- add connection names to connections
- stroke status / ipsec status shows them - added statusall for stroke - added status by connection name - some tests repaired, more to come
This commit is contained in:
+7
-5
@@ -17,13 +17,15 @@ FREESWANSRCDIR=../..
|
|||||||
ifeq ($(shell ls $(FREESWANSRCDIR)/Makefile.inc 2>&1), ../../Makefile.inc)
|
ifeq ($(shell ls $(FREESWANSRCDIR)/Makefile.inc 2>&1), ../../Makefile.inc)
|
||||||
include ${FREESWANSRCDIR}/Makefile.inc
|
include ${FREESWANSRCDIR}/Makefile.inc
|
||||||
else
|
else
|
||||||
# use leak detective by default
|
# Defaults if not using strongswan defines
|
||||||
USE_LEAK_DETECTIVE?=true
|
USE_LEAK_DETECTIVE?=false
|
||||||
|
INSTALL=install
|
||||||
|
INSTBINFLAGS=-b --suffix=.old
|
||||||
|
LIBEXECDIR=/usr/local/libexec/ipsec
|
||||||
|
SHAREDLIBDIR=/usr/local/lib
|
||||||
endif
|
endif
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
BUILD_DIR= ./bin/
|
BUILD_DIR= ./bin/
|
||||||
|
|
||||||
BINNAMECHARON= $(BUILD_DIR)charon
|
BINNAMECHARON= $(BUILD_DIR)charon
|
||||||
@@ -65,7 +67,7 @@ build_dir:
|
|||||||
mkdir -p $(BUILD_DIR)
|
mkdir -p $(BUILD_DIR)
|
||||||
|
|
||||||
$(BINNAMELIB) : build_dir $(LIB_OBJS)
|
$(BINNAMELIB) : build_dir $(LIB_OBJS)
|
||||||
$(CC) -ldl -lgmp -lpthread -shared $(LIB_OBJS) -o $@
|
$(CC) -lpthread -ldl -lgmp -shared $(LIB_OBJS) -o $@
|
||||||
|
|
||||||
$(BINNAMECHARON) : build_dir $(CHARON_OBJS) $(BINNAMELIB) $(BUILD_DIR)daemon.o
|
$(BINNAMECHARON) : build_dir $(CHARON_OBJS) $(BINNAMELIB) $(BUILD_DIR)daemon.o
|
||||||
$(CC) -L./bin -lstrongswan $(CHARON_OBJS) $(BUILD_DIR)daemon.o -o $@
|
$(CC) -L./bin -lstrongswan $(CHARON_OBJS) $(BUILD_DIR)daemon.o -o $@
|
||||||
|
|||||||
@@ -20,6 +20,8 @@
|
|||||||
* for more details.
|
* for more details.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
|
#include <string.h>
|
||||||
|
|
||||||
#include "connection.h"
|
#include "connection.h"
|
||||||
|
|
||||||
#include <utils/linked_list.h>
|
#include <utils/linked_list.h>
|
||||||
@@ -48,6 +50,11 @@ struct private_connection_t {
|
|||||||
*/
|
*/
|
||||||
connection_t public;
|
connection_t public;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Name of the connection
|
||||||
|
*/
|
||||||
|
char *name;
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* ID of us
|
* ID of us
|
||||||
*/
|
*/
|
||||||
@@ -79,6 +86,14 @@ struct private_connection_t {
|
|||||||
linked_list_t *proposals;
|
linked_list_t *proposals;
|
||||||
};
|
};
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Implementation of connection_t.get_name.
|
||||||
|
*/
|
||||||
|
static char *get_name (private_connection_t *this)
|
||||||
|
{
|
||||||
|
return this->name;
|
||||||
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Implementation of connection_t.get_my_id.
|
* Implementation of connection_t.get_my_id.
|
||||||
*/
|
*/
|
||||||
@@ -253,6 +268,7 @@ static connection_t *clone(private_connection_t *this)
|
|||||||
iterator_t *iterator;
|
iterator_t *iterator;
|
||||||
proposal_t *proposal;
|
proposal_t *proposal;
|
||||||
private_connection_t *clone = (private_connection_t*)connection_create(
|
private_connection_t *clone = (private_connection_t*)connection_create(
|
||||||
|
this->name,
|
||||||
this->my_host->clone(this->my_host),
|
this->my_host->clone(this->my_host),
|
||||||
this->other_host->clone(this->other_host),
|
this->other_host->clone(this->other_host),
|
||||||
this->my_id->clone(this->my_id),
|
this->my_id->clone(this->my_id),
|
||||||
@@ -295,11 +311,12 @@ static void destroy (private_connection_t *this)
|
|||||||
/**
|
/**
|
||||||
* Described in header.
|
* Described in header.
|
||||||
*/
|
*/
|
||||||
connection_t * connection_create(host_t *my_host, host_t *other_host, identification_t *my_id, identification_t *other_id, auth_method_t auth_method)
|
connection_t * connection_create(char *name, host_t *my_host, host_t *other_host, identification_t *my_id, identification_t *other_id, auth_method_t auth_method)
|
||||||
{
|
{
|
||||||
private_connection_t *this = malloc_thing(private_connection_t);
|
private_connection_t *this = malloc_thing(private_connection_t);
|
||||||
|
|
||||||
/* public functions */
|
/* public functions */
|
||||||
|
this->public.get_name = (char*(*)(connection_t*))get_name;
|
||||||
this->public.get_my_id = (identification_t*(*)(connection_t*))get_my_id;
|
this->public.get_my_id = (identification_t*(*)(connection_t*))get_my_id;
|
||||||
this->public.get_other_id = (identification_t*(*)(connection_t*))get_other_id;
|
this->public.get_other_id = (identification_t*(*)(connection_t*))get_other_id;
|
||||||
this->public.get_my_host = (host_t*(*)(connection_t*))get_my_host;
|
this->public.get_my_host = (host_t*(*)(connection_t*))get_my_host;
|
||||||
@@ -316,6 +333,7 @@ connection_t * connection_create(host_t *my_host, host_t *other_host, identifica
|
|||||||
this->public.destroy = (void(*)(connection_t*))destroy;
|
this->public.destroy = (void(*)(connection_t*))destroy;
|
||||||
|
|
||||||
/* private variables */
|
/* private variables */
|
||||||
|
this->name = strdup(name);
|
||||||
this->my_host = my_host;
|
this->my_host = my_host;
|
||||||
this->other_host = other_host;
|
this->other_host = other_host;
|
||||||
this->my_id = my_id;
|
this->my_id = my_id;
|
||||||
|
|||||||
@@ -185,6 +185,17 @@ struct connection_t {
|
|||||||
*/
|
*/
|
||||||
auth_method_t (*get_auth_method) (connection_t *this);
|
auth_method_t (*get_auth_method) (connection_t *this);
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @brief Get the connection name.
|
||||||
|
*
|
||||||
|
* Name must not be freed, since it points to
|
||||||
|
* internal data.
|
||||||
|
*
|
||||||
|
* @param this calling object
|
||||||
|
* @return name of the connection
|
||||||
|
*/
|
||||||
|
char* (*get_name) (connection_t *this);
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* @brief Get the DH group to use for connection initialization.
|
* @brief Get the DH group to use for connection initialization.
|
||||||
*
|
*
|
||||||
@@ -225,8 +236,9 @@ struct connection_t {
|
|||||||
*
|
*
|
||||||
* Supplied hosts/IDs become owned by connection, so
|
* Supplied hosts/IDs become owned by connection, so
|
||||||
* do not modify or destroy them after a call to
|
* do not modify or destroy them after a call to
|
||||||
* connection_create().
|
* connection_create(). Name gets cloned internally.
|
||||||
*
|
*
|
||||||
|
* @param name connection identifier
|
||||||
* @param my_host host_t representing local address
|
* @param my_host host_t representing local address
|
||||||
* @param other_host host_t representing remote address
|
* @param other_host host_t representing remote address
|
||||||
* @param my_id identification_t for me
|
* @param my_id identification_t for me
|
||||||
@@ -236,7 +248,8 @@ struct connection_t {
|
|||||||
*
|
*
|
||||||
* @ingroup config
|
* @ingroup config
|
||||||
*/
|
*/
|
||||||
connection_t * connection_create(host_t *my_host, host_t *other_host,
|
connection_t * connection_create(char *name,
|
||||||
|
host_t *my_host, host_t *other_host,
|
||||||
identification_t *my_id,
|
identification_t *my_id,
|
||||||
identification_t *other_id,
|
identification_t *other_id,
|
||||||
auth_method_t auth_method);
|
auth_method_t auth_method);
|
||||||
|
|||||||
@@ -73,6 +73,20 @@ struct connection_store_t {
|
|||||||
*/
|
*/
|
||||||
connection_t *(*get_connection_by_hosts) (connection_store_t *this, host_t *my_host, host_t *other_host);
|
connection_t *(*get_connection_by_hosts) (connection_store_t *this, host_t *my_host, host_t *other_host);
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @brief Returns a connection identified by its name.
|
||||||
|
*
|
||||||
|
* This call is usefull to get a connection identified its
|
||||||
|
* name, as on an connection setup.
|
||||||
|
*
|
||||||
|
* @param this calling object
|
||||||
|
* @param name name of the connection to get
|
||||||
|
* @return
|
||||||
|
* - connection_t, if found
|
||||||
|
* - NULL otherwise
|
||||||
|
*/
|
||||||
|
connection_t *(*get_connection_by_name) (connection_store_t *this, char *name);
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* @brief Add a connection to the store.
|
* @brief Add a connection to the store.
|
||||||
*
|
*
|
||||||
|
|||||||
@@ -20,6 +20,8 @@
|
|||||||
* for more details.
|
* for more details.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
|
#include <string.h>
|
||||||
|
|
||||||
#include "local_connection_store.h"
|
#include "local_connection_store.h"
|
||||||
|
|
||||||
#include <utils/linked_list.h>
|
#include <utils/linked_list.h>
|
||||||
@@ -158,10 +160,33 @@ static connection_t *get_connection_by_ids(private_local_connection_store_t *thi
|
|||||||
return found;
|
return found;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Implementation of connection_store_t.get_connection_by_name.
|
||||||
|
*/
|
||||||
|
static connection_t *get_connection_by_name(private_local_connection_store_t *this, char *name)
|
||||||
|
{
|
||||||
|
iterator_t *iterator;
|
||||||
|
connection_t *current, *found = NULL;
|
||||||
|
|
||||||
|
iterator = this->connections->create_iterator(this->connections, TRUE);
|
||||||
|
while (iterator->has_next(iterator))
|
||||||
|
{
|
||||||
|
iterator->current(iterator, (void**)¤t);
|
||||||
|
if (strcmp(name, current->get_name(current)) == 0)
|
||||||
|
{
|
||||||
|
found = current->clone(current);
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
iterator->destroy(iterator);
|
||||||
|
|
||||||
|
return found;
|
||||||
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Implementation of connection_store_t.add_connection.
|
* Implementation of connection_store_t.add_connection.
|
||||||
*/
|
*/
|
||||||
status_t add_connection(private_local_connection_store_t *this, connection_t *connection)
|
static status_t add_connection(private_local_connection_store_t *this, connection_t *connection)
|
||||||
{
|
{
|
||||||
this->connections->insert_last(this->connections, connection);
|
this->connections->insert_last(this->connections, connection);
|
||||||
return SUCCESS;
|
return SUCCESS;
|
||||||
@@ -191,6 +216,7 @@ local_connection_store_t * local_connection_store_create()
|
|||||||
|
|
||||||
this->public.connection_store.get_connection_by_hosts = (connection_t*(*)(connection_store_t*,host_t*,host_t*))get_connection_by_hosts;
|
this->public.connection_store.get_connection_by_hosts = (connection_t*(*)(connection_store_t*,host_t*,host_t*))get_connection_by_hosts;
|
||||||
this->public.connection_store.get_connection_by_ids = (connection_t*(*)(connection_store_t*,identification_t*,identification_t*))get_connection_by_ids;
|
this->public.connection_store.get_connection_by_ids = (connection_t*(*)(connection_store_t*,identification_t*,identification_t*))get_connection_by_ids;
|
||||||
|
this->public.connection_store.get_connection_by_name = (connection_t*(*)(connection_store_t*,char*))get_connection_by_name;
|
||||||
this->public.connection_store.add_connection = (status_t(*)(connection_store_t*,connection_t*))add_connection;
|
this->public.connection_store.add_connection = (status_t(*)(connection_store_t*,connection_t*))add_connection;
|
||||||
this->public.connection_store.destroy = (void(*)(connection_store_t*))destroy;
|
this->public.connection_store.destroy = (void(*)(connection_store_t*))destroy;
|
||||||
|
|
||||||
|
|||||||
@@ -66,6 +66,9 @@ static policy_t *get_policy(private_local_policy_store_t *this, identification_t
|
|||||||
iterator_t *iterator;
|
iterator_t *iterator;
|
||||||
policy_t *current, *found = NULL;
|
policy_t *current, *found = NULL;
|
||||||
|
|
||||||
|
this->logger->log(this->logger, CONTROL|LEVEL0, "Looking for policy for IDs %s - %s",
|
||||||
|
my_id ? my_id->get_string(my_id) : "%any",
|
||||||
|
other_id->get_string(other_id));
|
||||||
iterator = this->policies->create_iterator(this->policies, TRUE);
|
iterator = this->policies->create_iterator(this->policies, TRUE);
|
||||||
while (iterator->has_next(iterator))
|
while (iterator->has_next(iterator))
|
||||||
{
|
{
|
||||||
@@ -73,8 +76,12 @@ static policy_t *get_policy(private_local_policy_store_t *this, identification_t
|
|||||||
identification_t *config_my_id = current->get_my_id(current);
|
identification_t *config_my_id = current->get_my_id(current);
|
||||||
identification_t *config_other_id = current->get_other_id(current);
|
identification_t *config_other_id = current->get_other_id(current);
|
||||||
|
|
||||||
|
this->logger->log(this->logger, CONTROL|LEVEL0, "Found one for %s - %s",
|
||||||
|
config_my_id->get_string(config_my_id),
|
||||||
|
config_other_id->get_string(config_other_id));
|
||||||
|
|
||||||
/* check other host first */
|
/* check other host first */
|
||||||
if (config_other_id->belongs_to(config_other_id, other_id))
|
if (other_id->belongs_to(other_id, config_other_id))
|
||||||
{
|
{
|
||||||
/* get it if my_id not specified */
|
/* get it if my_id not specified */
|
||||||
if (my_id == NULL)
|
if (my_id == NULL)
|
||||||
@@ -82,7 +89,7 @@ static policy_t *get_policy(private_local_policy_store_t *this, identification_t
|
|||||||
found = current->clone(current);
|
found = current->clone(current);
|
||||||
break;
|
break;
|
||||||
}
|
}
|
||||||
if (config_my_id->belongs_to(config_my_id, my_id))
|
if (my_id->belongs_to(my_id, config_my_id))
|
||||||
{
|
{
|
||||||
found = current->clone(current);
|
found = current->clone(current);
|
||||||
break;
|
break;
|
||||||
|
|||||||
@@ -207,21 +207,21 @@
|
|||||||
*
|
*
|
||||||
* @ingroup charon
|
* @ingroup charon
|
||||||
*/
|
*/
|
||||||
#define IPSEC_DIR "/etc/ipsec.d/"
|
#define IPSEC_DIR "/etc/ipsec.d"
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Directory for private keys
|
* Directory for private keys
|
||||||
*
|
*
|
||||||
* @ingroup charon
|
* @ingroup charon
|
||||||
*/
|
*/
|
||||||
#define PRIVATE_KEY_DIR IPSEC_DIR "private/"
|
#define PRIVATE_KEY_DIR IPSEC_DIR "/private"
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Directory for trusted certificates
|
* Directory for trusted certificates
|
||||||
*
|
*
|
||||||
* @ingroup charon
|
* @ingroup charon
|
||||||
*/
|
*/
|
||||||
#define CERTIFICATE_DIR IPSEC_DIR "certs/"
|
#define CERTIFICATE_DIR IPSEC_DIR "/certs"
|
||||||
|
|
||||||
|
|
||||||
typedef struct daemon_t daemon_t;
|
typedef struct daemon_t daemon_t;
|
||||||
|
|||||||
@@ -467,7 +467,7 @@ static status_t add_policies(private_child_sa_t *this, linked_list_t *my_ts_list
|
|||||||
/**
|
/**
|
||||||
* Implementation of child_sa_t.log_status.
|
* Implementation of child_sa_t.log_status.
|
||||||
*/
|
*/
|
||||||
static void log_status(private_child_sa_t *this, logger_t *logger)
|
static void log_status(private_child_sa_t *this, logger_t *logger, char* name)
|
||||||
{
|
{
|
||||||
iterator_t *iterator;
|
iterator_t *iterator;
|
||||||
sa_policy_t *policy;
|
sa_policy_t *policy;
|
||||||
@@ -479,7 +479,8 @@ static void log_status(private_child_sa_t *this, logger_t *logger)
|
|||||||
{
|
{
|
||||||
logger = this->logger;
|
logger = this->logger;
|
||||||
}
|
}
|
||||||
logger->log(logger, CONTROL, " protected with ESP (%x/%x), AH (%x,%x); traffic:",
|
logger->log(logger, CONTROL|LEVEL1, "\"%s\": protected with ESP (%x/%x), AH (%x,%x):",
|
||||||
|
name,
|
||||||
htonl(this->my_esp_spi), htonl(this->other_esp_spi),
|
htonl(this->my_esp_spi), htonl(this->other_esp_spi),
|
||||||
htonl(this->my_ah_spi), htonl(this->other_ah_spi));
|
htonl(this->my_ah_spi), htonl(this->other_ah_spi));
|
||||||
iterator = this->policies->create_iterator(this->policies, TRUE);
|
iterator = this->policies->create_iterator(this->policies, TRUE);
|
||||||
@@ -498,7 +499,8 @@ static void log_status(private_child_sa_t *this, logger_t *logger)
|
|||||||
snprintf(proto_buf, sizeof(proto_buf), "<%d>", policy->upper_proto);
|
snprintf(proto_buf, sizeof(proto_buf), "<%d>", policy->upper_proto);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
logger->log(logger, CONTROL, " %s/%d===%s===%s/%d",
|
logger->log(logger, CONTROL, "\"%s\": %s/%d==%s==%s/%d",
|
||||||
|
name,
|
||||||
policy->my_net->get_address(policy->my_net), policy->my_net_mask,
|
policy->my_net->get_address(policy->my_net), policy->my_net_mask,
|
||||||
proto_name,
|
proto_name,
|
||||||
policy->other_net->get_address(policy->other_net), policy->other_net_mask);
|
policy->other_net->get_address(policy->other_net), policy->other_net_mask);
|
||||||
@@ -570,7 +572,7 @@ child_sa_t * child_sa_create(host_t *me, host_t* other)
|
|||||||
this->public.add = (status_t(*)(child_sa_t*,proposal_t*,prf_plus_t*))add;
|
this->public.add = (status_t(*)(child_sa_t*,proposal_t*,prf_plus_t*))add;
|
||||||
this->public.update = (status_t(*)(child_sa_t*,proposal_t*,prf_plus_t*))update;
|
this->public.update = (status_t(*)(child_sa_t*,proposal_t*,prf_plus_t*))update;
|
||||||
this->public.add_policies = (status_t (*)(child_sa_t*, linked_list_t*,linked_list_t*))add_policies;
|
this->public.add_policies = (status_t (*)(child_sa_t*, linked_list_t*,linked_list_t*))add_policies;
|
||||||
this->public.log_status = (void (*)(child_sa_t*, logger_t*))log_status;
|
this->public.log_status = (void (*)(child_sa_t*, logger_t*, char*))log_status;
|
||||||
this->public.destroy = (void(*)(child_sa_t*))destroy;
|
this->public.destroy = (void(*)(child_sa_t*))destroy;
|
||||||
|
|
||||||
/* private data */
|
/* private data */
|
||||||
|
|||||||
@@ -118,12 +118,14 @@ struct child_sa_t {
|
|||||||
* The status of ESP/AH SAs is logged with the supplied logger in
|
* The status of ESP/AH SAs is logged with the supplied logger in
|
||||||
* a human readable form.
|
* a human readable form.
|
||||||
* Supplying NULL as logger uses the internal child_sa logger
|
* Supplying NULL as logger uses the internal child_sa logger
|
||||||
* to do the logging.
|
* to do the logging. The name is only a log-prefix without further
|
||||||
|
* meaning.
|
||||||
*
|
*
|
||||||
* @param this calling object
|
* @param this calling object
|
||||||
* @param logger logger to use for logging
|
* @param logger logger to use for logging
|
||||||
|
* @param name connection name
|
||||||
*/
|
*/
|
||||||
void (*log_status) (child_sa_t *this, logger_t *logger);
|
void (*log_status) (child_sa_t *this, logger_t *logger, char *name);
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* @brief Destroys a child_sa.
|
* @brief Destroys a child_sa.
|
||||||
|
|||||||
@@ -979,11 +979,24 @@ static void reset_message_buffers (private_ike_sa_t *this)
|
|||||||
/**
|
/**
|
||||||
* Implementation of protected_ike_sa_t.log_status.
|
* Implementation of protected_ike_sa_t.log_status.
|
||||||
*/
|
*/
|
||||||
static void log_status(private_ike_sa_t *this, logger_t *logger)
|
static void log_status(private_ike_sa_t *this, logger_t *logger, char *name)
|
||||||
{
|
{
|
||||||
iterator_t *iterator;
|
iterator_t *iterator;
|
||||||
child_sa_t *child_sa;
|
child_sa_t *child_sa;
|
||||||
|
|
||||||
|
/* only log if name == NULL or name == connection_name */
|
||||||
|
if (name)
|
||||||
|
{
|
||||||
|
if (strcmp(this->connection->get_name(this->connection), name) != 0)
|
||||||
|
{
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
else
|
||||||
|
{
|
||||||
|
name = this->connection->get_name(this->connection);
|
||||||
|
}
|
||||||
|
|
||||||
host_t *my_host = this->connection->get_my_host(this->connection);
|
host_t *my_host = this->connection->get_my_host(this->connection);
|
||||||
host_t *other_host = this->connection->get_other_host(this->connection);
|
host_t *other_host = this->connection->get_other_host(this->connection);
|
||||||
|
|
||||||
@@ -994,11 +1007,13 @@ static void log_status(private_ike_sa_t *this, logger_t *logger)
|
|||||||
{
|
{
|
||||||
logger = this->logger;
|
logger = this->logger;
|
||||||
}
|
}
|
||||||
logger->log(logger, CONTROL, "IKE_SA in state %s, SPIs: %lld %lld",
|
logger->log(logger, CONTROL|LEVEL1, "\"%s\": IKE_SA in state %s, SPIs: %llx %llx",
|
||||||
|
name,
|
||||||
mapping_find(ike_sa_state_m, this->current_state->get_state(this->current_state)),
|
mapping_find(ike_sa_state_m, this->current_state->get_state(this->current_state)),
|
||||||
this->ike_sa_id->get_initiator_spi(this->ike_sa_id),
|
this->ike_sa_id->get_initiator_spi(this->ike_sa_id),
|
||||||
this->ike_sa_id->get_responder_spi(this->ike_sa_id));
|
this->ike_sa_id->get_responder_spi(this->ike_sa_id));
|
||||||
logger->log(logger, CONTROL, "%s[%s]...%s[%s]; tunnels:",
|
logger->log(logger, CONTROL, "\"%s\": %s[%s]...%s[%s]",
|
||||||
|
name,
|
||||||
my_host->get_address(my_host),
|
my_host->get_address(my_host),
|
||||||
my_id->get_string(my_id),
|
my_id->get_string(my_id),
|
||||||
other_host->get_address(other_host),
|
other_host->get_address(other_host),
|
||||||
@@ -1008,7 +1023,7 @@ static void log_status(private_ike_sa_t *this, logger_t *logger)
|
|||||||
while (iterator->has_next(iterator))
|
while (iterator->has_next(iterator))
|
||||||
{
|
{
|
||||||
iterator->current(iterator, (void**)&child_sa);
|
iterator->current(iterator, (void**)&child_sa);
|
||||||
child_sa->log_status(child_sa, logger);
|
child_sa->log_status(child_sa, logger, name);
|
||||||
}
|
}
|
||||||
iterator->destroy(iterator);
|
iterator->destroy(iterator);
|
||||||
}
|
}
|
||||||
@@ -1109,10 +1124,11 @@ ike_sa_t * ike_sa_create(ike_sa_id_t *ike_sa_id)
|
|||||||
this->protected.public.get_other_host = (host_t*(*)(ike_sa_t*)) get_other_host;
|
this->protected.public.get_other_host = (host_t*(*)(ike_sa_t*)) get_other_host;
|
||||||
this->protected.public.get_my_id = (identification_t*(*)(ike_sa_t*)) get_my_id;
|
this->protected.public.get_my_id = (identification_t*(*)(ike_sa_t*)) get_my_id;
|
||||||
this->protected.public.get_other_id = (identification_t*(*)(ike_sa_t*)) get_other_id;
|
this->protected.public.get_other_id = (identification_t*(*)(ike_sa_t*)) get_other_id;
|
||||||
|
this->protected.public.get_connection = (connection_t*(*)(ike_sa_t*)) get_connection;
|
||||||
this->protected.public.retransmit_request = (status_t (*) (ike_sa_t *, u_int32_t)) retransmit_request;
|
this->protected.public.retransmit_request = (status_t (*) (ike_sa_t *, u_int32_t)) retransmit_request;
|
||||||
this->protected.public.get_state = (ike_sa_state_t (*) (ike_sa_t *this)) get_state;
|
this->protected.public.get_state = (ike_sa_state_t (*) (ike_sa_t *this)) get_state;
|
||||||
this->protected.public.send_delete_ike_sa_request = (void (*)(ike_sa_t*)) send_delete_ike_sa_request;
|
this->protected.public.send_delete_ike_sa_request = (void (*)(ike_sa_t*)) send_delete_ike_sa_request;
|
||||||
this->protected.public.log_status = (void (*) (ike_sa_t*,logger_t*))log_status;
|
this->protected.public.log_status = (void (*) (ike_sa_t*,logger_t*,char*))log_status;
|
||||||
this->protected.public.destroy = (void(*)(ike_sa_t*))destroy;
|
this->protected.public.destroy = (void(*)(ike_sa_t*))destroy;
|
||||||
|
|
||||||
/* protected functions */
|
/* protected functions */
|
||||||
|
|||||||
@@ -154,6 +154,19 @@ struct ike_sa_t {
|
|||||||
*/
|
*/
|
||||||
identification_t* (*get_other_id) (ike_sa_t *this);
|
identification_t* (*get_other_id) (ike_sa_t *this);
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @brief Get the connection of the IKE_SA.
|
||||||
|
*
|
||||||
|
* The internal used connection specification
|
||||||
|
* can be queried to get some data of an IKE_SA.
|
||||||
|
* The connection is still owned to the IKE_SA
|
||||||
|
* and must not be manipulated.
|
||||||
|
*
|
||||||
|
* @param this calling object
|
||||||
|
* @return connection_t
|
||||||
|
*/
|
||||||
|
connection_t* (*get_connection) (ike_sa_t *this);
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* @brief Get the state of type of associated state object.
|
* @brief Get the state of type of associated state object.
|
||||||
*
|
*
|
||||||
@@ -167,12 +180,14 @@ struct ike_sa_t {
|
|||||||
*
|
*
|
||||||
* The status of the IKE SA and all child SAs is logged.
|
* The status of the IKE SA and all child SAs is logged.
|
||||||
* Supplying NULL as logger uses the internal child_sa logger
|
* Supplying NULL as logger uses the internal child_sa logger
|
||||||
* to do the logging.
|
* to do the logging. The log is only done if the supplied
|
||||||
|
* connection name is NULL or matches the connections name.
|
||||||
*
|
*
|
||||||
* @param this calling object
|
* @param this calling object
|
||||||
* @param logger logger to use for logging
|
* @param logger logger to use for logging
|
||||||
|
* @param name name of the connection
|
||||||
*/
|
*/
|
||||||
void (*log_status) (ike_sa_t *this, logger_t *logger);
|
void (*log_status) (ike_sa_t *this, logger_t *logger, char *name);
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* @brief Destroys a ike_sa_t object.
|
* @brief Destroys a ike_sa_t object.
|
||||||
|
|||||||
@@ -573,6 +573,27 @@ linked_list_t *get_ike_sa_list(private_ike_sa_manager_t* this)
|
|||||||
return list;
|
return list;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Implementation of ike_sa_manager_t.log_status.
|
||||||
|
*/
|
||||||
|
static void log_status(private_ike_sa_manager_t* this, logger_t* logger, char* name)
|
||||||
|
{
|
||||||
|
iterator_t *iterator;
|
||||||
|
|
||||||
|
pthread_mutex_lock(&(this->mutex));
|
||||||
|
|
||||||
|
iterator = this->ike_sa_list->create_iterator(this->ike_sa_list, TRUE);
|
||||||
|
while (iterator->has_next(iterator))
|
||||||
|
{
|
||||||
|
ike_sa_entry_t *entry;
|
||||||
|
iterator->current(iterator, (void**)&entry);
|
||||||
|
entry->ike_sa->log_status(entry->ike_sa, logger, name);
|
||||||
|
}
|
||||||
|
iterator->destroy(iterator);
|
||||||
|
|
||||||
|
pthread_mutex_unlock(&(this->mutex));
|
||||||
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Implementation of ike_sa_manager_t.checkin.
|
* Implementation of ike_sa_manager_t.checkin.
|
||||||
*/
|
*/
|
||||||
@@ -767,6 +788,7 @@ ike_sa_manager_t *ike_sa_manager_create()
|
|||||||
this->public.checkout = (status_t(*)(ike_sa_manager_t*, ike_sa_id_t*,ike_sa_t**))checkout;
|
this->public.checkout = (status_t(*)(ike_sa_manager_t*, ike_sa_id_t*,ike_sa_t**))checkout;
|
||||||
this->public.checkout_by_hosts = (status_t(*)(ike_sa_manager_t*,host_t*,host_t*,ike_sa_t**))checkout_by_hosts;
|
this->public.checkout_by_hosts = (status_t(*)(ike_sa_manager_t*,host_t*,host_t*,ike_sa_t**))checkout_by_hosts;
|
||||||
this->public.get_ike_sa_list = (linked_list_t*(*)(ike_sa_manager_t*))get_ike_sa_list;
|
this->public.get_ike_sa_list = (linked_list_t*(*)(ike_sa_manager_t*))get_ike_sa_list;
|
||||||
|
this->public.log_status = (void(*)(ike_sa_manager_t*,logger_t*,char*))log_status;
|
||||||
this->public.checkin = (status_t(*)(ike_sa_manager_t*,ike_sa_t*))checkin;
|
this->public.checkin = (status_t(*)(ike_sa_manager_t*,ike_sa_t*))checkin;
|
||||||
this->public.delete = (status_t(*)(ike_sa_manager_t*,ike_sa_id_t*))delete;
|
this->public.delete = (status_t(*)(ike_sa_manager_t*,ike_sa_id_t*))delete;
|
||||||
this->public.checkin_and_delete = (status_t(*)(ike_sa_manager_t*,ike_sa_t*))checkin_and_delete;
|
this->public.checkin_and_delete = (status_t(*)(ike_sa_manager_t*,ike_sa_t*))checkin_and_delete;
|
||||||
|
|||||||
@@ -25,6 +25,7 @@
|
|||||||
|
|
||||||
#include <types.h>
|
#include <types.h>
|
||||||
#include <sa/ike_sa.h>
|
#include <sa/ike_sa.h>
|
||||||
|
#include <utils/logger.h>
|
||||||
|
|
||||||
|
|
||||||
typedef struct ike_sa_manager_t ike_sa_manager_t;
|
typedef struct ike_sa_manager_t ike_sa_manager_t;
|
||||||
@@ -58,7 +59,7 @@ struct ike_sa_manager_t {
|
|||||||
* @warning checking out two times without checking in will
|
* @warning checking out two times without checking in will
|
||||||
* result in a deadlock!
|
* result in a deadlock!
|
||||||
*
|
*
|
||||||
* @param ike_sa_manager the manager object
|
* @param this the manager object
|
||||||
* @param ike_sa_id[in/out] the SA identifier, will be updated
|
* @param ike_sa_id[in/out] the SA identifier, will be updated
|
||||||
* @param ike_sa[out] checked out SA
|
* @param ike_sa[out] checked out SA
|
||||||
* @returns
|
* @returns
|
||||||
@@ -66,7 +67,7 @@ struct ike_sa_manager_t {
|
|||||||
* - NOT_FOUND when no such SA is available
|
* - NOT_FOUND when no such SA is available
|
||||||
* - CREATED if a new IKE_SA got created
|
* - CREATED if a new IKE_SA got created
|
||||||
*/
|
*/
|
||||||
status_t (*checkout) (ike_sa_manager_t* ike_sa_manager, ike_sa_id_t *sa_id, ike_sa_t **ike_sa);
|
status_t (*checkout) (ike_sa_manager_t* this, ike_sa_id_t *sa_id, ike_sa_t **ike_sa);
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* @brief Create and checkout an IKE_SA as original initator.
|
* @brief Create and checkout an IKE_SA as original initator.
|
||||||
@@ -74,10 +75,10 @@ struct ike_sa_manager_t {
|
|||||||
* Creates and checks out a SA as initiator.
|
* Creates and checks out a SA as initiator.
|
||||||
* Management of SPIs is the managers job, he will set it.
|
* Management of SPIs is the managers job, he will set it.
|
||||||
*
|
*
|
||||||
* @param ike_sa_manager the manager object
|
* @param this the manager object
|
||||||
* @param ike_sa[out] checked out SA
|
* @param ike_sa[out] checked out SA
|
||||||
*/
|
*/
|
||||||
void (*create_and_checkout) (ike_sa_manager_t* ike_sa_manager,ike_sa_t **ike_sa);
|
void (*create_and_checkout) (ike_sa_manager_t* this,ike_sa_t **ike_sa);
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* @brief Check out an IKE_SA, defined be the two peers.
|
* @brief Check out an IKE_SA, defined be the two peers.
|
||||||
@@ -86,7 +87,7 @@ struct ike_sa_manager_t {
|
|||||||
* for kernel traps, status querying and so on... one of the hosts
|
* for kernel traps, status querying and so on... one of the hosts
|
||||||
* may be 0.0.0.0 (defaultroute/any), but not both.
|
* may be 0.0.0.0 (defaultroute/any), but not both.
|
||||||
*
|
*
|
||||||
* @param ike_sa_manager the manager object
|
* @param this the manager object
|
||||||
* @param me host on local side
|
* @param me host on local side
|
||||||
* @param other host on remote side
|
* @param other host on remote side
|
||||||
* @param ike_sa[out] checked out SA
|
* @param ike_sa[out] checked out SA
|
||||||
@@ -94,7 +95,7 @@ struct ike_sa_manager_t {
|
|||||||
* - NOT_FOUND, if no such SA found
|
* - NOT_FOUND, if no such SA found
|
||||||
* - SUCCESS, if SA found and ike_sa set appropriatly
|
* - SUCCESS, if SA found and ike_sa set appropriatly
|
||||||
*/
|
*/
|
||||||
status_t (*checkout_by_hosts) (ike_sa_manager_t* ike_sa_manager, host_t *me, host_t *other, ike_sa_t **ike_sa);
|
status_t (*checkout_by_hosts) (ike_sa_manager_t* this, host_t *me, host_t *other, ike_sa_t **ike_sa);
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* @brief Get a list of all IKE_SA SAs currently set up.
|
* @brief Get a list of all IKE_SA SAs currently set up.
|
||||||
@@ -104,10 +105,23 @@ struct ike_sa_manager_t {
|
|||||||
* corrensponding ID really exists, since it may be deleted
|
* corrensponding ID really exists, since it may be deleted
|
||||||
* in the meantime by another thread.
|
* in the meantime by another thread.
|
||||||
*
|
*
|
||||||
* @param ike_sa_manager the manager object
|
* @param this the manager object
|
||||||
* @return a list with ike_sa_id_t s
|
* @return a list with ike_sa_id_t s
|
||||||
*/
|
*/
|
||||||
linked_list_t *(*get_ike_sa_list) (ike_sa_manager_t* ike_sa_manager);
|
linked_list_t *(*get_ike_sa_list) (ike_sa_manager_t* this);
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @brief Log the status of the IKE_SA's in the manager.
|
||||||
|
*
|
||||||
|
* A informational log is done to the supplied logger. If logger is
|
||||||
|
* NULL, an internal logger is used. If a name is supplied,
|
||||||
|
* only connections with the matching name will be logged.
|
||||||
|
*
|
||||||
|
* @param this the manager object
|
||||||
|
* @param logger logger to do the log, or NULL
|
||||||
|
* @param name name of a connection, or NULL
|
||||||
|
*/
|
||||||
|
void (*log_status) (ike_sa_manager_t* this, logger_t* logger, char* name);
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* @brief Checkin the SA after usage.
|
* @brief Checkin the SA after usage.
|
||||||
@@ -115,14 +129,14 @@ struct ike_sa_manager_t {
|
|||||||
* @warning the SA pointer MUST NOT be used after checkin!
|
* @warning the SA pointer MUST NOT be used after checkin!
|
||||||
* The SA must be checked out again!
|
* The SA must be checked out again!
|
||||||
*
|
*
|
||||||
* @param ike_sa_manager the manager object
|
* @param this the manager object
|
||||||
* @param ike_sa_id[in/out] the SA identifier, will be updated
|
* @param ike_sa_id[in/out] the SA identifier, will be updated
|
||||||
* @param ike_sa[out] checked out SA
|
* @param ike_sa[out] checked out SA
|
||||||
* @returns
|
* @returns
|
||||||
* - SUCCESS if checked in
|
* - SUCCESS if checked in
|
||||||
* - NOT_FOUND when not found (shouldn't happen!)
|
* - NOT_FOUND when not found (shouldn't happen!)
|
||||||
*/
|
*/
|
||||||
status_t (*checkin) (ike_sa_manager_t* ike_sa_manager, ike_sa_t *ike_sa);
|
status_t (*checkin) (ike_sa_manager_t* this, ike_sa_t *ike_sa);
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* @brief Delete a SA, which was not checked out.
|
* @brief Delete a SA, which was not checked out.
|
||||||
@@ -130,33 +144,33 @@ struct ike_sa_manager_t {
|
|||||||
* @warning do not use this when the SA is already checked out, this will
|
* @warning do not use this when the SA is already checked out, this will
|
||||||
* deadlock!
|
* deadlock!
|
||||||
*
|
*
|
||||||
* @param ike_sa_manager the manager object
|
* @param this the manager object
|
||||||
* @param ike_sa_id[in/out] the SA identifier
|
* @param ike_sa_id[in/out] the SA identifier
|
||||||
* @returns
|
* @returns
|
||||||
* - SUCCESS if found
|
* - SUCCESS if found
|
||||||
* - NOT_FOUND when no such SA is available
|
* - NOT_FOUND when no such SA is available
|
||||||
*/
|
*/
|
||||||
status_t (*delete) (ike_sa_manager_t* ike_sa_manager, ike_sa_id_t *ike_sa_id);
|
status_t (*delete) (ike_sa_manager_t* this, ike_sa_id_t *ike_sa_id);
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* @brief Delete a checked out SA.
|
* @brief Delete a checked out SA.
|
||||||
*
|
*
|
||||||
* @param ike_sa_manager the manager object
|
* @param this the manager object
|
||||||
* @param ike_sa SA to delete
|
* @param ike_sa SA to delete
|
||||||
* @returns
|
* @returns
|
||||||
* - SUCCESS if found
|
* - SUCCESS if found
|
||||||
* - NOT_FOUND when no such SA is available
|
* - NOT_FOUND when no such SA is available
|
||||||
*/
|
*/
|
||||||
status_t (*checkin_and_delete) (ike_sa_manager_t* ike_sa_manager, ike_sa_t *ike_sa);
|
status_t (*checkin_and_delete) (ike_sa_manager_t* this, ike_sa_t *ike_sa);
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* @brief Destroys the manager with all associated SAs.
|
* @brief Destroys the manager with all associated SAs.
|
||||||
*
|
*
|
||||||
* Threads will be driven out, so all SAs can be deleted cleanly.
|
* Threads will be driven out, so all SAs can be deleted cleanly.
|
||||||
*
|
*
|
||||||
* @param ike_sa_manager the manager object
|
* @param this the manager object
|
||||||
*/
|
*/
|
||||||
void (*destroy) (ike_sa_manager_t *ike_sa_manager);
|
void (*destroy) (ike_sa_manager_t *this);
|
||||||
};
|
};
|
||||||
|
|
||||||
/**
|
/**
|
||||||
|
|||||||
@@ -42,24 +42,6 @@
|
|||||||
|
|
||||||
struct sockaddr_un socket_addr = { AF_UNIX, STROKE_SOCKET};
|
struct sockaddr_un socket_addr = { AF_UNIX, STROKE_SOCKET};
|
||||||
|
|
||||||
typedef struct connection_entry_t connection_entry_t;
|
|
||||||
|
|
||||||
/**
|
|
||||||
* A connection entry combines a connection name with a connection.
|
|
||||||
*/
|
|
||||||
struct connection_entry_t {
|
|
||||||
|
|
||||||
/**
|
|
||||||
* connection name.
|
|
||||||
*/
|
|
||||||
char *name;
|
|
||||||
|
|
||||||
/**
|
|
||||||
* Configuration for IKE_SA_INIT exchange.
|
|
||||||
*/
|
|
||||||
connection_t *connection;
|
|
||||||
};
|
|
||||||
|
|
||||||
|
|
||||||
typedef struct private_stroke_t private_stroke_t;
|
typedef struct private_stroke_t private_stroke_t;
|
||||||
|
|
||||||
@@ -73,11 +55,6 @@ struct private_stroke_t {
|
|||||||
*/
|
*/
|
||||||
stroke_t public;
|
stroke_t public;
|
||||||
|
|
||||||
/**
|
|
||||||
* Holding all connections as connection_entry_t's.
|
|
||||||
*/
|
|
||||||
linked_list_t *connections;
|
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Assigned logger_t object in charon.
|
* Assigned logger_t object in charon.
|
||||||
*/
|
*/
|
||||||
@@ -102,11 +79,6 @@ struct private_stroke_t {
|
|||||||
* Read from the socket and handle stroke messages
|
* Read from the socket and handle stroke messages
|
||||||
*/
|
*/
|
||||||
void (*stroke_receive) (private_stroke_t *this);
|
void (*stroke_receive) (private_stroke_t *this);
|
||||||
|
|
||||||
/**
|
|
||||||
* find a connection in the config list by name
|
|
||||||
*/
|
|
||||||
connection_t *(*get_connection_by_name) (private_stroke_t *this, char *name);
|
|
||||||
};
|
};
|
||||||
|
|
||||||
/**
|
/**
|
||||||
@@ -147,7 +119,6 @@ static void stroke_add_conn(private_stroke_t *this, stroke_msg_t *msg)
|
|||||||
host_t *my_host, *other_host, *my_subnet, *other_subnet;
|
host_t *my_host, *other_host, *my_subnet, *other_subnet;
|
||||||
proposal_t *proposal;
|
proposal_t *proposal;
|
||||||
traffic_selector_t *my_ts, *other_ts;
|
traffic_selector_t *my_ts, *other_ts;
|
||||||
connection_entry_t *entry;
|
|
||||||
x509_t *cert;
|
x509_t *cert;
|
||||||
|
|
||||||
pop_string(msg, &msg->add_conn.name);
|
pop_string(msg, &msg->add_conn.name);
|
||||||
@@ -291,7 +262,9 @@ static void stroke_add_conn(private_stroke_t *this, stroke_msg_t *msg)
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
connection = connection_create(my_host, other_host, my_id->clone(my_id), other_id->clone(other_id),
|
connection = connection_create(msg->add_conn.name,
|
||||||
|
my_host, other_host,
|
||||||
|
my_id->clone(my_id), other_id->clone(other_id),
|
||||||
RSA_DIGITAL_SIGNATURE);
|
RSA_DIGITAL_SIGNATURE);
|
||||||
proposal = proposal_create(1);
|
proposal = proposal_create(1);
|
||||||
proposal->add_algorithm(proposal, PROTO_IKE, ENCRYPTION_ALGORITHM, ENCR_AES_CBC, 16);
|
proposal->add_algorithm(proposal, PROTO_IKE, ENCRYPTION_ALGORITHM, ENCR_AES_CBC, 16);
|
||||||
@@ -305,11 +278,6 @@ static void stroke_add_conn(private_stroke_t *this, stroke_msg_t *msg)
|
|||||||
proposal->add_algorithm(proposal, PROTO_IKE, DIFFIE_HELLMAN_GROUP, MODP_4096_BIT, 0);
|
proposal->add_algorithm(proposal, PROTO_IKE, DIFFIE_HELLMAN_GROUP, MODP_4096_BIT, 0);
|
||||||
proposal->add_algorithm(proposal, PROTO_IKE, DIFFIE_HELLMAN_GROUP, MODP_8192_BIT, 0);
|
proposal->add_algorithm(proposal, PROTO_IKE, DIFFIE_HELLMAN_GROUP, MODP_8192_BIT, 0);
|
||||||
connection->add_proposal(connection, proposal);
|
connection->add_proposal(connection, proposal);
|
||||||
/* add in our list, so we can manipulate the connection further via name */
|
|
||||||
entry = malloc_thing(connection_entry_t);
|
|
||||||
entry->name = strdup(msg->add_conn.name);
|
|
||||||
entry->connection = connection;
|
|
||||||
this->connections->insert_last(this->connections, entry);
|
|
||||||
/* add to global connection list */
|
/* add to global connection list */
|
||||||
charon->connections->add_connection(charon->connections, connection);
|
charon->connections->add_connection(charon->connections, connection);
|
||||||
|
|
||||||
@@ -337,7 +305,7 @@ static void stroke_initiate(private_stroke_t *this, stroke_msg_t *msg)
|
|||||||
|
|
||||||
pop_string(msg, &(msg->initiate.name));
|
pop_string(msg, &(msg->initiate.name));
|
||||||
this->logger->log(this->logger, CONTROL, "received stroke: initiate \"%s\"", msg->initiate.name);
|
this->logger->log(this->logger, CONTROL, "received stroke: initiate \"%s\"", msg->initiate.name);
|
||||||
connection = this->get_connection_by_name(this, msg->initiate.name);
|
connection = charon->connections->get_connection_by_name(charon->connections, msg->initiate.name);
|
||||||
if (connection == NULL)
|
if (connection == NULL)
|
||||||
{
|
{
|
||||||
this->stroke_logger->log(this->stroke_logger, ERROR, "could not find a connection named \"%s\"", msg->initiate.name);
|
this->stroke_logger->log(this->stroke_logger, ERROR, "could not find a connection named \"%s\"", msg->initiate.name);
|
||||||
@@ -361,13 +329,15 @@ static void stroke_terminate(private_stroke_t *this, stroke_msg_t *msg)
|
|||||||
|
|
||||||
pop_string(msg, &(msg->terminate.name));
|
pop_string(msg, &(msg->terminate.name));
|
||||||
this->logger->log(this->logger, CONTROL, "received stroke: terminate \"%s\"", msg->terminate.name);
|
this->logger->log(this->logger, CONTROL, "received stroke: terminate \"%s\"", msg->terminate.name);
|
||||||
connection = this->get_connection_by_name(this, msg->terminate.name);
|
connection = charon->connections->get_connection_by_name(charon->connections, msg->terminate.name);
|
||||||
|
|
||||||
if (connection)
|
if (connection)
|
||||||
{
|
{
|
||||||
my_host = connection->get_my_host(connection);
|
my_host = connection->get_my_host(connection);
|
||||||
other_host = connection->get_other_host(connection);
|
other_host = connection->get_other_host(connection);
|
||||||
|
|
||||||
|
/* TODO: Do this directly by name now */
|
||||||
|
/* TODO: terminate any instance of the name */
|
||||||
status = charon->ike_sa_manager->checkout_by_hosts(charon->ike_sa_manager,
|
status = charon->ike_sa_manager->checkout_by_hosts(charon->ike_sa_manager,
|
||||||
my_host, other_host, &ike_sa);
|
my_host, other_host, &ike_sa);
|
||||||
|
|
||||||
@@ -396,31 +366,11 @@ static void stroke_terminate(private_stroke_t *this, stroke_msg_t *msg)
|
|||||||
*/
|
*/
|
||||||
static void stroke_status(private_stroke_t *this, stroke_msg_t *msg)
|
static void stroke_status(private_stroke_t *this, stroke_msg_t *msg)
|
||||||
{
|
{
|
||||||
linked_list_t *list;
|
if (msg->status.name)
|
||||||
iterator_t *iterator;
|
|
||||||
status_t status;
|
|
||||||
|
|
||||||
|
|
||||||
list = charon->ike_sa_manager->get_ike_sa_list(charon->ike_sa_manager);
|
|
||||||
iterator = list->create_iterator(list, TRUE);
|
|
||||||
while (iterator->has_next(iterator))
|
|
||||||
{
|
{
|
||||||
ike_sa_id_t *ike_sa_id;
|
pop_string(msg, &(msg->status.name));
|
||||||
ike_sa_t *ike_sa;
|
|
||||||
iterator->current(iterator, (void**)&ike_sa_id);
|
|
||||||
/* TODO: A log_status method (as in IKE_SA/CHILD_SA) would be better than checking
|
|
||||||
* out every single IKE...
|
|
||||||
*/
|
|
||||||
status = charon->ike_sa_manager->checkout(charon->ike_sa_manager, ike_sa_id, &ike_sa);
|
|
||||||
if (status == SUCCESS)
|
|
||||||
{
|
|
||||||
ike_sa->log_status(ike_sa, this->stroke_logger);
|
|
||||||
charon->ike_sa_manager->checkin(charon->ike_sa_manager, ike_sa);
|
|
||||||
}
|
|
||||||
ike_sa_id->destroy(ike_sa_id);
|
|
||||||
}
|
}
|
||||||
iterator->destroy(iterator);
|
charon->ike_sa_manager->log_status(charon->ike_sa_manager, this->stroke_logger, msg->status.name);
|
||||||
list->destroy(list);
|
|
||||||
}
|
}
|
||||||
|
|
||||||
logger_context_t get_context(char *context)
|
logger_context_t get_context(char *context)
|
||||||
@@ -607,6 +557,12 @@ static void stroke_receive(private_stroke_t *this)
|
|||||||
stroke_status(this, msg);
|
stroke_status(this, msg);
|
||||||
break;
|
break;
|
||||||
}
|
}
|
||||||
|
case STR_STATUS_ALL:
|
||||||
|
{
|
||||||
|
this->stroke_logger->enable_level(this->stroke_logger, LEVEL1);
|
||||||
|
stroke_status(this, msg);
|
||||||
|
break;
|
||||||
|
}
|
||||||
case STR_ADD_CONN:
|
case STR_ADD_CONN:
|
||||||
{
|
{
|
||||||
stroke_add_conn(this, msg);
|
stroke_add_conn(this, msg);
|
||||||
@@ -632,51 +588,15 @@ static void stroke_receive(private_stroke_t *this)
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
||||||
/**
|
|
||||||
* Implementation of private_stroke_t.get_connection_by_name.
|
|
||||||
*/
|
|
||||||
static connection_t *get_connection_by_name(private_stroke_t *this, char *name)
|
|
||||||
{
|
|
||||||
iterator_t *iterator;
|
|
||||||
connection_t *found = NULL;
|
|
||||||
|
|
||||||
iterator = this->connections->create_iterator(this->connections, TRUE);
|
|
||||||
while (iterator->has_next(iterator))
|
|
||||||
{
|
|
||||||
connection_entry_t *entry;
|
|
||||||
iterator->current(iterator,(void **) &entry);
|
|
||||||
|
|
||||||
if (strcmp(entry->name,name) == 0)
|
|
||||||
{
|
|
||||||
/* found configuration */
|
|
||||||
found = entry->connection;
|
|
||||||
break;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
iterator->destroy(iterator);
|
|
||||||
|
|
||||||
return found;
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Implementation of stroke_t.destroy.
|
* Implementation of stroke_t.destroy.
|
||||||
*/
|
*/
|
||||||
static void destroy(private_stroke_t *this)
|
static void destroy(private_stroke_t *this)
|
||||||
{
|
{
|
||||||
connection_entry_t *entry;
|
|
||||||
|
|
||||||
pthread_cancel(this->assigned_thread);
|
pthread_cancel(this->assigned_thread);
|
||||||
pthread_join(this->assigned_thread, NULL);
|
pthread_join(this->assigned_thread, NULL);
|
||||||
|
|
||||||
while (this->connections->remove_first(this->connections, (void **)&entry) == SUCCESS)
|
|
||||||
{
|
|
||||||
/* connection is destroyed by global list */
|
|
||||||
free(entry->name);
|
|
||||||
free(entry);
|
|
||||||
}
|
|
||||||
this->connections->destroy(this->connections);
|
|
||||||
|
|
||||||
close(this->socket);
|
close(this->socket);
|
||||||
unlink(socket_addr.sun_path);
|
unlink(socket_addr.sun_path);
|
||||||
free(this);
|
free(this);
|
||||||
@@ -696,7 +616,6 @@ stroke_t *stroke_create()
|
|||||||
|
|
||||||
/* private functions */
|
/* private functions */
|
||||||
this->stroke_receive = stroke_receive;
|
this->stroke_receive = stroke_receive;
|
||||||
this->get_connection_by_name = get_connection_by_name;
|
|
||||||
|
|
||||||
this->logger = logger_manager->get_logger(logger_manager, CONFIG);
|
this->logger = logger_manager->get_logger(logger_manager, CONFIG);
|
||||||
|
|
||||||
@@ -738,8 +657,5 @@ stroke_t *stroke_create()
|
|||||||
return NULL;
|
return NULL;
|
||||||
}
|
}
|
||||||
|
|
||||||
/* private variables */
|
|
||||||
this->connections = linked_list_create();
|
|
||||||
|
|
||||||
return (&this->public);
|
return (&this->public);
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -14,6 +14,10 @@
|
|||||||
|
|
||||||
LIB_DIR= $(MAIN_DIR)lib/
|
LIB_DIR= $(MAIN_DIR)lib/
|
||||||
|
|
||||||
|
include $(MAIN_DIR)lib/utils/Makefile.utils
|
||||||
|
include $(MAIN_DIR)lib/crypto/Makefile.transforms
|
||||||
|
include $(MAIN_DIR)lib/asn1/Makefile.asn1
|
||||||
|
|
||||||
LIB_OBJS+= $(BUILD_DIR)types.o
|
LIB_OBJS+= $(BUILD_DIR)types.o
|
||||||
$(BUILD_DIR)types.o : $(LIB_DIR)types.c $(LIB_DIR)types.h
|
$(BUILD_DIR)types.o : $(LIB_DIR)types.c $(LIB_DIR)types.h
|
||||||
$(CC) $(CFLAGS) -c -o $@ $<
|
$(CC) $(CFLAGS) -c -o $@ $<
|
||||||
@@ -25,7 +29,3 @@ $(BUILD_DIR)definitions.o : $(LIB_DIR)definitions.c $(LIB_DIR)definitions.h
|
|||||||
LIB_OBJS+= $(BUILD_DIR)library.o
|
LIB_OBJS+= $(BUILD_DIR)library.o
|
||||||
$(BUILD_DIR)library.o : $(LIB_DIR)library.c $(LIB_DIR)library.h
|
$(BUILD_DIR)library.o : $(LIB_DIR)library.c $(LIB_DIR)library.h
|
||||||
$(CC) $(CFLAGS) -c -o $@ $<
|
$(CC) $(CFLAGS) -c -o $@ $<
|
||||||
|
|
||||||
include $(MAIN_DIR)lib/crypto/Makefile.transforms
|
|
||||||
include $(MAIN_DIR)lib/utils/Makefile.utils
|
|
||||||
include $(MAIN_DIR)lib/asn1/Makefile.asn1
|
|
||||||
|
|||||||
@@ -14,6 +14,9 @@
|
|||||||
|
|
||||||
UTILS_DIR= $(LIB_DIR)utils/
|
UTILS_DIR= $(LIB_DIR)utils/
|
||||||
|
|
||||||
|
LIB_OBJS+= $(BUILD_DIR)leak_detective.o
|
||||||
|
$(BUILD_DIR)leak_detective.o : $(UTILS_DIR)leak_detective.c $(UTILS_DIR)leak_detective.h
|
||||||
|
$(CC) $(CFLAGS) -c -o $@ $<
|
||||||
|
|
||||||
LIB_OBJS+= $(BUILD_DIR)linked_list.o
|
LIB_OBJS+= $(BUILD_DIR)linked_list.o
|
||||||
$(BUILD_DIR)linked_list.o : $(UTILS_DIR)linked_list.c $(UTILS_DIR)linked_list.h
|
$(BUILD_DIR)linked_list.o : $(UTILS_DIR)linked_list.c $(UTILS_DIR)linked_list.h
|
||||||
@@ -42,7 +45,3 @@ $(BUILD_DIR)identification.o : $(UTILS_DIR)identification.c $(UTILS_DIR)identifi
|
|||||||
LIB_OBJS+= $(BUILD_DIR)host.o
|
LIB_OBJS+= $(BUILD_DIR)host.o
|
||||||
$(BUILD_DIR)host.o : $(UTILS_DIR)host.c $(UTILS_DIR)host.h
|
$(BUILD_DIR)host.o : $(UTILS_DIR)host.c $(UTILS_DIR)host.h
|
||||||
$(CC) $(CFLAGS) -c -o $@ $<
|
$(CC) $(CFLAGS) -c -o $@ $<
|
||||||
|
|
||||||
LIB_OBJS+= $(BUILD_DIR)leak_detective.o
|
|
||||||
$(BUILD_DIR)leak_detective.o : $(UTILS_DIR)leak_detective.c $(UTILS_DIR)leak_detective.h
|
|
||||||
$(CC) $(CFLAGS) -c -o $@ $<
|
|
||||||
@@ -253,7 +253,7 @@ void free_hook(void *ptr, const void *caller)
|
|||||||
{
|
{
|
||||||
pthread_mutex_unlock(&mutex);
|
pthread_mutex_unlock(&mutex);
|
||||||
/* TODO: since pthread_join cannot be excluded cleanly, we are not whining about bad frees */
|
/* TODO: since pthread_join cannot be excluded cleanly, we are not whining about bad frees */
|
||||||
return;
|
//return;
|
||||||
logger->log(logger, ERROR, "freeing of invalid memory (%p)", ptr);
|
logger->log(logger, ERROR, "freeing of invalid memory (%p)", ptr);
|
||||||
stack_frame_count = backtrace(stack_frames, STACK_FRAMES_COUNT);
|
stack_frame_count = backtrace(stack_frames, STACK_FRAMES_COUNT);
|
||||||
log_stack_frames(stack_frames, stack_frame_count);
|
log_stack_frames(stack_frames, stack_frame_count);
|
||||||
@@ -323,8 +323,8 @@ void leak_detective_init()
|
|||||||
*/
|
*/
|
||||||
void leak_detective_cleanup()
|
void leak_detective_cleanup()
|
||||||
{
|
{
|
||||||
report_leaks();
|
|
||||||
uninstall_hooks();
|
uninstall_hooks();
|
||||||
|
report_leaks();
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
||||||
@@ -348,6 +348,7 @@ struct excluded_function {
|
|||||||
{"libpthread.so.0", "_pthread_cleanup_pop", NULL, NULL},
|
{"libpthread.so.0", "_pthread_cleanup_pop", NULL, NULL},
|
||||||
{"libc.so.6", "mktime", NULL, NULL},
|
{"libc.so.6", "mktime", NULL, NULL},
|
||||||
{"libc.so.6", "vsyslog", NULL, NULL},
|
{"libc.so.6", "vsyslog", NULL, NULL},
|
||||||
|
{"libc.so.6", "strerror", NULL, NULL},
|
||||||
};
|
};
|
||||||
#define INET_NTOA 0
|
#define INET_NTOA 0
|
||||||
#define PTHREAD_CREATE 1
|
#define PTHREAD_CREATE 1
|
||||||
@@ -357,6 +358,7 @@ struct excluded_function {
|
|||||||
#define PTHREAD_CLEANUP_POP 5
|
#define PTHREAD_CLEANUP_POP 5
|
||||||
#define MKTIME 6
|
#define MKTIME 6
|
||||||
#define VSYSLOG 7
|
#define VSYSLOG 7
|
||||||
|
#define STRERROR 8
|
||||||
|
|
||||||
|
|
||||||
/**
|
/**
|
||||||
@@ -402,92 +404,92 @@ char *inet_ntoa(struct in_addr in)
|
|||||||
return result;
|
return result;
|
||||||
}
|
}
|
||||||
|
|
||||||
int pthread_create(pthread_t *__restrict __threadp, __const pthread_attr_t *__restrict __attr,
|
// int pthread_create(pthread_t *__restrict __threadp, __const pthread_attr_t *__restrict __attr,
|
||||||
void *(*__start_routine) (void *), void *__restrict __arg)
|
// void *(*__start_routine) (void *), void *__restrict __arg)
|
||||||
{
|
// {
|
||||||
int (*_pthread_create) (pthread_t *__restrict __threadp,
|
// int (*_pthread_create) (pthread_t *__restrict __threadp,
|
||||||
__const pthread_attr_t *__restrict __attr,
|
// __const pthread_attr_t *__restrict __attr,
|
||||||
void *(*__start_routine) (void *),
|
// void *(*__start_routine) (void *),
|
||||||
void *__restrict __arg) = excluded_functions[PTHREAD_CREATE].lib_function;
|
// void *__restrict __arg) = excluded_functions[PTHREAD_CREATE].lib_function;
|
||||||
int result;
|
// int result;
|
||||||
|
//
|
||||||
pthread_mutex_lock(&mutex);
|
// pthread_mutex_lock(&mutex);
|
||||||
uninstall_hooks();
|
// uninstall_hooks();
|
||||||
|
//
|
||||||
result = _pthread_create(__threadp, __attr, __start_routine, __arg);
|
// result = _pthread_create(__threadp, __attr, __start_routine, __arg);
|
||||||
|
//
|
||||||
install_hooks();
|
// install_hooks();
|
||||||
pthread_mutex_unlock(&mutex);
|
// pthread_mutex_unlock(&mutex);
|
||||||
return result;
|
// return result;
|
||||||
}
|
// }
|
||||||
|
//
|
||||||
|
//
|
||||||
int pthread_cancel(pthread_t __th)
|
// int pthread_cancel(pthread_t __th)
|
||||||
{
|
// {
|
||||||
int (*_pthread_cancel) (pthread_t) = excluded_functions[PTHREAD_CANCEL].lib_function;
|
// int (*_pthread_cancel) (pthread_t) = excluded_functions[PTHREAD_CANCEL].lib_function;
|
||||||
int result;
|
// int result;
|
||||||
|
//
|
||||||
pthread_mutex_lock(&mutex);
|
// pthread_mutex_lock(&mutex);
|
||||||
uninstall_hooks();
|
// uninstall_hooks();
|
||||||
|
//
|
||||||
result = _pthread_cancel(__th);
|
// result = _pthread_cancel(__th);
|
||||||
|
//
|
||||||
install_hooks();
|
// install_hooks();
|
||||||
pthread_mutex_unlock(&mutex);
|
// pthread_mutex_unlock(&mutex);
|
||||||
return result;
|
// return result;
|
||||||
}
|
// }
|
||||||
|
//
|
||||||
/* TODO: join has probs, since it dellocates memory
|
// /* TODO: join has probs, since it dellocates memory
|
||||||
* allocated (somewhere) with leak_detective :-(.
|
// * allocated (somewhere) with leak_detective :-(.
|
||||||
* We should exclude all pthread_ functions to fix it !?
|
// * We should exclude all pthread_ functions to fix it !? */
|
||||||
int pthread_join(pthread_t __th, void **__thread_return)
|
// int pthread_join(pthread_t __th, void **__thread_return)
|
||||||
{
|
// {
|
||||||
int (*_pthread_join) (pthread_t, void **) = excluded_functions[PTHREAD_JOIN].lib_function;
|
// int (*_pthread_join) (pthread_t, void **) = excluded_functions[PTHREAD_JOIN].lib_function;
|
||||||
int result;
|
// int result;
|
||||||
|
//
|
||||||
pthread_mutex_lock(&mutex);
|
// pthread_mutex_lock(&mutex);
|
||||||
uninstall_hooks();
|
// uninstall_hooks();
|
||||||
|
//
|
||||||
result = _pthread_join(__th, __thread_return);
|
// result = _pthread_join(__th, __thread_return);
|
||||||
|
//
|
||||||
install_hooks();
|
// install_hooks();
|
||||||
pthread_mutex_unlock(&mutex);
|
// pthread_mutex_unlock(&mutex);
|
||||||
return result;
|
// return result;
|
||||||
}
|
// }
|
||||||
|
//
|
||||||
void _pthread_cleanup_push (struct _pthread_cleanup_buffer *__buffer,
|
// void _pthread_cleanup_push (struct _pthread_cleanup_buffer *__buffer,
|
||||||
void (*__routine) (void *),
|
// void (*__routine) (void *),
|
||||||
void *__arg)
|
// void *__arg)
|
||||||
{
|
// {
|
||||||
int (*__pthread_cleanup_push) (struct _pthread_cleanup_buffer *__buffer,
|
// int (*__pthread_cleanup_push) (struct _pthread_cleanup_buffer *__buffer,
|
||||||
void (*__routine) (void *),
|
// void (*__routine) (void *),
|
||||||
void *__arg) =
|
// void *__arg) =
|
||||||
excluded_functions[PTHREAD_CLEANUP_PUSH].lib_function;
|
// excluded_functions[PTHREAD_CLEANUP_PUSH].lib_function;
|
||||||
|
//
|
||||||
pthread_mutex_lock(&mutex);
|
// pthread_mutex_lock(&mutex);
|
||||||
uninstall_hooks();
|
// uninstall_hooks();
|
||||||
|
//
|
||||||
__pthread_cleanup_push(__buffer, __routine, __arg);
|
// __pthread_cleanup_push(__buffer, __routine, __arg);
|
||||||
|
//
|
||||||
install_hooks();
|
// install_hooks();
|
||||||
pthread_mutex_unlock(&mutex);
|
// pthread_mutex_unlock(&mutex);
|
||||||
return;
|
// return;
|
||||||
}
|
// }
|
||||||
|
//
|
||||||
void _pthread_cleanup_pop (struct _pthread_cleanup_buffer *__buffer, int __execute)
|
// void _pthread_cleanup_pop (struct _pthread_cleanup_buffer *__buffer, int __execute)
|
||||||
{
|
// {
|
||||||
int (*__pthread_cleanup_pop) (struct _pthread_cleanup_buffer *__buffer, int __execute) =
|
// int (*__pthread_cleanup_pop) (struct _pthread_cleanup_buffer *__buffer, int __execute) =
|
||||||
excluded_functions[PTHREAD_CLEANUP_POP].lib_function;
|
// excluded_functions[PTHREAD_CLEANUP_POP].lib_function;
|
||||||
|
//
|
||||||
pthread_mutex_lock(&mutex);
|
// pthread_mutex_lock(&mutex);
|
||||||
uninstall_hooks();
|
// uninstall_hooks();
|
||||||
|
//
|
||||||
__pthread_cleanup_pop(__buffer, __execute);
|
// __pthread_cleanup_pop(__buffer, __execute);
|
||||||
|
//
|
||||||
install_hooks();
|
// install_hooks();
|
||||||
pthread_mutex_unlock(&mutex);
|
// pthread_mutex_unlock(&mutex);
|
||||||
return;
|
// return;
|
||||||
}*/
|
// }
|
||||||
|
|
||||||
time_t mktime(struct tm *tm)
|
time_t mktime(struct tm *tm)
|
||||||
{
|
{
|
||||||
@@ -518,4 +520,21 @@ void vsyslog (int __pri, __const char *__fmt, __gnuc_va_list __ap)
|
|||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
char *strerror(int errnum)
|
||||||
|
{
|
||||||
|
char* (*_strerror) (int) = excluded_functions[STRERROR].lib_function;
|
||||||
|
char *result;
|
||||||
|
|
||||||
|
pthread_mutex_lock(&mutex);
|
||||||
|
uninstall_hooks();
|
||||||
|
|
||||||
|
result = _strerror(errnum);
|
||||||
|
|
||||||
|
install_hooks();
|
||||||
|
pthread_mutex_unlock(&mutex);
|
||||||
|
return result;
|
||||||
|
}
|
||||||
|
|
||||||
#endif /* LEAK_DETECTION */
|
#endif /* LEAK_DETECTION */
|
||||||
|
|||||||
@@ -65,13 +65,13 @@ diff -Naur strongswan-2.6.4/programs/ipsec/ipsec.in strongswan-2.6.4-charon/prog
|
|||||||
$IPSEC_EXECDIR/whack "--$op"
|
$IPSEC_EXECDIR/whack "--$op"
|
||||||
+ if test -e $IPSEC_EXECDIR/stroke
|
+ if test -e $IPSEC_EXECDIR/stroke
|
||||||
+ then
|
+ then
|
||||||
+ $IPSEC_EXECDIR/stroke status
|
+ $IPSEC_EXECDIR/stroke "$op"
|
||||||
+ fi
|
+ fi
|
||||||
else
|
else
|
||||||
$IPSEC_EXECDIR/whack --name "$1" "--$op"
|
$IPSEC_EXECDIR/whack --name "$1" "--$op"
|
||||||
+ if test -e $IPSEC_EXECDIR/stroke
|
+ if test -e $IPSEC_EXECDIR/stroke
|
||||||
+ then
|
+ then
|
||||||
+ $IPSEC_EXECDIR/stroke status
|
+ $IPSEC_EXECDIR/stroke "$op" "$1"
|
||||||
+ fi
|
+ fi
|
||||||
fi
|
fi
|
||||||
exit 0
|
exit 0
|
||||||
|
|||||||
+11
-3
@@ -146,13 +146,21 @@ static int terminate_connection(char *name)
|
|||||||
return res;
|
return res;
|
||||||
}
|
}
|
||||||
|
|
||||||
static int show_status()
|
static int show_status(char *mode, char *connection)
|
||||||
{
|
{
|
||||||
stroke_msg_t *msg = malloc(sizeof(stroke_msg_t));
|
stroke_msg_t *msg = malloc(sizeof(stroke_msg_t));
|
||||||
int res;
|
int res;
|
||||||
|
|
||||||
msg->length = sizeof(stroke_msg_t);
|
msg->length = sizeof(stroke_msg_t);
|
||||||
msg->type = STR_STATUS;
|
if (strcmp(mode, "statusall") == 0)
|
||||||
|
{
|
||||||
|
msg->type = STR_STATUS_ALL;
|
||||||
|
}
|
||||||
|
else
|
||||||
|
{
|
||||||
|
msg->type = STR_STATUS;
|
||||||
|
}
|
||||||
|
msg->status.name = push_string(&msg, connection);
|
||||||
res = send_stroke_msg(msg);
|
res = send_stroke_msg(msg);
|
||||||
free(msg);
|
free(msg);
|
||||||
return res;
|
return res;
|
||||||
@@ -240,7 +248,7 @@ int main(int argc, char *argv[])
|
|||||||
if (strcmp(argv[1], "status") == 0 ||
|
if (strcmp(argv[1], "status") == 0 ||
|
||||||
strcmp(argv[1], "statusall") == 0)
|
strcmp(argv[1], "statusall") == 0)
|
||||||
{
|
{
|
||||||
res = show_status();
|
res = show_status(argv[1], argc > 2 ? argv[2] : NULL);
|
||||||
}
|
}
|
||||||
|
|
||||||
else if (strcmp(argv[1], "up") == 0)
|
else if (strcmp(argv[1], "up") == 0)
|
||||||
|
|||||||
@@ -51,6 +51,8 @@ struct stroke_msg_t {
|
|||||||
STR_TERMINATE,
|
STR_TERMINATE,
|
||||||
/* show connection status */
|
/* show connection status */
|
||||||
STR_STATUS,
|
STR_STATUS,
|
||||||
|
/* show verbose connection status */
|
||||||
|
STR_STATUS_ALL,
|
||||||
/* set a log type to log/not log */
|
/* set a log type to log/not log */
|
||||||
STR_LOGTYPE,
|
STR_LOGTYPE,
|
||||||
/* set the verbosity of a logging context */
|
/* set the verbosity of a logging context */
|
||||||
@@ -61,7 +63,7 @@ struct stroke_msg_t {
|
|||||||
/* data for STR_INITIATE, STR_INSTALL, STR_UP, STR_DOWN */
|
/* data for STR_INITIATE, STR_INSTALL, STR_UP, STR_DOWN */
|
||||||
struct {
|
struct {
|
||||||
char *name;
|
char *name;
|
||||||
} initiate, install, terminate;
|
} initiate, install, terminate, status;
|
||||||
/* data for STR_ADD_CONN */
|
/* data for STR_ADD_CONN */
|
||||||
struct {
|
struct {
|
||||||
char *name;
|
char *name;
|
||||||
|
|||||||
@@ -86,10 +86,6 @@ TEST_OBJS+= $(BUILD_DIR)packet_test.o
|
|||||||
$(BUILD_DIR)packet_test.o : $(TESTCASES_DIR)packet_test.c $(TESTCASES_DIR)packet_test.h
|
$(BUILD_DIR)packet_test.o : $(TESTCASES_DIR)packet_test.c $(TESTCASES_DIR)packet_test.h
|
||||||
$(CC) $(CFLAGS) -c -o $@ $<
|
$(CC) $(CFLAGS) -c -o $@ $<
|
||||||
|
|
||||||
TEST_OBJS+= $(BUILD_DIR)receiver_test.o
|
|
||||||
$(BUILD_DIR)receiver_test.o : $(TESTCASES_DIR)receiver_test.c $(TESTCASES_DIR)receiver_test.h
|
|
||||||
$(CC) $(CFLAGS) -c -o $@ $<
|
|
||||||
|
|
||||||
TEST_OBJS+= $(BUILD_DIR)ike_sa_test.o
|
TEST_OBJS+= $(BUILD_DIR)ike_sa_test.o
|
||||||
$(BUILD_DIR)ike_sa_test.o : $(TESTCASES_DIR)ike_sa_test.c $(TESTCASES_DIR)ike_sa_test.h
|
$(BUILD_DIR)ike_sa_test.o : $(TESTCASES_DIR)ike_sa_test.c $(TESTCASES_DIR)ike_sa_test.h
|
||||||
$(CC) $(CFLAGS) -c -o $@ $<
|
$(CC) $(CFLAGS) -c -o $@ $<
|
||||||
|
|||||||
@@ -1,89 +0,0 @@
|
|||||||
/**
|
|
||||||
* @file receiver_test.c
|
|
||||||
*
|
|
||||||
* @brief Tests for the receiver_t class.
|
|
||||||
*
|
|
||||||
*/
|
|
||||||
|
|
||||||
/*
|
|
||||||
* Copyright (C) 2005 Jan Hutter, Martin Willi
|
|
||||||
* Hochschule fuer Technik Rapperswil
|
|
||||||
*
|
|
||||||
* This program is free software; you can redistribute it and/or modify it
|
|
||||||
* under the terms of the GNU General Public License as published by the
|
|
||||||
* Free Software Foundation; either version 2 of the License, or (at your
|
|
||||||
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
|
|
||||||
*
|
|
||||||
* This program is distributed in the hope that it will be useful, but
|
|
||||||
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
|
|
||||||
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
|
||||||
* for more details.
|
|
||||||
*/
|
|
||||||
|
|
||||||
#include <string.h>
|
|
||||||
#include <unistd.h>
|
|
||||||
|
|
||||||
#include "receiver_test.h"
|
|
||||||
|
|
||||||
#include <daemon.h>
|
|
||||||
#include <threads/receiver.h>
|
|
||||||
#include <network/packet.h>
|
|
||||||
#include <network/socket.h>
|
|
||||||
#include <queues/send_queue.h>
|
|
||||||
#include <queues/job_queue.h>
|
|
||||||
#include <queues/jobs/incoming_packet_job.h>
|
|
||||||
#include <encoding/payloads/encodings.h>
|
|
||||||
|
|
||||||
/**
|
|
||||||
* Number of packets to send by sender-thread
|
|
||||||
*/
|
|
||||||
#define NUMBER_OF_PACKETS_TO_SEND 100
|
|
||||||
|
|
||||||
/**
|
|
||||||
* Port to send the packets to
|
|
||||||
*/
|
|
||||||
#define PORT_TO_SEND 4600
|
|
||||||
|
|
||||||
/**
|
|
||||||
* Destination IP Address
|
|
||||||
*/
|
|
||||||
#define DESTINATION_IP "127.0.0.1"
|
|
||||||
|
|
||||||
void test_receiver(protected_tester_t *tester)
|
|
||||||
{
|
|
||||||
int i;
|
|
||||||
receiver_t *receiver;
|
|
||||||
packet_t *packet;
|
|
||||||
job_t *job;
|
|
||||||
packet_t *received_packet;
|
|
||||||
receiver = receiver_create();
|
|
||||||
chunk_t test_data;
|
|
||||||
|
|
||||||
for (i = 0; i < NUMBER_OF_PACKETS_TO_SEND; i++)
|
|
||||||
{
|
|
||||||
packet = packet_create();
|
|
||||||
packet->set_destination(packet, host_create(AF_INET,DESTINATION_IP,PORT_TO_SEND));
|
|
||||||
test_data.len = (sizeof(int));
|
|
||||||
test_data.ptr = malloc(test_data.len);
|
|
||||||
*((int *) (test_data.ptr)) = i;
|
|
||||||
packet->set_data(packet, test_data);
|
|
||||||
charon->socket->send(charon->socket, packet);
|
|
||||||
packet->destroy(packet);
|
|
||||||
}
|
|
||||||
|
|
||||||
for (i = 0; i < NUMBER_OF_PACKETS_TO_SEND; i++)
|
|
||||||
{
|
|
||||||
job = charon->job_queue->get(charon->job_queue);
|
|
||||||
tester->assert_true(tester, (job->get_type(job) == INCOMING_PACKET), "job type check");
|
|
||||||
|
|
||||||
received_packet = ((incoming_packet_job_t *)(job))->get_packet((incoming_packet_job_t *)(job));
|
|
||||||
test_data = received_packet->get_data(received_packet);
|
|
||||||
tester->assert_true(tester, (test_data.len == (sizeof(int))), "received data length check");
|
|
||||||
tester->assert_true(tester, (i == *((int *)(test_data.ptr))), "received data value check");
|
|
||||||
received_packet->destroy(received_packet);
|
|
||||||
|
|
||||||
job->destroy(job);
|
|
||||||
}
|
|
||||||
|
|
||||||
receiver->destroy(receiver);
|
|
||||||
}
|
|
||||||
@@ -1,37 +0,0 @@
|
|||||||
/**
|
|
||||||
* @file receiver_test.h
|
|
||||||
*
|
|
||||||
* @brief Tests for the receiver_t class.
|
|
||||||
*
|
|
||||||
*/
|
|
||||||
|
|
||||||
/*
|
|
||||||
* Copyright (C) 2005 Jan Hutter, Martin Willi
|
|
||||||
* Hochschule fuer Technik Rapperswil
|
|
||||||
*
|
|
||||||
* This program is free software; you can redistribute it and/or modify it
|
|
||||||
* under the terms of the GNU General Public License as published by the
|
|
||||||
* Free Software Foundation; either version 2 of the License, or (at your
|
|
||||||
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
|
|
||||||
*
|
|
||||||
* This program is distributed in the hope that it will be useful, but
|
|
||||||
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
|
|
||||||
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
|
||||||
* for more details.
|
|
||||||
*/
|
|
||||||
|
|
||||||
#ifndef RECEIVER_TEST_H_
|
|
||||||
#define RECEIVER_TEST_H_
|
|
||||||
|
|
||||||
#include <utils/tester.h>
|
|
||||||
|
|
||||||
/**
|
|
||||||
* @brief Test function for the type receiver_t.
|
|
||||||
*
|
|
||||||
* @param tester tester object
|
|
||||||
*
|
|
||||||
* @ingroup testcases
|
|
||||||
*/
|
|
||||||
void test_receiver(protected_tester_t *tester);
|
|
||||||
|
|
||||||
#endif /*RECEIVER_TEST_H_*/
|
|
||||||
@@ -30,50 +30,59 @@
|
|||||||
#include <network/socket.h>
|
#include <network/socket.h>
|
||||||
#include <queues/send_queue.h>
|
#include <queues/send_queue.h>
|
||||||
#include <queues/job_queue.h>
|
#include <queues/job_queue.h>
|
||||||
|
#include <queues/jobs/incoming_packet_job.h>
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Number of packets to send by sender-thread
|
* Number of packets to send by sender-thread
|
||||||
*/
|
*/
|
||||||
#define NUMBER_OF_PACKETS_TO_SEND 50
|
#define NUMBER_OF_PACKETS_TO_SEND 5
|
||||||
|
|
||||||
/**
|
|
||||||
* Port to send the packets to
|
|
||||||
*/
|
|
||||||
#define PORT_TO_SEND 4600
|
|
||||||
|
|
||||||
/**
|
|
||||||
* Destination IP Address
|
|
||||||
*/
|
|
||||||
#define DESTINATION_IP "127.0.0.1"
|
|
||||||
|
|
||||||
void test_sender(protected_tester_t *tester)
|
void test_sender(protected_tester_t *tester)
|
||||||
{
|
{
|
||||||
int i;
|
int i;
|
||||||
sender_t *sender;
|
sender_t *sender;
|
||||||
|
receiver_t *receiver;
|
||||||
|
job_t *job;
|
||||||
packet_t *packet;
|
packet_t *packet;
|
||||||
packet_t *received_packet;
|
packet_t *received_packet;
|
||||||
chunk_t packet_data;
|
char test_data[] = {
|
||||||
|
0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x03, /* spi */
|
||||||
|
0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x05, /* spi */
|
||||||
|
0x05, /* next payload */
|
||||||
|
0x20, /* IKE version */
|
||||||
|
0x00, /* exchange type */
|
||||||
|
0x00, /* flags */
|
||||||
|
0x00,0x00,0x00,0x01, /* message id */
|
||||||
|
0x00,0x00,0x00,0x24, /* length */
|
||||||
|
0x12,0x34,0x56,0x67, /* some data */
|
||||||
|
0x12,0x34,0x56,0x67,
|
||||||
|
};
|
||||||
|
chunk_t data = chunk_from_buf(test_data);
|
||||||
|
chunk_t received;
|
||||||
sender = sender_create();
|
sender = sender_create();
|
||||||
|
receiver = receiver_create();
|
||||||
|
|
||||||
for (i = 0; i < NUMBER_OF_PACKETS_TO_SEND; i++)
|
for (i = 0; i < NUMBER_OF_PACKETS_TO_SEND; i++)
|
||||||
{
|
{
|
||||||
packet = packet_create(AF_INET);
|
packet = packet_create(AF_INET);
|
||||||
packet->set_destination(packet, host_create(AF_INET,DESTINATION_IP,PORT_TO_SEND));
|
packet->set_destination(packet, host_create(AF_INET, "127.0.0.1", 500));
|
||||||
packet_data.len = ( sizeof(int));
|
packet->set_source(packet, host_create(AF_INET, "127.0.0.1", 500));
|
||||||
packet_data.ptr = malloc(packet_data.len);
|
packet->set_data(packet, chunk_clone(data));
|
||||||
*((int *) (packet_data.ptr)) = i;
|
|
||||||
packet->set_data(packet, packet_data);
|
|
||||||
charon->send_queue->add(charon->send_queue,packet);
|
charon->send_queue->add(charon->send_queue,packet);
|
||||||
}
|
}
|
||||||
|
|
||||||
for (i = 0; i < NUMBER_OF_PACKETS_TO_SEND; i++)
|
for (i = 0; i < NUMBER_OF_PACKETS_TO_SEND; i++)
|
||||||
{
|
{
|
||||||
charon->socket->receive(charon->socket,&received_packet);
|
job = charon->job_queue->get(charon->job_queue);
|
||||||
packet_data = received_packet->get_data(received_packet);
|
tester->assert_true(tester, (job->get_type(job) == INCOMING_PACKET), "job type check");
|
||||||
tester->assert_true(tester, (packet_data.len == (sizeof(int))), "received data length check");
|
received_packet = ((incoming_packet_job_t *)(job))->get_packet((incoming_packet_job_t *)(job));
|
||||||
tester->assert_true(tester, (i == *((int *)(packet_data.ptr))), "received data value check");
|
received = received_packet->get_data(received_packet);
|
||||||
|
tester->assert_true(tester, received.len == data.len, "received data length check");
|
||||||
|
tester->assert_true(tester, memcmp(received.ptr, data.ptr, data.len) == 0, "received data value check");
|
||||||
received_packet->destroy(received_packet);
|
received_packet->destroy(received_packet);
|
||||||
|
job->destroy(job);
|
||||||
}
|
}
|
||||||
|
|
||||||
sender->destroy(sender);
|
sender->destroy(sender);
|
||||||
|
receiver->destroy(receiver);
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -26,31 +26,40 @@
|
|||||||
#include "socket_test.h"
|
#include "socket_test.h"
|
||||||
|
|
||||||
#include <network/socket.h>
|
#include <network/socket.h>
|
||||||
|
#include <utils/logger.h>
|
||||||
|
|
||||||
/*
|
/*
|
||||||
* Description in header file
|
* Description in header file
|
||||||
*/
|
*/
|
||||||
void test_socket(protected_tester_t *tester)
|
void test_socket(protected_tester_t *tester)
|
||||||
{
|
{
|
||||||
int packet_count = 5;
|
int packet_count = 10;
|
||||||
int current;
|
int current;
|
||||||
socket_t *skt = socket_create(4500);
|
socket_t *skt = socket_create(500);
|
||||||
packet_t *pkt = packet_create(AF_INET);
|
packet_t *pkt = packet_create(AF_INET);
|
||||||
char *test_string = "Testing functionality of socket_t";
|
char test_data[] = {
|
||||||
chunk_t data;
|
0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x03, /* spi */
|
||||||
|
0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x05, /* spi */
|
||||||
|
0x05, /* next payload */
|
||||||
data.ptr = malloc(strlen(test_string) + 1);
|
0x20, /* IKE version */
|
||||||
memcpy(data.ptr,test_string,strlen(test_string) + 1);
|
0x00, /* exchange type */
|
||||||
data.len = strlen(test_string) + 1;
|
0x00, /* flags */
|
||||||
|
0x00,0x00,0x00,0x01, /* message id */
|
||||||
|
0x00,0x00,0x00,0x24, /* length */
|
||||||
|
0x12,0x34,0x56,0x67, /* some data */
|
||||||
|
0x12,0x34,0x56,0x67,
|
||||||
|
};
|
||||||
|
chunk_t data = chunk_from_buf(test_data);
|
||||||
|
chunk_t received;
|
||||||
|
|
||||||
/* send to previously bound socket */
|
/* send to previously bound socket */
|
||||||
pkt->set_destination(pkt, host_create(AF_INET, "127.0.0.1", 4500));
|
pkt->set_destination(pkt, host_create(AF_INET, "127.0.0.1", 500));
|
||||||
pkt->set_data(pkt, data);
|
pkt->set_source(pkt, host_create(AF_INET, "127.0.0.1", 500));
|
||||||
|
pkt->set_data(pkt, chunk_clone(data));
|
||||||
|
|
||||||
/* send packet_count packets */
|
/* send packet_count packets */
|
||||||
for (current = 0; current < packet_count; current++)
|
for (current = 0; current < packet_count; current++)
|
||||||
{
|
{
|
||||||
if (skt->send(skt, pkt) == FAILED)
|
if (skt->send(skt, pkt) == FAILED)
|
||||||
{
|
{
|
||||||
tester->assert_true(tester, 0, "packet send");
|
tester->assert_true(tester, 0, "packet send");
|
||||||
@@ -58,12 +67,13 @@ void test_socket(protected_tester_t *tester)
|
|||||||
}
|
}
|
||||||
pkt->destroy(pkt);
|
pkt->destroy(pkt);
|
||||||
|
|
||||||
|
|
||||||
/* receive packet_count packets */
|
/* receive packet_count packets */
|
||||||
for (current = 0; current < packet_count; current++)
|
for (current = 0; current < packet_count; current++)
|
||||||
{
|
{
|
||||||
skt->receive(skt, &pkt);
|
skt->receive(skt, &pkt);
|
||||||
data = pkt->get_data(pkt);
|
received = pkt->get_data(pkt);
|
||||||
tester->assert_false(tester, strcmp(test_string, data.ptr), "packet exchange");
|
tester->assert_false(tester, memcmp(received.ptr, data.ptr, max(received.len, data.len)), "packet exchange");
|
||||||
pkt->destroy(pkt);
|
pkt->destroy(pkt);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -41,7 +41,6 @@
|
|||||||
#include "socket_test.h"
|
#include "socket_test.h"
|
||||||
#include "sender_test.h"
|
#include "sender_test.h"
|
||||||
#include "scheduler_test.h"
|
#include "scheduler_test.h"
|
||||||
#include "receiver_test.h"
|
|
||||||
#include "ike_sa_id_test.h"
|
#include "ike_sa_id_test.h"
|
||||||
#include "ike_sa_test.h"
|
#include "ike_sa_test.h"
|
||||||
#include "ike_sa_manager_test.h"
|
#include "ike_sa_manager_test.h"
|
||||||
@@ -78,7 +77,6 @@ test_t socket_test = {test_socket,"Socket"};
|
|||||||
test_t thread_pool_test = {test_thread_pool,"Thread Pool"};
|
test_t thread_pool_test = {test_thread_pool,"Thread Pool"};
|
||||||
test_t sender_test = {test_sender,"Sender"};
|
test_t sender_test = {test_sender,"Sender"};
|
||||||
test_t scheduler_test = {test_scheduler,"Scheduler"};
|
test_t scheduler_test = {test_scheduler,"Scheduler"};
|
||||||
test_t receiver_test = {test_receiver,"Receiver"};
|
|
||||||
test_t ike_sa_id_test = {test_ike_sa_id,"IKE_SA-Identifier"};
|
test_t ike_sa_id_test = {test_ike_sa_id,"IKE_SA-Identifier"};
|
||||||
test_t ike_sa_test = {test_ike_sa,"IKE_SA"};
|
test_t ike_sa_test = {test_ike_sa,"IKE_SA"};
|
||||||
test_t ike_sa_manager_test = {test_ike_sa_manager, "IKE_SA-Manager"};
|
test_t ike_sa_manager_test = {test_ike_sa_manager, "IKE_SA-Manager"};
|
||||||
@@ -161,7 +159,7 @@ daemon_t *daemon_create()
|
|||||||
/* assign methods */
|
/* assign methods */
|
||||||
charon->kill = daemon_kill;
|
charon->kill = daemon_kill;
|
||||||
|
|
||||||
//charon->socket = socket_create(4510);
|
charon->socket = socket_create(500);
|
||||||
charon->ike_sa_manager = ike_sa_manager_create();
|
charon->ike_sa_manager = ike_sa_manager_create();
|
||||||
charon->job_queue = job_queue_create();
|
charon->job_queue = job_queue_create();
|
||||||
charon->event_queue = event_queue_create();
|
charon->event_queue = event_queue_create();
|
||||||
@@ -192,7 +190,6 @@ int main()
|
|||||||
&scheduler_test,
|
&scheduler_test,
|
||||||
&socket_test,
|
&socket_test,
|
||||||
&sender_test,
|
&sender_test,
|
||||||
&receiver_test,
|
|
||||||
&ike_sa_id_test,
|
&ike_sa_id_test,
|
||||||
&ike_sa_test,
|
&ike_sa_test,
|
||||||
&generator_test1,
|
&generator_test1,
|
||||||
@@ -254,8 +251,8 @@ int main()
|
|||||||
|
|
||||||
tester_t *tester = tester_create(test_output, FALSE);
|
tester_t *tester = tester_create(test_output, FALSE);
|
||||||
|
|
||||||
//tester->perform_tests(tester,all_tests);
|
tester->perform_tests(tester,all_tests);
|
||||||
tester->perform_test(tester,&certificate_test);
|
//tester->perform_test(tester,&sender_test);
|
||||||
|
|
||||||
|
|
||||||
tester->destroy(tester);
|
tester->destroy(tester);
|
||||||
|
|||||||
Reference in New Issue
Block a user