emit a single assig_vips bus message for all VIPs

This commit is contained in:
Andreas Steffen
2013-04-06 14:16:30 +02:00
parent ba2880d569
commit 12fa1784d0
8 changed files with 57 additions and 62 deletions
+5 -6
View File
@@ -759,8 +759,8 @@ METHOD(bus_t, narrow, void,
this->mutex->unlock(this->mutex); this->mutex->unlock(this->mutex);
} }
METHOD(bus_t, assign_vip, void, METHOD(bus_t, assign_vips, void,
private_bus_t *this, ike_sa_t *ike_sa, host_t *vip, bool assign) private_bus_t *this, ike_sa_t *ike_sa, bool assign)
{ {
enumerator_t *enumerator; enumerator_t *enumerator;
entry_t *entry; entry_t *entry;
@@ -770,13 +770,12 @@ METHOD(bus_t, assign_vip, void,
enumerator = this->listeners->create_enumerator(this->listeners); enumerator = this->listeners->create_enumerator(this->listeners);
while (enumerator->enumerate(enumerator, &entry)) while (enumerator->enumerate(enumerator, &entry))
{ {
if (entry->calling || !entry->listener->assign_vip) if (entry->calling || !entry->listener->assign_vips)
{ {
continue; continue;
} }
entry->calling++; entry->calling++;
keep = entry->listener->assign_vip(entry->listener, ike_sa, keep = entry->listener->assign_vips(entry->listener, ike_sa, assign);
vip, assign);
entry->calling--; entry->calling--;
if (!keep) if (!keep)
{ {
@@ -835,7 +834,7 @@ bus_t *bus_create()
.child_rekey = _child_rekey, .child_rekey = _child_rekey,
.authorize = _authorize, .authorize = _authorize,
.narrow = _narrow, .narrow = _narrow,
.assign_vip = _assign_vip, .assign_vips = _assign_vips,
.destroy = _destroy, .destroy = _destroy,
}, },
.listeners = linked_list_create(), .listeners = linked_list_create(),
+2 -3
View File
@@ -388,11 +388,10 @@ struct bus_t {
/** /**
* Virtual IP assignment hook. * Virtual IP assignment hook.
* *
* @param ike_sa IKE_SA the VIP is assigned to * @param ike_sa IKE_SA the VIPs are assigned to
* @param vip Virtual IPv4 or IV6 address
* @param assign TRUE if assigned to IKE_SA, FALSE if released * @param assign TRUE if assigned to IKE_SA, FALSE if released
*/ */
void (*assign_vip)(bus_t *this, ike_sa_t *ike_sa, host_t *vip, bool assign); void (*assign_vips)(bus_t *this, ike_sa_t *ike_sa, bool assign);
/** /**
* Destroy the event bus. * Destroy the event bus.
+2 -4
View File
@@ -197,13 +197,11 @@ struct listener_t {
* This hook gets invoked when a a Virtual IP address is assigned to an * This hook gets invoked when a a Virtual IP address is assigned to an
* IKE_SA (assign = TRUE) and again when it is released (assign = FALSE) * IKE_SA (assign = TRUE) and again when it is released (assign = FALSE)
* *
* @param ike_sa IKE_SA the VIP is assigned to * @param ike_sa IKE_SA the VIPs are assigned to
* @param vip Virtual IPv4 or IV6 address
* @param assign TRUE if assigned to IKE_SA, FALSE if released * @param assign TRUE if assigned to IKE_SA, FALSE if released
* @return TRUE to stay registered, FALSE to unregister * @return TRUE to stay registered, FALSE to unregister
*/ */
bool (*assign_vip)(listener_t *this, ike_sa_t *ike_sa, host_t *vip, bool (*assign_vips)(listener_t *this, ike_sa_t *ike_sa, bool assign);
bool assign);
}; };
@@ -71,9 +71,8 @@ static bool publish_device_ip_addresses(private_tnc_ifmap_listener_t *this)
*/ */
static bool reload_metadata(private_tnc_ifmap_listener_t *this) static bool reload_metadata(private_tnc_ifmap_listener_t *this)
{ {
enumerator_t *enumerator, *evips;
ike_sa_t *ike_sa; ike_sa_t *ike_sa;
host_t *vip; enumerator_t *enumerator;
bool success = TRUE; bool success = TRUE;
enumerator = charon->controller->create_ike_sa_enumerator( enumerator = charon->controller->create_ike_sa_enumerator(
@@ -84,21 +83,12 @@ static bool reload_metadata(private_tnc_ifmap_listener_t *this)
{ {
continue; continue;
} }
if (!this->ifmap->publish_ike_sa(this->ifmap, ike_sa, TRUE)) if (!this->ifmap->publish_ike_sa(this->ifmap, ike_sa, TRUE) ||
!this->ifmap->publish_virtual_ips(this->ifmap, ike_sa, TRUE))
{ {
success = FALSE; success = FALSE;
break; break;
} }
evips = ike_sa->create_virtual_ip_enumerator(ike_sa, FALSE);
while (evips->enumerate(evips, &vip))
{
if (!this->ifmap->publish_virtual_ip(this->ifmap, ike_sa, vip, TRUE))
{
success = FALSE;
break;
}
}
evips->destroy(evips);
} }
enumerator->destroy(enumerator); enumerator->destroy(enumerator);
@@ -115,11 +105,10 @@ METHOD(listener_t, ike_updown, bool,
return TRUE; return TRUE;
} }
METHOD(listener_t, assign_vip, bool, METHOD(listener_t, assign_vips, bool,
private_tnc_ifmap_listener_t *this, ike_sa_t *ike_sa, host_t *vip, private_tnc_ifmap_listener_t *this, ike_sa_t *ike_sa, bool assign)
bool assign)
{ {
this->ifmap->publish_virtual_ip(this->ifmap, ike_sa, vip, assign); this->ifmap->publish_virtual_ips(this->ifmap, ike_sa, assign);
return TRUE; return TRUE;
} }
@@ -163,7 +152,7 @@ tnc_ifmap_listener_t *tnc_ifmap_listener_create(bool reload)
.public = { .public = {
.listener = { .listener = {
.ike_updown = _ike_updown, .ike_updown = _ike_updown,
.assign_vip = _assign_vip, .assign_vips = _assign_vips,
.alert = _alert, .alert = _alert,
}, },
.destroy = _destroy, .destroy = _destroy,
@@ -579,12 +579,14 @@ METHOD(tnc_ifmap_soap_t, publish_device_ip, bool,
return success; return success;
} }
METHOD(tnc_ifmap_soap_t, publish_virtual_ip, bool, METHOD(tnc_ifmap_soap_t, publish_virtual_ips, bool,
private_tnc_ifmap_soap_t *this, ike_sa_t *ike_sa, host_t *vip, bool assign) private_tnc_ifmap_soap_t *this, ike_sa_t *ike_sa, bool assign)
{ {
tnc_ifmap_soap_msg_t *soap_msg; tnc_ifmap_soap_msg_t *soap_msg;
xmlNodePtr request, node; xmlNodePtr request, node;
u_int32_t ike_sa_id; u_int32_t ike_sa_id;
enumerator_t *enumerator;
host_t *vip;
bool success; bool success;
/* extract relevant data from IKE_SA*/ /* extract relevant data from IKE_SA*/
@@ -593,26 +595,31 @@ METHOD(tnc_ifmap_soap_t, publish_virtual_ip, bool,
/* build publish request */ /* build publish request */
request = create_publish_request(this); request = create_publish_request(this);
/** enumerator = ike_sa->create_virtual_ip_enumerator(ike_sa, FALSE);
* update or delete access-request-ip metadata for a virtual IP address while (enumerator->enumerate(enumerator, &vip))
*/
if (assign)
{ {
node = xmlNewNode(NULL, "update"); /**
} * update or delete access-request-ip metadata for a virtual IP address
else */
{ if (assign)
node = create_delete_filter(this, "access-request-ip"); {
} node = xmlNewNode(NULL, "update");
xmlAddChild(request, node); }
else
{
node = create_delete_filter(this, "access-request-ip");
}
xmlAddChild(request, node);
/* add access-request, virtual ip-address and [if assign] metadata */ /* add access-request, virtual ip-address and [if assign] metadata */
xmlAddChild(node, create_access_request(this, ike_sa_id)); xmlAddChild(node, create_access_request(this, ike_sa_id));
xmlAddChild(node, create_ip_address(this, vip)); xmlAddChild(node, create_ip_address(this, vip));
if (assign) if (assign)
{ {
xmlAddChild(node, create_metadata(this, "access-request-ip")); xmlAddChild(node, create_metadata(this, "access-request-ip"));
}
} }
enumerator->destroy(enumerator);
soap_msg = tnc_ifmap_soap_msg_create(this->uri, this->user_pass, this->tls); soap_msg = tnc_ifmap_soap_msg_create(this->uri, this->user_pass, this->tls);
success = soap_msg->post(soap_msg, request, "publishReceived", NULL); success = soap_msg->post(soap_msg, request, "publishReceived", NULL);
@@ -893,7 +900,7 @@ tnc_ifmap_soap_t *tnc_ifmap_soap_create()
.purgePublisher = _purgePublisher, .purgePublisher = _purgePublisher,
.publish_ike_sa = _publish_ike_sa, .publish_ike_sa = _publish_ike_sa,
.publish_device_ip = _publish_device_ip, .publish_device_ip = _publish_device_ip,
.publish_virtual_ip = _publish_virtual_ip, .publish_virtual_ips = _publish_virtual_ips,
.publish_enforcement_report = _publish_enforcement_report, .publish_enforcement_report = _publish_enforcement_report,
.endSession = _endSession, .endSession = _endSession,
.get_session_id = _get_session_id, .get_session_id = _get_session_id,
@@ -71,15 +71,14 @@ struct tnc_ifmap_soap_t {
bool (*publish_device_ip)(tnc_ifmap_soap_t *this, host_t *host); bool (*publish_device_ip)(tnc_ifmap_soap_t *this, host_t *host);
/** /**
* Publish Virtual IP access-request-ip metadata * Publish Virtual IP access-request-ip metadata
* *
* @param ike_sa IKE_SA for which metadata is published * @param ike_sa IKE_SA for which Virtual IP metadata is published
* @param vip Virtual IP address of peer
* @param assign TRUE if assigned, FALSE if removed * @param assign TRUE if assigned, FALSE if removed
* @return TRUE if command was successful * @return TRUE if command was successful
*/ */
bool (*publish_virtual_ip)(tnc_ifmap_soap_t *this, ike_sa_t *ike_sa, bool (*publish_virtual_ips)(tnc_ifmap_soap_t *this, ike_sa_t *ike_sa,
host_t *vip, bool assign); bool assign);
/** /**
* Publish enforcement-report metadata * Publish enforcement-report metadata
+8 -6
View File
@@ -766,7 +766,6 @@ METHOD(ike_sa_t, add_virtual_ip, void,
else else
{ {
this->other_vips->insert_last(this->other_vips, ip->clone(ip)); this->other_vips->insert_last(this->other_vips, ip->clone(ip));
charon->bus->assign_vip(charon->bus, &this->public, ip, TRUE);
} }
} }
@@ -777,6 +776,10 @@ METHOD(ike_sa_t, clear_virtual_ips, void,
linked_list_t *vips = local ? this->my_vips : this->other_vips; linked_list_t *vips = local ? this->my_vips : this->other_vips;
host_t *vip; host_t *vip;
if (!local && vips->get_count(vips))
{
charon->bus->assign_vips(charon->bus, &this->public, FALSE);
}
while (vips->remove_first(vips, (void**)&vip) == SUCCESS) while (vips->remove_first(vips, (void**)&vip) == SUCCESS)
{ {
if (local) if (local)
@@ -784,10 +787,6 @@ METHOD(ike_sa_t, clear_virtual_ips, void,
hydra->kernel_interface->del_ip(hydra->kernel_interface, hydra->kernel_interface->del_ip(hydra->kernel_interface,
vip, -1, TRUE); vip, -1, TRUE);
} }
else
{
charon->bus->assign_vip(charon->bus, &this->public, vip, FALSE);
}
vip->destroy(vip); vip->destroy(vip);
} }
} }
@@ -2110,6 +2109,10 @@ METHOD(ike_sa_t, destroy, void,
vip->destroy(vip); vip->destroy(vip);
} }
this->my_vips->destroy(this->my_vips); this->my_vips->destroy(this->my_vips);
if (this->other_vips->get_count(this->other_vips))
{
charon->bus->assign_vips(charon->bus, &this->public, FALSE);
}
while (this->other_vips->remove_last(this->other_vips, while (this->other_vips->remove_last(this->other_vips,
(void**)&vip) == SUCCESS) (void**)&vip) == SUCCESS)
{ {
@@ -2124,7 +2127,6 @@ METHOD(ike_sa_t, destroy, void,
hydra->attributes->release_address(hydra->attributes, pools, vip, id); hydra->attributes->release_address(hydra->attributes, pools, vip, id);
pools->destroy(pools); pools->destroy(pools);
} }
charon->bus->assign_vip(charon->bus, &this->public, vip, FALSE);
vip->destroy(vip); vip->destroy(vip);
} }
this->other_vips->destroy(this->other_vips); this->other_vips->destroy(this->other_vips);
@@ -387,6 +387,8 @@ METHOD(task_t, build_r, status_t,
pools->destroy(pools); pools->destroy(pools);
return SUCCESS; return SUCCESS;
} }
charon->bus->assign_vips(charon->bus, this->ike_sa, TRUE);
if (pools->get_count(pools) && !this->vips->get_count(this->vips)) if (pools->get_count(pools) && !this->vips->get_count(this->vips))
{ {
DBG1(DBG_IKE, "expected a virtual IP request, sending %N", DBG1(DBG_IKE, "expected a virtual IP request, sending %N",