From owner-svn-ports-head@freebsd.org Sat Mar 9 10:37:14 2019 Return-Path: Delivered-To: svn-ports-head@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id BED7F1540E8E; Sat, 9 Mar 2019 10:37:14 +0000 (UTC) (envelope-from pi@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) server-signature RSA-PSS (4096 bits) client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "Let's Encrypt Authority X3" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 5FDA181173; Sat, 9 Mar 2019 10:37:14 +0000 (UTC) (envelope-from pi@FreeBSD.org) Received: from repo.freebsd.org (repo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:0]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id 535499FF0; Sat, 9 Mar 2019 10:37:14 +0000 (UTC) (envelope-from pi@FreeBSD.org) Received: from repo.freebsd.org ([127.0.1.37]) by repo.freebsd.org (8.15.2/8.15.2) with ESMTP id x29AbEWJ054520; Sat, 9 Mar 2019 10:37:14 GMT (envelope-from pi@FreeBSD.org) Received: (from pi@localhost) by repo.freebsd.org (8.15.2/8.15.2/Submit) id x29AbEr0054518; Sat, 9 Mar 2019 10:37:14 GMT (envelope-from pi@FreeBSD.org) Message-Id: <201903091037.x29AbEr0054518@repo.freebsd.org> X-Authentication-Warning: repo.freebsd.org: pi set sender to pi@FreeBSD.org using -f From: Kurt Jaeger Date: Sat, 9 Mar 2019 10:37:14 +0000 (UTC) To: ports-committers@freebsd.org, svn-ports-all@freebsd.org, svn-ports-head@freebsd.org Subject: svn commit: r495117 - in head/security/strongswan: . files X-SVN-Group: ports-head X-SVN-Commit-Author: pi X-SVN-Commit-Paths: in head/security/strongswan: . files X-SVN-Commit-Revision: 495117 X-SVN-Commit-Repository: ports MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-Rspamd-Queue-Id: 5FDA181173 X-Spamd-Bar: -- Authentication-Results: mx1.freebsd.org X-Spamd-Result: default: False [-2.96 / 15.00]; local_wl_from(0.00)[FreeBSD.org]; NEURAL_HAM_MEDIUM(-1.00)[-1.000,0]; NEURAL_HAM_SHORT(-0.96)[-0.956,0]; ASN(0.00)[asn:11403, ipnet:2610:1c1:1::/48, country:US]; NEURAL_HAM_LONG(-1.00)[-1.000,0] X-BeenThere: svn-ports-head@freebsd.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: SVN commit messages for the ports tree for head List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sat, 09 Mar 2019 10:37:15 -0000 Author: pi Date: Sat Mar 9 10:37:13 2019 New Revision: 495117 URL: https://svnweb.freebsd.org/changeset/ports/495117 Log: security/strongswan: add vici-based configuration for the rc script The rc script is modified to allow both a legacy (ipsec.conf-based) startup or a new (swanctl.conf-based) config. Default is the legacy. The new setup is based on vici, the Versatile IKE Configuration Interface. For more details, see: https://wiki.strongswan.org/projects/strongswan/wiki/Vici PR: 234648 Submitted by: Jose Luis Duran Reviewed by: Sam Chen Approved by: strongswan@Nanoteq.com (maintainer) Differential Revision: D19367 Modified: head/security/strongswan/Makefile head/security/strongswan/files/strongswan.in Modified: head/security/strongswan/Makefile ============================================================================== --- head/security/strongswan/Makefile Sat Mar 9 10:23:44 2019 (r495116) +++ head/security/strongswan/Makefile Sat Mar 9 10:37:13 2019 (r495117) @@ -3,7 +3,7 @@ PORTNAME= strongswan PORTVERSION= 5.7.2 -PORTREVISION= 1 +PORTREVISION= 2 CATEGORIES= security MASTER_SITES= http://download.strongswan.org/ \ http://download2.strongswan.org/ Modified: head/security/strongswan/files/strongswan.in ============================================================================== --- head/security/strongswan/files/strongswan.in Sat Mar 9 10:23:44 2019 (r495116) +++ head/security/strongswan/files/strongswan.in Sat Mar 9 10:37:13 2019 (r495117) @@ -7,33 +7,91 @@ # BEFORE: LOGIN # KEYWORD: shutdown +# strongswan_enable (bool): +# Set it to "YES" to enable strongswan +# Default is "NO" +# strongswan_interface (string): +# Set the control interface to use. +# Valid options are: +# "stroke" for the old ipsec/startr interface +# "vici" for the newer swanctl intrface +# Default is "stroke" + . /etc/rc.subr name=strongswan +desc="Strongswan IPsec startup script" rcvar=strongswan_enable load_rc_config $name : ${strongswan_enable:=NO} +: ${strongswan_interface:="stroke"} extra_commands="reload statusall" -command="%%PREFIX%%/sbin/ipsec" +charon_command=%%PREFIX%%/libexec/ipsec/charon +charon_pidfile=/var/run/charon.pid +swanctl_command=%%PREFIX%%/sbin/swanctl -start_precmd="strongswan_precmd" -stop_cmd="strongswan_cmd" -status_cmd="strongswan_cmd" -reload_cmd="strongswan_cmd" -statusall_cmd="strongswan_cmd" +case $strongswan_interface in +[Ss][Tt][Rr][Oo][Kk][Ee]) + # "stroke" + command="%%PREFIX%%/sbin/ipsec" + start_precmd=command_args=start + stop_cmd="${command} stop" + status_cmd="${command} status" + reload_cmd="${command} reload" + statusall_cmd="${command} statusall" + ;; -strongswan_precmd() +[Vv][Ii][Cc][Ii]) + # "vici" + command=/usr/sbin/daemon + pidfile=/var/run/daemon-charon.pid + command_args="-S -P ${pidfile} ${charon_command} --use-syslog" + + required_files=${charon_command} + extra_commands="reload statusall" + + start_postcmd=${name}_swanctl_poststart + status_cmd="${swanctl_command} --stats" + reload_cmd=${name}_swanctl_reload + statusall_cmd=${name}_swanctl_statusall + ;; + + *) + # "default" + warn "\$strongswan_interface setting is invalid - options supported are \"stroke\" or \"vici\"." + exit 1 + ;; +esac + +strongswan_swanctl_poststart() { - command_args=${rc_arg} + local _waitmax=5 + + # Need to wait for charon to finish startup, + # else vici socket is unreadable + while [ ! -f ${charon_pidfile} ] && [ ${_waitmax} -gt 0 ]; do + sleep 1 + _waitmax=$((_waitmax - 1)) + done + + ${swanctl_command} --load-all --noprompt } -strongswan_cmd() +strongswan_swanctl_reload() { - ${command} ${rc_arg} + ${swanctl_command} --reload-settings + ${swanctl_command} --load-all --noprompt +} + +strongswan_swanctl_statusall() +{ + ${swanctl_command} --stats + ${swanctl_command} --list-conns + ${swanctl_command} --list-sas } run_rc_command "$1"