kernel-netlink: Only flush SAs of types we actually manage

This commit is contained in:
Tobias Brunner
2015-08-21 18:27:05 +02:00
parent d88cec920c
commit 82b5d1c018
@@ -2024,23 +2024,36 @@ METHOD(kernel_ipsec_t, flush_sas, status_t,
netlink_buf_t request; netlink_buf_t request;
struct nlmsghdr *hdr; struct nlmsghdr *hdr;
struct xfrm_usersa_flush *flush; struct xfrm_usersa_flush *flush;
struct {
u_int8_t proto;
char *name;
} protos[] = {
{ IPPROTO_AH, "AH" },
{ IPPROTO_ESP, "ESP" },
{ IPPROTO_COMP, "IPComp" },
};
int i;
memset(&request, 0, sizeof(request)); memset(&request, 0, sizeof(request));
DBG2(DBG_KNL, "flushing all SAD entries");
hdr = &request.hdr; hdr = &request.hdr;
hdr->nlmsg_flags = NLM_F_REQUEST | NLM_F_ACK; hdr->nlmsg_flags = NLM_F_REQUEST | NLM_F_ACK;
hdr->nlmsg_type = XFRM_MSG_FLUSHSA; hdr->nlmsg_type = XFRM_MSG_FLUSHSA;
hdr->nlmsg_len = NLMSG_LENGTH(sizeof(struct xfrm_usersa_flush)); hdr->nlmsg_len = NLMSG_LENGTH(sizeof(struct xfrm_usersa_flush));
flush = NLMSG_DATA(hdr); flush = NLMSG_DATA(hdr);
flush->proto = IPSEC_PROTO_ANY;
if (this->socket_xfrm->send_ack(this->socket_xfrm, hdr) != SUCCESS) for (i = 0; i < countof(protos); i++)
{ {
DBG1(DBG_KNL, "unable to flush SAD entries"); DBG2(DBG_KNL, "flushing all %s SAD entries", protos[i].name);
return FAILED;
flush->proto = protos[i].proto;
if (this->socket_xfrm->send_ack(this->socket_xfrm, hdr) != SUCCESS)
{
DBG1(DBG_KNL, "unable to flush %s SAD entries", protos[i].name);
return FAILED;
}
} }
return SUCCESS; return SUCCESS;
} }