[connman]Added support of EAP-FAST,EAP-PWD and EAP-AKA'.
[platform/upstream/connman.git] / vpn / vpn-provider.c
1 /*
2  *
3  *  ConnMan VPN daemon
4  *
5  *  Copyright (C) 2012-2013  Intel Corporation. All rights reserved.
6  *
7  *  This program is free software; you can redistribute it and/or modify
8  *  it under the terms of the GNU General Public License version 2 as
9  *  published by the Free Software Foundation.
10  *
11  *  This program is distributed in the hope that it will be useful,
12  *  but WITHOUT ANY WARRANTY; without even the implied warranty of
13  *  MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
14  *  GNU General Public License for more details.
15  *
16  *  You should have received a copy of the GNU General Public License
17  *  along with this program; if not, write to the Free Software
18  *  Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA  02110-1301  USA
19  *
20  */
21
22 #ifdef HAVE_CONFIG_H
23 #include <config.h>
24 #endif
25
26 #include <errno.h>
27 #include <stdio.h>
28 #include <string.h>
29 #include <stdlib.h>
30 #include <gdbus.h>
31 #include <connman/log.h>
32 #include <gweb/gresolv.h>
33 #include <netdb.h>
34
35 #include "../src/connman.h"
36 #include "connman/agent.h"
37 #include "connman/vpn-dbus.h"
38 #include "vpn-provider.h"
39 #include "vpn.h"
40
41 static DBusConnection *connection;
42 static GHashTable *provider_hash;
43 static GSList *driver_list;
44 static int configuration_count;
45 static bool handle_routes;
46
47 struct vpn_route {
48         int family;
49         char *network;
50         char *netmask;
51         char *gateway;
52 };
53
54 struct vpn_setting {
55         bool hide_value;
56         bool immutable;
57         char *value;
58 };
59
60 struct vpn_provider {
61         int refcount;
62         int index;
63         int fd;
64         enum vpn_provider_state state;
65         char *path;
66         char *identifier;
67         char *name;
68         char *type;
69         char *host;
70         char *domain;
71         int family;
72         GHashTable *routes;
73         struct vpn_provider_driver *driver;
74         void *driver_data;
75         GHashTable *setting_strings;
76         GHashTable *user_routes;
77         GSList *user_networks;
78         GResolv *resolv;
79         char **host_ip;
80         struct vpn_ipconfig *ipconfig_ipv4;
81         struct vpn_ipconfig *ipconfig_ipv6;
82         char **nameservers;
83         guint notify_id;
84         char *config_file;
85         char *config_entry;
86         bool immutable;
87         struct connman_ipaddress *prev_ipv4_addr;
88         struct connman_ipaddress *prev_ipv6_addr;
89 };
90
91 static void append_properties(DBusMessageIter *iter,
92                                 struct vpn_provider *provider);
93
94 static void free_route(gpointer data)
95 {
96         struct vpn_route *route = data;
97
98         g_free(route->network);
99         g_free(route->netmask);
100         g_free(route->gateway);
101
102         g_free(route);
103 }
104
105 static void free_setting(gpointer data)
106 {
107         struct vpn_setting *setting = data;
108
109         g_free(setting->value);
110         g_free(setting);
111 }
112
113 static void append_route(DBusMessageIter *iter, void *user_data)
114 {
115         struct vpn_route *route = user_data;
116         DBusMessageIter item;
117         int family = 0;
118
119         connman_dbus_dict_open(iter, &item);
120
121         if (!route)
122                 goto empty_dict;
123
124         if (route->family == AF_INET)
125                 family = 4;
126         else if (route->family == AF_INET6)
127                 family = 6;
128
129         if (family != 0)
130                 connman_dbus_dict_append_basic(&item, "ProtocolFamily",
131                                         DBUS_TYPE_INT32, &family);
132
133         if (route->network)
134                 connman_dbus_dict_append_basic(&item, "Network",
135                                         DBUS_TYPE_STRING, &route->network);
136
137         if (route->netmask)
138                 connman_dbus_dict_append_basic(&item, "Netmask",
139                                         DBUS_TYPE_STRING, &route->netmask);
140
141         if (route->gateway)
142                 connman_dbus_dict_append_basic(&item, "Gateway",
143                                         DBUS_TYPE_STRING, &route->gateway);
144
145 empty_dict:
146         connman_dbus_dict_close(iter, &item);
147 }
148
149 static void append_routes(DBusMessageIter *iter, void *user_data)
150 {
151         GHashTable *routes = user_data;
152         GHashTableIter hash;
153         gpointer value, key;
154
155         if (!routes) {
156                 append_route(iter, NULL);
157                 return;
158         }
159
160         g_hash_table_iter_init(&hash, routes);
161
162         while (g_hash_table_iter_next(&hash, &key, &value)) {
163                 DBusMessageIter dict;
164
165                 dbus_message_iter_open_container(iter, DBUS_TYPE_STRUCT, NULL,
166                                                 &dict);
167                 append_route(&dict, value);
168                 dbus_message_iter_close_container(iter, &dict);
169         }
170 }
171
172 static void send_routes(struct vpn_provider *provider, GHashTable *routes,
173                         const char *name)
174 {
175         connman_dbus_property_changed_array(provider->path,
176                                         VPN_CONNECTION_INTERFACE,
177                                         name,
178                                         DBUS_TYPE_DICT_ENTRY,
179                                         append_routes,
180                                         routes);
181 }
182
183 static int provider_routes_changed(struct vpn_provider *provider)
184 {
185         DBG("provider %p", provider);
186
187         send_routes(provider, provider->routes, "ServerRoutes");
188
189         return 0;
190 }
191
192 static GSList *read_route_dict(GSList *routes, DBusMessageIter *dicts)
193 {
194         DBusMessageIter dict, value, entry;
195         const char *network, *netmask, *gateway;
196         struct vpn_route *route;
197         int family, type;
198         const char *key;
199
200         dbus_message_iter_recurse(dicts, &entry);
201
202         network = netmask = gateway = NULL;
203         family = PF_UNSPEC;
204
205         while (dbus_message_iter_get_arg_type(&entry) == DBUS_TYPE_DICT_ENTRY) {
206
207                 dbus_message_iter_recurse(&entry, &dict);
208                 dbus_message_iter_get_basic(&dict, &key);
209
210                 dbus_message_iter_next(&dict);
211                 dbus_message_iter_recurse(&dict, &value);
212
213                 type = dbus_message_iter_get_arg_type(&value);
214
215                 switch (type) {
216                 case DBUS_TYPE_INT32:
217                         if (g_str_equal(key, "ProtocolFamily"))
218                                 dbus_message_iter_get_basic(&value, &family);
219                         break;
220
221                 case DBUS_TYPE_STRING:
222                         if (g_str_equal(key, "Network"))
223                                 dbus_message_iter_get_basic(&value, &network);
224                         else if (g_str_equal(key, "Netmask"))
225                                 dbus_message_iter_get_basic(&value, &netmask);
226                         else if (g_str_equal(key, "Gateway"))
227                                 dbus_message_iter_get_basic(&value, &gateway);
228                         break;
229                 }
230
231                 dbus_message_iter_next(&entry);
232         }
233
234         DBG("family %d network %s netmask %s gateway %s", family,
235                 network, netmask, gateway);
236
237         if (!network || !netmask) {
238                 DBG("Ignoring route as network/netmask is missing");
239                 return routes;
240         }
241
242         route = g_try_new(struct vpn_route, 1);
243         if (!route) {
244                 g_slist_free_full(routes, free_route);
245                 return NULL;
246         }
247
248         if (family == PF_UNSPEC) {
249                 family = connman_inet_check_ipaddress(network);
250                 if (family < 0) {
251                         DBG("Cannot get address family of %s (%d/%s)", network,
252                                 family, gai_strerror(family));
253
254                         g_free(route);
255                         return routes;
256                 }
257         } else {
258                 switch (family) {
259                 case '4':
260                         family = AF_INET;
261                         break;
262                 case '6':
263                         family = AF_INET6;
264                         break;
265                 default:
266                         family = PF_UNSPEC;
267                         break;
268                 }
269         }
270
271         route->family = family;
272         route->network = g_strdup(network);
273         route->netmask = g_strdup(netmask);
274         route->gateway = g_strdup(gateway);
275
276         routes = g_slist_prepend(routes, route);
277         return routes;
278 }
279
280 static GSList *get_user_networks(DBusMessageIter *array)
281 {
282         DBusMessageIter entry;
283         GSList *list = NULL;
284
285         while (dbus_message_iter_get_arg_type(array) == DBUS_TYPE_ARRAY) {
286
287                 dbus_message_iter_recurse(array, &entry);
288
289                 while (dbus_message_iter_get_arg_type(&entry) ==
290                                                         DBUS_TYPE_STRUCT) {
291                         DBusMessageIter dicts;
292
293                         dbus_message_iter_recurse(&entry, &dicts);
294
295                         while (dbus_message_iter_get_arg_type(&dicts) ==
296                                                         DBUS_TYPE_ARRAY) {
297
298                                 list = read_route_dict(list, &dicts);
299                                 dbus_message_iter_next(&dicts);
300                         }
301
302                         dbus_message_iter_next(&entry);
303                 }
304
305                 dbus_message_iter_next(array);
306         }
307
308         return list;
309 }
310
311 static void set_user_networks(struct vpn_provider *provider, GSList *networks)
312 {
313         GSList *list;
314
315         for (list = networks; list; list = g_slist_next(list)) {
316                 struct vpn_route *route = list->data;
317
318                 if (__vpn_provider_append_user_route(provider,
319                                         route->family, route->network,
320                                         route->netmask, route->gateway) != 0)
321                         break;
322         }
323 }
324
325 static void del_routes(struct vpn_provider *provider)
326 {
327         GHashTableIter hash;
328         gpointer value, key;
329
330         g_hash_table_iter_init(&hash, provider->user_routes);
331         while (handle_routes && g_hash_table_iter_next(&hash,
332                                                 &key, &value)) {
333                 struct vpn_route *route = value;
334                 if (route->family == AF_INET6) {
335                         unsigned char prefixlen = atoi(route->netmask);
336                         connman_inet_del_ipv6_network_route(provider->index,
337                                                         route->network,
338                                                         prefixlen);
339                 } else
340                         connman_inet_del_host_route(provider->index,
341                                                 route->network);
342         }
343
344         g_hash_table_remove_all(provider->user_routes);
345         g_slist_free_full(provider->user_networks, free_route);
346         provider->user_networks = NULL;
347 }
348
349 static void send_value(const char *path, const char *key, const char *value)
350 {
351         const char *empty = "";
352         const char *str;
353
354         if (value)
355                 str = value;
356         else
357                 str = empty;
358
359         connman_dbus_property_changed_basic(path,
360                                         VPN_CONNECTION_INTERFACE,
361                                         key,
362                                         DBUS_TYPE_STRING,
363                                         &str);
364 }
365
366 static gboolean provider_send_changed(gpointer data)
367 {
368         struct vpn_provider *provider = data;
369
370         provider_routes_changed(provider);
371
372         provider->notify_id = 0;
373
374         return FALSE;
375 }
376
377 static void provider_schedule_changed(struct vpn_provider *provider)
378 {
379         if (provider->notify_id != 0)
380                 g_source_remove(provider->notify_id);
381
382         provider->notify_id = g_timeout_add(100, provider_send_changed,
383                                                                 provider);
384 }
385
386 static DBusMessage *get_properties(DBusConnection *conn,
387                                         DBusMessage *msg, void *data)
388 {
389         struct vpn_provider *provider = data;
390         DBusMessage *reply;
391         DBusMessageIter array;
392
393         DBG("provider %p", provider);
394
395         reply = dbus_message_new_method_return(msg);
396         if (!reply)
397                 return NULL;
398
399         dbus_message_iter_init_append(reply, &array);
400
401         append_properties(&array, provider);
402
403         return reply;
404 }
405
406 static DBusMessage *set_property(DBusConnection *conn, DBusMessage *msg,
407                                                                 void *data)
408 {
409         struct vpn_provider *provider = data;
410         DBusMessageIter iter, value;
411         const char *name;
412         int type;
413
414         DBG("conn %p", conn);
415
416         if (provider->immutable)
417                 return __connman_error_not_supported(msg);
418
419         if (!dbus_message_iter_init(msg, &iter))
420                 return __connman_error_invalid_arguments(msg);
421
422         if (dbus_message_iter_get_arg_type(&iter) != DBUS_TYPE_STRING)
423                 return __connman_error_invalid_arguments(msg);
424
425         dbus_message_iter_get_basic(&iter, &name);
426         dbus_message_iter_next(&iter);
427
428         if (dbus_message_iter_get_arg_type(&iter) != DBUS_TYPE_VARIANT)
429                 return __connman_error_invalid_arguments(msg);
430
431         dbus_message_iter_recurse(&iter, &value);
432
433         type = dbus_message_iter_get_arg_type(&value);
434
435         if (g_str_equal(name, "UserRoutes")) {
436                 GSList *networks;
437
438                 if (type != DBUS_TYPE_ARRAY)
439                         return __connman_error_invalid_arguments(msg);
440
441                 networks = get_user_networks(&value);
442                 if (networks) {
443                         del_routes(provider);
444                         provider->user_networks = networks;
445                         set_user_networks(provider, provider->user_networks);
446
447                         if (!handle_routes)
448                                 send_routes(provider, provider->user_routes,
449                                                                 "UserRoutes");
450                 }
451         } else {
452                 const char *str;
453
454                 dbus_message_iter_get_basic(&value, &str);
455                 vpn_provider_set_string(provider, name, str);
456         }
457
458         return g_dbus_create_reply(msg, DBUS_TYPE_INVALID);
459 }
460
461 static DBusMessage *clear_property(DBusConnection *conn, DBusMessage *msg,
462                                                                 void *data)
463 {
464         struct vpn_provider *provider = data;
465         const char *name;
466
467         DBG("conn %p", conn);
468
469         if (provider->immutable)
470                 return __connman_error_not_supported(msg);
471
472         dbus_message_get_args(msg, NULL, DBUS_TYPE_STRING, &name,
473                                                         DBUS_TYPE_INVALID);
474
475         if (g_str_equal(name, "UserRoutes")) {
476                 del_routes(provider);
477
478                 if (!handle_routes)
479                         send_routes(provider, provider->user_routes, name);
480         } else if (vpn_provider_get_string(provider, name)) {
481                 vpn_provider_set_string(provider, name, NULL);
482         } else {
483                 return __connman_error_invalid_property(msg);
484         }
485
486         return g_dbus_create_reply(msg, DBUS_TYPE_INVALID);
487 }
488
489 static DBusMessage *do_connect(DBusConnection *conn, DBusMessage *msg,
490                                                                 void *data)
491 {
492         struct vpn_provider *provider = data;
493         int err;
494
495         DBG("conn %p provider %p", conn, provider);
496
497         err = __vpn_provider_connect(provider, msg);
498         if (err < 0)
499                 return __connman_error_failed(msg, -err);
500
501         return NULL;
502 }
503
504 static DBusMessage *do_connect2(DBusConnection *conn, DBusMessage *msg,
505                                                                 void *data)
506 {
507         return do_connect(conn, msg, data);
508 }
509
510 static DBusMessage *do_disconnect(DBusConnection *conn, DBusMessage *msg,
511                                                                 void *data)
512 {
513         struct vpn_provider *provider = data;
514         int err;
515
516         DBG("conn %p provider %p", conn, provider);
517
518         err = __vpn_provider_disconnect(provider);
519         if (err < 0 && err != -EINPROGRESS)
520                 return __connman_error_failed(msg, -err);
521
522         return g_dbus_create_reply(msg, DBUS_TYPE_INVALID);
523 }
524
525 static const GDBusMethodTable connection_methods[] = {
526         { GDBUS_METHOD("GetProperties",
527                         NULL, GDBUS_ARGS({ "properties", "a{sv}" }),
528                         get_properties) },
529         { GDBUS_METHOD("SetProperty",
530                         GDBUS_ARGS({ "name", "s" }, { "value", "v" }),
531                         NULL, set_property) },
532         { GDBUS_METHOD("ClearProperty",
533                         GDBUS_ARGS({ "name", "s" }), NULL,
534                         clear_property) },
535         { GDBUS_ASYNC_METHOD("Connect", NULL, NULL, do_connect) },
536         { GDBUS_ASYNC_METHOD("Connect2",
537                         GDBUS_ARGS({ "dbus_sender", "s" }),
538                         NULL, do_connect2) },
539         { GDBUS_METHOD("Disconnect", NULL, NULL, do_disconnect) },
540         { },
541 };
542
543 static const GDBusSignalTable connection_signals[] = {
544         { GDBUS_SIGNAL("PropertyChanged",
545                         GDBUS_ARGS({ "name", "s" }, { "value", "v" })) },
546         { },
547 };
548
549 static void resolv_result(GResolvResultStatus status,
550                                         char **results, gpointer user_data)
551 {
552         struct vpn_provider *provider = user_data;
553
554         DBG("status %d", status);
555
556         if (status == G_RESOLV_RESULT_STATUS_SUCCESS && results &&
557                                                 g_strv_length(results) > 0)
558                 provider->host_ip = g_strdupv(results);
559
560         vpn_provider_unref(provider);
561
562         /* Remove the resolver here so that it will not be left
563          * hanging around and cause double free in unregister_provider()
564          */
565         g_resolv_unref(provider->resolv);
566         provider->resolv = NULL;
567 }
568
569 static void provider_resolv_host_addr(struct vpn_provider *provider)
570 {
571         if (!provider->host)
572                 return;
573
574         if (connman_inet_check_ipaddress(provider->host) > 0)
575                 return;
576
577         if (provider->host_ip)
578                 return;
579
580         /*
581          * If the hostname is not numeric, try to resolv it. We do not wait
582          * the result as it might take some time. We will get the result
583          * before VPN will feed routes to us because VPN client will need
584          * the IP address also before VPN connection can be established.
585          */
586         provider->resolv = g_resolv_new(0);
587         if (!provider->resolv) {
588                 DBG("Cannot resolv %s", provider->host);
589                 return;
590         }
591
592         DBG("Trying to resolv %s", provider->host);
593
594         vpn_provider_ref(provider);
595
596         g_resolv_lookup_hostname(provider->resolv, provider->host,
597                                 resolv_result, provider);
598 }
599
600 void __vpn_provider_append_properties(struct vpn_provider *provider,
601                                                         DBusMessageIter *iter)
602 {
603         if (provider->host)
604                 connman_dbus_dict_append_basic(iter, "Host",
605                                         DBUS_TYPE_STRING, &provider->host);
606
607         if (provider->domain)
608                 connman_dbus_dict_append_basic(iter, "Domain",
609                                         DBUS_TYPE_STRING, &provider->domain);
610
611         if (provider->type)
612                 connman_dbus_dict_append_basic(iter, "Type", DBUS_TYPE_STRING,
613                                                  &provider->type);
614 }
615
616 int __vpn_provider_append_user_route(struct vpn_provider *provider,
617                                 int family, const char *network,
618                                 const char *netmask, const char *gateway)
619 {
620         struct vpn_route *route;
621         char *key = g_strdup_printf("%d/%s/%s/%s", family, network,
622                                 netmask, gateway ? gateway : "");
623
624         DBG("family %d network %s netmask %s gw %s", family, network,
625                                                         netmask, gateway);
626
627         route = g_hash_table_lookup(provider->user_routes, key);
628         if (!route) {
629                 route = g_try_new0(struct vpn_route, 1);
630                 if (!route) {
631                         connman_error("out of memory");
632                         return -ENOMEM;
633                 }
634
635                 route->family = family;
636                 route->network = g_strdup(network);
637                 route->netmask = g_strdup(netmask);
638                 route->gateway = g_strdup(gateway);
639
640                 g_hash_table_replace(provider->user_routes, key, route);
641         } else
642                 g_free(key);
643
644         return 0;
645 }
646
647 static struct vpn_route *get_route(char *route_str)
648 {
649         char **elems = g_strsplit(route_str, "/", 0);
650         char *network, *netmask, *gateway, *family_str;
651         int family = PF_UNSPEC;
652         struct vpn_route *route = NULL;
653
654         if (!elems)
655                 return NULL;
656
657         family_str = elems[0];
658
659         network = elems[1];
660         if (!network || network[0] == '\0')
661                 goto out;
662
663         netmask = elems[2];
664         if (!netmask || netmask[0] == '\0')
665                 goto out;
666
667         gateway = elems[3];
668
669         route = g_try_new0(struct vpn_route, 1);
670         if (!route)
671                 goto out;
672
673         if (family_str[0] == '\0' || atoi(family_str) == 0) {
674                 family = PF_UNSPEC;
675         } else {
676                 switch (family_str[0]) {
677                 case '4':
678                         family = AF_INET;
679                         break;
680                 case '6':
681                         family = AF_INET6;
682                         break;
683                 }
684         }
685
686         if (g_strrstr(network, ":")) {
687                 if (family != PF_UNSPEC && family != AF_INET6)
688                         DBG("You have IPv6 address but you have non IPv6 route");
689         } else if (g_strrstr(network, ".")) {
690                 if (family != PF_UNSPEC && family != AF_INET)
691                         DBG("You have IPv4 address but you have non IPv4 route");
692
693                 if (!g_strrstr(netmask, ".")) {
694                         /* We have netmask length */
695                         in_addr_t addr;
696                         struct in_addr netmask_in;
697                         unsigned char prefix_len = 32;
698                         char *ptr;
699                         long int value = strtol(netmask, &ptr, 10);
700
701                         if (ptr != netmask && *ptr == '\0' && value <= 32)
702                                 prefix_len = value;
703
704                         addr = 0xffffffff << (32 - prefix_len);
705                         netmask_in.s_addr = htonl(addr);
706                         netmask = inet_ntoa(netmask_in);
707
708                         DBG("network %s netmask %s", network, netmask);
709                 }
710         }
711
712         if (family == PF_UNSPEC) {
713                 family = connman_inet_check_ipaddress(network);
714                 if (family < 0 || family == PF_UNSPEC)
715                         goto out;
716         }
717
718         route->family = family;
719         route->network = g_strdup(network);
720         route->netmask = g_strdup(netmask);
721         route->gateway = g_strdup(gateway);
722
723 out:
724         g_strfreev(elems);
725         return route;
726 }
727
728 static GSList *get_routes(gchar **networks)
729 {
730         struct vpn_route *route;
731         GSList *routes = NULL;
732         int i;
733
734         for (i = 0; networks[i]; i++) {
735                 route = get_route(networks[i]);
736                 if (route)
737                         routes = g_slist_prepend(routes, route);
738         }
739
740         return routes;
741 }
742
743 static int provider_load_from_keyfile(struct vpn_provider *provider,
744                 GKeyFile *keyfile)
745 {
746         gsize idx = 0;
747         gchar **settings;
748         gchar *key, *value;
749         gsize length, num_user_networks;
750         gchar **networks = NULL;
751
752         settings = g_key_file_get_keys(keyfile, provider->identifier, &length,
753                                 NULL);
754         if (!settings) {
755                 g_key_file_free(keyfile);
756                 return -ENOENT;
757         }
758
759         while (idx < length) {
760                 key = settings[idx];
761                 if (key) {
762                         if (g_str_equal(key, "Networks")) {
763                                 networks = __vpn_config_get_string_list(keyfile,
764                                                 provider->identifier,
765                                                 key,
766                                                 &num_user_networks,
767                                                 NULL);
768                                 provider->user_networks = get_routes(networks);
769
770                         } else {
771                                 value = __vpn_config_get_string(keyfile,
772                                                         provider->identifier,
773                                                         key, NULL);
774                                 vpn_provider_set_string(provider, key,
775                                                         value);
776                                 g_free(value);
777                         }
778                 }
779                 idx += 1;
780         }
781         g_strfreev(settings);
782         g_strfreev(networks);
783
784         if (provider->user_networks)
785                 set_user_networks(provider, provider->user_networks);
786
787         return 0;
788 }
789
790
791 static int vpn_provider_load(struct vpn_provider *provider)
792 {
793         GKeyFile *keyfile;
794
795         DBG("provider %p", provider);
796
797         keyfile = __connman_storage_load_provider(provider->identifier);
798         if (!keyfile)
799                 return -ENOENT;
800
801         provider_load_from_keyfile(provider, keyfile);
802
803         g_key_file_free(keyfile);
804         return 0;
805 }
806
807 static gchar **create_network_list(GSList *networks, gsize *count)
808 {
809         GSList *list;
810         gchar **result = NULL;
811         gchar **prev_result;
812         unsigned int num_elems = 0;
813
814         for (list = networks; list; list = g_slist_next(list)) {
815                 struct vpn_route *route = list->data;
816                 int family;
817
818                 prev_result = result;
819                 result = g_try_realloc(result,
820                                 (num_elems + 1) * sizeof(gchar *));
821                 if (!result) {
822                         g_free(prev_result);
823                         return NULL;
824                 }
825
826                 switch (route->family) {
827                 case AF_INET:
828                         family = 4;
829                         break;
830                 case AF_INET6:
831                         family = 6;
832                         break;
833                 default:
834                         family = 0;
835                         break;
836                 }
837
838                 result[num_elems] = g_strdup_printf("%d/%s/%s/%s",
839                                 family, route->network, route->netmask,
840                                 !route->gateway ? "" : route->gateway);
841
842                 num_elems++;
843         }
844
845         prev_result = result;
846         result = g_try_realloc(result, (num_elems + 1) * sizeof(gchar *));
847         if (!result) {
848                 g_free(prev_result);
849                 return NULL;
850         }
851
852         result[num_elems] = NULL;
853         *count = num_elems;
854         return result;
855 }
856
857 static int vpn_provider_save(struct vpn_provider *provider)
858 {
859         GKeyFile *keyfile;
860
861         DBG("provider %p immutable %s", provider,
862                                         provider->immutable ? "yes" : "no");
863
864         if (provider->immutable) {
865                 /*
866                  * Do not save providers that are provisioned via .config
867                  * file.
868                  */
869                 return -EPERM;
870         }
871
872         keyfile = g_key_file_new();
873         if (!keyfile)
874                 return -ENOMEM;
875
876         g_key_file_set_string(keyfile, provider->identifier,
877                         "Name", provider->name);
878         g_key_file_set_string(keyfile, provider->identifier,
879                         "Type", provider->type);
880         g_key_file_set_string(keyfile, provider->identifier,
881                         "Host", provider->host);
882         g_key_file_set_string(keyfile, provider->identifier,
883                         "VPN.Domain", provider->domain);
884         if (provider->user_networks) {
885                 gchar **networks;
886                 gsize network_count;
887
888                 networks = create_network_list(provider->user_networks,
889                                                         &network_count);
890                 if (networks) {
891                         g_key_file_set_string_list(keyfile,
892                                                 provider->identifier,
893                                                 "Networks",
894                                                 (const gchar ** const)networks,
895                                                 network_count);
896                         g_strfreev(networks);
897                 }
898         }
899
900         if (provider->config_file && strlen(provider->config_file) > 0)
901                 g_key_file_set_string(keyfile, provider->identifier,
902                                 "Config.file", provider->config_file);
903
904         if (provider->config_entry &&
905                                         strlen(provider->config_entry) > 0)
906                 g_key_file_set_string(keyfile, provider->identifier,
907                                 "Config.ident", provider->config_entry);
908
909         if (provider->driver && provider->driver->save)
910                 provider->driver->save(provider, keyfile);
911
912         __connman_storage_save_provider(keyfile, provider->identifier);
913         g_key_file_free(keyfile);
914
915         return 0;
916 }
917
918 struct vpn_provider *__vpn_provider_lookup(const char *identifier)
919 {
920         struct vpn_provider *provider = NULL;
921
922         provider = g_hash_table_lookup(provider_hash, identifier);
923
924         return provider;
925 }
926
927 static bool match_driver(struct vpn_provider *provider,
928                                 struct vpn_provider_driver *driver)
929 {
930         if (g_strcmp0(driver->name, provider->type) == 0)
931                 return true;
932
933         return false;
934 }
935
936 static int provider_probe(struct vpn_provider *provider)
937 {
938         GSList *list;
939
940         DBG("provider %p driver %p name %s", provider, provider->driver,
941                                                 provider->name);
942
943         if (provider->driver)
944                 return -EALREADY;
945
946         for (list = driver_list; list; list = list->next) {
947                 struct vpn_provider_driver *driver = list->data;
948
949                 if (!match_driver(provider, driver))
950                         continue;
951
952                 DBG("driver %p name %s", driver, driver->name);
953
954                 if (driver->probe && driver->probe(provider) == 0) {
955                         provider->driver = driver;
956                         break;
957                 }
958         }
959
960         if (!provider->driver)
961                 return -ENODEV;
962
963         return 0;
964 }
965
966 static void provider_remove(struct vpn_provider *provider)
967 {
968         if (provider->driver) {
969                 provider->driver->remove(provider);
970                 provider->driver = NULL;
971         }
972 }
973
974 static int provider_register(struct vpn_provider *provider)
975 {
976         return provider_probe(provider);
977 }
978
979 static void provider_unregister(struct vpn_provider *provider)
980 {
981         provider_remove(provider);
982 }
983
984 struct vpn_provider *
985 vpn_provider_ref_debug(struct vpn_provider *provider,
986                         const char *file, int line, const char *caller)
987 {
988         DBG("%p ref %d by %s:%d:%s()", provider, provider->refcount + 1,
989                 file, line, caller);
990
991         __sync_fetch_and_add(&provider->refcount, 1);
992
993         return provider;
994 }
995
996 static void provider_destruct(struct vpn_provider *provider)
997 {
998         DBG("provider %p", provider);
999
1000         if (provider->notify_id != 0)
1001                 g_source_remove(provider->notify_id);
1002
1003         g_free(provider->name);
1004         g_free(provider->type);
1005         g_free(provider->host);
1006         g_free(provider->domain);
1007         g_free(provider->identifier);
1008         g_free(provider->path);
1009         g_slist_free_full(provider->user_networks, free_route);
1010         g_strfreev(provider->nameservers);
1011         g_hash_table_destroy(provider->routes);
1012         g_hash_table_destroy(provider->user_routes);
1013         g_hash_table_destroy(provider->setting_strings);
1014         if (provider->resolv) {
1015                 g_resolv_unref(provider->resolv);
1016                 provider->resolv = NULL;
1017         }
1018         __vpn_ipconfig_unref(provider->ipconfig_ipv4);
1019         __vpn_ipconfig_unref(provider->ipconfig_ipv6);
1020
1021         g_strfreev(provider->host_ip);
1022         g_free(provider->config_file);
1023         g_free(provider->config_entry);
1024         connman_ipaddress_free(provider->prev_ipv4_addr);
1025         connman_ipaddress_free(provider->prev_ipv6_addr);
1026         g_free(provider);
1027 }
1028
1029 void vpn_provider_unref_debug(struct vpn_provider *provider,
1030                                 const char *file, int line, const char *caller)
1031 {
1032         DBG("%p ref %d by %s:%d:%s()", provider, provider->refcount - 1,
1033                 file, line, caller);
1034
1035         if (__sync_fetch_and_sub(&provider->refcount, 1) != 1)
1036                 return;
1037
1038         provider_remove(provider);
1039
1040         provider_destruct(provider);
1041 }
1042
1043 static void configuration_count_add(void)
1044 {
1045         DBG("count %d", configuration_count + 1);
1046
1047         __sync_fetch_and_add(&configuration_count, 1);
1048 }
1049
1050 static void configuration_count_del(void)
1051 {
1052         DBG("count %d", configuration_count - 1);
1053
1054         if (__sync_fetch_and_sub(&configuration_count, 1) != 1)
1055                 return;
1056 }
1057
1058 int __vpn_provider_disconnect(struct vpn_provider *provider)
1059 {
1060         int err;
1061
1062         DBG("provider %p", provider);
1063
1064         if (provider->driver && provider->driver->disconnect)
1065                 err = provider->driver->disconnect(provider);
1066         else
1067                 return -EOPNOTSUPP;
1068
1069         if (err == -EINPROGRESS)
1070                 vpn_provider_set_state(provider, VPN_PROVIDER_STATE_CONNECT);
1071
1072         return err;
1073 }
1074
1075 static void connect_cb(struct vpn_provider *provider, void *user_data,
1076                                                                 int error)
1077 {
1078         DBusMessage *pending = user_data;
1079
1080         DBG("provider %p user %p error %d", provider, user_data, error);
1081
1082         if (error != 0) {
1083                 DBusMessage *reply = __connman_error_failed(pending, error);
1084                 if (reply)
1085                         g_dbus_send_message(connection, reply);
1086
1087                 vpn_provider_indicate_error(provider,
1088                                         VPN_PROVIDER_ERROR_CONNECT_FAILED);
1089                 vpn_provider_set_state(provider, VPN_PROVIDER_STATE_FAILURE);
1090         } else
1091                 g_dbus_send_reply(connection, pending, DBUS_TYPE_INVALID);
1092
1093         dbus_message_unref(pending);
1094 }
1095
1096 int __vpn_provider_connect(struct vpn_provider *provider, DBusMessage *msg)
1097 {
1098         int err;
1099
1100         DBG("provider %p", provider);
1101
1102         if (provider->driver && provider->driver->connect) {
1103                 const char *dbus_sender = dbus_message_get_sender(msg);
1104
1105                 dbus_message_ref(msg);
1106
1107                 if (dbus_message_has_signature(msg,
1108                                                 DBUS_TYPE_STRING_AS_STRING)) {
1109                         const char *sender = NULL;
1110
1111                         dbus_message_get_args(msg, NULL, DBUS_TYPE_STRING,
1112                                         &sender, DBUS_TYPE_INVALID);
1113                         if (sender && sender[0])
1114                                 dbus_sender = sender;
1115                 }
1116
1117                 err = provider->driver->connect(provider, connect_cb,
1118                                                 dbus_sender, msg);
1119         } else
1120                 return -EOPNOTSUPP;
1121
1122         if (err == -EINPROGRESS)
1123                 vpn_provider_set_state(provider, VPN_PROVIDER_STATE_CONNECT);
1124
1125         return err;
1126 }
1127
1128 static void connection_removed_signal(struct vpn_provider *provider)
1129 {
1130         DBusMessage *signal;
1131         DBusMessageIter iter;
1132
1133         signal = dbus_message_new_signal(VPN_MANAGER_PATH,
1134                         VPN_MANAGER_INTERFACE, "ConnectionRemoved");
1135         if (!signal)
1136                 return;
1137
1138         dbus_message_iter_init_append(signal, &iter);
1139         dbus_message_iter_append_basic(&iter, DBUS_TYPE_OBJECT_PATH,
1140                                                         &provider->path);
1141         dbus_connection_send(connection, signal, NULL);
1142         dbus_message_unref(signal);
1143 }
1144
1145 static char *get_ident(const char *path)
1146 {
1147         char *pos;
1148
1149         if (*path != '/')
1150                 return NULL;
1151
1152         pos = strrchr(path, '/');
1153         if (!pos)
1154                 return NULL;
1155
1156         return pos + 1;
1157 }
1158
1159 int __vpn_provider_remove(const char *path)
1160 {
1161         struct vpn_provider *provider;
1162         char *ident;
1163
1164         DBG("path %s", path);
1165
1166         ident = get_ident(path);
1167
1168         provider = __vpn_provider_lookup(ident);
1169         if (provider)
1170                 return __vpn_provider_delete(provider);
1171
1172         return -ENXIO;
1173 }
1174
1175 int __vpn_provider_delete(struct vpn_provider *provider)
1176 {
1177         DBG("Deleting VPN %s", provider->identifier);
1178
1179         connection_removed_signal(provider);
1180
1181         provider_unregister(provider);
1182
1183         __connman_storage_remove_provider(provider->identifier);
1184
1185         g_hash_table_remove(provider_hash, provider->identifier);
1186
1187         return 0;
1188 }
1189
1190 static void append_ipv4(DBusMessageIter *iter, void *user_data)
1191 {
1192         struct vpn_provider *provider = user_data;
1193         const char *address, *gateway, *peer;
1194
1195         address = __vpn_ipconfig_get_local(provider->ipconfig_ipv4);
1196         if (address) {
1197                 in_addr_t addr;
1198                 struct in_addr netmask;
1199                 char *mask;
1200                 int prefixlen;
1201
1202                 prefixlen = __vpn_ipconfig_get_prefixlen(
1203                                                 provider->ipconfig_ipv4);
1204
1205                 addr = 0xffffffff << (32 - prefixlen);
1206                 netmask.s_addr = htonl(addr);
1207                 mask = inet_ntoa(netmask);
1208
1209                 connman_dbus_dict_append_basic(iter, "Address",
1210                                                 DBUS_TYPE_STRING, &address);
1211
1212                 connman_dbus_dict_append_basic(iter, "Netmask",
1213                                                 DBUS_TYPE_STRING, &mask);
1214         }
1215
1216         gateway = __vpn_ipconfig_get_gateway(provider->ipconfig_ipv4);
1217         if (gateway)
1218                 connman_dbus_dict_append_basic(iter, "Gateway",
1219                                                 DBUS_TYPE_STRING, &gateway);
1220
1221         peer = __vpn_ipconfig_get_peer(provider->ipconfig_ipv4);
1222         if (peer)
1223                 connman_dbus_dict_append_basic(iter, "Peer",
1224                                                 DBUS_TYPE_STRING, &peer);
1225 }
1226
1227 static void append_ipv6(DBusMessageIter *iter, void *user_data)
1228 {
1229         struct vpn_provider *provider = user_data;
1230         const char *address, *gateway, *peer;
1231
1232         address = __vpn_ipconfig_get_local(provider->ipconfig_ipv6);
1233         if (address) {
1234                 unsigned char prefixlen;
1235
1236                 connman_dbus_dict_append_basic(iter, "Address",
1237                                                 DBUS_TYPE_STRING, &address);
1238
1239                 prefixlen = __vpn_ipconfig_get_prefixlen(
1240                                                 provider->ipconfig_ipv6);
1241
1242                 connman_dbus_dict_append_basic(iter, "PrefixLength",
1243                                                 DBUS_TYPE_BYTE, &prefixlen);
1244         }
1245
1246         gateway = __vpn_ipconfig_get_gateway(provider->ipconfig_ipv6);
1247         if (gateway)
1248                 connman_dbus_dict_append_basic(iter, "Gateway",
1249                                                 DBUS_TYPE_STRING, &gateway);
1250
1251         peer = __vpn_ipconfig_get_peer(provider->ipconfig_ipv6);
1252         if (peer)
1253                 connman_dbus_dict_append_basic(iter, "Peer",
1254                                                 DBUS_TYPE_STRING, &peer);
1255 }
1256
1257 static const char *state2string(enum vpn_provider_state state)
1258 {
1259         switch (state) {
1260         case VPN_PROVIDER_STATE_UNKNOWN:
1261                 break;
1262         case VPN_PROVIDER_STATE_IDLE:
1263                 return "idle";
1264         case VPN_PROVIDER_STATE_CONNECT:
1265                 return "configuration";
1266         case VPN_PROVIDER_STATE_READY:
1267                 return "ready";
1268         case VPN_PROVIDER_STATE_DISCONNECT:
1269                 return "disconnect";
1270         case VPN_PROVIDER_STATE_FAILURE:
1271                 return "failure";
1272         }
1273
1274         return NULL;
1275 }
1276
1277 static void append_nameservers(DBusMessageIter *iter, char **servers)
1278 {
1279         int i;
1280
1281         DBG("%p", servers);
1282
1283         for (i = 0; servers[i]; i++) {
1284                 DBG("servers[%d] %s", i, servers[i]);
1285                 dbus_message_iter_append_basic(iter,
1286                                         DBUS_TYPE_STRING, &servers[i]);
1287         }
1288 }
1289
1290 static void append_dns(DBusMessageIter *iter, void *user_data)
1291 {
1292         struct vpn_provider *provider = user_data;
1293
1294         if (provider->nameservers)
1295                 append_nameservers(iter, provider->nameservers);
1296 }
1297
1298 static int provider_indicate_state(struct vpn_provider *provider,
1299                                 enum vpn_provider_state state)
1300 {
1301         const char *str;
1302         enum vpn_provider_state old_state;
1303
1304         str = state2string(state);
1305         DBG("provider %p state %s/%d", provider, str, state);
1306         if (!str)
1307                 return -EINVAL;
1308
1309         old_state = provider->state;
1310         provider->state = state;
1311
1312         if (state == VPN_PROVIDER_STATE_READY) {
1313                 connman_dbus_property_changed_basic(provider->path,
1314                                         VPN_CONNECTION_INTERFACE, "Index",
1315                                         DBUS_TYPE_INT32, &provider->index);
1316
1317                 if (provider->family == AF_INET)
1318                         connman_dbus_property_changed_dict(provider->path,
1319                                         VPN_CONNECTION_INTERFACE, "IPv4",
1320                                         append_ipv4, provider);
1321                 else if (provider->family == AF_INET6)
1322                         connman_dbus_property_changed_dict(provider->path,
1323                                         VPN_CONNECTION_INTERFACE, "IPv6",
1324                                         append_ipv6, provider);
1325
1326                 connman_dbus_property_changed_array(provider->path,
1327                                                 VPN_CONNECTION_INTERFACE,
1328                                                 "Nameservers",
1329                                                 DBUS_TYPE_STRING,
1330                                                 append_dns, provider);
1331
1332                 if (provider->domain)
1333                         connman_dbus_property_changed_basic(provider->path,
1334                                                 VPN_CONNECTION_INTERFACE,
1335                                                 "Domain",
1336                                                 DBUS_TYPE_STRING,
1337                                                 &provider->domain);
1338         }
1339
1340         if (old_state != state)
1341                 connman_dbus_property_changed_basic(provider->path,
1342                                         VPN_CONNECTION_INTERFACE, "State",
1343                                         DBUS_TYPE_STRING, &str);
1344
1345         return 0;
1346 }
1347
1348 static void append_state(DBusMessageIter *iter,
1349                                         struct vpn_provider *provider)
1350 {
1351         char *str;
1352
1353         switch (provider->state) {
1354         case VPN_PROVIDER_STATE_UNKNOWN:
1355         case VPN_PROVIDER_STATE_IDLE:
1356                 str = "idle";
1357                 break;
1358         case VPN_PROVIDER_STATE_CONNECT:
1359                 str = "configuration";
1360                 break;
1361         case VPN_PROVIDER_STATE_READY:
1362                 str = "ready";
1363                 break;
1364         case VPN_PROVIDER_STATE_DISCONNECT:
1365                 str = "disconnect";
1366                 break;
1367         case VPN_PROVIDER_STATE_FAILURE:
1368                 str = "failure";
1369                 break;
1370         }
1371
1372         connman_dbus_dict_append_basic(iter, "State",
1373                                 DBUS_TYPE_STRING, &str);
1374 }
1375
1376 static void append_properties(DBusMessageIter *iter,
1377                                         struct vpn_provider *provider)
1378 {
1379         DBusMessageIter dict;
1380         GHashTableIter hash;
1381         gpointer value, key;
1382         dbus_bool_t immutable;
1383
1384         connman_dbus_dict_open(iter, &dict);
1385
1386         append_state(&dict, provider);
1387
1388         if (provider->type)
1389                 connman_dbus_dict_append_basic(&dict, "Type",
1390                                         DBUS_TYPE_STRING, &provider->type);
1391
1392         if (provider->name)
1393                 connman_dbus_dict_append_basic(&dict, "Name",
1394                                         DBUS_TYPE_STRING, &provider->name);
1395
1396         if (provider->host)
1397                 connman_dbus_dict_append_basic(&dict, "Host",
1398                                         DBUS_TYPE_STRING, &provider->host);
1399         if (provider->index >= 0)
1400                 connman_dbus_dict_append_basic(&dict, "Index",
1401                                         DBUS_TYPE_INT32, &provider->index);
1402         if (provider->domain)
1403                 connman_dbus_dict_append_basic(&dict, "Domain",
1404                                         DBUS_TYPE_STRING, &provider->domain);
1405
1406         immutable = provider->immutable;
1407         connman_dbus_dict_append_basic(&dict, "Immutable", DBUS_TYPE_BOOLEAN,
1408                                         &immutable);
1409
1410         if (provider->family == AF_INET)
1411                 connman_dbus_dict_append_dict(&dict, "IPv4", append_ipv4,
1412                                                 provider);
1413         else if (provider->family == AF_INET6)
1414                 connman_dbus_dict_append_dict(&dict, "IPv6", append_ipv6,
1415                                                 provider);
1416
1417         connman_dbus_dict_append_array(&dict, "Nameservers",
1418                                 DBUS_TYPE_STRING, append_dns, provider);
1419
1420         connman_dbus_dict_append_array(&dict, "UserRoutes",
1421                                 DBUS_TYPE_DICT_ENTRY, append_routes,
1422                                 provider->user_routes);
1423
1424         connman_dbus_dict_append_array(&dict, "ServerRoutes",
1425                                 DBUS_TYPE_DICT_ENTRY, append_routes,
1426                                 provider->routes);
1427
1428         if (provider->setting_strings) {
1429                 g_hash_table_iter_init(&hash, provider->setting_strings);
1430
1431                 while (g_hash_table_iter_next(&hash, &key, &value)) {
1432                         struct vpn_setting *setting = value;
1433
1434                         if (!setting->hide_value &&
1435                                                         setting->value)
1436                                 connman_dbus_dict_append_basic(&dict, key,
1437                                                         DBUS_TYPE_STRING,
1438                                                         &setting->value);
1439                 }
1440         }
1441
1442         connman_dbus_dict_close(iter, &dict);
1443 }
1444
1445 static void connection_added_signal(struct vpn_provider *provider)
1446 {
1447         DBusMessage *signal;
1448         DBusMessageIter iter;
1449
1450         signal = dbus_message_new_signal(VPN_MANAGER_PATH,
1451                         VPN_MANAGER_INTERFACE, "ConnectionAdded");
1452         if (!signal)
1453                 return;
1454
1455         dbus_message_iter_init_append(signal, &iter);
1456         dbus_message_iter_append_basic(&iter, DBUS_TYPE_OBJECT_PATH,
1457                                                         &provider->path);
1458         append_properties(&iter, provider);
1459
1460         dbus_connection_send(connection, signal, NULL);
1461         dbus_message_unref(signal);
1462 }
1463
1464 static bool check_host(char **hosts, char *host)
1465 {
1466         int i;
1467
1468         if (!hosts)
1469                 return false;
1470
1471         for (i = 0; hosts[i]; i++) {
1472                 if (g_strcmp0(hosts[i], host) == 0)
1473                         return true;
1474         }
1475
1476         return false;
1477 }
1478
1479 static void provider_append_routes(gpointer key, gpointer value,
1480                                         gpointer user_data)
1481 {
1482         struct vpn_route *route = value;
1483         struct vpn_provider *provider = user_data;
1484         int index = provider->index;
1485
1486         if (!handle_routes)
1487                 return;
1488
1489         /*
1490          * If the VPN administrator/user has given a route to
1491          * VPN server, then we must discard that because the
1492          * server cannot be contacted via VPN tunnel.
1493          */
1494         if (check_host(provider->host_ip, route->network)) {
1495                 DBG("Discarding VPN route to %s via %s at index %d",
1496                         route->network, route->gateway, index);
1497                 return;
1498         }
1499
1500         if (route->family == AF_INET6) {
1501                 unsigned char prefix_len = atoi(route->netmask);
1502
1503                 connman_inet_add_ipv6_network_route(index, route->network,
1504                                                         route->gateway,
1505                                                         prefix_len);
1506         } else {
1507                 connman_inet_add_network_route(index, route->network,
1508                                                 route->gateway,
1509                                                 route->netmask);
1510         }
1511 }
1512
1513 static int set_connected(struct vpn_provider *provider,
1514                                         bool connected)
1515 {
1516         struct vpn_ipconfig *ipconfig;
1517
1518         DBG("provider %p id %s connected %d", provider,
1519                                         provider->identifier, connected);
1520
1521         if (connected) {
1522                 if (provider->family == AF_INET6)
1523                         ipconfig = provider->ipconfig_ipv6;
1524                 else
1525                         ipconfig = provider->ipconfig_ipv4;
1526
1527                 __vpn_ipconfig_address_add(ipconfig, provider->family);
1528
1529                 if (handle_routes)
1530                         __vpn_ipconfig_gateway_add(ipconfig, provider->family);
1531
1532                 provider_indicate_state(provider,
1533                                         VPN_PROVIDER_STATE_READY);
1534
1535                 g_hash_table_foreach(provider->routes, provider_append_routes,
1536                                         provider);
1537
1538                 g_hash_table_foreach(provider->user_routes,
1539                                         provider_append_routes, provider);
1540
1541         } else {
1542                 provider_indicate_state(provider,
1543                                         VPN_PROVIDER_STATE_DISCONNECT);
1544
1545                 provider_indicate_state(provider,
1546                                         VPN_PROVIDER_STATE_IDLE);
1547         }
1548
1549         return 0;
1550 }
1551
1552 int vpn_provider_set_state(struct vpn_provider *provider,
1553                                         enum vpn_provider_state state)
1554 {
1555         if (!provider)
1556                 return -EINVAL;
1557
1558         switch (state) {
1559         case VPN_PROVIDER_STATE_UNKNOWN:
1560                 return -EINVAL;
1561         case VPN_PROVIDER_STATE_IDLE:
1562                 return set_connected(provider, false);
1563         case VPN_PROVIDER_STATE_CONNECT:
1564                 return provider_indicate_state(provider, state);
1565         case VPN_PROVIDER_STATE_READY:
1566                 return set_connected(provider, true);
1567         case VPN_PROVIDER_STATE_DISCONNECT:
1568                 return provider_indicate_state(provider, state);
1569         case VPN_PROVIDER_STATE_FAILURE:
1570                 return provider_indicate_state(provider, state);
1571         }
1572         return -EINVAL;
1573 }
1574
1575 int vpn_provider_indicate_error(struct vpn_provider *provider,
1576                                         enum vpn_provider_error error)
1577 {
1578         DBG("provider %p id %s error %d", provider, provider->identifier,
1579                                                                         error);
1580
1581         vpn_provider_set_state(provider, VPN_PROVIDER_STATE_FAILURE);
1582
1583         switch (error) {
1584         case VPN_PROVIDER_ERROR_UNKNOWN:
1585         case VPN_PROVIDER_ERROR_CONNECT_FAILED:
1586                 break;
1587
1588         case VPN_PROVIDER_ERROR_LOGIN_FAILED:
1589         case VPN_PROVIDER_ERROR_AUTH_FAILED:
1590                 vpn_provider_set_state(provider, VPN_PROVIDER_STATE_IDLE);
1591                 break;
1592         }
1593
1594         if (provider->driver && provider->driver->set_state)
1595                 provider->driver->set_state(provider, provider->state);
1596
1597         return 0;
1598 }
1599
1600 static int connection_unregister(struct vpn_provider *provider)
1601 {
1602         DBG("provider %p path %s", provider, provider->path);
1603
1604         if (!provider->path)
1605                 return -EALREADY;
1606
1607         g_dbus_unregister_interface(connection, provider->path,
1608                                 VPN_CONNECTION_INTERFACE);
1609
1610         g_free(provider->path);
1611         provider->path = NULL;
1612
1613         return 0;
1614 }
1615
1616 static int connection_register(struct vpn_provider *provider)
1617 {
1618         DBG("provider %p path %s", provider, provider->path);
1619
1620         if (provider->path)
1621                 return -EALREADY;
1622
1623         provider->path = g_strdup_printf("%s/connection/%s", VPN_PATH,
1624                                                 provider->identifier);
1625
1626         g_dbus_register_interface(connection, provider->path,
1627                                 VPN_CONNECTION_INTERFACE,
1628                                 connection_methods, connection_signals,
1629                                 NULL, provider, NULL);
1630
1631         return 0;
1632 }
1633
1634 static void unregister_provider(gpointer data)
1635 {
1636         struct vpn_provider *provider = data;
1637
1638         configuration_count_del();
1639
1640         connection_unregister(provider);
1641
1642         /* If the provider has any DNS resolver queries pending,
1643          * they need to be cleared here because the unref will not
1644          * be able to do that (because the provider_resolv_host_addr()
1645          * has increased the ref count by 1). This is quite rare as
1646          * normally the resolving either returns a value or has a
1647          * timeout which clears the memory. Typically resolv_result() will
1648          * unref the provider but in this case that call has not yet
1649          * happened.
1650          */
1651         if (provider->resolv)
1652                 vpn_provider_unref(provider);
1653
1654         vpn_provider_unref(provider);
1655 }
1656
1657 static void provider_initialize(struct vpn_provider *provider)
1658 {
1659         DBG("provider %p", provider);
1660
1661         provider->index = 0;
1662         provider->fd = -1;
1663         provider->name = NULL;
1664         provider->type = NULL;
1665         provider->domain = NULL;
1666         provider->identifier = NULL;
1667         provider->immutable = false;
1668         provider->user_networks = NULL;
1669         provider->routes = g_hash_table_new_full(g_direct_hash, g_direct_equal,
1670                                         NULL, free_route);
1671         provider->user_routes = g_hash_table_new_full(g_str_hash, g_str_equal,
1672                                         g_free, free_route);
1673         provider->setting_strings = g_hash_table_new_full(g_str_hash,
1674                                         g_str_equal, g_free, free_setting);
1675 }
1676
1677 static struct vpn_provider *vpn_provider_new(void)
1678 {
1679         struct vpn_provider *provider;
1680
1681         provider = g_try_new0(struct vpn_provider, 1);
1682         if (!provider)
1683                 return NULL;
1684
1685         provider->refcount = 1;
1686
1687         DBG("provider %p", provider);
1688         provider_initialize(provider);
1689
1690         return provider;
1691 }
1692
1693 static struct vpn_provider *vpn_provider_get(const char *identifier)
1694 {
1695         struct vpn_provider *provider;
1696
1697         provider = g_hash_table_lookup(provider_hash, identifier);
1698         if (provider)
1699                 return provider;
1700
1701         provider = vpn_provider_new();
1702         if (!provider)
1703                 return NULL;
1704
1705         DBG("provider %p", provider);
1706
1707         provider->identifier = g_strdup(identifier);
1708
1709         g_hash_table_insert(provider_hash, provider->identifier, provider);
1710
1711         configuration_count_add();
1712
1713         return provider;
1714 }
1715
1716 static void provider_dbus_ident(char *ident)
1717 {
1718         int i, len = strlen(ident);
1719
1720         for (i = 0; i < len; i++) {
1721                 if (ident[i] >= '0' && ident[i] <= '9')
1722                         continue;
1723                 if (ident[i] >= 'a' && ident[i] <= 'z')
1724                         continue;
1725                 if (ident[i] >= 'A' && ident[i] <= 'Z')
1726                         continue;
1727                 ident[i] = '_';
1728         }
1729 }
1730
1731 static struct vpn_provider *provider_create_from_keyfile(GKeyFile *keyfile,
1732                 const char *ident)
1733 {
1734         struct vpn_provider *provider;
1735
1736         if (!keyfile || !ident)
1737                 return NULL;
1738
1739         provider = __vpn_provider_lookup(ident);
1740         if (!provider) {
1741                 provider = vpn_provider_get(ident);
1742                 if (!provider) {
1743                         DBG("can not create provider");
1744                         return NULL;
1745                 }
1746
1747                 provider_load_from_keyfile(provider, keyfile);
1748
1749                 if (!provider->name || !provider->host ||
1750                                 !provider->domain) {
1751                         DBG("cannot get name, host or domain");
1752                         vpn_provider_unref(provider);
1753                         return NULL;
1754                 }
1755
1756                 if (provider_register(provider) == 0)
1757                         connection_register(provider);
1758         }
1759         return provider;
1760 }
1761
1762 static void provider_create_all_from_type(const char *provider_type)
1763 {
1764         unsigned int i;
1765         char **providers;
1766         char *id, *type;
1767         GKeyFile *keyfile;
1768
1769         DBG("provider type %s", provider_type);
1770
1771         providers = __connman_storage_get_providers();
1772
1773         if (!providers)
1774                 return;
1775
1776         for (i = 0; providers[i]; i += 1) {
1777
1778                 if (strncmp(providers[i], "provider_", 9) != 0)
1779                         continue;
1780
1781                 id = providers[i] + 9;
1782                 keyfile = __connman_storage_load_provider(id);
1783
1784                 if (!keyfile)
1785                         continue;
1786
1787                 type = __vpn_config_get_string(keyfile, id, "Type", NULL);
1788
1789                 DBG("keyfile %p id %s type %s", keyfile, id, type);
1790
1791                 if (strcmp(provider_type, type) != 0) {
1792                         g_free(type);
1793                         g_key_file_free(keyfile);
1794                         continue;
1795                 }
1796
1797                 if (!provider_create_from_keyfile(keyfile, id))
1798                         DBG("could not create provider");
1799
1800                 g_free(type);
1801                 g_key_file_free(keyfile);
1802         }
1803         g_strfreev(providers);
1804 }
1805
1806 #if !defined TIZEN_EXT
1807 char *__vpn_provider_create_identifier(const char *host, const char *domain)
1808 {
1809         char *ident;
1810
1811         ident = g_strdup_printf("%s_%s", host, domain);
1812         if (!ident)
1813                 return NULL;
1814
1815         provider_dbus_ident(ident);
1816
1817         return ident;
1818 }
1819 #else
1820 char *__vpn_provider_create_identifier(const char *host, const char *domain, const char *name)
1821 {
1822         char *ident;
1823
1824         ident = g_strdup_printf("%s_%s_%s", host, domain, name);
1825         if (!ident)
1826                 return NULL;
1827
1828         provider_dbus_ident(ident);
1829
1830         return ident;
1831 }
1832 #endif
1833
1834 int __vpn_provider_create(DBusMessage *msg)
1835 {
1836         struct vpn_provider *provider;
1837         DBusMessageIter iter, array;
1838         const char *type = NULL, *name = NULL;
1839         const char *host = NULL, *domain = NULL;
1840         GSList *networks = NULL;
1841         char *ident;
1842         int err;
1843
1844         dbus_message_iter_init(msg, &iter);
1845         dbus_message_iter_recurse(&iter, &array);
1846
1847         while (dbus_message_iter_get_arg_type(&array) == DBUS_TYPE_DICT_ENTRY) {
1848                 DBusMessageIter entry, value;
1849                 const char *key;
1850
1851                 dbus_message_iter_recurse(&array, &entry);
1852                 dbus_message_iter_get_basic(&entry, &key);
1853
1854                 dbus_message_iter_next(&entry);
1855                 dbus_message_iter_recurse(&entry, &value);
1856
1857                 switch (dbus_message_iter_get_arg_type(&value)) {
1858                 case DBUS_TYPE_STRING:
1859                         if (g_str_equal(key, "Type"))
1860                                 dbus_message_iter_get_basic(&value, &type);
1861                         else if (g_str_equal(key, "Name"))
1862                                 dbus_message_iter_get_basic(&value, &name);
1863                         else if (g_str_equal(key, "Host"))
1864                                 dbus_message_iter_get_basic(&value, &host);
1865                         else if (g_str_equal(key, "VPN.Domain") ||
1866                                         g_str_equal(key, "Domain"))
1867                                 dbus_message_iter_get_basic(&value, &domain);
1868                         break;
1869                 case DBUS_TYPE_ARRAY:
1870                         if (g_str_equal(key, "UserRoutes"))
1871                                 networks = get_user_networks(&value);
1872                         break;
1873                 }
1874
1875                 dbus_message_iter_next(&array);
1876         }
1877
1878         if (!host || !domain)
1879                 return -EINVAL;
1880
1881         DBG("Type %s name %s networks %p", type, name, networks);
1882
1883         if (!type || !name)
1884                 return -EOPNOTSUPP;
1885
1886 #if !defined TIZEN_EXT
1887         ident = __vpn_provider_create_identifier(host, domain);
1888 #else
1889         ident = __vpn_provider_create_identifier(host, domain, name);
1890 #endif
1891         DBG("ident %s", ident);
1892
1893         provider = __vpn_provider_lookup(ident);
1894         if (!provider) {
1895                 provider = vpn_provider_get(ident);
1896                 if (!provider) {
1897                         DBG("can not create provider");
1898                         g_free(ident);
1899                         return -EOPNOTSUPP;
1900                 }
1901
1902                 provider->host = g_strdup(host);
1903                 provider->domain = g_strdup(domain);
1904                 provider->name = g_strdup(name);
1905                 provider->type = g_strdup(type);
1906
1907                 if (provider_register(provider) == 0)
1908                         vpn_provider_load(provider);
1909
1910                 provider_resolv_host_addr(provider);
1911         }
1912
1913         if (networks) {
1914                 g_slist_free_full(provider->user_networks, free_route);
1915                 provider->user_networks = networks;
1916                 set_user_networks(provider, provider->user_networks);
1917         }
1918
1919         dbus_message_iter_init(msg, &iter);
1920         dbus_message_iter_recurse(&iter, &array);
1921
1922         while (dbus_message_iter_get_arg_type(&array) == DBUS_TYPE_DICT_ENTRY) {
1923                 DBusMessageIter entry, value;
1924                 const char *key, *str;
1925
1926                 dbus_message_iter_recurse(&array, &entry);
1927                 dbus_message_iter_get_basic(&entry, &key);
1928
1929                 dbus_message_iter_next(&entry);
1930                 dbus_message_iter_recurse(&entry, &value);
1931
1932                 switch (dbus_message_iter_get_arg_type(&value)) {
1933                 case DBUS_TYPE_STRING:
1934                         dbus_message_iter_get_basic(&value, &str);
1935                         vpn_provider_set_string(provider, key, str);
1936                         break;
1937                 }
1938
1939                 dbus_message_iter_next(&array);
1940         }
1941
1942         g_free(ident);
1943
1944         vpn_provider_save(provider);
1945
1946         err = provider_register(provider);
1947         if (err != 0 && err != -EALREADY)
1948                 return err;
1949
1950         connection_register(provider);
1951
1952         DBG("provider %p index %d path %s", provider, provider->index,
1953                                                         provider->path);
1954
1955         g_dbus_send_reply(connection, msg,
1956                                 DBUS_TYPE_OBJECT_PATH, &provider->path,
1957                                 DBUS_TYPE_INVALID);
1958
1959         connection_added_signal(provider);
1960
1961         return 0;
1962 }
1963
1964 static const char *get_string(GHashTable *settings, const char *key)
1965 {
1966         DBG("settings %p key %s", settings, key);
1967
1968         return g_hash_table_lookup(settings, key);
1969 }
1970
1971 static GSList *parse_user_networks(const char *network_str)
1972 {
1973         GSList *networks = NULL;
1974         char **elems;
1975         int i = 0;
1976
1977         if (!network_str)
1978                 return NULL;
1979
1980         elems = g_strsplit(network_str, ",", 0);
1981         if (!elems)
1982                 return NULL;
1983
1984         while (elems[i]) {
1985                 struct vpn_route *vpn_route;
1986                 char *network, *netmask, *gateway;
1987                 int family;
1988                 char **route;
1989
1990                 route = g_strsplit(elems[i], "/", 0);
1991                 if (!route)
1992                         goto next;
1993
1994                 network = route[0];
1995                 if (!network || network[0] == '\0')
1996                         goto next;
1997
1998                 family = connman_inet_check_ipaddress(network);
1999                 if (family < 0) {
2000                         DBG("Cannot get address family of %s (%d/%s)", network,
2001                                 family, gai_strerror(family));
2002
2003                         goto next;
2004                 }
2005
2006                 switch (family) {
2007                 case AF_INET:
2008                         break;
2009                 case AF_INET6:
2010                         break;
2011                 default:
2012                         DBG("Unsupported address family %d", family);
2013                         goto next;
2014                 }
2015
2016                 netmask = route[1];
2017                 if (!netmask || netmask[0] == '\0')
2018                         goto next;
2019
2020                 gateway = route[2];
2021
2022                 vpn_route = g_try_new0(struct vpn_route, 1);
2023                 if (!vpn_route) {
2024                         g_strfreev(route);
2025                         break;
2026                 }
2027
2028                 vpn_route->family = family;
2029                 vpn_route->network = g_strdup(network);
2030                 vpn_route->netmask = g_strdup(netmask);
2031                 vpn_route->gateway = g_strdup(gateway);
2032
2033                 DBG("route %s/%s%s%s", network, netmask,
2034                         gateway ? " via " : "", gateway ? gateway : "");
2035
2036                 networks = g_slist_prepend(networks, vpn_route);
2037
2038         next:
2039                 g_strfreev(route);
2040                 i++;
2041         }
2042
2043         g_strfreev(elems);
2044
2045         return g_slist_reverse(networks);
2046 }
2047
2048 int __vpn_provider_create_from_config(GHashTable *settings,
2049                                 const char *config_ident,
2050                                 const char *config_entry)
2051 {
2052         struct vpn_provider *provider;
2053         const char *type, *name, *host, *domain, *networks_str;
2054         GSList *networks;
2055         char *ident = NULL;
2056         GHashTableIter hash;
2057         gpointer value, key;
2058         int err;
2059
2060         type = get_string(settings, "Type");
2061         name = get_string(settings, "Name");
2062         host = get_string(settings, "Host");
2063         domain = get_string(settings, "Domain");
2064         networks_str = get_string(settings, "Networks");
2065         networks = parse_user_networks(networks_str);
2066
2067         if (!host || !domain) {
2068                 err = -EINVAL;
2069                 goto fail;
2070         }
2071
2072         DBG("type %s name %s networks %s", type, name, networks_str);
2073
2074         if (!type || !name) {
2075                 err = -EOPNOTSUPP;
2076                 goto fail;
2077         }
2078
2079 #if !defined TIZEN_EXT
2080         ident = __vpn_provider_create_identifier(host, domain);
2081 #else
2082         ident = __vpn_provider_create_identifier(host, domain, name);
2083 #endif
2084         DBG("ident %s", ident);
2085
2086         provider = __vpn_provider_lookup(ident);
2087         if (!provider) {
2088                 provider = vpn_provider_get(ident);
2089                 if (!provider) {
2090                         DBG("can not create provider");
2091                         err = -EOPNOTSUPP;
2092                         goto fail;
2093                 }
2094
2095                 provider->host = g_strdup(host);
2096                 provider->domain = g_strdup(domain);
2097                 provider->name = g_strdup(name);
2098                 provider->type = g_ascii_strdown(type, -1);
2099
2100                 provider->config_file = g_strdup(config_ident);
2101                 provider->config_entry = g_strdup(config_entry);
2102
2103                 provider_register(provider);
2104
2105                 provider_resolv_host_addr(provider);
2106         }
2107
2108         if (networks) {
2109                 g_slist_free_full(provider->user_networks, free_route);
2110                 provider->user_networks = networks;
2111                 set_user_networks(provider, provider->user_networks);
2112         }
2113
2114         g_hash_table_iter_init(&hash, settings);
2115
2116         while (g_hash_table_iter_next(&hash, &key, &value))
2117                 __vpn_provider_set_string_immutable(provider, key, value);
2118
2119         provider->immutable = true;
2120
2121         vpn_provider_save(provider);
2122
2123         err = provider_register(provider);
2124         if (err != 0 && err != -EALREADY)
2125                 goto fail;
2126
2127         connection_register(provider);
2128
2129         DBG("provider %p index %d path %s", provider, provider->index,
2130                                                         provider->path);
2131
2132         connection_added_signal(provider);
2133
2134         g_free(ident);
2135
2136         return 0;
2137
2138 fail:
2139         g_free(ident);
2140         g_slist_free_full(networks, free_route);
2141
2142         return err;
2143 }
2144
2145 static void append_connection_structs(DBusMessageIter *iter, void *user_data)
2146 {
2147         DBusMessageIter entry;
2148         GHashTableIter hash;
2149         gpointer value, key;
2150
2151         g_hash_table_iter_init(&hash, provider_hash);
2152
2153         while (g_hash_table_iter_next(&hash, &key, &value)) {
2154                 struct vpn_provider *provider = value;
2155
2156                 DBG("path %s", provider->path);
2157
2158                 if (!provider->identifier)
2159                         continue;
2160
2161                 dbus_message_iter_open_container(iter, DBUS_TYPE_STRUCT,
2162                                 NULL, &entry);
2163                 dbus_message_iter_append_basic(&entry, DBUS_TYPE_OBJECT_PATH,
2164                                 &provider->path);
2165                 append_properties(&entry, provider);
2166                 dbus_message_iter_close_container(iter, &entry);
2167         }
2168 }
2169
2170 DBusMessage *__vpn_provider_get_connections(DBusMessage *msg)
2171 {
2172         DBusMessage *reply;
2173
2174         DBG("");
2175
2176         reply = dbus_message_new_method_return(msg);
2177         if (!reply)
2178                 return NULL;
2179
2180         __connman_dbus_append_objpath_dict_array(reply,
2181                         append_connection_structs, NULL);
2182
2183         return reply;
2184 }
2185
2186 const char *__vpn_provider_get_ident(struct vpn_provider *provider)
2187 {
2188         if (!provider)
2189                 return NULL;
2190
2191         return provider->identifier;
2192 }
2193
2194 static int set_string(struct vpn_provider *provider,
2195                         const char *key, const char *value,
2196                         bool hide_value, bool immutable)
2197 {
2198         DBG("provider %p key %s immutable %s value %s", provider, key,
2199                 immutable ? "yes" : "no",
2200                 hide_value ? "<not printed>" : value);
2201
2202         if (g_str_equal(key, "Type")) {
2203                 g_free(provider->type);
2204                 provider->type = g_ascii_strdown(value, -1);
2205                 send_value(provider->path, "Type", provider->type);
2206         } else if (g_str_equal(key, "Name")) {
2207                 g_free(provider->name);
2208                 provider->name = g_strdup(value);
2209                 send_value(provider->path, "Name", provider->name);
2210         } else if (g_str_equal(key, "Host")) {
2211                 g_free(provider->host);
2212                 provider->host = g_strdup(value);
2213                 send_value(provider->path, "Host", provider->host);
2214         } else if (g_str_equal(key, "VPN.Domain") ||
2215                         g_str_equal(key, "Domain")) {
2216                 g_free(provider->domain);
2217                 provider->domain = g_strdup(value);
2218                 send_value(provider->path, "Domain", provider->domain);
2219         } else {
2220                 struct vpn_setting *setting;
2221
2222                 setting = g_hash_table_lookup(provider->setting_strings, key);
2223                 if (setting && !immutable &&
2224                                                 setting->immutable) {
2225                         DBG("Trying to set immutable variable %s", key);
2226                         return -EPERM;
2227                 }
2228
2229                 setting = g_try_new0(struct vpn_setting, 1);
2230                 if (!setting)
2231                         return -ENOMEM;
2232
2233                 setting->value = g_strdup(value);
2234                 setting->hide_value = hide_value;
2235
2236                 if (immutable)
2237                         setting->immutable = true;
2238
2239                 if (!hide_value)
2240                         send_value(provider->path, key, setting->value);
2241
2242                 g_hash_table_replace(provider->setting_strings,
2243                                 g_strdup(key), setting);
2244         }
2245
2246         return 0;
2247 }
2248
2249 int vpn_provider_set_string(struct vpn_provider *provider,
2250                                         const char *key, const char *value)
2251 {
2252         return set_string(provider, key, value, false, false);
2253 }
2254
2255 int vpn_provider_set_string_hide_value(struct vpn_provider *provider,
2256                                         const char *key, const char *value)
2257 {
2258         return set_string(provider, key, value, true, false);
2259 }
2260
2261 int __vpn_provider_set_string_immutable(struct vpn_provider *provider,
2262                                         const char *key, const char *value)
2263 {
2264         return set_string(provider, key, value, false, true);
2265 }
2266
2267 const char *vpn_provider_get_string(struct vpn_provider *provider,
2268                                                         const char *key)
2269 {
2270         struct vpn_setting *setting;
2271
2272         DBG("provider %p key %s", provider, key);
2273
2274         if (g_str_equal(key, "Type"))
2275                 return provider->type;
2276         else if (g_str_equal(key, "Name"))
2277                 return provider->name;
2278         else if (g_str_equal(key, "Host"))
2279                 return provider->host;
2280         else if (g_str_equal(key, "HostIP")) {
2281                 if (!provider->host_ip ||
2282                                 !provider->host_ip[0])
2283                         return provider->host;
2284                 else
2285                         return provider->host_ip[0];
2286         } else if (g_str_equal(key, "VPN.Domain") ||
2287                         g_str_equal(key, "Domain"))
2288                 return provider->domain;
2289
2290         setting = g_hash_table_lookup(provider->setting_strings, key);
2291         if (!setting)
2292                 return NULL;
2293
2294         return setting->value;
2295 }
2296
2297 bool __vpn_provider_check_routes(struct vpn_provider *provider)
2298 {
2299         if (!provider)
2300                 return false;
2301
2302         if (provider->user_routes &&
2303                         g_hash_table_size(provider->user_routes) > 0)
2304                 return true;
2305
2306         if (provider->routes &&
2307                         g_hash_table_size(provider->routes) > 0)
2308                 return true;
2309
2310         return false;
2311 }
2312
2313 void *vpn_provider_get_data(struct vpn_provider *provider)
2314 {
2315         return provider->driver_data;
2316 }
2317
2318 void vpn_provider_set_data(struct vpn_provider *provider, void *data)
2319 {
2320         provider->driver_data = data;
2321 }
2322
2323 void vpn_provider_set_index(struct vpn_provider *provider, int index)
2324 {
2325         DBG("index %d provider %p", index, provider);
2326
2327         if (!provider->ipconfig_ipv4) {
2328                 provider->ipconfig_ipv4 = __vpn_ipconfig_create(index,
2329                                                                 AF_INET);
2330                 if (!provider->ipconfig_ipv4) {
2331                         DBG("Couldnt create ipconfig for IPv4");
2332                         goto done;
2333                 }
2334         }
2335
2336         __vpn_ipconfig_set_index(provider->ipconfig_ipv4, index);
2337
2338         if (!provider->ipconfig_ipv6) {
2339                 provider->ipconfig_ipv6 = __vpn_ipconfig_create(index,
2340                                                                 AF_INET6);
2341                 if (!provider->ipconfig_ipv6) {
2342                         DBG("Couldnt create ipconfig for IPv6");
2343                         goto done;
2344                 }
2345         }
2346
2347         __vpn_ipconfig_set_index(provider->ipconfig_ipv6, index);
2348
2349 done:
2350         provider->index = index;
2351 }
2352
2353 int vpn_provider_get_index(struct vpn_provider *provider)
2354 {
2355         return provider->index;
2356 }
2357
2358 int vpn_provider_set_ipaddress(struct vpn_provider *provider,
2359                                         struct connman_ipaddress *ipaddress)
2360 {
2361         struct vpn_ipconfig *ipconfig = NULL;
2362
2363         switch (ipaddress->family) {
2364         case AF_INET:
2365                 ipconfig = provider->ipconfig_ipv4;
2366                 break;
2367         case AF_INET6:
2368                 ipconfig = provider->ipconfig_ipv6;
2369                 break;
2370         default:
2371                 break;
2372         }
2373
2374         DBG("provider %p state %d ipconfig %p family %d", provider,
2375                 provider->state, ipconfig, ipaddress->family);
2376
2377         if (!ipconfig)
2378                 return -EINVAL;
2379
2380         provider->family = ipaddress->family;
2381
2382         if (provider->state == VPN_PROVIDER_STATE_CONNECT ||
2383                         provider->state == VPN_PROVIDER_STATE_READY) {
2384                 struct connman_ipaddress *addr =
2385                                         __vpn_ipconfig_get_address(ipconfig);
2386
2387                 /*
2388                  * Remember the old address so that we can remove it in notify
2389                  * function in plugins/vpn.c if we ever restart
2390                  */
2391                 if (ipaddress->family == AF_INET6) {
2392                         connman_ipaddress_free(provider->prev_ipv6_addr);
2393                         provider->prev_ipv6_addr =
2394                                                 connman_ipaddress_copy(addr);
2395                 } else {
2396                         connman_ipaddress_free(provider->prev_ipv4_addr);
2397                         provider->prev_ipv4_addr =
2398                                                 connman_ipaddress_copy(addr);
2399                 }
2400         }
2401
2402         if (ipaddress->local) {
2403                 __vpn_ipconfig_set_local(ipconfig, ipaddress->local);
2404                 __vpn_ipconfig_set_peer(ipconfig, ipaddress->peer);
2405                 __vpn_ipconfig_set_broadcast(ipconfig, ipaddress->broadcast);
2406                 __vpn_ipconfig_set_gateway(ipconfig, ipaddress->gateway);
2407                 __vpn_ipconfig_set_prefixlen(ipconfig, ipaddress->prefixlen);
2408         }
2409
2410         return 0;
2411 }
2412
2413 int vpn_provider_set_pac(struct vpn_provider *provider,
2414                                 const char *pac)
2415 {
2416         DBG("provider %p pac %s", provider, pac);
2417
2418         return 0;
2419 }
2420
2421
2422 int vpn_provider_set_domain(struct vpn_provider *provider,
2423                                         const char *domain)
2424 {
2425         DBG("provider %p domain %s", provider, domain);
2426
2427         g_free(provider->domain);
2428         provider->domain = g_strdup(domain);
2429
2430         return 0;
2431 }
2432
2433 int vpn_provider_set_nameservers(struct vpn_provider *provider,
2434                                         const char *nameservers)
2435 {
2436         DBG("provider %p nameservers %s", provider, nameservers);
2437
2438         g_strfreev(provider->nameservers);
2439         provider->nameservers = NULL;
2440
2441         if (!nameservers)
2442                 return 0;
2443
2444         provider->nameservers = g_strsplit(nameservers, " ", 0);
2445
2446         return 0;
2447 }
2448
2449 enum provider_route_type {
2450         PROVIDER_ROUTE_TYPE_NONE = 0,
2451         PROVIDER_ROUTE_TYPE_MASK = 1,
2452         PROVIDER_ROUTE_TYPE_ADDR = 2,
2453         PROVIDER_ROUTE_TYPE_GW   = 3,
2454 };
2455
2456 static int route_env_parse(struct vpn_provider *provider, const char *key,
2457                                 int *family, unsigned long *idx,
2458                                 enum provider_route_type *type)
2459 {
2460         char *end;
2461         const char *start;
2462
2463         DBG("name %s", provider->name);
2464
2465         if (!strcmp(provider->type, "openvpn")) {
2466                 if (g_str_has_prefix(key, "route_network_")) {
2467                         start = key + strlen("route_network_");
2468                         *type = PROVIDER_ROUTE_TYPE_ADDR;
2469                 } else if (g_str_has_prefix(key, "route_netmask_")) {
2470                         start = key + strlen("route_netmask_");
2471                         *type = PROVIDER_ROUTE_TYPE_MASK;
2472                 } else if (g_str_has_prefix(key, "route_gateway_")) {
2473                         start = key + strlen("route_gateway_");
2474                         *type = PROVIDER_ROUTE_TYPE_GW;
2475                 } else
2476                         return -EINVAL;
2477
2478                 *family = AF_INET;
2479                 *idx = g_ascii_strtoull(start, &end, 10);
2480
2481         } else if (!strcmp(provider->type, "openconnect")) {
2482                 if (g_str_has_prefix(key, "CISCO_SPLIT_INC_")) {
2483                         *family = AF_INET;
2484                         start = key + strlen("CISCO_SPLIT_INC_");
2485                 } else if (g_str_has_prefix(key,
2486                                         "CISCO_IPV6_SPLIT_INC_")) {
2487                         *family = AF_INET6;
2488                         start = key + strlen("CISCO_IPV6_SPLIT_INC_");
2489                 } else
2490                         return -EINVAL;
2491
2492                 *idx = g_ascii_strtoull(start, &end, 10);
2493
2494                 if (strncmp(end, "_ADDR", 5) == 0)
2495                         *type = PROVIDER_ROUTE_TYPE_ADDR;
2496                 else if (strncmp(end, "_MASK", 5) == 0)
2497                         *type = PROVIDER_ROUTE_TYPE_MASK;
2498                 else if (strncmp(end, "_MASKLEN", 8) == 0 &&
2499                                 *family == AF_INET6) {
2500                         *type = PROVIDER_ROUTE_TYPE_MASK;
2501                 } else
2502                         return -EINVAL;
2503         }
2504
2505         return 0;
2506 }
2507
2508 int vpn_provider_append_route(struct vpn_provider *provider,
2509                                         const char *key, const char *value)
2510 {
2511         struct vpn_route *route;
2512         int ret, family = 0;
2513         unsigned long idx = 0;
2514         enum provider_route_type type = PROVIDER_ROUTE_TYPE_NONE;
2515
2516         DBG("key %s value %s", key, value);
2517
2518         ret = route_env_parse(provider, key, &family, &idx, &type);
2519         if (ret < 0)
2520                 return ret;
2521
2522         DBG("idx %lu family %d type %d", idx, family, type);
2523
2524         route = g_hash_table_lookup(provider->routes, GINT_TO_POINTER(idx));
2525         if (!route) {
2526                 route = g_try_new0(struct vpn_route, 1);
2527                 if (!route) {
2528                         connman_error("out of memory");
2529                         return -ENOMEM;
2530                 }
2531
2532                 route->family = family;
2533
2534                 g_hash_table_replace(provider->routes, GINT_TO_POINTER(idx),
2535                                                 route);
2536         }
2537
2538         switch (type) {
2539         case PROVIDER_ROUTE_TYPE_NONE:
2540                 break;
2541         case PROVIDER_ROUTE_TYPE_MASK:
2542                 route->netmask = g_strdup(value);
2543                 break;
2544         case PROVIDER_ROUTE_TYPE_ADDR:
2545                 route->network = g_strdup(value);
2546                 break;
2547         case PROVIDER_ROUTE_TYPE_GW:
2548                 route->gateway = g_strdup(value);
2549                 break;
2550         }
2551
2552         if (!handle_routes) {
2553                 if (route->netmask && route->gateway &&
2554                                                         route->network)
2555                         provider_schedule_changed(provider);
2556         }
2557
2558         return 0;
2559 }
2560
2561 const char *vpn_provider_get_driver_name(struct vpn_provider *provider)
2562 {
2563         if (!provider->driver)
2564                 return NULL;
2565
2566         return provider->driver->name;
2567 }
2568
2569 const char *vpn_provider_get_save_group(struct vpn_provider *provider)
2570 {
2571         return provider->identifier;
2572 }
2573
2574 static gint compare_priority(gconstpointer a, gconstpointer b)
2575 {
2576         return 0;
2577 }
2578
2579 static void clean_provider(gpointer key, gpointer value, gpointer user_data)
2580 {
2581         struct vpn_provider *provider = value;
2582
2583         if (provider->driver && provider->driver->remove)
2584                 provider->driver->remove(provider);
2585
2586         connection_unregister(provider);
2587 }
2588
2589 int vpn_provider_driver_register(struct vpn_provider_driver *driver)
2590 {
2591         DBG("driver %p name %s", driver, driver->name);
2592
2593         driver_list = g_slist_insert_sorted(driver_list, driver,
2594                                                         compare_priority);
2595         provider_create_all_from_type(driver->name);
2596         return 0;
2597 }
2598
2599 void vpn_provider_driver_unregister(struct vpn_provider_driver *driver)
2600 {
2601         GHashTableIter iter;
2602         gpointer value, key;
2603
2604         DBG("driver %p name %s", driver, driver->name);
2605
2606         driver_list = g_slist_remove(driver_list, driver);
2607
2608         g_hash_table_iter_init(&iter, provider_hash);
2609         while (g_hash_table_iter_next(&iter, &key, &value)) {
2610                 struct vpn_provider *provider = value;
2611
2612                 if (provider && provider->driver &&
2613                                 provider->driver->type == driver->type &&
2614                                 g_strcmp0(provider->driver->name,
2615                                                         driver->name) == 0) {
2616                         provider->driver = NULL;
2617                 }
2618         }
2619 }
2620
2621 const char *vpn_provider_get_name(struct vpn_provider *provider)
2622 {
2623         return provider->name;
2624 }
2625
2626 const char *vpn_provider_get_host(struct vpn_provider *provider)
2627 {
2628         return provider->host;
2629 }
2630
2631 const char *vpn_provider_get_path(struct vpn_provider *provider)
2632 {
2633         return provider->path;
2634 }
2635
2636 void vpn_provider_change_address(struct vpn_provider *provider)
2637 {
2638         switch (provider->family) {
2639         case AF_INET:
2640                 connman_inet_set_address(provider->index,
2641                         __vpn_ipconfig_get_address(provider->ipconfig_ipv4));
2642                 break;
2643         case AF_INET6:
2644                 connman_inet_set_ipv6_address(provider->index,
2645                         __vpn_ipconfig_get_address(provider->ipconfig_ipv6));
2646                 break;
2647         default:
2648                 break;
2649         }
2650 }
2651
2652 void vpn_provider_clear_address(struct vpn_provider *provider, int family)
2653 {
2654         const char *address;
2655         unsigned char len;
2656
2657         DBG("provider %p family %d ipv4 %p ipv6 %p", provider, family,
2658                 provider->prev_ipv4_addr, provider->prev_ipv6_addr);
2659
2660         switch (family) {
2661         case AF_INET:
2662                 if (provider->prev_ipv4_addr) {
2663                         connman_ipaddress_get_ip(provider->prev_ipv4_addr,
2664                                                 &address, &len);
2665
2666                         DBG("ipv4 %s/%d", address, len);
2667
2668                         connman_inet_clear_address(provider->index,
2669                                         provider->prev_ipv4_addr);
2670                         connman_ipaddress_free(provider->prev_ipv4_addr);
2671                         provider->prev_ipv4_addr = NULL;
2672                 }
2673                 break;
2674         case AF_INET6:
2675                 if (provider->prev_ipv6_addr) {
2676                         connman_ipaddress_get_ip(provider->prev_ipv6_addr,
2677                                                 &address, &len);
2678
2679                         DBG("ipv6 %s/%d", address, len);
2680
2681                         connman_inet_clear_ipv6_address(provider->index,
2682                                                         address, len);
2683
2684                         connman_ipaddress_free(provider->prev_ipv6_addr);
2685                         provider->prev_ipv6_addr = NULL;
2686                 }
2687                 break;
2688         default:
2689                 break;
2690         }
2691 }
2692
2693 static int agent_probe(struct connman_agent *agent)
2694 {
2695         DBG("agent %p", agent);
2696         return 0;
2697 }
2698
2699 static void agent_remove(struct connman_agent *agent)
2700 {
2701         DBG("agent %p", agent);
2702 }
2703
2704 static struct connman_agent_driver agent_driver = {
2705         .name           = "vpn",
2706         .interface      = VPN_AGENT_INTERFACE,
2707         .probe          = agent_probe,
2708         .remove         = agent_remove,
2709 };
2710
2711 static void remove_unprovisioned_providers(void)
2712 {
2713         gchar **providers;
2714         GKeyFile *keyfile, *configkeyfile;
2715         char *file, *section;
2716         int i = 0;
2717
2718         providers = __connman_storage_get_providers();
2719         if (!providers)
2720                 return;
2721
2722         for (; providers[i]; i++) {
2723                 char *group = providers[i] + sizeof("provider_") - 1;
2724                 file = section = NULL;
2725                 keyfile = configkeyfile = NULL;
2726
2727                 keyfile = __connman_storage_load_provider(group);
2728                 if (!keyfile)
2729                         continue;
2730
2731                 file = __vpn_config_get_string(keyfile, group,
2732                                         "Config.file", NULL);
2733                 if (!file)
2734                         goto next;
2735
2736                 section = __vpn_config_get_string(keyfile, group,
2737                                         "Config.ident", NULL);
2738                 if (!section)
2739                         goto next;
2740
2741                 configkeyfile = __connman_storage_load_provider_config(file);
2742                 if (!configkeyfile) {
2743                         /*
2744                          * Config file is missing, remove the provisioned
2745                          * service.
2746                          */
2747                         __connman_storage_remove_provider(group);
2748                         goto next;
2749                 }
2750
2751                 if (!g_key_file_has_group(configkeyfile, section))
2752                         /*
2753                          * Config section is missing, remove the provisioned
2754                          * service.
2755                          */
2756                         __connman_storage_remove_provider(group);
2757
2758         next:
2759                 if (keyfile)
2760                         g_key_file_free(keyfile);
2761
2762                 if (configkeyfile)
2763                         g_key_file_free(configkeyfile);
2764
2765                 g_free(section);
2766                 g_free(file);
2767         }
2768
2769         g_strfreev(providers);
2770 }
2771
2772 int __vpn_provider_init(bool do_routes)
2773 {
2774         int err;
2775
2776         DBG("");
2777
2778         handle_routes = do_routes;
2779
2780         err = connman_agent_driver_register(&agent_driver);
2781         if (err < 0) {
2782                 connman_error("Cannot register agent driver for %s",
2783                                                 agent_driver.name);
2784                 return err;
2785         }
2786
2787         connection = connman_dbus_get_connection();
2788
2789         remove_unprovisioned_providers();
2790
2791         provider_hash = g_hash_table_new_full(g_str_hash, g_str_equal,
2792                                                 NULL, unregister_provider);
2793         return 0;
2794 }
2795
2796 void __vpn_provider_cleanup(void)
2797 {
2798         DBG("");
2799
2800         connman_agent_driver_unregister(&agent_driver);
2801
2802         g_hash_table_foreach(provider_hash, clean_provider, NULL);
2803
2804         g_hash_table_destroy(provider_hash);
2805         provider_hash = NULL;
2806
2807         dbus_connection_unref(connection);
2808 }