controller: Use the CHILD_SA unique_id to terminate CHILD_SAs
[strongswan.git] / src / conftest / actions.c
1 /*
2 * Copyright (C) 2010 Martin Willi
3 * Copyright (C) 2010 revosec AG
4 *
5 * This program is free software; you can redistribute it and/or modify it
6 * under the terms of the GNU General Public License as published by the
7 * Free Software Foundation; either version 2 of the License, or (at your
8 * option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
9 *
10 * This program is distributed in the hope that it will be useful, but
11 * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
12 * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
13 * for more details.
14 */
15
16 #include "actions.h"
17 #include "conftest.h"
18
19 #include <daemon.h>
20 #include <processing/jobs/callback_job.h>
21 #include <processing/jobs/rekey_ike_sa_job.h>
22 #include <processing/jobs/rekey_child_sa_job.h>
23 #include <processing/jobs/send_dpd_job.h>
24
25 typedef struct private_actions_t private_actions_t;
26
27 /**
28 * Private data of an actions_t object.
29 */
30 struct private_actions_t {
31
32 /**
33 * Public actions_t interface.
34 */
35 actions_t public;
36 };
37
38 /**
39 * Initiate a CHILD_SA
40 */
41 static job_requeue_t initiate(char *config)
42 {
43 peer_cfg_t *peer_cfg;
44 child_cfg_t *child_cfg = NULL, *current;
45 enumerator_t *enumerator;
46
47 peer_cfg = charon->backends->get_peer_cfg_by_name(charon->backends, config);
48 if (!peer_cfg)
49 {
50 DBG1(DBG_CFG, "initiating '%s' failed, config not found", config);
51 return JOB_REQUEUE_NONE;
52 }
53 enumerator = peer_cfg->create_child_cfg_enumerator(peer_cfg);
54 while (enumerator->enumerate(enumerator, &current))
55 {
56 if (streq(current->get_name(current), config))
57 {
58 child_cfg = current;
59 child_cfg->get_ref(child_cfg);
60 break;
61 }
62 }
63 enumerator->destroy(enumerator);
64 if (child_cfg)
65 {
66 DBG1(DBG_CFG, "initiating IKE_SA for CHILD_SA config '%s'", config);
67 charon->controller->initiate(charon->controller, peer_cfg, child_cfg,
68 NULL, NULL, 0);
69 }
70 else
71 {
72 DBG1(DBG_CFG, "initiating '%s' failed, CHILD_SA config not found",
73 config);
74 }
75
76 return JOB_REQUEUE_NONE;
77 }
78
79 /**
80 * Rekey an IKE_SA
81 */
82 static job_requeue_t rekey_ike(char *config)
83 {
84 enumerator_t *enumerator;
85 job_t *job = NULL;
86 ike_sa_t *ike_sa;
87
88 enumerator = charon->controller->create_ike_sa_enumerator(
89 charon->controller, TRUE);
90 while (enumerator->enumerate(enumerator, &ike_sa))
91 {
92 if (strcaseeq(config, ike_sa->get_name(ike_sa)))
93 {
94 job = (job_t*)rekey_ike_sa_job_create(ike_sa->get_id(ike_sa), FALSE);
95 break;
96 }
97 }
98 enumerator->destroy(enumerator);
99
100 if (job)
101 {
102 DBG1(DBG_CFG, "starting rekey of IKE_SA '%s'", config);
103 lib->processor->queue_job(lib->processor, job);
104 }
105 else
106 {
107 DBG1(DBG_CFG, "rekeying '%s' failed, IKE_SA not found", config);
108 }
109 return JOB_REQUEUE_NONE;
110 }
111
112 /**
113 * Rekey an CHILD_SA
114 */
115 static job_requeue_t rekey_child(char *config)
116 {
117 enumerator_t *enumerator, *children;
118 ike_sa_t *ike_sa;
119 child_sa_t *child_sa;
120 u_int32_t reqid = 0, spi = 0;
121 protocol_id_t proto = PROTO_ESP;
122
123 enumerator = charon->controller->create_ike_sa_enumerator(
124 charon->controller, TRUE);
125 while (enumerator->enumerate(enumerator, &ike_sa))
126 {
127 children = ike_sa->create_child_sa_enumerator(ike_sa);
128 while (children->enumerate(children, (void**)&child_sa))
129 {
130 if (streq(config, child_sa->get_name(child_sa)))
131 {
132 reqid = child_sa->get_reqid(child_sa);
133 proto = child_sa->get_protocol(child_sa);
134 spi = child_sa->get_spi(child_sa, TRUE);
135 break;
136 }
137 }
138 children->destroy(children);
139 }
140 enumerator->destroy(enumerator);
141 if (reqid)
142 {
143 DBG1(DBG_CFG, "starting rekey of CHILD_SA '%s'", config);
144 lib->processor->queue_job(lib->processor,
145 (job_t*)rekey_child_sa_job_create(reqid, proto, spi));
146 }
147 else
148 {
149 DBG1(DBG_CFG, "rekeying '%s' failed, CHILD_SA not found", config);
150 }
151 return JOB_REQUEUE_NONE;
152 }
153
154 /**
155 * Do a liveness check
156 */
157 static job_requeue_t liveness(char *config)
158 {
159 enumerator_t *enumerator;
160 job_t *job = NULL;
161 ike_sa_t *ike_sa;
162
163 enumerator = charon->controller->create_ike_sa_enumerator(
164 charon->controller, TRUE);
165 while (enumerator->enumerate(enumerator, &ike_sa))
166 {
167 if (strcaseeq(config, ike_sa->get_name(ike_sa)))
168 {
169 job = (job_t*)send_dpd_job_create(ike_sa->get_id(ike_sa));
170 break;
171 }
172 }
173 enumerator->destroy(enumerator);
174
175 if (job)
176 {
177 DBG1(DBG_CFG, "starting liveness check of IKE_SA '%s'", config);
178 lib->processor->queue_job(lib->processor, job);
179 }
180 else
181 {
182 DBG1(DBG_CFG, "liveness check for '%s' failed, IKE_SA not found", config);
183 }
184 return JOB_REQUEUE_NONE;
185 }
186
187 /**
188 * Close an IKE_SA with all CHILD_SAs
189 */
190 static job_requeue_t close_ike(char *config)
191 {
192 enumerator_t *enumerator;
193 ike_sa_t *ike_sa;
194 int id = 0;
195
196 enumerator = charon->controller->create_ike_sa_enumerator(
197 charon->controller, TRUE);
198 while (enumerator->enumerate(enumerator, &ike_sa))
199 {
200 if (strcaseeq(config, ike_sa->get_name(ike_sa)))
201 {
202 id = ike_sa->get_unique_id(ike_sa);
203 break;
204 }
205 }
206 enumerator->destroy(enumerator);
207 if (id)
208 {
209 DBG1(DBG_CFG, "closing IKE_SA '%s'", config);
210 charon->controller->terminate_ike(charon->controller, id, NULL, NULL, 0);
211 }
212 else
213 {
214 DBG1(DBG_CFG, "unable to close IKE_SA '%s', not found", config);
215 }
216 return JOB_REQUEUE_NONE;
217 }
218
219 /**
220 * Close a CHILD_SAs
221 */
222 static job_requeue_t close_child(char *config)
223 {
224 enumerator_t *enumerator, *children;
225 ike_sa_t *ike_sa;
226 child_sa_t *child_sa;
227 int id = 0;
228
229 enumerator = charon->controller->create_ike_sa_enumerator(
230 charon->controller, TRUE);
231 while (enumerator->enumerate(enumerator, &ike_sa))
232 {
233
234 children = ike_sa->create_child_sa_enumerator(ike_sa);
235 while (children->enumerate(children, (void**)&child_sa))
236 {
237 if (streq(config, child_sa->get_name(child_sa)))
238 {
239 id = child_sa->get_unique_id(child_sa);
240 break;
241 }
242 }
243 children->destroy(children);
244 }
245 enumerator->destroy(enumerator);
246 if (id)
247 {
248 DBG1(DBG_CFG, "closing CHILD_SA '%s'", config);
249 charon->controller->terminate_child(charon->controller, id,
250 NULL, NULL, 0);
251 }
252 else
253 {
254 DBG1(DBG_CFG, "unable to close CHILD_SA '%s', not found", config);
255 }
256 return JOB_REQUEUE_NONE;
257 }
258
259 /**
260 * Load a single action
261 */
262 static void load_action(settings_t *settings, char *action)
263 {
264 static struct {
265 char *name;
266 callback_job_cb_t cb;
267 } actions[] = {
268 {"initiate", (void*)initiate},
269 {"rekey_ike", (void*)rekey_ike},
270 {"rekey_child", (void*)rekey_child},
271 {"liveness", (void*)liveness},
272 {"close_ike", (void*)close_ike},
273 {"close_child", (void*)close_child},
274 };
275 bool found = FALSE;
276 int i;
277
278 for (i = 0; i < countof(actions); i++)
279 {
280 if (strncaseeq(actions[i].name, action, strlen(actions[i].name)))
281 {
282 int delay;
283 char *config;
284
285 found = TRUE;
286 delay = settings->get_int(settings, "actions.%s.delay", 0, action);
287 config = settings->get_str(settings, "actions.%s.config",
288 NULL, action);
289 if (!config)
290 {
291 DBG1(DBG_CFG, "no config defined for action '%s'", action);
292 break;
293 }
294 lib->scheduler->schedule_job(lib->scheduler,
295 (job_t*)callback_job_create(actions[i].cb, config, NULL, NULL),
296 delay);
297 }
298 }
299 if (!found)
300 {
301 DBG1(DBG_CFG, "unknown action '%s', skipped", action);
302 }
303 }
304
305 /**
306 * Load configured actions
307 */
308 static void load_actions(settings_t *settings)
309 {
310 enumerator_t *enumerator;
311 char *action;
312
313 enumerator = settings->create_section_enumerator(settings, "actions");
314 while (enumerator->enumerate(enumerator, &action))
315 {
316 load_action(settings, action);
317 }
318 enumerator->destroy(enumerator);
319 }
320
321 METHOD(actions_t, destroy, void,
322 private_actions_t *this)
323 {
324 free(this);
325 }
326
327 /**
328 * See header
329 */
330 actions_t *actions_create()
331 {
332 private_actions_t *this;
333
334 INIT(this,
335 .public = {
336 .destroy = _destroy,
337 },
338 );
339
340 load_actions(conftest->test);
341
342 return &this->public;
343 }