3
0
mirror of https://git.kernel.org/pub/scm/network/wireless/iwd.git synced 2025-01-22 03:14:05 +01:00

storage: Add TLS session cache file read/write utils

Add storage_tls_session_cache_{load,sync} similar to
storage_known_frequencies_{load,sync}.
This commit is contained in:
Andrew Zaborowski 2022-11-09 18:04:37 +01:00 committed by Denis Kenzior
parent 91c6dea57b
commit 644586e273
2 changed files with 38 additions and 0 deletions

View File

@ -53,6 +53,7 @@
#define STORAGE_FILE_MODE (S_IRUSR | S_IWUSR)
#define KNOWN_FREQ_FILENAME ".known_network.freq"
#define TLS_CACHE_FILENAME ".tls-session-cache"
static char *storage_path = NULL;
static char *storage_hotspot_path = NULL;
@ -701,6 +702,40 @@ void storage_known_frequencies_sync(struct l_settings *known_freqs)
l_free(known_freq_file_path);
}
struct l_settings *storage_tls_session_cache_load(void)
{
_auto_(l_settings_free) struct l_settings *cache = l_settings_new();
_auto_(l_free) char *tls_cache_file_path =
storage_get_path("%s", TLS_CACHE_FILENAME);
if (unlikely(!l_settings_load_from_file(cache, tls_cache_file_path)))
return NULL;
return l_steal_ptr(cache);
}
void storage_tls_session_cache_sync(struct l_settings *cache)
{
_auto_(l_free) char *tls_cache_file_path = NULL;
_auto_(l_free) char *data = NULL;
size_t len;
if (!cache)
return;
tls_cache_file_path = storage_get_path("%s", TLS_CACHE_FILENAME);
data = l_settings_to_data(cache, &len);
/*
* Note this data contains cryptographic secrets. write_file()
* happens to set the right permissions on the file.
*
* TODO: consider encrypting with system_key.
*/
write_file(data, len, false, "%s", tls_cache_file_path);
explicit_bzero(data, len);
}
bool storage_is_file(const char *filename)
{
char *path;

View File

@ -51,6 +51,9 @@ int storage_network_remove(enum security type, const char *ssid);
struct l_settings *storage_known_frequencies_load(void);
void storage_known_frequencies_sync(struct l_settings *known_freqs);
struct l_settings *storage_tls_session_cache_load(void);
void storage_tls_session_cache_sync(struct l_settings *cache);
int __storage_decrypt(struct l_settings *settings, const char *ssid,
bool *changed);
char *__storage_encrypt(const struct l_settings *settings, const char *ssid,