diff --git a/INSTALL b/INSTALL index cbc4cb351..873aba869 100644 --- a/INSTALL +++ b/INSTALL @@ -75,16 +75,13 @@ Contents If you intend to dynamically fetch Certificate Revocation Lists (CRLs) from an HTTP server or as an alternative want to use the Online - Certificate Status Protocol (OCSP) then you will need the either of the - following libraries: + Certificate Status Protocol (OCSP) then you will need the following library: * The cURL library (libcurl) https://curl.se/libcurl/ - * The LibSoup library (libsoup) - https://live.gnome.org/LibSoup - In order to activate the use of either of these libraries in strongSwan you - must enable the appropriate ./configure switch. + In order to activate the use of this library in strongSwan you must enable + the appropriate ./configure switch. 3.2 LDAP diff --git a/configure.ac b/configure.ac index 60774a95a..bf5a5fee9 100644 --- a/configure.ac +++ b/configure.ac @@ -173,7 +173,6 @@ ARG_ENABL_SET([openxpki], [enable OCSP responder accessing OpenXPKI certif ARG_ENABL_SET([curl], [enable CURL fetcher plugin to fetch files via libcurl. Requires libcurl.]) ARG_ENABL_SET([files], [enable simple file:// URI fetcher.]) ARG_ENABL_SET([ldap], [enable LDAP fetching plugin to fetch files via libldap. Requires openLDAP.]) -ARG_ENABL_SET([soup], [enable soup fetcher plugin to fetch from HTTP via libsoup. Requires libsoup.]) ARG_ENABL_SET([unbound], [enable UNBOUND resolver plugin to perform DNS queries via libunbound. Requires libldns and libunbound.]) ARG_ENABL_SET([winhttp], [enable WinHTTP based HTTP/HTTPS fetching plugin.]) # database plugins @@ -1018,12 +1017,6 @@ if test x$unbound = xtrue; then AC_CHECK_HEADER([unbound.h],,[AC_MSG_ERROR([UNBOUND header unbound.h not found!])]) fi -if test x$soup = xtrue; then - PKG_CHECK_MODULES(soup, [libsoup-3.0]) - AC_SUBST(soup_CFLAGS) - AC_SUBST(soup_LIBS) -fi - if test x$xml = xtrue; then PKG_CHECK_MODULES(xml, [libxml-2.0]) AC_SUBST(xml_CFLAGS) @@ -1522,7 +1515,6 @@ ADD_PLUGIN([drbg], [s charon swanctl pki scripts nm cmd]) ADD_PLUGIN([curl], [s charon pki scripts nm cmd]) ADD_PLUGIN([files], [s charon pki scripts nm cmd]) ADD_PLUGIN([winhttp], [s charon pki scripts]) -ADD_PLUGIN([soup], [s charon pki scripts nm cmd]) ADD_PLUGIN([mysql], [s charon pki pool attest]) ADD_PLUGIN([sqlite], [s charon pki pool attest]) ADD_PLUGIN([openxpki], [s pki]) @@ -1625,7 +1617,6 @@ AM_CONDITIONAL(USE_CURL, test x$curl = xtrue) AM_CONDITIONAL(USE_FILES, test x$files = xtrue) AM_CONDITIONAL(USE_WINHTTP, test x$winhttp = xtrue) AM_CONDITIONAL(USE_UNBOUND, test x$unbound = xtrue) -AM_CONDITIONAL(USE_SOUP, test x$soup = xtrue) AM_CONDITIONAL(USE_LDAP, test x$ldap = xtrue) AM_CONDITIONAL(USE_AES, test x$aes = xtrue) AM_CONDITIONAL(USE_DES, test x$des = xtrue) @@ -1940,7 +1931,6 @@ AC_CONFIG_FILES([ src/libstrongswan/plugins/files/Makefile src/libstrongswan/plugins/winhttp/Makefile src/libstrongswan/plugins/unbound/Makefile - src/libstrongswan/plugins/soup/Makefile src/libstrongswan/plugins/ldap/Makefile src/libstrongswan/plugins/mysql/Makefile src/libstrongswan/plugins/sqlite/Makefile diff --git a/scripts/test.sh b/scripts/test.sh index 2a4d32c7d..034f68c3e 100755 --- a/scripts/test.sh +++ b/scripts/test.sh @@ -272,7 +272,7 @@ all|alpine|codeql|coverage|sonarcloud|no-dbg|no-testable-ke) if [ "$TEST" = "no-testable-ke" ]; then CONFIG="$CONFIG --without-testable-ke" fi - DEPS="$DEPS libcurl4-gnutls-dev libsoup-3.0-dev libunbound-dev libldns-dev + DEPS="$DEPS libcurl4-gnutls-dev libunbound-dev libldns-dev libmysqlclient-dev libsqlite3-dev libldap2-dev libpcsclite-dev libpam0g-dev binutils-dev libnm-dev libjson-c-dev libtspi-dev libsystemd-dev @@ -285,7 +285,7 @@ all|alpine|codeql|coverage|sonarcloud|no-dbg|no-testable-ke) fi if [ "$TEST" = "alpine" ]; then # override the whole list for alpine - DEPS="git gmp-dev openldap-dev curl-dev ldns-dev unbound-dev libsoup3-dev + DEPS="git gmp-dev openldap-dev curl-dev ldns-dev unbound-dev libxml2-dev tpm2-tss-dev tpm2-tss-sys mariadb-dev wolfssl-dev botan3-dev pcsc-lite-dev networkmanager-dev linux-pam-dev iptables-dev libselinux-dev binutils-dev libunwind-dev diff --git a/src/libstrongswan/Makefile.am b/src/libstrongswan/Makefile.am index f4a70b6e9..3687135fa 100644 --- a/src/libstrongswan/Makefile.am +++ b/src/libstrongswan/Makefile.am @@ -537,13 +537,6 @@ if MONOLITHIC endif endif -if USE_SOUP - SUBDIRS += plugins/soup -if MONOLITHIC - libstrongswan_la_LIBADD += plugins/soup/libstrongswan-soup.la -endif -endif - if USE_LDAP SUBDIRS += plugins/ldap if MONOLITHIC diff --git a/src/libstrongswan/plugins/soup/Makefile.am b/src/libstrongswan/plugins/soup/Makefile.am deleted file mode 100644 index a600fc04c..000000000 --- a/src/libstrongswan/plugins/soup/Makefile.am +++ /dev/null @@ -1,18 +0,0 @@ -AM_CPPFLAGS = \ - -I$(top_srcdir)/src/libstrongswan - -AM_CFLAGS = \ - ${soup_CFLAGS} \ - $(PLUGIN_CFLAGS) - -if MONOLITHIC -noinst_LTLIBRARIES = libstrongswan-soup.la -else -plugin_LTLIBRARIES = libstrongswan-soup.la -endif - -libstrongswan_soup_la_SOURCES = \ - soup_plugin.h soup_plugin.c soup_fetcher.c soup_fetcher.h - -libstrongswan_soup_la_LDFLAGS = -module -avoid-version -libstrongswan_soup_la_LIBADD = ${soup_LIBS} diff --git a/src/libstrongswan/plugins/soup/soup_fetcher.c b/src/libstrongswan/plugins/soup/soup_fetcher.c deleted file mode 100644 index 6c0cba2cb..000000000 --- a/src/libstrongswan/plugins/soup/soup_fetcher.c +++ /dev/null @@ -1,188 +0,0 @@ -/* - * Copyright (C) 2010 Martin Willi - * - * Copyright (C) secunet Security Networks AG - * - * This program is free software; you can redistribute it and/or modify it - * under the terms of the GNU General Public License as published by the - * Free Software Foundation; either version 2 of the License, or (at your - * option) any later version. See . - * - * This program is distributed in the hope that it will be useful, but - * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY - * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License - * for more details. - */ - -#include "soup_fetcher.h" - -#include - -#include -#include - -#define DEFAULT_TIMEOUT 10 - -typedef struct private_soup_fetcher_t private_soup_fetcher_t; - -/** - * private data of a soup_fetcher_t object. - */ -struct private_soup_fetcher_t { - - /** - * Public data - */ - soup_fetcher_t public; - - /** - * HTTP request method - */ - const char *method; - - /** - * Request content type - */ - char *type; - - /** - * Request data - */ - chunk_t data; - - /** - * Request timeout - */ - u_int timeout; - - /** - * Fetcher callback function - */ - fetcher_callback_t cb; - - /** - * Response status - */ - u_int *result; -}; - -METHOD(fetcher_t, fetch, status_t, - private_soup_fetcher_t *this, char *uri, void *userdata) -{ - SoupMessage *message; - status_t status = FAILED; - GBytes *request_body, *res; - SoupSession *session; - - message = soup_message_new(this->method, uri); - if (!message) - { - return NOT_SUPPORTED; - } - if (this->cb == fetcher_default_callback) - { - *(chunk_t*)userdata = chunk_empty; - } - if (this->type) - { - request_body = g_bytes_new_static(this->data.ptr, this->data.len); - soup_message_set_request_body_from_bytes(message, this->type, - request_body); - g_bytes_unref(request_body); - } - session = soup_session_new_with_options("timeout", (guint)this->timeout, - NULL); - - DBG2(DBG_LIB, "sending http request to '%s'...", uri); - res = soup_session_send_and_read(session, message, NULL, NULL); - if (this->result) - { - *this->result = soup_message_get_status(message); - } - if (SOUP_STATUS_IS_SUCCESSFUL(soup_message_get_status(message))) - { - status = SUCCESS; - } - else if (!this->result) - { /* only log an error if the code is not returned */ - DBG1(DBG_LIB, "HTTP request failed: %s", - soup_message_get_reason_phrase(message)); - } - if (res) - { - gpointer data; - gsize data_len; - - data = g_bytes_unref_to_data(res, &data_len); - if (!this->cb(userdata, chunk_create(data, data_len))) - { - status = FAILED; - } - g_free(data); - } - g_object_unref(G_OBJECT(message)); - g_object_unref(G_OBJECT(session)); - return status; -} - -METHOD(fetcher_t, set_option, bool, - private_soup_fetcher_t *this, fetcher_option_t option, ...) -{ - bool supported = TRUE; - va_list args; - - va_start(args, option); - switch (option) - { - case FETCH_REQUEST_DATA: - this->method = SOUP_METHOD_POST; - this->data = va_arg(args, chunk_t); - break; - case FETCH_REQUEST_TYPE: - this->type = va_arg(args, char*); - break; - case FETCH_TIMEOUT: - this->timeout = va_arg(args, u_int); - break; - case FETCH_CALLBACK: - this->cb = va_arg(args, fetcher_callback_t); - break; - case FETCH_RESPONSE_CODE: - this->result = va_arg(args, u_int*); - break; - default: - supported = FALSE; - break; - } - va_end(args); - return supported; -} - -METHOD(fetcher_t, destroy, void, - private_soup_fetcher_t *this) -{ - free(this); -} - -/* - * Described in header. - */ -soup_fetcher_t *soup_fetcher_create() -{ - private_soup_fetcher_t *this; - - INIT(this, - .public = { - .interface = { - .fetch = _fetch, - .set_option = _set_option, - .destroy = _destroy, - }, - }, - .method = SOUP_METHOD_GET, - .timeout = DEFAULT_TIMEOUT, - .cb = fetcher_default_callback, - ); - - return &this->public; -} diff --git a/src/libstrongswan/plugins/soup/soup_fetcher.h b/src/libstrongswan/plugins/soup/soup_fetcher.h deleted file mode 100644 index 53123a0e1..000000000 --- a/src/libstrongswan/plugins/soup/soup_fetcher.h +++ /dev/null @@ -1,45 +0,0 @@ -/* - * Copyright (C) 2010 Martin Willi - * - * Copyright (C) secunet Security Networks AG - * - * This program is free software; you can redistribute it and/or modify it - * under the terms of the GNU General Public License as published by the - * Free Software Foundation; either version 2 of the License, or (at your - * option) any later version. See . - * - * This program is distributed in the hope that it will be useful, but - * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY - * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License - * for more details. - */ - -/** - * @defgroup soup_fetcher soup_fetcher - * @{ @ingroup soup_p - */ - -#ifndef SOUP_FETCHER_H_ -#define SOUP_FETCHER_H_ - -#include - -typedef struct soup_fetcher_t soup_fetcher_t; - -/** - * Fetcher implementation for HTTP using libsoup. - */ -struct soup_fetcher_t { - - /** - * Implements fetcher interface. - */ - fetcher_t interface; -}; - -/** - * Create a soup_fetcher instance. - */ -soup_fetcher_t *soup_fetcher_create(); - -#endif /** SOUP_FETCHER_H_ @}*/ diff --git a/src/libstrongswan/plugins/soup/soup_plugin.c b/src/libstrongswan/plugins/soup/soup_plugin.c deleted file mode 100644 index 9ab881f0e..000000000 --- a/src/libstrongswan/plugins/soup/soup_plugin.c +++ /dev/null @@ -1,91 +0,0 @@ -/* - * Copyright (C) 2010 Martin Willi - * - * Copyright (C) secunet Security Networks AG - * - * This program is free software; you can redistribute it and/or modify it - * under the terms of the GNU General Public License as published by the - * Free Software Foundation; either version 2 of the License, or (at your - * option) any later version. See . - * - * This program is distributed in the hope that it will be useful, but - * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY - * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License - * for more details. - */ - -#include "soup_plugin.h" -#include "soup_fetcher.h" - -#include -#include - -#include - -typedef struct private_soup_plugin_t private_soup_plugin_t; - -/** - * private data of soup_plugin - */ -struct private_soup_plugin_t { - - /** - * public functions - */ - soup_plugin_t public; -}; - -METHOD(plugin_t, get_name, char*, - private_soup_plugin_t *this) -{ - return "soup"; -} - -METHOD(plugin_t, get_features, int, - private_soup_plugin_t *this, plugin_feature_t *features[]) -{ - static plugin_feature_t f[] = { - PLUGIN_REGISTER(FETCHER, soup_fetcher_create), - PLUGIN_PROVIDE(FETCHER, "http://"), - PLUGIN_PROVIDE(FETCHER, "https://"), - }; - *features = f; - return countof(f); -} - -METHOD(plugin_t, destroy, void, - private_soup_plugin_t *this) -{ - free(this); -} - -/* - * see header file - */ -PLUGIN_DEFINE(soup) -{ - private_soup_plugin_t *this; - -#if !GLIB_CHECK_VERSION(2,36,0) - g_type_init(); -#endif - -#if !GLIB_CHECK_VERSION(2,23,0) - if (!g_thread_get_initialized()) - { - g_thread_init(NULL); - } -#endif - - INIT(this, - .public = { - .plugin = { - .get_name = _get_name, - .get_features = _get_features, - .destroy = _destroy, - }, - }, - ); - - return &this->public.plugin; -} diff --git a/src/libstrongswan/plugins/soup/soup_plugin.h b/src/libstrongswan/plugins/soup/soup_plugin.h deleted file mode 100644 index cab654272..000000000 --- a/src/libstrongswan/plugins/soup/soup_plugin.h +++ /dev/null @@ -1,43 +0,0 @@ -/* - * Copyright (C) 2010 Martin Willi - * - * Copyright (C) secunet Security Networks AG - * - * This program is free software; you can redistribute it and/or modify it - * under the terms of the GNU General Public License as published by the - * Free Software Foundation; either version 2 of the License, or (at your - * option) any later version. See . - * - * This program is distributed in the hope that it will be useful, but - * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY - * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License - * for more details. - */ - -/** - * @defgroup soup_p soup - * @ingroup plugins - * - * @defgroup soup_plugin soup_plugin - * @{ @ingroup soup_p - */ - -#ifndef SOUP_PLUGIN_H_ -#define SOUP_PLUGIN_H_ - -#include - -typedef struct soup_plugin_t soup_plugin_t; - -/** - * Plugin implementing fetcher interface for HTTP using libsoup. - */ -struct soup_plugin_t { - - /** - * Implements plugin interface - */ - plugin_t plugin; -}; - -#endif /** SOUP_PLUGIN_H_ @}*/