Commit Graph
100 Commits
Author SHA1 Message Date
Tobias Brunner 34ee14dd28 plugin-loader: Collect statistics while loading features, print them in case features failed to load
There is no need to explicitly search for failed features in critical
plugins as this is now detected while loading the features.
2013-06-21 15:13:25 +02:00
Tobias Brunner 681e53c70c plugin-loader: Use different log level if failed feature is in critical plugin 2013-06-21 15:13:25 +02:00
Tobias Brunner 13d2d8f634 plugin-loader: Log message when failing to load plugin 2013-06-21 15:13:25 +02:00
Tobias Brunner 51b9d7513d plugin-loader: Reduce verbosity while loading plugins 2013-06-21 15:13:25 +02:00
Tobias Brunner 0adf165c7e Fix crash if the initiator has no suitable proposal available
Could be triggered with a typo in the ike or esp options when ! is used.
2013-06-21 11:09:03 +02:00
Tobias Brunner 8c88ca0fcf stroke: Add statusall-nb as alias for statusallnb 2013-06-21 10:51:41 +02:00
Tobias Brunner 4182c86aed stroke: Add non-blocking versions of up and down
stroke up-nb and stroke down-nb do not block until the command has
finished.  Instead, they return right after initiating the respective
operation.
2013-06-21 10:49:39 +02:00
Tobias Brunner 9afc6e6a70 starter: Make ipsec.conf path configurable via command line 2013-06-21 10:08:56 +02:00
Tobias Brunner c0d0391a51 pubkey: Improve comparison of raw public key certificate objects 2013-06-21 10:02:25 +02:00
Tobias Brunner 4d04e2c63b utils: Remove volatile qualifier from refcount_t typedef
It's not really required anymore (if it ever was) and may cause compiler
warnings when using the non atomic versions of ref_get/ref_put.
2013-06-19 09:28:30 +02:00
Tobias Brunner c6f1929a45 socket-default: Make sure sockets are open when checking with FD_ISSET 2013-06-14 17:25:16 +02:00
Tobias Brunner 1889837767 socket-default: Properly initialize NAT-T port if opening regular socket failed 2013-06-14 16:42:56 +02:00
Tobias Brunner 92f102c21b android: Forward initiator flag to libipsec when adding IPsec SA 2013-06-13 13:55:58 +02:00
Tobias Brunner 52d7c530e9 libipsec: Add initiator flag to definition of ipsec_sa_mgr_t.add_sa() 2013-06-13 13:54:05 +02:00
Tobias Brunner 44fb978169 ha: Fix CHILD_SA installation in ha_dispatcher after adding initiator flag 2013-06-13 13:17:55 +02:00
Tobias Brunner f5f7053bcd leak-detective: Resolve hooked functions during initialization
If uses of dlopen(), e.g. when loading plugins, produce errors an error
string could get allocated dynamically.  At this point realloc() might not
yet be resolved and when dlsym() is later called by leak detective to do
so the error string might get freed while leak detective is disabled and
real_free() will be called with a pointer into one of leak detective's
memory blocks instead of a pointer to the block itself, causing a SIGSEGV.
2013-06-11 15:48:26 +02:00
Tobias Brunner 3873526f3e Properly compare CHILD_SAs during rekey collision
The previous code did not properly check for the situation when the
DELETE for a redundant CHILD_SA created by a responder during a
CHILD_SA rekey collision arrives before the responder's answer to the
initiator's winning CREATE_CHILD_SA request.
2013-06-11 14:00:02 +02:00
Tobias Brunner 5744226e92 Merge branch 'plugin-loader'
Improves how plugin loader resolves dependencies between plugins.  The
old loader had problems if plugins had dependencies on features provided
by plugins listed later in the plugin list.  For instance, it was not
possible to use the X.509 implementation provided by the x509 plugin
while using all the crypto primitives provided by the openssl plugin.
Because the x509 plugin has a dependency on SHA1, the old loader skipped
that plugin until it loaded a SHA1 implementation.  Because the loader
also loaded all features with resolved dependencies provided by a specific
plugin it would, while loading the openssl plugin's SHA1 implementation,
also load its X.509 implementation.  So to use the x509 plugin it was
necessary to load the sha1 plugin before it so that its dependencies
could be properly resolved.

With the new implementation the plugins don't have to be in a specific
order to resolve dependencies.  But the order still matters if two
plugins provide the same feature.

Also, support for the get_features() interface was added to all plugins.
2013-06-11 11:36:40 +02:00
Tobias Brunner 31a416a5b2 Removed stray *_plugin_create() declarations from header files 2013-06-11 11:18:19 +02:00
Tobias Brunner 460488b180 eap-radius: Do initialization in a plugin feature callback 2013-06-11 11:18:19 +02:00
Tobias Brunner 49d7a98f47 Refactored plugin-loader with improved dependency resolution
With the new implementation the plugins don't have to be listed in any
special order, dependencies are properly resolved.  The order only
matters if two plugins provide the same feature.
2013-06-11 11:18:19 +02:00
Tobias Brunner facc781500 android-log: Use plugin features 2013-06-11 11:18:19 +02:00
Tobias Brunner df60999b5f android-dns: Use plugin features to register attribute handler 2013-06-11 11:18:19 +02:00
Tobias Brunner e183a6c36d maemo: Use plugin features 2013-06-11 11:18:19 +02:00
Tobias Brunner 6d766925b2 medsrv: Use plugin features with dependency on database implementation 2013-06-11 11:18:19 +02:00
Tobias Brunner da7c3f8900 medcli: Use plugin features with dependency on database implementation 2013-06-11 11:18:19 +02:00
Tobias Brunner d0ccae4dd2 whitelist: Use plugin features to register listener 2013-06-11 11:18:19 +02:00
Tobias Brunner 49d333ac67 updown: Use plugin features to register listener and attribute handler 2013-06-11 11:18:19 +02:00
Tobias Brunner 819cb66298 unity: Use plugin features to register listener and attribute handler/provider 2013-06-11 11:18:19 +02:00
Tobias Brunner b033d59d1e unit-tester: Use plugin features 2013-06-11 11:18:19 +02:00
Tobias Brunner e1360331e9 uci: Use plugin features to register backend and credential set 2013-06-11 11:18:19 +02:00
Tobias Brunner 36f27c1506 systime-fix: Use plugin features to register validator 2013-06-11 11:18:19 +02:00
Tobias Brunner c1f5841bb2 smp: Use plugin features 2013-06-11 11:18:19 +02:00
Tobias Brunner 64b0c2575f radattr: Use plugin features to register listener 2013-06-11 11:18:18 +02:00
Tobias Brunner d94c0913b1 lookip: Use plugin features to register listener 2013-06-11 11:18:18 +02:00
Tobias Brunner dfe97d63d8 led: Use plugin features to register listener 2013-06-11 11:18:18 +02:00
Tobias Brunner da04914933 test-vectors: Use plugin features 2013-06-11 11:18:18 +02:00
Tobias Brunner 17f00db6d6 revocation: Use plugin features with soft dependencies on fetcher and en-/decoding 2013-06-11 11:18:18 +02:00
Tobias Brunner 25da1943b3 padlock: Use plugin features to properly register algorithms 2013-06-11 11:18:18 +02:00
Tobias Brunner 7756c0383e pkcs11: Use plugin_features_add() in get_features() 2013-06-11 11:18:18 +02:00
Tobias Brunner 886a40d75e plugin-feature: Added helper function to extend arrays of plugin features 2013-06-11 11:18:18 +02:00
Tobias Brunner c172a92bfb constraints: Use plugin features with soft dependency on X.509 decoding 2013-06-11 11:18:18 +02:00
Tobias Brunner e3bdf03af4 blowfish: Use plugin features to properly register crypter 2013-06-11 11:18:18 +02:00
Tobias Brunner 8f49a8d0a6 resolve: Use plugin features to register attribute handler 2013-06-11 11:18:18 +02:00
Tobias Brunner 44d5e10d9e attr: Use plugin features to register attribute provider 2013-06-11 11:18:18 +02:00
Tobias Brunner 21d094f402 ipseckey: Allow en-/disabling at runtime using plugin reload feature 2013-06-11 11:18:18 +02:00
Tobias Brunner 82d3f5122b ipseckey: Use plugin features and depend on RESOLVER
Also fixed a double-free of the resolver instance.
2013-06-11 11:18:18 +02:00
Tobias Brunner d895721489 unbound: Use plugin features and provide RESOLVER 2013-06-11 11:18:18 +02:00
Tobias Brunner f5bd1a5e09 plugin-feature: Add feature for DNSSEC-enabled resolvers 2013-06-11 11:18:18 +02:00
Tobias Brunner 924196d6d4 ha: Use plugin features to register listeners and attribute provider 2013-06-11 11:18:18 +02:00
Tobias Brunner e5f4b3ca5b farp: Use plugin features to register listener 2013-06-11 11:18:17 +02:00
Tobias Brunner aa71f5f515 error-notify: Use plugin features to register listener 2013-06-11 11:18:17 +02:00
Tobias Brunner 57c29f6895 duplicheck: Use plugin features to register listener 2013-06-11 11:18:17 +02:00
Tobias Brunner 6c51ff745c coupling: Use plugin features and soft depend on SHA1 2013-06-11 11:18:17 +02:00
Tobias Brunner 0c52198bc1 certexpire: Use plugin features to register listener 2013-06-11 11:18:17 +02:00
Tobias Brunner 94ca7252c1 addrblock: Use plugin features with soft dependency on X.509 decoding 2013-06-11 11:18:17 +02:00
Tobias Brunner 12459a4dc8 dhcp: Use plugin features with dependency to RNG implementation 2013-06-11 11:18:17 +02:00
Tobias Brunner 11a27ea28f sql: Use plugin features with dependency to database backend 2013-06-11 11:18:17 +02:00
Tobias Brunner 989ec772b5 attr-sql: Use plugin features with dependency to database backend 2013-06-11 11:18:17 +02:00
Tobias Brunner 8a6cc1e35f plugin-feature: Function added to exactly compare plugin features 2013-06-11 11:18:17 +02:00
Tobias Brunner 270e425b24 Socket plugins soft depend on the kernel-ipsec plugin feature
On most platforms calls to methods to bypass the IKE sockets and enabling
UDP decapsulation are required.
2013-06-11 11:18:17 +02:00
Tobias Brunner c50da645b8 Merge branch 'unit-tests'
Adds a test runner and several test suites for libstrongswan.
Also adds an option to produce a test coverage report.

Several bugs were fixed in the process and chunk_hash() was replaced
with an improved implementation based on SipHash-2-4 (with a randomly
allocated key to prevent hash flooding attacks).
2013-06-11 11:16:30 +02:00
Tobias Brunner bde35a6fb2 Suppress log messages during tests 2013-06-11 11:03:13 +02:00
Tobias Brunner f2eeb54e8b Remove explicit leak detective checks as these are now done for all tests 2013-06-11 11:03:13 +02:00
Tobias Brunner 95e9915074 Enable leak detective for all test cases 2013-06-11 11:03:13 +02:00
Tobias Brunner 2b4902973b Added tests for bio_writer_t 2013-06-11 11:03:13 +02:00
Tobias Brunner eeb73dec79 Ensure buffer in bio_writer_t is properly increased
The previous code was problematic if bufsize/increase was smaller than 8
and an u_int64_t was written when the buffer was too small.  Also, for
large chunks and small bufsizes realloc() was called several times
instead of just once.
2013-06-11 11:03:13 +02:00
Tobias Brunner b4029a4aae Added tests for bio_reader_t 2013-06-11 11:03:13 +02:00
Tobias Brunner 01e15ab5c7 Add getter for the number of leaks to leak_detective_t 2013-06-11 11:03:13 +02:00
Tobias Brunner 80d9a9b722 Added tests for utils/enum.c 2013-06-11 11:03:13 +02:00
Tobias Brunner 9947a1f2f4 Gracefully handle NULL as argument for enum_from_name() 2013-06-11 11:03:13 +02:00
Tobias Brunner 06f6d80245 Additional tests for identification_t added 2013-06-11 11:03:13 +02:00
Tobias Brunner b1abf22bd0 Fail DN parsing if OID is unterminated
This is the case if the last OID is not followed by a = or if the string
starts with a =.
2013-06-11 11:03:12 +02:00
Tobias Brunner f00c350688 Fix DN printing if last RDN has an empty value 2013-06-11 11:03:12 +02:00
Tobias Brunner 10584df24f Fix DN parsing if last RDN has an empty value 2013-06-11 11:03:12 +02:00
Tobias Brunner c04498b608 Fix output of ASN.1 GN 2013-06-11 11:03:12 +02:00
Tobias Brunner 78c37de15a Use chunk_from_str in identification_from_string
We always have a non-empty string in those cases as "" is now handled
as ID_ANY.
2013-06-11 11:03:12 +02:00
Tobias Brunner c1be5d66cd Use local variable in chunk_from_str()
This allows using strdup() or other string functions as argument
without calling them twice.
2013-06-11 11:03:12 +02:00
Tobias Brunner 456a31e895 Parse empty string as ID_ANY 2013-06-11 11:03:12 +02:00
Tobias Brunner af67613ed6 Added tests for utils/utils.[ch] 2013-06-11 11:03:12 +02:00
Tobias Brunner 7b91011d6e Allow memstr() to be called with NULL arguments 2013-06-11 11:03:12 +02:00
Tobias Brunner 438a6693ca Removed unused clalloc() function 2013-06-11 11:03:12 +02:00
Tobias Brunner 819c02dbc6 timeval_add_ms() fixed
1000000us are exactly 1s so.
2013-06-11 11:03:12 +02:00
Tobias Brunner c2dba63bd4 Additional tests for chunk_t 2013-06-11 11:03:12 +02:00
Tobias Brunner ab73ae67d3 Also capture coverage data for tests but filter them from the result
Otherwise calls from test cases to static inline functions are not captured.
2013-06-11 11:03:12 +02:00
Tobias Brunner 9a8c873e90 Add tests for lib->get|set 2013-06-11 11:03:12 +02:00
Tobias Brunner 0e55270aea Remove dead code in token enumerator
Since we always search for the nearest separator (and strip them from
the front of the next token) there can't be any separators left at the
end of a token.
2013-06-11 11:03:12 +02:00
Tobias Brunner 7e9f6b276b Additional and improved enumerator_t tests 2013-06-11 11:03:11 +02:00
Tobias Brunner 0713c90927 Test remove and remove_at of hashtable_t if all items are in the same bucket 2013-06-11 11:03:11 +02:00
Tobias Brunner c721d6b6a3 Add test cases for invoke_* and clone_* of linked_list_t 2013-06-11 11:03:11 +02:00
Tobias Brunner afb6d9c301 Improve tests for linked_list_t.replace() 2013-06-11 11:03:11 +02:00
Tobias Brunner cca70ed331 Add additional tests for linked_list_t 2013-06-11 11:03:11 +02:00
Tobias Brunner bc90b3dd0a Improved test for linked_list_t.insert_before() 2013-06-11 11:03:11 +02:00
Tobias Brunner 01a3ba9e0f Enable coverage report for libstrongswan 2013-06-11 11:03:11 +02:00
Tobias Brunner 1f14b4a1f9 Add --enable-coverage configure option
This configure flag enables lcov [1] coverage generation and is intended
to be used with unit tests (--enable-unit-tests is implied).

A html coverage report can be generated by issuing the following command
in the toplevel build directory:

make coverage

[1] - http://ltp.sourceforge.net/coverage/lcov.php

Based on a patch by Adrian-Ken Rueegsegger.
2013-06-11 11:03:11 +02:00
Tobias Brunner 952073b8a7 Use proper type for enumerator_t/linked_list_t tests
Worked with -O2 but not with -O0.
2013-06-11 11:03:11 +02:00
Tobias Brunner de42bf35f9 Converted test for recursive mutex_t 2013-06-11 11:03:11 +02:00
Tobias Brunner bed4bc1327 Randomly allocate chunk_hash() key during first use
This avoids hash flooding attacks.
2013-06-11 11:03:11 +02:00
Tobias Brunner d1953fe403 Replace chunk_hash() with output from chunk_mac()
The quality is way better, the calculation is a bit slower though.

The key is statically initialized to zero, which will be changed later
to prevent hash flooding.
2013-06-11 11:03:11 +02:00
Tobias Brunner 1255de5a20 Adding chunk_mac() which calculates a 64-bit MAC using SipHash-2-4 2013-06-11 11:03:11 +02:00