child-sa: Pass default interface ID inherited from IKE_SA

Also pass optional arguments as struct.
This commit is contained in:
Tobias Brunner
2019-04-04 09:36:38 +02:00
parent dec3c184a6
commit fafa76984d
6 changed files with 117 additions and 131 deletions
+37 -58
View File
@@ -151,29 +151,9 @@ struct private_quick_mode_t {
uint64_t lifebytes;
/**
* Reqid to use, 0 for auto-allocate
* Data collected to create the CHILD_SA
*/
uint32_t reqid;
/**
* Explicit inbound mark value to use, if any
*/
uint32_t mark_in;
/**
* Explicit outbound mark value to use, if any
*/
uint32_t mark_out;
/**
* Explicit inbound interface ID to use, if any
*/
uint32_t if_id_in;
/**
* Explicit outbound interface ID to use, if any
*/
uint32_t if_id_out;
child_sa_create_t child;
/**
* SPI of SA we rekey
@@ -195,11 +175,6 @@ struct private_quick_mode_t {
*/
protocol_id_t proto;
/**
* Use UDP encapsulation
*/
bool udp;
/**
* Message ID of handled quick mode exchange
*/
@@ -637,7 +612,7 @@ static bool get_ts(private_quick_mode_t *this, message_t *message)
tsr = traffic_selector_create_from_subnet(hsr->clone(hsr),
hsr->get_family(hsr) == AF_INET ? 32 : 128, 0, 0, 65535);
}
if (this->mode == MODE_TRANSPORT && this->udp &&
if (this->mode == MODE_TRANSPORT && this->child.encap &&
(!tsi->is_host(tsi, hsi) || !tsr->is_host(tsr, hsr)))
{ /* change TS in case of a NAT in transport mode */
DBG2(DBG_IKE, "changing received traffic selectors %R=== %R due to NAT",
@@ -849,16 +824,19 @@ METHOD(task_t, build_i, status_t,
diffie_hellman_group_t group;
encap_t encap;
this->udp = this->ike_sa->has_condition(this->ike_sa, COND_NAT_ANY);
this->mode = this->config->get_mode(this->config);
this->child.if_id_in_def = this->ike_sa->get_if_id(this->ike_sa,
TRUE);
this->child.if_id_out_def = this->ike_sa->get_if_id(this->ike_sa,
FALSE);
this->child.encap = this->ike_sa->has_condition(this->ike_sa,
COND_NAT_ANY);
this->child_sa = child_sa_create(
this->ike_sa->get_my_host(this->ike_sa),
this->ike_sa->get_other_host(this->ike_sa),
this->config, this->reqid, this->udp,
this->mark_in, this->mark_out,
this->if_id_in, this->if_id_out);
this->config, &this->child);
if (this->udp && this->mode == MODE_TRANSPORT)
if (this->child.encap && this->mode == MODE_TRANSPORT)
{
/* TODO-IKEv1: disable NAT-T for TRANSPORT mode by default? */
add_nat_oa_payloads(this, message);
@@ -925,7 +903,7 @@ METHOD(task_t, build_i, status_t,
}
get_lifetimes(this);
encap = get_encap(this->ike_sa, this->udp);
encap = get_encap(this->ike_sa, this->child.encap);
sa_payload = sa_payload_create_from_proposals_v1(list,
this->lifetime, this->lifebytes, AUTH_NONE,
this->mode, encap, this->cpi_i);
@@ -1037,7 +1015,7 @@ static void check_for_rekeyed_child(private_quick_mode_t *this, bool responder)
name = this->config->get_name(this->config);
enumerator = this->ike_sa->create_child_sa_enumerator(this->ike_sa);
while (this->reqid == 0 && enumerator->enumerate(enumerator, &child_sa))
while (!this->child.reqid && enumerator->enumerate(enumerator, &child_sa))
{
if (streq(child_sa->get_name(child_sa), name))
{
@@ -1052,14 +1030,16 @@ static void check_for_rekeyed_child(private_quick_mode_t *this, bool responder)
remote->equals(remote, other_ts) &&
this->proposal->equals(this->proposal, proposal))
{
this->reqid = child_sa->get_reqid(child_sa);
this->rekey = child_sa->get_spi(child_sa, TRUE);
this->mark_in = child_sa->get_mark(child_sa,
TRUE).value;
this->mark_out = child_sa->get_mark(child_sa,
FALSE).value;
this->if_id_in = child_sa->get_if_id(child_sa, TRUE);
this->if_id_out = child_sa->get_if_id(child_sa, FALSE);
this->child.reqid = child_sa->get_reqid(child_sa);
this->child.mark_in = child_sa->get_mark(child_sa,
TRUE).value;
this->child.mark_out = child_sa->get_mark(child_sa,
FALSE).value;
this->child.if_id_in = child_sa->get_if_id(child_sa,
TRUE);
this->child.if_id_out = child_sa->get_if_id(child_sa,
FALSE);
child_sa->set_state(child_sa, CHILD_REKEYING);
DBG1(DBG_IKE, "detected rekeying of CHILD_SA %s{%u}",
child_sa->get_name(child_sa),
@@ -1102,7 +1082,8 @@ METHOD(task_t, process_r, status_t,
return send_notify(this, INVALID_PAYLOAD_TYPE);
}
this->mode = sa_payload->get_encap_mode(sa_payload, &this->udp);
this->mode = sa_payload->get_encap_mode(sa_payload,
&this->child.encap);
if (!get_ts(this, message))
{
@@ -1193,13 +1174,14 @@ METHOD(task_t, process_r, status_t,
}
check_for_rekeyed_child(this, TRUE);
this->child.if_id_in_def = this->ike_sa->get_if_id(this->ike_sa,
TRUE);
this->child.if_id_out_def = this->ike_sa->get_if_id(this->ike_sa,
FALSE);
this->child_sa = child_sa_create(
this->ike_sa->get_my_host(this->ike_sa),
this->ike_sa->get_other_host(this->ike_sa),
this->config, this->reqid, this->udp,
this->mark_in, this->mark_out,
this->if_id_in, this->if_id_out);
this->config, &this->child);
tsi = linked_list_create_with_items(this->tsi, NULL);
tsr = linked_list_create_with_items(this->tsr, NULL);
@@ -1291,13 +1273,13 @@ METHOD(task_t, build_r, status_t,
}
}
if (this->udp && this->mode == MODE_TRANSPORT)
if (this->child.encap && this->mode == MODE_TRANSPORT)
{
/* TODO-IKEv1: disable NAT-T for TRANSPORT mode by default? */
add_nat_oa_payloads(this, message);
}
encap = get_encap(this->ike_sa, this->udp);
encap = get_encap(this->ike_sa, this->child.encap);
sa_payload = sa_payload_create_from_proposal_v1(this->proposal,
this->lifetime, this->lifebytes, AUTH_NONE,
this->mode, encap, this->cpi_r);
@@ -1422,21 +1404,21 @@ METHOD(quick_mode_t, get_mid, uint32_t,
METHOD(quick_mode_t, use_reqid, void,
private_quick_mode_t *this, uint32_t reqid)
{
this->reqid = reqid;
this->child.reqid = reqid;
}
METHOD(quick_mode_t, use_marks, void,
private_quick_mode_t *this, uint32_t in, uint32_t out)
{
this->mark_in = in;
this->mark_out = out;
this->child.mark_in = in;
this->child.mark_out = out;
}
METHOD(quick_mode_t, use_if_ids, void,
private_quick_mode_t *this, uint32_t in, uint32_t out)
{
this->if_id_in = in;
this->if_id_out = out;
this->child.if_id_in = in;
this->child.if_id_out = out;
}
METHOD(quick_mode_t, rekey, void,
@@ -1467,10 +1449,7 @@ METHOD(task_t, migrate, void,
this->dh = NULL;
this->spi_i = 0;
this->spi_r = 0;
this->mark_in = 0;
this->mark_out = 0;
this->if_id_in = 0;
this->if_id_out = 0;
this->child = (child_sa_create_t){};
if (!this->initiator)
{