From 3a23a56b29776e9ab961352df1c35e1538b23545 Mon Sep 17 00:00:00 2001 From: Tobias Brunner Date: Fri, 24 Jul 2026 15:27:12 +0200 Subject: [PATCH] soup: Remove limited fetcher plugin Besides the relatively recent update to libsoup-3, this has not seen much development and lacks several features. There does not seem to be any advantage over using the curl plugin. So just remove it to reduce the maintenance burden. --- INSTALL | 9 +- configure.ac | 10 - scripts/test.sh | 4 +- src/libstrongswan/Makefile.am | 7 - src/libstrongswan/plugins/soup/Makefile.am | 18 -- src/libstrongswan/plugins/soup/soup_fetcher.c | 188 ------------------ src/libstrongswan/plugins/soup/soup_fetcher.h | 45 ----- src/libstrongswan/plugins/soup/soup_plugin.c | 91 --------- src/libstrongswan/plugins/soup/soup_plugin.h | 43 ---- 9 files changed, 5 insertions(+), 410 deletions(-) delete mode 100644 src/libstrongswan/plugins/soup/Makefile.am delete mode 100644 src/libstrongswan/plugins/soup/soup_fetcher.c delete mode 100644 src/libstrongswan/plugins/soup/soup_fetcher.h delete mode 100644 src/libstrongswan/plugins/soup/soup_plugin.c delete mode 100644 src/libstrongswan/plugins/soup/soup_plugin.h diff --git a/INSTALL b/INSTALL index cbc4cb351..873aba869 100644 --- a/INSTALL +++ b/INSTALL @@ -75,16 +75,13 @@ Contents If you intend to dynamically fetch Certificate Revocation Lists (CRLs) from an HTTP server or as an alternative want to use the Online - Certificate Status Protocol (OCSP) then you will need the either of the - following libraries: + Certificate Status Protocol (OCSP) then you will need the following library: * The cURL library (libcurl) https://curl.se/libcurl/ - * The LibSoup library (libsoup) - https://live.gnome.org/LibSoup - In order to activate the use of either of these libraries in strongSwan you - must enable the appropriate ./configure switch. + In order to activate the use of this library in strongSwan you must enable + the appropriate ./configure switch. 3.2 LDAP diff --git a/configure.ac b/configure.ac index 60774a95a..bf5a5fee9 100644 --- a/configure.ac +++ b/configure.ac @@ -173,7 +173,6 @@ ARG_ENABL_SET([openxpki], [enable OCSP responder accessing OpenXPKI certif ARG_ENABL_SET([curl], [enable CURL fetcher plugin to fetch files via libcurl. Requires libcurl.]) ARG_ENABL_SET([files], [enable simple file:// URI fetcher.]) ARG_ENABL_SET([ldap], [enable LDAP fetching plugin to fetch files via libldap. Requires openLDAP.]) -ARG_ENABL_SET([soup], [enable soup fetcher plugin to fetch from HTTP via libsoup. Requires libsoup.]) ARG_ENABL_SET([unbound], [enable UNBOUND resolver plugin to perform DNS queries via libunbound. Requires libldns and libunbound.]) ARG_ENABL_SET([winhttp], [enable WinHTTP based HTTP/HTTPS fetching plugin.]) # database plugins @@ -1018,12 +1017,6 @@ if test x$unbound = xtrue; then AC_CHECK_HEADER([unbound.h],,[AC_MSG_ERROR([UNBOUND header unbound.h not found!])]) fi -if test x$soup = xtrue; then - PKG_CHECK_MODULES(soup, [libsoup-3.0]) - AC_SUBST(soup_CFLAGS) - AC_SUBST(soup_LIBS) -fi - if test x$xml = xtrue; then PKG_CHECK_MODULES(xml, [libxml-2.0]) AC_SUBST(xml_CFLAGS) @@ -1522,7 +1515,6 @@ ADD_PLUGIN([drbg], [s charon swanctl pki scripts nm cmd]) ADD_PLUGIN([curl], [s charon pki scripts nm cmd]) ADD_PLUGIN([files], [s charon pki scripts nm cmd]) ADD_PLUGIN([winhttp], [s charon pki scripts]) -ADD_PLUGIN([soup], [s charon pki scripts nm cmd]) ADD_PLUGIN([mysql], [s charon pki pool attest]) ADD_PLUGIN([sqlite], [s charon pki pool attest]) ADD_PLUGIN([openxpki], [s pki]) @@ -1625,7 +1617,6 @@ AM_CONDITIONAL(USE_CURL, test x$curl = xtrue) AM_CONDITIONAL(USE_FILES, test x$files = xtrue) AM_CONDITIONAL(USE_WINHTTP, test x$winhttp = xtrue) AM_CONDITIONAL(USE_UNBOUND, test x$unbound = xtrue) -AM_CONDITIONAL(USE_SOUP, test x$soup = xtrue) AM_CONDITIONAL(USE_LDAP, test x$ldap = xtrue) AM_CONDITIONAL(USE_AES, test x$aes = xtrue) AM_CONDITIONAL(USE_DES, test x$des = xtrue) @@ -1940,7 +1931,6 @@ AC_CONFIG_FILES([ src/libstrongswan/plugins/files/Makefile src/libstrongswan/plugins/winhttp/Makefile src/libstrongswan/plugins/unbound/Makefile - src/libstrongswan/plugins/soup/Makefile src/libstrongswan/plugins/ldap/Makefile src/libstrongswan/plugins/mysql/Makefile src/libstrongswan/plugins/sqlite/Makefile diff --git a/scripts/test.sh b/scripts/test.sh index 2a4d32c7d..034f68c3e 100755 --- a/scripts/test.sh +++ b/scripts/test.sh @@ -272,7 +272,7 @@ all|alpine|codeql|coverage|sonarcloud|no-dbg|no-testable-ke) if [ "$TEST" = "no-testable-ke" ]; then CONFIG="$CONFIG --without-testable-ke" fi - DEPS="$DEPS libcurl4-gnutls-dev libsoup-3.0-dev libunbound-dev libldns-dev + DEPS="$DEPS libcurl4-gnutls-dev libunbound-dev libldns-dev libmysqlclient-dev libsqlite3-dev libldap2-dev libpcsclite-dev libpam0g-dev binutils-dev libnm-dev libjson-c-dev libtspi-dev libsystemd-dev @@ -285,7 +285,7 @@ all|alpine|codeql|coverage|sonarcloud|no-dbg|no-testable-ke) fi if [ "$TEST" = "alpine" ]; then # override the whole list for alpine - DEPS="git gmp-dev openldap-dev curl-dev ldns-dev unbound-dev libsoup3-dev + DEPS="git gmp-dev openldap-dev curl-dev ldns-dev unbound-dev libxml2-dev tpm2-tss-dev tpm2-tss-sys mariadb-dev wolfssl-dev botan3-dev pcsc-lite-dev networkmanager-dev linux-pam-dev iptables-dev libselinux-dev binutils-dev libunwind-dev diff --git a/src/libstrongswan/Makefile.am b/src/libstrongswan/Makefile.am index f4a70b6e9..3687135fa 100644 --- a/src/libstrongswan/Makefile.am +++ b/src/libstrongswan/Makefile.am @@ -537,13 +537,6 @@ if MONOLITHIC endif endif -if USE_SOUP - SUBDIRS += plugins/soup -if MONOLITHIC - libstrongswan_la_LIBADD += plugins/soup/libstrongswan-soup.la -endif -endif - if USE_LDAP SUBDIRS += plugins/ldap if MONOLITHIC diff --git a/src/libstrongswan/plugins/soup/Makefile.am b/src/libstrongswan/plugins/soup/Makefile.am deleted file mode 100644 index a600fc04c..000000000 --- a/src/libstrongswan/plugins/soup/Makefile.am +++ /dev/null @@ -1,18 +0,0 @@ -AM_CPPFLAGS = \ - -I$(top_srcdir)/src/libstrongswan - -AM_CFLAGS = \ - ${soup_CFLAGS} \ - $(PLUGIN_CFLAGS) - -if MONOLITHIC -noinst_LTLIBRARIES = libstrongswan-soup.la -else -plugin_LTLIBRARIES = libstrongswan-soup.la -endif - -libstrongswan_soup_la_SOURCES = \ - soup_plugin.h soup_plugin.c soup_fetcher.c soup_fetcher.h - -libstrongswan_soup_la_LDFLAGS = -module -avoid-version -libstrongswan_soup_la_LIBADD = ${soup_LIBS} diff --git a/src/libstrongswan/plugins/soup/soup_fetcher.c b/src/libstrongswan/plugins/soup/soup_fetcher.c deleted file mode 100644 index 6c0cba2cb..000000000 --- a/src/libstrongswan/plugins/soup/soup_fetcher.c +++ /dev/null @@ -1,188 +0,0 @@ -/* - * Copyright (C) 2010 Martin Willi - * - * Copyright (C) secunet Security Networks AG - * - * This program is free software; you can redistribute it and/or modify it - * under the terms of the GNU General Public License as published by the - * Free Software Foundation; either version 2 of the License, or (at your - * option) any later version. See . - * - * This program is distributed in the hope that it will be useful, but - * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY - * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License - * for more details. - */ - -#include "soup_fetcher.h" - -#include - -#include -#include - -#define DEFAULT_TIMEOUT 10 - -typedef struct private_soup_fetcher_t private_soup_fetcher_t; - -/** - * private data of a soup_fetcher_t object. - */ -struct private_soup_fetcher_t { - - /** - * Public data - */ - soup_fetcher_t public; - - /** - * HTTP request method - */ - const char *method; - - /** - * Request content type - */ - char *type; - - /** - * Request data - */ - chunk_t data; - - /** - * Request timeout - */ - u_int timeout; - - /** - * Fetcher callback function - */ - fetcher_callback_t cb; - - /** - * Response status - */ - u_int *result; -}; - -METHOD(fetcher_t, fetch, status_t, - private_soup_fetcher_t *this, char *uri, void *userdata) -{ - SoupMessage *message; - status_t status = FAILED; - GBytes *request_body, *res; - SoupSession *session; - - message = soup_message_new(this->method, uri); - if (!message) - { - return NOT_SUPPORTED; - } - if (this->cb == fetcher_default_callback) - { - *(chunk_t*)userdata = chunk_empty; - } - if (this->type) - { - request_body = g_bytes_new_static(this->data.ptr, this->data.len); - soup_message_set_request_body_from_bytes(message, this->type, - request_body); - g_bytes_unref(request_body); - } - session = soup_session_new_with_options("timeout", (guint)this->timeout, - NULL); - - DBG2(DBG_LIB, "sending http request to '%s'...", uri); - res = soup_session_send_and_read(session, message, NULL, NULL); - if (this->result) - { - *this->result = soup_message_get_status(message); - } - if (SOUP_STATUS_IS_SUCCESSFUL(soup_message_get_status(message))) - { - status = SUCCESS; - } - else if (!this->result) - { /* only log an error if the code is not returned */ - DBG1(DBG_LIB, "HTTP request failed: %s", - soup_message_get_reason_phrase(message)); - } - if (res) - { - gpointer data; - gsize data_len; - - data = g_bytes_unref_to_data(res, &data_len); - if (!this->cb(userdata, chunk_create(data, data_len))) - { - status = FAILED; - } - g_free(data); - } - g_object_unref(G_OBJECT(message)); - g_object_unref(G_OBJECT(session)); - return status; -} - -METHOD(fetcher_t, set_option, bool, - private_soup_fetcher_t *this, fetcher_option_t option, ...) -{ - bool supported = TRUE; - va_list args; - - va_start(args, option); - switch (option) - { - case FETCH_REQUEST_DATA: - this->method = SOUP_METHOD_POST; - this->data = va_arg(args, chunk_t); - break; - case FETCH_REQUEST_TYPE: - this->type = va_arg(args, char*); - break; - case FETCH_TIMEOUT: - this->timeout = va_arg(args, u_int); - break; - case FETCH_CALLBACK: - this->cb = va_arg(args, fetcher_callback_t); - break; - case FETCH_RESPONSE_CODE: - this->result = va_arg(args, u_int*); - break; - default: - supported = FALSE; - break; - } - va_end(args); - return supported; -} - -METHOD(fetcher_t, destroy, void, - private_soup_fetcher_t *this) -{ - free(this); -} - -/* - * Described in header. - */ -soup_fetcher_t *soup_fetcher_create() -{ - private_soup_fetcher_t *this; - - INIT(this, - .public = { - .interface = { - .fetch = _fetch, - .set_option = _set_option, - .destroy = _destroy, - }, - }, - .method = SOUP_METHOD_GET, - .timeout = DEFAULT_TIMEOUT, - .cb = fetcher_default_callback, - ); - - return &this->public; -} diff --git a/src/libstrongswan/plugins/soup/soup_fetcher.h b/src/libstrongswan/plugins/soup/soup_fetcher.h deleted file mode 100644 index 53123a0e1..000000000 --- a/src/libstrongswan/plugins/soup/soup_fetcher.h +++ /dev/null @@ -1,45 +0,0 @@ -/* - * Copyright (C) 2010 Martin Willi - * - * Copyright (C) secunet Security Networks AG - * - * This program is free software; you can redistribute it and/or modify it - * under the terms of the GNU General Public License as published by the - * Free Software Foundation; either version 2 of the License, or (at your - * option) any later version. See . - * - * This program is distributed in the hope that it will be useful, but - * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY - * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License - * for more details. - */ - -/** - * @defgroup soup_fetcher soup_fetcher - * @{ @ingroup soup_p - */ - -#ifndef SOUP_FETCHER_H_ -#define SOUP_FETCHER_H_ - -#include - -typedef struct soup_fetcher_t soup_fetcher_t; - -/** - * Fetcher implementation for HTTP using libsoup. - */ -struct soup_fetcher_t { - - /** - * Implements fetcher interface. - */ - fetcher_t interface; -}; - -/** - * Create a soup_fetcher instance. - */ -soup_fetcher_t *soup_fetcher_create(); - -#endif /** SOUP_FETCHER_H_ @}*/ diff --git a/src/libstrongswan/plugins/soup/soup_plugin.c b/src/libstrongswan/plugins/soup/soup_plugin.c deleted file mode 100644 index 9ab881f0e..000000000 --- a/src/libstrongswan/plugins/soup/soup_plugin.c +++ /dev/null @@ -1,91 +0,0 @@ -/* - * Copyright (C) 2010 Martin Willi - * - * Copyright (C) secunet Security Networks AG - * - * This program is free software; you can redistribute it and/or modify it - * under the terms of the GNU General Public License as published by the - * Free Software Foundation; either version 2 of the License, or (at your - * option) any later version. See . - * - * This program is distributed in the hope that it will be useful, but - * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY - * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License - * for more details. - */ - -#include "soup_plugin.h" -#include "soup_fetcher.h" - -#include -#include - -#include - -typedef struct private_soup_plugin_t private_soup_plugin_t; - -/** - * private data of soup_plugin - */ -struct private_soup_plugin_t { - - /** - * public functions - */ - soup_plugin_t public; -}; - -METHOD(plugin_t, get_name, char*, - private_soup_plugin_t *this) -{ - return "soup"; -} - -METHOD(plugin_t, get_features, int, - private_soup_plugin_t *this, plugin_feature_t *features[]) -{ - static plugin_feature_t f[] = { - PLUGIN_REGISTER(FETCHER, soup_fetcher_create), - PLUGIN_PROVIDE(FETCHER, "http://"), - PLUGIN_PROVIDE(FETCHER, "https://"), - }; - *features = f; - return countof(f); -} - -METHOD(plugin_t, destroy, void, - private_soup_plugin_t *this) -{ - free(this); -} - -/* - * see header file - */ -PLUGIN_DEFINE(soup) -{ - private_soup_plugin_t *this; - -#if !GLIB_CHECK_VERSION(2,36,0) - g_type_init(); -#endif - -#if !GLIB_CHECK_VERSION(2,23,0) - if (!g_thread_get_initialized()) - { - g_thread_init(NULL); - } -#endif - - INIT(this, - .public = { - .plugin = { - .get_name = _get_name, - .get_features = _get_features, - .destroy = _destroy, - }, - }, - ); - - return &this->public.plugin; -} diff --git a/src/libstrongswan/plugins/soup/soup_plugin.h b/src/libstrongswan/plugins/soup/soup_plugin.h deleted file mode 100644 index cab654272..000000000 --- a/src/libstrongswan/plugins/soup/soup_plugin.h +++ /dev/null @@ -1,43 +0,0 @@ -/* - * Copyright (C) 2010 Martin Willi - * - * Copyright (C) secunet Security Networks AG - * - * This program is free software; you can redistribute it and/or modify it - * under the terms of the GNU General Public License as published by the - * Free Software Foundation; either version 2 of the License, or (at your - * option) any later version. See . - * - * This program is distributed in the hope that it will be useful, but - * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY - * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License - * for more details. - */ - -/** - * @defgroup soup_p soup - * @ingroup plugins - * - * @defgroup soup_plugin soup_plugin - * @{ @ingroup soup_p - */ - -#ifndef SOUP_PLUGIN_H_ -#define SOUP_PLUGIN_H_ - -#include - -typedef struct soup_plugin_t soup_plugin_t; - -/** - * Plugin implementing fetcher interface for HTTP using libsoup. - */ -struct soup_plugin_t { - - /** - * Implements plugin interface - */ - plugin_t plugin; -}; - -#endif /** SOUP_PLUGIN_H_ @}*/