simple roaming of the client works (not MOBIKE conform yet!)
This commit is contained in:
@@ -1393,10 +1393,10 @@ static host_t* get_source_addr(private_kernel_interface_t *this, host_t *dest)
|
|||||||
msg = (struct rtmsg*)NLMSG_DATA(hdr);
|
msg = (struct rtmsg*)NLMSG_DATA(hdr);
|
||||||
msg->rtm_family = dest->get_family(dest);
|
msg->rtm_family = dest->get_family(dest);
|
||||||
msg->rtm_dst_len = msg->rtm_family == AF_INET ? 32 : 128;
|
msg->rtm_dst_len = msg->rtm_family == AF_INET ? 32 : 128;
|
||||||
msg->rtm_table = RT_TABLE_UNSPEC;
|
msg->rtm_table = RT_TABLE_MAIN;
|
||||||
msg->rtm_protocol = RTPROT_UNSPEC;
|
msg->rtm_protocol = RTPROT_STATIC;
|
||||||
msg->rtm_type = RTN_UNICAST;
|
msg->rtm_type = RTN_UNICAST;
|
||||||
msg->rtm_scope = RT_SCOPE_HOST;
|
msg->rtm_scope = RT_SCOPE_UNIVERSE;
|
||||||
|
|
||||||
chunk = dest->get_address(dest);
|
chunk = dest->get_address(dest);
|
||||||
add_attribute(hdr, RTA_DST, chunk, sizeof(request));
|
add_attribute(hdr, RTA_DST, chunk, sizeof(request));
|
||||||
@@ -1443,12 +1443,11 @@ static host_t* get_source_addr(private_kernel_interface_t *this, host_t *dest)
|
|||||||
break;
|
break;
|
||||||
}
|
}
|
||||||
free(out);
|
free(out);
|
||||||
if (source)
|
if (source == NULL)
|
||||||
{
|
{
|
||||||
return source;
|
DBG2(DBG_KNL, "no route found to %H", dest);
|
||||||
}
|
}
|
||||||
DBG2(DBG_KNL, "no route found to %H", dest);
|
return source;
|
||||||
return NULL;
|
|
||||||
}
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
@@ -1784,10 +1783,9 @@ static status_t add_sa(private_kernel_interface_t *this,
|
|||||||
* Implementation of kernel_interface_t.update_sa.
|
* Implementation of kernel_interface_t.update_sa.
|
||||||
*/
|
*/
|
||||||
static status_t update_sa(private_kernel_interface_t *this,
|
static status_t update_sa(private_kernel_interface_t *this,
|
||||||
host_t *dst, u_int32_t spi,
|
u_int32_t spi, protocol_id_t protocol,
|
||||||
protocol_id_t protocol,
|
host_t *src, host_t *dst,
|
||||||
host_t *new_src, host_t *new_dst,
|
host_t *new_src, host_t *new_dst)
|
||||||
host_diff_t src_changes, host_diff_t dst_changes)
|
|
||||||
{
|
{
|
||||||
unsigned char request[BUFFER_SIZE];
|
unsigned char request[BUFFER_SIZE];
|
||||||
struct nlmsghdr *hdr, *out = NULL;
|
struct nlmsghdr *hdr, *out = NULL;
|
||||||
@@ -1797,8 +1795,9 @@ static status_t update_sa(private_kernel_interface_t *this,
|
|||||||
|
|
||||||
memset(&request, 0, sizeof(request));
|
memset(&request, 0, sizeof(request));
|
||||||
|
|
||||||
DBG2(DBG_KNL, "querying SAD entry with SPI 0x%x", spi);
|
DBG2(DBG_KNL, "querying SAD entry with SPI 0x%x for update", spi);
|
||||||
|
|
||||||
|
/* query the exisiting SA first */
|
||||||
hdr = (struct nlmsghdr*)request;
|
hdr = (struct nlmsghdr*)request;
|
||||||
hdr->nlmsg_flags = NLM_F_REQUEST;
|
hdr->nlmsg_flags = NLM_F_REQUEST;
|
||||||
hdr->nlmsg_type = XFRM_MSG_GETSA;
|
hdr->nlmsg_type = XFRM_MSG_GETSA;
|
||||||
@@ -1838,31 +1837,33 @@ static status_t update_sa(private_kernel_interface_t *this,
|
|||||||
break;
|
break;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
if (sa == NULL)
|
if (sa == NULL ||
|
||||||
|
this->public.del_sa(&this->public, dst, spi, protocol) != SUCCESS)
|
||||||
{
|
{
|
||||||
DBG1(DBG_KNL, "unable to update SAD entry with SPI 0x%x", spi);
|
DBG1(DBG_KNL, "unable to update SAD entry with SPI 0x%x", spi);
|
||||||
free(out);
|
free(out);
|
||||||
return FAILED;
|
return FAILED;
|
||||||
}
|
}
|
||||||
|
|
||||||
DBG2(DBG_KNL, "updating SAD entry with SPI 0x%x", spi);
|
DBG2(DBG_KNL, "updating SAD entry with SPI 0x%x from %#H..%#H to %#H..%#H",
|
||||||
|
spi, src, dst, new_src, new_dst);
|
||||||
|
|
||||||
|
/* update the values in the queried SA */
|
||||||
hdr = out;
|
hdr = out;
|
||||||
hdr->nlmsg_flags = NLM_F_REQUEST | NLM_F_ACK;
|
hdr->nlmsg_flags = NLM_F_REQUEST | NLM_F_ACK;
|
||||||
hdr->nlmsg_type = XFRM_MSG_UPDSA;
|
hdr->nlmsg_type = XFRM_MSG_NEWSA;
|
||||||
|
|
||||||
if (src_changes & HOST_DIFF_ADDR)
|
if (!src->ip_equals(src, new_src))
|
||||||
{
|
{
|
||||||
host2xfrm(new_src, &sa->saddr);
|
host2xfrm(new_src, &sa->saddr);
|
||||||
}
|
}
|
||||||
|
if (!dst->ip_equals(dst, new_dst))
|
||||||
if (dst_changes & HOST_DIFF_ADDR)
|
|
||||||
{
|
{
|
||||||
hdr->nlmsg_type = XFRM_MSG_NEWSA;
|
|
||||||
host2xfrm(new_dst, &sa->id.daddr);
|
host2xfrm(new_dst, &sa->id.daddr);
|
||||||
}
|
}
|
||||||
|
|
||||||
if (src_changes & HOST_DIFF_PORT || dst_changes & HOST_DIFF_PORT)
|
if (src->get_port(src) != new_src->get_port(new_src) ||
|
||||||
|
dst->get_port(dst) != new_dst->get_port(new_dst))
|
||||||
{
|
{
|
||||||
struct rtattr *rtattr = XFRM_RTA(hdr, struct xfrm_usersa_info);
|
struct rtattr *rtattr = XFRM_RTA(hdr, struct xfrm_usersa_info);
|
||||||
size_t rtsize = XFRM_PAYLOAD(hdr, struct xfrm_usersa_info);
|
size_t rtsize = XFRM_PAYLOAD(hdr, struct xfrm_usersa_info);
|
||||||
@@ -1887,10 +1888,6 @@ static status_t update_sa(private_kernel_interface_t *this,
|
|||||||
}
|
}
|
||||||
free(out);
|
free(out);
|
||||||
|
|
||||||
if (dst_changes & HOST_DIFF_ADDR)
|
|
||||||
{
|
|
||||||
return this->public.del_sa(&this->public, dst, spi, protocol);
|
|
||||||
}
|
|
||||||
return SUCCESS;
|
return SUCCESS;
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -2318,7 +2315,7 @@ kernel_interface_t *kernel_interface_create()
|
|||||||
/* public functions */
|
/* public functions */
|
||||||
this->public.get_spi = (status_t(*)(kernel_interface_t*,host_t*,host_t*,protocol_id_t,u_int32_t,u_int32_t*))get_spi;
|
this->public.get_spi = (status_t(*)(kernel_interface_t*,host_t*,host_t*,protocol_id_t,u_int32_t,u_int32_t*))get_spi;
|
||||||
this->public.add_sa = (status_t(*)(kernel_interface_t *,host_t*,host_t*,u_int32_t,protocol_id_t,u_int32_t,u_int64_t,u_int64_t,algorithm_t*,algorithm_t*,prf_plus_t*,natt_conf_t*,mode_t,bool))add_sa;
|
this->public.add_sa = (status_t(*)(kernel_interface_t *,host_t*,host_t*,u_int32_t,protocol_id_t,u_int32_t,u_int64_t,u_int64_t,algorithm_t*,algorithm_t*,prf_plus_t*,natt_conf_t*,mode_t,bool))add_sa;
|
||||||
this->public.update_sa = (status_t(*)(kernel_interface_t*,host_t*,u_int32_t,protocol_id_t,host_t*,host_t*,host_diff_t,host_diff_t))update_sa;
|
this->public.update_sa = (status_t(*)(kernel_interface_t*,u_int32_t,protocol_id_t,host_t*,host_t*,host_t*,host_t*))update_sa;
|
||||||
this->public.query_sa = (status_t(*)(kernel_interface_t*,host_t*,u_int32_t,protocol_id_t,u_int32_t*))query_sa;
|
this->public.query_sa = (status_t(*)(kernel_interface_t*,host_t*,u_int32_t,protocol_id_t,u_int32_t*))query_sa;
|
||||||
this->public.del_sa = (status_t(*)(kernel_interface_t*,host_t*,u_int32_t,protocol_id_t))del_sa;
|
this->public.del_sa = (status_t(*)(kernel_interface_t*,host_t*,u_int32_t,protocol_id_t))del_sa;
|
||||||
this->public.add_policy = (status_t(*)(kernel_interface_t*,host_t*,host_t*,traffic_selector_t*,traffic_selector_t*,policy_dir_t,protocol_id_t,u_int32_t,bool,mode_t,bool))add_policy;
|
this->public.add_policy = (status_t(*)(kernel_interface_t*,host_t*,host_t*,traffic_selector_t*,traffic_selector_t*,policy_dir_t,protocol_id_t,u_int32_t,bool,mode_t,bool))add_policy;
|
||||||
|
|||||||
@@ -145,21 +145,20 @@ struct kernel_interface_t {
|
|||||||
* create a new SA and delete the old one.
|
* create a new SA and delete the old one.
|
||||||
*
|
*
|
||||||
* @param this calling object
|
* @param this calling object
|
||||||
* @param dst destination address for this SA
|
|
||||||
* @param spi SPI of the SA
|
* @param spi SPI of the SA
|
||||||
* @param protocol protocol for this SA (ESP/AH)
|
* @param protocol protocol for this SA (ESP/AH)
|
||||||
* @param new_src new source address for this SA
|
* @param src current source address
|
||||||
* @param new_dst new destination address for this SA
|
* @param dst current destination address
|
||||||
* @param src_changes changes in src
|
* @param new_src new source address
|
||||||
* @param dst_changes changes in dst
|
* @param new_dst new destination address
|
||||||
* @return
|
* @return
|
||||||
* - SUCCESS
|
* - SUCCESS
|
||||||
* - FAILED if kernel comm failed
|
* - FAILED if kernel comm failed
|
||||||
*/
|
*/
|
||||||
status_t (*update_sa)(kernel_interface_t *this, host_t *dst, u_int32_t spi,
|
status_t (*update_sa)(kernel_interface_t *this,
|
||||||
protocol_id_t protocol,
|
u_int32_t spi, protocol_id_t protocol,
|
||||||
host_t *new_src, host_t *new_dst,
|
host_t *src, host_t *dst,
|
||||||
host_diff_t src_changes, host_diff_t dst_changes);
|
host_t *new_src, host_t *new_dst);
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* @brief Query the use time of an SA.
|
* @brief Query the use time of an SA.
|
||||||
|
|||||||
+47
-107
@@ -781,140 +781,80 @@ static status_t get_use_time(private_child_sa_t *this, bool inbound, time_t *use
|
|||||||
return status;
|
return status;
|
||||||
}
|
}
|
||||||
|
|
||||||
/**
|
|
||||||
* Update the host adress/port of a SA
|
|
||||||
*/
|
|
||||||
static status_t update_sa_hosts(private_child_sa_t *this, host_t *new_me, host_t *new_other,
|
|
||||||
int my_changes, int other_changes, bool mine)
|
|
||||||
{
|
|
||||||
host_t *src, *dst, *new_src, *new_dst;
|
|
||||||
int src_changes, dst_changes;
|
|
||||||
status_t status;
|
|
||||||
u_int32_t spi;
|
|
||||||
|
|
||||||
if (mine)
|
|
||||||
{
|
|
||||||
src = this->other.addr;
|
|
||||||
dst = this->me.addr;
|
|
||||||
new_src = new_other;
|
|
||||||
new_dst = new_me;
|
|
||||||
src_changes = other_changes;
|
|
||||||
dst_changes = my_changes;
|
|
||||||
spi = this->other.spi;
|
|
||||||
}
|
|
||||||
else
|
|
||||||
{
|
|
||||||
src = this->me.addr;
|
|
||||||
dst = this->other.addr;
|
|
||||||
new_src = new_me;
|
|
||||||
new_dst = new_other;
|
|
||||||
src_changes = my_changes;
|
|
||||||
dst_changes = other_changes;
|
|
||||||
spi = this->me.spi;
|
|
||||||
}
|
|
||||||
|
|
||||||
DBG2(DBG_CHD, "updating %N SA 0x%x, from %#H..#H to %#H..%#H",
|
|
||||||
protocol_id_names, this->protocol, ntohl(spi), src, dst, new_src, new_dst);
|
|
||||||
|
|
||||||
status = charon->kernel_interface->update_sa(charon->kernel_interface,
|
|
||||||
dst, spi, this->protocol,
|
|
||||||
new_src, new_dst,
|
|
||||||
src_changes, dst_changes);
|
|
||||||
|
|
||||||
if (status != SUCCESS)
|
|
||||||
{
|
|
||||||
return FAILED;
|
|
||||||
}
|
|
||||||
return SUCCESS;
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
|
||||||
* Update the host adress/port of a policy
|
|
||||||
*/
|
|
||||||
static status_t update_policy_hosts(private_child_sa_t *this, host_t *new_me, host_t *new_other)
|
|
||||||
{
|
|
||||||
iterator_t *iterator;
|
|
||||||
sa_policy_t *policy;
|
|
||||||
status_t status;
|
|
||||||
/* we always use high priorities, as hosts getting updated are INSTALLED */
|
|
||||||
|
|
||||||
iterator = this->policies->create_iterator(this->policies, TRUE);
|
|
||||||
while (iterator->iterate(iterator, (void**)&policy))
|
|
||||||
{
|
|
||||||
status = charon->kernel_interface->add_policy(
|
|
||||||
charon->kernel_interface,
|
|
||||||
new_me, new_other,
|
|
||||||
policy->my_ts, policy->other_ts,
|
|
||||||
POLICY_OUT, this->protocol, this->reqid, TRUE, this->mode, TRUE);
|
|
||||||
|
|
||||||
status |= charon->kernel_interface->add_policy(
|
|
||||||
charon->kernel_interface,
|
|
||||||
new_other, new_me,
|
|
||||||
policy->other_ts, policy->my_ts,
|
|
||||||
POLICY_IN, this->protocol, this->reqid, TRUE, this->mode, TRUE);
|
|
||||||
|
|
||||||
status |= charon->kernel_interface->add_policy(
|
|
||||||
charon->kernel_interface,
|
|
||||||
new_other, new_me,
|
|
||||||
policy->other_ts, policy->my_ts,
|
|
||||||
POLICY_FWD, this->protocol, this->reqid, TRUE, this->mode, TRUE);
|
|
||||||
|
|
||||||
if (status != SUCCESS)
|
|
||||||
{
|
|
||||||
iterator->destroy(iterator);
|
|
||||||
return FAILED;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
iterator->destroy(iterator);
|
|
||||||
|
|
||||||
return SUCCESS;
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Implementation of child_sa_t.update_hosts.
|
* Implementation of child_sa_t.update_hosts.
|
||||||
*/
|
*/
|
||||||
static status_t update_hosts(private_child_sa_t *this, host_t *new_me, host_t *new_other,
|
static status_t update_hosts(private_child_sa_t *this, host_t *me, host_t *other)
|
||||||
host_diff_t my_changes, host_diff_t other_changes)
|
|
||||||
{
|
{
|
||||||
if (!my_changes && !other_changes)
|
/* anything changed at all? */
|
||||||
|
if (me->equals(me, this->me.addr) && other->equals(other, this->other.addr))
|
||||||
{
|
{
|
||||||
return SUCCESS;
|
return SUCCESS;
|
||||||
}
|
}
|
||||||
|
|
||||||
/* update our (initator) SAs */
|
/* update our (initator) SAs */
|
||||||
if (update_sa_hosts(this, new_me, new_other, my_changes, other_changes, TRUE) != SUCCESS)
|
if (charon->kernel_interface->update_sa(
|
||||||
|
charon->kernel_interface, this->me.spi, this->protocol,
|
||||||
|
this->other.addr, this->me.addr, other, me) != SUCCESS)
|
||||||
{
|
{
|
||||||
return FAILED;
|
return FAILED;
|
||||||
}
|
}
|
||||||
|
|
||||||
/* update his (responder) SAs */
|
/* update his (responder) SAs */
|
||||||
if (update_sa_hosts(this, new_me, new_other, my_changes, other_changes, FALSE) != SUCCESS)
|
if (charon->kernel_interface->update_sa(
|
||||||
|
charon->kernel_interface, this->other.spi, this->protocol,
|
||||||
|
this->me.addr, this->other.addr, me, other) != SUCCESS)
|
||||||
{
|
{
|
||||||
return FAILED;
|
return FAILED;
|
||||||
}
|
}
|
||||||
|
|
||||||
/* update policies */
|
/* update policies */
|
||||||
if (my_changes & HOST_DIFF_ADDR || other_changes & HOST_DIFF_ADDR)
|
if (!me->ip_equals(me, this->me.addr) ||
|
||||||
|
!other->ip_equals(other, this->other.addr))
|
||||||
{
|
{
|
||||||
if (update_policy_hosts(this, new_me, new_other) != SUCCESS)
|
iterator_t *iterator;
|
||||||
|
sa_policy_t *policy;
|
||||||
|
status_t status;
|
||||||
|
|
||||||
|
/* always use high priorities, as hosts getting updated are INSTALLED */
|
||||||
|
iterator = this->policies->create_iterator(this->policies, TRUE);
|
||||||
|
while (iterator->iterate(iterator, (void**)&policy))
|
||||||
{
|
{
|
||||||
return FAILED;
|
status = charon->kernel_interface->add_policy(
|
||||||
|
charon->kernel_interface, me, other,
|
||||||
|
policy->my_ts, policy->other_ts, POLICY_OUT,
|
||||||
|
this->protocol, this->reqid, TRUE, this->mode, TRUE);
|
||||||
|
|
||||||
|
status |= charon->kernel_interface->add_policy(
|
||||||
|
charon->kernel_interface, other, me,
|
||||||
|
policy->other_ts, policy->my_ts, POLICY_IN,
|
||||||
|
this->protocol, this->reqid, TRUE, this->mode, TRUE);
|
||||||
|
|
||||||
|
status |= charon->kernel_interface->add_policy(
|
||||||
|
charon->kernel_interface, other, me,
|
||||||
|
policy->other_ts, policy->my_ts, POLICY_FWD,
|
||||||
|
this->protocol, this->reqid, TRUE, this->mode, TRUE);
|
||||||
|
|
||||||
|
if (status != SUCCESS)
|
||||||
|
{
|
||||||
|
iterator->destroy(iterator);
|
||||||
|
return FAILED;
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
iterator->destroy(iterator);
|
||||||
}
|
}
|
||||||
|
|
||||||
/* update hosts */
|
/* finally apply hosts */
|
||||||
if (my_changes)
|
if (!me->equals(me, this->me.addr))
|
||||||
{
|
{
|
||||||
this->me.addr->destroy(this->me.addr);
|
this->me.addr->destroy(this->me.addr);
|
||||||
this->me.addr = new_me->clone(new_me);
|
this->me.addr = me->clone(me);
|
||||||
}
|
}
|
||||||
|
if (other->equals(other, this->other.addr))
|
||||||
if (other_changes)
|
|
||||||
{
|
{
|
||||||
this->other.addr->destroy(this->other.addr);
|
this->other.addr->destroy(this->other.addr);
|
||||||
this->other.addr = new_other->clone(new_other);
|
this->other.addr = other->clone(other);
|
||||||
}
|
}
|
||||||
|
|
||||||
return SUCCESS;
|
return SUCCESS;
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -1011,7 +951,7 @@ child_sa_t * child_sa_create(host_t *me, host_t* other,
|
|||||||
this->public.alloc = (status_t(*)(child_sa_t*,linked_list_t*))alloc;
|
this->public.alloc = (status_t(*)(child_sa_t*,linked_list_t*))alloc;
|
||||||
this->public.add = (status_t(*)(child_sa_t*,proposal_t*,mode_t,prf_plus_t*))add;
|
this->public.add = (status_t(*)(child_sa_t*,proposal_t*,mode_t,prf_plus_t*))add;
|
||||||
this->public.update = (status_t(*)(child_sa_t*,proposal_t*,mode_t,prf_plus_t*))update;
|
this->public.update = (status_t(*)(child_sa_t*,proposal_t*,mode_t,prf_plus_t*))update;
|
||||||
this->public.update_hosts = (status_t (*)(child_sa_t*,host_t*,host_t*,host_diff_t,host_diff_t))update_hosts;
|
this->public.update_hosts = (status_t (*)(child_sa_t*,host_t*,host_t*))update_hosts;
|
||||||
this->public.add_policies = (status_t (*)(child_sa_t*, linked_list_t*,linked_list_t*,mode_t))add_policies;
|
this->public.add_policies = (status_t (*)(child_sa_t*, linked_list_t*,linked_list_t*,mode_t))add_policies;
|
||||||
this->public.get_traffic_selectors = (linked_list_t*(*)(child_sa_t*,bool))get_traffic_selectors;
|
this->public.get_traffic_selectors = (linked_list_t*(*)(child_sa_t*,bool))get_traffic_selectors;
|
||||||
this->public.get_use_time = (status_t (*)(child_sa_t*,bool,time_t*))get_use_time;
|
this->public.get_use_time = (status_t (*)(child_sa_t*,bool,time_t*))get_use_time;
|
||||||
|
|||||||
@@ -200,19 +200,16 @@ struct child_sa_t {
|
|||||||
prf_plus_t *prf_plus);
|
prf_plus_t *prf_plus);
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* @brief Update the hosts in the kernel SAs and policies
|
* @brief Update the hosts in the kernel SAs and policies.
|
||||||
*
|
*
|
||||||
* @warning only call this after update() has been called.
|
* The CHILD must be INSTALLED to do this update.
|
||||||
*
|
*
|
||||||
* @param this calling object
|
* @param this calling object
|
||||||
* @param new_me the new local host
|
* @param me the new local host
|
||||||
* @param new_other the new remote host
|
* @param other the new remote host
|
||||||
* @param my_diff differences to apply for me
|
* @return SUCCESS or FAILED
|
||||||
* @param other_diff differences to apply for other
|
|
||||||
* @return SUCCESS or FAILED
|
|
||||||
*/
|
*/
|
||||||
status_t (*update_hosts)(child_sa_t *this, host_t *new_me, host_t *new_other,
|
status_t (*update_hosts)(child_sa_t *this, host_t *me, host_t *other);
|
||||||
host_diff_t my_diff, host_diff_t other_diff);
|
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* @brief Install the policies using some traffic selectors.
|
* @brief Install the policies using some traffic selectors.
|
||||||
|
|||||||
+147
-147
@@ -385,6 +385,40 @@ static void set_peer_cfg(private_ike_sa_t *this, peer_cfg_t *peer_cfg)
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Implementation of ike_sa_t.send_keepalive
|
||||||
|
*/
|
||||||
|
static void send_keepalive(private_ike_sa_t *this)
|
||||||
|
{
|
||||||
|
send_keepalive_job_t *job;
|
||||||
|
time_t last_out, now, diff;
|
||||||
|
|
||||||
|
last_out = get_use_time(this, FALSE);
|
||||||
|
now = time(NULL);
|
||||||
|
|
||||||
|
diff = now - last_out;
|
||||||
|
|
||||||
|
if (diff >= KEEPALIVE_INTERVAL)
|
||||||
|
{
|
||||||
|
packet_t *packet;
|
||||||
|
chunk_t data;
|
||||||
|
|
||||||
|
packet = packet_create();
|
||||||
|
packet->set_source(packet, this->my_host->clone(this->my_host));
|
||||||
|
packet->set_destination(packet, this->other_host->clone(this->other_host));
|
||||||
|
data.ptr = malloc(1);
|
||||||
|
data.ptr[0] = 0xFF;
|
||||||
|
data.len = 1;
|
||||||
|
packet->set_data(packet, data);
|
||||||
|
charon->sender->send(charon->sender, packet);
|
||||||
|
DBG1(DBG_IKE, "sending keep alive");
|
||||||
|
diff = 0;
|
||||||
|
}
|
||||||
|
job = send_keepalive_job_create(this->ike_sa_id);
|
||||||
|
charon->scheduler->schedule_job(charon->scheduler, (job_t*)job,
|
||||||
|
(KEEPALIVE_INTERVAL - diff) * 1000);
|
||||||
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Implementation of ike_sa_t.get_ike_cfg
|
* Implementation of ike_sa_t.get_ike_cfg
|
||||||
*/
|
*/
|
||||||
@@ -401,6 +435,74 @@ static void set_ike_cfg(private_ike_sa_t *this, ike_cfg_t *ike_cfg)
|
|||||||
ike_cfg->get_ref(ike_cfg);
|
ike_cfg->get_ref(ike_cfg);
|
||||||
this->ike_cfg = ike_cfg;
|
this->ike_cfg = ike_cfg;
|
||||||
}
|
}
|
||||||
|
/**
|
||||||
|
* Implementation of ike_sa_t.enable_extension.
|
||||||
|
*/
|
||||||
|
static void enable_extension(private_ike_sa_t *this, ike_extension_t extension)
|
||||||
|
{
|
||||||
|
this->extensions |= extension;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Implementation of ike_sa_t.has_extension.
|
||||||
|
*/
|
||||||
|
static bool supports_extension(private_ike_sa_t *this, ike_extension_t extension)
|
||||||
|
{
|
||||||
|
return (this->extensions & extension) != FALSE;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Implementation of ike_sa_t.has_condition.
|
||||||
|
*/
|
||||||
|
static bool has_condition(private_ike_sa_t *this, ike_condition_t condition)
|
||||||
|
{
|
||||||
|
return (this->conditions & condition) != FALSE;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Implementation of ike_sa_t.enable_condition.
|
||||||
|
*/
|
||||||
|
static void set_condition(private_ike_sa_t *this, ike_condition_t condition,
|
||||||
|
bool enable)
|
||||||
|
{
|
||||||
|
if (has_condition(this, condition) != enable)
|
||||||
|
{
|
||||||
|
if (enable)
|
||||||
|
{
|
||||||
|
switch (condition)
|
||||||
|
{
|
||||||
|
case COND_STALE:
|
||||||
|
DBG1(DBG_IKE, "no route to %H, setting IKE_SA to stale",
|
||||||
|
this->other_host);
|
||||||
|
break;
|
||||||
|
case COND_NAT_HERE:
|
||||||
|
DBG1(DBG_IKE, "local host is behind NAT, sending keep alives");
|
||||||
|
this->conditions |= COND_NAT_ANY;
|
||||||
|
send_keepalive(this);
|
||||||
|
break;
|
||||||
|
case COND_NAT_THERE:
|
||||||
|
DBG1(DBG_IKE, "remote host is behind NAT");
|
||||||
|
this->conditions |= COND_NAT_ANY;
|
||||||
|
break;
|
||||||
|
default:
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
this->conditions |= condition;
|
||||||
|
}
|
||||||
|
else
|
||||||
|
{
|
||||||
|
switch (condition)
|
||||||
|
{
|
||||||
|
case COND_STALE:
|
||||||
|
DBG1(DBG_IKE, "new route to %H found", this->other_host);
|
||||||
|
break;
|
||||||
|
default:
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
this->conditions &= ~condition;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Implementation of ike_sa_t.send_dpd
|
* Implementation of ike_sa_t.send_dpd
|
||||||
@@ -450,40 +552,6 @@ static status_t send_dpd(private_ike_sa_t *this)
|
|||||||
return SUCCESS;
|
return SUCCESS;
|
||||||
}
|
}
|
||||||
|
|
||||||
/**
|
|
||||||
* Implementation of ike_sa_t.send_keepalive
|
|
||||||
*/
|
|
||||||
static void send_keepalive(private_ike_sa_t *this)
|
|
||||||
{
|
|
||||||
send_keepalive_job_t *job;
|
|
||||||
time_t last_out, now, diff;
|
|
||||||
|
|
||||||
last_out = get_use_time(this, FALSE);
|
|
||||||
now = time(NULL);
|
|
||||||
|
|
||||||
diff = now - last_out;
|
|
||||||
|
|
||||||
if (diff >= KEEPALIVE_INTERVAL)
|
|
||||||
{
|
|
||||||
packet_t *packet;
|
|
||||||
chunk_t data;
|
|
||||||
|
|
||||||
packet = packet_create();
|
|
||||||
packet->set_source(packet, this->my_host->clone(this->my_host));
|
|
||||||
packet->set_destination(packet, this->other_host->clone(this->other_host));
|
|
||||||
data.ptr = malloc(1);
|
|
||||||
data.ptr[0] = 0xFF;
|
|
||||||
data.len = 1;
|
|
||||||
packet->set_data(packet, data);
|
|
||||||
charon->sender->send(charon->sender, packet);
|
|
||||||
DBG1(DBG_IKE, "sending keep alive");
|
|
||||||
diff = 0;
|
|
||||||
}
|
|
||||||
job = send_keepalive_job_create(this->ike_sa_id);
|
|
||||||
charon->scheduler->schedule_job(charon->scheduler, (job_t*)job,
|
|
||||||
(KEEPALIVE_INTERVAL - diff) * 1000);
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Implementation of ike_sa_t.get_state.
|
* Implementation of ike_sa_t.get_state.
|
||||||
*/
|
*/
|
||||||
@@ -577,63 +645,60 @@ static void reset(private_ike_sa_t *this)
|
|||||||
*/
|
*/
|
||||||
static void update_hosts(private_ike_sa_t *this, host_t *me, host_t *other)
|
static void update_hosts(private_ike_sa_t *this, host_t *me, host_t *other)
|
||||||
{
|
{
|
||||||
iterator_t *iterator = NULL;
|
bool update = FALSE;
|
||||||
child_sa_t *child_sa = NULL;
|
|
||||||
host_diff_t my_diff, other_diff;
|
|
||||||
|
|
||||||
|
if (me == NULL)
|
||||||
|
{
|
||||||
|
me = this->my_host;
|
||||||
|
}
|
||||||
|
if (other == NULL)
|
||||||
|
{
|
||||||
|
other = this->other_host;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* apply hosts on first received message */
|
||||||
if (this->my_host->is_anyaddr(this->my_host) ||
|
if (this->my_host->is_anyaddr(this->my_host) ||
|
||||||
this->other_host->is_anyaddr(this->other_host))
|
this->other_host->is_anyaddr(this->other_host))
|
||||||
{
|
{
|
||||||
/* on first received message */
|
set_my_host(this, me->clone(me));
|
||||||
this->my_host->destroy(this->my_host);
|
set_other_host(this, other->clone(other));
|
||||||
this->my_host = me->clone(me);
|
update = TRUE;
|
||||||
this->other_host->destroy(this->other_host);
|
|
||||||
this->other_host = other->clone(other);
|
|
||||||
return;
|
|
||||||
}
|
|
||||||
|
|
||||||
my_diff = me->get_differences(me, this->my_host);
|
|
||||||
other_diff = other->get_differences(other, this->other_host);
|
|
||||||
|
|
||||||
if (!my_diff && !other_diff)
|
|
||||||
{
|
|
||||||
return;
|
|
||||||
}
|
|
||||||
|
|
||||||
if (my_diff)
|
|
||||||
{
|
|
||||||
this->my_host->destroy(this->my_host);
|
|
||||||
this->my_host = me->clone(me);
|
|
||||||
}
|
|
||||||
|
|
||||||
if (!(this->conditions & COND_NAT_THERE))
|
|
||||||
{
|
|
||||||
/* update without restrictions if we are not NATted */
|
|
||||||
if (other_diff)
|
|
||||||
{
|
|
||||||
this->other_host->destroy(this->other_host);
|
|
||||||
this->other_host = other->clone(other);
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
else
|
else
|
||||||
{
|
{
|
||||||
/* if we are natted, only port may change */
|
/* update our address in any case */
|
||||||
if (other_diff & HOST_DIFF_ADDR)
|
if (!me->equals(me, this->my_host))
|
||||||
{
|
{
|
||||||
return;
|
set_my_host(this, me->clone(me));
|
||||||
|
update = TRUE;
|
||||||
}
|
}
|
||||||
else if (other_diff & HOST_DIFF_PORT)
|
|
||||||
|
if (!other->equals(other, this->other_host))
|
||||||
{
|
{
|
||||||
this->other_host->set_port(this->other_host, other->get_port(other));
|
/* update others adress if we are NOT NATed,
|
||||||
|
* and allow port changes if we are NATed */
|
||||||
|
if (!has_condition(this, COND_NAT_HERE) ||
|
||||||
|
other->ip_equals(other, this->other_host))
|
||||||
|
{
|
||||||
|
set_other_host(this, other->clone(other));
|
||||||
|
update = TRUE;
|
||||||
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
iterator = this->child_sas->create_iterator(this->child_sas, TRUE);
|
|
||||||
while (iterator->iterate(iterator, (void**)&child_sa))
|
/* update all associated CHILD_SAs, if required */
|
||||||
|
if (update)
|
||||||
{
|
{
|
||||||
child_sa->update_hosts(child_sa, this->my_host, this->other_host,
|
iterator_t *iterator;
|
||||||
my_diff, other_diff);
|
child_sa_t *child_sa;
|
||||||
|
|
||||||
|
iterator = this->child_sas->create_iterator(this->child_sas, TRUE);
|
||||||
|
while (iterator->iterate(iterator, (void**)&child_sa))
|
||||||
|
{
|
||||||
|
child_sa->update_hosts(child_sa, this->my_host, this->other_host);
|
||||||
|
}
|
||||||
|
iterator->destroy(iterator);
|
||||||
}
|
}
|
||||||
iterator->destroy(iterator);
|
|
||||||
}
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
@@ -1248,75 +1313,6 @@ static host_t* get_virtual_ip(private_ike_sa_t *this, bool local)
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
/**
|
|
||||||
* Implementation of ike_sa_t.enable_extension.
|
|
||||||
*/
|
|
||||||
static void enable_extension(private_ike_sa_t *this, ike_extension_t extension)
|
|
||||||
{
|
|
||||||
this->extensions |= extension;
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
|
||||||
* Implementation of ike_sa_t.has_extension.
|
|
||||||
*/
|
|
||||||
static bool supports_extension(private_ike_sa_t *this, ike_extension_t extension)
|
|
||||||
{
|
|
||||||
return (this->extensions & extension) != FALSE;
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
|
||||||
* Implementation of ike_sa_t.has_condition.
|
|
||||||
*/
|
|
||||||
static bool has_condition(private_ike_sa_t *this, ike_condition_t condition)
|
|
||||||
{
|
|
||||||
return (this->conditions & condition) != FALSE;
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
|
||||||
* Implementation of ike_sa_t.enable_condition.
|
|
||||||
*/
|
|
||||||
static void set_condition(private_ike_sa_t *this, ike_condition_t condition,
|
|
||||||
bool enable)
|
|
||||||
{
|
|
||||||
if (has_condition(this, condition) != enable)
|
|
||||||
{
|
|
||||||
if (enable)
|
|
||||||
{
|
|
||||||
switch (condition)
|
|
||||||
{
|
|
||||||
case COND_STALE:
|
|
||||||
DBG1(DBG_IKE, "no route to %H, setting IKE_SA to stale",
|
|
||||||
this->other_host);
|
|
||||||
break;
|
|
||||||
case COND_NAT_HERE:
|
|
||||||
DBG1(DBG_IKE, "local host is behind NAT, sending keep alives");
|
|
||||||
this->conditions |= COND_NAT_ANY;
|
|
||||||
send_keepalive(this);
|
|
||||||
break;
|
|
||||||
case COND_NAT_THERE:
|
|
||||||
DBG1(DBG_IKE, "remote host is behind NAT");
|
|
||||||
this->conditions |= COND_NAT_ANY;
|
|
||||||
break;
|
|
||||||
default:
|
|
||||||
break;
|
|
||||||
}
|
|
||||||
this->conditions |= condition;
|
|
||||||
}
|
|
||||||
else
|
|
||||||
{
|
|
||||||
switch (condition)
|
|
||||||
{
|
|
||||||
case COND_STALE:
|
|
||||||
DBG1(DBG_IKE, "new route to %H found", this->other_host);
|
|
||||||
break;
|
|
||||||
default:
|
|
||||||
break;
|
|
||||||
}
|
|
||||||
this->conditions &= ~condition;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Implementation of ike_sa_t.add_additional_address.
|
* Implementation of ike_sa_t.add_additional_address.
|
||||||
*/
|
*/
|
||||||
@@ -1682,7 +1678,7 @@ static status_t roam(private_ike_sa_t *this)
|
|||||||
|
|
||||||
me = charon->kernel_interface->get_source_addr(charon->kernel_interface,
|
me = charon->kernel_interface->get_source_addr(charon->kernel_interface,
|
||||||
this->other_host);
|
this->other_host);
|
||||||
if (me && me->ip_equals(me, this->my_virtual_ip))
|
if (me && this->my_virtual_ip && me->ip_equals(me, this->my_virtual_ip))
|
||||||
{ /* do not roam to the virtual IP of this IKE_SA */
|
{ /* do not roam to the virtual IP of this IKE_SA */
|
||||||
me->destroy(me);
|
me->destroy(me);
|
||||||
me = NULL;
|
me = NULL;
|
||||||
@@ -1704,11 +1700,13 @@ static status_t roam(private_ike_sa_t *this)
|
|||||||
/* our attachement changed, update if we have mobike */
|
/* our attachement changed, update if we have mobike */
|
||||||
if (supports_extension(this, EXT_MOBIKE))
|
if (supports_extension(this, EXT_MOBIKE))
|
||||||
{
|
{
|
||||||
|
DBG1(DBG_IKE, "requesting address change using MOBIKE");
|
||||||
mobike = ike_mobike_create(&this->public, TRUE);
|
mobike = ike_mobike_create(&this->public, TRUE);
|
||||||
mobike->roam(mobike, me, NULL);
|
mobike->roam(mobike, me, NULL);
|
||||||
this->task_manager->queue_task(this->task_manager, (task_t*)mobike);
|
this->task_manager->queue_task(this->task_manager, (task_t*)mobike);
|
||||||
return this->task_manager->initiate(this->task_manager);
|
return this->task_manager->initiate(this->task_manager);
|
||||||
}
|
}
|
||||||
|
DBG1(DBG_IKE, "reestablishing IKE_SA due address change");
|
||||||
/* reestablish if not */
|
/* reestablish if not */
|
||||||
set_my_host(this, me);
|
set_my_host(this, me);
|
||||||
return reestablish(this);
|
return reestablish(this);
|
||||||
@@ -1736,6 +1734,7 @@ static status_t roam(private_ike_sa_t *this)
|
|||||||
if (me)
|
if (me)
|
||||||
{
|
{
|
||||||
/* good, we have a new route. Use MOBIKE to update */
|
/* good, we have a new route. Use MOBIKE to update */
|
||||||
|
set_condition(this, COND_STALE, FALSE);
|
||||||
iterator->destroy(iterator);
|
iterator->destroy(iterator);
|
||||||
me->set_port(me, this->my_host->get_port(this->my_host));
|
me->set_port(me, this->my_host->get_port(this->my_host));
|
||||||
other->set_port(other, this->other_host->get_port(this->other_host));
|
other->set_port(other, this->other_host->get_port(this->other_host));
|
||||||
@@ -2006,6 +2005,7 @@ ike_sa_t * ike_sa_create(ike_sa_id_t *ike_sa_id)
|
|||||||
this->public.set_my_host = (void (*)(ike_sa_t*,host_t*)) set_my_host;
|
this->public.set_my_host = (void (*)(ike_sa_t*,host_t*)) set_my_host;
|
||||||
this->public.get_other_host = (host_t* (*)(ike_sa_t*)) get_other_host;
|
this->public.get_other_host = (host_t* (*)(ike_sa_t*)) get_other_host;
|
||||||
this->public.set_other_host = (void (*)(ike_sa_t*,host_t*)) set_other_host;
|
this->public.set_other_host = (void (*)(ike_sa_t*,host_t*)) set_other_host;
|
||||||
|
this->public.update_hosts = (void(*)(ike_sa_t*, host_t *me, host_t *other))update_hosts;
|
||||||
this->public.get_my_id = (identification_t* (*)(ike_sa_t*)) get_my_id;
|
this->public.get_my_id = (identification_t* (*)(ike_sa_t*)) get_my_id;
|
||||||
this->public.set_my_id = (void (*)(ike_sa_t*,identification_t*)) set_my_id;
|
this->public.set_my_id = (void (*)(ike_sa_t*,identification_t*)) set_my_id;
|
||||||
this->public.get_other_id = (identification_t* (*)(ike_sa_t*)) get_other_id;
|
this->public.get_other_id = (identification_t* (*)(ike_sa_t*)) get_other_id;
|
||||||
|
|||||||
@@ -282,6 +282,17 @@ struct ike_sa_t {
|
|||||||
*/
|
*/
|
||||||
void (*set_other_host) (ike_sa_t *this, host_t *other);
|
void (*set_other_host) (ike_sa_t *this, host_t *other);
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @brief Update the IKE_SAs host.
|
||||||
|
*
|
||||||
|
* Hosts may be NULL to use current host.
|
||||||
|
*
|
||||||
|
* @param this calling object
|
||||||
|
* @param me new local host address, or NULL
|
||||||
|
* @param other new remote host address, or NULL
|
||||||
|
*/
|
||||||
|
void (*update_hosts)(ike_sa_t *this, host_t *me, host_t *other);
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* @brief Get the own identification.
|
* @brief Get the own identification.
|
||||||
*
|
*
|
||||||
|
|||||||
@@ -355,6 +355,8 @@ static status_t build_request(private_task_manager_t *this)
|
|||||||
case IKE_REKEY:
|
case IKE_REKEY:
|
||||||
exchange = CREATE_CHILD_SA;
|
exchange = CREATE_CHILD_SA;
|
||||||
break;
|
break;
|
||||||
|
case IKE_MOBIKE:
|
||||||
|
exchange = INFORMATIONAL;
|
||||||
default:
|
default:
|
||||||
continue;
|
continue;
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -208,14 +208,7 @@ static status_t build_i(private_ike_mobike_t *this, message_t *message)
|
|||||||
/* TODO: NAT discovery */
|
/* TODO: NAT discovery */
|
||||||
|
|
||||||
/* set new addresses */
|
/* set new addresses */
|
||||||
if (this->me)
|
this->ike_sa->update_hosts(this->ike_sa, this->me, this->other);
|
||||||
{
|
|
||||||
this->ike_sa->set_my_host(this->ike_sa, this->me->clone(this->me));
|
|
||||||
}
|
|
||||||
if (this->other)
|
|
||||||
{
|
|
||||||
this->ike_sa->set_other_host(this->ike_sa, this->other->clone(this->other));
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
return NEED_MORE;
|
return NEED_MORE;
|
||||||
@@ -251,6 +244,10 @@ static status_t build_r(private_ike_mobike_t *this, message_t *message)
|
|||||||
}
|
}
|
||||||
return SUCCESS;
|
return SUCCESS;
|
||||||
}
|
}
|
||||||
|
else if (message->get_exchange_type(message) == INFORMATIONAL)
|
||||||
|
{
|
||||||
|
return SUCCESS;
|
||||||
|
}
|
||||||
return NEED_MORE;
|
return NEED_MORE;
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -265,6 +262,10 @@ static status_t process_i(private_ike_mobike_t *this, message_t *message)
|
|||||||
process_payloads(this, message);
|
process_payloads(this, message);
|
||||||
return SUCCESS;
|
return SUCCESS;
|
||||||
}
|
}
|
||||||
|
else if (message->get_exchange_type(message) == INFORMATIONAL)
|
||||||
|
{
|
||||||
|
return SUCCESS;
|
||||||
|
}
|
||||||
return NEED_MORE;
|
return NEED_MORE;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user