Store IKE version of an SA on ike_sa_t.

This commit is contained in:
Tobias Brunner
2012-03-20 17:30:43 +01:00
parent 0fc9acdd23
commit 0b611540ef
7 changed files with 48 additions and 17 deletions
+1 -1
View File
@@ -89,7 +89,7 @@ static void process_ike_add(private_ha_dispatcher_t *this, ha_message_t *message
switch (attribute) switch (attribute)
{ {
case HA_IKE_ID: case HA_IKE_ID:
ike_sa = ike_sa_create(value.ike_sa_id); ike_sa = ike_sa_create(value.ike_sa_id, IKEV2);
break; break;
case HA_IKE_REKEY_ID: case HA_IKE_REKEY_ID:
old_sa = charon->ike_sa_manager->checkout(charon->ike_sa_manager, old_sa = charon->ike_sa_manager->checkout(charon->ike_sa_manager,
+16 -2
View File
@@ -86,6 +86,11 @@ struct private_ike_sa_t {
*/ */
ike_sa_id_t *ike_sa_id; ike_sa_id_t *ike_sa_id;
/**
* IKE version of this SA.
*/
ike_version_t version;
/** /**
* unique numerical ID for this IKE_SA. * unique numerical ID for this IKE_SA.
*/ */
@@ -1328,6 +1333,12 @@ METHOD(ike_sa_t, get_id, ike_sa_id_t*,
return this->ike_sa_id; return this->ike_sa_id;
} }
METHOD(ike_sa_t, get_version, ike_version_t,
private_ike_sa_t *this)
{
return this->version;
}
METHOD(ike_sa_t, get_my_id, identification_t*, METHOD(ike_sa_t, get_my_id, identification_t*,
private_ike_sa_t *this) private_ike_sa_t *this)
{ {
@@ -1606,7 +1617,8 @@ METHOD(ike_sa_t, reestablish, status_t,
return FAILED; return FAILED;
} }
new = charon->ike_sa_manager->checkout_new(charon->ike_sa_manager, TRUE); new = charon->ike_sa_manager->checkout_new(charon->ike_sa_manager,
this->version, TRUE);
new->set_peer_cfg(new, this->peer_cfg); new->set_peer_cfg(new, this->peer_cfg);
host = this->other_host; host = this->other_host;
new->set_other_host(new, host->clone(host)); new->set_other_host(new, host->clone(host));
@@ -2105,13 +2117,14 @@ METHOD(ike_sa_t, destroy, void,
/* /*
* Described in header. * Described in header.
*/ */
ike_sa_t * ike_sa_create(ike_sa_id_t *ike_sa_id) ike_sa_t * ike_sa_create(ike_sa_id_t *ike_sa_id, ike_version_t version)
{ {
private_ike_sa_t *this; private_ike_sa_t *this;
static u_int32_t unique_id = 0; static u_int32_t unique_id = 0;
INIT(this, INIT(this,
.public = { .public = {
.get_version = _get_version,
.get_state = _get_state, .get_state = _get_state,
.set_state = _set_state, .set_state = _set_state,
.get_name = _get_name, .get_name = _get_name,
@@ -2191,6 +2204,7 @@ ike_sa_t * ike_sa_create(ike_sa_id_t *ike_sa_id)
#endif /* ME */ #endif /* ME */
}, },
.ike_sa_id = ike_sa_id->clone(ike_sa_id), .ike_sa_id = ike_sa_id->clone(ike_sa_id),
.version = version,
.child_sas = linked_list_create(), .child_sas = linked_list_create(),
.my_host = host_create_any(AF_INET), .my_host = host_create_any(AF_INET),
.other_host = host_create_any(AF_INET), .other_host = host_create_any(AF_INET),
+10 -4
View File
@@ -269,6 +269,11 @@ struct ike_sa_t {
*/ */
ike_sa_id_t* (*get_id) (ike_sa_t *this); ike_sa_id_t* (*get_id) (ike_sa_t *this);
/**
* Gets the IKE version of the SA
*/
ike_version_t (*get_version)(ike_sa_t *this);
/** /**
* Get the numerical ID uniquely defining this IKE_SA. * Get the numerical ID uniquely defining this IKE_SA.
* *
@@ -288,7 +293,7 @@ struct ike_sa_t {
* *
* @param state state to set for the IKE_SA * @param state state to set for the IKE_SA
*/ */
void (*set_state) (ike_sa_t *this, ike_sa_state_t ike_sa); void (*set_state) (ike_sa_t *this, ike_sa_state_t state);
/** /**
* Get the name of the connection this IKE_SA uses. * Get the name of the connection this IKE_SA uses.
@@ -951,11 +956,12 @@ struct ike_sa_t {
}; };
/** /**
* Creates an ike_sa_t object with a specific ID. * Creates an ike_sa_t object with a specific ID and IKE version.
* *
* @param ike_sa_id ike_sa_id_t object to associate with new IKE_SA * @param ike_sa_id ike_sa_id_t to associate with new IKE_SA/ISAKMP_SA
* @param version IKE version of this SA
* @return ike_sa_t object * @return ike_sa_t object
*/ */
ike_sa_t *ike_sa_create(ike_sa_id_t *ike_sa_id); ike_sa_t *ike_sa_create(ike_sa_id_t *ike_sa_id, ike_version_t version);
#endif /** IKE_SA_H_ @}*/ #endif /** IKE_SA_H_ @}*/
+8 -5
View File
@@ -941,7 +941,7 @@ METHOD(ike_sa_manager_t, checkout, ike_sa_t*,
} }
METHOD(ike_sa_manager_t, checkout_new, ike_sa_t*, METHOD(ike_sa_manager_t, checkout_new, ike_sa_t*,
private_ike_sa_manager_t* this, bool initiator) private_ike_sa_manager_t* this, ike_version_t version, bool initiator)
{ {
ike_sa_id_t *ike_sa_id; ike_sa_id_t *ike_sa_id;
ike_sa_t *ike_sa; ike_sa_t *ike_sa;
@@ -954,7 +954,7 @@ METHOD(ike_sa_manager_t, checkout_new, ike_sa_t*,
{ {
ike_sa_id = ike_sa_id_create(0, get_spi(this), FALSE); ike_sa_id = ike_sa_id_create(0, get_spi(this), FALSE);
} }
ike_sa = ike_sa_create(ike_sa_id); ike_sa = ike_sa_create(ike_sa_id, version);
ike_sa_id->destroy(ike_sa_id); ike_sa_id->destroy(ike_sa_id);
DBG2(DBG_MGR, "created IKE_SA %s[%u]", ike_sa->get_name(ike_sa), DBG2(DBG_MGR, "created IKE_SA %s[%u]", ike_sa->get_name(ike_sa),
@@ -970,6 +970,7 @@ METHOD(ike_sa_manager_t, checkout_by_message, ike_sa_t*,
entry_t *entry; entry_t *entry;
ike_sa_t *ike_sa = NULL; ike_sa_t *ike_sa = NULL;
ike_sa_id_t *id; ike_sa_id_t *id;
ike_version_t ike_version;
bool is_init = FALSE; bool is_init = FALSE;
id = message->get_ike_sa_id(message); id = message->get_ike_sa_id(message);
@@ -985,6 +986,7 @@ METHOD(ike_sa_manager_t, checkout_by_message, ike_sa_t*,
if (message->get_exchange_type(message) == IKE_SA_INIT && if (message->get_exchange_type(message) == IKE_SA_INIT &&
message->get_request(message)) message->get_request(message))
{ {
ike_version = IKEV2;
is_init = TRUE; is_init = TRUE;
} }
} }
@@ -993,6 +995,7 @@ METHOD(ike_sa_manager_t, checkout_by_message, ike_sa_t*,
if (message->get_exchange_type(message) == ID_PROT || if (message->get_exchange_type(message) == ID_PROT ||
message->get_exchange_type(message) == AGGRESSIVE) message->get_exchange_type(message) == AGGRESSIVE)
{ {
ike_version = IKEV1;
is_init = TRUE; is_init = TRUE;
} }
} }
@@ -1034,7 +1037,7 @@ METHOD(ike_sa_manager_t, checkout_by_message, ike_sa_t*,
/* no IKE_SA found, create a new one */ /* no IKE_SA found, create a new one */
id->set_responder_spi(id, get_spi(this)); id->set_responder_spi(id, get_spi(this));
entry = entry_create(); entry = entry_create();
entry->ike_sa = ike_sa_create(id); entry->ike_sa = ike_sa_create(id, ike_version);
entry->ike_sa_id = id->clone(id); entry->ike_sa_id = id->clone(id);
segment = put_entry(this, entry); segment = put_entry(this, entry);
@@ -1103,7 +1106,7 @@ METHOD(ike_sa_manager_t, checkout_by_config, ike_sa_t*,
if (!this->reuse_ikesa) if (!this->reuse_ikesa)
{ /* IKE_SA reuse disable by config */ { /* IKE_SA reuse disable by config */
ike_sa = checkout_new(this, TRUE); ike_sa = checkout_new(this, peer_cfg->get_ike_version(peer_cfg), TRUE);
charon->bus->set_sa(charon->bus, ike_sa); charon->bus->set_sa(charon->bus, ike_sa);
return ike_sa; return ike_sa;
} }
@@ -1139,7 +1142,7 @@ METHOD(ike_sa_manager_t, checkout_by_config, ike_sa_t*,
if (!ike_sa) if (!ike_sa)
{ /* no IKE_SA using such a config, hand out a new */ { /* no IKE_SA using such a config, hand out a new */
ike_sa = checkout_new(this, TRUE); ike_sa = checkout_new(this, peer_cfg->get_ike_version(peer_cfg), TRUE);
} }
charon->bus->set_sa(charon->bus, ike_sa); charon->bus->set_sa(charon->bus, ike_sa);
return ike_sa; return ike_sa;
+3 -1
View File
@@ -52,10 +52,12 @@ struct ike_sa_manager_t {
/** /**
* Create and check out a new IKE_SA. * Create and check out a new IKE_SA.
* *
* @param version IKE version of this SA
* @param initiator TRUE for initiator, FALSE otherwise * @param initiator TRUE for initiator, FALSE otherwise
* @returns created and checked out IKE_SA * @returns created and checked out IKE_SA
*/ */
ike_sa_t* (*checkout_new) (ike_sa_manager_t* this, bool initiator); ike_sa_t* (*checkout_new) (ike_sa_manager_t* this, ike_version_t version,
bool initiator);
/** /**
* Checkout an IKE_SA by a message. * Checkout an IKE_SA by a message.
+4 -1
View File
@@ -54,6 +54,7 @@ METHOD(task_t, process_i, status_t,
ike_sa_t *new; ike_sa_t *new;
host_t *host; host_t *host;
enumerator_t *enumerator; enumerator_t *enumerator;
ike_version_t version;
child_sa_t *child_sa; child_sa_t *child_sa;
peer_cfg_t *peer_cfg; peer_cfg_t *peer_cfg;
@@ -74,7 +75,9 @@ METHOD(task_t, process_i, status_t,
return FAILED; return FAILED;
} }
new = charon->ike_sa_manager->checkout_new(charon->ike_sa_manager, TRUE); version = this->ike_sa->get_version(this->ike_sa);
new = charon->ike_sa_manager->checkout_new(charon->ike_sa_manager, version,
TRUE);
new->set_peer_cfg(new, peer_cfg); new->set_peer_cfg(new, peer_cfg);
host = this->ike_sa->get_other_host(this->ike_sa); host = this->ike_sa->get_other_host(this->ike_sa);
+6 -3
View File
@@ -129,8 +129,9 @@ METHOD(task_t, build_i, status_t,
/* create new SA only on first try */ /* create new SA only on first try */
if (this->new_sa == NULL) if (this->new_sa == NULL)
{ {
this->new_sa = charon->ike_sa_manager->checkout_new(charon->ike_sa_manager, ike_version_t version = this->ike_sa->get_version(this->ike_sa);
TRUE); this->new_sa = charon->ike_sa_manager->checkout_new(
charon->ike_sa_manager, version, TRUE);
peer_cfg = this->ike_sa->get_peer_cfg(this->ike_sa); peer_cfg = this->ike_sa->get_peer_cfg(this->ike_sa);
other_host = this->ike_sa->get_other_host(this->ike_sa); other_host = this->ike_sa->get_other_host(this->ike_sa);
@@ -148,6 +149,7 @@ METHOD(task_t, process_r, status_t,
private_ike_rekey_t *this, message_t *message) private_ike_rekey_t *this, message_t *message)
{ {
enumerator_t *enumerator; enumerator_t *enumerator;
ike_version_t version;
peer_cfg_t *peer_cfg; peer_cfg_t *peer_cfg;
child_sa_t *child_sa; child_sa_t *child_sa;
@@ -175,8 +177,9 @@ METHOD(task_t, process_r, status_t,
} }
enumerator->destroy(enumerator); enumerator->destroy(enumerator);
version = this->ike_sa->get_version(this->ike_sa);
this->new_sa = charon->ike_sa_manager->checkout_new(charon->ike_sa_manager, this->new_sa = charon->ike_sa_manager->checkout_new(charon->ike_sa_manager,
FALSE); version, FALSE);
peer_cfg = this->ike_sa->get_peer_cfg(this->ike_sa); peer_cfg = this->ike_sa->get_peer_cfg(this->ike_sa);
this->new_sa->set_peer_cfg(this->new_sa, peer_cfg); this->new_sa->set_peer_cfg(this->new_sa, peer_cfg);