checkin of non-existing IKE_SAs
removed unneeded checkin() return values
This commit is contained in:
@@ -235,12 +235,13 @@ static status_t initiate_execute(interface_job_t *job)
|
|||||||
}
|
}
|
||||||
peer_cfg->destroy(peer_cfg);
|
peer_cfg->destroy(peer_cfg);
|
||||||
|
|
||||||
if (ike_sa->initiate(ike_sa, listener->child_cfg) != SUCCESS)
|
if (ike_sa->initiate(ike_sa, listener->child_cfg) == SUCCESS)
|
||||||
{
|
{
|
||||||
return charon->ike_sa_manager->checkin_and_destroy(
|
charon->ike_sa_manager->checkin(charon->ike_sa_manager, ike_sa);
|
||||||
charon->ike_sa_manager, ike_sa);
|
return SUCCESS;
|
||||||
}
|
}
|
||||||
return charon->ike_sa_manager->checkin(charon->ike_sa_manager, ike_sa);
|
charon->ike_sa_manager->checkin_and_destroy(charon->ike_sa_manager, ike_sa);
|
||||||
|
return FAILED;
|
||||||
}
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
@@ -285,12 +286,15 @@ static status_t terminate_ike_execute(interface_job_t *job)
|
|||||||
ike_sa_t *ike_sa = listener->ike_sa;
|
ike_sa_t *ike_sa = listener->ike_sa;
|
||||||
|
|
||||||
charon->bus->set_sa(charon->bus, ike_sa);
|
charon->bus->set_sa(charon->bus, ike_sa);
|
||||||
if (ike_sa->delete(ike_sa) == DESTROY_ME)
|
|
||||||
|
if (ike_sa->delete(ike_sa) != DESTROY_ME)
|
||||||
{
|
{
|
||||||
return charon->ike_sa_manager->checkin_and_destroy(
|
charon->ike_sa_manager->checkin(charon->ike_sa_manager, ike_sa);
|
||||||
charon->ike_sa_manager, ike_sa);
|
/* delete failed */
|
||||||
|
return FAILED;
|
||||||
}
|
}
|
||||||
return charon->ike_sa_manager->checkin(charon->ike_sa_manager, ike_sa);
|
charon->ike_sa_manager->checkin_and_destroy(charon->ike_sa_manager, ike_sa);
|
||||||
|
return SUCCESS;
|
||||||
}
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
@@ -346,12 +350,13 @@ static status_t terminate_child_execute(interface_job_t *job)
|
|||||||
|
|
||||||
charon->bus->set_sa(charon->bus, ike_sa);
|
charon->bus->set_sa(charon->bus, ike_sa);
|
||||||
if (ike_sa->delete_child_sa(ike_sa, child_sa->get_protocol(child_sa),
|
if (ike_sa->delete_child_sa(ike_sa, child_sa->get_protocol(child_sa),
|
||||||
child_sa->get_spi(child_sa, TRUE)) == DESTROY_ME)
|
child_sa->get_spi(child_sa, TRUE)) != DESTROY_ME)
|
||||||
{
|
{
|
||||||
return charon->ike_sa_manager->checkin_and_destroy(
|
charon->ike_sa_manager->checkin(charon->ike_sa_manager, ike_sa);
|
||||||
charon->ike_sa_manager, ike_sa);
|
return SUCCESS;
|
||||||
}
|
}
|
||||||
return charon->ike_sa_manager->checkin(charon->ike_sa_manager, ike_sa);
|
charon->ike_sa_manager->checkin_and_destroy(charon->ike_sa_manager, ike_sa);
|
||||||
|
return FAILED;
|
||||||
}
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
@@ -429,12 +434,13 @@ static status_t route_execute(interface_job_t *job)
|
|||||||
ike_sa_t *ike_sa = listener->ike_sa;
|
ike_sa_t *ike_sa = listener->ike_sa;
|
||||||
|
|
||||||
charon->bus->set_sa(charon->bus, ike_sa);
|
charon->bus->set_sa(charon->bus, ike_sa);
|
||||||
if (ike_sa->route(ike_sa, listener->child_cfg) == DESTROY_ME)
|
if (ike_sa->route(ike_sa, listener->child_cfg) != DESTROY_ME)
|
||||||
{
|
{
|
||||||
return charon->ike_sa_manager->checkin_and_destroy(
|
charon->ike_sa_manager->checkin(charon->ike_sa_manager, ike_sa);
|
||||||
charon->ike_sa_manager, ike_sa);
|
return SUCCESS;
|
||||||
}
|
}
|
||||||
return charon->ike_sa_manager->checkin(charon->ike_sa_manager, ike_sa);
|
charon->ike_sa_manager->checkin_and_destroy(charon->ike_sa_manager, ike_sa);
|
||||||
|
return FAILED;
|
||||||
}
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
@@ -487,12 +493,13 @@ static status_t unroute_execute(interface_job_t *job)
|
|||||||
interface_listener_t *listener = &job->listener;
|
interface_listener_t *listener = &job->listener;
|
||||||
ike_sa_t *ike_sa = listener->ike_sa;
|
ike_sa_t *ike_sa = listener->ike_sa;
|
||||||
|
|
||||||
if (ike_sa->unroute(ike_sa, listener->id) == DESTROY_ME)
|
if (ike_sa->unroute(ike_sa, listener->id) != DESTROY_ME)
|
||||||
{
|
{
|
||||||
return charon->ike_sa_manager->checkin_and_destroy(
|
charon->ike_sa_manager->checkin(charon->ike_sa_manager, ike_sa);
|
||||||
charon->ike_sa_manager, ike_sa);
|
return SUCCESS;
|
||||||
}
|
}
|
||||||
return charon->ike_sa_manager->checkin(charon->ike_sa_manager, ike_sa);
|
charon->ike_sa_manager->checkin_and_destroy(charon->ike_sa_manager, ike_sa);
|
||||||
|
return SUCCESS;
|
||||||
}
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
|
|||||||
@@ -130,7 +130,7 @@ static status_t entry_destroy(entry_t *this)
|
|||||||
/**
|
/**
|
||||||
* Creates a new entry for the ike_sa_t list.
|
* Creates a new entry for the ike_sa_t list.
|
||||||
*/
|
*/
|
||||||
static entry_t *entry_create(ike_sa_id_t *ike_sa_id)
|
static entry_t *entry_create()
|
||||||
{
|
{
|
||||||
entry_t *this = malloc_thing(entry_t);
|
entry_t *this = malloc_thing(entry_t);
|
||||||
|
|
||||||
@@ -147,12 +147,8 @@ static entry_t *entry_create(ike_sa_id_t *ike_sa_id)
|
|||||||
this->half_open = FALSE;
|
this->half_open = FALSE;
|
||||||
this->my_id = NULL;
|
this->my_id = NULL;
|
||||||
this->other_id = NULL;
|
this->other_id = NULL;
|
||||||
|
this->ike_sa_id = NULL;
|
||||||
/* ike_sa_id is always cloned */
|
this->ike_sa = NULL;
|
||||||
this->ike_sa_id = ike_sa_id->clone(ike_sa_id);
|
|
||||||
|
|
||||||
/* create new ike_sa */
|
|
||||||
this->ike_sa = ike_sa_create(ike_sa_id);
|
|
||||||
|
|
||||||
return this;
|
return this;
|
||||||
}
|
}
|
||||||
@@ -752,19 +748,18 @@ static ike_sa_t* checkout(private_ike_sa_manager_t *this, ike_sa_id_t *ike_sa_id
|
|||||||
static ike_sa_t *checkout_new(private_ike_sa_manager_t* this, bool initiator)
|
static ike_sa_t *checkout_new(private_ike_sa_manager_t* this, bool initiator)
|
||||||
{
|
{
|
||||||
entry_t *entry;
|
entry_t *entry;
|
||||||
ike_sa_id_t *id;
|
|
||||||
u_int segment;
|
u_int segment;
|
||||||
|
|
||||||
|
entry = entry_create();
|
||||||
if (initiator)
|
if (initiator)
|
||||||
{
|
{
|
||||||
id = ike_sa_id_create(get_next_spi(this), 0, TRUE);
|
entry->ike_sa_id = ike_sa_id_create(get_next_spi(this), 0, TRUE);
|
||||||
}
|
}
|
||||||
else
|
else
|
||||||
{
|
{
|
||||||
id = ike_sa_id_create(0, get_next_spi(this), FALSE);
|
entry->ike_sa_id = ike_sa_id_create(0, get_next_spi(this), FALSE);
|
||||||
}
|
}
|
||||||
entry = entry_create(id);
|
entry->ike_sa = ike_sa_create(entry->ike_sa_id);
|
||||||
id->destroy(id);
|
|
||||||
|
|
||||||
segment = put_entry(this, entry);
|
segment = put_entry(this, entry);
|
||||||
entry->checked_out = TRUE;
|
entry->checked_out = TRUE;
|
||||||
@@ -827,7 +822,9 @@ static ike_sa_t* checkout_by_message(private_ike_sa_manager_t* this,
|
|||||||
{
|
{
|
||||||
/* no IKE_SA found, create a new one */
|
/* no IKE_SA found, create a new one */
|
||||||
id->set_responder_spi(id, get_next_spi(this));
|
id->set_responder_spi(id, get_next_spi(this));
|
||||||
entry = entry_create(id);
|
entry = entry_create();
|
||||||
|
entry->ike_sa = ike_sa_create(id);
|
||||||
|
entry->ike_sa_id = id->clone(id);
|
||||||
|
|
||||||
segment = put_entry(this, entry);
|
segment = put_entry(this, entry);
|
||||||
entry->checked_out = TRUE;
|
entry->checked_out = TRUE;
|
||||||
@@ -963,21 +960,16 @@ static ike_sa_t* checkout_by_config(private_ike_sa_manager_t *this,
|
|||||||
|
|
||||||
if (!ike_sa)
|
if (!ike_sa)
|
||||||
{
|
{
|
||||||
entry_t *new_entry;
|
entry = entry_create();
|
||||||
ike_sa_id_t *new_ike_sa_id;
|
entry->ike_sa_id = ike_sa_id_create(get_next_spi(this), 0, TRUE);
|
||||||
|
entry->ike_sa = ike_sa_create(entry->ike_sa_id);
|
||||||
|
|
||||||
new_ike_sa_id = ike_sa_id_create(get_next_spi(this), 0, TRUE);
|
segment = put_entry(this, entry);
|
||||||
|
|
||||||
/* create entry */
|
|
||||||
new_entry = entry_create(new_ike_sa_id);
|
|
||||||
new_ike_sa_id->destroy(new_ike_sa_id);
|
|
||||||
|
|
||||||
segment = put_entry(this, new_entry);
|
|
||||||
|
|
||||||
/* check ike_sa out */
|
/* check ike_sa out */
|
||||||
DBG2(DBG_MGR, "new IKE_SA created for IDs [%D]...[%D]", my_id, other_id);
|
DBG2(DBG_MGR, "new IKE_SA created for IDs [%D]...[%D]", my_id, other_id);
|
||||||
new_entry->checked_out = TRUE;
|
entry->checked_out = TRUE;
|
||||||
ike_sa = new_entry->ike_sa;
|
ike_sa = entry->ike_sa;
|
||||||
unlock_single_segment(this, segment);
|
unlock_single_segment(this, segment);
|
||||||
}
|
}
|
||||||
charon->bus->set_sa(charon->bus, ike_sa);
|
charon->bus->set_sa(charon->bus, ike_sa);
|
||||||
@@ -1157,7 +1149,7 @@ static enumerator_t *create_enumerator(private_ike_sa_manager_t* this)
|
|||||||
/**
|
/**
|
||||||
* Implementation of ike_sa_manager_t.checkin.
|
* Implementation of ike_sa_manager_t.checkin.
|
||||||
*/
|
*/
|
||||||
static status_t checkin(private_ike_sa_manager_t *this, ike_sa_t *ike_sa)
|
static void checkin(private_ike_sa_manager_t *this, ike_sa_t *ike_sa)
|
||||||
{
|
{
|
||||||
/* to check the SA back in, we look for the pointer of the ike_sa
|
/* to check the SA back in, we look for the pointer of the ike_sa
|
||||||
* in all entries.
|
* in all entries.
|
||||||
@@ -1165,7 +1157,6 @@ static status_t checkin(private_ike_sa_manager_t *this, ike_sa_t *ike_sa)
|
|||||||
* on reception of a IKE_SA_INIT response) the lookup will work but
|
* on reception of a IKE_SA_INIT response) the lookup will work but
|
||||||
* updating of the SPI MAY be necessary...
|
* updating of the SPI MAY be necessary...
|
||||||
*/
|
*/
|
||||||
status_t retval;
|
|
||||||
entry_t *entry;
|
entry_t *entry;
|
||||||
ike_sa_id_t *ike_sa_id;
|
ike_sa_id_t *ike_sa_id;
|
||||||
host_t *other;
|
host_t *other;
|
||||||
@@ -1173,6 +1164,9 @@ static status_t checkin(private_ike_sa_manager_t *this, ike_sa_t *ike_sa)
|
|||||||
u_int segment;
|
u_int segment;
|
||||||
|
|
||||||
ike_sa_id = ike_sa->get_id(ike_sa);
|
ike_sa_id = ike_sa->get_id(ike_sa);
|
||||||
|
my_id = ike_sa->get_my_id(ike_sa);
|
||||||
|
other_id = ike_sa->get_other_id(ike_sa);
|
||||||
|
other = ike_sa->get_other_host(ike_sa);
|
||||||
|
|
||||||
DBG2(DBG_MGR, "checkin IKE_SA");
|
DBG2(DBG_MGR, "checkin IKE_SA");
|
||||||
|
|
||||||
@@ -1185,7 +1179,6 @@ static status_t checkin(private_ike_sa_manager_t *this, ike_sa_t *ike_sa)
|
|||||||
entry->checked_out = FALSE;
|
entry->checked_out = FALSE;
|
||||||
entry->message_id = -1;
|
entry->message_id = -1;
|
||||||
/* check if this SA is half-open */
|
/* check if this SA is half-open */
|
||||||
other = ike_sa->get_other_host(ike_sa);
|
|
||||||
if (entry->half_open && ike_sa->get_state(ike_sa) != IKE_CONNECTING)
|
if (entry->half_open && ike_sa->get_state(ike_sa) != IKE_CONNECTING)
|
||||||
{
|
{
|
||||||
/* not half open anymore */
|
/* not half open anymore */
|
||||||
@@ -1210,8 +1203,6 @@ static status_t checkin(private_ike_sa_manager_t *this, ike_sa_t *ike_sa)
|
|||||||
put_half_open(this, entry);
|
put_half_open(this, entry);
|
||||||
}
|
}
|
||||||
/* apply identities for duplicate test */
|
/* apply identities for duplicate test */
|
||||||
my_id = ike_sa->get_my_id(ike_sa);
|
|
||||||
other_id = ike_sa->get_other_id(ike_sa);
|
|
||||||
if (!entry->my_id ||
|
if (!entry->my_id ||
|
||||||
entry->my_id->get_type(entry->my_id) == ID_ANY)
|
entry->my_id->get_type(entry->my_id) == ID_ANY)
|
||||||
{
|
{
|
||||||
@@ -1226,25 +1217,26 @@ static status_t checkin(private_ike_sa_manager_t *this, ike_sa_t *ike_sa)
|
|||||||
}
|
}
|
||||||
DBG2(DBG_MGR, "check-in of IKE_SA successful.");
|
DBG2(DBG_MGR, "check-in of IKE_SA successful.");
|
||||||
entry->condvar->signal(entry->condvar);
|
entry->condvar->signal(entry->condvar);
|
||||||
retval = SUCCESS;
|
|
||||||
unlock_single_segment(this, segment);
|
unlock_single_segment(this, segment);
|
||||||
}
|
}
|
||||||
else
|
else
|
||||||
{
|
{
|
||||||
DBG2(DBG_MGR, "tried to check in nonexisting IKE_SA");
|
entry = entry_create();
|
||||||
/* this SA is no more, this REALLY should not happen */
|
entry->ike_sa_id = ike_sa_id->clone(ike_sa_id);
|
||||||
retval = NOT_FOUND;
|
entry->ike_sa = ike_sa;
|
||||||
|
entry->my_id = my_id->clone(my_id);
|
||||||
|
entry->other_id = other_id->clone(other_id);
|
||||||
|
|
||||||
|
unlock_single_segment(this, put_entry(this, entry));
|
||||||
}
|
}
|
||||||
|
|
||||||
charon->bus->set_sa(charon->bus, NULL);
|
charon->bus->set_sa(charon->bus, NULL);
|
||||||
return retval;
|
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Implementation of ike_sa_manager_t.checkin_and_destroy.
|
* Implementation of ike_sa_manager_t.checkin_and_destroy.
|
||||||
*/
|
*/
|
||||||
static status_t checkin_and_destroy(private_ike_sa_manager_t *this, ike_sa_t *ike_sa)
|
static void checkin_and_destroy(private_ike_sa_manager_t *this, ike_sa_t *ike_sa)
|
||||||
{
|
{
|
||||||
/* deletion is a bit complex, we must ensure that no thread is waiting for
|
/* deletion is a bit complex, we must ensure that no thread is waiting for
|
||||||
* this SA.
|
* this SA.
|
||||||
@@ -1252,7 +1244,6 @@ static status_t checkin_and_destroy(private_ike_sa_manager_t *this, ike_sa_t *ik
|
|||||||
* are in the condvar.
|
* are in the condvar.
|
||||||
*/
|
*/
|
||||||
entry_t *entry;
|
entry_t *entry;
|
||||||
status_t retval;
|
|
||||||
ike_sa_id_t *ike_sa_id;
|
ike_sa_id_t *ike_sa_id;
|
||||||
u_int segment;
|
u_int segment;
|
||||||
|
|
||||||
@@ -1285,15 +1276,13 @@ static status_t checkin_and_destroy(private_ike_sa_manager_t *this, ike_sa_t *ik
|
|||||||
unlock_single_segment(this, segment);
|
unlock_single_segment(this, segment);
|
||||||
|
|
||||||
DBG2(DBG_MGR, "check-in and destroy of IKE_SA successful");
|
DBG2(DBG_MGR, "check-in and destroy of IKE_SA successful");
|
||||||
retval = SUCCESS;
|
|
||||||
}
|
}
|
||||||
else
|
else
|
||||||
{
|
{
|
||||||
DBG2(DBG_MGR, "tried to check-in and delete nonexisting IKE_SA");
|
DBG1(DBG_MGR, "tried to check-in and delete nonexisting IKE_SA");
|
||||||
retval = NOT_FOUND;
|
ike_sa->destroy(ike_sa);
|
||||||
}
|
}
|
||||||
charon->bus->set_sa(charon->bus, NULL);
|
charon->bus->set_sa(charon->bus, NULL);
|
||||||
return retval;
|
|
||||||
}
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
@@ -1315,6 +1304,7 @@ static int get_half_open_count(private_ike_sa_manager_t *this, host_t *ip)
|
|||||||
if ((list = this->half_open_table[row]) != NULL)
|
if ((list = this->half_open_table[row]) != NULL)
|
||||||
{
|
{
|
||||||
half_open_t *current;
|
half_open_t *current;
|
||||||
|
|
||||||
if (list->find_first(list, (linked_list_match_t)half_open_match,
|
if (list->find_first(list, (linked_list_match_t)half_open_match,
|
||||||
(void**)¤t, &addr) == SUCCESS)
|
(void**)¤t, &addr) == SUCCESS)
|
||||||
{
|
{
|
||||||
@@ -1326,6 +1316,7 @@ static int get_half_open_count(private_ike_sa_manager_t *this, host_t *ip)
|
|||||||
else
|
else
|
||||||
{
|
{
|
||||||
u_int segment;
|
u_int segment;
|
||||||
|
|
||||||
for (segment = 0; segment < this->segment_count; ++segment)
|
for (segment = 0; segment < this->segment_count; ++segment)
|
||||||
{
|
{
|
||||||
rwlock_t *lock;
|
rwlock_t *lock;
|
||||||
@@ -1475,8 +1466,8 @@ ike_sa_manager_t *ike_sa_manager_create()
|
|||||||
this->public.checkout_by_name = (ike_sa_t*(*)(ike_sa_manager_t*,char*,bool))checkout_by_name;
|
this->public.checkout_by_name = (ike_sa_t*(*)(ike_sa_manager_t*,char*,bool))checkout_by_name;
|
||||||
this->public.checkout_duplicate = (ike_sa_t*(*)(ike_sa_manager_t*, ike_sa_t *ike_sa))checkout_duplicate;
|
this->public.checkout_duplicate = (ike_sa_t*(*)(ike_sa_manager_t*, ike_sa_t *ike_sa))checkout_duplicate;
|
||||||
this->public.create_enumerator = (enumerator_t*(*)(ike_sa_manager_t*))create_enumerator;
|
this->public.create_enumerator = (enumerator_t*(*)(ike_sa_manager_t*))create_enumerator;
|
||||||
this->public.checkin = (status_t(*)(ike_sa_manager_t*,ike_sa_t*))checkin;
|
this->public.checkin = (void(*)(ike_sa_manager_t*,ike_sa_t*))checkin;
|
||||||
this->public.checkin_and_destroy = (status_t(*)(ike_sa_manager_t*,ike_sa_t*))checkin_and_destroy;
|
this->public.checkin_and_destroy = (void(*)(ike_sa_manager_t*,ike_sa_t*))checkin_and_destroy;
|
||||||
this->public.get_half_open_count = (int(*)(ike_sa_manager_t*,host_t*))get_half_open_count;
|
this->public.get_half_open_count = (int(*)(ike_sa_manager_t*,host_t*))get_half_open_count;
|
||||||
|
|
||||||
/* initialize private variables */
|
/* initialize private variables */
|
||||||
|
|||||||
@@ -157,14 +157,12 @@ struct ike_sa_manager_t {
|
|||||||
*
|
*
|
||||||
* @warning the SA pointer MUST NOT be used after checkin!
|
* @warning the SA pointer MUST NOT be used after checkin!
|
||||||
* The SA must be checked out again!
|
* The SA must be checked out again!
|
||||||
|
* If the IKE_SA is not registered in the manager, a new entry is created.
|
||||||
*
|
*
|
||||||
* @param ike_sa_id the SA identifier, will be updated
|
* @param ike_sa_id the SA identifier, will be updated
|
||||||
* @param ike_sa checked out SA
|
* @param ike_sa checked out SA
|
||||||
* @returns
|
|
||||||
* - SUCCESS if checked in
|
|
||||||
* - NOT_FOUND when not found (shouldn't happen!)
|
|
||||||
*/
|
*/
|
||||||
status_t (*checkin) (ike_sa_manager_t* this, ike_sa_t *ike_sa);
|
void (*checkin) (ike_sa_manager_t* this, ike_sa_t *ike_sa);
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Destroy a checked out SA.
|
* Destroy a checked out SA.
|
||||||
@@ -177,11 +175,8 @@ struct ike_sa_manager_t {
|
|||||||
* risk that another thread can get the SA.
|
* risk that another thread can get the SA.
|
||||||
*
|
*
|
||||||
* @param ike_sa SA to delete
|
* @param ike_sa SA to delete
|
||||||
* @returns
|
|
||||||
* - SUCCESS if found
|
|
||||||
* - NOT_FOUND when no such SA is available
|
|
||||||
*/
|
*/
|
||||||
status_t (*checkin_and_destroy) (ike_sa_manager_t* this, ike_sa_t *ike_sa);
|
void (*checkin_and_destroy) (ike_sa_manager_t* this, ike_sa_t *ike_sa);
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Get the number of IKE_SAs which are in the connecting state.
|
* Get the number of IKE_SAs which are in the connecting state.
|
||||||
|
|||||||
Reference in New Issue
Block a user