Skip to content

Commit e3e2f07

Browse files
florincorasDamjan Marion
authored andcommitted
tls: add stop listen handler
Change-Id: I233d02a669b6a0504cd54590c6c8e4fefadc4713 Signed-off-by: Florin Coras <[email protected]>
1 parent 03f942a commit e3e2f07

File tree

3 files changed

+144
-20
lines changed

3 files changed

+144
-20
lines changed

src/tests/vnet/session/tcp_echo.c

Lines changed: 102 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -135,6 +135,58 @@ echo_main_t echo_main;
135135
#define NITER 4000000
136136
#endif
137137

138+
const char test_srv_crt_rsa[] =
139+
"-----BEGIN CERTIFICATE-----\r\n"
140+
"MIIDNzCCAh+gAwIBAgIBAjANBgkqhkiG9w0BAQUFADA7MQswCQYDVQQGEwJOTDER\r\n"
141+
"MA8GA1UEChMIUG9sYXJTU0wxGTAXBgNVBAMTEFBvbGFyU1NMIFRlc3QgQ0EwHhcN\r\n"
142+
"MTEwMjEyMTQ0NDA2WhcNMjEwMjEyMTQ0NDA2WjA0MQswCQYDVQQGEwJOTDERMA8G\r\n"
143+
"A1UEChMIUG9sYXJTU0wxEjAQBgNVBAMTCWxvY2FsaG9zdDCCASIwDQYJKoZIhvcN\r\n"
144+
"AQEBBQADggEPADCCAQoCggEBAMFNo93nzR3RBNdJcriZrA545Do8Ss86ExbQWuTN\r\n"
145+
"owCIp+4ea5anUrSQ7y1yej4kmvy2NKwk9XfgJmSMnLAofaHa6ozmyRyWvP7BBFKz\r\n"
146+
"NtSj+uGxdtiQwWG0ZlI2oiZTqqt0Xgd9GYLbKtgfoNkNHC1JZvdbJXNG6AuKT2kM\r\n"
147+
"tQCQ4dqCEGZ9rlQri2V5kaHiYcPNQEkI7mgM8YuG0ka/0LiqEQMef1aoGh5EGA8P\r\n"
148+
"hYvai0Re4hjGYi/HZo36Xdh98yeJKQHFkA4/J/EwyEoO79bex8cna8cFPXrEAjya\r\n"
149+
"HT4P6DSYW8tzS1KW2BGiLICIaTla0w+w3lkvEcf36hIBMJcCAwEAAaNNMEswCQYD\r\n"
150+
"VR0TBAIwADAdBgNVHQ4EFgQUpQXoZLjc32APUBJNYKhkr02LQ5MwHwYDVR0jBBgw\r\n"
151+
"FoAUtFrkpbPe0lL2udWmlQ/rPrzH/f8wDQYJKoZIhvcNAQEFBQADggEBAJxnXClY\r\n"
152+
"oHkbp70cqBrsGXLybA74czbO5RdLEgFs7rHVS9r+c293luS/KdliLScZqAzYVylw\r\n"
153+
"UfRWvKMoWhHYKp3dEIS4xTXk6/5zXxhv9Rw8SGc8qn6vITHk1S1mPevtekgasY5Y\r\n"
154+
"iWQuM3h4YVlRH3HHEMAD1TnAexfXHHDFQGe+Bd1iAbz1/sH9H8l4StwX6egvTK3M\r\n"
155+
"wXRwkKkvjKaEDA9ATbZx0mI8LGsxSuCqe9r9dyjmttd47J1p1Rulz3CLzaRcVIuS\r\n"
156+
"RRQfaD8neM9c1S/iJ/amTVqJxA1KOdOS5780WhPfSArA+g4qAmSjelc3p4wWpha8\r\n"
157+
"zhuYwjVuX6JHG0c=\r\n" "-----END CERTIFICATE-----\r\n";
158+
const u32 test_srv_crt_rsa_len = sizeof (test_srv_crt_rsa);
159+
160+
const char test_srv_key_rsa[] =
161+
"-----BEGIN RSA PRIVATE KEY-----\r\n"
162+
"MIIEpAIBAAKCAQEAwU2j3efNHdEE10lyuJmsDnjkOjxKzzoTFtBa5M2jAIin7h5r\r\n"
163+
"lqdStJDvLXJ6PiSa/LY0rCT1d+AmZIycsCh9odrqjObJHJa8/sEEUrM21KP64bF2\r\n"
164+
"2JDBYbRmUjaiJlOqq3ReB30Zgtsq2B+g2Q0cLUlm91slc0boC4pPaQy1AJDh2oIQ\r\n"
165+
"Zn2uVCuLZXmRoeJhw81ASQjuaAzxi4bSRr/QuKoRAx5/VqgaHkQYDw+Fi9qLRF7i\r\n"
166+
"GMZiL8dmjfpd2H3zJ4kpAcWQDj8n8TDISg7v1t7HxydrxwU9esQCPJodPg/oNJhb\r\n"
167+
"y3NLUpbYEaIsgIhpOVrTD7DeWS8Rx/fqEgEwlwIDAQABAoIBAQCXR0S8EIHFGORZ\r\n"
168+
"++AtOg6eENxD+xVs0f1IeGz57Tjo3QnXX7VBZNdj+p1ECvhCE/G7XnkgU5hLZX+G\r\n"
169+
"Z0jkz/tqJOI0vRSdLBbipHnWouyBQ4e/A1yIJdlBtqXxJ1KE/ituHRbNc4j4kL8Z\r\n"
170+
"/r6pvwnTI0PSx2Eqs048YdS92LT6qAv4flbNDxMn2uY7s4ycS4Q8w1JXnCeaAnYm\r\n"
171+
"WYI5wxO+bvRELR2Mcz5DmVnL8jRyml6l6582bSv5oufReFIbyPZbQWlXgYnpu6He\r\n"
172+
"GTc7E1zKYQGG/9+DQUl/1vQuCPqQwny0tQoX2w5tdYpdMdVm+zkLtbajzdTviJJa\r\n"
173+
"TWzL6lt5AoGBAN86+SVeJDcmQJcv4Eq6UhtRr4QGMiQMz0Sod6ettYxYzMgxtw28\r\n"
174+
"CIrgpozCc+UaZJLo7UxvC6an85r1b2nKPCLQFaggJ0H4Q0J/sZOhBIXaoBzWxveK\r\n"
175+
"nupceKdVxGsFi8CDy86DBfiyFivfBj+47BbaQzPBj7C4rK7UlLjab2rDAoGBAN2u\r\n"
176+
"AM2gchoFiu4v1HFL8D7lweEpi6ZnMJjnEu/dEgGQJFjwdpLnPbsj4c75odQ4Gz8g\r\n"
177+
"sw9lao9VVzbusoRE/JGI4aTdO0pATXyG7eG1Qu+5Yc1YGXcCrliA2xM9xx+d7f+s\r\n"
178+
"mPzN+WIEg5GJDYZDjAzHG5BNvi/FfM1C9dOtjv2dAoGAF0t5KmwbjWHBhcVqO4Ic\r\n"
179+
"BVvN3BIlc1ue2YRXEDlxY5b0r8N4XceMgKmW18OHApZxfl8uPDauWZLXOgl4uepv\r\n"
180+
"whZC3EuWrSyyICNhLY21Ah7hbIEBPF3L3ZsOwC+UErL+dXWLdB56Jgy3gZaBeW7b\r\n"
181+
"vDrEnocJbqCm7IukhXHOBK8CgYEAwqdHB0hqyNSzIOGY7v9abzB6pUdA3BZiQvEs\r\n"
182+
"3LjHVd4HPJ2x0N8CgrBIWOE0q8+0hSMmeE96WW/7jD3fPWwCR5zlXknxBQsfv0gP\r\n"
183+
"3BC5PR0Qdypz+d+9zfMf625kyit4T/hzwhDveZUzHnk1Cf+IG7Q+TOEnLnWAWBED\r\n"
184+
"ISOWmrUCgYAFEmRxgwAc/u+D6t0syCwAYh6POtscq9Y0i9GyWk89NzgC4NdwwbBH\r\n"
185+
"4AgahOxIxXx2gxJnq3yfkJfIjwf0s2DyP0kY2y6Ua1OeomPeY9mrIS4tCuDQ6LrE\r\n"
186+
"TB6l9VGoxJL4fyHnZb8L5gGvnB1bbD8cL6YPaDiOhcRseC9vBiEuVg==\r\n"
187+
"-----END RSA PRIVATE KEY-----\r\n";
188+
const u32 test_srv_key_rsa_len = sizeof (test_srv_key_rsa);
189+
138190
static u8 *
139191
format_api_error (u8 * s, va_list * args)
140192
{
@@ -191,6 +243,9 @@ void
191243
application_send_attach (echo_main_t * em)
192244
{
193245
vl_api_application_attach_t *bmp;
246+
vl_api_application_tls_cert_add_t *cert_mp;
247+
vl_api_application_tls_key_add_t *key_mp;
248+
194249
u32 fifo_size = 4 << 20;
195250
bmp = vl_msg_api_alloc (sizeof (*bmp));
196251
memset (bmp, 0, sizeof (*bmp));
@@ -206,6 +261,24 @@ application_send_attach (echo_main_t * em)
206261
bmp->options[APP_OPTIONS_ADD_SEGMENT_SIZE] = 128 << 20;
207262
bmp->options[APP_OPTIONS_SEGMENT_SIZE] = 256 << 20;
208263
vl_msg_api_send_shmem (em->vl_input_queue, (u8 *) & bmp);
264+
265+
cert_mp = vl_msg_api_alloc (sizeof (*cert_mp) + test_srv_crt_rsa_len);
266+
memset (cert_mp, 0, sizeof (*cert_mp));
267+
cert_mp->_vl_msg_id = ntohs (VL_API_APPLICATION_TLS_CERT_ADD);
268+
cert_mp->client_index = em->my_client_index;
269+
cert_mp->context = ntohl (0xfeedface);
270+
cert_mp->cert_len = clib_host_to_net_u16 (test_srv_crt_rsa_len);
271+
clib_memcpy (cert_mp->cert, test_srv_crt_rsa, test_srv_crt_rsa_len);
272+
vl_msg_api_send_shmem (em->vl_input_queue, (u8 *) & cert_mp);
273+
274+
key_mp = vl_msg_api_alloc (sizeof (*key_mp) + test_srv_key_rsa_len);
275+
memset (key_mp, 0, sizeof (*key_mp) + test_srv_key_rsa_len);
276+
key_mp->_vl_msg_id = ntohs (VL_API_APPLICATION_TLS_KEY_ADD);
277+
key_mp->client_index = em->my_client_index;
278+
key_mp->context = ntohl (0xfeedface);
279+
key_mp->key_len = clib_host_to_net_u16 (test_srv_key_rsa_len);
280+
clib_memcpy (key_mp->key, test_srv_key_rsa, test_srv_key_rsa_len);
281+
vl_msg_api_send_shmem (em->vl_input_queue, (u8 *) & key_mp);
209282
}
210283

211284
int
@@ -1218,17 +1291,35 @@ vl_api_disconnect_session_reply_t_handler (vl_api_disconnect_session_reply_t *
12181291
session_print_stats (em, session);
12191292
}
12201293

1221-
#define foreach_tcp_echo_msg \
1222-
_(BIND_URI_REPLY, bind_uri_reply) \
1223-
_(UNBIND_URI_REPLY, unbind_uri_reply) \
1224-
_(ACCEPT_SESSION, accept_session) \
1225-
_(CONNECT_SESSION_REPLY, connect_session_reply) \
1226-
_(DISCONNECT_SESSION, disconnect_session) \
1227-
_(DISCONNECT_SESSION_REPLY, disconnect_session_reply) \
1228-
_(RESET_SESSION, reset_session) \
1229-
_(APPLICATION_ATTACH_REPLY, application_attach_reply) \
1230-
_(APPLICATION_DETACH_REPLY, application_detach_reply) \
1231-
_(MAP_ANOTHER_SEGMENT, map_another_segment) \
1294+
static void
1295+
vl_api_application_tls_cert_add_reply_t_handler
1296+
(vl_api_application_tls_cert_add_reply_t * mp)
1297+
{
1298+
if (mp->retval)
1299+
clib_warning ("failed to add tls cert");
1300+
}
1301+
1302+
static void
1303+
vl_api_application_tls_key_add_reply_t_handler
1304+
(vl_api_application_tls_key_add_reply_t * mp)
1305+
{
1306+
if (mp->retval)
1307+
clib_warning ("failed to add tls key");
1308+
}
1309+
1310+
#define foreach_tcp_echo_msg \
1311+
_(BIND_URI_REPLY, bind_uri_reply) \
1312+
_(UNBIND_URI_REPLY, unbind_uri_reply) \
1313+
_(ACCEPT_SESSION, accept_session) \
1314+
_(CONNECT_SESSION_REPLY, connect_session_reply) \
1315+
_(DISCONNECT_SESSION, disconnect_session) \
1316+
_(DISCONNECT_SESSION_REPLY, disconnect_session_reply) \
1317+
_(RESET_SESSION, reset_session) \
1318+
_(APPLICATION_ATTACH_REPLY, application_attach_reply) \
1319+
_(APPLICATION_DETACH_REPLY, application_detach_reply) \
1320+
_(MAP_ANOTHER_SEGMENT, map_another_segment) \
1321+
_(APPLICATION_TLS_CERT_ADD_REPLY, application_tls_cert_add_reply) \
1322+
_(APPLICATION_TLS_KEY_ADD_REPLY, application_tls_key_add_reply) \
12321323

12331324
void
12341325
tcp_echo_api_hookup (echo_main_t * em)

src/vnet/session-apps/tls.c

Lines changed: 28 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -221,9 +221,9 @@ tls_listener_ctx_alloc (void)
221221
}
222222

223223
void
224-
tls_ctx_listener_free (tls_ctx_t * ctx)
224+
tls_listener_ctx_free (tls_ctx_t * ctx)
225225
{
226-
pool_put (tls_main.half_open_ctx_pool, ctx);
226+
pool_put (tls_main.listener_ctx_pool, ctx);
227227
}
228228

229229
tls_ctx_t *
@@ -936,6 +936,13 @@ tls_disconnect (u32 ctx_index, u32 thread_index)
936936
app_session->server_tx_fifo);
937937
session_free (app_session);
938938
}
939+
if (ctx->ssl.conf->endpoint == MBEDTLS_SSL_IS_SERVER)
940+
{
941+
mbedtls_x509_crt_free (&ctx->srvcert);
942+
mbedtls_pk_free (&ctx->pkey);
943+
}
944+
mbedtls_ssl_free (&ctx->ssl);
945+
mbedtls_ssl_config_free (&ctx->conf);
939946
tls_ctx_free (ctx);
940947
}
941948

@@ -974,12 +981,26 @@ tls_start_listen (u32 app_listener_index, transport_endpoint_t * tep)
974981
}
975982

976983
u32
977-
tls_stop_listen (u32 listener_index)
984+
tls_stop_listen (u32 lctx_index)
978985
{
979-
clib_warning ("TBD");
986+
tls_main_t *tm = &tls_main;
987+
application_t *tls_app;
988+
tls_ctx_t *lctx;
989+
lctx = tls_listener_ctx_get (lctx_index);
990+
tls_app = application_get (tm->app_index);
991+
application_stop_listen (tls_app, lctx->tls_session_handle);
992+
tls_listener_ctx_free (lctx);
980993
return 0;
981994
}
982995

996+
transport_connection_t *
997+
tls_connection_get (u32 ctx_index, u32 thread_index)
998+
{
999+
tls_ctx_t *ctx;
1000+
ctx = tls_ctx_get_w_thread (ctx_index, thread_index);
1001+
return &ctx->connection;
1002+
}
1003+
9831004
transport_connection_t *
9841005
tls_listener_get (u32 listener_index)
9851006
{
@@ -999,9 +1020,8 @@ format_tls_ctx (u8 * s, va_list * args)
9991020
if (thread_index != child_ti)
10001021
clib_warning ("app and tls sessions are on different threads!");
10011022

1002-
s =
1003-
format (s, "[#%d][TLS] app %u child %u", child_ti, ctx->parent_app_index,
1004-
child_si);
1023+
s = format (s, "[#%d][TLS] app %u child %u", child_ti,
1024+
ctx->parent_app_index, child_si);
10051025
return s;
10061026
}
10071027

@@ -1055,6 +1075,7 @@ const static transport_proto_vft_t tls_proto = {
10551075
.open = tls_connect,
10561076
.close = tls_disconnect,
10571077
.bind = tls_start_listen,
1078+
.get_connection = tls_connection_get,
10581079
.get_listener = tls_listener_get,
10591080
.unbind = tls_stop_listen,
10601081
.tx_type = TRANSPORT_TX_INTERNAL,

src/vnet/session/session_api.c

Lines changed: 14 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1111,15 +1111,21 @@ vl_api_application_tls_cert_add_t_handler (vl_api_application_tls_cert_add_t *
11111111
vl_api_app_namespace_add_del_reply_t *rmp;
11121112
vnet_app_add_tls_cert_args_t _a, *a = &_a;
11131113
clib_error_t *error;
1114+
application_t *app;
11141115
u32 cert_len;
11151116
int rv = 0;
11161117
if (!session_manager_is_enabled ())
11171118
{
11181119
rv = VNET_API_ERROR_FEATURE_DISABLED;
11191120
goto done;
11201121
}
1122+
if (!(app = application_lookup (mp->client_index)))
1123+
{
1124+
rv = VNET_API_ERROR_APPLICATION_NOT_ATTACHED;
1125+
goto done;
1126+
}
11211127
memset (a, 0, sizeof (*a));
1122-
a->app_index = clib_net_to_host_u32 (mp->app_index);
1128+
a->app_index = app->index;
11231129
cert_len = clib_net_to_host_u16 (mp->cert_len);
11241130
vec_validate (a->cert, cert_len);
11251131
clib_memcpy (a->cert, mp->cert, cert_len);
@@ -1140,15 +1146,21 @@ vl_api_application_tls_key_add_t_handler (vl_api_application_tls_key_add_t *
11401146
vl_api_app_namespace_add_del_reply_t *rmp;
11411147
vnet_app_add_tls_key_args_t _a, *a = &_a;
11421148
clib_error_t *error;
1149+
application_t *app;
11431150
u32 key_len;
11441151
int rv = 0;
11451152
if (!session_manager_is_enabled ())
11461153
{
11471154
rv = VNET_API_ERROR_FEATURE_DISABLED;
11481155
goto done;
11491156
}
1157+
if (!(app = application_lookup (mp->client_index)))
1158+
{
1159+
rv = VNET_API_ERROR_APPLICATION_NOT_ATTACHED;
1160+
goto done;
1161+
}
11501162
memset (a, 0, sizeof (*a));
1151-
a->app_index = clib_net_to_host_u32 (mp->app_index);
1163+
a->app_index = app->index;
11521164
key_len = clib_net_to_host_u16 (mp->key_len);
11531165
vec_validate (a->key, key_len);
11541166
clib_memcpy (a->key, mp->key, key_len);

0 commit comments

Comments
 (0)