3 years agounit-tests: Make IKE and ESP proposals configurable
Tobias Brunner [Tue, 24 May 2016 12:14:05 +0000 (14:14 +0200)]
unit-tests: Make IKE and ESP proposals configurable

3 years agounit-tests: Add tests for CHILD_SA rekeying/deletion collisions
Tobias Brunner [Sat, 21 May 2016 10:22:06 +0000 (12:22 +0200)]
unit-tests: Add tests for CHILD_SA rekeying/deletion collisions

3 years agounit-tests: Add asserts against job scheduling
Tobias Brunner [Sat, 21 May 2016 09:12:16 +0000 (11:12 +0200)]
unit-tests: Add asserts against job scheduling

3 years agoikev2: Use CHILD_REKEYED for replaced CHILD_SAs after rekeying
Tobias Brunner [Fri, 20 May 2016 08:49:21 +0000 (10:49 +0200)]
ikev2: Use CHILD_REKEYED for replaced CHILD_SAs after rekeying

This allows handling collisions better, in particular with deletions.

3 years agounit-tests: Add asserts against task queues of IKE_SAs
Tobias Brunner [Thu, 19 May 2016 17:25:12 +0000 (19:25 +0200)]
unit-tests: Add asserts against task queues of IKE_SAs

3 years agochild-rekey: Use more appropriate error notifies if CHILD_SA is not found or getting...
Tobias Brunner [Thu, 19 May 2016 15:23:32 +0000 (17:23 +0200)]
child-rekey: Use more appropriate error notifies if CHILD_SA is not found or getting deleted

These are the notifies we should return according to RFC 7296.

3 years agochild-rekey: Recreate the CHILD_SA if we receive a CHILD_SA_NOT_FOUND notify
Tobias Brunner [Thu, 19 May 2016 13:31:02 +0000 (15:31 +0200)]
child-rekey: Recreate the CHILD_SA if we receive a CHILD_SA_NOT_FOUND notify

3 years agochild-create: Handle TEMPORARY_FAILURE notify as failure
Tobias Brunner [Thu, 19 May 2016 13:06:27 +0000 (15:06 +0200)]
child-create: Handle TEMPORARY_FAILURE notify as failure

We will later add code to retry creating the CHILD_SA if we are not
rekeying.  Rekeying is already rescheduled as with any other errors.

3 years agounit-tests: Add unit tests for basic CHILD_SA rekeying
Tobias Brunner [Tue, 17 May 2016 18:07:09 +0000 (20:07 +0200)]
unit-tests: Add unit tests for basic CHILD_SA rekeying

3 years agounit-tests: Add asserts against ike|child_rekey hooks
Tobias Brunner [Wed, 18 May 2016 15:16:29 +0000 (17:16 +0200)]
unit-tests: Add asserts against ike|child_rekey hooks

3 years agounit-tests: Match in and outbound SPIs in SA asserts
Tobias Brunner [Wed, 18 May 2016 15:15:12 +0000 (17:15 +0200)]
unit-tests: Match in and outbound SPIs in SA asserts

Since we use unique sequential SPIs that should be OK.

3 years agounit-tests: Register nonce generator and make first nonce byte configurable
Tobias Brunner [Tue, 17 May 2016 18:06:24 +0000 (20:06 +0200)]
unit-tests: Register nonce generator and make first nonce byte configurable

3 years agocrypto-factory: Stop after successfully creating one nonce generator
Tobias Brunner [Tue, 17 May 2016 18:05:06 +0000 (20:05 +0200)]
crypto-factory: Stop after successfully creating one nonce generator

Fixes: e2fc09c186c3 ("Add nonce generator interface")

3 years agounit-tests: Add mock nonce generator
Tobias Brunner [Tue, 17 May 2016 18:03:59 +0000 (20:03 +0200)]
unit-tests: Add mock nonce generator

We don't make the full nonces configurable but only the first byte,
which should be enough to force a nonce to be smaller than others.

3 years agounit-tests: Make message asserts more flexible
Tobias Brunner [Tue, 17 May 2016 11:49:58 +0000 (13:49 +0200)]
unit-tests: Make message asserts more flexible

3 years agounit-tests: Add another CHILD_SA delete collision
Tobias Brunner [Mon, 16 May 2016 17:35:14 +0000 (19:35 +0200)]
unit-tests: Add another CHILD_SA delete collision

3 years agounit-tests: Register mock DH implementation as static plugin feature
Tobias Brunner [Fri, 13 May 2016 10:16:45 +0000 (12:16 +0200)]
unit-tests: Register mock DH implementation as static plugin feature

3 years agounit-tests: Add mock DH implementation that's basically a noop
Tobias Brunner [Fri, 13 May 2016 10:12:51 +0000 (12:12 +0200)]
unit-tests: Add mock DH implementation that's basically a noop

If the openssl plugin is built DH isn't that much of an overhead as
ecp256 is used, but the default MODP group is now modp3072.

3 years agounit-tests: Make IKE SPIs predictable
Tobias Brunner [Fri, 13 May 2016 06:50:17 +0000 (08:50 +0200)]
unit-tests: Make IKE SPIs predictable

3 years agounit-tests: Call methods on IKE_SAs in their context
Tobias Brunner [Fri, 13 May 2016 06:44:13 +0000 (08:44 +0200)]
unit-tests: Call methods on IKE_SAs in their context

3 years agounit-tests: Add a unit test for CHILD_SA DELETE collisions
Tobias Brunner [Thu, 12 May 2016 15:25:42 +0000 (17:25 +0200)]
unit-tests: Add a unit test for CHILD_SA DELETE collisions

3 years agochild-delete: Remove unnecessary call to destroy_child_sa()
Tobias Brunner [Thu, 12 May 2016 10:22:35 +0000 (12:22 +0200)]
child-delete: Remove unnecessary call to destroy_child_sa()

Generally, we will not find the CHILD_SA by searching for it with the
outbound SPI (the initiator of the DELETE sent its inbound SPI) - and if
we found a CHILD_SA it would most likely be the wrong one (one in which
we used the same inbound SPI as the peer used for the one it deletes).

And we don't actually want to destroy the CHILD_SA at this point as we
know we already initiated a DELETE ourselves, which means that task
still has a reference to it and will destroy the CHILD_SA when it
receives the response from the other peer.

3 years agounit-tests: Add asserts against hooks on listener_t and messages captured there
Tobias Brunner [Fri, 13 May 2016 18:48:44 +0000 (20:48 +0200)]
unit-tests: Add asserts against hooks on listener_t and messages captured there

3 years agounit-tests: Add asserts against SAs (e.g. their states)
Tobias Brunner [Thu, 12 May 2016 15:59:42 +0000 (17:59 +0200)]
unit-tests: Add asserts against SAs (e.g. their states)

3 years agounit-tests: Add separate test runner to test IKEv2 exchanges
Tobias Brunner [Fri, 13 May 2016 09:57:11 +0000 (11:57 +0200)]
unit-tests: Add separate test runner to test IKEv2 exchanges

This allows proper initialization of the daemon and the helper object.

3 years agounit-tests: Add helper class/object to test IKE exchanges
Tobias Brunner [Thu, 12 May 2016 15:03:44 +0000 (17:03 +0200)]
unit-tests: Add helper class/object to test IKE exchanges

3 years agounit-tests: Add mock kernel_ipsec_t implementation for unit tests
Tobias Brunner [Thu, 12 May 2016 14:14:03 +0000 (16:14 +0200)]
unit-tests: Add mock kernel_ipsec_t implementation for unit tests

Provides predictable sequential SPIs.

3 years agounit-tests: Add mock sender_t implementation for unit testing
Tobias Brunner [Thu, 12 May 2016 13:33:44 +0000 (15:33 +0200)]
unit-tests: Add mock sender_t implementation for unit testing

This allows to retrieve packets sent by an IKE_SA and pass it to another
IKE_SA directly via process_message().

3 years agounit-tests: Defining TESTS_RUNNERS allows to only run specific test runners
Tobias Brunner [Thu, 12 May 2016 12:30:54 +0000 (14:30 +0200)]
unit-tests: Defining TESTS_RUNNERS allows to only run specific test runners

3 years agounit-tests: Don't unload plugins before calling libcharon_deinit()
Tobias Brunner [Thu, 12 May 2016 11:49:11 +0000 (13:49 +0200)]
unit-tests: Don't unload plugins before calling libcharon_deinit()

libcharon_deinit() already calls all the functions we called manually.
Unloading the plugins will not work if charon->initialize() is called
as charon's static plugin features would already be unloaded before the
destroyed members are accessed in destroy() to flush them.

3 years agokernel-netlink: Don't set replay window for outbound SAs
Tobias Brunner [Fri, 17 Jun 2016 12:56:37 +0000 (14:56 +0200)]
kernel-netlink: Don't set replay window for outbound SAs

It's not necessary and might waste memory.  However, if ESN is used we set
the window to 1 as the kernel rejects the attribute otherwise.

3 years agokernel-pfkey: Only set the replay window for inbound SAs
Tobias Brunner [Fri, 17 Jun 2016 12:52:11 +0000 (14:52 +0200)]
kernel-pfkey: Only set the replay window for inbound SAs

It is not necessary for outbound SAs and might waste memory when large
window sizes are used.

3 years agotesting: Fix race in tnc/tnccs-20-pdp-pt-tls scenario
Tobias Brunner [Fri, 17 Jun 2016 09:18:25 +0000 (11:18 +0200)]
testing: Fix race in tnc/tnccs-20-pdp-pt-tls scenario

aacf84d837e7 ("testing: Add expect-connection calls for all tests and
hosts") removed the expect-connection call for the non-existing aaa
connection.  However, because the credentials were loaded asynchronously
via start-script the clients might have been connecting when the secrets
were not yet loaded.  As `swanctl --load-creds` is a synchronous call
this change avoids that issue without having to add a sleep or failing
expect-connection call.

3 years agodaemon: Don't hold settings lock while executing start/stop scripts
Tobias Brunner [Fri, 17 Jun 2016 08:19:37 +0000 (10:19 +0200)]
daemon: Don't hold settings lock while executing start/stop scripts

If a called script interacts with the daemon or one of its plugins
another thread might have to acquire the write lock (e.g. to configure a
fallback or set a value).  Holding the read lock prevents that, potentially
resulting in a deadlock.

3 years agotesting: Use TLS 1.2 in RADIUS test cases
Tobias Brunner [Thu, 26 Nov 2015 18:06:41 +0000 (19:06 +0100)]
testing: Use TLS 1.2 in RADIUS test cases

This took a while as in the OpenSSL package shipped with Debian and on which
our FIPS-enabled package is based, the function SSL_export_keying_material(),
which is used by FreeRADIUS to derive the MSK, did not use the correct digest
to calculate the result when TLS 1.2 was used.  This caused IKE to fail with
"verification of AUTH payload with EAP MSK failed".  The fix was only
backported to jessie recently.

3 years agotesting: Update FreeRADIUS to 2.2.8
Tobias Brunner [Thu, 26 Nov 2015 17:48:43 +0000 (18:48 +0100)]
testing: Update FreeRADIUS to 2.2.8

While this is not the latest 2.x release it is the latest in /old.

Upgrading to 3.0 might be possible, not sure if the TNC-FHH patches could
be easily updated, though.  Upgrading to 3.1 will definitely not be possible
directly as that version removes the EAP-TNC module.  So we'd first have to
get rid of the TNC-FHH stuff.

3 years agoRevert "configure: Cache result of pthread_condattr_setclock() check"
Tobias Brunner [Fri, 17 Jun 2016 13:04:17 +0000 (15:04 +0200)]
Revert "configure: Cache result of pthread_condattr_setclock() check"

This reverts commit 8d79bfa8318ddd1b9b863241fe0e637be73af5f4 as it does
not provide any advantage over setting ac_cv_func_pthread_condattr_setclock=no.

References #1502.

3 years agoconfigure: Cache result of pthread_condattr_setclock() check
Tobias Brunner [Thu, 16 Jun 2016 15:57:37 +0000 (17:57 +0200)]
configure: Cache result of pthread_condattr_setclock() check

Even if not using caching when running the configure script (-C) this
allows pre-defining the result by setting the environment variable
before/while running the script.

As the check requires running a test program this might be helpful
when cross-compiling to disable using monotonic time if
pthread_condattr_setclock() is defined but not actually usable with

References #1502.

3 years agoconfigure: Fix typo in pthread_condattr_setclock() check
Tobias Brunner [Thu, 16 Jun 2016 15:19:10 +0000 (17:19 +0200)]
configure: Fix typo in pthread_condattr_setclock() check

3 years agoquick-mode: Fix reporting lifebytes if lifetime is configured
Tobias Brunner [Wed, 15 Jun 2016 15:43:55 +0000 (17:43 +0200)]
quick-mode: Fix reporting lifebytes if lifetime is configured

3 years agoload-tester: Fix load-tester on platforms where plain `char` is signed
Tobias Brunner [Fri, 17 Jun 2016 08:22:25 +0000 (10:22 +0200)]
load-tester: Fix load-tester on platforms where plain `char` is signed

fgetc() returns an int and EOF is usually -1 so when this gets casted to
a char the result depends on whether `char` means `signed char` or
`unsigned char` (the C standard does not specify it).  If it is unsigned
then its value is 0xff so the comparison with EOF will fail as that is an
implicit signed int.

3 years agotesting: Fix firewall rule on alice in tnc/tnccs-20-pdp-pt-tls scenario
Tobias Brunner [Fri, 17 Jun 2016 08:22:03 +0000 (10:22 +0200)]
testing: Fix firewall rule on alice in tnc/tnccs-20-pdp-pt-tls scenario

3 years agoMerge branch 'testing-jessie'
Tobias Brunner [Thu, 16 Jun 2016 14:28:51 +0000 (16:28 +0200)]
Merge branch 'testing-jessie'

Updates the default Debian image used for the test environment from wheezy
to jessie.  Also adds a script that allows chrooting to an image (base,
root or one of the guests).  In pretty much all test scenarios
expect-connection is used to make test runs more reliable.

Fixes #1382.

3 years agotesting: Build hostapd from sources
Tobias Brunner [Wed, 15 Jun 2016 16:19:23 +0000 (18:19 +0200)]
testing: Build hostapd from sources

There is a bug (fix at [1]) in hostapd 2.1-2.3 that let it crash when used
with the wired driver.  The package in jessie (and sid) is affected, so we
build it from sources (same, older, version as wpa_supplicant).


3 years agotesting: Update download URL for wpa_supplicant
Tobias Brunner [Wed, 15 Jun 2016 15:42:28 +0000 (17:42 +0200)]
testing: Update download URL for wpa_supplicant

3 years agotesting: Wait for packets to be processed by tcpdump
Tobias Brunner [Tue, 14 Jun 2016 18:41:43 +0000 (20:41 +0200)]
testing: Wait for packets to be processed by tcpdump

Sometimes tcpdump fails to process all packets during the short running
time of a scenario:

0 packets captured
18 packets received by filter
0 packets dropped by kernel

So 18 packets were captured by libpcap but tcpdump did not yet process
and print them.

This tries to use --immediate-mode if supported by tcpdump (the one
currently in jessie or wheezy does not, but the one in jessie-backports
does), which disables the buffering in libpcap.

However, even with immediate mode there are cases where it takes a while
longer for all packets to get processed.  And without it we also need a
workaround (even though the version in wheezy actually works fine).
That's why there now is a loop checking for differences in captured vs.
received packets.  There are actually cases where these numbers are not
equal but we still captured all packets we're interested in, so we abort
after 1s of retrying.  But sometimes it could still happen that packets
we expected got lost somewhere ("packets dropped by kernel" is not
always 0 either).

3 years agotesting: Fix expect-connection for tkm tests
Tobias Brunner [Thu, 16 Jun 2016 12:35:26 +0000 (14:35 +0200)]
testing: Fix expect-connection for tkm tests

We don't use swanctl there but there is no load statement either.

3 years agotesting: Add expect-connection calls for all tests and hosts
Tobias Brunner [Tue, 14 Jun 2016 18:41:14 +0000 (20:41 +0200)]
testing: Add expect-connection calls for all tests and hosts

There are some exceptions (e.g. those that use auto=start or p2pnat).

3 years agotesting: Update test scenarios for Debian jessie
Tobias Brunner [Tue, 14 Jun 2016 16:58:12 +0000 (18:58 +0200)]
testing: Update test scenarios for Debian jessie

The main difference is that ping now reports icmp_seq instead of
icmp_req, so we match for icmp_.eq, which works with both releases.

tcpdump now also reports port 4500 as ipsec-nat-t.

3 years agolibimcv: Add Debian 8.5 to database
Tobias Brunner [Tue, 14 Jun 2016 13:40:24 +0000 (15:40 +0200)]
libimcv: Add Debian 8.5 to database

3 years agotesting: Fix posttest.dat for ikev2/rw-dnssec scenario
Tobias Brunner [Tue, 8 Dec 2015 17:14:32 +0000 (18:14 +0100)]
testing: Fix posttest.dat for ikev2/rw-dnssec scenario

3 years agotesting: Make sure tcpdump is actually terminated before analyzing/collecting logs
Tobias Brunner [Tue, 8 Dec 2015 15:16:51 +0000 (16:16 +0100)]
testing: Make sure tcpdump is actually terminated before analyzing/collecting logs

3 years agotesting: Correctly dis-/enable services with systemd
Tobias Brunner [Tue, 8 Dec 2015 17:15:19 +0000 (18:15 +0100)]
testing: Correctly dis-/enable services with systemd

3 years agotesting: Install packages like the FIPS-enabled OpenSSL from a custom apt repo
Tobias Brunner [Tue, 8 Dec 2015 14:22:15 +0000 (15:22 +0100)]
testing: Install packages like the FIPS-enabled OpenSSL from a custom apt repo

3 years agotesting: Update base image to Debian jessie
Tobias Brunner [Fri, 20 Nov 2015 16:50:29 +0000 (17:50 +0100)]
testing: Update base image to Debian jessie

Several packages got renamed/updated, libgcrypt was apparently installed
by default previously.

Since most libraries changed we have to completely rebuild all the tools
installed in the root image.  We currently don't provide a clean target in
the recipes, and even if we did we'd have to track which base image we
last built for.  It's easier to just use a different build directory for
each base image, at the cost of some additional disk space (if not manually
cleaned).  However, that's also the case when updating kernel or
software versions.

3 years agotesting: Update 4.x kernel configs to be compatible with Debian 8/systemd
Tobias Brunner [Tue, 24 Nov 2015 16:28:49 +0000 (17:28 +0100)]
testing: Update 4.x kernel configs to be compatible with Debian 8/systemd

3 years agotesting: Add root to fstab
Tobias Brunner [Tue, 24 Nov 2015 17:33:57 +0000 (18:33 +0100)]
testing: Add root to fstab

This seems to be required for systemd to remount it.

3 years agotesting: Update Apache config for newer Debian releases
Tobias Brunner [Tue, 24 Nov 2015 17:32:23 +0000 (18:32 +0100)]
testing: Update Apache config for newer Debian releases

It is still compatible with the current release as the config in
sites-available will be ignored, while conf-enabled does not exist and
is not included in the main config.

3 years agotesting: Explicitly enable RC4 in SSH server config
Tobias Brunner [Tue, 24 Nov 2015 16:26:16 +0000 (17:26 +0100)]
testing: Explicitly enable RC4 in SSH server config

Newer OpenSSH versions disable this by default because it's unsafe.
Since this is not relevant for our use case we enable it due to its

3 years agotesting: Add script to chroot into an image
Tobias Brunner [Tue, 24 Nov 2015 10:08:57 +0000 (11:08 +0100)]
testing: Add script to chroot into an image

If changes are made to the base or root image the images depending on
these have to be rebuilt.

3 years agotesting: Add a patch to tnc-fhh that avoids building the tncsim package
Tobias Brunner [Fri, 20 Nov 2015 16:51:54 +0000 (17:51 +0100)]
testing: Add a patch to tnc-fhh that avoids building the tncsim package

This sub-package does not build on Debian jessie.

3 years agotesting: Don't attempt to stop services when building base image
Tobias Brunner [Fri, 20 Nov 2015 16:42:55 +0000 (17:42 +0100)]
testing: Don't attempt to stop services when building base image

Unlike `apt-get install` in a chroot debootstrap does not seem to start
the services but stopping them might cause problems if they were running
outside the chroot.

3 years agoleak-detective: Make sure to actually call malloc() from calloc() hook
Tobias Brunner [Wed, 15 Jun 2016 09:22:04 +0000 (11:22 +0200)]
leak-detective: Make sure to actually call malloc() from calloc() hook

Newer versions of GCC are too "smart" and replace a call to malloc(X)
followed by a call to memset(0,X) with a call co calloc(), which obviously
results in an infinite loop when it does that in our own calloc()
implementation.  Using `volatile` for the variable storing the total size
prevents the optimization and we actually call malloc().

3 years agoleak-detective: Whitelist __fprintf_chk as seen on newer systems
Tobias Brunner [Wed, 15 Jun 2016 09:21:16 +0000 (11:21 +0200)]
leak-detective: Whitelist __fprintf_chk as seen on newer systems

3 years agoconfigure: Check for and explicitly link against -latomic
Martin Willi [Wed, 8 Jun 2016 12:46:35 +0000 (14:46 +0200)]
configure: Check for and explicitly link against -latomic

Some C libraries, such as uClibc, require an explicit link for some atomic
functions. Check for any libatomic, and explcily link it.

3 years agotesting: Fix scenarios that check /etc/resolv.conf
Tobias Brunner [Mon, 13 Jun 2016 14:18:38 +0000 (16:18 +0200)]
testing: Fix scenarios that check /etc/resolv.conf

3 years agoandroid: Catch exception if numbers are too large for Integer
Tobias Brunner [Mon, 13 Jun 2016 14:12:17 +0000 (16:12 +0200)]
android: Catch exception if numbers are too large for Integer

3 years agoandroid: Use non-aliased cipher identifiers
Tobias Brunner [Mon, 13 Jun 2016 08:37:17 +0000 (10:37 +0200)]
android: Use non-aliased cipher identifiers

Some of these are also understood by BoringSSL.

Fixes #1510.

3 years agoandroid: Update Gradle plugin
Tobias Brunner [Mon, 13 Jun 2016 08:19:13 +0000 (10:19 +0200)]
android: Update Gradle plugin

3 years agoandroid: Fix signature of get_nexthop()
Tobias Brunner [Mon, 13 Jun 2016 08:18:45 +0000 (10:18 +0200)]
android: Fix signature of get_nexthop()

3 years agoresolve: Add refcounting for installed DNS servers
Tobias Brunner [Wed, 8 Jun 2016 17:43:13 +0000 (19:43 +0200)]
resolve: Add refcounting for installed DNS servers

This fixes DNS server installation if make-before-break reauthentication
is used as there the new SA and DNS server is installed before it then
is removed again when the old IKE_SA is torn down.

3 years agoresolve: Use process abstraction when calling resolvconf
Tobias Brunner [Tue, 7 Jun 2016 14:51:04 +0000 (16:51 +0200)]
resolve: Use process abstraction when calling resolvconf

This allows us to capture output written to stderr/stdout.

3 years agoresolve: Make sure to clean up if calling resolvconf failed
Tobias Brunner [Tue, 7 Jun 2016 13:58:05 +0000 (15:58 +0200)]
resolve: Make sure to clean up if calling resolvconf failed

If running resolvconf fails handle() fails release() is not called, which
might leave an interface file on the system (or depending on which script
called by resolvconf actually failed even the installed DNS server).

3 years agoMerge branch 'interface-for-routes'
Tobias Brunner [Fri, 10 Jun 2016 16:15:42 +0000 (18:15 +0200)]
Merge branch 'interface-for-routes'

Changes how the interface for routes installed with policies is
determined.  In most cases we now use the interface over which we reach the
other peer, not the interface on which the local address (or the source IP) is
installed.  However, that might be the same interface depending on the
configuration (i.e. in practice there will often not be a change).

Routes are not installed anymore for drop policies and for policies with
protocol/port selectors.

Fixes #809, #824, #1347.

3 years agokernel-pfroute: Return interface to reach destination from get_nexthop()
Tobias Brunner [Fri, 10 Jun 2016 15:13:22 +0000 (17:13 +0200)]
kernel-pfroute: Return interface to reach destination from get_nexthop()

3 years agokernel-pfkey: Install routes with OUT policies
Tobias Brunner [Fri, 10 Jun 2016 08:30:00 +0000 (10:30 +0200)]
kernel-pfkey: Install routes with OUT policies

3 years agokernel-netlink: Install routes with OUT policies
Tobias Brunner [Fri, 10 Jun 2016 08:10:09 +0000 (10:10 +0200)]
kernel-netlink: Install routes with OUT policies

This is the direction we actually need routes in and makes the code
easier to read.

3 years agokernel-pfkey: Don't install routes for drop policies and if protocol/ports are in...
Tobias Brunner [Thu, 9 Jun 2016 13:46:32 +0000 (15:46 +0200)]
kernel-pfkey: Don't install routes for drop policies and if protocol/ports are in the selector

3 years agokernel-netlink: Don't install routes for drop policies and if protocol/ports are...
Tobias Brunner [Thu, 9 Jun 2016 13:38:37 +0000 (15:38 +0200)]
kernel-netlink: Don't install routes for drop policies and if protocol/ports are in the selector

We don't need them for drop policies and they might even mess with other
routes we install.  Routes for policies with protocol/ports in the
selector will always be too broad and might conflict with other routes
we install.

3 years agokernel-pfkey: Also use interface returned by get_nexthop() for IPsec policies
Tobias Brunner [Mon, 6 Jun 2016 14:20:34 +0000 (16:20 +0200)]
kernel-pfkey: Also use interface returned by get_nexthop() for IPsec policies

An exception is if the local address is virtual, in which case we want
the route to be via TUN device.

3 years agokernel-netlink: Also use interface returned by get_nexthop() for IPsec policies
Tobias Brunner [Mon, 6 Jun 2016 14:01:43 +0000 (16:01 +0200)]
kernel-netlink: Also use interface returned by get_nexthop() for IPsec policies

3 years agokernel-pfkey: Use interface to next hop for shunt policies
Tobias Brunner [Fri, 11 Mar 2016 18:17:03 +0000 (19:17 +0100)]
kernel-pfkey: Use interface to next hop for shunt policies

3 years agokernel-netlink: Use interface to next hop for shunt policies
Tobias Brunner [Fri, 11 Mar 2016 18:09:54 +0000 (19:09 +0100)]
kernel-netlink: Use interface to next hop for shunt policies

Using the source address to determine the interface is not correct for
net-to-net shunts between two interfaces on which the host has IP addresses
for each subnet.

3 years agokernel-netlink: Return outbound interface in get_nexthop()
Tobias Brunner [Fri, 11 Mar 2016 18:07:10 +0000 (19:07 +0100)]
kernel-netlink: Return outbound interface in get_nexthop()

3 years agokernel-net: Let get_nexthop() return an optional interface name
Tobias Brunner [Fri, 11 Mar 2016 17:54:31 +0000 (18:54 +0100)]
kernel-net: Let get_nexthop() return an optional interface name

The returned name should be the interface over which the destination
address/net is reachable.

3 years agokernel-interface: Always set `vip` if get_address_by_ts() returns successfully
Tobias Brunner [Fri, 10 Jun 2016 11:52:30 +0000 (13:52 +0200)]
kernel-interface: Always set `vip` if get_address_by_ts() returns successfully

3 years agokernel-netlink: Let only a single thread work on a specific policy
Tobias Brunner [Wed, 25 May 2016 10:15:38 +0000 (12:15 +0200)]
kernel-netlink: Let only a single thread work on a specific policy

Other threads are free to add/update/delete other policies.

This tries to prevent race conditions caused by releasing the mutex while
sending messages to the kernel.  For instance, if break-before-make
reauthentication is used and one thread on the responder is delayed in
deleting the policies that another thread is concurrently adding for the
new SA.  This could have resulted in no policies being installed

Fixes #1400.

3 years agokernel-netlink: Add priority and refcount to policy log
Tobias Brunner [Fri, 27 May 2016 15:31:04 +0000 (17:31 +0200)]
kernel-netlink: Add priority and refcount to policy log

3 years agokernel-netlink: Consistently print mark in log messages only if set
Tobias Brunner [Fri, 27 May 2016 15:03:26 +0000 (17:03 +0200)]
kernel-netlink: Consistently print mark in log messages only if set

3 years agokernel-netlink: Provide error information for Netlink sockets
Tobias Brunner [Fri, 27 May 2016 11:43:41 +0000 (13:43 +0200)]
kernel-netlink: Provide error information for Netlink sockets


3 years agokernel-netlink: Allow definition of a custom priority calculation function
Tobias Brunner [Thu, 28 Apr 2016 16:05:36 +0000 (18:05 +0200)]
kernel-netlink: Allow definition of a custom priority calculation function

3 years agoMerge branch 'ipsec-sa-cfg-equals'
Tobias Brunner [Thu, 9 Jun 2016 09:46:06 +0000 (11:46 +0200)]
Merge branch 'ipsec-sa-cfg-equals'

Fixes the comparison of ipsec_sa_cfg_t instances in case there is
padding that's not initialized to zero.

Fixes #1503.

3 years agokernel-pfkey: Use ipsec_sa_cfg_equals()
Tobias Brunner [Wed, 8 Jun 2016 14:11:07 +0000 (16:11 +0200)]
kernel-pfkey: Use ipsec_sa_cfg_equals()

3 years agokernel-netlink: Use ipsec_sa_cfg_equals() and compare marks properly
Tobias Brunner [Wed, 8 Jun 2016 14:10:30 +0000 (16:10 +0200)]
kernel-netlink: Use ipsec_sa_cfg_equals() and compare marks properly

3 years agoipsec: Add function to compare two ipsec_sa_cfg_t instances
Tobias Brunner [Wed, 8 Jun 2016 14:06:53 +0000 (16:06 +0200)]
ipsec: Add function to compare two ipsec_sa_cfg_t instances

memeq() is currently used to compare these but if there is padding that
is not initialized the same for two instances the comparison fails.
Using this function ensures the objects are compared correctly.

3 years agoeap-simaka-pseudonym: Properly store mappings
Tobias Brunner [Tue, 24 May 2016 08:26:38 +0000 (10:26 +0200)]
eap-simaka-pseudonym: Properly store mappings

If a pseudonym changed a new entry was added to the table storing
permanent identity objects (that are used as keys in the other table).
However, the old mapping was not removed while replacing the mapping in
the pseudonym table caused the old pseudonym to get destroyed.  This
eventually caused crashes when a new pseudonym had the same hash value as
such a defunct entry and keys had to be compared.

Fixes strongswan/strongswan#46.

3 years agochild-sa: Use non-static variable to store generated unique mark
Tobias Brunner [Thu, 19 May 2016 09:56:44 +0000 (11:56 +0200)]
child-sa: Use non-static variable to store generated unique mark

If two CHILD_SAs with mark=%unique are created concurrently they could
otherwise end up with either the same mark or different marks in both

3 years agoike: Don't trigger message hook when fragmenting pre-generated messages
Tobias Brunner [Wed, 25 May 2016 07:42:08 +0000 (09:42 +0200)]
ike: Don't trigger message hook when fragmenting pre-generated messages

This is the case for the IKE_SA_INIT and the initial IKEv1 messages, which
are pre-generated in tasks as at least parts of it are used to generate
the AUTH payload.  The IKE_SA_INIT message will never be fragmented, but
the IKEv1 messages might be, so we can't just call generate_message().

Fixes #1478.

3 years agoerror-notify: Notify listeners upon IKE retransmit
Thomas Egerer [Tue, 16 Feb 2016 11:58:20 +0000 (12:58 +0100)]
error-notify: Notify listeners upon IKE retransmit

Signed-off-by: Thomas Egerer <>
3 years agotask-manager: Add retransmit cleared alert
Tobias Brunner [Tue, 3 May 2016 09:23:43 +0000 (11:23 +0200)]
task-manager: Add retransmit cleared alert