check on-disk and loaded segment integrity of libstrongswan
This commit is contained in:
@@ -137,7 +137,7 @@ static u_int32_t build_segment(private_integrity_checker_t *this, void *sym)
|
|||||||
|
|
||||||
if (dladdr(sym, &dli) == 0)
|
if (dladdr(sym, &dli) == 0)
|
||||||
{
|
{
|
||||||
DBG1("unable to locate symbol: %s", strerror(errno));
|
DBG1("unable to locate symbol: %s", dlerror());
|
||||||
return 0;
|
return 0;
|
||||||
}
|
}
|
||||||
/* we reuse the Dl_info struct as in/out parameter */
|
/* we reuse the Dl_info struct as in/out parameter */
|
||||||
@@ -220,6 +220,29 @@ static bool check_segment(private_integrity_checker_t *this,
|
|||||||
return TRUE;
|
return TRUE;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Implementation of integrity_checker_t.check
|
||||||
|
*/
|
||||||
|
static bool check(private_integrity_checker_t *this, char *name, void *sym)
|
||||||
|
{
|
||||||
|
Dl_info dli;
|
||||||
|
|
||||||
|
if (dladdr(sym, &dli) == 0)
|
||||||
|
{
|
||||||
|
DBG1("unable to locate symbol: %s", dlerror());
|
||||||
|
return FALSE;
|
||||||
|
}
|
||||||
|
if (!check_file(this, name, (char*)dli.dli_fname))
|
||||||
|
{
|
||||||
|
return FALSE;
|
||||||
|
}
|
||||||
|
if (!check_segment(this, name, sym))
|
||||||
|
{
|
||||||
|
return FALSE;
|
||||||
|
}
|
||||||
|
return TRUE;
|
||||||
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Implementation of integrity_checker_t.destroy.
|
* Implementation of integrity_checker_t.destroy.
|
||||||
*/
|
*/
|
||||||
@@ -243,6 +266,7 @@ integrity_checker_t *integrity_checker_create(char *checksum_library)
|
|||||||
this->public.build_file = (u_int32_t(*)(integrity_checker_t*, char *file))build_file;
|
this->public.build_file = (u_int32_t(*)(integrity_checker_t*, char *file))build_file;
|
||||||
this->public.check_segment = (bool(*)(integrity_checker_t*, char *name, void *sym))check_segment;
|
this->public.check_segment = (bool(*)(integrity_checker_t*, char *name, void *sym))check_segment;
|
||||||
this->public.build_segment = (u_int32_t(*)(integrity_checker_t*, void *sym))build_segment;
|
this->public.build_segment = (u_int32_t(*)(integrity_checker_t*, void *sym))build_segment;
|
||||||
|
this->public.check = (bool(*)(integrity_checker_t*, char *name, void *sym))check;
|
||||||
this->public.destroy = (void(*)(integrity_checker_t*))destroy;
|
this->public.destroy = (void(*)(integrity_checker_t*))destroy;
|
||||||
|
|
||||||
this->checksum_count = 0;
|
this->checksum_count = 0;
|
||||||
|
|||||||
@@ -81,6 +81,15 @@ struct integrity_checker_t {
|
|||||||
*/
|
*/
|
||||||
u_int32_t (*build_segment)(integrity_checker_t *this, void *sym);
|
u_int32_t (*build_segment)(integrity_checker_t *this, void *sym);
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Check both, on disk file integrity and loaded segment.
|
||||||
|
*
|
||||||
|
* @param name name to lookup checksum
|
||||||
|
* @param sym a symbol to look up library and segment
|
||||||
|
* @return TRUE if integrity tested successfully
|
||||||
|
*/
|
||||||
|
bool (*check)(integrity_checker_t *this, char *name, void *sym);
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Destroy a integrity_checker_t.
|
* Destroy a integrity_checker_t.
|
||||||
*/
|
*/
|
||||||
|
|||||||
@@ -132,8 +132,7 @@ bool library_init(char *settings)
|
|||||||
"libstrongswan.integrity_test", FALSE))
|
"libstrongswan.integrity_test", FALSE))
|
||||||
{
|
{
|
||||||
this->public.integrity = integrity_checker_create(CHECKSUM_LIBRARY);
|
this->public.integrity = integrity_checker_create(CHECKSUM_LIBRARY);
|
||||||
if (!lib->integrity->check_segment(lib->integrity,
|
if (!lib->integrity->check(lib->integrity, "libstrongswan", library_init))
|
||||||
"libstrongswan", library_init))
|
|
||||||
{
|
{
|
||||||
DBG1("integrity check of libstrongswan failed");
|
DBG1("integrity check of libstrongswan failed");
|
||||||
return FALSE;
|
return FALSE;
|
||||||
|
|||||||
Reference in New Issue
Block a user