refactored TNC framework
This commit is contained in:
@@ -1,14 +1,20 @@
|
||||
|
||||
INCLUDES = -I$(top_srcdir)/src/libstrongswan -I$(top_srcdir)/src/libhydra \
|
||||
-I$(top_srcdir)/src/libcharon -I$(top_srcdir)/src/libtncif
|
||||
INCLUDES = \
|
||||
-I$(top_srcdir)/src/libstrongswan \
|
||||
-I$(top_srcdir)/src/libhydra \
|
||||
-I$(top_srcdir)/src/libcharon \
|
||||
-I$(top_srcdir)/src/libtncif \
|
||||
-I$(top_srcdir)/src/libtnccs
|
||||
|
||||
AM_CFLAGS = -DUSE_TNC -rdynamic
|
||||
AM_CFLAGS = -rdynamic
|
||||
|
||||
if MONOLITHIC
|
||||
noinst_LTLIBRARIES = libstrongswan-tnc-imv.la
|
||||
else
|
||||
plugin_LTLIBRARIES = libstrongswan-tnc-imv.la
|
||||
libstrongswan_tnc_imv_la_LIBADD = $(top_builddir)/src/libtncif/libtncif.la
|
||||
libstrongswan_tnc_imv_la_LIBADD = \
|
||||
$(top_builddir)/src/libtncif/libtncif.la \
|
||||
$(top_builddir)/src/libtnccs/libtnccs.la
|
||||
endif
|
||||
|
||||
libstrongswan_tnc_imv_la_SOURCES = \
|
||||
|
||||
@@ -13,10 +13,11 @@
|
||||
* for more details.
|
||||
*/
|
||||
|
||||
#include "tnc_imv.h"
|
||||
#include <tnc/tnc.h>
|
||||
#include <tnc/imv/imv_manager.h>
|
||||
#include <tnc/tnccs/tnccs_manager.h>
|
||||
|
||||
#include <debug.h>
|
||||
#include <daemon.h>
|
||||
|
||||
#define TNC_IMCID_ANY 0xffff
|
||||
|
||||
@@ -28,14 +29,14 @@ TNC_Result TNC_TNCS_ReportMessageTypes(TNC_IMVID imv_id,
|
||||
TNC_MessageTypeList supported_types,
|
||||
TNC_UInt32 type_count)
|
||||
{
|
||||
if (!charon->imvs->is_registered(charon->imvs, imv_id))
|
||||
if (!tnc->imvs->is_registered(tnc->imvs, imv_id))
|
||||
{
|
||||
DBG1(DBG_TNC, "ignoring ReportMessageTypes() from unregistered IMV %u",
|
||||
imv_id);
|
||||
return TNC_RESULT_INVALID_PARAMETER;
|
||||
}
|
||||
return charon->imvs->set_message_types(charon->imvs, imv_id,
|
||||
supported_types, type_count);
|
||||
return tnc->imvs->set_message_types(tnc->imvs, imv_id, supported_types,
|
||||
type_count);
|
||||
}
|
||||
|
||||
/**
|
||||
@@ -45,14 +46,14 @@ TNC_Result TNC_TNCS_RequestHandshakeRetry(TNC_IMVID imv_id,
|
||||
TNC_ConnectionID connection_id,
|
||||
TNC_RetryReason reason)
|
||||
{
|
||||
if (!charon->imvs->is_registered(charon->imvs, imv_id))
|
||||
if (!tnc->imvs->is_registered(tnc->imvs, imv_id))
|
||||
{
|
||||
DBG1(DBG_TNC, "ignoring RequestHandshakeRetry() from unregistered IMV %u",
|
||||
imv_id);
|
||||
return TNC_RESULT_INVALID_PARAMETER;
|
||||
}
|
||||
return charon->tnccs->request_handshake_retry(charon->tnccs, FALSE, imv_id,
|
||||
connection_id, reason);
|
||||
return tnc->tnccs->request_handshake_retry(tnc->tnccs, FALSE, imv_id,
|
||||
connection_id, reason);
|
||||
}
|
||||
|
||||
/**
|
||||
@@ -64,14 +65,14 @@ TNC_Result TNC_TNCS_SendMessage(TNC_IMVID imv_id,
|
||||
TNC_UInt32 msg_len,
|
||||
TNC_MessageType msg_type)
|
||||
{
|
||||
if (!charon->imvs->is_registered(charon->imvs, imv_id))
|
||||
if (!tnc->imvs->is_registered(tnc->imvs, imv_id))
|
||||
{
|
||||
DBG1(DBG_TNC, "ignoring SendMessage() from unregistered IMV %u",
|
||||
imv_id);
|
||||
return TNC_RESULT_INVALID_PARAMETER;
|
||||
}
|
||||
return charon->tnccs->send_message(charon->tnccs, TNC_IMCID_ANY, imv_id,
|
||||
connection_id, msg, msg_len, msg_type);
|
||||
return tnc->tnccs->send_message(tnc->tnccs, TNC_IMCID_ANY, imv_id,
|
||||
connection_id, msg, msg_len, msg_type);
|
||||
}
|
||||
|
||||
/**
|
||||
@@ -83,14 +84,14 @@ TNC_Result TNC_TNCS_ProvideRecommendation(TNC_IMVID imv_id,
|
||||
TNC_IMV_Action_Recommendation recommendation,
|
||||
TNC_IMV_Evaluation_Result evaluation)
|
||||
{
|
||||
if (!charon->imvs->is_registered(charon->imvs, imv_id))
|
||||
if (!tnc->imvs->is_registered(tnc->imvs, imv_id))
|
||||
{
|
||||
DBG1(DBG_TNC, "ignoring ProvideRecommendation() from unregistered IMV %u",
|
||||
imv_id);
|
||||
return TNC_RESULT_INVALID_PARAMETER;
|
||||
}
|
||||
return charon->tnccs->provide_recommendation(charon->tnccs, imv_id,
|
||||
connection_id, recommendation, evaluation);
|
||||
return tnc->tnccs->provide_recommendation(tnc->tnccs, imv_id, connection_id,
|
||||
recommendation, evaluation);
|
||||
}
|
||||
|
||||
/**
|
||||
@@ -104,13 +105,13 @@ TNC_Result TNC_TNCS_GetAttribute(TNC_IMVID imv_id,
|
||||
TNC_BufferReference buffer,
|
||||
TNC_UInt32 *out_value_len)
|
||||
{
|
||||
if (!charon->imvs->is_registered(charon->imvs, imv_id))
|
||||
if (!tnc->imvs->is_registered(tnc->imvs, imv_id))
|
||||
{
|
||||
DBG1(DBG_TNC, "ignoring GetAttribute() from unregistered IMV %u",
|
||||
imv_id);
|
||||
return TNC_RESULT_INVALID_PARAMETER;
|
||||
}
|
||||
return charon->tnccs->get_attribute(charon->tnccs, imv_id, connection_id,
|
||||
return tnc->tnccs->get_attribute(tnc->tnccs, imv_id, connection_id,
|
||||
attribute_id, buffer_len, buffer, out_value_len);
|
||||
}
|
||||
|
||||
@@ -124,14 +125,14 @@ TNC_Result TNC_TNCS_SetAttribute(TNC_IMVID imv_id,
|
||||
TNC_UInt32 buffer_len,
|
||||
TNC_BufferReference buffer)
|
||||
{
|
||||
if (!charon->imvs->is_registered(charon->imvs, imv_id))
|
||||
if (!tnc->imvs->is_registered(tnc->imvs, imv_id))
|
||||
{
|
||||
DBG1(DBG_TNC, "ignoring SetAttribute() from unregistered IMV %u",
|
||||
imv_id);
|
||||
return TNC_RESULT_INVALID_PARAMETER;
|
||||
}
|
||||
return charon->tnccs->set_attribute(charon->tnccs, imv_id, connection_id,
|
||||
attribute_id, buffer_len, buffer);
|
||||
return tnc->tnccs->set_attribute(tnc->tnccs, imv_id, connection_id,
|
||||
attribute_id, buffer_len, buffer);
|
||||
}
|
||||
|
||||
/**
|
||||
|
||||
@@ -14,15 +14,22 @@
|
||||
*/
|
||||
|
||||
#include "tnc_imv_manager.h"
|
||||
#include "tnc_imv.h"
|
||||
#include "tnc_imv_recommendations.h"
|
||||
|
||||
#include <tnc/imv/imv_manager.h>
|
||||
|
||||
#include <tncifimv.h>
|
||||
#include <tncif_names.h>
|
||||
|
||||
#include <debug.h>
|
||||
#include <sys/types.h>
|
||||
#include <sys/stat.h>
|
||||
#include <sys/mman.h>
|
||||
#include <unistd.h>
|
||||
#include <errno.h>
|
||||
#include <fcntl.h>
|
||||
|
||||
#include <daemon.h>
|
||||
#include <utils/lexparser.h>
|
||||
#include <debug.h>
|
||||
#include <threading/mutex.h>
|
||||
|
||||
typedef struct private_tnc_imv_manager_t private_tnc_imv_manager_t;
|
||||
@@ -103,6 +110,124 @@ METHOD(imv_manager_t, remove_, imv_t*,
|
||||
return removed_imv;
|
||||
}
|
||||
|
||||
METHOD(imv_manager_t, load_all, bool,
|
||||
private_tnc_imv_manager_t *this, char *filename)
|
||||
{
|
||||
int fd, line_nr = 0;
|
||||
chunk_t src, line;
|
||||
struct stat sb;
|
||||
void *addr;
|
||||
|
||||
DBG1(DBG_TNC, "loading IMVs from '%s'", filename);
|
||||
fd = open(filename, O_RDONLY);
|
||||
if (fd == -1)
|
||||
{
|
||||
DBG1(DBG_TNC, "opening configuration file '%s' failed: %s", filename,
|
||||
strerror(errno));
|
||||
return FALSE;
|
||||
}
|
||||
if (fstat(fd, &sb) == -1)
|
||||
{
|
||||
DBG1(DBG_LIB, "getting file size of '%s' failed: %s", filename,
|
||||
strerror(errno));
|
||||
close(fd);
|
||||
return FALSE;
|
||||
}
|
||||
addr = mmap(NULL, sb.st_size, PROT_READ | PROT_WRITE, MAP_PRIVATE, fd, 0);
|
||||
if (addr == MAP_FAILED)
|
||||
{
|
||||
DBG1(DBG_LIB, "mapping '%s' failed: %s", filename, strerror(errno));
|
||||
close(fd);
|
||||
return FALSE;
|
||||
}
|
||||
src = chunk_create(addr, sb.st_size);
|
||||
|
||||
while (fetchline(&src, &line))
|
||||
{
|
||||
char *name, *path;
|
||||
chunk_t token;
|
||||
imv_t *imv;
|
||||
|
||||
line_nr++;
|
||||
|
||||
/* skip comments or empty lines */
|
||||
if (*line.ptr == '#' || !eat_whitespace(&line))
|
||||
{
|
||||
continue;
|
||||
}
|
||||
|
||||
/* determine keyword */
|
||||
if (!extract_token(&token, ' ', &line))
|
||||
{
|
||||
DBG1(DBG_TNC, "line %d: keyword must be followed by a space",
|
||||
line_nr);
|
||||
return FALSE;
|
||||
}
|
||||
|
||||
/* only interested in IMVs */
|
||||
if (!match("IMV", &token))
|
||||
{
|
||||
continue;
|
||||
}
|
||||
|
||||
/* advance to the IMV name and extract it */
|
||||
if (!extract_token(&token, '"', &line) ||
|
||||
!extract_token(&token, '"', &line))
|
||||
{
|
||||
DBG1(DBG_TNC, "line %d: IMV name must be set in double quotes",
|
||||
line_nr);
|
||||
return FALSE;
|
||||
}
|
||||
|
||||
/* copy the IMV name */
|
||||
name = malloc(token.len + 1);
|
||||
memcpy(name, token.ptr, token.len);
|
||||
name[token.len] = '\0';
|
||||
|
||||
/* advance to the IMV path and extract it */
|
||||
if (!eat_whitespace(&line))
|
||||
{
|
||||
DBG1(DBG_TNC, "line %d: IMV path is missing", line_nr);
|
||||
free(name);
|
||||
return FALSE;
|
||||
}
|
||||
if (!extract_token(&token, ' ', &line))
|
||||
{
|
||||
token = line;
|
||||
}
|
||||
|
||||
/* copy the IMV path */
|
||||
path = malloc(token.len + 1);
|
||||
memcpy(path, token.ptr, token.len);
|
||||
path[token.len] = '\0';
|
||||
|
||||
/* load and register IMV instance */
|
||||
imv = tnc_imv_create(name, path);
|
||||
if (!imv)
|
||||
{
|
||||
free(name);
|
||||
free(path);
|
||||
return FALSE;
|
||||
}
|
||||
if (!add(this, imv))
|
||||
{
|
||||
if (imv->terminate &&
|
||||
imv->terminate(imv->get_id(imv)) != TNC_RESULT_SUCCESS)
|
||||
{
|
||||
DBG1(DBG_TNC, "IMV \"%s\" not terminated successfully",
|
||||
imv->get_name(imv));
|
||||
}
|
||||
imv->destroy(imv);
|
||||
return FALSE;
|
||||
}
|
||||
DBG1(DBG_TNC, "IMV %u \"%s\" loaded from '%s'", imv->get_id(imv),
|
||||
name, path);
|
||||
}
|
||||
munmap(addr, sb.st_size);
|
||||
close(fd);
|
||||
return TRUE;
|
||||
}
|
||||
|
||||
METHOD(imv_manager_t, is_registered, bool,
|
||||
private_tnc_imv_manager_t *this, TNC_IMVID id)
|
||||
{
|
||||
@@ -291,6 +416,7 @@ METHOD(imv_manager_t, batch_ending, void,
|
||||
enumerator->destroy(enumerator);
|
||||
}
|
||||
|
||||
|
||||
METHOD(imv_manager_t, destroy, void,
|
||||
private_tnc_imv_manager_t *this)
|
||||
{
|
||||
@@ -322,6 +448,7 @@ imv_manager_t* tnc_imv_manager_create(void)
|
||||
.public = {
|
||||
.add = _add,
|
||||
.remove = _remove_, /* avoid name conflict with stdio.h */
|
||||
.load_all = _load_all,
|
||||
.is_registered = _is_registered,
|
||||
.get_recommendation_policy = _get_recommendation_policy,
|
||||
.create_recommendations = _create_recommendations,
|
||||
@@ -336,6 +463,7 @@ imv_manager_t* tnc_imv_manager_create(void)
|
||||
.imvs = linked_list_create(),
|
||||
.next_imv_id = 1,
|
||||
);
|
||||
|
||||
policy = enum_from_name(recommendation_policy_names,
|
||||
lib->settings->get_str(lib->settings,
|
||||
"charon.plugins.tnc-imv.recommendation_policy", "default"));
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright (C) 2010 Andreas Steffen
|
||||
* Copyright (C) 2010-2011 Andreas Steffen
|
||||
* HSR Hochschule fuer Technik Rapperswil
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify it
|
||||
@@ -15,17 +15,9 @@
|
||||
|
||||
#include "tnc_imv_plugin.h"
|
||||
#include "tnc_imv_manager.h"
|
||||
#include "tnc_imv.h"
|
||||
|
||||
#include <sys/types.h>
|
||||
#include <sys/stat.h>
|
||||
#include <sys/mman.h>
|
||||
#include <unistd.h>
|
||||
#include <errno.h>
|
||||
#include <fcntl.h>
|
||||
#include <tnc/tnc.h>
|
||||
|
||||
#include <utils/lexparser.h>
|
||||
#include <debug.h>
|
||||
|
||||
typedef struct private_tnc_imv_plugin_t private_tnc_imv_plugin_t;
|
||||
|
||||
@@ -39,131 +31,8 @@ struct private_tnc_imv_plugin_t {
|
||||
*/
|
||||
tnc_imv_plugin_t public;
|
||||
|
||||
/**
|
||||
* TNC IMV manager controlling Integrity Measurement Verifiers
|
||||
*/
|
||||
imv_manager_t *imvs;
|
||||
};
|
||||
|
||||
/**
|
||||
* load IMVs from a configuration file
|
||||
*/
|
||||
static bool load_imvs(private_tnc_imv_plugin_t *this, char *filename)
|
||||
{
|
||||
int fd, line_nr = 0;
|
||||
chunk_t src, line;
|
||||
struct stat sb;
|
||||
void *addr;
|
||||
|
||||
DBG1(DBG_TNC, "loading IMVs from '%s'", filename);
|
||||
fd = open(filename, O_RDONLY);
|
||||
if (fd == -1)
|
||||
{
|
||||
DBG1(DBG_TNC, "opening configuration file '%s' failed: %s", filename,
|
||||
strerror(errno));
|
||||
return FALSE;
|
||||
}
|
||||
if (fstat(fd, &sb) == -1)
|
||||
{
|
||||
DBG1(DBG_LIB, "getting file size of '%s' failed: %s", filename,
|
||||
strerror(errno));
|
||||
close(fd);
|
||||
return FALSE;
|
||||
}
|
||||
addr = mmap(NULL, sb.st_size, PROT_READ | PROT_WRITE, MAP_PRIVATE, fd, 0);
|
||||
if (addr == MAP_FAILED)
|
||||
{
|
||||
DBG1(DBG_LIB, "mapping '%s' failed: %s", filename, strerror(errno));
|
||||
close(fd);
|
||||
return FALSE;
|
||||
}
|
||||
src = chunk_create(addr, sb.st_size);
|
||||
|
||||
while (fetchline(&src, &line))
|
||||
{
|
||||
char *name, *path;
|
||||
chunk_t token;
|
||||
imv_t *imv;
|
||||
|
||||
line_nr++;
|
||||
|
||||
/* skip comments or empty lines */
|
||||
if (*line.ptr == '#' || !eat_whitespace(&line))
|
||||
{
|
||||
continue;
|
||||
}
|
||||
|
||||
/* determine keyword */
|
||||
if (!extract_token(&token, ' ', &line))
|
||||
{
|
||||
DBG1(DBG_TNC, "line %d: keyword must be followed by a space",
|
||||
line_nr);
|
||||
return FALSE;
|
||||
}
|
||||
|
||||
/* only interested in IMVs */
|
||||
if (!match("IMV", &token))
|
||||
{
|
||||
continue;
|
||||
}
|
||||
|
||||
/* advance to the IMV name and extract it */
|
||||
if (!extract_token(&token, '"', &line) ||
|
||||
!extract_token(&token, '"', &line))
|
||||
{
|
||||
DBG1(DBG_TNC, "line %d: IMV name must be set in double quotes",
|
||||
line_nr);
|
||||
return FALSE;
|
||||
}
|
||||
|
||||
/* copy the IMV name */
|
||||
name = malloc(token.len + 1);
|
||||
memcpy(name, token.ptr, token.len);
|
||||
name[token.len] = '\0';
|
||||
|
||||
/* advance to the IMV path and extract it */
|
||||
if (!eat_whitespace(&line))
|
||||
{
|
||||
DBG1(DBG_TNC, "line %d: IMV path is missing", line_nr);
|
||||
free(name);
|
||||
return FALSE;
|
||||
}
|
||||
if (!extract_token(&token, ' ', &line))
|
||||
{
|
||||
token = line;
|
||||
}
|
||||
|
||||
/* copy the IMV path */
|
||||
path = malloc(token.len + 1);
|
||||
memcpy(path, token.ptr, token.len);
|
||||
path[token.len] = '\0';
|
||||
|
||||
/* load and register IMV instance */
|
||||
imv = tnc_imv_create(name, path);
|
||||
if (!imv)
|
||||
{
|
||||
free(name);
|
||||
free(path);
|
||||
return FALSE;
|
||||
}
|
||||
if (!this->imvs->add(this->imvs, imv))
|
||||
{
|
||||
if (imv->terminate &&
|
||||
imv->terminate(imv->get_id(imv)) != TNC_RESULT_SUCCESS)
|
||||
{
|
||||
DBG1(DBG_TNC, "IMV \"%s\" not terminated successfully",
|
||||
imv->get_name(imv));
|
||||
}
|
||||
imv->destroy(imv);
|
||||
return FALSE;
|
||||
}
|
||||
DBG1(DBG_TNC, "IMV %u \"%s\" loaded from '%s'", imv->get_id(imv),
|
||||
name, path);
|
||||
}
|
||||
munmap(addr, sb.st_size);
|
||||
close(fd);
|
||||
return TRUE;
|
||||
}
|
||||
|
||||
METHOD(plugin_t, get_name, char*,
|
||||
tnc_imv_plugin_t *this)
|
||||
@@ -175,17 +44,17 @@ METHOD(plugin_t, get_features, int,
|
||||
private_tnc_imv_plugin_t *this, plugin_feature_t *features[])
|
||||
{
|
||||
static plugin_feature_t f[] = {
|
||||
PLUGIN_PROVIDE(CUSTOM, "imv-manager"),
|
||||
PLUGIN_CALLBACK(tnc_manager_register, tnc_imv_manager_create),
|
||||
PLUGIN_PROVIDE(CUSTOM, "imv-manager"),
|
||||
PLUGIN_DEPENDS(CUSTOM, "tnccs-manager"),
|
||||
};
|
||||
*features = f;
|
||||
return countof(f);
|
||||
}
|
||||
|
||||
METHOD(plugin_t, destroy, void,
|
||||
tnc_imv_plugin_t *this)
|
||||
private_tnc_imv_plugin_t *this)
|
||||
{
|
||||
lib->set(lib, "imv-manager", NULL);
|
||||
this->imvs->destroy(this->imvs);
|
||||
free(this);
|
||||
}
|
||||
|
||||
@@ -194,8 +63,7 @@ METHOD(plugin_t, destroy, void,
|
||||
*/
|
||||
plugin_t *tnc_imv_plugin_create()
|
||||
{
|
||||
char *tnc_config;
|
||||
tnc_imv_plugin_t *this;
|
||||
private_tnc_imv_plugin_t *this;
|
||||
|
||||
INIT(this,
|
||||
.public = {
|
||||
@@ -205,19 +73,8 @@ plugin_t *tnc_imv_plugin_create()
|
||||
.destroy = _destroy,
|
||||
},
|
||||
},
|
||||
.imvs = tnc_imv_manager_create(),
|
||||
);
|
||||
|
||||
lib->set(lib, "imv-manager", this->imvs);
|
||||
|
||||
/* Load IMVs and abort if not all instances initalize successfully */
|
||||
tnc_config = lib->settings->get_str(lib->settings,
|
||||
"charon.plugins.tnc-imv.tnc_config", "/etc/tnc_config");
|
||||
if (!load_imvs(this, tnc_config))
|
||||
{
|
||||
destroy(this);
|
||||
return NULL;
|
||||
}
|
||||
return &this->public.plugin;
|
||||
}
|
||||
|
||||
|
||||
@@ -12,15 +12,17 @@
|
||||
* for more details.
|
||||
*/
|
||||
|
||||
#include <debug.h>
|
||||
#include <daemon.h>
|
||||
|
||||
#include <tncifimv.h>
|
||||
#include <tncif_names.h>
|
||||
|
||||
#include <tnc/tnc.h>
|
||||
#include <tnc/imv/imv.h>
|
||||
#include <tnc/imv/imv_manager.h>
|
||||
#include <tnc/imv/imv_recommendations.h>
|
||||
|
||||
#include <debug.h>
|
||||
#include <utils/linked_list.h>
|
||||
|
||||
typedef struct private_tnc_imv_recommendations_t private_tnc_imv_recommendations_t;
|
||||
typedef struct recommendation_entry_t recommendation_entry_t;
|
||||
|
||||
@@ -129,7 +131,7 @@ METHOD(recommendations_t, have_recommendation, bool,
|
||||
DBG1(DBG_TNC, "there are no IMVs to make a recommendation");
|
||||
return TRUE;
|
||||
}
|
||||
policy = charon->imvs->get_recommendation_policy(charon->imvs);
|
||||
policy = tnc->imvs->get_recommendation_policy(tnc->imvs);
|
||||
|
||||
enumerator = this->recs->create_enumerator(this->recs);
|
||||
while (enumerator->enumerate(enumerator, &entry))
|
||||
|
||||
Reference in New Issue
Block a user