1
1
mirror of https://github.com/systemd/systemd-stable.git synced 2024-12-24 21:34:08 +03:00

wireguard: check whether PrivateKey= and PublicKey= are set

This commit is contained in:
Yu Watanabe 2019-03-04 14:31:36 +09:00
parent fedcb4c3eb
commit 9cc9021aed

View File

@ -812,6 +812,21 @@ static void wireguard_done(NetDev *netdev) {
set_free(w->peers_with_failed_endpoint);
}
static int wireguard_peer_verify(WireguardPeer *peer) {
NetDev *netdev = NETDEV(peer->wireguard);
if (section_is_invalid(peer->section))
return -EINVAL;
if (eqzero(peer->public_key))
return log_netdev_error_errno(netdev, SYNTHETIC_ERRNO(EINVAL),
"%s: WireGuardPeer section without PublicKey= configured. "
"Ignoring [WireGuardPeer] section from line %u.",
peer->section->filename, peer->section->line);
return 0;
}
static int wireguard_verify(NetDev *netdev, const char *filename) {
WireguardPeer *peer, *peer_next;
Wireguard *w;
@ -820,8 +835,13 @@ static int wireguard_verify(NetDev *netdev, const char *filename) {
w = WIREGUARD(netdev);
assert(w);
if (eqzero(w->private_key))
return log_netdev_error_errno(netdev, SYNTHETIC_ERRNO(EINVAL),
"%s: Missing PrivateKey= or PrivateKeyFile=, ignoring.",
filename);
LIST_FOREACH_SAFE(peers, peer, peer_next, w->peers)
if (section_is_invalid(peer->section))
if (wireguard_peer_verify(peer) < 0)
wireguard_peer_free(peer);
return 0;