ifmap plugin subscribes to assing_vip bus signal

This commit is contained in:
Andreas Steffen
2013-04-06 11:09:41 +02:00
parent 5cb4f5519b
commit ba2880d569
7 changed files with 135 additions and 2 deletions
@@ -71,8 +71,9 @@ static bool publish_device_ip_addresses(private_tnc_ifmap_listener_t *this)
*/
static bool reload_metadata(private_tnc_ifmap_listener_t *this)
{
enumerator_t *enumerator;
enumerator_t *enumerator, *evips;
ike_sa_t *ike_sa;
host_t *vip;
bool success = TRUE;
enumerator = charon->controller->create_ike_sa_enumerator(
@@ -88,6 +89,16 @@ static bool reload_metadata(private_tnc_ifmap_listener_t *this)
success = FALSE;
break;
}
evips = ike_sa->create_virtual_ip_enumerator(ike_sa, FALSE);
while (evips->enumerate(evips, &vip))
{
if (!this->ifmap->publish_virtual_ip(this->ifmap, ike_sa, vip, TRUE))
{
success = FALSE;
break;
}
}
evips->destroy(evips);
}
enumerator->destroy(enumerator);
@@ -104,6 +115,14 @@ METHOD(listener_t, ike_updown, bool,
return TRUE;
}
METHOD(listener_t, assign_vip, bool,
private_tnc_ifmap_listener_t *this, ike_sa_t *ike_sa, host_t *vip,
bool assign)
{
this->ifmap->publish_virtual_ip(this->ifmap, ike_sa, vip, assign);
return TRUE;
}
METHOD(listener_t, alert, bool,
private_tnc_ifmap_listener_t *this, ike_sa_t *ike_sa, alert_t alert,
va_list args)
@@ -144,6 +163,7 @@ tnc_ifmap_listener_t *tnc_ifmap_listener_create(bool reload)
.public = {
.listener = {
.ike_updown = _ike_updown,
.assign_vip = _assign_vip,
.alert = _alert,
},
.destroy = _destroy,
@@ -579,6 +579,48 @@ METHOD(tnc_ifmap_soap_t, publish_device_ip, bool,
return success;
}
METHOD(tnc_ifmap_soap_t, publish_virtual_ip, bool,
private_tnc_ifmap_soap_t *this, ike_sa_t *ike_sa, host_t *vip, bool assign)
{
tnc_ifmap_soap_msg_t *soap_msg;
xmlNodePtr request, node;
u_int32_t ike_sa_id;
bool success;
/* extract relevant data from IKE_SA*/
ike_sa_id = ike_sa->get_unique_id(ike_sa);
/* build publish request */
request = create_publish_request(this);
/**
* update or delete access-request-ip metadata for a virtual IP address
*/
if (assign)
{
node = xmlNewNode(NULL, "update");
}
else
{
node = create_delete_filter(this, "access-request-ip");
}
xmlAddChild(request, node);
/* add access-request, virtual ip-address and [if assign] metadata */
xmlAddChild(node, create_access_request(this, ike_sa_id));
xmlAddChild(node, create_ip_address(this, vip));
if (assign)
{
xmlAddChild(node, create_metadata(this, "access-request-ip"));
}
soap_msg = tnc_ifmap_soap_msg_create(this->uri, this->user_pass, this->tls);
success = soap_msg->post(soap_msg, request, "publishReceived", NULL);
soap_msg->destroy(soap_msg);
return success;
}
METHOD(tnc_ifmap_soap_t, publish_enforcement_report, bool,
private_tnc_ifmap_soap_t *this, host_t *host, char *action, char *reason)
{
@@ -851,6 +893,7 @@ tnc_ifmap_soap_t *tnc_ifmap_soap_create()
.purgePublisher = _purgePublisher,
.publish_ike_sa = _publish_ike_sa,
.publish_device_ip = _publish_device_ip,
.publish_virtual_ip = _publish_virtual_ip,
.publish_enforcement_report = _publish_enforcement_report,
.endSession = _endSession,
.get_session_id = _get_session_id,
@@ -56,7 +56,7 @@ struct tnc_ifmap_soap_t {
/**
* Publish metadata about established/deleted IKE_SAs
*
* @param ike_sa IKE_SA for which metadate is published
* @param ike_sa IKE_SA for which metadata is published
* @param up TRUE if IKE_SEA is up, FALSE if down
* @return TRUE if command was successful
*/
@@ -70,6 +70,17 @@ struct tnc_ifmap_soap_t {
*/
bool (*publish_device_ip)(tnc_ifmap_soap_t *this, host_t *host);
/**
* Publish Virtual IP access-request-ip metadata
*
* @param ike_sa IKE_SA for which metadata is published
* @param vip Virtual IP address of peer
* @param assign TRUE if assigned, FALSE if removed
* @return TRUE if command was successful
*/
bool (*publish_virtual_ip)(tnc_ifmap_soap_t *this, ike_sa_t *ike_sa,
host_t *vip, bool assign);
/**
* Publish enforcement-report metadata
*