soup: Remove limited fetcher plugin

Besides the relatively recent update to libsoup-3, this has not seen
much development and lacks several features.  There does not seem to be
any advantage over using the curl plugin.  So just remove it to reduce
the maintenance burden.
This commit is contained in:
Tobias Brunner
2026-07-27 08:09:39 +02:00
parent 7d122d5a98
commit 3a23a56b29
9 changed files with 5 additions and 410 deletions
+3 -6
View File
@@ -75,16 +75,13 @@ Contents
If you intend to dynamically fetch Certificate Revocation Lists (CRLs) If you intend to dynamically fetch Certificate Revocation Lists (CRLs)
from an HTTP server or as an alternative want to use the Online from an HTTP server or as an alternative want to use the Online
Certificate Status Protocol (OCSP) then you will need the either of the Certificate Status Protocol (OCSP) then you will need the following library:
following libraries:
* The cURL library (libcurl) * The cURL library (libcurl)
https://curl.se/libcurl/ https://curl.se/libcurl/
* The LibSoup library (libsoup)
https://live.gnome.org/LibSoup
In order to activate the use of either of these libraries in strongSwan you In order to activate the use of this library in strongSwan you must enable
must enable the appropriate ./configure switch. the appropriate ./configure switch.
3.2 LDAP 3.2 LDAP
-10
View File
@@ -173,7 +173,6 @@ ARG_ENABL_SET([openxpki], [enable OCSP responder accessing OpenXPKI certif
ARG_ENABL_SET([curl], [enable CURL fetcher plugin to fetch files via libcurl. Requires libcurl.]) ARG_ENABL_SET([curl], [enable CURL fetcher plugin to fetch files via libcurl. Requires libcurl.])
ARG_ENABL_SET([files], [enable simple file:// URI fetcher.]) ARG_ENABL_SET([files], [enable simple file:// URI fetcher.])
ARG_ENABL_SET([ldap], [enable LDAP fetching plugin to fetch files via libldap. Requires openLDAP.]) ARG_ENABL_SET([ldap], [enable LDAP fetching plugin to fetch files via libldap. Requires openLDAP.])
ARG_ENABL_SET([soup], [enable soup fetcher plugin to fetch from HTTP via libsoup. Requires libsoup.])
ARG_ENABL_SET([unbound], [enable UNBOUND resolver plugin to perform DNS queries via libunbound. Requires libldns and libunbound.]) ARG_ENABL_SET([unbound], [enable UNBOUND resolver plugin to perform DNS queries via libunbound. Requires libldns and libunbound.])
ARG_ENABL_SET([winhttp], [enable WinHTTP based HTTP/HTTPS fetching plugin.]) ARG_ENABL_SET([winhttp], [enable WinHTTP based HTTP/HTTPS fetching plugin.])
# database plugins # database plugins
@@ -1018,12 +1017,6 @@ if test x$unbound = xtrue; then
AC_CHECK_HEADER([unbound.h],,[AC_MSG_ERROR([UNBOUND header unbound.h not found!])]) AC_CHECK_HEADER([unbound.h],,[AC_MSG_ERROR([UNBOUND header unbound.h not found!])])
fi fi
if test x$soup = xtrue; then
PKG_CHECK_MODULES(soup, [libsoup-3.0])
AC_SUBST(soup_CFLAGS)
AC_SUBST(soup_LIBS)
fi
if test x$xml = xtrue; then if test x$xml = xtrue; then
PKG_CHECK_MODULES(xml, [libxml-2.0]) PKG_CHECK_MODULES(xml, [libxml-2.0])
AC_SUBST(xml_CFLAGS) AC_SUBST(xml_CFLAGS)
@@ -1522,7 +1515,6 @@ ADD_PLUGIN([drbg], [s charon swanctl pki scripts nm cmd])
ADD_PLUGIN([curl], [s charon pki scripts nm cmd]) ADD_PLUGIN([curl], [s charon pki scripts nm cmd])
ADD_PLUGIN([files], [s charon pki scripts nm cmd]) ADD_PLUGIN([files], [s charon pki scripts nm cmd])
ADD_PLUGIN([winhttp], [s charon pki scripts]) ADD_PLUGIN([winhttp], [s charon pki scripts])
ADD_PLUGIN([soup], [s charon pki scripts nm cmd])
ADD_PLUGIN([mysql], [s charon pki pool attest]) ADD_PLUGIN([mysql], [s charon pki pool attest])
ADD_PLUGIN([sqlite], [s charon pki pool attest]) ADD_PLUGIN([sqlite], [s charon pki pool attest])
ADD_PLUGIN([openxpki], [s pki]) ADD_PLUGIN([openxpki], [s pki])
@@ -1625,7 +1617,6 @@ AM_CONDITIONAL(USE_CURL, test x$curl = xtrue)
AM_CONDITIONAL(USE_FILES, test x$files = xtrue) AM_CONDITIONAL(USE_FILES, test x$files = xtrue)
AM_CONDITIONAL(USE_WINHTTP, test x$winhttp = xtrue) AM_CONDITIONAL(USE_WINHTTP, test x$winhttp = xtrue)
AM_CONDITIONAL(USE_UNBOUND, test x$unbound = xtrue) AM_CONDITIONAL(USE_UNBOUND, test x$unbound = xtrue)
AM_CONDITIONAL(USE_SOUP, test x$soup = xtrue)
AM_CONDITIONAL(USE_LDAP, test x$ldap = xtrue) AM_CONDITIONAL(USE_LDAP, test x$ldap = xtrue)
AM_CONDITIONAL(USE_AES, test x$aes = xtrue) AM_CONDITIONAL(USE_AES, test x$aes = xtrue)
AM_CONDITIONAL(USE_DES, test x$des = xtrue) AM_CONDITIONAL(USE_DES, test x$des = xtrue)
@@ -1940,7 +1931,6 @@ AC_CONFIG_FILES([
src/libstrongswan/plugins/files/Makefile src/libstrongswan/plugins/files/Makefile
src/libstrongswan/plugins/winhttp/Makefile src/libstrongswan/plugins/winhttp/Makefile
src/libstrongswan/plugins/unbound/Makefile src/libstrongswan/plugins/unbound/Makefile
src/libstrongswan/plugins/soup/Makefile
src/libstrongswan/plugins/ldap/Makefile src/libstrongswan/plugins/ldap/Makefile
src/libstrongswan/plugins/mysql/Makefile src/libstrongswan/plugins/mysql/Makefile
src/libstrongswan/plugins/sqlite/Makefile src/libstrongswan/plugins/sqlite/Makefile
+2 -2
View File
@@ -272,7 +272,7 @@ all|alpine|codeql|coverage|sonarcloud|no-dbg|no-testable-ke)
if [ "$TEST" = "no-testable-ke" ]; then if [ "$TEST" = "no-testable-ke" ]; then
CONFIG="$CONFIG --without-testable-ke" CONFIG="$CONFIG --without-testable-ke"
fi fi
DEPS="$DEPS libcurl4-gnutls-dev libsoup-3.0-dev libunbound-dev libldns-dev DEPS="$DEPS libcurl4-gnutls-dev libunbound-dev libldns-dev
libmysqlclient-dev libsqlite3-dev libmysqlclient-dev libsqlite3-dev
libldap2-dev libpcsclite-dev libpam0g-dev binutils-dev libnm-dev libldap2-dev libpcsclite-dev libpam0g-dev binutils-dev libnm-dev
libjson-c-dev libtspi-dev libsystemd-dev libjson-c-dev libtspi-dev libsystemd-dev
@@ -285,7 +285,7 @@ all|alpine|codeql|coverage|sonarcloud|no-dbg|no-testable-ke)
fi fi
if [ "$TEST" = "alpine" ]; then if [ "$TEST" = "alpine" ]; then
# override the whole list for alpine # override the whole list for alpine
DEPS="git gmp-dev openldap-dev curl-dev ldns-dev unbound-dev libsoup3-dev DEPS="git gmp-dev openldap-dev curl-dev ldns-dev unbound-dev
libxml2-dev tpm2-tss-dev tpm2-tss-sys mariadb-dev wolfssl-dev libxml2-dev tpm2-tss-dev tpm2-tss-sys mariadb-dev wolfssl-dev
botan3-dev pcsc-lite-dev networkmanager-dev botan3-dev pcsc-lite-dev networkmanager-dev
linux-pam-dev iptables-dev libselinux-dev binutils-dev libunwind-dev linux-pam-dev iptables-dev libselinux-dev binutils-dev libunwind-dev
-7
View File
@@ -537,13 +537,6 @@ if MONOLITHIC
endif endif
endif endif
if USE_SOUP
SUBDIRS += plugins/soup
if MONOLITHIC
libstrongswan_la_LIBADD += plugins/soup/libstrongswan-soup.la
endif
endif
if USE_LDAP if USE_LDAP
SUBDIRS += plugins/ldap SUBDIRS += plugins/ldap
if MONOLITHIC if MONOLITHIC
@@ -1,18 +0,0 @@
AM_CPPFLAGS = \
-I$(top_srcdir)/src/libstrongswan
AM_CFLAGS = \
${soup_CFLAGS} \
$(PLUGIN_CFLAGS)
if MONOLITHIC
noinst_LTLIBRARIES = libstrongswan-soup.la
else
plugin_LTLIBRARIES = libstrongswan-soup.la
endif
libstrongswan_soup_la_SOURCES = \
soup_plugin.h soup_plugin.c soup_fetcher.c soup_fetcher.h
libstrongswan_soup_la_LDFLAGS = -module -avoid-version
libstrongswan_soup_la_LIBADD = ${soup_LIBS}
@@ -1,188 +0,0 @@
/*
* Copyright (C) 2010 Martin Willi
*
* Copyright (C) secunet Security Networks AG
*
* This program is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License as published by the
* Free Software Foundation; either version 2 of the License, or (at your
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
*
* This program is distributed in the hope that it will be useful, but
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* for more details.
*/
#include "soup_fetcher.h"
#include <libsoup/soup.h>
#include <library.h>
#include <utils/debug.h>
#define DEFAULT_TIMEOUT 10
typedef struct private_soup_fetcher_t private_soup_fetcher_t;
/**
* private data of a soup_fetcher_t object.
*/
struct private_soup_fetcher_t {
/**
* Public data
*/
soup_fetcher_t public;
/**
* HTTP request method
*/
const char *method;
/**
* Request content type
*/
char *type;
/**
* Request data
*/
chunk_t data;
/**
* Request timeout
*/
u_int timeout;
/**
* Fetcher callback function
*/
fetcher_callback_t cb;
/**
* Response status
*/
u_int *result;
};
METHOD(fetcher_t, fetch, status_t,
private_soup_fetcher_t *this, char *uri, void *userdata)
{
SoupMessage *message;
status_t status = FAILED;
GBytes *request_body, *res;
SoupSession *session;
message = soup_message_new(this->method, uri);
if (!message)
{
return NOT_SUPPORTED;
}
if (this->cb == fetcher_default_callback)
{
*(chunk_t*)userdata = chunk_empty;
}
if (this->type)
{
request_body = g_bytes_new_static(this->data.ptr, this->data.len);
soup_message_set_request_body_from_bytes(message, this->type,
request_body);
g_bytes_unref(request_body);
}
session = soup_session_new_with_options("timeout", (guint)this->timeout,
NULL);
DBG2(DBG_LIB, "sending http request to '%s'...", uri);
res = soup_session_send_and_read(session, message, NULL, NULL);
if (this->result)
{
*this->result = soup_message_get_status(message);
}
if (SOUP_STATUS_IS_SUCCESSFUL(soup_message_get_status(message)))
{
status = SUCCESS;
}
else if (!this->result)
{ /* only log an error if the code is not returned */
DBG1(DBG_LIB, "HTTP request failed: %s",
soup_message_get_reason_phrase(message));
}
if (res)
{
gpointer data;
gsize data_len;
data = g_bytes_unref_to_data(res, &data_len);
if (!this->cb(userdata, chunk_create(data, data_len)))
{
status = FAILED;
}
g_free(data);
}
g_object_unref(G_OBJECT(message));
g_object_unref(G_OBJECT(session));
return status;
}
METHOD(fetcher_t, set_option, bool,
private_soup_fetcher_t *this, fetcher_option_t option, ...)
{
bool supported = TRUE;
va_list args;
va_start(args, option);
switch (option)
{
case FETCH_REQUEST_DATA:
this->method = SOUP_METHOD_POST;
this->data = va_arg(args, chunk_t);
break;
case FETCH_REQUEST_TYPE:
this->type = va_arg(args, char*);
break;
case FETCH_TIMEOUT:
this->timeout = va_arg(args, u_int);
break;
case FETCH_CALLBACK:
this->cb = va_arg(args, fetcher_callback_t);
break;
case FETCH_RESPONSE_CODE:
this->result = va_arg(args, u_int*);
break;
default:
supported = FALSE;
break;
}
va_end(args);
return supported;
}
METHOD(fetcher_t, destroy, void,
private_soup_fetcher_t *this)
{
free(this);
}
/*
* Described in header.
*/
soup_fetcher_t *soup_fetcher_create()
{
private_soup_fetcher_t *this;
INIT(this,
.public = {
.interface = {
.fetch = _fetch,
.set_option = _set_option,
.destroy = _destroy,
},
},
.method = SOUP_METHOD_GET,
.timeout = DEFAULT_TIMEOUT,
.cb = fetcher_default_callback,
);
return &this->public;
}
@@ -1,45 +0,0 @@
/*
* Copyright (C) 2010 Martin Willi
*
* Copyright (C) secunet Security Networks AG
*
* This program is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License as published by the
* Free Software Foundation; either version 2 of the License, or (at your
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
*
* This program is distributed in the hope that it will be useful, but
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* for more details.
*/
/**
* @defgroup soup_fetcher soup_fetcher
* @{ @ingroup soup_p
*/
#ifndef SOUP_FETCHER_H_
#define SOUP_FETCHER_H_
#include <library.h>
typedef struct soup_fetcher_t soup_fetcher_t;
/**
* Fetcher implementation for HTTP using libsoup.
*/
struct soup_fetcher_t {
/**
* Implements fetcher interface.
*/
fetcher_t interface;
};
/**
* Create a soup_fetcher instance.
*/
soup_fetcher_t *soup_fetcher_create();
#endif /** SOUP_FETCHER_H_ @}*/
@@ -1,91 +0,0 @@
/*
* Copyright (C) 2010 Martin Willi
*
* Copyright (C) secunet Security Networks AG
*
* This program is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License as published by the
* Free Software Foundation; either version 2 of the License, or (at your
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
*
* This program is distributed in the hope that it will be useful, but
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* for more details.
*/
#include "soup_plugin.h"
#include "soup_fetcher.h"
#include <glib.h>
#include <glib-object.h>
#include <library.h>
typedef struct private_soup_plugin_t private_soup_plugin_t;
/**
* private data of soup_plugin
*/
struct private_soup_plugin_t {
/**
* public functions
*/
soup_plugin_t public;
};
METHOD(plugin_t, get_name, char*,
private_soup_plugin_t *this)
{
return "soup";
}
METHOD(plugin_t, get_features, int,
private_soup_plugin_t *this, plugin_feature_t *features[])
{
static plugin_feature_t f[] = {
PLUGIN_REGISTER(FETCHER, soup_fetcher_create),
PLUGIN_PROVIDE(FETCHER, "http://"),
PLUGIN_PROVIDE(FETCHER, "https://"),
};
*features = f;
return countof(f);
}
METHOD(plugin_t, destroy, void,
private_soup_plugin_t *this)
{
free(this);
}
/*
* see header file
*/
PLUGIN_DEFINE(soup)
{
private_soup_plugin_t *this;
#if !GLIB_CHECK_VERSION(2,36,0)
g_type_init();
#endif
#if !GLIB_CHECK_VERSION(2,23,0)
if (!g_thread_get_initialized())
{
g_thread_init(NULL);
}
#endif
INIT(this,
.public = {
.plugin = {
.get_name = _get_name,
.get_features = _get_features,
.destroy = _destroy,
},
},
);
return &this->public.plugin;
}
@@ -1,43 +0,0 @@
/*
* Copyright (C) 2010 Martin Willi
*
* Copyright (C) secunet Security Networks AG
*
* This program is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License as published by the
* Free Software Foundation; either version 2 of the License, or (at your
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
*
* This program is distributed in the hope that it will be useful, but
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* for more details.
*/
/**
* @defgroup soup_p soup
* @ingroup plugins
*
* @defgroup soup_plugin soup_plugin
* @{ @ingroup soup_p
*/
#ifndef SOUP_PLUGIN_H_
#define SOUP_PLUGIN_H_
#include <plugins/plugin.h>
typedef struct soup_plugin_t soup_plugin_t;
/**
* Plugin implementing fetcher interface for HTTP using libsoup.
*/
struct soup_plugin_t {
/**
* Implements plugin interface
*/
plugin_t plugin;
};
#endif /** SOUP_PLUGIN_H_ @}*/