2008-11-17 15:58:39 +00:00
|
|
|
/*
|
|
|
|
* Copyright (C) 2008 Martin Willi
|
|
|
|
* Hochschule fuer Technik Rapperswil
|
|
|
|
*
|
|
|
|
* This program is free software; you can redistribute it and/or modify it
|
|
|
|
* under the terms of the GNU General Public License as published by the
|
|
|
|
* Free Software Foundation; either version 2 of the License, or (at your
|
|
|
|
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
|
|
|
|
*
|
|
|
|
* This program is distributed in the hope that it will be useful, but
|
|
|
|
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
|
|
|
|
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
|
|
|
* for more details.
|
|
|
|
*/
|
|
|
|
|
2008-11-28 15:45:17 +00:00
|
|
|
#include "ha_sync_segments.h"
|
2008-11-17 15:58:39 +00:00
|
|
|
|
2009-09-22 12:32:52 +00:00
|
|
|
#include <utils/mutex.h>
|
2008-11-17 15:58:39 +00:00
|
|
|
#include <utils/linked_list.h>
|
|
|
|
|
2008-11-28 15:45:17 +00:00
|
|
|
typedef struct private_ha_sync_segments_t private_ha_sync_segments_t;
|
2008-11-17 15:58:39 +00:00
|
|
|
|
|
|
|
/**
|
2008-11-28 15:45:17 +00:00
|
|
|
* Private data of an ha_sync_segments_t object.
|
2008-11-17 15:58:39 +00:00
|
|
|
*/
|
2008-11-28 15:45:17 +00:00
|
|
|
struct private_ha_sync_segments_t {
|
2008-11-17 15:58:39 +00:00
|
|
|
|
|
|
|
/**
|
2008-11-28 15:45:17 +00:00
|
|
|
* Public ha_sync_segments_t interface.
|
2008-11-17 15:58:39 +00:00
|
|
|
*/
|
2008-11-28 15:45:17 +00:00
|
|
|
ha_sync_segments_t public;
|
2008-11-27 09:57:31 +00:00
|
|
|
|
2009-09-22 12:33:38 +00:00
|
|
|
/**
|
|
|
|
* communication socket
|
|
|
|
*/
|
|
|
|
ha_sync_socket_t *socket;
|
|
|
|
|
2009-09-22 12:32:52 +00:00
|
|
|
/**
|
2009-09-22 13:19:43 +00:00
|
|
|
* Interface to control segments at kernel level
|
2009-09-22 12:32:52 +00:00
|
|
|
*/
|
2009-09-22 13:19:43 +00:00
|
|
|
ha_sync_kernel_t *kernel;
|
2009-09-22 12:32:52 +00:00
|
|
|
|
2008-11-27 09:57:31 +00:00
|
|
|
/**
|
2009-09-22 13:19:43 +00:00
|
|
|
* read/write lock for segment manipulation
|
2008-11-27 09:57:31 +00:00
|
|
|
*/
|
2009-09-22 13:19:43 +00:00
|
|
|
rwlock_t *lock;
|
2008-11-27 09:57:31 +00:00
|
|
|
|
|
|
|
/**
|
|
|
|
* Total number of ClusterIP segments
|
|
|
|
*/
|
|
|
|
u_int segment_count;
|
|
|
|
|
|
|
|
/**
|
|
|
|
* mask of active segments
|
|
|
|
*/
|
2009-09-22 12:53:03 +00:00
|
|
|
segment_mask_t active;
|
2008-11-17 15:58:39 +00:00
|
|
|
};
|
|
|
|
|
2008-11-27 09:57:31 +00:00
|
|
|
/**
|
|
|
|
* Log currently active segments
|
|
|
|
*/
|
2008-11-28 15:45:17 +00:00
|
|
|
static void log_segments(private_ha_sync_segments_t *this, bool activated,
|
2008-11-27 09:57:31 +00:00
|
|
|
u_int segment)
|
|
|
|
{
|
2009-06-25 09:24:18 +00:00
|
|
|
char buf[64] = "none", *pos = buf;
|
2008-11-27 09:57:31 +00:00
|
|
|
int i;
|
|
|
|
bool first = TRUE;
|
|
|
|
|
|
|
|
for (i = 0; i < this->segment_count; i++)
|
|
|
|
{
|
|
|
|
if (this->active & 0x01 << i)
|
|
|
|
{
|
|
|
|
if (first)
|
|
|
|
{
|
|
|
|
first = FALSE;
|
|
|
|
}
|
|
|
|
else
|
|
|
|
{
|
|
|
|
pos += snprintf(pos, buf + sizeof(buf) - pos, ",");
|
|
|
|
}
|
|
|
|
pos += snprintf(pos, buf + sizeof(buf) - pos, "%d", i+1);
|
|
|
|
}
|
|
|
|
}
|
2008-12-01 18:38:40 +00:00
|
|
|
DBG1(DBG_CFG, "HA sync segment %d %sactivated, now active: %s",
|
2008-11-27 09:57:31 +00:00
|
|
|
segment, activated ? "" : "de", buf);
|
|
|
|
}
|
|
|
|
|
2009-09-15 14:19:39 +00:00
|
|
|
/**
|
|
|
|
* Enable/Disable an an IKE_SA.
|
|
|
|
*/
|
|
|
|
static void enable_disable(private_ha_sync_segments_t *this, u_int segment,
|
|
|
|
ike_sa_state_t old, ike_sa_state_t new, bool enable)
|
2008-11-17 15:58:39 +00:00
|
|
|
{
|
|
|
|
ike_sa_t *ike_sa;
|
2008-11-27 09:57:31 +00:00
|
|
|
enumerator_t *enumerator;
|
2009-09-15 14:19:39 +00:00
|
|
|
u_int i, limit;
|
2008-11-27 09:57:31 +00:00
|
|
|
|
2009-09-22 12:32:52 +00:00
|
|
|
this->lock->write_lock(this->lock);
|
|
|
|
|
2009-09-15 14:19:39 +00:00
|
|
|
if (segment == 0 || segment <= this->segment_count)
|
2008-11-27 09:57:31 +00:00
|
|
|
{
|
2009-09-15 14:19:39 +00:00
|
|
|
if (segment)
|
|
|
|
{ /* loop once for single segment ... */
|
|
|
|
limit = segment + 1;
|
|
|
|
}
|
|
|
|
else
|
|
|
|
{ /* or segment_count times for all segments */
|
|
|
|
limit = this->segment_count;
|
|
|
|
}
|
2008-11-28 15:45:17 +00:00
|
|
|
enumerator = charon->ike_sa_manager->create_enumerator(charon->ike_sa_manager);
|
2008-11-27 09:57:31 +00:00
|
|
|
while (enumerator->enumerate(enumerator, &ike_sa))
|
|
|
|
{
|
2009-09-15 14:19:39 +00:00
|
|
|
if (ike_sa->get_state(ike_sa) == old)
|
2008-11-27 09:57:31 +00:00
|
|
|
{
|
2009-09-15 14:19:39 +00:00
|
|
|
for (i = segment; i < limit; i++)
|
|
|
|
{
|
2009-09-22 13:19:43 +00:00
|
|
|
if (this->kernel->in_segment(this->kernel,
|
|
|
|
ike_sa->get_other_host(ike_sa), i))
|
2009-09-15 14:19:39 +00:00
|
|
|
{
|
|
|
|
ike_sa->set_state(ike_sa, new);
|
|
|
|
}
|
|
|
|
}
|
2008-11-27 09:57:31 +00:00
|
|
|
}
|
|
|
|
}
|
|
|
|
enumerator->destroy(enumerator);
|
2009-09-22 14:51:47 +00:00
|
|
|
for (i = segment; i < limit; i++)
|
|
|
|
{
|
|
|
|
if (enable)
|
|
|
|
{
|
2009-09-23 08:42:05 +00:00
|
|
|
if (!(this->active & SEGMENTS_BIT(i)))
|
|
|
|
{
|
|
|
|
this->active |= SEGMENTS_BIT(i);
|
|
|
|
this->kernel->activate(this->kernel, i);
|
|
|
|
}
|
2009-09-22 14:51:47 +00:00
|
|
|
}
|
|
|
|
else
|
|
|
|
{
|
2009-09-23 08:42:05 +00:00
|
|
|
if (this->active & SEGMENTS_BIT(i))
|
|
|
|
{
|
|
|
|
this->active &= ~SEGMENTS_BIT(i);
|
|
|
|
this->kernel->deactivate(this->kernel, i);
|
|
|
|
}
|
2009-09-22 14:51:47 +00:00
|
|
|
}
|
|
|
|
}
|
2008-11-28 15:45:17 +00:00
|
|
|
|
2009-09-15 14:19:39 +00:00
|
|
|
log_segments(this, enable, segment);
|
2008-11-27 09:57:31 +00:00
|
|
|
}
|
2009-09-22 12:32:52 +00:00
|
|
|
|
|
|
|
this->lock->unlock(this->lock);
|
2008-11-27 09:57:31 +00:00
|
|
|
}
|
|
|
|
|
2009-09-15 14:19:39 +00:00
|
|
|
/**
|
|
|
|
* Implementation of ha_sync_segments_t.activate
|
|
|
|
*/
|
2009-09-22 12:33:38 +00:00
|
|
|
static void activate(private_ha_sync_segments_t *this, u_int segment,
|
|
|
|
bool notify)
|
2009-09-15 14:19:39 +00:00
|
|
|
{
|
2009-09-22 12:33:38 +00:00
|
|
|
ha_sync_message_t *message;
|
|
|
|
|
|
|
|
enable_disable(this, segment, IKE_PASSIVE, IKE_ESTABLISHED, TRUE);
|
|
|
|
|
|
|
|
if (notify)
|
|
|
|
{
|
|
|
|
message = ha_sync_message_create(HA_SYNC_SEGMENT_TAKE);
|
|
|
|
message->add_attribute(message, HA_SYNC_SEGMENT, segment);
|
|
|
|
this->socket->push(this->socket, message);
|
|
|
|
}
|
2009-09-15 14:19:39 +00:00
|
|
|
}
|
|
|
|
|
2008-11-27 09:57:31 +00:00
|
|
|
/**
|
2008-11-28 15:45:17 +00:00
|
|
|
* Implementation of ha_sync_segments_t.deactivate
|
2008-11-27 09:57:31 +00:00
|
|
|
*/
|
2009-09-22 12:33:38 +00:00
|
|
|
static void deactivate(private_ha_sync_segments_t *this, u_int segment,
|
|
|
|
bool notify)
|
2008-11-27 09:57:31 +00:00
|
|
|
{
|
2009-09-22 12:33:38 +00:00
|
|
|
ha_sync_message_t *message;
|
|
|
|
|
|
|
|
enable_disable(this, segment, IKE_ESTABLISHED, IKE_PASSIVE, FALSE);
|
|
|
|
|
|
|
|
if (notify)
|
|
|
|
{
|
|
|
|
message = ha_sync_message_create(HA_SYNC_SEGMENT_DROP);
|
|
|
|
message->add_attribute(message, HA_SYNC_SEGMENT, segment);
|
|
|
|
this->socket->push(this->socket, message);
|
|
|
|
}
|
2008-11-17 15:58:39 +00:00
|
|
|
}
|
|
|
|
|
2008-12-01 18:38:40 +00:00
|
|
|
/**
|
|
|
|
* Rekey all children of an IKE_SA
|
|
|
|
*/
|
|
|
|
static status_t rekey_children(ike_sa_t *ike_sa)
|
|
|
|
{
|
|
|
|
iterator_t *iterator;
|
|
|
|
child_sa_t *child_sa;
|
|
|
|
status_t status = SUCCESS;
|
|
|
|
|
|
|
|
iterator = ike_sa->create_child_sa_iterator(ike_sa);
|
|
|
|
while (iterator->iterate(iterator, (void**)&child_sa))
|
|
|
|
{
|
|
|
|
DBG1(DBG_CFG, "resyncing CHILD_SA");
|
|
|
|
status = ike_sa->rekey_child_sa(ike_sa, child_sa->get_protocol(child_sa),
|
|
|
|
child_sa->get_spi(child_sa, TRUE));
|
|
|
|
if (status == DESTROY_ME)
|
|
|
|
{
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
iterator->destroy(iterator);
|
|
|
|
return status;
|
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
|
|
|
* Implementation of ha_sync_segments_t.resync
|
|
|
|
*/
|
|
|
|
static void resync(private_ha_sync_segments_t *this, u_int segment)
|
|
|
|
{
|
|
|
|
ike_sa_t *ike_sa;
|
|
|
|
enumerator_t *enumerator;
|
|
|
|
linked_list_t *list;
|
|
|
|
ike_sa_id_t *id;
|
2009-09-22 12:53:03 +00:00
|
|
|
u_int16_t mask = SEGMENTS_BIT(segment);
|
2008-12-01 18:38:40 +00:00
|
|
|
|
2009-09-22 12:32:52 +00:00
|
|
|
list = linked_list_create();
|
|
|
|
this->lock->read_lock(this->lock);
|
|
|
|
|
2008-12-01 18:38:40 +00:00
|
|
|
if (segment > 0 && segment <= this->segment_count && (this->active & mask))
|
|
|
|
{
|
|
|
|
this->active &= ~mask;
|
|
|
|
|
|
|
|
DBG1(DBG_CFG, "resyncing HA sync segment %d", segment);
|
|
|
|
|
|
|
|
/* we do the actual rekeying in a seperate loop to avoid rekeying
|
|
|
|
* an SA twice. */
|
|
|
|
enumerator = charon->ike_sa_manager->create_enumerator(
|
|
|
|
charon->ike_sa_manager);
|
|
|
|
while (enumerator->enumerate(enumerator, &ike_sa))
|
|
|
|
{
|
|
|
|
if (ike_sa->get_state(ike_sa) == IKE_ESTABLISHED &&
|
2009-09-22 13:19:43 +00:00
|
|
|
this->kernel->in_segment(this->kernel,
|
|
|
|
ike_sa->get_other_host(ike_sa), segment))
|
2008-12-01 18:38:40 +00:00
|
|
|
{
|
|
|
|
id = ike_sa->get_id(ike_sa);
|
|
|
|
list->insert_last(list, id->clone(id));
|
|
|
|
}
|
|
|
|
}
|
|
|
|
enumerator->destroy(enumerator);
|
2009-09-22 12:32:52 +00:00
|
|
|
}
|
|
|
|
this->lock->unlock(this->lock);
|
2008-12-01 18:38:40 +00:00
|
|
|
|
2009-09-22 12:32:52 +00:00
|
|
|
while (list->remove_last(list, (void**)&id) == SUCCESS)
|
|
|
|
{
|
|
|
|
ike_sa = charon->ike_sa_manager->checkout(charon->ike_sa_manager, id);
|
|
|
|
id->destroy(id);
|
|
|
|
if (ike_sa)
|
2008-12-01 18:38:40 +00:00
|
|
|
{
|
2009-09-22 12:32:52 +00:00
|
|
|
DBG1(DBG_CFG, "resyncing IKE_SA");
|
|
|
|
if (ike_sa->rekey(ike_sa) != DESTROY_ME)
|
2008-12-01 18:38:40 +00:00
|
|
|
{
|
2009-09-22 12:32:52 +00:00
|
|
|
if (rekey_children(ike_sa) != DESTROY_ME)
|
2008-12-01 18:38:40 +00:00
|
|
|
{
|
2009-09-22 12:32:52 +00:00
|
|
|
charon->ike_sa_manager->checkin(
|
|
|
|
charon->ike_sa_manager, ike_sa);
|
|
|
|
continue;
|
2008-12-01 18:38:40 +00:00
|
|
|
}
|
|
|
|
}
|
2009-09-22 12:32:52 +00:00
|
|
|
charon->ike_sa_manager->checkin_and_destroy(
|
|
|
|
charon->ike_sa_manager, ike_sa);
|
2008-12-01 18:38:40 +00:00
|
|
|
}
|
|
|
|
}
|
2009-09-22 12:32:52 +00:00
|
|
|
list->destroy(list);
|
2008-12-01 18:38:40 +00:00
|
|
|
}
|
|
|
|
|
2009-09-22 15:10:25 +00:00
|
|
|
/**
|
|
|
|
* Implementation of listener_t.alert
|
|
|
|
*/
|
|
|
|
static bool alert_hook(private_ha_sync_segments_t *this, ike_sa_t *ike_sa,
|
|
|
|
alert_t alert, va_list args)
|
|
|
|
{
|
|
|
|
if (alert == ALERT_SHUTDOWN_SIGNAL)
|
|
|
|
{
|
|
|
|
int i;
|
|
|
|
|
|
|
|
for (i = 0; i < SEGMENTS_MAX; i++)
|
|
|
|
{
|
|
|
|
if (this->active & SEGMENTS_BIT(i))
|
|
|
|
{
|
|
|
|
deactivate(this, i, TRUE);
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
return TRUE;
|
|
|
|
}
|
|
|
|
|
2008-11-17 15:58:39 +00:00
|
|
|
/**
|
2008-11-28 15:45:17 +00:00
|
|
|
* Implementation of ha_sync_segments_t.destroy.
|
2008-11-17 15:58:39 +00:00
|
|
|
*/
|
2008-11-28 15:45:17 +00:00
|
|
|
static void destroy(private_ha_sync_segments_t *this)
|
2008-11-17 15:58:39 +00:00
|
|
|
{
|
2009-09-22 12:32:52 +00:00
|
|
|
this->lock->destroy(this->lock);
|
2008-11-17 15:58:39 +00:00
|
|
|
free(this);
|
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
|
|
|
* See header
|
|
|
|
*/
|
2009-09-22 12:53:03 +00:00
|
|
|
ha_sync_segments_t *ha_sync_segments_create(ha_sync_socket_t *socket,
|
2009-09-22 13:19:43 +00:00
|
|
|
ha_sync_kernel_t *kernel,
|
2009-09-22 12:53:03 +00:00
|
|
|
u_int count, segment_mask_t active)
|
2008-11-17 15:58:39 +00:00
|
|
|
{
|
2008-11-28 15:45:17 +00:00
|
|
|
private_ha_sync_segments_t *this = malloc_thing(private_ha_sync_segments_t);
|
2008-11-17 15:58:39 +00:00
|
|
|
|
2009-09-22 15:10:25 +00:00
|
|
|
memset(&this->public.listener, 0, sizeof(listener_t));
|
|
|
|
this->public.listener.alert = (bool(*)(listener_t*, ike_sa_t *, alert_t, va_list))alert_hook;
|
2009-09-22 12:33:38 +00:00
|
|
|
this->public.activate = (void(*)(ha_sync_segments_t*, u_int segment,bool))activate;
|
|
|
|
this->public.deactivate = (void(*)(ha_sync_segments_t*, u_int segment,bool))deactivate;
|
2008-12-01 18:38:40 +00:00
|
|
|
this->public.resync = (void(*)(ha_sync_segments_t*, u_int segment))resync;
|
2008-11-28 15:45:17 +00:00
|
|
|
this->public.destroy = (void(*)(ha_sync_segments_t*))destroy;
|
2008-11-17 15:58:39 +00:00
|
|
|
|
2009-09-22 12:33:38 +00:00
|
|
|
this->socket = socket;
|
2009-09-22 13:19:43 +00:00
|
|
|
this->kernel = kernel;
|
2009-09-22 12:32:52 +00:00
|
|
|
this->lock = rwlock_create(RWLOCK_TYPE_DEFAULT);
|
2009-09-22 12:53:03 +00:00
|
|
|
this->active = active;
|
|
|
|
this->segment_count = count;
|
2008-11-17 15:58:39 +00:00
|
|
|
|
|
|
|
return &this->public;
|
|
|
|
}
|
|
|
|
|