@@ -0,0 +1,42 @@
|
||||
/*
|
||||
* Copyright (C) 2009 Tobias Brunner
|
||||
* Hochschule fuer Technik Rapperswil
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify it
|
||||
* under the terms of the GNU General Public License as published by the
|
||||
* Free Software Foundation; either version 2 of the License, or (at your
|
||||
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
|
||||
*
|
||||
* This program is distributed in the hope that it will be useful, but
|
||||
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
|
||||
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
||||
* for more details.
|
||||
*/
|
||||
|
||||
/**
|
||||
* @defgroup kernel_pfroute kernel_pfroute
|
||||
* @ingroup hplugins
|
||||
*
|
||||
* @defgroup kernel_pfroute_plugin kernel_pfroute_plugin
|
||||
* @{ @ingroup kernel_pfroute
|
||||
*/
|
||||
|
||||
#ifndef KERNEL_PFROUTE_PLUGIN_H_
|
||||
#define KERNEL_PFROUTE_PLUGIN_H_
|
||||
|
||||
#include <plugins/plugin.h>
|
||||
|
||||
typedef struct kernel_pfroute_plugin_t kernel_pfroute_plugin_t;
|
||||
|
||||
/**
|
||||
* PF_ROUTE kernel interface plugin
|
||||
*/
|
||||
struct kernel_pfroute_plugin_t {
|
||||
|
||||
/**
|
||||
* implements plugin interface
|
||||
*/
|
||||
plugin_t plugin;
|
||||
};
|
||||
|
||||
#endif /** KERNEL_PFROUTE_PLUGIN_H_ @}*/
|
||||
Reference in New Issue
Block a user