ha: Skip SA for sync messages when resyncing HA segments
This commit is contained in:
@@ -42,6 +42,11 @@ struct private_ha_cache_t {
|
|||||||
*/
|
*/
|
||||||
ha_socket_t *socket;
|
ha_socket_t *socket;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Tunnel securing sync messages
|
||||||
|
*/
|
||||||
|
ha_tunnel_t *tunnel;
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Total number of segments
|
* Total number of segments
|
||||||
*/
|
*/
|
||||||
@@ -259,6 +264,10 @@ static void rekey_segment(private_ha_cache_t *this, u_int segment)
|
|||||||
charon->ike_sa_manager, TRUE);
|
charon->ike_sa_manager, TRUE);
|
||||||
while (enumerator->enumerate(enumerator, &ike_sa))
|
while (enumerator->enumerate(enumerator, &ike_sa))
|
||||||
{
|
{
|
||||||
|
if (this->tunnel && this->tunnel->is_sa(this->tunnel, ike_sa))
|
||||||
|
{
|
||||||
|
continue;
|
||||||
|
}
|
||||||
if (ike_sa->get_state(ike_sa) == IKE_ESTABLISHED &&
|
if (ike_sa->get_state(ike_sa) == IKE_ESTABLISHED &&
|
||||||
this->kernel->get_segment(this->kernel,
|
this->kernel->get_segment(this->kernel,
|
||||||
ike_sa->get_other_host(ike_sa)) == segment)
|
ike_sa->get_other_host(ike_sa)) == segment)
|
||||||
@@ -365,7 +374,7 @@ METHOD(ha_cache_t, destroy, void,
|
|||||||
* See header
|
* See header
|
||||||
*/
|
*/
|
||||||
ha_cache_t *ha_cache_create(ha_kernel_t *kernel, ha_socket_t *socket,
|
ha_cache_t *ha_cache_create(ha_kernel_t *kernel, ha_socket_t *socket,
|
||||||
bool sync, u_int count)
|
ha_tunnel_t *tunnel, bool sync, u_int count)
|
||||||
{
|
{
|
||||||
private_ha_cache_t *this;
|
private_ha_cache_t *this;
|
||||||
|
|
||||||
@@ -379,6 +388,7 @@ ha_cache_t *ha_cache_create(ha_kernel_t *kernel, ha_socket_t *socket,
|
|||||||
.count = count,
|
.count = count,
|
||||||
.kernel = kernel,
|
.kernel = kernel,
|
||||||
.socket = socket,
|
.socket = socket,
|
||||||
|
.tunnel = tunnel,
|
||||||
.cache = hashtable_create(hashtable_hash_ptr, hashtable_equals_ptr, 8),
|
.cache = hashtable_create(hashtable_hash_ptr, hashtable_equals_ptr, 8),
|
||||||
.mutex = mutex_create(MUTEX_TYPE_DEFAULT),
|
.mutex = mutex_create(MUTEX_TYPE_DEFAULT),
|
||||||
);
|
);
|
||||||
|
|||||||
@@ -73,6 +73,6 @@ struct ha_cache_t {
|
|||||||
* @param count total number of segments
|
* @param count total number of segments
|
||||||
*/
|
*/
|
||||||
ha_cache_t *ha_cache_create(ha_kernel_t *kernel, ha_socket_t *socket,
|
ha_cache_t *ha_cache_create(ha_kernel_t *kernel, ha_socket_t *socket,
|
||||||
bool resync, u_int count);
|
ha_tunnel_t *tunnel, bool resync, u_int count);
|
||||||
|
|
||||||
#endif /** HA_CACHE_H_ @}*/
|
#endif /** HA_CACHE_H_ @}*/
|
||||||
|
|||||||
@@ -137,7 +137,8 @@ static bool initialize_plugin(private_ha_plugin_t *this)
|
|||||||
this->kernel = ha_kernel_create(count);
|
this->kernel = ha_kernel_create(count);
|
||||||
this->segments = ha_segments_create(this->socket, this->kernel, this->tunnel,
|
this->segments = ha_segments_create(this->socket, this->kernel, this->tunnel,
|
||||||
count, strcmp(local, remote) > 0, monitor);
|
count, strcmp(local, remote) > 0, monitor);
|
||||||
this->cache = ha_cache_create(this->kernel, this->socket, resync, count);
|
this->cache = ha_cache_create(this->kernel, this->socket, this->tunnel,
|
||||||
|
resync, count);
|
||||||
if (fifo)
|
if (fifo)
|
||||||
{
|
{
|
||||||
this->ctl = ha_ctl_create(this->segments, this->cache);
|
this->ctl = ha_ctl_create(this->segments, this->cache);
|
||||||
|
|||||||
Reference in New Issue
Block a user