mem-pool: Fix issue with make-before-break reauth and multiple IKE_SAs
If uniqueness checks are disabled and multiple IKE_SAs with the same identities are created, an offline lease could have gotten reassigned during a make-before-break reauthentication if such an SA was closed earlier. Checking for an online lease for the same client (IP/port) first ensures that the correct IP is reassigned during the reauthentication. References strongswan/strongswan#2472
This commit is contained in:
@@ -287,6 +287,31 @@ static int get_existing(private_mem_pool_t *this, identification_t *id,
|
|||||||
return 0;
|
return 0;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
if (peer)
|
||||||
|
{
|
||||||
|
/* check for a valid online lease to reassign during make-before-break
|
||||||
|
* reauthentication */
|
||||||
|
enumerator = array_create_enumerator(entry->online);
|
||||||
|
while (enumerator->enumerate(enumerator, &lease))
|
||||||
|
{
|
||||||
|
if (lease->hash == hash_addr(peer) &&
|
||||||
|
(requested->is_anyaddr(requested) ||
|
||||||
|
lease->offset == host2offset(this, requested)))
|
||||||
|
{
|
||||||
|
offset = lease->offset;
|
||||||
|
/* add an additional "online" entry */
|
||||||
|
array_insert(entry->online, ARRAY_TAIL, lease);
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
enumerator->destroy(enumerator);
|
||||||
|
if (offset)
|
||||||
|
{
|
||||||
|
DBG1(DBG_CFG, "reassigning online lease to '%Y'", id);
|
||||||
|
return offset;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
/* check for a valid offline lease, refresh */
|
/* check for a valid offline lease, refresh */
|
||||||
enumerator = array_create_enumerator(entry->offline);
|
enumerator = array_create_enumerator(entry->offline);
|
||||||
if (enumerator->enumerate(enumerator, ¤t))
|
if (enumerator->enumerate(enumerator, ¤t))
|
||||||
@@ -300,30 +325,6 @@ static int get_existing(private_mem_pool_t *this, identification_t *id,
|
|||||||
if (offset)
|
if (offset)
|
||||||
{
|
{
|
||||||
DBG1(DBG_CFG, "reassigning offline lease to '%Y'", id);
|
DBG1(DBG_CFG, "reassigning offline lease to '%Y'", id);
|
||||||
return offset;
|
|
||||||
}
|
|
||||||
if (!peer)
|
|
||||||
{
|
|
||||||
return 0;
|
|
||||||
}
|
|
||||||
/* check for a valid online lease to reassign */
|
|
||||||
enumerator = array_create_enumerator(entry->online);
|
|
||||||
while (enumerator->enumerate(enumerator, &lease))
|
|
||||||
{
|
|
||||||
if (lease->hash == hash_addr(peer) &&
|
|
||||||
(requested->is_anyaddr(requested) ||
|
|
||||||
lease->offset == host2offset(this, requested)))
|
|
||||||
{
|
|
||||||
offset = lease->offset;
|
|
||||||
/* add an additional "online" entry */
|
|
||||||
array_insert(entry->online, ARRAY_TAIL, lease);
|
|
||||||
break;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
enumerator->destroy(enumerator);
|
|
||||||
if (offset)
|
|
||||||
{
|
|
||||||
DBG1(DBG_CFG, "reassigning online lease to '%Y'", id);
|
|
||||||
}
|
}
|
||||||
return offset;
|
return offset;
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user