diff packages/net/bsd_tcpip/current/src/sys/netkey/keydb.c @ 1382:56b339272cd4

* include/net/if_gif.h include/net/if_sec.h include/net/zlib.h include/netinet/ip_ecn.h include/netinet6/ah.h include/netinet6/esp.h include/netinet6/esp_rijndael.h include/netinet6/esp_twofish.h include/netinet6/in6_gif.h include/netinet6/ipcomp.h include/netkey/key.h include/netkey/key_debug.h include/netkey/keysock.h src/sys/netkey src/sys/netinet/ip_ecn.c src/sys/netinet6/ah_core.c src/sys/netinet6/ah_input.c src/sys/netinet6/ah_output.c src/sys/netinet6/esp_core.c src/sys/netinet6/esp_input.c src/sys/netinet6/esp_output.c src/sys/netinet6/esp_rijndael.c src/sys/netinet6/esp_twofish.c src/sys/netinet6/in6_gif.c src/sys/netinet6/ipcomp_core.c src/sys/netinet6/ipcomp_input.c src/sys/netinet6/ipcomp_output.c src/sys/netinet6/ipsec.c: Added back the original KAME FreeBSD IPSEC files. * cdl/freebsd_net.cdl: CDl to control the compilation of IPSEC * include/sys/malloc.h: New memory type needed by IPSEC * include/sys/param.h: Name munging for IPSEC symbols * src/ecos/support.c: read_random_unlimited() should return the number of random bytes in the buffer. * src/sys/kern/kern_sysctl.c: Added missing copyright header. * src/sys/netinet/ip_output.c: Removed user() checks in IPSEC code. * src/sys/netinet6/ip6_output.c: Compiler warning fixes.
author asl
date Sat, 22 Nov 2003 12:59:20 +0000
parents
children
line wrap: on
line diff
new file mode 100644
--- /dev/null
+++ b/packages/net/bsd_tcpip/current/src/sys/netkey/keydb.c
@@ -0,0 +1,236 @@
+//==========================================================================
+//
+//      src/sys/netkey/keydb.c
+//
+//==========================================================================
+//####BSDCOPYRIGHTBEGIN####
+//
+// -------------------------------------------
+//
+// Portions of this software may have been derived from OpenBSD, 
+// FreeBSD or other sources, and are covered by the appropriate
+// copyright disclaimers included herein.
+//
+// Portions created by Red Hat are
+// Copyright (C) 2002 Red Hat, Inc. All Rights Reserved.
+//
+// -------------------------------------------
+//
+//####BSDCOPYRIGHTEND####
+//==========================================================================
+
+/*	$KAME: keydb.c,v 1.64 2000/05/11 17:02:30 itojun Exp $	*/
+
+/*
+ * Copyright (C) 1995, 1996, 1997, and 1998 WIDE Project.
+ * All rights reserved.
+ *
+ * Redistribution and use in source and binary forms, with or without
+ * modification, are permitted provided that the following conditions
+ * are met:
+ * 1. Redistributions of source code must retain the above copyright
+ *    notice, this list of conditions and the following disclaimer.
+ * 2. Redistributions in binary form must reproduce the above copyright
+ *    notice, this list of conditions and the following disclaimer in the
+ *    documentation and/or other materials provided with the distribution.
+ * 3. Neither the name of the project nor the names of its contributors
+ *    may be used to endorse or promote products derived from this software
+ *    without specific prior written permission.
+ *
+ * THIS SOFTWARE IS PROVIDED BY THE PROJECT AND CONTRIBUTORS ``AS IS'' AND
+ * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
+ * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
+ * ARE DISCLAIMED.  IN NO EVENT SHALL THE PROJECT OR CONTRIBUTORS BE LIABLE
+ * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
+ * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
+ * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
+ * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
+ * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
+ * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
+ * SUCH DAMAGE.
+ */
+
+#include <sys/types.h>
+#include <sys/socket.h>
+#include <sys/param.h>
+#include <sys/malloc.h>
+#include <sys/errno.h>
+#include <sys/queue.h>
+
+#include <net/if.h>
+#include <net/route.h>
+
+#include <netinet/in.h>
+
+#include <net/pfkeyv2.h>
+#include <netkey/keydb.h>
+#include <netinet6/ipsec.h>
+
+static void keydb_delsecasvar __P((struct secasvar *));
+
+/*
+ * secpolicy management
+ */
+struct secpolicy *
+keydb_newsecpolicy()
+{
+	struct secpolicy *p;
+
+	p = (struct secpolicy *)malloc(sizeof(*p), M_SECA, M_NOWAIT);
+	if (!p)
+		return p;
+	bzero(p, sizeof(*p));
+	return p;
+}
+
+void
+keydb_delsecpolicy(p)
+	struct secpolicy *p;
+{
+
+	free(p, M_SECA);
+}
+
+/*
+ * secashead management
+ */
+struct secashead *
+keydb_newsecashead()
+{
+	struct secashead *p;
+	int i;
+
+	p = (struct secashead *)malloc(sizeof(*p), M_SECA, M_NOWAIT);
+	if (!p)
+		return p;
+	bzero(p, sizeof(*p));
+	for (i = 0; i < sizeof(p->savtree)/sizeof(p->savtree[0]); i++)
+		LIST_INIT(&p->savtree[i]);
+	return p;
+}
+
+void
+keydb_delsecashead(p)
+	struct secashead *p;
+{
+
+	free(p, M_SECA);
+}
+
+/*
+ * secasvar management (reference counted)
+ */
+struct secasvar *
+keydb_newsecasvar()
+{
+	struct secasvar *p;
+
+	p = (struct secasvar *)malloc(sizeof(*p), M_SECA, M_NOWAIT);
+	if (!p)
+		return p;
+	bzero(p, sizeof(*p));
+	p->refcnt = 1;
+	return p;
+}
+
+void
+keydb_refsecasvar(p)
+	struct secasvar *p;
+{
+	int s;
+
+#ifdef __NetBSD__
+	s = splsoftnet();
+#else
+	s = splnet();
+#endif
+	p->refcnt++;
+	splx(s);
+}
+
+void
+keydb_freesecasvar(p)
+	struct secasvar *p;
+{
+	int s;
+
+#ifdef __NetBSD__
+	s = splsoftnet();
+#else
+	s = splnet();
+#endif
+	p->refcnt--;
+	/* negative refcnt will cause panic intentionally */
+	if (p->refcnt <= 0)
+		keydb_delsecasvar(p);
+	splx(s);
+}
+
+static void
+keydb_delsecasvar(p)
+	struct secasvar *p;
+{
+
+	if (p->refcnt)
+		panic("keydb_delsecasvar called with refcnt != 0");
+
+	free(p, M_SECA);
+}
+
+/*
+ * secreplay management
+ */
+struct secreplay *
+keydb_newsecreplay(wsize)
+	size_t wsize;
+{
+	struct secreplay *p;
+
+	p = (struct secreplay *)malloc(sizeof(*p), M_SECA, M_NOWAIT);
+	if (!p)
+		return p;
+
+	bzero(p, sizeof(*p));
+	if (wsize != 0) {
+		p->bitmap = (caddr_t)malloc(wsize, M_SECA, M_NOWAIT);
+		if (!p->bitmap) {
+			free(p, M_SECA);
+			return NULL;
+		}
+		bzero(p->bitmap, wsize);
+	}
+	p->wsize = wsize;
+	return p;
+}
+
+void
+keydb_delsecreplay(p)
+	struct secreplay *p;
+{
+
+	if (p->bitmap)
+		free(p->bitmap, M_SECA);
+	free(p, M_SECA);
+}
+
+/*
+ * secreg management
+ */
+struct secreg *
+keydb_newsecreg()
+{
+	struct secreg *p;
+
+	p = (struct secreg *)malloc(sizeof(*p), M_SECA, M_NOWAIT);
+	if (p)
+		bzero(p, sizeof(*p));
+	return p;
+}
+
+void
+keydb_delsecreg(p)
+	struct secreg *p;
+{
+
+	free(p, M_SECA);
+}