refactored TNC framework

This commit is contained in:
Andreas Steffen
2011-10-25 01:10:16 +02:00
parent c008d2cc46
commit f0a8bf47f7
52 changed files with 971 additions and 605 deletions
+10 -4
View File
@@ -1,14 +1,20 @@
INCLUDES = -I$(top_srcdir)/src/libstrongswan -I$(top_srcdir)/src/libhydra \
-I$(top_srcdir)/src/libcharon -I$(top_srcdir)/src/libtncif
INCLUDES = \
-I$(top_srcdir)/src/libstrongswan \
-I$(top_srcdir)/src/libhydra \
-I$(top_srcdir)/src/libcharon \
-I$(top_srcdir)/src/libtncif \
-I$(top_srcdir)/src/libtnccs
AM_CFLAGS = -DUSE_TNC -rdynamic
AM_CFLAGS = -rdynamic
if MONOLITHIC
noinst_LTLIBRARIES = libstrongswan-tnc-imv.la
else
plugin_LTLIBRARIES = libstrongswan-tnc-imv.la
libstrongswan_tnc_imv_la_LIBADD = $(top_builddir)/src/libtncif/libtncif.la
libstrongswan_tnc_imv_la_LIBADD = \
$(top_builddir)/src/libtncif/libtncif.la \
$(top_builddir)/src/libtnccs/libtnccs.la
endif
libstrongswan_tnc_imv_la_SOURCES = \
@@ -13,10 +13,11 @@
* for more details.
*/
#include "tnc_imv.h"
#include <tnc/tnc.h>
#include <tnc/imv/imv_manager.h>
#include <tnc/tnccs/tnccs_manager.h>
#include <debug.h>
#include <daemon.h>
#define TNC_IMCID_ANY 0xffff
@@ -28,14 +29,14 @@ TNC_Result TNC_TNCS_ReportMessageTypes(TNC_IMVID imv_id,
TNC_MessageTypeList supported_types,
TNC_UInt32 type_count)
{
if (!charon->imvs->is_registered(charon->imvs, imv_id))
if (!tnc->imvs->is_registered(tnc->imvs, imv_id))
{
DBG1(DBG_TNC, "ignoring ReportMessageTypes() from unregistered IMV %u",
imv_id);
return TNC_RESULT_INVALID_PARAMETER;
}
return charon->imvs->set_message_types(charon->imvs, imv_id,
supported_types, type_count);
return tnc->imvs->set_message_types(tnc->imvs, imv_id, supported_types,
type_count);
}
/**
@@ -45,14 +46,14 @@ TNC_Result TNC_TNCS_RequestHandshakeRetry(TNC_IMVID imv_id,
TNC_ConnectionID connection_id,
TNC_RetryReason reason)
{
if (!charon->imvs->is_registered(charon->imvs, imv_id))
if (!tnc->imvs->is_registered(tnc->imvs, imv_id))
{
DBG1(DBG_TNC, "ignoring RequestHandshakeRetry() from unregistered IMV %u",
imv_id);
return TNC_RESULT_INVALID_PARAMETER;
}
return charon->tnccs->request_handshake_retry(charon->tnccs, FALSE, imv_id,
connection_id, reason);
return tnc->tnccs->request_handshake_retry(tnc->tnccs, FALSE, imv_id,
connection_id, reason);
}
/**
@@ -64,14 +65,14 @@ TNC_Result TNC_TNCS_SendMessage(TNC_IMVID imv_id,
TNC_UInt32 msg_len,
TNC_MessageType msg_type)
{
if (!charon->imvs->is_registered(charon->imvs, imv_id))
if (!tnc->imvs->is_registered(tnc->imvs, imv_id))
{
DBG1(DBG_TNC, "ignoring SendMessage() from unregistered IMV %u",
imv_id);
return TNC_RESULT_INVALID_PARAMETER;
}
return charon->tnccs->send_message(charon->tnccs, TNC_IMCID_ANY, imv_id,
connection_id, msg, msg_len, msg_type);
return tnc->tnccs->send_message(tnc->tnccs, TNC_IMCID_ANY, imv_id,
connection_id, msg, msg_len, msg_type);
}
/**
@@ -83,14 +84,14 @@ TNC_Result TNC_TNCS_ProvideRecommendation(TNC_IMVID imv_id,
TNC_IMV_Action_Recommendation recommendation,
TNC_IMV_Evaluation_Result evaluation)
{
if (!charon->imvs->is_registered(charon->imvs, imv_id))
if (!tnc->imvs->is_registered(tnc->imvs, imv_id))
{
DBG1(DBG_TNC, "ignoring ProvideRecommendation() from unregistered IMV %u",
imv_id);
return TNC_RESULT_INVALID_PARAMETER;
}
return charon->tnccs->provide_recommendation(charon->tnccs, imv_id,
connection_id, recommendation, evaluation);
return tnc->tnccs->provide_recommendation(tnc->tnccs, imv_id, connection_id,
recommendation, evaluation);
}
/**
@@ -104,13 +105,13 @@ TNC_Result TNC_TNCS_GetAttribute(TNC_IMVID imv_id,
TNC_BufferReference buffer,
TNC_UInt32 *out_value_len)
{
if (!charon->imvs->is_registered(charon->imvs, imv_id))
if (!tnc->imvs->is_registered(tnc->imvs, imv_id))
{
DBG1(DBG_TNC, "ignoring GetAttribute() from unregistered IMV %u",
imv_id);
return TNC_RESULT_INVALID_PARAMETER;
}
return charon->tnccs->get_attribute(charon->tnccs, imv_id, connection_id,
return tnc->tnccs->get_attribute(tnc->tnccs, imv_id, connection_id,
attribute_id, buffer_len, buffer, out_value_len);
}
@@ -124,14 +125,14 @@ TNC_Result TNC_TNCS_SetAttribute(TNC_IMVID imv_id,
TNC_UInt32 buffer_len,
TNC_BufferReference buffer)
{
if (!charon->imvs->is_registered(charon->imvs, imv_id))
if (!tnc->imvs->is_registered(tnc->imvs, imv_id))
{
DBG1(DBG_TNC, "ignoring SetAttribute() from unregistered IMV %u",
imv_id);
return TNC_RESULT_INVALID_PARAMETER;
}
return charon->tnccs->set_attribute(charon->tnccs, imv_id, connection_id,
attribute_id, buffer_len, buffer);
return tnc->tnccs->set_attribute(tnc->tnccs, imv_id, connection_id,
attribute_id, buffer_len, buffer);
}
/**
+131 -3
View File
@@ -14,15 +14,22 @@
*/
#include "tnc_imv_manager.h"
#include "tnc_imv.h"
#include "tnc_imv_recommendations.h"
#include <tnc/imv/imv_manager.h>
#include <tncifimv.h>
#include <tncif_names.h>
#include <debug.h>
#include <sys/types.h>
#include <sys/stat.h>
#include <sys/mman.h>
#include <unistd.h>
#include <errno.h>
#include <fcntl.h>
#include <daemon.h>
#include <utils/lexparser.h>
#include <debug.h>
#include <threading/mutex.h>
typedef struct private_tnc_imv_manager_t private_tnc_imv_manager_t;
@@ -103,6 +110,124 @@ METHOD(imv_manager_t, remove_, imv_t*,
return removed_imv;
}
METHOD(imv_manager_t, load_all, bool,
private_tnc_imv_manager_t *this, char *filename)
{
int fd, line_nr = 0;
chunk_t src, line;
struct stat sb;
void *addr;
DBG1(DBG_TNC, "loading IMVs from '%s'", filename);
fd = open(filename, O_RDONLY);
if (fd == -1)
{
DBG1(DBG_TNC, "opening configuration file '%s' failed: %s", filename,
strerror(errno));
return FALSE;
}
if (fstat(fd, &sb) == -1)
{
DBG1(DBG_LIB, "getting file size of '%s' failed: %s", filename,
strerror(errno));
close(fd);
return FALSE;
}
addr = mmap(NULL, sb.st_size, PROT_READ | PROT_WRITE, MAP_PRIVATE, fd, 0);
if (addr == MAP_FAILED)
{
DBG1(DBG_LIB, "mapping '%s' failed: %s", filename, strerror(errno));
close(fd);
return FALSE;
}
src = chunk_create(addr, sb.st_size);
while (fetchline(&src, &line))
{
char *name, *path;
chunk_t token;
imv_t *imv;
line_nr++;
/* skip comments or empty lines */
if (*line.ptr == '#' || !eat_whitespace(&line))
{
continue;
}
/* determine keyword */
if (!extract_token(&token, ' ', &line))
{
DBG1(DBG_TNC, "line %d: keyword must be followed by a space",
line_nr);
return FALSE;
}
/* only interested in IMVs */
if (!match("IMV", &token))
{
continue;
}
/* advance to the IMV name and extract it */
if (!extract_token(&token, '"', &line) ||
!extract_token(&token, '"', &line))
{
DBG1(DBG_TNC, "line %d: IMV name must be set in double quotes",
line_nr);
return FALSE;
}
/* copy the IMV name */
name = malloc(token.len + 1);
memcpy(name, token.ptr, token.len);
name[token.len] = '\0';
/* advance to the IMV path and extract it */
if (!eat_whitespace(&line))
{
DBG1(DBG_TNC, "line %d: IMV path is missing", line_nr);
free(name);
return FALSE;
}
if (!extract_token(&token, ' ', &line))
{
token = line;
}
/* copy the IMV path */
path = malloc(token.len + 1);
memcpy(path, token.ptr, token.len);
path[token.len] = '\0';
/* load and register IMV instance */
imv = tnc_imv_create(name, path);
if (!imv)
{
free(name);
free(path);
return FALSE;
}
if (!add(this, imv))
{
if (imv->terminate &&
imv->terminate(imv->get_id(imv)) != TNC_RESULT_SUCCESS)
{
DBG1(DBG_TNC, "IMV \"%s\" not terminated successfully",
imv->get_name(imv));
}
imv->destroy(imv);
return FALSE;
}
DBG1(DBG_TNC, "IMV %u \"%s\" loaded from '%s'", imv->get_id(imv),
name, path);
}
munmap(addr, sb.st_size);
close(fd);
return TRUE;
}
METHOD(imv_manager_t, is_registered, bool,
private_tnc_imv_manager_t *this, TNC_IMVID id)
{
@@ -291,6 +416,7 @@ METHOD(imv_manager_t, batch_ending, void,
enumerator->destroy(enumerator);
}
METHOD(imv_manager_t, destroy, void,
private_tnc_imv_manager_t *this)
{
@@ -322,6 +448,7 @@ imv_manager_t* tnc_imv_manager_create(void)
.public = {
.add = _add,
.remove = _remove_, /* avoid name conflict with stdio.h */
.load_all = _load_all,
.is_registered = _is_registered,
.get_recommendation_policy = _get_recommendation_policy,
.create_recommendations = _create_recommendations,
@@ -336,6 +463,7 @@ imv_manager_t* tnc_imv_manager_create(void)
.imvs = linked_list_create(),
.next_imv_id = 1,
);
policy = enum_from_name(recommendation_policy_names,
lib->settings->get_str(lib->settings,
"charon.plugins.tnc-imv.recommendation_policy", "default"));
+7 -150
View File
@@ -1,5 +1,5 @@
/*
* Copyright (C) 2010 Andreas Steffen
* Copyright (C) 2010-2011 Andreas Steffen
* HSR Hochschule fuer Technik Rapperswil
*
* This program is free software; you can redistribute it and/or modify it
@@ -15,17 +15,9 @@
#include "tnc_imv_plugin.h"
#include "tnc_imv_manager.h"
#include "tnc_imv.h"
#include <sys/types.h>
#include <sys/stat.h>
#include <sys/mman.h>
#include <unistd.h>
#include <errno.h>
#include <fcntl.h>
#include <tnc/tnc.h>
#include <utils/lexparser.h>
#include <debug.h>
typedef struct private_tnc_imv_plugin_t private_tnc_imv_plugin_t;
@@ -39,131 +31,8 @@ struct private_tnc_imv_plugin_t {
*/
tnc_imv_plugin_t public;
/**
* TNC IMV manager controlling Integrity Measurement Verifiers
*/
imv_manager_t *imvs;
};
/**
* load IMVs from a configuration file
*/
static bool load_imvs(private_tnc_imv_plugin_t *this, char *filename)
{
int fd, line_nr = 0;
chunk_t src, line;
struct stat sb;
void *addr;
DBG1(DBG_TNC, "loading IMVs from '%s'", filename);
fd = open(filename, O_RDONLY);
if (fd == -1)
{
DBG1(DBG_TNC, "opening configuration file '%s' failed: %s", filename,
strerror(errno));
return FALSE;
}
if (fstat(fd, &sb) == -1)
{
DBG1(DBG_LIB, "getting file size of '%s' failed: %s", filename,
strerror(errno));
close(fd);
return FALSE;
}
addr = mmap(NULL, sb.st_size, PROT_READ | PROT_WRITE, MAP_PRIVATE, fd, 0);
if (addr == MAP_FAILED)
{
DBG1(DBG_LIB, "mapping '%s' failed: %s", filename, strerror(errno));
close(fd);
return FALSE;
}
src = chunk_create(addr, sb.st_size);
while (fetchline(&src, &line))
{
char *name, *path;
chunk_t token;
imv_t *imv;
line_nr++;
/* skip comments or empty lines */
if (*line.ptr == '#' || !eat_whitespace(&line))
{
continue;
}
/* determine keyword */
if (!extract_token(&token, ' ', &line))
{
DBG1(DBG_TNC, "line %d: keyword must be followed by a space",
line_nr);
return FALSE;
}
/* only interested in IMVs */
if (!match("IMV", &token))
{
continue;
}
/* advance to the IMV name and extract it */
if (!extract_token(&token, '"', &line) ||
!extract_token(&token, '"', &line))
{
DBG1(DBG_TNC, "line %d: IMV name must be set in double quotes",
line_nr);
return FALSE;
}
/* copy the IMV name */
name = malloc(token.len + 1);
memcpy(name, token.ptr, token.len);
name[token.len] = '\0';
/* advance to the IMV path and extract it */
if (!eat_whitespace(&line))
{
DBG1(DBG_TNC, "line %d: IMV path is missing", line_nr);
free(name);
return FALSE;
}
if (!extract_token(&token, ' ', &line))
{
token = line;
}
/* copy the IMV path */
path = malloc(token.len + 1);
memcpy(path, token.ptr, token.len);
path[token.len] = '\0';
/* load and register IMV instance */
imv = tnc_imv_create(name, path);
if (!imv)
{
free(name);
free(path);
return FALSE;
}
if (!this->imvs->add(this->imvs, imv))
{
if (imv->terminate &&
imv->terminate(imv->get_id(imv)) != TNC_RESULT_SUCCESS)
{
DBG1(DBG_TNC, "IMV \"%s\" not terminated successfully",
imv->get_name(imv));
}
imv->destroy(imv);
return FALSE;
}
DBG1(DBG_TNC, "IMV %u \"%s\" loaded from '%s'", imv->get_id(imv),
name, path);
}
munmap(addr, sb.st_size);
close(fd);
return TRUE;
}
METHOD(plugin_t, get_name, char*,
tnc_imv_plugin_t *this)
@@ -175,17 +44,17 @@ METHOD(plugin_t, get_features, int,
private_tnc_imv_plugin_t *this, plugin_feature_t *features[])
{
static plugin_feature_t f[] = {
PLUGIN_PROVIDE(CUSTOM, "imv-manager"),
PLUGIN_CALLBACK(tnc_manager_register, tnc_imv_manager_create),
PLUGIN_PROVIDE(CUSTOM, "imv-manager"),
PLUGIN_DEPENDS(CUSTOM, "tnccs-manager"),
};
*features = f;
return countof(f);
}
METHOD(plugin_t, destroy, void,
tnc_imv_plugin_t *this)
private_tnc_imv_plugin_t *this)
{
lib->set(lib, "imv-manager", NULL);
this->imvs->destroy(this->imvs);
free(this);
}
@@ -194,8 +63,7 @@ METHOD(plugin_t, destroy, void,
*/
plugin_t *tnc_imv_plugin_create()
{
char *tnc_config;
tnc_imv_plugin_t *this;
private_tnc_imv_plugin_t *this;
INIT(this,
.public = {
@@ -205,19 +73,8 @@ plugin_t *tnc_imv_plugin_create()
.destroy = _destroy,
},
},
.imvs = tnc_imv_manager_create(),
);
lib->set(lib, "imv-manager", this->imvs);
/* Load IMVs and abort if not all instances initalize successfully */
tnc_config = lib->settings->get_str(lib->settings,
"charon.plugins.tnc-imv.tnc_config", "/etc/tnc_config");
if (!load_imvs(this, tnc_config))
{
destroy(this);
return NULL;
}
return &this->public.plugin;
}
@@ -12,15 +12,17 @@
* for more details.
*/
#include <debug.h>
#include <daemon.h>
#include <tncifimv.h>
#include <tncif_names.h>
#include <tnc/tnc.h>
#include <tnc/imv/imv.h>
#include <tnc/imv/imv_manager.h>
#include <tnc/imv/imv_recommendations.h>
#include <debug.h>
#include <utils/linked_list.h>
typedef struct private_tnc_imv_recommendations_t private_tnc_imv_recommendations_t;
typedef struct recommendation_entry_t recommendation_entry_t;
@@ -129,7 +131,7 @@ METHOD(recommendations_t, have_recommendation, bool,
DBG1(DBG_TNC, "there are no IMVs to make a recommendation");
return TRUE;
}
policy = charon->imvs->get_recommendation_policy(charon->imvs);
policy = tnc->imvs->get_recommendation_policy(tnc->imvs);
enumerator = this->recs->create_enumerator(this->recs);
while (enumerator->enumerate(enumerator, &entry))