vpn-provider: Parse user networks correctly
[platform/upstream/connman.git] / vpn / vpn-provider.c
1 /*
2  *
3  *  ConnMan VPN daemon
4  *
5  *  Copyright (C) 2012  Intel Corporation. All rights reserved.
6  *
7  *  This program is free software; you can redistribute it and/or modify
8  *  it under the terms of the GNU General Public License version 2 as
9  *  published by the Free Software Foundation.
10  *
11  *  This program is distributed in the hope that it will be useful,
12  *  but WITHOUT ANY WARRANTY; without even the implied warranty of
13  *  MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
14  *  GNU General Public License for more details.
15  *
16  *  You should have received a copy of the GNU General Public License
17  *  along with this program; if not, write to the Free Software
18  *  Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA  02110-1301  USA
19  *
20  */
21
22 #ifdef HAVE_CONFIG_H
23 #include <config.h>
24 #endif
25
26 #include <errno.h>
27 #include <stdio.h>
28 #include <string.h>
29 #include <stdlib.h>
30 #include <gdbus.h>
31 #include <connman/log.h>
32 #include <gweb/gresolv.h>
33 #include <netdb.h>
34
35 #include "../src/connman.h"
36 #include "connman/agent.h"
37 #include "connman/vpn-dbus.h"
38 #include "vpn-provider.h"
39 #include "vpn.h"
40
41 static DBusConnection *connection;
42 static GHashTable *provider_hash;
43 static GSList *driver_list;
44 static int configuration_count;
45 static gboolean handle_routes;
46
47 struct vpn_route {
48         int family;
49         char *network;
50         char *netmask;
51         char *gateway;
52 };
53
54 struct vpn_setting {
55         gboolean hide_value;
56         char *value;
57 };
58
59 struct vpn_provider {
60         int refcount;
61         int index;
62         int fd;
63         enum vpn_provider_state state;
64         char *path;
65         char *identifier;
66         char *name;
67         char *type;
68         char *host;
69         char *domain;
70         int family;
71         GHashTable *routes;
72         struct vpn_provider_driver *driver;
73         void *driver_data;
74         GHashTable *setting_strings;
75         GHashTable *user_routes;
76         GSList *user_networks;
77         GResolv *resolv;
78         char **host_ip;
79         struct vpn_ipconfig *ipconfig_ipv4;
80         struct vpn_ipconfig *ipconfig_ipv6;
81         char **nameservers;
82         guint notify_id;
83         char *config_file;
84         char *config_entry;
85 };
86
87 static void append_properties(DBusMessageIter *iter,
88                                 struct vpn_provider *provider);
89
90 static void free_route(gpointer data)
91 {
92         struct vpn_route *route = data;
93
94         g_free(route->network);
95         g_free(route->netmask);
96         g_free(route->gateway);
97
98         g_free(route);
99 }
100
101 static void free_setting(gpointer data)
102 {
103         struct vpn_setting *setting = data;
104
105         g_free(setting->value);
106         g_free(setting);
107 }
108
109 static void append_route(DBusMessageIter *iter, void *user_data)
110 {
111         struct vpn_route *route = user_data;
112         DBusMessageIter item;
113         int family = 0;
114
115         connman_dbus_dict_open(iter, &item);
116
117         if (route == NULL)
118                 goto empty_dict;
119
120         if (route->family == AF_INET)
121                 family = 4;
122         else if (route->family == AF_INET6)
123                 family = 6;
124
125         if (family != 0)
126                 connman_dbus_dict_append_basic(&item, "ProtocolFamily",
127                                         DBUS_TYPE_INT32, &family);
128
129         if (route->network != NULL)
130                 connman_dbus_dict_append_basic(&item, "Network",
131                                         DBUS_TYPE_STRING, &route->network);
132
133         if (route->netmask != NULL)
134                 connman_dbus_dict_append_basic(&item, "Netmask",
135                                         DBUS_TYPE_STRING, &route->netmask);
136
137         if (route->gateway != NULL)
138                 connman_dbus_dict_append_basic(&item, "Gateway",
139                                         DBUS_TYPE_STRING, &route->gateway);
140
141 empty_dict:
142         connman_dbus_dict_close(iter, &item);
143 }
144
145 static void append_routes(DBusMessageIter *iter, void *user_data)
146 {
147         GHashTable *routes = user_data;
148         GHashTableIter hash;
149         gpointer value, key;
150
151         if (routes == NULL) {
152                 append_route(iter, NULL);
153                 return;
154         }
155
156         g_hash_table_iter_init(&hash, routes);
157
158         while (g_hash_table_iter_next(&hash, &key, &value) == TRUE) {
159                 DBusMessageIter dict;
160
161                 dbus_message_iter_open_container(iter, DBUS_TYPE_STRUCT, NULL,
162                                                 &dict);
163                 append_route(&dict, value);
164                 dbus_message_iter_close_container(iter, &dict);
165         }
166 }
167
168 static void send_routes(struct vpn_provider *provider, GHashTable *routes,
169                         const char *name)
170 {
171         connman_dbus_property_changed_array(provider->path,
172                                         VPN_CONNECTION_INTERFACE,
173                                         name,
174                                         DBUS_TYPE_DICT_ENTRY,
175                                         append_routes,
176                                         routes);
177 }
178
179 static int provider_routes_changed(struct vpn_provider *provider)
180 {
181         DBG("provider %p", provider);
182
183         send_routes(provider, provider->routes, "ServerRoutes");
184
185         return 0;
186 }
187
188 static GSList *read_route_dict(GSList *routes, DBusMessageIter *dicts)
189 {
190         DBusMessageIter dict, value, entry;
191         const char *network, *netmask, *gateway;
192         struct vpn_route *route;
193         int family, type;
194         const char *key;
195
196         dbus_message_iter_recurse(dicts, &entry);
197
198         network = netmask = gateway = NULL;
199         family = PF_UNSPEC;
200
201         while (dbus_message_iter_get_arg_type(&entry) == DBUS_TYPE_DICT_ENTRY) {
202
203                 dbus_message_iter_recurse(&entry, &dict);
204                 dbus_message_iter_get_basic(&dict, &key);
205
206                 dbus_message_iter_next(&dict);
207                 dbus_message_iter_recurse(&dict, &value);
208
209                 type = dbus_message_iter_get_arg_type(&value);
210
211                 switch (type) {
212                 case DBUS_TYPE_STRING:
213                         if (g_str_equal(key, "ProtocolFamily") == TRUE)
214                                 dbus_message_iter_get_basic(&value, &family);
215                         else if (g_str_equal(key, "Network") == TRUE)
216                                 dbus_message_iter_get_basic(&value, &network);
217                         else if (g_str_equal(key, "Netmask") == TRUE)
218                                 dbus_message_iter_get_basic(&value, &netmask);
219                         else if (g_str_equal(key, "Gateway") == TRUE)
220                                 dbus_message_iter_get_basic(&value, &gateway);
221                         break;
222                 }
223
224                 dbus_message_iter_next(&entry);
225         }
226
227         DBG("family %d network %s netmask %s gateway %s", family,
228                 network, netmask, gateway);
229
230         if (network == NULL || netmask == NULL) {
231                 DBG("Ignoring route as network/netmask is missing");
232                 return routes;
233         }
234
235         route = g_try_new(struct vpn_route, 1);
236         if (route == NULL) {
237                 g_slist_free_full(routes, free_route);
238                 return NULL;
239         }
240
241         if (family == PF_UNSPEC) {
242                 family = connman_inet_check_ipaddress(network);
243                 if (family < 0) {
244                         DBG("Cannot get address family of %s (%d/%s)", network,
245                                 family, gai_strerror(family));
246
247                         g_free(route);
248                         return routes;
249                 }
250         } else {
251                 switch (family) {
252                 case '4':
253                         family = AF_INET;
254                         break;
255                 case '6':
256                         family = AF_INET6;
257                         break;
258                 default:
259                         family = PF_UNSPEC;
260                         break;
261                 }
262         }
263
264         route->family = family;
265         route->network = g_strdup(network);
266         route->netmask = g_strdup(netmask);
267         route->gateway = g_strdup(gateway);
268
269         routes = g_slist_prepend(routes, route);
270         return routes;
271 }
272
273 static GSList *get_user_networks(DBusMessageIter *array)
274 {
275         DBusMessageIter entry;
276         GSList *list = NULL;
277
278         while (dbus_message_iter_get_arg_type(array) == DBUS_TYPE_ARRAY) {
279
280                 dbus_message_iter_recurse(array, &entry);
281
282                 while (dbus_message_iter_get_arg_type(&entry) ==
283                                                         DBUS_TYPE_STRUCT) {
284                         DBusMessageIter dicts;
285
286                         dbus_message_iter_recurse(&entry, &dicts);
287
288                         while (dbus_message_iter_get_arg_type(&dicts) ==
289                                                         DBUS_TYPE_ARRAY) {
290
291                                 list = read_route_dict(list, &dicts);
292                                 dbus_message_iter_next(&dicts);
293                         }
294
295                         dbus_message_iter_next(&entry);
296                 }
297
298                 dbus_message_iter_next(array);
299         }
300
301         return list;
302 }
303
304 static void set_user_networks(struct vpn_provider *provider, GSList *networks)
305 {
306         GSList *list;
307
308         for (list = networks; list != NULL; list = g_slist_next(list)) {
309                 struct vpn_route *route = list->data;
310
311                 if (__vpn_provider_append_user_route(provider,
312                                         route->family, route->network,
313                                         route->netmask, route->gateway) != 0)
314                         break;
315         }
316 }
317
318 static void del_routes(struct vpn_provider *provider)
319 {
320         GHashTableIter hash;
321         gpointer value, key;
322
323         g_hash_table_iter_init(&hash, provider->user_routes);
324         while (handle_routes == TRUE && g_hash_table_iter_next(&hash,
325                                                 &key, &value) == TRUE) {
326                 struct vpn_route *route = value;
327                 if (route->family == AF_INET6) {
328                         unsigned char prefixlen = atoi(route->netmask);
329                         connman_inet_del_ipv6_network_route(provider->index,
330                                                         route->network,
331                                                         prefixlen);
332                 } else
333                         connman_inet_del_host_route(provider->index,
334                                                 route->network);
335         }
336
337         g_hash_table_remove_all(provider->user_routes);
338         g_slist_free_full(provider->user_networks, free_route);
339         provider->user_networks = NULL;
340 }
341
342 static void send_value(const char *path, const char *key, const char *value)
343 {
344         const char *empty = "";
345         const char *str;
346
347         if (value != NULL)
348                 str = value;
349         else
350                 str = empty;
351
352         connman_dbus_property_changed_basic(path,
353                                         VPN_CONNECTION_INTERFACE,
354                                         key,
355                                         DBUS_TYPE_STRING,
356                                         &str);
357 }
358
359 static gboolean provider_send_changed(gpointer data)
360 {
361         struct vpn_provider *provider = data;
362
363         provider_routes_changed(provider);
364
365         provider->notify_id = 0;
366
367         return FALSE;
368 }
369
370 static void provider_schedule_changed(struct vpn_provider *provider)
371 {
372         if (provider->notify_id != 0)
373                 g_source_remove(provider->notify_id);
374
375         provider->notify_id = g_timeout_add(100, provider_send_changed,
376                                                                 provider);
377 }
378
379 static DBusMessage *get_properties(DBusConnection *conn,
380                                         DBusMessage *msg, void *data)
381 {
382         struct vpn_provider *provider = data;
383         DBusMessage *reply;
384         DBusMessageIter array;
385
386         DBG("provider %p", provider);
387
388         reply = dbus_message_new_method_return(msg);
389         if (reply == NULL)
390                 return NULL;
391
392         dbus_message_iter_init_append(reply, &array);
393
394         append_properties(&array, provider);
395
396         return reply;
397 }
398
399 static DBusMessage *set_property(DBusConnection *conn, DBusMessage *msg,
400                                                                 void *data)
401 {
402         struct vpn_provider *provider = data;
403         DBusMessageIter iter, value;
404         const char *name;
405         int type;
406
407         DBG("conn %p", conn);
408
409         if (dbus_message_iter_init(msg, &iter) == FALSE)
410                 return __connman_error_invalid_arguments(msg);
411
412         if (dbus_message_iter_get_arg_type(&iter) != DBUS_TYPE_STRING)
413                 return __connman_error_invalid_arguments(msg);
414
415         dbus_message_iter_get_basic(&iter, &name);
416         dbus_message_iter_next(&iter);
417
418         if (dbus_message_iter_get_arg_type(&iter) != DBUS_TYPE_VARIANT)
419                 return __connman_error_invalid_arguments(msg);
420
421         dbus_message_iter_recurse(&iter, &value);
422
423         type = dbus_message_iter_get_arg_type(&value);
424
425         if (g_str_equal(name, "UserRoutes") == TRUE) {
426                 GSList *networks;
427
428                 if (type != DBUS_TYPE_ARRAY)
429                         return __connman_error_invalid_arguments(msg);
430
431                 networks = get_user_networks(&value);
432                 if (networks != NULL) {
433                         del_routes(provider);
434                         provider->user_networks = networks;
435                         set_user_networks(provider, provider->user_networks);
436
437                         if (handle_routes == FALSE)
438                                 send_routes(provider, provider->user_routes,
439                                                                 "UserRoutes");
440                 }
441         } else {
442                 const char *str;
443
444                 dbus_message_iter_get_basic(&value, &str);
445                 vpn_provider_set_string(provider, name, str);
446         }
447
448         return g_dbus_create_reply(msg, DBUS_TYPE_INVALID);
449 }
450
451 static DBusMessage *clear_property(DBusConnection *conn, DBusMessage *msg,
452                                                                 void *data)
453 {
454         struct vpn_provider *provider = data;
455         const char *name;
456
457         DBG("conn %p", conn);
458
459         dbus_message_get_args(msg, NULL, DBUS_TYPE_STRING, &name,
460                                                         DBUS_TYPE_INVALID);
461
462         if (g_str_equal(name, "UserRoutes") == TRUE) {
463                 del_routes(provider);
464
465                 if (handle_routes == FALSE)
466                         send_routes(provider, provider->user_routes, name);
467         } else if (vpn_provider_get_string(provider, name) != NULL) {
468                 vpn_provider_set_string(provider, name, NULL);
469         } else {
470                 return __connman_error_invalid_property(msg);
471         }
472
473         return g_dbus_create_reply(msg, DBUS_TYPE_INVALID);
474 }
475
476 static DBusMessage *do_connect(DBusConnection *conn, DBusMessage *msg,
477                                                                 void *data)
478 {
479         struct vpn_provider *provider = data;
480         int err;
481
482         DBG("conn %p provider %p", conn, provider);
483
484         err = __vpn_provider_connect(provider, msg);
485         if (err < 0)
486                 return __connman_error_failed(msg, -err);
487
488         return NULL;
489 }
490
491 static DBusMessage *do_disconnect(DBusConnection *conn, DBusMessage *msg,
492                                                                 void *data)
493 {
494         struct vpn_provider *provider = data;
495         int err;
496
497         DBG("conn %p provider %p", conn, provider);
498
499         err = __vpn_provider_disconnect(provider);
500         if (err < 0 && err != -EINPROGRESS)
501                 return __connman_error_failed(msg, -err);
502
503         return g_dbus_create_reply(msg, DBUS_TYPE_INVALID);
504 }
505
506 static const GDBusMethodTable connection_methods[] = {
507         { GDBUS_METHOD("GetProperties",
508                         NULL, GDBUS_ARGS({ "properties", "a{sv}" }),
509                         get_properties) },
510         { GDBUS_METHOD("SetProperty",
511                         GDBUS_ARGS({ "name", "s" }, { "value", "v" }),
512                         NULL, set_property) },
513         { GDBUS_METHOD("ClearProperty",
514                         GDBUS_ARGS({ "name", "s" }), NULL,
515                         clear_property) },
516         { GDBUS_ASYNC_METHOD("Connect", NULL, NULL, do_connect) },
517         { GDBUS_METHOD("Disconnect", NULL, NULL, do_disconnect) },
518         { },
519 };
520
521 static const GDBusSignalTable connection_signals[] = {
522         { GDBUS_SIGNAL("PropertyChanged",
523                         GDBUS_ARGS({ "name", "s" }, { "value", "v" })) },
524         { },
525 };
526
527 static void resolv_result(GResolvResultStatus status,
528                                         char **results, gpointer user_data)
529 {
530         struct vpn_provider *provider = user_data;
531
532         DBG("status %d", status);
533
534         if (status == G_RESOLV_RESULT_STATUS_SUCCESS && results != NULL &&
535                                                 g_strv_length(results) > 0)
536                 provider->host_ip = g_strdupv(results);
537
538         vpn_provider_unref(provider);
539 }
540
541 static void provider_resolv_host_addr(struct vpn_provider *provider)
542 {
543         if (provider->host == NULL)
544                 return;
545
546         if (connman_inet_check_ipaddress(provider->host) > 0)
547                 return;
548
549         if (provider->host_ip != NULL)
550                 return;
551
552         /*
553          * If the hostname is not numeric, try to resolv it. We do not wait
554          * the result as it might take some time. We will get the result
555          * before VPN will feed routes to us because VPN client will need
556          * the IP address also before VPN connection can be established.
557          */
558         provider->resolv = g_resolv_new(0);
559         if (provider->resolv == NULL) {
560                 DBG("Cannot resolv %s", provider->host);
561                 return;
562         }
563
564         DBG("Trying to resolv %s", provider->host);
565
566         vpn_provider_ref(provider);
567
568         g_resolv_lookup_hostname(provider->resolv, provider->host,
569                                 resolv_result, provider);
570 }
571
572 void __vpn_provider_append_properties(struct vpn_provider *provider,
573                                                         DBusMessageIter *iter)
574 {
575         if (provider->host != NULL)
576                 connman_dbus_dict_append_basic(iter, "Host",
577                                         DBUS_TYPE_STRING, &provider->host);
578
579         if (provider->domain != NULL)
580                 connman_dbus_dict_append_basic(iter, "Domain",
581                                         DBUS_TYPE_STRING, &provider->domain);
582
583         if (provider->type != NULL)
584                 connman_dbus_dict_append_basic(iter, "Type", DBUS_TYPE_STRING,
585                                                  &provider->type);
586 }
587
588 int __vpn_provider_append_user_route(struct vpn_provider *provider,
589                                 int family, const char *network,
590                                 const char *netmask, const char *gateway)
591 {
592         struct vpn_route *route;
593         char *key = g_strdup_printf("%d/%s/%s/%s", family, network,
594                                 netmask, gateway != NULL ? gateway : "");
595
596         DBG("family %d network %s netmask %s gw %s", family, network,
597                                                         netmask, gateway);
598
599         route = g_hash_table_lookup(provider->user_routes, key);
600         if (route == NULL) {
601                 route = g_try_new0(struct vpn_route, 1);
602                 if (route == NULL) {
603                         connman_error("out of memory");
604                         return -ENOMEM;
605                 }
606
607                 route->family = family;
608                 route->network = g_strdup(network);
609                 route->netmask = g_strdup(netmask);
610                 route->gateway = g_strdup(gateway);
611
612                 g_hash_table_replace(provider->user_routes, key, route);
613         } else
614                 g_free(key);
615
616         return 0;
617 }
618
619 static struct vpn_route *get_route(char *route_str)
620 {
621         char **elems = g_strsplit(route_str, "/", 0);
622         char *network, *netmask, *gateway, *family_str;
623         int family = PF_UNSPEC;
624         struct vpn_route *route = NULL;
625
626         if (elems == NULL)
627                 return NULL;
628
629         family_str = elems[0];
630
631         network = elems[1];
632         if (network == NULL || network[0] == '\0')
633                 goto out;
634
635         netmask = elems[2];
636         if (netmask == NULL || netmask[0] == '\0')
637                 goto out;
638
639         gateway = elems[3];
640
641         route = g_try_new0(struct vpn_route, 1);
642         if (route == NULL)
643                 goto out;
644
645         if (family_str[0] == '\0' || atoi(family_str) == 0) {
646                 family = PF_UNSPEC;
647         } else {
648                 switch (family_str[0]) {
649                 case '4':
650                         family = AF_INET;
651                         break;
652                 case '6':
653                         family = AF_INET6;
654                         break;
655                 }
656         }
657
658         if (g_strrstr(network, ":") != NULL) {
659                 if (family != PF_UNSPEC && family != AF_INET6)
660                         DBG("You have IPv6 address but you have non IPv6 route");
661         } else if (g_strrstr(network, ".") != NULL) {
662                 if (family != PF_UNSPEC && family != AF_INET)
663                         DBG("You have IPv4 address but you have non IPv4 route");
664
665                 if (g_strrstr(netmask, ".") == NULL) {
666                         /* We have netmask length */
667                         in_addr_t addr;
668                         struct in_addr netmask_in;
669                         unsigned char prefix_len = 32;
670
671                         if (netmask != NULL) {
672                                 char *ptr;
673                                 long int value = strtol(netmask, &ptr, 10);
674                                 if (ptr != netmask && *ptr == '\0' &&
675                                                                 value <= 32)
676                                         prefix_len = value;
677                         }
678
679                         addr = 0xffffffff << (32 - prefix_len);
680                         netmask_in.s_addr = htonl(addr);
681                         netmask = inet_ntoa(netmask_in);
682
683                         DBG("network %s netmask %s", network, netmask);
684                 }
685         }
686
687         if (family == PF_UNSPEC) {
688                 family = connman_inet_check_ipaddress(network);
689                 if (family < 0 || family == PF_UNSPEC)
690                         goto out;
691         }
692
693         route->family = family;
694         route->network = g_strdup(network);
695         route->netmask = g_strdup(netmask);
696         route->gateway = g_strdup(gateway);
697
698 out:
699         g_strfreev(elems);
700         return route;
701 }
702
703 static GSList *get_routes(gchar **networks)
704 {
705         struct vpn_route *route;
706         GSList *routes = NULL;
707         int i;
708
709         for (i = 0; networks[i] != NULL; i++) {
710                 route = get_route(networks[i]);
711                 if (route != NULL)
712                         routes = g_slist_prepend(routes, route);
713         }
714
715         return routes;
716 }
717
718 static int provider_load_from_keyfile(struct vpn_provider *provider,
719                 GKeyFile *keyfile)
720 {
721         gsize idx = 0;
722         gchar **settings;
723         gchar *key, *value;
724         gsize length, num_user_networks;
725         gchar **networks = NULL;
726
727         settings = g_key_file_get_keys(keyfile, provider->identifier, &length,
728                                 NULL);
729         if (settings == NULL) {
730                 g_key_file_free(keyfile);
731                 return -ENOENT;
732         }
733
734         while (idx < length) {
735                 key = settings[idx];
736                 if (key != NULL) {
737                         if (g_str_equal(key, "Networks") == TRUE) {
738                                 networks = g_key_file_get_string_list(keyfile,
739                                                 provider->identifier,
740                                                 key,
741                                                 &num_user_networks,
742                                                 NULL);
743                                 provider->user_networks = get_routes(networks);
744
745                         } else {
746                                 value = g_key_file_get_string(keyfile,
747                                                         provider->identifier,
748                                                         key, NULL);
749                                 vpn_provider_set_string(provider, key,
750                                                         value);
751                                 g_free(value);
752                         }
753                 }
754                 idx += 1;
755         }
756         g_strfreev(settings);
757         g_strfreev(networks);
758
759         if (provider->user_networks != NULL)
760                 set_user_networks(provider, provider->user_networks);
761
762         return 0;
763 }
764
765
766 static int vpn_provider_load(struct vpn_provider *provider)
767 {
768         GKeyFile *keyfile;
769
770         DBG("provider %p", provider);
771
772         keyfile = __connman_storage_load_provider(provider->identifier);
773         if (keyfile == NULL)
774                 return -ENOENT;
775
776         provider_load_from_keyfile(provider, keyfile);
777
778         g_key_file_free(keyfile);
779         return 0;
780 }
781
782 static gchar **create_network_list(GSList *networks, gsize *count)
783 {
784         GSList *list;
785         gchar **result = NULL;
786         unsigned int num_elems = 0;
787
788         for (list = networks; list != NULL; list = g_slist_next(list)) {
789                 struct vpn_route *route = list->data;
790                 int family;
791
792                 result = g_try_realloc(result,
793                                 (num_elems + 1) * sizeof(gchar *));
794                 if (result == NULL)
795                         return NULL;
796
797                 switch (route->family) {
798                 case AF_INET:
799                         family = 4;
800                         break;
801                 case AF_INET6:
802                         family = 6;
803                         break;
804                 default:
805                         family = 0;
806                         break;
807                 }
808
809                 result[num_elems] = g_strdup_printf("%d/%s/%s/%s",
810                                 family, route->network, route->netmask,
811                                 route->gateway == NULL ? "" : route->gateway);
812
813                 num_elems++;
814         }
815
816         result = g_try_realloc(result, (num_elems + 1) * sizeof(gchar *));
817         if (result == NULL)
818                 return NULL;
819
820         result[num_elems] = NULL;
821         *count = num_elems;
822         return result;
823 }
824
825 static int vpn_provider_save(struct vpn_provider *provider)
826 {
827         GKeyFile *keyfile;
828
829         DBG("provider %p", provider);
830
831         keyfile = g_key_file_new();
832         if (keyfile == NULL)
833                 return -ENOMEM;
834
835         g_key_file_set_string(keyfile, provider->identifier,
836                         "Name", provider->name);
837         g_key_file_set_string(keyfile, provider->identifier,
838                         "Type", provider->type);
839         g_key_file_set_string(keyfile, provider->identifier,
840                         "Host", provider->host);
841         g_key_file_set_string(keyfile, provider->identifier,
842                         "VPN.Domain", provider->domain);
843         if (provider->user_networks != NULL) {
844                 gchar **networks;
845                 gsize network_count;
846
847                 networks = create_network_list(provider->user_networks,
848                                                         &network_count);
849                 if (networks != NULL) {
850                         g_key_file_set_string_list(keyfile,
851                                                 provider->identifier,
852                                                 "Networks",
853                                                 (const gchar ** const)networks,
854                                                 network_count);
855                         g_strfreev(networks);
856                 }
857         }
858
859         if (provider->config_file != NULL && strlen(provider->config_file) > 0)
860                 g_key_file_set_string(keyfile, provider->identifier,
861                                 "Config.file", provider->config_file);
862
863         if (provider->config_entry != NULL &&
864                                         strlen(provider->config_entry) > 0)
865                 g_key_file_set_string(keyfile, provider->identifier,
866                                 "Config.ident", provider->config_entry);
867
868         if (provider->driver != NULL && provider->driver->save != NULL)
869                 provider->driver->save(provider, keyfile);
870
871         __connman_storage_save_provider(keyfile, provider->identifier);
872         g_key_file_free(keyfile);
873
874         return 0;
875 }
876
877 struct vpn_provider *__vpn_provider_lookup(const char *identifier)
878 {
879         struct vpn_provider *provider = NULL;
880
881         provider = g_hash_table_lookup(provider_hash, identifier);
882
883         return provider;
884 }
885
886 static gboolean match_driver(struct vpn_provider *provider,
887                                 struct vpn_provider_driver *driver)
888 {
889         if (g_strcmp0(driver->name, provider->type) == 0)
890                 return TRUE;
891
892         return FALSE;
893 }
894
895 static int provider_probe(struct vpn_provider *provider)
896 {
897         GSList *list;
898
899         DBG("provider %p driver %p name %s", provider, provider->driver,
900                                                 provider->name);
901
902         if (provider->driver != NULL)
903                 return -EALREADY;
904
905         for (list = driver_list; list; list = list->next) {
906                 struct vpn_provider_driver *driver = list->data;
907
908                 if (match_driver(provider, driver) == FALSE)
909                         continue;
910
911                 DBG("driver %p name %s", driver, driver->name);
912
913                 if (driver->probe != NULL && driver->probe(provider) == 0) {
914                         provider->driver = driver;
915                         break;
916                 }
917         }
918
919         if (provider->driver == NULL)
920                 return -ENODEV;
921
922         return 0;
923 }
924
925 static void provider_remove(struct vpn_provider *provider)
926 {
927         if (provider->driver != NULL) {
928                 provider->driver->remove(provider);
929                 provider->driver = NULL;
930         }
931 }
932
933 static int provider_register(struct vpn_provider *provider)
934 {
935         return provider_probe(provider);
936 }
937
938 static void provider_unregister(struct vpn_provider *provider)
939 {
940         provider_remove(provider);
941 }
942
943 struct vpn_provider *
944 vpn_provider_ref_debug(struct vpn_provider *provider,
945                         const char *file, int line, const char *caller)
946 {
947         DBG("%p ref %d by %s:%d:%s()", provider, provider->refcount + 1,
948                 file, line, caller);
949
950         __sync_fetch_and_add(&provider->refcount, 1);
951
952         return provider;
953 }
954
955 static void provider_destruct(struct vpn_provider *provider)
956 {
957         DBG("provider %p", provider);
958
959         if (provider->notify_id != 0)
960                 g_source_remove(provider->notify_id);
961
962         g_free(provider->name);
963         g_free(provider->type);
964         g_free(provider->host);
965         g_free(provider->domain);
966         g_free(provider->identifier);
967         g_free(provider->path);
968         g_slist_free_full(provider->user_networks, free_route);
969         g_strfreev(provider->nameservers);
970         g_hash_table_destroy(provider->routes);
971         g_hash_table_destroy(provider->user_routes);
972         g_hash_table_destroy(provider->setting_strings);
973         if (provider->resolv != NULL) {
974                 g_resolv_unref(provider->resolv);
975                 provider->resolv = NULL;
976         }
977         __vpn_ipconfig_unref(provider->ipconfig_ipv4);
978         __vpn_ipconfig_unref(provider->ipconfig_ipv6);
979
980         g_strfreev(provider->host_ip);
981         g_free(provider->config_file);
982         g_free(provider->config_entry);
983         g_free(provider);
984 }
985
986 void vpn_provider_unref_debug(struct vpn_provider *provider,
987                                 const char *file, int line, const char *caller)
988 {
989         DBG("%p ref %d by %s:%d:%s()", provider, provider->refcount - 1,
990                 file, line, caller);
991
992         if (__sync_fetch_and_sub(&provider->refcount, 1) != 1)
993                 return;
994
995         provider_remove(provider);
996
997         provider_destruct(provider);
998 }
999
1000 static void configuration_count_add(void)
1001 {
1002         DBG("count %d", configuration_count + 1);
1003
1004         __sync_fetch_and_add(&configuration_count, 1);
1005 }
1006
1007 static void configuration_count_del(void)
1008 {
1009         DBG("count %d", configuration_count - 1);
1010
1011         if (__sync_fetch_and_sub(&configuration_count, 1) != 1)
1012                 return;
1013
1014         raise(SIGTERM);
1015 }
1016
1017 int __vpn_provider_disconnect(struct vpn_provider *provider)
1018 {
1019         int err;
1020
1021         DBG("provider %p", provider);
1022
1023         if (provider->driver != NULL && provider->driver->disconnect != NULL)
1024                 err = provider->driver->disconnect(provider);
1025         else
1026                 return -EOPNOTSUPP;
1027
1028         if (err == -EINPROGRESS)
1029                 vpn_provider_set_state(provider, VPN_PROVIDER_STATE_CONNECT);
1030
1031         return err;
1032 }
1033
1034 static void connect_cb(struct vpn_provider *provider, void *user_data,
1035                                                                 int error)
1036 {
1037         DBusMessage *pending = user_data;
1038
1039         DBG("provider %p user %p error %d", provider, user_data, error);
1040
1041         if (error != 0) {
1042                 DBusMessage *reply = __connman_error_failed(pending, error);
1043                 if (reply != NULL)
1044                         g_dbus_send_message(connection, reply);
1045
1046                 vpn_provider_indicate_error(provider,
1047                                         VPN_PROVIDER_ERROR_CONNECT_FAILED);
1048                 vpn_provider_set_state(provider, VPN_PROVIDER_STATE_FAILURE);
1049         } else
1050                 g_dbus_send_reply(connection, pending, DBUS_TYPE_INVALID);
1051
1052         dbus_message_unref(pending);
1053 }
1054
1055 int __vpn_provider_connect(struct vpn_provider *provider, DBusMessage *msg)
1056 {
1057         int err;
1058
1059         DBG("provider %p", provider);
1060
1061         if (provider->driver != NULL && provider->driver->connect != NULL) {
1062                 dbus_message_ref(msg);
1063                 err = provider->driver->connect(provider, connect_cb, msg);
1064         } else
1065                 return -EOPNOTSUPP;
1066
1067         if (err == -EINPROGRESS)
1068                 vpn_provider_set_state(provider, VPN_PROVIDER_STATE_CONNECT);
1069
1070         return err;
1071 }
1072
1073 static void connection_removed_signal(struct vpn_provider *provider)
1074 {
1075         DBusMessage *signal;
1076         DBusMessageIter iter;
1077
1078         signal = dbus_message_new_signal(VPN_MANAGER_PATH,
1079                         VPN_MANAGER_INTERFACE, "ConnectionRemoved");
1080         if (signal == NULL)
1081                 return;
1082
1083         dbus_message_iter_init_append(signal, &iter);
1084         dbus_message_iter_append_basic(&iter, DBUS_TYPE_OBJECT_PATH,
1085                                                         &provider->path);
1086         dbus_connection_send(connection, signal, NULL);
1087         dbus_message_unref(signal);
1088 }
1089
1090 static char *get_ident(const char *path)
1091 {
1092         char *pos;
1093
1094         if (*path != '/')
1095                 return NULL;
1096
1097         pos = strrchr(path, '/');
1098         if (pos == NULL)
1099                 return NULL;
1100
1101         return pos + 1;
1102 }
1103
1104 int __vpn_provider_remove(const char *path)
1105 {
1106         struct vpn_provider *provider;
1107         char *ident;
1108
1109         DBG("path %s", path);
1110
1111         ident = get_ident(path);
1112
1113         provider = __vpn_provider_lookup(ident);
1114         if (provider != NULL)
1115                 return __vpn_provider_delete(provider);
1116
1117         return -ENXIO;
1118 }
1119
1120 int __vpn_provider_delete(struct vpn_provider *provider)
1121 {
1122         DBG("Deleting VPN %s", provider->identifier);
1123
1124         connection_removed_signal(provider);
1125
1126         provider_unregister(provider);
1127
1128         __connman_storage_remove_provider(provider->identifier);
1129
1130         g_hash_table_remove(provider_hash, provider->identifier);
1131
1132         return 0;
1133 }
1134
1135 static void append_ipv4(DBusMessageIter *iter, void *user_data)
1136 {
1137         struct vpn_provider *provider = user_data;
1138         const char *address, *gateway, *peer;
1139
1140         address = __vpn_ipconfig_get_local(provider->ipconfig_ipv4);
1141         if (address != NULL) {
1142                 in_addr_t addr;
1143                 struct in_addr netmask;
1144                 char *mask;
1145                 int prefixlen;
1146
1147                 prefixlen = __vpn_ipconfig_get_prefixlen(
1148                                                 provider->ipconfig_ipv4);
1149
1150                 addr = 0xffffffff << (32 - prefixlen);
1151                 netmask.s_addr = htonl(addr);
1152                 mask = inet_ntoa(netmask);
1153
1154                 connman_dbus_dict_append_basic(iter, "Address",
1155                                                 DBUS_TYPE_STRING, &address);
1156
1157                 connman_dbus_dict_append_basic(iter, "Netmask",
1158                                                 DBUS_TYPE_STRING, &mask);
1159         }
1160
1161         gateway = __vpn_ipconfig_get_gateway(provider->ipconfig_ipv4);
1162         if (gateway != NULL)
1163                 connman_dbus_dict_append_basic(iter, "Gateway",
1164                                                 DBUS_TYPE_STRING, &gateway);
1165
1166         peer = __vpn_ipconfig_get_peer(provider->ipconfig_ipv4);
1167         if (peer != NULL)
1168                 connman_dbus_dict_append_basic(iter, "Peer",
1169                                                 DBUS_TYPE_STRING, &peer);
1170 }
1171
1172 static void append_ipv6(DBusMessageIter *iter, void *user_data)
1173 {
1174         struct vpn_provider *provider = user_data;
1175         const char *address, *gateway, *peer;
1176
1177         address = __vpn_ipconfig_get_local(provider->ipconfig_ipv6);
1178         if (address != NULL) {
1179                 unsigned char prefixlen;
1180
1181                 connman_dbus_dict_append_basic(iter, "Address",
1182                                                 DBUS_TYPE_STRING, &address);
1183
1184                 prefixlen = __vpn_ipconfig_get_prefixlen(
1185                                                 provider->ipconfig_ipv6);
1186
1187                 connman_dbus_dict_append_basic(iter, "PrefixLength",
1188                                                 DBUS_TYPE_BYTE, &prefixlen);
1189         }
1190
1191         gateway = __vpn_ipconfig_get_gateway(provider->ipconfig_ipv6);
1192         if (gateway != NULL)
1193                 connman_dbus_dict_append_basic(iter, "Gateway",
1194                                                 DBUS_TYPE_STRING, &gateway);
1195
1196         peer = __vpn_ipconfig_get_peer(provider->ipconfig_ipv6);
1197         if (peer != NULL)
1198                 connman_dbus_dict_append_basic(iter, "Peer",
1199                                                 DBUS_TYPE_STRING, &peer);
1200 }
1201
1202 static const char *state2string(enum vpn_provider_state state)
1203 {
1204         switch (state) {
1205         case VPN_PROVIDER_STATE_UNKNOWN:
1206                 break;
1207         case VPN_PROVIDER_STATE_IDLE:
1208                 return "idle";
1209         case VPN_PROVIDER_STATE_CONNECT:
1210                 return "configuration";
1211         case VPN_PROVIDER_STATE_READY:
1212                 return "ready";
1213         case VPN_PROVIDER_STATE_DISCONNECT:
1214                 return "disconnect";
1215         case VPN_PROVIDER_STATE_FAILURE:
1216                 return "failure";
1217         }
1218
1219         return NULL;
1220 }
1221
1222 static int provider_indicate_state(struct vpn_provider *provider,
1223                                 enum vpn_provider_state state)
1224 {
1225         const char *str;
1226         enum vpn_provider_state old_state;
1227
1228         str = state2string(state);
1229         DBG("provider %p state %s/%d", provider, str, state);
1230         if (str == NULL)
1231                 return -EINVAL;
1232
1233         old_state = provider->state;
1234         provider->state = state;
1235
1236         if (state == VPN_PROVIDER_STATE_READY) {
1237                 connman_dbus_property_changed_basic(provider->path,
1238                                         VPN_CONNECTION_INTERFACE, "Index",
1239                                         DBUS_TYPE_INT32, &provider->index);
1240
1241                 if (provider->family == AF_INET)
1242                         connman_dbus_property_changed_dict(provider->path,
1243                                         VPN_CONNECTION_INTERFACE, "IPv4",
1244                                         append_ipv4, provider);
1245                 else if (provider->family == AF_INET6)
1246                         connman_dbus_property_changed_dict(provider->path,
1247                                         VPN_CONNECTION_INTERFACE, "IPv6",
1248                                         append_ipv6, provider);
1249         }
1250
1251         if (old_state != state)
1252                 connman_dbus_property_changed_basic(provider->path,
1253                                         VPN_CONNECTION_INTERFACE, "State",
1254                                         DBUS_TYPE_STRING, &str);
1255
1256         /*
1257          * We do not stay in failure state as clients like connmand can
1258          * get confused about our current state.
1259          */
1260         if (provider->state == VPN_PROVIDER_STATE_FAILURE)
1261                 provider->state = VPN_PROVIDER_STATE_IDLE;
1262
1263         return 0;
1264 }
1265
1266 static void append_nameservers(DBusMessageIter *iter, char **servers)
1267 {
1268         int i;
1269
1270         DBG("%p", servers);
1271
1272         for (i = 0; servers[i] != NULL; i++) {
1273                 DBG("servers[%d] %s", i, servers[i]);
1274                 dbus_message_iter_append_basic(iter,
1275                                         DBUS_TYPE_STRING, &servers[i]);
1276         }
1277 }
1278
1279 static void append_dns(DBusMessageIter *iter, void *user_data)
1280 {
1281         struct vpn_provider *provider = user_data;
1282
1283         if (provider->nameservers != NULL)
1284                 append_nameservers(iter, provider->nameservers);
1285 }
1286
1287 static void append_state(DBusMessageIter *iter,
1288                                         struct vpn_provider *provider)
1289 {
1290         char *str;
1291
1292         switch (provider->state) {
1293         case VPN_PROVIDER_STATE_UNKNOWN:
1294         case VPN_PROVIDER_STATE_IDLE:
1295                 str = "idle";
1296                 break;
1297         case VPN_PROVIDER_STATE_CONNECT:
1298                 str = "configuration";
1299                 break;
1300         case VPN_PROVIDER_STATE_READY:
1301                 str = "ready";
1302                 break;
1303         case VPN_PROVIDER_STATE_DISCONNECT:
1304                 str = "disconnect";
1305                 break;
1306         case VPN_PROVIDER_STATE_FAILURE:
1307                 str = "failure";
1308                 break;
1309         }
1310
1311         connman_dbus_dict_append_basic(iter, "State",
1312                                 DBUS_TYPE_STRING, &str);
1313 }
1314
1315 static void append_properties(DBusMessageIter *iter,
1316                                         struct vpn_provider *provider)
1317 {
1318         DBusMessageIter dict;
1319         GHashTableIter hash;
1320         gpointer value, key;
1321
1322         connman_dbus_dict_open(iter, &dict);
1323
1324         append_state(&dict, provider);
1325
1326         if (provider->type != NULL)
1327                 connman_dbus_dict_append_basic(&dict, "Type",
1328                                         DBUS_TYPE_STRING, &provider->type);
1329
1330         if (provider->name != NULL)
1331                 connman_dbus_dict_append_basic(&dict, "Name",
1332                                         DBUS_TYPE_STRING, &provider->name);
1333
1334         if (provider->host != NULL)
1335                 connman_dbus_dict_append_basic(&dict, "Host",
1336                                         DBUS_TYPE_STRING, &provider->host);
1337         if (provider->index >= 0)
1338                 connman_dbus_dict_append_basic(&dict, "Index",
1339                                         DBUS_TYPE_INT32, &provider->index);
1340         if (provider->domain != NULL)
1341                 connman_dbus_dict_append_basic(&dict, "Domain",
1342                                         DBUS_TYPE_STRING, &provider->domain);
1343
1344         if (provider->family == AF_INET)
1345                 connman_dbus_dict_append_dict(&dict, "IPv4", append_ipv4,
1346                                                 provider);
1347         else if (provider->family == AF_INET6)
1348                 connman_dbus_dict_append_dict(&dict, "IPv6", append_ipv6,
1349                                                 provider);
1350
1351         connman_dbus_dict_append_array(&dict, "Nameservers",
1352                                 DBUS_TYPE_STRING, append_dns, provider);
1353
1354         connman_dbus_dict_append_array(&dict, "UserRoutes",
1355                                 DBUS_TYPE_DICT_ENTRY, append_routes,
1356                                 provider->user_routes);
1357
1358         connman_dbus_dict_append_array(&dict, "ServerRoutes",
1359                                 DBUS_TYPE_DICT_ENTRY, append_routes,
1360                                 provider->routes);
1361
1362         if (provider->setting_strings != NULL) {
1363                 g_hash_table_iter_init(&hash, provider->setting_strings);
1364
1365                 while (g_hash_table_iter_next(&hash, &key, &value) == TRUE) {
1366                         struct vpn_setting *setting = value;
1367
1368                         if (setting->hide_value == FALSE &&
1369                                                         setting->value != NULL)
1370                                 connman_dbus_dict_append_basic(&dict, key,
1371                                                         DBUS_TYPE_STRING,
1372                                                         &setting->value);
1373                 }
1374         }
1375
1376         connman_dbus_dict_close(iter, &dict);
1377 }
1378
1379 static void connection_added_signal(struct vpn_provider *provider)
1380 {
1381         DBusMessage *signal;
1382         DBusMessageIter iter;
1383
1384         signal = dbus_message_new_signal(VPN_MANAGER_PATH,
1385                         VPN_MANAGER_INTERFACE, "ConnectionAdded");
1386         if (signal == NULL)
1387                 return;
1388
1389         dbus_message_iter_init_append(signal, &iter);
1390         dbus_message_iter_append_basic(&iter, DBUS_TYPE_OBJECT_PATH,
1391                                                         &provider->path);
1392         append_properties(&iter, provider);
1393
1394         dbus_connection_send(connection, signal, NULL);
1395         dbus_message_unref(signal);
1396 }
1397
1398 static connman_bool_t check_host(char **hosts, char *host)
1399 {
1400         int i;
1401
1402         if (hosts == NULL)
1403                 return FALSE;
1404
1405         for (i = 0; hosts[i] != NULL; i++) {
1406                 if (g_strcmp0(hosts[i], host) == 0)
1407                         return TRUE;
1408         }
1409
1410         return FALSE;
1411 }
1412
1413 static void provider_append_routes(gpointer key, gpointer value,
1414                                         gpointer user_data)
1415 {
1416         struct vpn_route *route = value;
1417         struct vpn_provider *provider = user_data;
1418         int index = provider->index;
1419
1420         if (handle_routes == FALSE)
1421                 return;
1422
1423         /*
1424          * If the VPN administrator/user has given a route to
1425          * VPN server, then we must discard that because the
1426          * server cannot be contacted via VPN tunnel.
1427          */
1428         if (check_host(provider->host_ip, route->network) == TRUE) {
1429                 DBG("Discarding VPN route to %s via %s at index %d",
1430                         route->network, route->gateway, index);
1431                 return;
1432         }
1433
1434         if (route->family == AF_INET6) {
1435                 unsigned char prefix_len = atoi(route->netmask);
1436
1437                 connman_inet_add_ipv6_network_route(index, route->network,
1438                                                         route->gateway,
1439                                                         prefix_len);
1440         } else {
1441                 connman_inet_add_network_route(index, route->network,
1442                                                 route->gateway,
1443                                                 route->netmask);
1444         }
1445 }
1446
1447 static int set_connected(struct vpn_provider *provider,
1448                                         connman_bool_t connected)
1449 {
1450         struct vpn_ipconfig *ipconfig;
1451
1452         DBG("provider %p id %s connected %d", provider,
1453                                         provider->identifier, connected);
1454
1455         if (connected == TRUE) {
1456                 if (provider->family == AF_INET6)
1457                         ipconfig = provider->ipconfig_ipv6;
1458                 else
1459                         ipconfig = provider->ipconfig_ipv4;
1460
1461                 __vpn_ipconfig_address_add(ipconfig, provider->family);
1462
1463                 if (handle_routes == TRUE)
1464                         __vpn_ipconfig_gateway_add(ipconfig, provider->family);
1465
1466                 provider_indicate_state(provider,
1467                                         VPN_PROVIDER_STATE_READY);
1468
1469                 g_hash_table_foreach(provider->routes, provider_append_routes,
1470                                         provider);
1471
1472                 g_hash_table_foreach(provider->user_routes,
1473                                         provider_append_routes, provider);
1474
1475         } else {
1476                 provider_indicate_state(provider,
1477                                         VPN_PROVIDER_STATE_DISCONNECT);
1478
1479                 provider_indicate_state(provider,
1480                                         VPN_PROVIDER_STATE_IDLE);
1481         }
1482
1483         return 0;
1484 }
1485
1486 int vpn_provider_set_state(struct vpn_provider *provider,
1487                                         enum vpn_provider_state state)
1488 {
1489         if (provider == NULL)
1490                 return -EINVAL;
1491
1492         switch (state) {
1493         case VPN_PROVIDER_STATE_UNKNOWN:
1494                 return -EINVAL;
1495         case VPN_PROVIDER_STATE_IDLE:
1496                 return set_connected(provider, FALSE);
1497         case VPN_PROVIDER_STATE_CONNECT:
1498                 return provider_indicate_state(provider, state);
1499         case VPN_PROVIDER_STATE_READY:
1500                 return set_connected(provider, TRUE);
1501         case VPN_PROVIDER_STATE_DISCONNECT:
1502                 return provider_indicate_state(provider, state);
1503         case VPN_PROVIDER_STATE_FAILURE:
1504                 return provider_indicate_state(provider, state);
1505         }
1506         return -EINVAL;
1507 }
1508
1509 int vpn_provider_indicate_error(struct vpn_provider *provider,
1510                                         enum vpn_provider_error error)
1511 {
1512         DBG("provider %p id %s error %d", provider, provider->identifier,
1513                                                                         error);
1514
1515         switch (error) {
1516         case VPN_PROVIDER_ERROR_LOGIN_FAILED:
1517                 break;
1518         case VPN_PROVIDER_ERROR_AUTH_FAILED:
1519                 vpn_provider_set_state(provider, VPN_PROVIDER_STATE_FAILURE);
1520                 break;
1521         case VPN_PROVIDER_ERROR_CONNECT_FAILED:
1522                 break;
1523         default:
1524                 break;
1525         }
1526
1527         return 0;
1528 }
1529
1530 static int connection_unregister(struct vpn_provider *provider)
1531 {
1532         DBG("provider %p path %s", provider, provider->path);
1533
1534         if (provider->path == NULL)
1535                 return -EALREADY;
1536
1537         g_dbus_unregister_interface(connection, provider->path,
1538                                 VPN_CONNECTION_INTERFACE);
1539
1540         g_free(provider->path);
1541         provider->path = NULL;
1542
1543         return 0;
1544 }
1545
1546 static int connection_register(struct vpn_provider *provider)
1547 {
1548         DBG("provider %p path %s", provider, provider->path);
1549
1550         if (provider->path != NULL)
1551                 return -EALREADY;
1552
1553         provider->path = g_strdup_printf("%s/connection/%s", VPN_PATH,
1554                                                 provider->identifier);
1555
1556         g_dbus_register_interface(connection, provider->path,
1557                                 VPN_CONNECTION_INTERFACE,
1558                                 connection_methods, connection_signals,
1559                                 NULL, provider, NULL);
1560
1561         return 0;
1562 }
1563
1564 static void unregister_provider(gpointer data)
1565 {
1566         struct vpn_provider *provider = data;
1567
1568         configuration_count_del();
1569
1570         connection_unregister(provider);
1571
1572         vpn_provider_unref(provider);
1573 }
1574
1575 static void provider_initialize(struct vpn_provider *provider)
1576 {
1577         DBG("provider %p", provider);
1578
1579         provider->index = 0;
1580         provider->fd = -1;
1581         provider->name = NULL;
1582         provider->type = NULL;
1583         provider->domain = NULL;
1584         provider->identifier = NULL;
1585         provider->user_networks = NULL;
1586         provider->routes = g_hash_table_new_full(g_direct_hash, g_direct_equal,
1587                                         NULL, free_route);
1588         provider->user_routes = g_hash_table_new_full(g_str_hash, g_str_equal,
1589                                         g_free, free_route);
1590         provider->setting_strings = g_hash_table_new_full(g_str_hash,
1591                                         g_str_equal, g_free, free_setting);
1592 }
1593
1594 static struct vpn_provider *vpn_provider_new(void)
1595 {
1596         struct vpn_provider *provider;
1597
1598         provider = g_try_new0(struct vpn_provider, 1);
1599         if (provider == NULL)
1600                 return NULL;
1601
1602         provider->refcount = 1;
1603
1604         DBG("provider %p", provider);
1605         provider_initialize(provider);
1606
1607         return provider;
1608 }
1609
1610 static struct vpn_provider *vpn_provider_get(const char *identifier)
1611 {
1612         struct vpn_provider *provider;
1613
1614         provider = g_hash_table_lookup(provider_hash, identifier);
1615         if (provider != NULL)
1616                 return provider;
1617
1618         provider = vpn_provider_new();
1619         if (provider == NULL)
1620                 return NULL;
1621
1622         DBG("provider %p", provider);
1623
1624         provider->identifier = g_strdup(identifier);
1625
1626         g_hash_table_insert(provider_hash, provider->identifier, provider);
1627
1628         configuration_count_add();
1629
1630         return provider;
1631 }
1632
1633 static void provider_dbus_ident(char *ident)
1634 {
1635         int i, len = strlen(ident);
1636
1637         for (i = 0; i < len; i++) {
1638                 if (ident[i] >= '0' && ident[i] <= '9')
1639                         continue;
1640                 if (ident[i] >= 'a' && ident[i] <= 'z')
1641                         continue;
1642                 if (ident[i] >= 'A' && ident[i] <= 'Z')
1643                         continue;
1644                 ident[i] = '_';
1645         }
1646 }
1647
1648 static struct vpn_provider *provider_create_from_keyfile(GKeyFile *keyfile,
1649                 const char *ident)
1650 {
1651         struct vpn_provider *provider;
1652
1653         if (keyfile == NULL || ident == NULL)
1654                 return NULL;
1655
1656         provider = __vpn_provider_lookup(ident);
1657         if (provider == NULL) {
1658                 provider = vpn_provider_get(ident);
1659                 if (provider == NULL) {
1660                         DBG("can not create provider");
1661                         return NULL;
1662                 }
1663
1664                 provider_load_from_keyfile(provider, keyfile);
1665
1666                 if (provider->name == NULL || provider->host == NULL ||
1667                                 provider->domain == NULL) {
1668                         DBG("cannot get name, host or domain");
1669                         vpn_provider_unref(provider);
1670                         return NULL;
1671                 }
1672
1673                 if (provider_register(provider) == 0)
1674                         connection_register(provider);
1675         }
1676         return provider;
1677 }
1678
1679 static void provider_create_all_from_type(const char *provider_type)
1680 {
1681         unsigned int i;
1682         char **providers;
1683         char *id, *type;
1684         GKeyFile *keyfile;
1685
1686         DBG("provider type %s", provider_type);
1687
1688         providers = __connman_storage_get_providers();
1689
1690         if (providers == NULL)
1691                 return;
1692
1693         for (i = 0; providers[i] != NULL; i+=1) {
1694
1695                 if (strncmp(providers[i], "provider_", 9) != 0)
1696                         continue;
1697
1698                 id = providers[i] + 9;
1699                 keyfile = __connman_storage_load_provider(id);
1700
1701                 if (keyfile == NULL)
1702                         continue;
1703
1704                 type = g_key_file_get_string(keyfile, id, "Type", NULL);
1705
1706                 DBG("keyfile %p id %s type %s", keyfile, id, type);
1707
1708                 if (strcmp(provider_type, type) != 0) {
1709                         g_free(type);
1710                         g_key_file_free(keyfile);
1711                         continue;
1712                 }
1713
1714                 if (provider_create_from_keyfile(keyfile, id) == NULL)
1715                         DBG("could not create provider");
1716
1717                 g_free(type);
1718                 g_key_file_free(keyfile);
1719         }
1720         g_strfreev(providers);
1721 }
1722
1723 char *__vpn_provider_create_identifier(const char *host, const char *domain)
1724 {
1725         char *ident;
1726
1727         ident = g_strdup_printf("%s_%s", host, domain);
1728         if (ident == NULL)
1729                 return NULL;
1730
1731         provider_dbus_ident(ident);
1732
1733         return ident;
1734 }
1735
1736 int __vpn_provider_create(DBusMessage *msg)
1737 {
1738         struct vpn_provider *provider;
1739         DBusMessageIter iter, array;
1740         const char *type = NULL, *name = NULL;
1741         const char *host = NULL, *domain = NULL;
1742         GSList *networks = NULL;
1743         char *ident;
1744         int err;
1745
1746         dbus_message_iter_init(msg, &iter);
1747         dbus_message_iter_recurse(&iter, &array);
1748
1749         while (dbus_message_iter_get_arg_type(&array) == DBUS_TYPE_DICT_ENTRY) {
1750                 DBusMessageIter entry, value;
1751                 const char *key;
1752
1753                 dbus_message_iter_recurse(&array, &entry);
1754                 dbus_message_iter_get_basic(&entry, &key);
1755
1756                 dbus_message_iter_next(&entry);
1757                 dbus_message_iter_recurse(&entry, &value);
1758
1759                 switch (dbus_message_iter_get_arg_type(&value)) {
1760                 case DBUS_TYPE_STRING:
1761                         if (g_str_equal(key, "Type") == TRUE)
1762                                 dbus_message_iter_get_basic(&value, &type);
1763                         else if (g_str_equal(key, "Name") == TRUE)
1764                                 dbus_message_iter_get_basic(&value, &name);
1765                         else if (g_str_equal(key, "Host") == TRUE)
1766                                 dbus_message_iter_get_basic(&value, &host);
1767                         else if (g_str_equal(key, "VPN.Domain") == TRUE ||
1768                                         g_str_equal(key, "Domain") == TRUE)
1769                                 dbus_message_iter_get_basic(&value, &domain);
1770                         break;
1771                 case DBUS_TYPE_ARRAY:
1772                         if (g_str_equal(key, "UserRoutes") == TRUE)
1773                                 networks = get_user_networks(&value);
1774                         break;
1775                 }
1776
1777                 dbus_message_iter_next(&array);
1778         }
1779
1780         if (host == NULL || domain == NULL)
1781                 return -EINVAL;
1782
1783         DBG("Type %s name %s networks %p", type, name, networks);
1784
1785         if (type == NULL || name == NULL)
1786                 return -EOPNOTSUPP;
1787
1788         ident = __vpn_provider_create_identifier(host, domain);
1789         DBG("ident %s", ident);
1790
1791         provider = __vpn_provider_lookup(ident);
1792         if (provider == NULL) {
1793                 provider = vpn_provider_get(ident);
1794                 if (provider == NULL) {
1795                         DBG("can not create provider");
1796                         g_free(ident);
1797                         return -EOPNOTSUPP;
1798                 }
1799
1800                 provider->host = g_strdup(host);
1801                 provider->domain = g_strdup(domain);
1802                 provider->name = g_strdup(name);
1803                 provider->type = g_strdup(type);
1804
1805                 if (provider_register(provider) == 0)
1806                         vpn_provider_load(provider);
1807
1808                 provider_resolv_host_addr(provider);
1809         }
1810
1811         if (networks != NULL) {
1812                 g_slist_free_full(provider->user_networks, free_route);
1813                 provider->user_networks = networks;
1814                 set_user_networks(provider, provider->user_networks);
1815         }
1816
1817         dbus_message_iter_init(msg, &iter);
1818         dbus_message_iter_recurse(&iter, &array);
1819
1820         while (dbus_message_iter_get_arg_type(&array) == DBUS_TYPE_DICT_ENTRY) {
1821                 DBusMessageIter entry, value;
1822                 const char *key, *str;
1823
1824                 dbus_message_iter_recurse(&array, &entry);
1825                 dbus_message_iter_get_basic(&entry, &key);
1826
1827                 dbus_message_iter_next(&entry);
1828                 dbus_message_iter_recurse(&entry, &value);
1829
1830                 switch (dbus_message_iter_get_arg_type(&value)) {
1831                 case DBUS_TYPE_STRING:
1832                         dbus_message_iter_get_basic(&value, &str);
1833                         vpn_provider_set_string(provider, key, str);
1834                         break;
1835                 }
1836
1837                 dbus_message_iter_next(&array);
1838         }
1839
1840         g_free(ident);
1841
1842         vpn_provider_save(provider);
1843
1844         err = provider_register(provider);
1845         if (err != 0 && err != -EALREADY)
1846                 return err;
1847
1848         connection_register(provider);
1849
1850         DBG("provider %p index %d path %s", provider, provider->index,
1851                                                         provider->path);
1852
1853         g_dbus_send_reply(connection, msg,
1854                                 DBUS_TYPE_OBJECT_PATH, &provider->path,
1855                                 DBUS_TYPE_INVALID);
1856
1857         connection_added_signal(provider);
1858
1859         return 0;
1860 }
1861
1862 static const char *get_string(GHashTable *settings, const char *key)
1863 {
1864         DBG("settings %p key %s", settings, key);
1865
1866         return g_hash_table_lookup(settings, key);
1867 }
1868
1869 static GSList *parse_user_networks(const char *network_str)
1870 {
1871         GSList *networks = NULL;
1872         char **elems;
1873         int i = 0;
1874
1875         if (network_str == NULL)
1876                 return NULL;
1877
1878         elems = g_strsplit(network_str, ",", 0);
1879         if (elems == NULL)
1880                 return NULL;
1881
1882         while (elems[i] != NULL) {
1883                 struct vpn_route *vpn_route;
1884                 char *network, *netmask, *gateway;
1885                 int family;
1886                 char **route;
1887
1888                 route = g_strsplit(elems[i], "/", 0);
1889                 if (route == NULL)
1890                         goto next;
1891
1892                 network = route[0];
1893                 if (network == NULL || network[0] == '\0')
1894                         goto next;
1895
1896                 family = connman_inet_check_ipaddress(network);
1897                 if (family < 0) {
1898                         DBG("Cannot get address family of %s (%d/%s)", network,
1899                                 family, gai_strerror(family));
1900
1901                         goto next;
1902                 }
1903
1904                 switch (family) {
1905                 case AF_INET:
1906                         break;
1907                 case AF_INET6:
1908                         break;
1909                 default:
1910                         DBG("Unsupported address family %d", family);
1911                         goto next;
1912                 }
1913
1914                 netmask = route[1];
1915                 if (netmask == NULL || netmask[0] == '\0')
1916                         goto next;
1917
1918                 gateway = route[2];
1919
1920                 vpn_route = g_try_new0(struct vpn_route, 1);
1921                 if (vpn_route == NULL) {
1922                         g_strfreev(route);
1923                         break;
1924                 }
1925
1926                 vpn_route->family = family;
1927                 vpn_route->network = g_strdup(network);
1928                 vpn_route->netmask = g_strdup(netmask);
1929                 vpn_route->gateway = g_strdup(gateway);
1930
1931                 DBG("route %s/%s%s%s", network, netmask,
1932                         gateway ? " via " : "", gateway ? gateway : "");
1933
1934                 networks = g_slist_prepend(networks, vpn_route);
1935
1936         next:
1937                 g_strfreev(route);
1938                 i++;
1939         }
1940
1941         g_strfreev(elems);
1942
1943         return g_slist_reverse(networks);
1944 }
1945
1946 int __vpn_provider_create_from_config(GHashTable *settings,
1947                                 const char *config_ident,
1948                                 const char *config_entry)
1949 {
1950         struct vpn_provider *provider;
1951         const char *type, *name, *host, *domain, *networks_str;
1952         GSList *networks;
1953         char *ident = NULL;
1954         GHashTableIter hash;
1955         gpointer value, key;
1956         int err;
1957
1958         type = get_string(settings, "Type");
1959         name = get_string(settings, "Name");
1960         host = get_string(settings, "Host");
1961         domain = get_string(settings, "Domain");
1962         networks_str = get_string(settings, "Networks");
1963         networks = parse_user_networks(networks_str);
1964
1965         if (host == NULL || domain == NULL) {
1966                 err = -EINVAL;
1967                 goto fail;
1968         }
1969
1970         DBG("type %s name %s networks %s", type, name, networks_str);
1971
1972         if (type == NULL || name == NULL) {
1973                 err = -EOPNOTSUPP;
1974                 goto fail;
1975         }
1976
1977         ident = __vpn_provider_create_identifier(host, domain);
1978         DBG("ident %s", ident);
1979
1980         provider = __vpn_provider_lookup(ident);
1981         if (provider == NULL) {
1982                 provider = vpn_provider_get(ident);
1983                 if (provider == NULL) {
1984                         DBG("can not create provider");
1985                         err = -EOPNOTSUPP;
1986                         goto fail;
1987                 }
1988
1989                 provider->host = g_strdup(host);
1990                 provider->domain = g_strdup(domain);
1991                 provider->name = g_strdup(name);
1992                 provider->type = g_ascii_strdown(type, -1);
1993
1994                 provider->config_file = g_strdup(config_ident);
1995                 provider->config_entry = g_strdup(config_entry);
1996
1997                 if (provider_register(provider) == 0)
1998                         vpn_provider_load(provider);
1999
2000                 provider_resolv_host_addr(provider);
2001         }
2002
2003         if (networks != NULL) {
2004                 g_slist_free_full(provider->user_networks, free_route);
2005                 provider->user_networks = networks;
2006                 set_user_networks(provider, provider->user_networks);
2007         }
2008
2009         g_hash_table_iter_init(&hash, settings);
2010
2011         while (g_hash_table_iter_next(&hash, &key, &value) == TRUE)
2012                 vpn_provider_set_string(provider, key, value);
2013
2014         vpn_provider_save(provider);
2015
2016         err = provider_register(provider);
2017         if (err != 0 && err != -EALREADY)
2018                 goto fail;
2019
2020         connection_register(provider);
2021
2022         DBG("provider %p index %d path %s", provider, provider->index,
2023                                                         provider->path);
2024
2025         connection_added_signal(provider);
2026
2027         g_free(ident);
2028
2029         return 0;
2030
2031 fail:
2032         g_free(ident);
2033         g_slist_free_full(networks, free_route);
2034
2035         return err;
2036 }
2037
2038 static void append_connection_structs(DBusMessageIter *iter, void *user_data)
2039 {
2040         DBusMessageIter entry;
2041         GHashTableIter hash;
2042         gpointer value, key;
2043
2044         g_hash_table_iter_init(&hash, provider_hash);
2045
2046         while (g_hash_table_iter_next(&hash, &key, &value) == TRUE) {
2047                 struct vpn_provider *provider = value;
2048
2049                 DBG("path %s", provider->path);
2050
2051                 if (provider->identifier == NULL)
2052                         continue;
2053
2054                 dbus_message_iter_open_container(iter, DBUS_TYPE_STRUCT,
2055                                 NULL, &entry);
2056                 dbus_message_iter_append_basic(&entry, DBUS_TYPE_OBJECT_PATH,
2057                                 &provider->path);
2058                 append_properties(&entry, provider);
2059                 dbus_message_iter_close_container(iter, &entry);
2060         }
2061 }
2062
2063 DBusMessage *__vpn_provider_get_connections(DBusMessage *msg)
2064 {
2065         DBusMessage *reply;
2066
2067         DBG("");
2068
2069         reply = dbus_message_new_method_return(msg);
2070         if (reply == NULL)
2071                 return NULL;
2072
2073         __connman_dbus_append_objpath_dict_array(reply,
2074                         append_connection_structs, NULL);
2075
2076         return reply;
2077 }
2078
2079 const char * __vpn_provider_get_ident(struct vpn_provider *provider)
2080 {
2081         if (provider == NULL)
2082                 return NULL;
2083
2084         return provider->identifier;
2085 }
2086
2087 static int set_string(struct vpn_provider *provider,
2088                 const char *key, const char *value, gboolean hide_value)
2089 {
2090         DBG("provider %p key %s value %s", provider, key,
2091                 hide_value ? "<not printed>" : value);
2092
2093         if (g_str_equal(key, "Type") == TRUE) {
2094                 g_free(provider->type);
2095                 provider->type = g_ascii_strdown(value, -1);
2096                 send_value(provider->path, "Type", provider->type);
2097         } else if (g_str_equal(key, "Name") == TRUE) {
2098                 g_free(provider->name);
2099                 provider->name = g_strdup(value);
2100                 send_value(provider->path, "Name", provider->name);
2101         } else if (g_str_equal(key, "Host") == TRUE) {
2102                 g_free(provider->host);
2103                 provider->host = g_strdup(value);
2104                 send_value(provider->path, "Host", provider->host);
2105         } else if (g_str_equal(key, "VPN.Domain") == TRUE ||
2106                         g_str_equal(key, "Domain") == TRUE) {
2107                 g_free(provider->domain);
2108                 provider->domain = g_strdup(value);
2109                 send_value(provider->path, "Domain", provider->domain);
2110         } else {
2111                 struct vpn_setting *setting;
2112
2113                 setting = g_try_new(struct vpn_setting, 1);
2114                 if (setting == NULL)
2115                         return -ENOMEM;
2116
2117                 setting->value = g_strdup(value);
2118                 setting->hide_value = hide_value;
2119
2120                 if (hide_value == FALSE)
2121                         send_value(provider->path, key, setting->value);
2122
2123                 g_hash_table_replace(provider->setting_strings,
2124                                 g_strdup(key), setting);
2125         }
2126
2127         return 0;
2128 }
2129
2130 int vpn_provider_set_string(struct vpn_provider *provider,
2131                                         const char *key, const char *value)
2132 {
2133         return set_string(provider, key, value, FALSE);
2134 }
2135
2136 int vpn_provider_set_string_hide_value(struct vpn_provider *provider,
2137                                         const char *key, const char *value)
2138 {
2139         return set_string(provider, key, value, TRUE);
2140 }
2141
2142 const char *vpn_provider_get_string(struct vpn_provider *provider,
2143                                                         const char *key)
2144 {
2145         struct vpn_setting *setting;
2146
2147         DBG("provider %p key %s", provider, key);
2148
2149         if (g_str_equal(key, "Type") == TRUE)
2150                 return provider->type;
2151         else if (g_str_equal(key, "Name") == TRUE)
2152                 return provider->name;
2153         else if (g_str_equal(key, "Host") == TRUE)
2154                 return provider->host;
2155         else if (g_str_equal(key, "HostIP") == TRUE) {
2156                 if (provider->host_ip == NULL ||
2157                                 provider->host_ip[0] == NULL)
2158                         return provider->host;
2159                 else
2160                         return provider->host_ip[0];
2161         } else if (g_str_equal(key, "VPN.Domain") == TRUE ||
2162                         g_str_equal(key, "Domain") == TRUE)
2163                 return provider->domain;
2164
2165         setting = g_hash_table_lookup(provider->setting_strings, key);
2166         if (setting == NULL)
2167                 return NULL;
2168
2169         return setting->value;
2170 }
2171
2172 connman_bool_t __vpn_provider_check_routes(struct vpn_provider *provider)
2173 {
2174         if (provider == NULL)
2175                 return FALSE;
2176
2177         if (provider->user_routes != NULL &&
2178                         g_hash_table_size(provider->user_routes) > 0)
2179                 return TRUE;
2180
2181         if (provider->routes != NULL &&
2182                         g_hash_table_size(provider->routes) > 0)
2183                 return TRUE;
2184
2185         return FALSE;
2186 }
2187
2188 void *vpn_provider_get_data(struct vpn_provider *provider)
2189 {
2190         return provider->driver_data;
2191 }
2192
2193 void vpn_provider_set_data(struct vpn_provider *provider, void *data)
2194 {
2195         provider->driver_data = data;
2196 }
2197
2198 void vpn_provider_set_index(struct vpn_provider *provider, int index)
2199 {
2200         DBG("index %d provider %p", index, provider);
2201
2202         if (provider->ipconfig_ipv4 == NULL) {
2203                 provider->ipconfig_ipv4 = __vpn_ipconfig_create(index,
2204                                                                 AF_INET);
2205                 if (provider->ipconfig_ipv4 == NULL) {
2206                         DBG("Couldnt create ipconfig for IPv4");
2207                         goto done;
2208                 }
2209         }
2210
2211         __vpn_ipconfig_set_index(provider->ipconfig_ipv4, index);
2212
2213         if (provider->ipconfig_ipv6 == NULL) {
2214                 provider->ipconfig_ipv6 = __vpn_ipconfig_create(index,
2215                                                                 AF_INET6);
2216                 if (provider->ipconfig_ipv6 == NULL) {
2217                         DBG("Couldnt create ipconfig for IPv6");
2218                         goto done;
2219                 }
2220         }
2221
2222         __vpn_ipconfig_set_index(provider->ipconfig_ipv6, index);
2223
2224 done:
2225         provider->index = index;
2226 }
2227
2228 int vpn_provider_get_index(struct vpn_provider *provider)
2229 {
2230         return provider->index;
2231 }
2232
2233 int vpn_provider_set_ipaddress(struct vpn_provider *provider,
2234                                         struct connman_ipaddress *ipaddress)
2235 {
2236         struct vpn_ipconfig *ipconfig = NULL;
2237
2238         switch (ipaddress->family) {
2239         case AF_INET:
2240                 ipconfig = provider->ipconfig_ipv4;
2241                 break;
2242         case AF_INET6:
2243                 ipconfig = provider->ipconfig_ipv6;
2244                 break;
2245         default:
2246                 break;
2247         }
2248
2249         DBG("provider %p ipconfig %p family %d", provider, ipconfig,
2250                                                         ipaddress->family);
2251
2252         if (ipconfig == NULL)
2253                 return -EINVAL;
2254
2255         provider->family = ipaddress->family;
2256
2257         __vpn_ipconfig_set_local(ipconfig, ipaddress->local);
2258         __vpn_ipconfig_set_peer(ipconfig, ipaddress->peer);
2259         __vpn_ipconfig_set_broadcast(ipconfig, ipaddress->broadcast);
2260         __vpn_ipconfig_set_gateway(ipconfig, ipaddress->gateway);
2261         __vpn_ipconfig_set_prefixlen(ipconfig, ipaddress->prefixlen);
2262
2263         return 0;
2264 }
2265
2266 int vpn_provider_set_pac(struct vpn_provider *provider,
2267                                 const char *pac)
2268 {
2269         DBG("provider %p pac %s", provider, pac);
2270
2271         return 0;
2272 }
2273
2274
2275 int vpn_provider_set_domain(struct vpn_provider *provider,
2276                                         const char *domain)
2277 {
2278         DBG("provider %p domain %s", provider, domain);
2279
2280         g_free(provider->domain);
2281         provider->domain = g_strdup(domain);
2282
2283         return 0;
2284 }
2285
2286 int vpn_provider_set_nameservers(struct vpn_provider *provider,
2287                                         const char *nameservers)
2288 {
2289         DBG("provider %p nameservers %s", provider, nameservers);
2290
2291         g_strfreev(provider->nameservers);
2292         provider->nameservers = NULL;
2293
2294         if (nameservers == NULL)
2295                 return 0;
2296
2297         provider->nameservers = g_strsplit(nameservers, " ", 0);
2298
2299         return 0;
2300 }
2301
2302 enum provider_route_type {
2303         PROVIDER_ROUTE_TYPE_NONE = 0,
2304         PROVIDER_ROUTE_TYPE_MASK = 1,
2305         PROVIDER_ROUTE_TYPE_ADDR = 2,
2306         PROVIDER_ROUTE_TYPE_GW   = 3,
2307 };
2308
2309 static int route_env_parse(struct vpn_provider *provider, const char *key,
2310                                 int *family, unsigned long *idx,
2311                                 enum provider_route_type *type)
2312 {
2313         char *end;
2314         const char *start;
2315
2316         DBG("name %s", provider->name);
2317
2318         if (!strcmp(provider->type, "openvpn")) {
2319                 if (g_str_has_prefix(key, "route_network_") == TRUE) {
2320                         start = key + strlen("route_network_");
2321                         *type = PROVIDER_ROUTE_TYPE_ADDR;
2322                 } else if (g_str_has_prefix(key, "route_netmask_") == TRUE) {
2323                         start = key + strlen("route_netmask_");
2324                         *type = PROVIDER_ROUTE_TYPE_MASK;
2325                 } else if (g_str_has_prefix(key, "route_gateway_") == TRUE) {
2326                         start = key + strlen("route_gateway_");
2327                         *type = PROVIDER_ROUTE_TYPE_GW;
2328                 } else
2329                         return -EINVAL;
2330
2331                 *family = AF_INET;
2332                 *idx = g_ascii_strtoull(start, &end, 10);
2333
2334         } else if (!strcmp(provider->type, "openconnect")) {
2335                 if (g_str_has_prefix(key, "CISCO_SPLIT_INC_") == TRUE) {
2336                         *family = AF_INET;
2337                         start = key + strlen("CISCO_SPLIT_INC_");
2338                 } else if (g_str_has_prefix(key,
2339                                         "CISCO_IPV6_SPLIT_INC_") == TRUE) {
2340                         *family = AF_INET6;
2341                         start = key + strlen("CISCO_IPV6_SPLIT_INC_");
2342                 } else
2343                         return -EINVAL;
2344
2345                 *idx = g_ascii_strtoull(start, &end, 10);
2346
2347                 if (strncmp(end, "_ADDR", 5) == 0)
2348                         *type = PROVIDER_ROUTE_TYPE_ADDR;
2349                 else if (strncmp(end, "_MASK", 5) == 0)
2350                         *type = PROVIDER_ROUTE_TYPE_MASK;
2351                 else if (strncmp(end, "_MASKLEN", 8) == 0 &&
2352                                 *family == AF_INET6) {
2353                         *type = PROVIDER_ROUTE_TYPE_MASK;
2354                 } else
2355                         return -EINVAL;
2356         }
2357
2358         return 0;
2359 }
2360
2361 int vpn_provider_append_route(struct vpn_provider *provider,
2362                                         const char *key, const char *value)
2363 {
2364         struct vpn_route *route;
2365         int ret, family = 0;
2366         unsigned long idx = 0;
2367         enum provider_route_type type = PROVIDER_ROUTE_TYPE_NONE;
2368
2369         DBG("key %s value %s", key, value);
2370
2371         ret = route_env_parse(provider, key, &family, &idx, &type);
2372         if (ret < 0)
2373                 return ret;
2374
2375         DBG("idx %lu family %d type %d", idx, family, type);
2376
2377         route = g_hash_table_lookup(provider->routes, GINT_TO_POINTER(idx));
2378         if (route == NULL) {
2379                 route = g_try_new0(struct vpn_route, 1);
2380                 if (route == NULL) {
2381                         connman_error("out of memory");
2382                         return -ENOMEM;
2383                 }
2384
2385                 route->family = family;
2386
2387                 g_hash_table_replace(provider->routes, GINT_TO_POINTER(idx),
2388                                                 route);
2389         }
2390
2391         switch (type) {
2392         case PROVIDER_ROUTE_TYPE_NONE:
2393                 break;
2394         case PROVIDER_ROUTE_TYPE_MASK:
2395                 route->netmask = g_strdup(value);
2396                 break;
2397         case PROVIDER_ROUTE_TYPE_ADDR:
2398                 route->network = g_strdup(value);
2399                 break;
2400         case PROVIDER_ROUTE_TYPE_GW:
2401                 route->gateway = g_strdup(value);
2402                 break;
2403         }
2404
2405         if (handle_routes == FALSE) {
2406                 if (route->netmask != NULL && route->gateway != NULL &&
2407                                                         route->network != NULL)
2408                         provider_schedule_changed(provider);
2409         }
2410
2411         return 0;
2412 }
2413
2414 const char *vpn_provider_get_driver_name(struct vpn_provider *provider)
2415 {
2416         if (provider->driver == NULL)
2417                 return NULL;
2418
2419         return provider->driver->name;
2420 }
2421
2422 const char *vpn_provider_get_save_group(struct vpn_provider *provider)
2423 {
2424         return provider->identifier;
2425 }
2426
2427 static gint compare_priority(gconstpointer a, gconstpointer b)
2428 {
2429         return 0;
2430 }
2431
2432 static void clean_provider(gpointer key, gpointer value, gpointer user_data)
2433 {
2434         struct vpn_provider *provider = value;
2435
2436         if (provider->driver != NULL && provider->driver->remove)
2437                 provider->driver->remove(provider);
2438
2439         connection_unregister(provider);
2440 }
2441
2442 int vpn_provider_driver_register(struct vpn_provider_driver *driver)
2443 {
2444         DBG("driver %p name %s", driver, driver->name);
2445
2446         driver_list = g_slist_insert_sorted(driver_list, driver,
2447                                                         compare_priority);
2448         provider_create_all_from_type(driver->name);
2449         return 0;
2450 }
2451
2452 void vpn_provider_driver_unregister(struct vpn_provider_driver *driver)
2453 {
2454         GHashTableIter iter;
2455         gpointer value, key;
2456
2457         DBG("driver %p name %s", driver, driver->name);
2458
2459         driver_list = g_slist_remove(driver_list, driver);
2460
2461         g_hash_table_iter_init(&iter, provider_hash);
2462         while (g_hash_table_iter_next(&iter, &key, &value) == TRUE) {
2463                 struct vpn_provider *provider = value;
2464
2465                 if (provider != NULL && provider->driver != NULL &&
2466                                 provider->driver->type == driver->type &&
2467                                 g_strcmp0(provider->driver->name,
2468                                                         driver->name) == 0) {
2469                         provider->driver = NULL;
2470                 }
2471         }
2472 }
2473
2474 static gboolean check_vpn_count(gpointer data)
2475 {
2476         if (configuration_count == 0) {
2477                 connman_info("No VPN configurations found, quitting.");
2478                 raise(SIGTERM);
2479         }
2480
2481         return FALSE;
2482 }
2483
2484 void __vpn_provider_check_connections(void)
2485 {
2486         /*
2487          * If we were started when there is no providers configured,
2488          * then just quit. This happens when connman starts and its
2489          * vpn plugin asks connman-vpnd if it has any connections
2490          * configured. If there are none, then we can stop the vpn
2491          * daemon.
2492          */
2493         g_timeout_add(1000, check_vpn_count, NULL);
2494 }
2495
2496 const char *vpn_provider_get_name(struct vpn_provider *provider)
2497 {
2498         return provider->name;
2499 }
2500
2501 const char *vpn_provider_get_host(struct vpn_provider *provider)
2502 {
2503         return provider->host;
2504 }
2505
2506 const char *vpn_provider_get_path(struct vpn_provider *provider)
2507 {
2508         return provider->path;
2509 }
2510
2511 static int agent_probe(struct connman_agent *agent)
2512 {
2513         DBG("agent %p", agent);
2514         return 0;
2515 }
2516
2517 static void agent_remove(struct connman_agent *agent)
2518 {
2519         DBG("agent %p", agent);
2520 }
2521
2522 static struct connman_agent_driver agent_driver = {
2523         .name           = "vpn",
2524         .interface      = VPN_AGENT_INTERFACE,
2525         .probe          = agent_probe,
2526         .remove         = agent_remove,
2527 };
2528
2529 static void remove_unprovisioned_providers()
2530 {
2531         gchar **providers;
2532         GKeyFile *keyfile, *configkeyfile;
2533         char *file, *section;
2534         int i = 0;
2535
2536         providers = __connman_storage_get_providers();
2537         if (providers == NULL)
2538                 return;
2539
2540         for (; providers[i] != NULL; i++) {
2541                 char *group = providers[i] + sizeof("provider_") - 1;
2542                 file = section = NULL;
2543                 keyfile = configkeyfile = NULL;
2544
2545                 keyfile = __connman_storage_load_provider(group);
2546                 if (keyfile == NULL)
2547                         continue;
2548
2549                 file = g_key_file_get_string(keyfile, group,
2550                                         "Config.file", NULL);
2551                 if (file == NULL)
2552                         goto next;
2553
2554                 section = g_key_file_get_string(keyfile, group,
2555                                         "Config.ident", NULL);
2556                 if (section == NULL)
2557                         goto next;
2558
2559                 configkeyfile = __connman_storage_load_provider_config(file);
2560                 if (configkeyfile == NULL) {
2561                         /*
2562                          * Config file is missing, remove the provisioned
2563                          * service.
2564                          */
2565                         __connman_storage_remove_provider(group);
2566                         goto next;
2567                 }
2568
2569                 if (g_key_file_has_group(configkeyfile, section) == FALSE)
2570                         /*
2571                          * Config section is missing, remove the provisioned
2572                          * service.
2573                          */
2574                         __connman_storage_remove_provider(group);
2575
2576         next:
2577                 if (keyfile != NULL)
2578                         g_key_file_free(keyfile);
2579
2580                 if (configkeyfile != NULL)
2581                         g_key_file_free(configkeyfile);
2582
2583                 g_free(section);
2584                 g_free(file);
2585         }
2586
2587         g_strfreev(providers);
2588 }
2589
2590 int __vpn_provider_init(gboolean do_routes)
2591 {
2592         int err;
2593
2594         DBG("");
2595
2596         handle_routes = do_routes;
2597
2598         err = connman_agent_driver_register(&agent_driver);
2599         if (err < 0) {
2600                 connman_error("Cannot register agent driver for %s",
2601                                                 agent_driver.name);
2602                 return err;
2603         }
2604
2605         connection = connman_dbus_get_connection();
2606
2607         remove_unprovisioned_providers();
2608
2609         provider_hash = g_hash_table_new_full(g_str_hash, g_str_equal,
2610                                                 NULL, unregister_provider);
2611         return 0;
2612 }
2613
2614 void __vpn_provider_cleanup(void)
2615 {
2616         DBG("");
2617
2618         g_hash_table_foreach(provider_hash, clean_provider, NULL);
2619
2620         g_hash_table_destroy(provider_hash);
2621         provider_hash = NULL;
2622
2623         connman_agent_driver_unregister(&agent_driver);
2624
2625         dbus_connection_unref(connection);
2626 }