Tobias Brunner
7c0c2349a9
Make number of concurrently handled stroke messages configurable.
2011-12-29 18:41:39 +01:00
Tobias Brunner
8ff513a863
Limit the number of concurrently handled stroke messages.
...
This avoids clogging the thread pool with potentially blocking jobs.
2011-12-29 18:39:34 +01:00
Tobias Brunner
fc726f1359
Fix deadlock in trap_manager_t during acquire.
...
Also fixes a TOCTOU issue regarding the use of entry_t.pending.
The deadlock was caused because the rwlock was being locked while
waiting for an IKE_SA. Triggering the deadlock was a bit tricky, here
is the description by Thomas Egerer (the reporter of this issue):
"
The deadlock occurs when the following happens (in the given order):
a) an IKE_SA is built and a thread is processing the IKE_AUTH request,
which can take a bit longer when a smartcard is involved. This
causes the ike_sa_manager to lock a particular IKE_SA exclusively.
b) an acquire is triggered which causes the rwlock in the trap_manager
to be read-locked, the subsequent call to
ike_sa_manager->checkout_by_config has to wait until a) unlocks
it's ike_sa.
c) a child_cfg contained in the peer_cfg belonging to the ike_sa
a) has locked is routed causes the child_configs contained
in the peer config to be locked by c) while the actual routing
code within trap_manager tries to writelock it's rwlock.
That's about it. As soon as a) finishes authentication of the peer
and tries to find a matching child sa it will try to lock the child
configs of the peer config which is not possible since it has been
locked by c).
Thread | Resource locked | Resource desired
-------+--------------------------------+--------------------------------
(a) | ike_sa in ike_sa_manager | child_cfgs of peer_cfg
| |
(b) | rwlock in trap-manager (read) | ike_sa in ike_sa_manager
| |
(c) | child_cfgs of peer_cfg | rwlock in trap-manager (write)
"
With this patch thread (b) now does not hold the lock while waiting for
the IKE_SA. Thus (c) can get the write lock, and (a) can subsequently
lock the mutex in the peer_cfg which then finally allows (b) to checkout
the IKE_SA.
2011-12-23 11:07:14 +01:00
Tobias Brunner
d6656f11e4
Fixed flush() method of trap_manager_t.
...
A segmentation fault could have happened during destruction of the trap
manager after calling flush().
2011-12-23 10:38:10 +01:00
Tobias Brunner
a5951a2861
Make sure the certificate cache is flushed when plugins are unloaded.
...
This avoids segmentation faults when plugins implementing cert_t are
already unloaded when the cache is flushed during destruction.
2011-12-15 12:20:09 +01:00
Tobias Brunner
3eff54a5ca
Added missing libsimaka files to Android.mk.
2011-12-14 16:38:30 +01:00
Tobias Brunner
406c5a593b
Destroy mediation managers before unloading plugins.
2011-12-14 14:24:37 +01:00
Andreas Steffen
54f53f9081
implemented IMC/IMV ReceiveMessageLong functions
2011-12-09 23:32:30 +01:00
Andreas Steffen
ac3331e1cd
added IMC/IMV support for send_message_long() and reserve_additional_id() functions
2011-12-09 17:11:31 +01:00
Andreas Steffen
170f918596
implemented IF-IMC/IMV 1.3 attributes
2011-12-08 17:57:39 +01:00
Andreas Steffen
d6c892169c
added TNC_TNCC_GetAttribute() and TNC_TNCC_SetAttribute() functions
2011-12-08 14:52:08 +01:00
Andreas Steffen
584282d7c9
added TNC_IMC_ReceiveMessageLong() and TNC_IMV_ReceiveMessageLong() support
2011-12-08 12:38:45 +01:00
Andreas Steffen
115d49a748
fixed typo in function name
2011-12-08 12:30:57 +01:00
Andreas Steffen
aae76e9ba0
added TNC_TNCS_ReserveAdditionalIMVID() function
2011-12-07 17:55:26 +01:00
Andreas Steffen
194b23bb6e
return with TNC_RESULT_SUCCESS
2011-12-07 17:36:04 +01:00
Andreas Steffen
80ca4e50c9
added TNC_TNCC_ReserveAdditionalIMCID() function
2011-12-07 17:31:49 +01:00
Andreas Steffen
dcb5c5906e
added TNC_TNCC_SendMessageLong() and TNC_TNCS_SendMessageLong() functions
2011-12-07 11:44:29 +01:00
Andreas Steffen
f77505b8c8
corrected function name in error message
2011-12-07 00:12:15 +01:00
Andreas Steffen
10b9d52400
added TNC_TNCC_ReportMessageTypesLong() and TNC_TNCS_ReportMessageTypesLong() messages
2011-12-06 23:39:01 +01:00
Andreas Steffen
db183a92b7
upgraded IF-IMC/IMV inteface definitions to version 1.3
2011-12-04 12:48:30 +01:00
Sansar Choinyambuu
a66719d7d6
Reversed unintended commit
2011-11-28 21:17:16 +01:00
Sansar Choinyambuu
824ace105a
Changed the static function name in openssl_rsa_public_key object
...
Removed unused chunk variable from PTS verify_quote_signature function
2011-11-28 21:17:16 +01:00
Sansar Choinyambuu
103218b912
Reversed unintended commit
2011-11-28 14:39:53 +01:00
Sansar Choinyambuu
71741df078
Changed the static function name in openssl_rsa_public_key object
...
Removed unused chunk variable from PTS verify_quote_signature function
2011-11-28 14:39:53 +01:00
Tobias Brunner
b46a5cd4ef
Fixed check for log groups when debug_t is unsigned.
...
The range and signedness of enum types is up to the compiler.
2011-11-25 09:48:32 +01:00
Martin Willi
b2e493ab58
Fixed proposal numbering check in sa_payload
2011-11-21 09:12:00 +01:00
Martin Willi
3fcacd283e
Fix unaligned aliasing warning in raw socket
2011-11-17 18:22:07 +01:00
Tobias Brunner
856baca23e
Fixed monolithic build of libcharon with libtnccs enabled.
2011-11-08 18:35:11 +01:00
Tobias Brunner
59c5f048bb
Correctly refer to tnc-tnccs plugin when building monolithically.
2011-11-08 18:35:11 +01:00
Tobias Brunner
48e87e12ab
Revert "fixed integrity tests of plugins using libtls or libtnccs"
...
This reverts commit b597ac4a4c (not
completely).
2011-11-08 18:35:11 +01:00
Tobias Brunner
e034cc9ca9
Revert "fixed integrity tests of plugins using libsimaka"
...
This reverts commit 8c42f16dee .
Conflicts:
src/charon/Makefile.am
2011-11-08 18:35:11 +01:00
Tobias Brunner
39b30518c2
Syntax error in sqlite.sql fixed.
2011-11-04 14:37:22 +01:00
Andreas Steffen
8c42f16dee
fixed integrity tests of plugins using libsimaka
2011-11-04 11:27:19 +01:00
Thomas Egerer
dbd2169569
Change order of destroy/get_ref function calls
...
Since DESTROY_IF might destroy the peer_cfg, a get_ref on a freed object
is subject to fail.
2011-11-04 11:11:17 +01:00
Andreas Steffen
b597ac4a4c
fixed integrity tests of plugins using libtls or libtnccs
2011-11-02 06:42:08 +01:00
Tobias Brunner
abb89a97d1
Some Doxygen fixes.
2011-10-28 21:24:52 +02:00
Andreas Steffen
b21cfa93f8
Cosmetics
2011-10-26 10:32:54 +02:00
Tobias Brunner
87c65e76fc
Don't link to tnc libraries on Android as no tnc plugins are currently enabled.
2011-10-25 11:57:00 +02:00
Tobias Brunner
ba5b559b41
Build libtnccs on Android.
2011-10-25 11:56:26 +02:00
Andreas Steffen
5d36af6936
share some code between IMC and IMV managers
2011-10-25 09:45:35 +02:00
Andreas Steffen
61f7036e69
removed unneeded includes
2011-10-25 09:45:35 +02:00
Andreas Steffen
f0a8bf47f7
refactored TNC framework
2011-10-25 01:10:16 +02:00
Andreas Steffen
c008d2cc46
moved imv_manager to libtnccs
2011-10-25 01:10:16 +02:00
Andreas Steffen
f0fa002fd1
moved imc_manager to libtnccs
2011-10-25 01:10:16 +02:00
Tobias Brunner
5d549cd4e1
Log if charon failed to establish a CHILD_SA but keeps the IKE_SA up.
2011-10-21 18:09:02 +02:00
Tobias Brunner
677955e9d4
The load-tester plugin does not support SAD/SPD flushing.
2011-10-21 14:24:33 +02:00
Tobias Brunner
bf3c2dde68
Fixed indention in load-tester kernel interface.
2011-10-21 14:18:14 +02:00
Andreas Steffen
e50c853597
Add features support to tnccs plugins
2011-10-20 14:06:12 +02:00
Tobias Brunner
039a976745
Log messages with a loglevel > 1 to ANDROID_LOG_DEBUG.
2011-10-18 15:05:51 +02:00
Andreas Steffen
3c9dd593bb
fixed copy-and-paste error
2011-10-17 14:08:50 +02:00