Moving charon to libcharon.

This commit is contained in:
Tobias Brunner
2010-03-19 13:34:52 +01:00
parent 7c11d10eb8
commit 08c5572602
480 changed files with 0 additions and 0 deletions
+18
View File
@@ -0,0 +1,18 @@
INCLUDES = -I$(top_srcdir)/src/libstrongswan -I$(top_srcdir)/src/charon
AM_CFLAGS = -rdynamic
if MONOLITHIC
noinst_LTLIBRARIES = libstrongswan-uci.la
else
plugin_LTLIBRARIES = libstrongswan-uci.la
endif
libstrongswan_uci_la_SOURCES = \
uci_plugin.h uci_plugin.c uci_parser.h uci_parser.c \
uci_config.h uci_config.c uci_creds.h uci_creds.c \
uci_control.h uci_control.c
libstrongswan_uci_la_LDFLAGS = -module -avoid-version
libstrongswan_uci_la_LIBADD = -luci
+361
View File
@@ -0,0 +1,361 @@
/*
* Copyright (C) 2008 Thomas Kallenberg
* Copyright (C) 2008 Tobias Brunner
* Copyright (C) 2008 Martin Willi
* Hochschule fuer Technik Rapperswil
*
* This program is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License as published by the
* Free Software Foundation; either version 2 of the License, or (at your
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
*
* This program is distributed in the hope that it will be useful, but
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* for more details.
*/
#define _GNU_SOURCE
#include <string.h>
#include "uci_config.h"
#include "uci_parser.h"
#include <daemon.h>
typedef struct private_uci_config_t private_uci_config_t;
/**
* Private data of an uci_config_t object
*/
struct private_uci_config_t {
/**
* Public part
*/
uci_config_t public;
/**
* UCI parser context
*/
uci_parser_t *parser;
};
/**
* enumerator implementation for create_peer_cfg_enumerator
*/
typedef struct {
/** implements enumerator */
enumerator_t public;
/** currently enumerated peer config */
peer_cfg_t *peer_cfg;
/** inner uci_parser section enumerator */
enumerator_t *inner;
} peer_enumerator_t;
/**
* create a proposal from a string, with fallback to default
*/
static proposal_t *create_proposal(char *string, protocol_id_t proto)
{
proposal_t *proposal = NULL;
if (string)
{
proposal = proposal_create_from_string(proto, string);
}
if (!proposal)
{ /* UCI default is aes/sha1 only */
if (proto == PROTO_IKE)
{
proposal = proposal_create_from_string(proto,
"aes128-aes192-aes256-sha1-modp1536-modp2048");
}
else
{
proposal = proposal_create_from_string(proto,
"aes128-aes192-aes256-sha1");
}
}
return proposal;
}
/**
* create an traffic selector, fallback to dynamic
*/
static traffic_selector_t *create_ts(char *string)
{
if (string)
{
int netbits = 32;
host_t *net;
char *pos;
string = strdupa(string);
pos = strchr(string, '/');
if (pos)
{
*pos++ = '\0';
netbits = atoi(pos);
}
else
{
if (strchr(string, ':'))
{
netbits = 128;
}
}
net = host_create_from_string(string, 0);
if (net)
{
return traffic_selector_create_from_subnet(net, netbits, 0, 0);
}
}
return traffic_selector_create_dynamic(0, 0, 65535);
}
/**
* create a rekey time from a string with hours, with fallback
*/
static u_int create_rekey(char *string)
{
u_int rekey = 0;
if (string)
{
rekey = atoi(string);
if (rekey)
{
return rekey * 3600;
}
}
/* every 12 hours */
return 12 * 3600;
}
/**
* Implementation of peer_enumerator_t.public.enumerate
*/
static bool peer_enumerator_enumerate(peer_enumerator_t *this, peer_cfg_t **cfg)
{
char *name, *ike_proposal, *esp_proposal, *ike_rekey, *esp_rekey;
char *local_id, *local_addr, *local_net;
char *remote_id, *remote_addr, *remote_net;
child_cfg_t *child_cfg;
ike_cfg_t *ike_cfg;
auth_cfg_t *auth;
lifetime_cfg_t lifetime = {
.time = {
.life = create_rekey(esp_rekey) + 300,
.rekey = create_rekey(esp_rekey),
.jitter = 300
}
};
/* defaults */
name = "unnamed";
local_id = NULL;
remote_id = NULL;
local_addr = "0.0.0.0";
remote_addr = "0.0.0.0";
local_net = NULL;
remote_net = NULL;
ike_proposal = NULL;
esp_proposal = NULL;
ike_rekey = NULL;
esp_rekey = NULL;
if (this->inner->enumerate(this->inner, &name, &local_id, &remote_id,
&local_addr, &remote_addr, &local_net, &remote_net,
&ike_proposal, &esp_proposal, &ike_rekey, &esp_rekey))
{
DESTROY_IF(this->peer_cfg);
ike_cfg = ike_cfg_create(FALSE, FALSE,
local_addr, IKEV2_UDP_PORT, remote_addr, IKEV2_UDP_PORT);
ike_cfg->add_proposal(ike_cfg, create_proposal(ike_proposal, PROTO_IKE));
this->peer_cfg = peer_cfg_create(
name, 2, ike_cfg, CERT_SEND_IF_ASKED, UNIQUE_NO,
1, create_rekey(ike_rekey), 0, /* keytries, rekey, reauth */
1800, 900, /* jitter, overtime */
TRUE, 60, /* mobike, dpddelay */
NULL, NULL, /* vip, pool */
FALSE, NULL, NULL); /* mediation, med by, peer id */
auth = auth_cfg_create();
auth->add(auth, AUTH_RULE_AUTH_CLASS, AUTH_CLASS_PSK);
auth->add(auth, AUTH_RULE_IDENTITY,
identification_create_from_string(local_id));
this->peer_cfg->add_auth_cfg(this->peer_cfg, auth, TRUE);
auth = auth_cfg_create();
auth->add(auth, AUTH_RULE_AUTH_CLASS, AUTH_CLASS_PSK);
if (remote_id)
{
auth->add(auth, AUTH_RULE_IDENTITY,
identification_create_from_string(remote_id));
}
this->peer_cfg->add_auth_cfg(this->peer_cfg, auth, FALSE);
child_cfg = child_cfg_create(name, &lifetime, NULL, TRUE, MODE_TUNNEL,
ACTION_NONE, ACTION_NONE, FALSE, 0);
child_cfg->add_proposal(child_cfg, create_proposal(esp_proposal, PROTO_ESP));
child_cfg->add_traffic_selector(child_cfg, TRUE, create_ts(local_net));
child_cfg->add_traffic_selector(child_cfg, FALSE, create_ts(remote_net));
this->peer_cfg->add_child_cfg(this->peer_cfg, child_cfg);
*cfg = this->peer_cfg;
return TRUE;
}
return FALSE;
}
/**
* Implementation of peer_enumerator_t.public.destroy
*/
static void peer_enumerator_destroy(peer_enumerator_t *this)
{
DESTROY_IF(this->peer_cfg);
this->inner->destroy(this->inner);
free(this);
}
/**
* Implementation of backend_t.create_peer_cfg_enumerator.
*/
static enumerator_t* create_peer_cfg_enumerator(private_uci_config_t *this,
identification_t *me,
identification_t *other)
{
peer_enumerator_t *e = malloc_thing(peer_enumerator_t);
e->public.enumerate = (void*)peer_enumerator_enumerate;
e->public.destroy = (void*)peer_enumerator_destroy;
e->peer_cfg = NULL;
e->inner = this->parser->create_section_enumerator(this->parser,
"local_id", "remote_id", "local_addr", "remote_addr",
"local_net", "remote_net", "ike_proposal", "esp_proposal",
"ike_rekey", "esp_rekey", NULL);
if (!e->inner)
{
free(e);
return NULL;
}
return &e->public;
}
/**
* enumerator implementation for create_ike_cfg_enumerator
*/
typedef struct {
/** implements enumerator */
enumerator_t public;
/** currently enumerated ike config */
ike_cfg_t *ike_cfg;
/** inner uci_parser section enumerator */
enumerator_t *inner;
} ike_enumerator_t;
/**
* Implementation of peer_enumerator_t.public.enumerate
*/
static bool ike_enumerator_enumerate(ike_enumerator_t *this, ike_cfg_t **cfg)
{
char *local_addr, *remote_addr, *ike_proposal;
/* defaults */
local_addr = "0.0.0.0";
remote_addr = "0.0.0.0";
ike_proposal = NULL;
if (this->inner->enumerate(this->inner, NULL,
&local_addr, &remote_addr, &ike_proposal))
{
DESTROY_IF(this->ike_cfg);
this->ike_cfg = ike_cfg_create(FALSE, FALSE, local_addr, IKEV2_UDP_PORT,
remote_addr, IKEV2_UDP_PORT);
this->ike_cfg->add_proposal(this->ike_cfg,
create_proposal(ike_proposal, PROTO_IKE));
*cfg = this->ike_cfg;
return TRUE;
}
return FALSE;
}
/**
* Implementation of ike_enumerator_t.public.destroy
*/
static void ike_enumerator_destroy(ike_enumerator_t *this)
{
DESTROY_IF(this->ike_cfg);
this->inner->destroy(this->inner);
free(this);
}
/**
* Implementation of backend_t.create_ike_cfg_enumerator.
*/
static enumerator_t* create_ike_cfg_enumerator(private_uci_config_t *this,
host_t *me, host_t *other)
{
ike_enumerator_t *e = malloc_thing(ike_enumerator_t);
e->public.enumerate = (void*)ike_enumerator_enumerate;
e->public.destroy = (void*)ike_enumerator_destroy;
e->ike_cfg = NULL;
e->inner = this->parser->create_section_enumerator(this->parser,
"local_addr", "remote_addr", "ike_proposal", NULL);
if (!e->inner)
{
free(e);
return NULL;
}
return &e->public;
}
/**
* implements backend_t.get_peer_cfg_by_name.
*/
static peer_cfg_t *get_peer_cfg_by_name(private_uci_config_t *this, char *name)
{
enumerator_t *enumerator;
peer_cfg_t *current, *found = NULL;
enumerator = create_peer_cfg_enumerator(this, NULL, NULL);
if (enumerator)
{
while (enumerator->enumerate(enumerator, &current))
{
if (streq(name, current->get_name(current)))
{
found = current->get_ref(current);
break;
}
}
enumerator->destroy(enumerator);
}
return found;
}
/**
* Implementation of uci_config_t.destroy.
*/
static void destroy(private_uci_config_t *this)
{
free(this);
}
/**
* Described in header.
*/
uci_config_t *uci_config_create(uci_parser_t *parser)
{
private_uci_config_t *this = malloc_thing(private_uci_config_t);
this->public.backend.create_peer_cfg_enumerator = (enumerator_t*(*)(backend_t*, identification_t *me, identification_t *other))create_peer_cfg_enumerator;
this->public.backend.create_ike_cfg_enumerator = (enumerator_t*(*)(backend_t*, host_t *me, host_t *other))create_ike_cfg_enumerator;
this->public.backend.get_peer_cfg_by_name = (peer_cfg_t* (*)(backend_t*,char*))get_peer_cfg_by_name;
this->public.destroy = (void(*)(uci_config_t*))destroy;
this->parser = parser;
return &this->public;
}
+55
View File
@@ -0,0 +1,55 @@
/*
* Copyright (C) 2008 Martin Willi
* Copyright (C) 2008 Thomas Kallenberg
* Hochschule fuer Technik Rapperswil
*
* This program is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License as published by the
* Free Software Foundation; either version 2 of the License, or (at your
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
*
* This program is distributed in the hope that it will be useful, but
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* for more details.
*/
/**
* @defgroup uci_config_t uci_config
* @{ @ingroup uci
*/
#ifndef UCI_CONFIG_H_
#define UCI_CONFIG_H_
#include "uci_parser.h"
#include <config/backend.h>
typedef struct uci_config_t uci_config_t;
/**
* OpenWRT UCI configuration backend.
*/
struct uci_config_t {
/**
* Implements backend_t interface
*/
backend_t backend;
/**
* Destroy the backend.
*/
void (*destroy)(uci_config_t *this);
};
/**
* Create a UCI based configuration backend.
*
* @param parser UCI parser to use
* @return configuration backend
*/
uci_config_t *uci_config_create(uci_parser_t *parser);
#endif /** UCI_CONFIG_H_ @}*/
+301
View File
@@ -0,0 +1,301 @@
/*
* Copyright (C) 2008 Thomas Kallenberg
* Copyright (C) 2008 Martin Willi
* Hochschule fuer Technik Rapperswil
*
* This program is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License as published by the
* Free Software Foundation; either version 2 of the License, or (at your
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
*
* This program is distributed in the hope that it will be useful, but
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* for more details.
*/
#define _GNU_SOURCE
#include <string.h>
#include <stdio.h>
#include <unistd.h>
#include <sys/types.h>
#include <sys/stat.h>
#include <errno.h>
#include "uci_control.h"
#include <daemon.h>
#include <threading/thread.h>
#include <processing/jobs/callback_job.h>
#define FIFO_FILE "/var/run/charon.fifo"
typedef struct private_uci_control_t private_uci_control_t;
/**
* private data of uci_control_t
*/
struct private_uci_control_t {
/**
* Public part
*/
uci_control_t public;
/**
* Job
*/
callback_job_t *job;
};
/**
* write answer to fifo
*/
static void write_fifo(private_uci_control_t *this, char *format, ...)
{
va_list args;
FILE *out;
out = fopen(FIFO_FILE, "w");
if (out)
{
va_start(args, format);
vfprintf(out, format, args);
va_end(args);
fclose(out);
}
else
{
DBG1(DBG_CFG, "writing to UCI fifo failed: %s", strerror(errno));
}
}
/**
* print IKE_SA status information
*/
static void status(private_uci_control_t *this, char *name)
{
enumerator_t *configs, *sas;
iterator_t *children;
ike_sa_t *ike_sa;
child_sa_t *child_sa;
peer_cfg_t *peer_cfg;
char buf[2048];
FILE *out = NULL;
configs = charon->backends->create_peer_cfg_enumerator(charon->backends,
NULL, NULL, NULL, NULL);
while (configs->enumerate(configs, &peer_cfg))
{
if (name && !streq(name, peer_cfg->get_name(peer_cfg)))
{
continue;
}
sas = charon->controller->create_ike_sa_enumerator(charon->controller);
while (sas->enumerate(sas, &ike_sa))
{
if (!streq(ike_sa->get_name(ike_sa), peer_cfg->get_name(peer_cfg)))
{
continue;
}
if (!out)
{
out = fmemopen(buf, sizeof(buf), "w");
if (!out)
{
continue;
}
}
fprintf(out, "%-8s %-20D %-16H ", ike_sa->get_name(ike_sa),
ike_sa->get_other_id(ike_sa), ike_sa->get_other_host(ike_sa));
children = ike_sa->create_child_sa_iterator(ike_sa);
while (children->iterate(children, (void**)&child_sa))
{
fprintf(out, "%#R",
child_sa->get_traffic_selectors(child_sa, FALSE));
}
children->destroy(children);
fprintf(out, "\n");
}
sas->destroy(sas);
}
configs->destroy(configs);
if (out)
{
fclose(out);
write_fifo(this, "%s", buf);
}
else
{
write_fifo(this, "");
}
}
/**
* Initiate an IKE_SA
*/
static void initiate(private_uci_control_t *this, char *name)
{
peer_cfg_t *peer_cfg;
child_cfg_t *child_cfg;
enumerator_t *enumerator;
peer_cfg = charon->backends->get_peer_cfg_by_name(charon->backends, name);
if (peer_cfg)
{
enumerator = peer_cfg->create_child_cfg_enumerator(peer_cfg);
if (enumerator->enumerate(enumerator, &child_cfg) &&
charon->controller->initiate(charon->controller, peer_cfg,
child_cfg->get_ref(child_cfg),
controller_cb_empty, NULL) == SUCCESS)
{
write_fifo(this, "connection '%s' established\n", name);
}
else
{
write_fifo(this, "establishing connection '%s' failed\n", name);
}
enumerator->destroy(enumerator);
}
else
{
write_fifo(this, "no connection named '%s' found\n", name);
}
}
/**
* terminate an IKE_SA
*/
static void terminate(private_uci_control_t *this, char *name)
{
enumerator_t *enumerator;
ike_sa_t *ike_sa;
u_int id;
enumerator = charon->controller->create_ike_sa_enumerator(charon->controller);
while (enumerator->enumerate(enumerator, &ike_sa))
{
if (streq(name, ike_sa->get_name(ike_sa)))
{
id = ike_sa->get_unique_id(ike_sa);
enumerator->destroy(enumerator);
charon->controller->terminate_ike(charon->controller, id,
controller_cb_empty, NULL);
write_fifo(this, "connection '%s' terminated\n", name);
return;
}
}
enumerator->destroy(enumerator);
write_fifo(this, "no active connection named '%s'\n", name);
}
/**
* dispatch control request
*/
static void process(private_uci_control_t *this, char *message)
{
enumerator_t* enumerator;
enumerator = enumerator_create_token(message, " \n", "");
if (enumerator->enumerate(enumerator, &message))
{
if (streq(message, "status"))
{
if (enumerator->enumerate(enumerator, &message))
{
status(this, message);
}
else
{
status(this, NULL);
}
}
else if (streq(message, "up") &&
enumerator->enumerate(enumerator, &message))
{
initiate(this, message);
}
else if (streq(message, "down") &&
enumerator->enumerate(enumerator, &message))
{
terminate(this, message);
}
else
{
write_fifo(this, "usage: status [<name>] | up <name> | down <name>\n"
" status format: name peer-id peer-addr tunnel(s)\n");
}
}
enumerator->destroy(enumerator);
}
/**
* read from fifo
*/
static job_requeue_t receive(private_uci_control_t *this)
{
char message[128];
int len;
bool oldstate;
FILE *in;
memset(message, 0, sizeof(message));
oldstate = thread_cancelability(TRUE);
in = fopen(FIFO_FILE, "r");
thread_cancelability(oldstate);
if (in)
{
len = fread(message, 1, sizeof(message) - 1, in);
fclose(in);
if (len > 0)
{
process(this, message);
}
else
{
DBG1(DBG_DMN, "reading from UCI fifo failed: %s", strerror(errno));
}
}
else
{
DBG1(DBG_DMN, "opening UCI fifo failed: %s", strerror(errno));
}
return JOB_REQUEUE_FAIR;
}
/**
* Implementation of uci_control_t.destroy
*/
static void destroy(private_uci_control_t *this)
{
this->job->cancel(this->job);
unlink(FIFO_FILE);
free(this);
}
/**
* Described in header.
*/
uci_control_t *uci_control_create()
{
private_uci_control_t *this = malloc_thing(private_uci_control_t);
this->public.destroy = (void(*)(uci_control_t*))destroy;
unlink(FIFO_FILE);
if (mkfifo(FIFO_FILE, S_IRUSR|S_IWUSR) != 0)
{
DBG1(DBG_CFG, "creating UCI control fifo '%s' failed: %s",
FIFO_FILE, strerror(errno));
}
else
{
this->job = callback_job_create((callback_job_cb_t)receive,
this, NULL, NULL);
charon->processor->queue_job(charon->processor, (job_t*)this->job);
}
return &this->public;
}
+42
View File
@@ -0,0 +1,42 @@
/*
* Copyright (C) 2008 Thomas Kallenberg
* Hochschule fuer Technik Rapperswil
*
* This program is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License as published by the
* Free Software Foundation; either version 2 of the License, or (at your
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
*
* This program is distributed in the hope that it will be useful, but
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* for more details.
*/
/**
* @defgroup uci_control_t uci_control
* @{ @ingroup uci
*/
#ifndef UCI_CONTROL_H_
#define UCI_CONTROL_H_
typedef struct uci_control_t uci_control_t;
/**
* UCI control interface, uses a simple FIFO file
*/
struct uci_control_t {
/**
* Destroy the controller
*/
void (*destroy)(uci_control_t *this);
};
/**
* Create a UCI based configuration backend.
*/
uci_control_t *uci_control_create();
#endif /** UCI_CONTROL_H_ @}*/
+174
View File
@@ -0,0 +1,174 @@
/*
* Copyright (C) 2008 Thomas Kallenberg
* Copyright (C) 2008 Martin Willi
* Copyright (C) 2008 Tobias Brunner
* Hochschule fuer Technik Rapperswil
*
* This program is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License as published by the
* Free Software Foundation; either version 2 of the License, or (at your
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
*
* This program is distributed in the hope that it will be useful, but
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* for more details.
*/
#include "uci_creds.h"
#include <daemon.h>
#include <credentials/keys/shared_key.h>
#include <utils/identification.h>
typedef struct private_uci_creds_t private_uci_creds_t;
/**
* Private data of an uci_creds_t object
*/
struct private_uci_creds_t {
/**
* Public part
*/
uci_creds_t public;
/**
* UCI parser context
*/
uci_parser_t *parser;
};
typedef struct {
/** implements enumerator */
enumerator_t public;
/** inneer UCI enumerator */
enumerator_t *inner;
/** currently enumerated shared shared */
shared_key_t *current;
/** local ID to match */
identification_t *me;
/** remote ID to match */
identification_t *other;
} shared_enumerator_t;
/**
* Implementation of shared_enumerator_t.public.enumerate
*/
static bool shared_enumerator_enumerate(shared_enumerator_t *this,
shared_key_t **key, id_match_t *me, id_match_t *other)
{
char *local_id, *remote_id, *psk;
identification_t *local, *remote;
while (TRUE)
{
/* defaults */
local_id = "%any";
remote_id = "%any";
psk = NULL;
if (!this->inner->enumerate(this->inner, NULL,
&local_id, &remote_id, &psk))
{
return FALSE;
}
if (psk == NULL)
{
continue;
}
if (me)
{
local = identification_create_from_string(local_id);
*me = this->me ? this->me->matches(this->me, local)
: ID_MATCH_ANY;
local->destroy(local);
if (!*me)
{
continue;
}
}
if (other)
{
remote = identification_create_from_string(remote_id);
*other = this->other ? this->other->matches(this->other, remote)
: ID_MATCH_ANY;
remote->destroy(remote);
if (!*other)
{
continue;
}
}
break;
}
DESTROY_IF(this->current);
this->current = shared_key_create(SHARED_IKE,
chunk_clone(chunk_create(psk, strlen(psk))));
*key = this->current;
return TRUE;
}
/**
* Implementation of shared_enumerator_t.public.destroy
*/
static void shared_enumerator_destroy(shared_enumerator_t *this)
{
this->inner->destroy(this->inner);
DESTROY_IF(this->current);
free(this);
}
/**
* Implementation of backend_t.create_shared_cfg_enumerator.
*/
static enumerator_t* create_shared_enumerator(private_uci_creds_t *this,
shared_key_type_t type,
identification_t *me,
identification_t *other)
{
shared_enumerator_t *e;
if (type != SHARED_IKE)
{
return NULL;
}
e = malloc_thing(shared_enumerator_t);
e->current = NULL;
e->public.enumerate = (void*)shared_enumerator_enumerate;
e->public.destroy = (void*)shared_enumerator_destroy;
e->me = me;
e->other = other;
e->inner = this->parser->create_section_enumerator(this->parser,
"local_id", "remote_id", "psk", NULL);
if (!e->inner)
{
free(e);
return NULL;
}
return &e->public;
}
/**
* Implementation of uci_creds_t.destroy
*/
static void destroy(private_uci_creds_t *this)
{
free(this);
}
uci_creds_t *uci_creds_create(uci_parser_t *parser)
{
private_uci_creds_t *this = malloc_thing(private_uci_creds_t);
this->public.credential_set.create_shared_enumerator = (enumerator_t*(*)(credential_set_t*, shared_key_type_t, identification_t*, identification_t*))create_shared_enumerator;
this->public.credential_set.create_private_enumerator = (enumerator_t*(*) (credential_set_t*, key_type_t, identification_t*))return_null;
this->public.credential_set.create_cert_enumerator = (enumerator_t*(*) (credential_set_t*, certificate_type_t, key_type_t,identification_t *, bool))return_null;
this->public.credential_set.create_cdp_enumerator = (enumerator_t*(*) (credential_set_t *,certificate_type_t, identification_t *))return_null;
this->public.credential_set.cache_cert = (void (*)(credential_set_t *, certificate_t *))nop;
this->public.destroy = (void(*) (uci_creds_t*))destroy;
this->parser = parser;
return &this->public;
}
+55
View File
@@ -0,0 +1,55 @@
/*
* Copyright (C) 2008 Martin Willi
* Copyright (C) 2008 Thomas Kallenberg
* Hochschule fuer Technik Rapperswil
*
* This program is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License as published by the
* Free Software Foundation; either version 2 of the License, or (at your
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
*
* This program is distributed in the hope that it will be useful, but
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* for more details.
*/
/**
* @defgroup uci_creds_t uci_creds
* @{ @ingroup uci
*/
#ifndef UCI_CREDS_H_
#define UCI_CREDS_H_
#include "uci_parser.h"
#include <credentials/credential_set.h>
typedef struct uci_creds_t uci_creds_t;
/**
* OpenWRT UCI credential set implementation.
*/
struct uci_creds_t {
/**
* Implements credential set interface.
*/
credential_set_t credential_set;
/**
* Destroy the backend.
*/
void (*destroy)(uci_creds_t *this);
};
/**
* Create a UCI based credential set.
*
* @param parser UCI parser to use
* @return credential set
*/
uci_creds_t *uci_creds_create(uci_parser_t *parser);
#endif /** UCI_CREDS_H_ @}*/
+186
View File
@@ -0,0 +1,186 @@
/*
* Copyright (C) 2008 Martin Willi
* Copyright (C) 2008 Thomas Kallenberg
* Hochschule fuer Technik Rapperswil
*
* This program is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License as published by the
* Free Software Foundation; either version 2 of the License, or (at your
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
*
* This program is distributed in the hope that it will be useful, but
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* for more details.
*/
#include "uci_parser.h"
#include <stdarg.h>
#include <library.h>
#include <uci.h>
typedef struct private_uci_parser_t private_uci_parser_t;
/**
* Private data of an uci_parser_t object
*/
struct private_uci_parser_t {
/**
* Public part
*/
uci_parser_t public;
/**
* UCI package name this parser reads
*/
char *package;
};
/**
* enumerator implementation create_section_enumerator
*/
typedef struct {
/** implements enumerator */
enumerator_t public;
/** currently enumerated uci section */
struct uci_element *current;
/** all uci ipsec config sections */
struct uci_list *list;
/** uci conntext */
struct uci_context *ctx;
/** ipsec uci package */
struct uci_package *package;
/** NULL terminated list of keywords */
char *keywords[];
} section_enumerator_t;
/**
* Implementation of section_enumerator_t.enumerate
*/
static bool section_enumerator_enumerate(section_enumerator_t *this, ...)
{
struct uci_element *element;
char **value;
va_list args;
int i;
if (&this->current->list == this->list)
{
return FALSE;
}
va_start(args, this);
value = va_arg(args, char**);
if (value)
{
if (uci_lookup(this->ctx, &element, this->package,
this->current->name, "name") == UCI_OK)
{ /* use "name" attribute as config name if available ... */
*value = uci_to_option(element)->value;
}
else
{ /* ... or the section name becomes config name */
*value = uci_to_section(this->current)->type;
}
}
/* followed by keyword parameters */
for (i = 0; this->keywords[i]; i++)
{
value = va_arg(args, char**);
if (value && uci_lookup(this->ctx, &element, this->package,
this->current->name, this->keywords[i]) == UCI_OK)
{
*value = uci_to_option(element)->value;
}
}
va_end(args);
this->current = list_to_element(this->current->list.next);
return TRUE;
}
/**
* Implementation of section_enumerator_t.public.destroy
*/
static void section_enumerator_destroy(section_enumerator_t *this)
{
uci_free_context(this->ctx);
free(this);
}
/**
* Implementation of backend_t.create_section_enumerator.
*/
static enumerator_t* create_section_enumerator(private_uci_parser_t *this, ...)
{
section_enumerator_t *e;
va_list args;
int i;
/* allocate enumerator large enought to hold keyword pointers */
i = 1;
va_start(args, this);
while (va_arg(args, char*))
{
i++;
}
va_end(args);
e = malloc(sizeof(section_enumerator_t) + sizeof(char*) * i);
i = 0;
va_start(args, this);
do
{
e->keywords[i] = va_arg(args, char*);
}
while (e->keywords[i++]);
va_end(args);
e->public.enumerate = (void*)section_enumerator_enumerate;
e->public.destroy = (void*)section_enumerator_destroy;
/* load uci context */
e->ctx = uci_alloc_context();
if (uci_load(e->ctx, this->package, &e->package) != UCI_OK)
{
section_enumerator_destroy(e);
return NULL;
}
e->list = &e->package->sections;
e->current = list_to_element(e->list->next);
if (e->current->type != UCI_TYPE_SECTION)
{
section_enumerator_destroy(e);
return NULL;
}
return &e->public;
}
/**
* Implementation of uci_parser_t.destroy.
*/
static void destroy(private_uci_parser_t *this)
{
free(this->package);
free(this);
}
/**
* Described in header.
*/
uci_parser_t *uci_parser_create(char *package)
{
private_uci_parser_t *this = malloc_thing(private_uci_parser_t);
this->public.create_section_enumerator = (enumerator_t*(*)(uci_parser_t*, ...))create_section_enumerator;
this->public.destroy = (void(*)(uci_parser_t*))destroy;
this->package = strdup(package);
return &this->public;
}
+59
View File
@@ -0,0 +1,59 @@
/*
* Copyright (C) 2008 Martin Willi
* Copyright (C) 2008 Thomas Kallenberg
* Hochschule fuer Technik Rapperswil
*
* This program is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License as published by the
* Free Software Foundation; either version 2 of the License, or (at your
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
*
* This program is distributed in the hope that it will be useful, but
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* for more details.
*/
/**
* @defgroup uci_parser_t uci_parser
* @{ @ingroup uci
*/
#ifndef UCI_PARSER_H_
#define UCI_PARSER_H_
#include <utils/enumerator.h>
typedef struct uci_parser_t uci_parser_t;
/**
* Wrapper to parse UCI sections with an enumerator.
*/
struct uci_parser_t {
/**
* Create an enumerator over a section.
*
* The enumerator returns a section name followed by values for the keywords
* specified in the variable argument list of this function.
*
* @param ... variable argument list with keywords, NULL terminated
* @return enumerator over sections
*/
enumerator_t* (*create_section_enumerator)(uci_parser_t *this, ...);
/**
* Destroy the parser.
*/
void (*destroy)(uci_parser_t *this);
};
/**
* Create a UCI parser.
*
* @param package UCI package this parser should read
* @return parser context
*/
uci_parser_t *uci_parser_create(char *package);
#endif /** UCI_PARSER_H_ @}*/
+93
View File
@@ -0,0 +1,93 @@
/*
* Copyright (C) 2008 Thomas Kallenberg
* Hochschule fuer Technik Rapperswil
*
* This program is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License as published by the
* Free Software Foundation; either version 2 of the License, or (at your
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
*
* This program is distributed in the hope that it will be useful, but
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* for more details.
*/
#include "uci_plugin.h"
#include "uci_config.h"
#include "uci_creds.h"
#include "uci_control.h"
#include <daemon.h>
/**
* UCI package name to use for lookups
*/
#define UCI_PACKAGE "strongswan"
typedef struct private_uci_plugin_t private_uci_plugin_t;
/**
* private data of uci plugin
*/
struct private_uci_plugin_t {
/**
* implements plugin interface
*/
uci_plugin_t public;
/**
* UCI configuration backend
*/
uci_config_t *config;
/**
* UCI credential set implementation
*/
uci_creds_t *creds;
/**
* UCI parser wrapper
*/
uci_parser_t *parser;
/**
* UCI control interface
*/
uci_control_t *control;
};
/**
* Implementation of plugin_t.destroy
*/
static void destroy(private_uci_plugin_t *this)
{
charon->backends->remove_backend(charon->backends, &this->config->backend);
charon->credentials->remove_set(charon->credentials, &this->creds->credential_set);
this->config->destroy(this->config);
this->creds->destroy(this->creds);
this->parser->destroy(this->parser);
this->control->destroy(this->control);
free(this);
}
/*
* see header file
*/
plugin_t *uci_plugin_create()
{
private_uci_plugin_t *this = malloc_thing(private_uci_plugin_t);
this->public.plugin.destroy = (void(*)(plugin_t*))destroy;
this->parser = uci_parser_create(UCI_PACKAGE);
this->config = uci_config_create(this->parser);
this->creds = uci_creds_create(this->parser);
this->control = uci_control_create();
charon->backends->add_backend(charon->backends, &this->config->backend);
charon->credentials->add_set(charon->credentials, &this->creds->credential_set);
return &this->public.plugin;
}
+43
View File
@@ -0,0 +1,43 @@
/*
* Copyright (C) 2008 Thomas Kallenberg
* Copyright (C) 2008 Martin Willi
* Hochschule fuer Technik Rapperswil
*
* This program is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License as published by the
* Free Software Foundation; either version 2 of the License, or (at your
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
*
* This program is distributed in the hope that it will be useful, but
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* for more details.
*/
/**
* @defgroup uci uci
* @ingroup cplugins
*
* @defgroup uci_plugin uci_plugin
* @{ @ingroup uci
*/
#ifndef UCI_PLUGIN_H_
#define UCI_PLUGIN_H_
#include <plugins/plugin.h>
typedef struct uci_plugin_t uci_plugin_t;
/**
* OpenWRT UCI (Unified Configuration Interface) configuration plugin.
*/
struct uci_plugin_t {
/**
* implements plugin interface
*/
plugin_t plugin;
};
#endif /** UCI_PLUGIN_H_ @}*/