purge auth_info when IKE_SA is established, releases cert memory
This commit is contained in:
@@ -560,9 +560,9 @@ static void destroy_item_value(item_t *item)
|
|||||||
}
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Implementation of auth_info_t.destroy
|
* Implementation of auth_info_t.purge
|
||||||
*/
|
*/
|
||||||
static void destroy(private_auth_info_t *this)
|
static void purge(private_auth_info_t *this)
|
||||||
{
|
{
|
||||||
item_t *item;
|
item_t *item;
|
||||||
|
|
||||||
@@ -571,6 +571,14 @@ static void destroy(private_auth_info_t *this)
|
|||||||
destroy_item_value(item);
|
destroy_item_value(item);
|
||||||
free(item);
|
free(item);
|
||||||
}
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Implementation of auth_info_t.destroy
|
||||||
|
*/
|
||||||
|
static void destroy(private_auth_info_t *this)
|
||||||
|
{
|
||||||
|
purge(this);
|
||||||
this->items->destroy(this->items);
|
this->items->destroy(this->items);
|
||||||
free(this);
|
free(this);
|
||||||
}
|
}
|
||||||
@@ -588,6 +596,7 @@ auth_info_t *auth_info_create()
|
|||||||
this->public.create_item_enumerator = (enumerator_t*(*)(auth_info_t*))create_item_enumerator;
|
this->public.create_item_enumerator = (enumerator_t*(*)(auth_info_t*))create_item_enumerator;
|
||||||
this->public.complies = (bool(*)(auth_info_t*, auth_info_t *))complies;
|
this->public.complies = (bool(*)(auth_info_t*, auth_info_t *))complies;
|
||||||
this->public.merge = (void(*)(auth_info_t*, auth_info_t *other))merge;
|
this->public.merge = (void(*)(auth_info_t*, auth_info_t *other))merge;
|
||||||
|
this->public.purge = (void(*)(auth_info_t*))purge;
|
||||||
this->public.equals = (bool(*)(auth_info_t*, auth_info_t *other))equals;
|
this->public.equals = (bool(*)(auth_info_t*, auth_info_t *other))equals;
|
||||||
this->public.destroy = (void(*)(auth_info_t*))destroy;
|
this->public.destroy = (void(*)(auth_info_t*))destroy;
|
||||||
|
|
||||||
|
|||||||
@@ -171,6 +171,11 @@ struct auth_info_t {
|
|||||||
*/
|
*/
|
||||||
void (*merge)(auth_info_t *this, auth_info_t *other);
|
void (*merge)(auth_info_t *this, auth_info_t *other);
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Purge all items in auth_info.
|
||||||
|
*/
|
||||||
|
void (*purge)(auth_info_t *this);
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Check two auth_infos for equality.
|
* Check two auth_infos for equality.
|
||||||
*
|
*
|
||||||
|
|||||||
@@ -709,6 +709,12 @@ static void set_state(private_ike_sa_t *this, ike_sa_state_t state)
|
|||||||
break;
|
break;
|
||||||
}
|
}
|
||||||
charon->bus->ike_state_change(charon->bus, &this->public, state);
|
charon->bus->ike_state_change(charon->bus, &this->public, state);
|
||||||
|
if (state == IKE_ESTABLISHED)
|
||||||
|
{ /* purge auth items after hook invocation, as they contain certs
|
||||||
|
* and other memory wasting elements */
|
||||||
|
this->my_auth->purge(this->my_auth);
|
||||||
|
this->other_auth->purge(this->other_auth);
|
||||||
|
}
|
||||||
this->state = state;
|
this->state = state;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user