Only load kernel plugins in starter when flushing SAD/SPD entries

This avoids keeping the kernel sockets open when they are not actually
needed, which could lead to resource problems (in particular with PF_KEY
where all open sockets receive all messages).

Fixes #217.
This commit is contained in:
Tobias Brunner
2012-08-16 16:14:15 +02:00
parent aaefeafb49
commit 71b89d6722
2 changed files with 8 additions and 9 deletions
+7
View File
@@ -58,6 +58,13 @@ bool starter_netkey_init(void)
void starter_netkey_cleanup(void) void starter_netkey_cleanup(void)
{ {
if (!lib->plugins->load(lib->plugins, NULL,
lib->settings->get_str(lib->settings, "starter.load", PLUGINS)))
{
DBG1(DBG_APP, "unable to load kernel plugins");
return;
}
hydra->kernel_interface->flush_sas(hydra->kernel_interface); hydra->kernel_interface->flush_sas(hydra->kernel_interface);
hydra->kernel_interface->flush_policies(hydra->kernel_interface); hydra->kernel_interface->flush_policies(hydra->kernel_interface);
lib->plugins->unload(lib->plugins);
} }
+1 -9
View File
@@ -19,7 +19,7 @@
#include <stdlib.h> #include <stdlib.h>
#include <stdio.h> #include <stdio.h>
#include <signal.h> #include <signal.h>
#include <syslog.h> #include <syslog.h>
#include <unistd.h> #include <unistd.h>
#include <sys/time.h> #include <sys/time.h>
#include <time.h> #include <time.h>
@@ -525,13 +525,6 @@ int main (int argc, char **argv)
} }
} }
/* load plugins */
if (!lib->plugins->load(lib->plugins, NULL,
lib->settings->get_str(lib->settings, "starter.load", PLUGINS)))
{
exit(LSB_RC_FAILURE);
}
/* we handle these signals only in pselect() */ /* we handle these signals only in pselect() */
memset(&action, 0, sizeof(action)); memset(&action, 0, sizeof(action));
sigemptyset(&action.sa_mask); sigemptyset(&action.sa_mask);
@@ -580,7 +573,6 @@ int main (int argc, char **argv)
confread_free(cfg); confread_free(cfg);
unlink(STARTER_PID_FILE); unlink(STARTER_PID_FILE);
DBG1(DBG_APP, "ipsec starter stopped"); DBG1(DBG_APP, "ipsec starter stopped");
lib->plugins->unload(lib->plugins);
close_log(); close_log();
exit(LSB_RC_SUCCESS); exit(LSB_RC_SUCCESS);
} }