starter: Use kernel interfaces to flush SAD and SPD.
This now supports platforms where neither 'ip xfrm' nor 'setkey' are available (like Android).
This commit is contained in:
+4
-4
@@ -807,10 +807,10 @@ ADD_PLUGIN([xauth], [p pluto])
|
|||||||
ADD_PLUGIN([attr], [h libcharon pluto])
|
ADD_PLUGIN([attr], [h libcharon pluto])
|
||||||
ADD_PLUGIN([attr-sql], [h libcharon pluto])
|
ADD_PLUGIN([attr-sql], [h libcharon pluto])
|
||||||
ADD_PLUGIN([load-tester], [c libcharon])
|
ADD_PLUGIN([load-tester], [c libcharon])
|
||||||
ADD_PLUGIN([kernel-pfkey], [h libcharon pluto])
|
ADD_PLUGIN([kernel-pfkey], [h libcharon pluto starter])
|
||||||
ADD_PLUGIN([kernel-pfroute], [h libcharon pluto])
|
ADD_PLUGIN([kernel-pfroute], [h libcharon pluto starter])
|
||||||
ADD_PLUGIN([kernel-klips], [h libcharon pluto])
|
ADD_PLUGIN([kernel-klips], [h libcharon pluto starter])
|
||||||
ADD_PLUGIN([kernel-netlink], [h libcharon pluto])
|
ADD_PLUGIN([kernel-netlink], [h libcharon pluto starter])
|
||||||
ADD_PLUGIN([resolve], [h libcharon pluto])
|
ADD_PLUGIN([resolve], [h libcharon pluto])
|
||||||
ADD_PLUGIN([socket-default], [c libcharon])
|
ADD_PLUGIN([socket-default], [c libcharon])
|
||||||
ADD_PLUGIN([socket-raw], [c libcharon])
|
ADD_PLUGIN([socket-raw], [c libcharon])
|
||||||
|
|||||||
@@ -27,7 +27,7 @@ AM_CFLAGS = \
|
|||||||
|
|
||||||
AM_YFLAGS = -v -d
|
AM_YFLAGS = -v -d
|
||||||
|
|
||||||
starter_LDADD = defs.o $(top_builddir)/src/libfreeswan/libfreeswan.a $(top_builddir)/src/libstrongswan/libstrongswan.la $(SOCKLIB)
|
starter_LDADD = defs.o $(top_builddir)/src/libfreeswan/libfreeswan.a $(top_builddir)/src/libstrongswan/libstrongswan.la $(top_builddir)/src/libhydra/libhydra.la $(SOCKLIB)
|
||||||
EXTRA_DIST = keywords.txt ipsec.conf
|
EXTRA_DIST = keywords.txt ipsec.conf
|
||||||
MAINTAINERCLEANFILES = keywords.c
|
MAINTAINERCLEANFILES = keywords.c
|
||||||
BUILT_SOURCES = parser.h
|
BUILT_SOURCES = parser.h
|
||||||
|
|||||||
+3
-14
@@ -17,6 +17,7 @@
|
|||||||
#include <stdlib.h>
|
#include <stdlib.h>
|
||||||
|
|
||||||
#include <freeswan.h>
|
#include <freeswan.h>
|
||||||
|
#include <hydra.h>
|
||||||
|
|
||||||
#include "../pluto/constants.h"
|
#include "../pluto/constants.h"
|
||||||
#include "../pluto/defs.h"
|
#include "../pluto/defs.h"
|
||||||
@@ -66,18 +67,6 @@ starter_netkey_init(void)
|
|||||||
void
|
void
|
||||||
starter_netkey_cleanup(void)
|
starter_netkey_cleanup(void)
|
||||||
{
|
{
|
||||||
if (system("ip xfrm state > /dev/null 2>&1") == 0)
|
hydra->kernel_interface->flush_sas(hydra->kernel_interface);
|
||||||
{
|
hydra->kernel_interface->flush_policies(hydra->kernel_interface);
|
||||||
ignore_result(system("ip xfrm state flush"));
|
|
||||||
ignore_result(system("ip xfrm policy flush"));
|
|
||||||
}
|
|
||||||
else if (system("type setkey > /dev/null 2>&1") == 0)
|
|
||||||
{
|
|
||||||
ignore_result(system("setkey -F"));
|
|
||||||
ignore_result(system("setkey -FP"));
|
|
||||||
}
|
|
||||||
else
|
|
||||||
{
|
|
||||||
plog("WARNING: cannot flush IPsec state/policy database");
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -29,6 +29,7 @@
|
|||||||
|
|
||||||
#include <freeswan.h>
|
#include <freeswan.h>
|
||||||
#include <library.h>
|
#include <library.h>
|
||||||
|
#include <hydra.h>
|
||||||
|
|
||||||
#include "../pluto/constants.h"
|
#include "../pluto/constants.h"
|
||||||
#include "../pluto/defs.h"
|
#include "../pluto/defs.h"
|
||||||
@@ -281,6 +282,9 @@ int main (int argc, char **argv)
|
|||||||
library_init(NULL);
|
library_init(NULL);
|
||||||
atexit(library_deinit);
|
atexit(library_deinit);
|
||||||
|
|
||||||
|
libhydra_init("starter");
|
||||||
|
atexit(libhydra_deinit);
|
||||||
|
|
||||||
/* parse command line */
|
/* parse command line */
|
||||||
for (i = 1; i < argc; i++)
|
for (i = 1; i < argc; i++)
|
||||||
{
|
{
|
||||||
|
|||||||
Reference in New Issue
Block a user