Added a hook to reset ESP sequence numbers
[strongswan.git] / src / conftest / hooks / reset_seq.c
1 /*
2 * Copyright (C) 2010 Martin Willi
3 * Copyright (C) 2010 revosec AG
4 *
5 * This program is free software; you can redistribute it and/or modify it
6 * under the terms of the GNU General Public License as published by the
7 * Free Software Foundation; either version 2 of the License, or (at your
8 * option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
9 *
10 * This program is distributed in the hope that it will be useful, but
11 * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
12 * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
13 * for more details.
14 */
15
16 #include "hook.h"
17
18 #include <linux/xfrm.h>
19 #include <unistd.h>
20 #include <errno.h>
21
22 #include <processing/jobs/callback_job.h>
23 #include <plugins/kernel_netlink/kernel_netlink_shared.h>
24
25 #define XFRM_RTA(nlh, x) ((struct rtattr*)(NLMSG_DATA(nlh) + NLMSG_ALIGN(sizeof(x))))
26
27 typedef struct private_reset_seq_t private_reset_seq_t;
28
29 /**
30 * Private data of an reset_seq_t object.
31 */
32 struct private_reset_seq_t {
33
34 /**
35 * Implements the hook_t interface.
36 */
37 hook_t hook;
38
39 /**
40 * Delay for reset
41 */
42 int delay;
43 };
44
45 /**
46 * Callback job
47 */
48 static job_requeue_t reset_cb(struct xfrm_usersa_id *data)
49 {
50 netlink_buf_t request;
51 struct nlmsghdr *hdr;
52 struct xfrm_aevent_id *id;
53 struct rtattr *rthdr;
54 struct xfrm_replay_state *replay;
55 struct sockaddr_nl addr;
56 int s, len;
57
58 DBG1(DBG_CFG, "resetting sequence number of SPI 0x%x", htonl(data->spi));
59
60 memset(&request, 0, sizeof(request));
61
62 hdr = (struct nlmsghdr*)request;
63 hdr->nlmsg_flags = NLM_F_REQUEST | NLM_F_ACK | NLM_F_REPLACE;
64 hdr->nlmsg_seq = 201;
65 hdr->nlmsg_pid = getpid();
66 hdr->nlmsg_type = XFRM_MSG_NEWAE;
67 hdr->nlmsg_len = NLMSG_LENGTH(sizeof(struct xfrm_aevent_id));
68
69 id = (struct xfrm_aevent_id*)NLMSG_DATA(hdr);
70 id->sa_id = *data;
71
72 rthdr = XFRM_RTA(hdr, struct xfrm_aevent_id);
73 rthdr->rta_type = XFRMA_REPLAY_VAL;
74 rthdr->rta_len = RTA_LENGTH(sizeof(struct xfrm_replay_state));
75 hdr->nlmsg_len += rthdr->rta_len;
76
77 replay = (struct xfrm_replay_state*)RTA_DATA(rthdr);
78
79 s = socket(AF_NETLINK, SOCK_RAW, NETLINK_XFRM);
80 if (s == -1)
81 {
82 DBG1(DBG_CFG, "opening XFRM socket failed: %s", strerror(errno));
83 return JOB_REQUEUE_NONE;
84 }
85 memset(&addr, 0, sizeof(addr));
86 addr.nl_family = AF_NETLINK;
87 len = sendto(s, hdr, hdr->nlmsg_len, 0,
88 (struct sockaddr*)&addr, sizeof(addr));
89 if (len != hdr->nlmsg_len)
90 {
91 DBG1(DBG_CFG, "sending XFRM aevent failed: %s", strerror(errno));
92 }
93 close(s);
94 return JOB_REQUEUE_NONE;
95 }
96
97 /**
98 * Schedule sequence number reset job
99 */
100 static void schedule_reset_job(private_reset_seq_t *this, host_t *dst,
101 u_int32_t spi)
102 {
103 struct xfrm_usersa_id *data;
104 chunk_t chunk;
105
106 INIT(data,
107 .spi = spi,
108 .family = dst->get_family(dst),
109 .proto = IPPROTO_ESP,
110 );
111
112 chunk = dst->get_address(dst);
113 memcpy(&data->daddr, chunk.ptr, min(chunk.len, sizeof(xfrm_address_t)));
114
115 lib->scheduler->schedule_job(lib->scheduler,
116 (job_t*)callback_job_create(
117 (void*)reset_cb, data, (void*)free, NULL),
118 this->delay);
119 }
120
121 METHOD(listener_t, child_updown, bool,
122 private_reset_seq_t *this, ike_sa_t *ike_sa, child_sa_t *child_sa,
123 bool up)
124 {
125 if (up)
126 {
127 schedule_reset_job(this, ike_sa->get_other_host(ike_sa),
128 child_sa->get_spi(child_sa, FALSE));
129 }
130 return TRUE;
131 }
132
133 METHOD(hook_t, destroy, void,
134 private_reset_seq_t *this)
135 {
136 free(this);
137 }
138
139 /**
140 * Create the IKE_AUTH fill hook
141 */
142 hook_t *reset_seq_hook_create(char *name)
143 {
144 private_reset_seq_t *this;
145
146 INIT(this,
147 .hook = {
148 .listener = {
149 .child_updown = _child_updown,
150 },
151 .destroy = _destroy,
152 },
153 .delay = conftest->test->get_int(conftest->test,
154 "hooks.%s.delay", 10, name),
155 );
156
157 return &this->hook;
158 }