vici: Match identity with wildcards against remote ID in redirect command
[strongswan.git] / src / swanctl / commands / install.c
1 /*
2 * Copyright (C) 2014 Martin Willi
3 * Copyright (C) 2014 revosec AG
4 *
5 * This program is free software; you can redistribute it and/or modify it
6 * under the terms of the GNU General Public License as published by the
7 * Free Software Foundation; either version 2 of the License, or (at your
8 * option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
9 *
10 * This program is distributed in the hope that it will be useful, but
11 * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
12 * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
13 * for more details.
14 */
15
16 #include "command.h"
17
18 #include <errno.h>
19
20 static int manage_policy(vici_conn_t *conn, char *label)
21 {
22 vici_req_t *req;
23 vici_res_t *res;
24 command_format_options_t format = COMMAND_FORMAT_NONE;
25 char *arg, *child = NULL;
26 int ret = 0;
27
28 while (TRUE)
29 {
30 switch (command_getopt(&arg))
31 {
32 case 'h':
33 return command_usage(NULL);
34 case 'P':
35 format |= COMMAND_FORMAT_RAW;
36 /* fall through to raw */
37 case 'r':
38 format |= COMMAND_FORMAT_PRETTY;
39 continue;
40 case 'c':
41 child = arg;
42 continue;
43 case EOF:
44 break;
45 default:
46 return command_usage("invalid --%s option", label);
47 }
48 break;
49 }
50 req = vici_begin(label);
51 if (child)
52 {
53 vici_add_key_valuef(req, "child", "%s", child);
54 }
55 res = vici_submit(req, conn);
56 if (!res)
57 {
58 ret = errno;
59 fprintf(stderr, "%s request failed: %s\n", label, strerror(errno));
60 return ret;
61 }
62 if (format & COMMAND_FORMAT_RAW)
63 {
64 puts(label);
65 vici_dump(res, " reply", format & COMMAND_FORMAT_PRETTY, stdout);
66 }
67 else
68 {
69 if (streq(vici_find_str(res, "no", "success"), "yes"))
70 {
71 printf("%s completed successfully\n", label);
72 }
73 else
74 {
75 fprintf(stderr, "%s failed: %s\n",
76 label, vici_find_str(res, "", "errmsg"));
77 ret = 1;
78 }
79 }
80 vici_free_res(res);
81 return ret;
82 }
83
84 static int uninstall(vici_conn_t *conn)
85 {
86 return manage_policy(conn, "uninstall");
87 }
88
89 static int install(vici_conn_t *conn)
90 {
91 return manage_policy(conn, "install");
92 }
93
94 /**
95 * Register the uninstall command.
96 */
97 static void __attribute__ ((constructor))reg_uninstall()
98 {
99 command_register((command_t) {
100 uninstall, 'u', "uninstall", "uninstall a trap or shunt policy",
101 {"--child <name> [--raw|--pretty]"},
102 {
103 {"help", 'h', 0, "show usage information"},
104 {"child", 'c', 1, "CHILD_SA configuration to uninstall"},
105 {"raw", 'r', 0, "dump raw response message"},
106 {"pretty", 'P', 0, "dump raw response message in pretty print"},
107 }
108 });
109 }
110
111 /**
112 * Register install the command.
113 */
114 static void __attribute__ ((constructor))reg_install()
115 {
116 command_register((command_t) {
117 install, 'p', "install", "install a trap or shunt policy",
118 {"--child <name> [--raw|--pretty]"},
119 {
120 {"help", 'h', 0, "show usage information"},
121 {"child", 'c', 1, "CHILD_SA configuration to install"},
122 {"raw", 'r', 0, "dump raw response message"},
123 {"pretty", 'P', 0, "dump raw response message in pretty print"},
124 }
125 });
126 }