kernel-netlink: Only flush SAs of types we actually manage
This commit is contained in:
@@ -2024,23 +2024,36 @@ METHOD(kernel_ipsec_t, flush_sas, status_t,
|
|||||||
netlink_buf_t request;
|
netlink_buf_t request;
|
||||||
struct nlmsghdr *hdr;
|
struct nlmsghdr *hdr;
|
||||||
struct xfrm_usersa_flush *flush;
|
struct xfrm_usersa_flush *flush;
|
||||||
|
struct {
|
||||||
|
u_int8_t proto;
|
||||||
|
char *name;
|
||||||
|
} protos[] = {
|
||||||
|
{ IPPROTO_AH, "AH" },
|
||||||
|
{ IPPROTO_ESP, "ESP" },
|
||||||
|
{ IPPROTO_COMP, "IPComp" },
|
||||||
|
};
|
||||||
|
int i;
|
||||||
|
|
||||||
memset(&request, 0, sizeof(request));
|
memset(&request, 0, sizeof(request));
|
||||||
|
|
||||||
DBG2(DBG_KNL, "flushing all SAD entries");
|
|
||||||
|
|
||||||
hdr = &request.hdr;
|
hdr = &request.hdr;
|
||||||
hdr->nlmsg_flags = NLM_F_REQUEST | NLM_F_ACK;
|
hdr->nlmsg_flags = NLM_F_REQUEST | NLM_F_ACK;
|
||||||
hdr->nlmsg_type = XFRM_MSG_FLUSHSA;
|
hdr->nlmsg_type = XFRM_MSG_FLUSHSA;
|
||||||
hdr->nlmsg_len = NLMSG_LENGTH(sizeof(struct xfrm_usersa_flush));
|
hdr->nlmsg_len = NLMSG_LENGTH(sizeof(struct xfrm_usersa_flush));
|
||||||
|
|
||||||
flush = NLMSG_DATA(hdr);
|
flush = NLMSG_DATA(hdr);
|
||||||
flush->proto = IPSEC_PROTO_ANY;
|
|
||||||
|
|
||||||
if (this->socket_xfrm->send_ack(this->socket_xfrm, hdr) != SUCCESS)
|
for (i = 0; i < countof(protos); i++)
|
||||||
{
|
{
|
||||||
DBG1(DBG_KNL, "unable to flush SAD entries");
|
DBG2(DBG_KNL, "flushing all %s SAD entries", protos[i].name);
|
||||||
return FAILED;
|
|
||||||
|
flush->proto = protos[i].proto;
|
||||||
|
|
||||||
|
if (this->socket_xfrm->send_ack(this->socket_xfrm, hdr) != SUCCESS)
|
||||||
|
{
|
||||||
|
DBG1(DBG_KNL, "unable to flush %s SAD entries", protos[i].name);
|
||||||
|
return FAILED;
|
||||||
|
}
|
||||||
}
|
}
|
||||||
return SUCCESS;
|
return SUCCESS;
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user