017c058daf4b6ebc5f8c2a734d161faa7393f6ae
[strongswan.git] / src / charon / plugins / ha_sync / ha_sync_segments.c
1 /*
2 * Copyright (C) 2008 Martin Willi
3 * Hochschule fuer Technik Rapperswil
4 *
5 * This program is free software; you can redistribute it and/or modify it
6 * under the terms of the GNU General Public License as published by the
7 * Free Software Foundation; either version 2 of the License, or (at your
8 * option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
9 *
10 * This program is distributed in the hope that it will be useful, but
11 * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
12 * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
13 * for more details.
14 */
15
16 #include "ha_sync_segments.h"
17
18 #include <utils/mutex.h>
19 #include <utils/linked_list.h>
20
21 typedef u_int32_t u32;
22 typedef u_int8_t u8;
23
24 #include <linux/jhash.h>
25
26 #define MAX_SEGMENTS 16
27
28 typedef struct private_ha_sync_segments_t private_ha_sync_segments_t;
29
30 /**
31 * Private data of an ha_sync_segments_t object.
32 */
33 struct private_ha_sync_segments_t {
34
35 /**
36 * Public ha_sync_segments_t interface.
37 */
38 ha_sync_segments_t public;
39
40 /**
41 * read/write lock for segment manipulation
42 */
43 rwlock_t *lock;
44
45 /**
46 * Init value for jhash
47 */
48 u_int initval;
49
50 /**
51 * Total number of ClusterIP segments
52 */
53 u_int segment_count;
54
55 /**
56 * mask of active segments
57 */
58 u_int16_t active;
59 };
60
61 /**
62 * Check if a host address is in the CLUSTERIP segment
63 */
64 static bool in_segment(private_ha_sync_segments_t *this,
65 host_t *host, u_int segment)
66 {
67 if (host->get_family(host) == AF_INET)
68 {
69 unsigned long hash;
70 u_int32_t addr;
71
72 addr = *(u_int32_t*)host->get_address(host).ptr;
73 hash = jhash_1word(ntohl(addr), this->initval);
74
75 if ((((u_int64_t)hash * this->segment_count) >> 32) + 1 == segment)
76 {
77 return TRUE;
78 }
79 }
80 return FALSE;
81 }
82
83 /**
84 * Log currently active segments
85 */
86 static void log_segments(private_ha_sync_segments_t *this, bool activated,
87 u_int segment)
88 {
89 char buf[64] = "none", *pos = buf;
90 int i;
91 bool first = TRUE;
92
93 for (i = 0; i < this->segment_count; i++)
94 {
95 if (this->active & 0x01 << i)
96 {
97 if (first)
98 {
99 first = FALSE;
100 }
101 else
102 {
103 pos += snprintf(pos, buf + sizeof(buf) - pos, ",");
104 }
105 pos += snprintf(pos, buf + sizeof(buf) - pos, "%d", i+1);
106 }
107 }
108 DBG1(DBG_CFG, "HA sync segment %d %sactivated, now active: %s",
109 segment, activated ? "" : "de", buf);
110 }
111
112 /**
113 * Get the bit of the segment in the bitmask
114 */
115 static inline u_int16_t bit_of(u_int segment)
116 {
117 return 0x01 << (segment - 1);
118 }
119
120 /**
121 * Enable/Disable an an IKE_SA.
122 */
123 static void enable_disable(private_ha_sync_segments_t *this, u_int segment,
124 ike_sa_state_t old, ike_sa_state_t new, bool enable)
125 {
126 ike_sa_t *ike_sa;
127 enumerator_t *enumerator;
128 u_int i, limit;
129
130 this->lock->write_lock(this->lock);
131
132 if (segment == 0 || segment <= this->segment_count)
133 {
134 if (segment)
135 { /* loop once for single segment ... */
136 limit = segment + 1;
137 }
138 else
139 { /* or segment_count times for all segments */
140 limit = this->segment_count;
141 }
142 for (i = segment; i < limit; i++)
143 {
144 if (enable)
145 {
146 this->active |= bit_of(i);
147 }
148 else
149 {
150 this->active &= ~bit_of(i);
151 }
152 }
153 enumerator = charon->ike_sa_manager->create_enumerator(charon->ike_sa_manager);
154 while (enumerator->enumerate(enumerator, &ike_sa))
155 {
156 if (ike_sa->get_state(ike_sa) == old)
157 {
158 for (i = segment; i < limit; i++)
159 {
160 if (in_segment(this, ike_sa->get_other_host(ike_sa), i))
161 {
162 ike_sa->set_state(ike_sa, new);
163 }
164 }
165 }
166 }
167 enumerator->destroy(enumerator);
168
169 log_segments(this, enable, segment);
170 }
171
172 this->lock->unlock(this->lock);
173 }
174
175 /**
176 * Implementation of ha_sync_segments_t.activate
177 */
178 static void activate(private_ha_sync_segments_t *this, u_int segment)
179 {
180 return enable_disable(this, segment, IKE_PASSIVE, IKE_ESTABLISHED, TRUE);
181 }
182
183 /**
184 * Implementation of ha_sync_segments_t.deactivate
185 */
186 static void deactivate(private_ha_sync_segments_t *this, u_int segment)
187 {
188 return enable_disable(this, segment, IKE_ESTABLISHED, IKE_PASSIVE, FALSE);
189 }
190
191 /**
192 * Rekey all children of an IKE_SA
193 */
194 static status_t rekey_children(ike_sa_t *ike_sa)
195 {
196 iterator_t *iterator;
197 child_sa_t *child_sa;
198 status_t status = SUCCESS;
199
200 iterator = ike_sa->create_child_sa_iterator(ike_sa);
201 while (iterator->iterate(iterator, (void**)&child_sa))
202 {
203 DBG1(DBG_CFG, "resyncing CHILD_SA");
204 status = ike_sa->rekey_child_sa(ike_sa, child_sa->get_protocol(child_sa),
205 child_sa->get_spi(child_sa, TRUE));
206 if (status == DESTROY_ME)
207 {
208 break;
209 }
210 }
211 iterator->destroy(iterator);
212 return status;
213 }
214
215 /**
216 * Implementation of ha_sync_segments_t.resync
217 */
218 static void resync(private_ha_sync_segments_t *this, u_int segment)
219 {
220 ike_sa_t *ike_sa;
221 enumerator_t *enumerator;
222 linked_list_t *list;
223 ike_sa_id_t *id;
224 u_int16_t mask = bit_of(segment);
225
226 list = linked_list_create();
227 this->lock->read_lock(this->lock);
228
229 if (segment > 0 && segment <= this->segment_count && (this->active & mask))
230 {
231 this->active &= ~mask;
232
233 DBG1(DBG_CFG, "resyncing HA sync segment %d", segment);
234
235 /* we do the actual rekeying in a seperate loop to avoid rekeying
236 * an SA twice. */
237 enumerator = charon->ike_sa_manager->create_enumerator(
238 charon->ike_sa_manager);
239 while (enumerator->enumerate(enumerator, &ike_sa))
240 {
241 if (ike_sa->get_state(ike_sa) == IKE_ESTABLISHED &&
242 in_segment(this, ike_sa->get_other_host(ike_sa), segment))
243 {
244 id = ike_sa->get_id(ike_sa);
245 list->insert_last(list, id->clone(id));
246 }
247 }
248 enumerator->destroy(enumerator);
249 }
250 this->lock->unlock(this->lock);
251
252 while (list->remove_last(list, (void**)&id) == SUCCESS)
253 {
254 ike_sa = charon->ike_sa_manager->checkout(charon->ike_sa_manager, id);
255 id->destroy(id);
256 if (ike_sa)
257 {
258 DBG1(DBG_CFG, "resyncing IKE_SA");
259 if (ike_sa->rekey(ike_sa) != DESTROY_ME)
260 {
261 if (rekey_children(ike_sa) != DESTROY_ME)
262 {
263 charon->ike_sa_manager->checkin(
264 charon->ike_sa_manager, ike_sa);
265 continue;
266 }
267 }
268 charon->ike_sa_manager->checkin_and_destroy(
269 charon->ike_sa_manager, ike_sa);
270 }
271 }
272 list->destroy(list);
273 }
274
275 /**
276 * Implementation of ha_sync_segments_t.destroy.
277 */
278 static void destroy(private_ha_sync_segments_t *this)
279 {
280 this->lock->destroy(this->lock);
281 free(this);
282 }
283
284 /**
285 * See header
286 */
287 ha_sync_segments_t *ha_sync_segments_create()
288 {
289 private_ha_sync_segments_t *this = malloc_thing(private_ha_sync_segments_t);
290 enumerator_t *enumerator;
291 u_int segment;
292 char *str;
293
294 this->public.activate = (void(*)(ha_sync_segments_t*, u_int segment))activate;
295 this->public.deactivate = (void(*)(ha_sync_segments_t*, u_int segment))deactivate;
296 this->public.resync = (void(*)(ha_sync_segments_t*, u_int segment))resync;
297 this->public.destroy = (void(*)(ha_sync_segments_t*))destroy;
298
299 this->lock = rwlock_create(RWLOCK_TYPE_DEFAULT);
300 this->initval = 0;
301 this->active = 0;
302 this->segment_count = lib->settings->get_int(lib->settings,
303 "charon.plugins.ha_sync.segment_count", 1);
304 this->segment_count = min(this->segment_count, MAX_SEGMENTS);
305 str = lib->settings->get_str(lib->settings,
306 "charon.plugins.ha_sync.active_segments", "1");
307 enumerator = enumerator_create_token(str, ",", " ");
308 while (enumerator->enumerate(enumerator, &str))
309 {
310 segment = atoi(str);
311 if (segment > 0 && segment < MAX_SEGMENTS)
312 {
313 this->active |= bit_of(segment);
314 }
315 }
316 enumerator->destroy(enumerator);
317
318 return &this->public;
319 }
320