vpn-provider: Set the state to FAILURE after auth error
[platform/upstream/connman.git] / vpn / vpn-provider.c
1 /*
2  *
3  *  ConnMan VPN daemon
4  *
5  *  Copyright (C) 2012  Intel Corporation. All rights reserved.
6  *
7  *  This program is free software; you can redistribute it and/or modify
8  *  it under the terms of the GNU General Public License version 2 as
9  *  published by the Free Software Foundation.
10  *
11  *  This program is distributed in the hope that it will be useful,
12  *  but WITHOUT ANY WARRANTY; without even the implied warranty of
13  *  MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
14  *  GNU General Public License for more details.
15  *
16  *  You should have received a copy of the GNU General Public License
17  *  along with this program; if not, write to the Free Software
18  *  Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA  02110-1301  USA
19  *
20  */
21
22 #ifdef HAVE_CONFIG_H
23 #include <config.h>
24 #endif
25
26 #include <errno.h>
27 #include <stdio.h>
28 #include <string.h>
29 #include <stdlib.h>
30 #include <gdbus.h>
31 #include <connman/log.h>
32 #include <gweb/gresolv.h>
33 #include <netdb.h>
34
35 #include "../src/connman.h"
36 #include "connman/agent.h"
37 #include "connman/vpn-dbus.h"
38 #include "vpn-provider.h"
39 #include "vpn.h"
40
41 enum {
42         USER_ROUTES_CHANGED = 0x01,
43         SERVER_ROUTES_CHANGED = 0x02,
44 };
45
46 static DBusConnection *connection;
47 static GHashTable *provider_hash;
48 static GSList *driver_list;
49 static int configuration_count;
50 static gboolean handle_routes;
51
52 struct vpn_route {
53         int family;
54         char *network;
55         char *netmask;
56         char *gateway;
57 };
58
59 struct vpn_provider {
60         int refcount;
61         int index;
62         int fd;
63         enum vpn_provider_state state;
64         char *path;
65         char *identifier;
66         char *name;
67         char *type;
68         char *host;
69         char *domain;
70         int family;
71         GHashTable *routes;
72         struct vpn_provider_driver *driver;
73         void *driver_data;
74         GHashTable *setting_strings;
75         GHashTable *user_routes;
76         GSList *user_networks;
77         GResolv *resolv;
78         char **host_ip;
79         struct vpn_ipconfig *ipconfig_ipv4;
80         struct vpn_ipconfig *ipconfig_ipv6;
81         char **nameservers;
82         int what_changed;
83         guint notify_id;
84         char *config_file;
85         char *config_entry;
86 };
87
88 static void free_route(gpointer data)
89 {
90         struct vpn_route *route = data;
91
92         g_free(route->network);
93         g_free(route->netmask);
94         g_free(route->gateway);
95
96         g_free(route);
97 }
98
99 static void append_route(DBusMessageIter *iter, void *user_data)
100 {
101         struct vpn_route *route = user_data;
102         DBusMessageIter item;
103         int family = 0;
104
105         connman_dbus_dict_open(iter, &item);
106
107         if (route == NULL)
108                 goto empty_dict;
109
110         if (route->family == AF_INET)
111                 family = 4;
112         else if (route->family == AF_INET6)
113                 family = 6;
114
115         if (family != 0)
116                 connman_dbus_dict_append_basic(&item, "ProtocolFamily",
117                                         DBUS_TYPE_INT32, &family);
118
119         if (route->network != NULL)
120                 connman_dbus_dict_append_basic(&item, "Network",
121                                         DBUS_TYPE_STRING, &route->network);
122
123         if (route->netmask != NULL)
124                 connman_dbus_dict_append_basic(&item, "Netmask",
125                                         DBUS_TYPE_STRING, &route->netmask);
126
127         if (route->gateway != NULL)
128                 connman_dbus_dict_append_basic(&item, "Gateway",
129                                         DBUS_TYPE_STRING, &route->gateway);
130
131 empty_dict:
132         connman_dbus_dict_close(iter, &item);
133 }
134
135 static void append_routes(DBusMessageIter *iter, void *user_data)
136 {
137         GHashTable *routes = user_data;
138         GHashTableIter hash;
139         gpointer value, key;
140
141         if (routes == NULL) {
142                 append_route(iter, NULL);
143                 return;
144         }
145
146         g_hash_table_iter_init(&hash, routes);
147
148         while (g_hash_table_iter_next(&hash, &key, &value) == TRUE) {
149                 DBusMessageIter dict;
150
151                 dbus_message_iter_open_container(iter, DBUS_TYPE_STRUCT, NULL,
152                                                 &dict);
153                 append_route(&dict, value);
154                 dbus_message_iter_close_container(iter, &dict);
155         }
156 }
157
158 static void send_routes(struct vpn_provider *provider, GHashTable *routes,
159                         const char *name)
160 {
161         connman_dbus_property_changed_array(provider->path,
162                                         VPN_CONNECTION_INTERFACE,
163                                         name,
164                                         DBUS_TYPE_DICT_ENTRY,
165                                         append_routes,
166                                         routes);
167 }
168
169 static int provider_property_changed(struct vpn_provider *provider,
170                                 const char *name)
171 {
172         DBG("provider %p name %s", provider, name);
173
174         if (g_str_equal(name, "UserRoutes") == TRUE)
175                 send_routes(provider, provider->user_routes, name);
176         else if (g_str_equal(name, "ServerRoutes") == TRUE)
177                 send_routes(provider, provider->routes, name);
178
179         return 0;
180 }
181
182 static GSList *read_route_dict(GSList *routes, DBusMessageIter *dicts)
183 {
184         DBusMessageIter dict, value, entry;
185         const char *network, *netmask, *gateway;
186         struct vpn_route *route;
187         int family, type;
188         const char *key;
189
190         dbus_message_iter_recurse(dicts, &entry);
191
192         network = netmask = gateway = NULL;
193         family = PF_UNSPEC;
194
195         while (dbus_message_iter_get_arg_type(&entry) == DBUS_TYPE_DICT_ENTRY) {
196
197                 dbus_message_iter_recurse(&entry, &dict);
198                 dbus_message_iter_get_basic(&dict, &key);
199
200                 dbus_message_iter_next(&dict);
201                 dbus_message_iter_recurse(&dict, &value);
202
203                 type = dbus_message_iter_get_arg_type(&value);
204
205                 switch (type) {
206                 case DBUS_TYPE_STRING:
207                         if (g_str_equal(key, "ProtocolFamily") == TRUE)
208                                 dbus_message_iter_get_basic(&value, &family);
209                         else if (g_str_equal(key, "Network") == TRUE)
210                                 dbus_message_iter_get_basic(&value, &network);
211                         else if (g_str_equal(key, "Netmask") == TRUE)
212                                 dbus_message_iter_get_basic(&value, &netmask);
213                         else if (g_str_equal(key, "Gateway") == TRUE)
214                                 dbus_message_iter_get_basic(&value, &gateway);
215                         break;
216                 }
217
218                 dbus_message_iter_next(&entry);
219         }
220
221         DBG("family %d network %s netmask %s gateway %s", family,
222                 network, netmask, gateway);
223
224         if (network == NULL || netmask == NULL) {
225                 DBG("Ignoring route as network/netmask is missing");
226                 return routes;
227         }
228
229         route = g_try_new(struct vpn_route, 1);
230         if (route == NULL) {
231                 g_slist_free_full(routes, free_route);
232                 return NULL;
233         }
234
235         if (family == PF_UNSPEC) {
236                 family = connman_inet_check_ipaddress(network);
237                 if (family < 0) {
238                         DBG("Cannot get address family of %s (%d/%s)", network,
239                                 family, gai_strerror(family));
240
241                         g_free(route);
242                         return routes;
243                 }
244         } else {
245                 switch (family) {
246                 case '4':
247                         family = AF_INET;
248                         break;
249                 case '6':
250                         family = AF_INET6;
251                         break;
252                 default:
253                         family = PF_UNSPEC;
254                         break;
255                 }
256         }
257
258         route->family = family;
259         route->network = g_strdup(network);
260         route->netmask = g_strdup(netmask);
261         route->gateway = g_strdup(gateway);
262
263         routes = g_slist_prepend(routes, route);
264         return routes;
265 }
266
267 static GSList *get_user_networks(DBusMessageIter *array)
268 {
269         DBusMessageIter entry;
270         GSList *list = NULL;
271
272         while (dbus_message_iter_get_arg_type(array) == DBUS_TYPE_ARRAY) {
273
274                 dbus_message_iter_recurse(array, &entry);
275
276                 while (dbus_message_iter_get_arg_type(&entry) ==
277                                                         DBUS_TYPE_STRUCT) {
278                         DBusMessageIter dicts;
279
280                         dbus_message_iter_recurse(&entry, &dicts);
281
282                         while (dbus_message_iter_get_arg_type(&dicts) ==
283                                                         DBUS_TYPE_ARRAY) {
284
285                                 list = read_route_dict(list, &dicts);
286                                 dbus_message_iter_next(&dicts);
287                         }
288
289                         dbus_message_iter_next(&entry);
290                 }
291
292                 dbus_message_iter_next(array);
293         }
294
295         return list;
296 }
297
298 static void set_user_networks(struct vpn_provider *provider, GSList *networks)
299 {
300         GSList *list;
301
302         for (list = networks; list != NULL; list = g_slist_next(list)) {
303                 struct vpn_route *route = list->data;
304
305                 if (__vpn_provider_append_user_route(provider,
306                                         route->family, route->network,
307                                         route->netmask, route->gateway) != 0)
308                         break;
309         }
310 }
311
312 static void del_routes(struct vpn_provider *provider)
313 {
314         GHashTableIter hash;
315         gpointer value, key;
316
317         g_hash_table_iter_init(&hash, provider->user_routes);
318         while (handle_routes == TRUE && g_hash_table_iter_next(&hash,
319                                                 &key, &value) == TRUE) {
320                 struct vpn_route *route = value;
321                 if (route->family == AF_INET6) {
322                         unsigned char prefixlen = atoi(route->netmask);
323                         connman_inet_del_ipv6_network_route(provider->index,
324                                                         route->network,
325                                                         prefixlen);
326                 } else
327                         connman_inet_del_host_route(provider->index,
328                                                 route->network);
329         }
330
331         g_hash_table_remove_all(provider->user_routes);
332         g_slist_free_full(provider->user_networks, free_route);
333         provider->user_networks = NULL;
334 }
335
336 static gboolean provider_send_changed(gpointer data)
337 {
338         struct vpn_provider *provider = data;
339
340         if (provider->what_changed & USER_ROUTES_CHANGED)
341                 provider_property_changed(provider, "UserRoutes");
342
343         if (provider->what_changed & SERVER_ROUTES_CHANGED)
344                 provider_property_changed(provider, "ServerRoutes");
345
346         provider->what_changed = 0;
347         provider->notify_id = 0;
348
349         return FALSE;
350 }
351
352 static void provider_schedule_changed(struct vpn_provider *provider, int flag)
353 {
354         if (provider->notify_id != 0)
355                 g_source_remove(provider->notify_id);
356
357         provider->what_changed |= flag;
358
359         provider->notify_id = g_timeout_add(100, provider_send_changed,
360                                                                 provider);
361 }
362
363 static DBusMessage *set_property(DBusConnection *conn, DBusMessage *msg,
364                                                                 void *data)
365 {
366         struct vpn_provider *provider = data;
367         DBusMessageIter iter, value;
368         const char *name;
369         int type;
370
371         DBG("conn %p", conn);
372
373         if (dbus_message_iter_init(msg, &iter) == FALSE)
374                 return __connman_error_invalid_arguments(msg);
375
376         if (dbus_message_iter_get_arg_type(&iter) != DBUS_TYPE_STRING)
377                 return __connman_error_invalid_arguments(msg);
378
379         dbus_message_iter_get_basic(&iter, &name);
380         dbus_message_iter_next(&iter);
381
382         if (dbus_message_iter_get_arg_type(&iter) != DBUS_TYPE_VARIANT)
383                 return __connman_error_invalid_arguments(msg);
384
385         dbus_message_iter_recurse(&iter, &value);
386
387         type = dbus_message_iter_get_arg_type(&value);
388
389         if (g_str_equal(name, "UserRoutes") == TRUE) {
390                 GSList *networks;
391
392                 if (type != DBUS_TYPE_ARRAY)
393                         return __connman_error_invalid_arguments(msg);
394
395                 networks = get_user_networks(&value);
396                 if (networks != NULL) {
397                         del_routes(provider);
398                         provider->user_networks = networks;
399                         set_user_networks(provider, provider->user_networks);
400
401                         if (handle_routes == FALSE)
402                                 provider_schedule_changed(provider,
403                                                         USER_ROUTES_CHANGED);
404                 }
405         } else
406                 return __connman_error_invalid_property(msg);
407
408         return g_dbus_create_reply(msg, DBUS_TYPE_INVALID);
409 }
410
411 static DBusMessage *clear_property(DBusConnection *conn, DBusMessage *msg,
412                                                                 void *data)
413 {
414         struct vpn_provider *provider = data;
415         const char *name;
416
417         DBG("conn %p", conn);
418
419         dbus_message_get_args(msg, NULL, DBUS_TYPE_STRING, &name,
420                                                         DBUS_TYPE_INVALID);
421
422         if (g_str_equal(name, "UserRoutes") == TRUE) {
423                 del_routes(provider);
424
425                 if (handle_routes == FALSE)
426                         provider_property_changed(provider, name);
427         } else {
428                 return __connman_error_invalid_property(msg);
429         }
430
431         return g_dbus_create_reply(msg, DBUS_TYPE_INVALID);
432 }
433
434 static DBusMessage *do_connect(DBusConnection *conn, DBusMessage *msg,
435                                                                 void *data)
436 {
437         struct vpn_provider *provider = data;
438         int err;
439
440         DBG("conn %p provider %p", conn, provider);
441
442         err = __vpn_provider_connect(provider, msg);
443         if (err < 0)
444                 return __connman_error_failed(msg, -err);
445
446         return NULL;
447 }
448
449 static DBusMessage *do_disconnect(DBusConnection *conn, DBusMessage *msg,
450                                                                 void *data)
451 {
452         struct vpn_provider *provider = data;
453         int err;
454
455         DBG("conn %p provider %p", conn, provider);
456
457         err = __vpn_provider_disconnect(provider);
458         if (err < 0 && err != -EINPROGRESS)
459                 return __connman_error_failed(msg, -err);
460
461         return g_dbus_create_reply(msg, DBUS_TYPE_INVALID);
462 }
463
464 static const GDBusMethodTable connection_methods[] = {
465         { GDBUS_METHOD("SetProperty",
466                         GDBUS_ARGS({ "name", "s" }, { "value", "v" }),
467                         NULL, set_property) },
468         { GDBUS_METHOD("ClearProperty",
469                         GDBUS_ARGS({ "name", "s" }), NULL,
470                         clear_property) },
471         { GDBUS_ASYNC_METHOD("Connect", NULL, NULL, do_connect) },
472         { GDBUS_METHOD("Disconnect", NULL, NULL, do_disconnect) },
473         { },
474 };
475
476 static const GDBusSignalTable connection_signals[] = {
477         { GDBUS_SIGNAL("PropertyChanged",
478                         GDBUS_ARGS({ "name", "s" }, { "value", "v" })) },
479         { },
480 };
481
482 static void resolv_result(GResolvResultStatus status,
483                                         char **results, gpointer user_data)
484 {
485         struct vpn_provider *provider = user_data;
486
487         DBG("status %d", status);
488
489         if (status == G_RESOLV_RESULT_STATUS_SUCCESS && results != NULL &&
490                                                 g_strv_length(results) > 0)
491                 provider->host_ip = g_strdupv(results);
492
493         vpn_provider_unref(provider);
494 }
495
496 static void provider_resolv_host_addr(struct vpn_provider *provider)
497 {
498         if (provider->host == NULL)
499                 return;
500
501         if (connman_inet_check_ipaddress(provider->host) > 0)
502                 return;
503
504         if (provider->host_ip != NULL)
505                 return;
506
507         /*
508          * If the hostname is not numeric, try to resolv it. We do not wait
509          * the result as it might take some time. We will get the result
510          * before VPN will feed routes to us because VPN client will need
511          * the IP address also before VPN connection can be established.
512          */
513         provider->resolv = g_resolv_new(0);
514         if (provider->resolv == NULL) {
515                 DBG("Cannot resolv %s", provider->host);
516                 return;
517         }
518
519         DBG("Trying to resolv %s", provider->host);
520
521         vpn_provider_ref(provider);
522
523         g_resolv_lookup_hostname(provider->resolv, provider->host,
524                                 resolv_result, provider);
525 }
526
527 void __vpn_provider_append_properties(struct vpn_provider *provider,
528                                                         DBusMessageIter *iter)
529 {
530         if (provider->host != NULL)
531                 connman_dbus_dict_append_basic(iter, "Host",
532                                         DBUS_TYPE_STRING, &provider->host);
533
534         if (provider->domain != NULL)
535                 connman_dbus_dict_append_basic(iter, "Domain",
536                                         DBUS_TYPE_STRING, &provider->domain);
537
538         if (provider->type != NULL)
539                 connman_dbus_dict_append_basic(iter, "Type", DBUS_TYPE_STRING,
540                                                  &provider->type);
541 }
542
543 int __vpn_provider_append_user_route(struct vpn_provider *provider,
544                                 int family, const char *network,
545                                 const char *netmask, const char *gateway)
546 {
547         struct vpn_route *route;
548         char *key = g_strdup_printf("%d/%s/%s/%s", family, network,
549                                 netmask, gateway != NULL ? gateway : "");
550
551         DBG("family %d network %s netmask %s gw %s", family, network,
552                                                         netmask, gateway);
553
554         route = g_hash_table_lookup(provider->user_routes, key);
555         if (route == NULL) {
556                 route = g_try_new0(struct vpn_route, 1);
557                 if (route == NULL) {
558                         connman_error("out of memory");
559                         return -ENOMEM;
560                 }
561
562                 route->family = family;
563                 route->network = g_strdup(network);
564                 route->netmask = g_strdup(netmask);
565                 route->gateway = g_strdup(gateway);
566
567                 g_hash_table_replace(provider->user_routes, key, route);
568         } else
569                 g_free(key);
570
571         return 0;
572 }
573
574 static struct vpn_route *get_route(char *route_str)
575 {
576         char **elems = g_strsplit(route_str, "/", 0);
577         char *network, *netmask, *gateway, *family_str;
578         int family = PF_UNSPEC;
579         struct vpn_route *route = NULL;
580
581         if (elems == NULL)
582                 return NULL;
583
584         family_str = elems[0];
585
586         network = elems[1];
587         if (network == NULL || network[0] == '\0')
588                 goto out;
589
590         netmask = elems[2];
591         if (netmask == NULL || netmask[0] == '\0')
592                 goto out;
593
594         gateway = elems[3];
595
596         route = g_try_new0(struct vpn_route, 1);
597         if (route == NULL)
598                 goto out;
599
600         if (family_str[0] == '\0' || atoi(family_str) == 0) {
601                 family = PF_UNSPEC;
602         } else {
603                 switch (family_str[0]) {
604                 case '4':
605                         family = AF_INET;
606                         break;
607                 case '6':
608                         family = AF_INET6;
609                         break;
610                 }
611         }
612
613         if (g_strrstr(network, ":") != NULL) {
614                 if (family != PF_UNSPEC && family != AF_INET6)
615                         DBG("You have IPv6 address but you have non IPv6 route");
616         } else if (g_strrstr(network, ".") != NULL) {
617                 if (family != PF_UNSPEC && family != AF_INET)
618                         DBG("You have IPv4 address but you have non IPv4 route");
619
620                 if (g_strrstr(netmask, ".") == NULL) {
621                         /* We have netmask length */
622                         in_addr_t addr;
623                         struct in_addr netmask_in;
624                         unsigned char prefix_len = 32;
625
626                         if (netmask != NULL) {
627                                 char *ptr;
628                                 long int value = strtol(netmask, &ptr, 10);
629                                 if (ptr != netmask && *ptr == '\0' &&
630                                                                 value <= 32)
631                                         prefix_len = value;
632                         }
633
634                         addr = 0xffffffff << (32 - prefix_len);
635                         netmask_in.s_addr = htonl(addr);
636                         netmask = inet_ntoa(netmask_in);
637
638                         DBG("network %s netmask %s", network, netmask);
639                 }
640         }
641
642         if (family == PF_UNSPEC) {
643                 family = connman_inet_check_ipaddress(network);
644                 if (family < 0 || family == PF_UNSPEC)
645                         goto out;
646         }
647
648         route->family = family;
649         route->network = g_strdup(network);
650         route->netmask = g_strdup(netmask);
651         route->gateway = g_strdup(gateway);
652
653 out:
654         g_strfreev(elems);
655         return route;
656 }
657
658 static GSList *get_routes(gchar **networks)
659 {
660         struct vpn_route *route;
661         GSList *routes = NULL;
662         int i;
663
664         for (i = 0; networks[i] != NULL; i++) {
665                 route = get_route(networks[i]);
666                 if (route != NULL)
667                         routes = g_slist_prepend(routes, route);
668         }
669
670         return routes;
671 }
672
673 static int provider_load_from_keyfile(struct vpn_provider *provider,
674                 GKeyFile *keyfile)
675 {
676         gsize idx = 0;
677         gchar **settings;
678         gchar *key, *value;
679         gsize length, num_user_networks;
680         gchar **networks = NULL;
681
682         settings = g_key_file_get_keys(keyfile, provider->identifier, &length,
683                                 NULL);
684         if (settings == NULL) {
685                 g_key_file_free(keyfile);
686                 return -ENOENT;
687         }
688
689         while (idx < length) {
690                 key = settings[idx];
691                 if (key != NULL) {
692                         if (g_str_equal(key, "Networks") == TRUE) {
693                                 networks = g_key_file_get_string_list(keyfile,
694                                                 provider->identifier,
695                                                 key,
696                                                 &num_user_networks,
697                                                 NULL);
698                                 provider->user_networks = get_routes(networks);
699
700                         } else {
701                                 value = g_key_file_get_string(keyfile,
702                                                         provider->identifier,
703                                                         key, NULL);
704                                 vpn_provider_set_string(provider, key,
705                                                         value);
706                                 g_free(value);
707                         }
708                 }
709                 idx += 1;
710         }
711         g_strfreev(settings);
712         g_strfreev(networks);
713
714         if (provider->user_networks != NULL)
715                 set_user_networks(provider, provider->user_networks);
716
717         return 0;
718 }
719
720
721 static int vpn_provider_load(struct vpn_provider *provider)
722 {
723         GKeyFile *keyfile;
724
725         DBG("provider %p", provider);
726
727         keyfile = __connman_storage_load_provider(provider->identifier);
728         if (keyfile == NULL)
729                 return -ENOENT;
730
731         provider_load_from_keyfile(provider, keyfile);
732
733         g_key_file_free(keyfile);
734         return 0;
735 }
736
737 static gchar **create_network_list(GSList *networks, gsize *count)
738 {
739         GSList *list;
740         gchar **result = NULL;
741         unsigned int num_elems = 0;
742
743         for (list = networks; list != NULL; list = g_slist_next(list)) {
744                 struct vpn_route *route = list->data;
745                 int family;
746
747                 result = g_try_realloc(result,
748                                 (num_elems + 1) * sizeof(gchar *));
749                 if (result == NULL)
750                         return NULL;
751
752                 switch (route->family) {
753                 case AF_INET:
754                         family = 4;
755                         break;
756                 case AF_INET6:
757                         family = 6;
758                         break;
759                 default:
760                         family = 0;
761                         break;
762                 }
763
764                 result[num_elems] = g_strdup_printf("%d/%s/%s/%s",
765                                 family, route->network, route->netmask,
766                                 route->gateway == NULL ? "" : route->gateway);
767
768                 num_elems++;
769         }
770
771         result = g_try_realloc(result, (num_elems + 1) * sizeof(gchar *));
772         if (result == NULL)
773                 return NULL;
774
775         result[num_elems] = NULL;
776         *count = num_elems;
777         return result;
778 }
779
780 static int vpn_provider_save(struct vpn_provider *provider)
781 {
782         GKeyFile *keyfile;
783
784         DBG("provider %p", provider);
785
786         keyfile = g_key_file_new();
787         if (keyfile == NULL)
788                 return -ENOMEM;
789
790         g_key_file_set_string(keyfile, provider->identifier,
791                         "Name", provider->name);
792         g_key_file_set_string(keyfile, provider->identifier,
793                         "Type", provider->type);
794         g_key_file_set_string(keyfile, provider->identifier,
795                         "Host", provider->host);
796         g_key_file_set_string(keyfile, provider->identifier,
797                         "VPN.Domain", provider->domain);
798         if (provider->user_networks != NULL) {
799                 gchar **networks;
800                 gsize network_count;
801
802                 networks = create_network_list(provider->user_networks,
803                                                         &network_count);
804                 if (networks != NULL) {
805                         g_key_file_set_string_list(keyfile,
806                                                 provider->identifier,
807                                                 "Networks",
808                                                 (const gchar ** const)networks,
809                                                 network_count);
810                         g_strfreev(networks);
811                 }
812         }
813
814         if (provider->config_file != NULL && strlen(provider->config_file) > 0)
815                 g_key_file_set_string(keyfile, provider->identifier,
816                                 "Config.file", provider->config_file);
817
818         if (provider->config_entry != NULL &&
819                                         strlen(provider->config_entry) > 0)
820                 g_key_file_set_string(keyfile, provider->identifier,
821                                 "Config.ident", provider->config_entry);
822
823         if (provider->driver != NULL && provider->driver->save != NULL)
824                 provider->driver->save(provider, keyfile);
825
826         __connman_storage_save_provider(keyfile, provider->identifier);
827         g_key_file_free(keyfile);
828
829         return 0;
830 }
831
832 struct vpn_provider *__vpn_provider_lookup(const char *identifier)
833 {
834         struct vpn_provider *provider = NULL;
835
836         provider = g_hash_table_lookup(provider_hash, identifier);
837
838         return provider;
839 }
840
841 static gboolean match_driver(struct vpn_provider *provider,
842                                 struct vpn_provider_driver *driver)
843 {
844         if (g_strcmp0(driver->name, provider->type) == 0)
845                 return TRUE;
846
847         return FALSE;
848 }
849
850 static int provider_probe(struct vpn_provider *provider)
851 {
852         GSList *list;
853
854         DBG("provider %p driver %p name %s", provider, provider->driver,
855                                                 provider->name);
856
857         if (provider->driver != NULL)
858                 return -EALREADY;
859
860         for (list = driver_list; list; list = list->next) {
861                 struct vpn_provider_driver *driver = list->data;
862
863                 if (match_driver(provider, driver) == FALSE)
864                         continue;
865
866                 DBG("driver %p name %s", driver, driver->name);
867
868                 if (driver->probe != NULL && driver->probe(provider) == 0) {
869                         provider->driver = driver;
870                         break;
871                 }
872         }
873
874         if (provider->driver == NULL)
875                 return -ENODEV;
876
877         return 0;
878 }
879
880 static void provider_remove(struct vpn_provider *provider)
881 {
882         if (provider->driver != NULL) {
883                 provider->driver->remove(provider);
884                 provider->driver = NULL;
885         }
886 }
887
888 static int provider_register(struct vpn_provider *provider)
889 {
890         return provider_probe(provider);
891 }
892
893 static void provider_unregister(struct vpn_provider *provider)
894 {
895         provider_remove(provider);
896 }
897
898 struct vpn_provider *
899 vpn_provider_ref_debug(struct vpn_provider *provider,
900                         const char *file, int line, const char *caller)
901 {
902         DBG("%p ref %d by %s:%d:%s()", provider, provider->refcount + 1,
903                 file, line, caller);
904
905         __sync_fetch_and_add(&provider->refcount, 1);
906
907         return provider;
908 }
909
910 static void provider_destruct(struct vpn_provider *provider)
911 {
912         DBG("provider %p", provider);
913
914         if (provider->notify_id != 0)
915                 g_source_remove(provider->notify_id);
916
917         g_free(provider->name);
918         g_free(provider->type);
919         g_free(provider->host);
920         g_free(provider->domain);
921         g_free(provider->identifier);
922         g_free(provider->path);
923         g_slist_free_full(provider->user_networks, free_route);
924         g_strfreev(provider->nameservers);
925         g_hash_table_destroy(provider->routes);
926         g_hash_table_destroy(provider->user_routes);
927         g_hash_table_destroy(provider->setting_strings);
928         if (provider->resolv != NULL) {
929                 g_resolv_unref(provider->resolv);
930                 provider->resolv = NULL;
931         }
932         __vpn_ipconfig_unref(provider->ipconfig_ipv4);
933         __vpn_ipconfig_unref(provider->ipconfig_ipv6);
934
935         g_strfreev(provider->host_ip);
936         g_free(provider->config_file);
937         g_free(provider->config_entry);
938         g_free(provider);
939 }
940
941 void vpn_provider_unref_debug(struct vpn_provider *provider,
942                                 const char *file, int line, const char *caller)
943 {
944         DBG("%p ref %d by %s:%d:%s()", provider, provider->refcount - 1,
945                 file, line, caller);
946
947         if (__sync_fetch_and_sub(&provider->refcount, 1) != 1)
948                 return;
949
950         provider_remove(provider);
951
952         provider_destruct(provider);
953 }
954
955 static void configuration_count_add(void)
956 {
957         DBG("count %d", configuration_count + 1);
958
959         __sync_fetch_and_add(&configuration_count, 1);
960 }
961
962 static void configuration_count_del(void)
963 {
964         DBG("count %d", configuration_count - 1);
965
966         if (__sync_fetch_and_sub(&configuration_count, 1) != 1)
967                 return;
968
969         raise(SIGTERM);
970 }
971
972 int __vpn_provider_disconnect(struct vpn_provider *provider)
973 {
974         int err;
975
976         DBG("provider %p", provider);
977
978         if (provider->driver != NULL && provider->driver->disconnect != NULL)
979                 err = provider->driver->disconnect(provider);
980         else
981                 return -EOPNOTSUPP;
982
983         if (err == -EINPROGRESS)
984                 vpn_provider_set_state(provider, VPN_PROVIDER_STATE_CONNECT);
985
986         return err;
987 }
988
989 static void connect_cb(struct vpn_provider *provider, void *user_data,
990                                                                 int error)
991 {
992         DBusMessage *pending = user_data;
993
994         DBG("provider %p user %p error %d", provider, user_data, error);
995
996         if (error != 0) {
997                 DBusMessage *reply = __connman_error_failed(pending, error);
998                 if (reply != NULL)
999                         g_dbus_send_message(connection, reply);
1000
1001                 vpn_provider_indicate_error(provider,
1002                                         VPN_PROVIDER_ERROR_CONNECT_FAILED);
1003                 vpn_provider_set_state(provider, VPN_PROVIDER_STATE_FAILURE);
1004         } else
1005                 g_dbus_send_reply(connection, pending, DBUS_TYPE_INVALID);
1006
1007         dbus_message_unref(pending);
1008 }
1009
1010 int __vpn_provider_connect(struct vpn_provider *provider, DBusMessage *msg)
1011 {
1012         int err;
1013
1014         DBG("provider %p", provider);
1015
1016         if (provider->driver != NULL && provider->driver->connect != NULL) {
1017                 dbus_message_ref(msg);
1018                 err = provider->driver->connect(provider, connect_cb, msg);
1019         } else
1020                 return -EOPNOTSUPP;
1021
1022         if (err == -EINPROGRESS)
1023                 vpn_provider_set_state(provider, VPN_PROVIDER_STATE_CONNECT);
1024
1025         return err;
1026 }
1027
1028 static void connection_removed_signal(struct vpn_provider *provider)
1029 {
1030         DBusMessage *signal;
1031         DBusMessageIter iter;
1032
1033         signal = dbus_message_new_signal(VPN_MANAGER_PATH,
1034                         VPN_MANAGER_INTERFACE, "ConnectionRemoved");
1035         if (signal == NULL)
1036                 return;
1037
1038         dbus_message_iter_init_append(signal, &iter);
1039         dbus_message_iter_append_basic(&iter, DBUS_TYPE_OBJECT_PATH,
1040                                                         &provider->path);
1041         dbus_connection_send(connection, signal, NULL);
1042         dbus_message_unref(signal);
1043 }
1044
1045 static char *get_ident(const char *path)
1046 {
1047         char *pos;
1048
1049         if (*path != '/')
1050                 return NULL;
1051
1052         pos = strrchr(path, '/');
1053         if (pos == NULL)
1054                 return NULL;
1055
1056         return pos + 1;
1057 }
1058
1059 int __vpn_provider_remove(const char *path)
1060 {
1061         struct vpn_provider *provider;
1062         char *ident;
1063
1064         DBG("path %s", path);
1065
1066         ident = get_ident(path);
1067
1068         provider = __vpn_provider_lookup(ident);
1069         if (provider != NULL)
1070                 return __vpn_provider_delete(provider);
1071
1072         return -ENXIO;
1073 }
1074
1075 int __vpn_provider_delete(struct vpn_provider *provider)
1076 {
1077         DBG("Deleting VPN %s", provider->identifier);
1078
1079         connection_removed_signal(provider);
1080
1081         provider_unregister(provider);
1082
1083         __connman_storage_remove_provider(provider->identifier);
1084
1085         g_hash_table_remove(provider_hash, provider->identifier);
1086
1087         return 0;
1088 }
1089
1090 static void append_ipv4(DBusMessageIter *iter, void *user_data)
1091 {
1092         struct vpn_provider *provider = user_data;
1093         const char *address, *gateway, *peer;
1094
1095         address = __vpn_ipconfig_get_local(provider->ipconfig_ipv4);
1096         if (address != NULL) {
1097                 in_addr_t addr;
1098                 struct in_addr netmask;
1099                 char *mask;
1100                 int prefixlen;
1101
1102                 prefixlen = __vpn_ipconfig_get_prefixlen(
1103                                                 provider->ipconfig_ipv4);
1104
1105                 addr = 0xffffffff << (32 - prefixlen);
1106                 netmask.s_addr = htonl(addr);
1107                 mask = inet_ntoa(netmask);
1108
1109                 connman_dbus_dict_append_basic(iter, "Address",
1110                                                 DBUS_TYPE_STRING, &address);
1111
1112                 connman_dbus_dict_append_basic(iter, "Netmask",
1113                                                 DBUS_TYPE_STRING, &mask);
1114         }
1115
1116         gateway = __vpn_ipconfig_get_gateway(provider->ipconfig_ipv4);
1117         if (gateway != NULL)
1118                 connman_dbus_dict_append_basic(iter, "Gateway",
1119                                                 DBUS_TYPE_STRING, &gateway);
1120
1121         peer = __vpn_ipconfig_get_peer(provider->ipconfig_ipv4);
1122         if (peer != NULL)
1123                 connman_dbus_dict_append_basic(iter, "Peer",
1124                                                 DBUS_TYPE_STRING, &peer);
1125 }
1126
1127 static void append_ipv6(DBusMessageIter *iter, void *user_data)
1128 {
1129         struct vpn_provider *provider = user_data;
1130         const char *address, *gateway, *peer;
1131
1132         address = __vpn_ipconfig_get_local(provider->ipconfig_ipv6);
1133         if (address != NULL) {
1134                 unsigned char prefixlen;
1135
1136                 connman_dbus_dict_append_basic(iter, "Address",
1137                                                 DBUS_TYPE_STRING, &address);
1138
1139                 prefixlen = __vpn_ipconfig_get_prefixlen(
1140                                                 provider->ipconfig_ipv6);
1141
1142                 connman_dbus_dict_append_basic(iter, "PrefixLength",
1143                                                 DBUS_TYPE_BYTE, &prefixlen);
1144         }
1145
1146         gateway = __vpn_ipconfig_get_gateway(provider->ipconfig_ipv6);
1147         if (gateway != NULL)
1148                 connman_dbus_dict_append_basic(iter, "Gateway",
1149                                                 DBUS_TYPE_STRING, &gateway);
1150
1151         peer = __vpn_ipconfig_get_peer(provider->ipconfig_ipv6);
1152         if (peer != NULL)
1153                 connman_dbus_dict_append_basic(iter, "Peer",
1154                                                 DBUS_TYPE_STRING, &peer);
1155 }
1156
1157 static const char *state2string(enum vpn_provider_state state)
1158 {
1159         switch (state) {
1160         case VPN_PROVIDER_STATE_UNKNOWN:
1161                 break;
1162         case VPN_PROVIDER_STATE_IDLE:
1163                 return "idle";
1164         case VPN_PROVIDER_STATE_CONNECT:
1165                 return "configuration";
1166         case VPN_PROVIDER_STATE_READY:
1167                 return "ready";
1168         case VPN_PROVIDER_STATE_DISCONNECT:
1169                 return "disconnect";
1170         case VPN_PROVIDER_STATE_FAILURE:
1171                 return "failure";
1172         }
1173
1174         return NULL;
1175 }
1176
1177 static int provider_indicate_state(struct vpn_provider *provider,
1178                                 enum vpn_provider_state state)
1179 {
1180         const char *str;
1181
1182         str = state2string(state);
1183         DBG("provider %p state %s/%d", provider, str, state);
1184         if (str == NULL)
1185                 return -EINVAL;
1186
1187         provider->state = state;
1188
1189         if (state == VPN_PROVIDER_STATE_READY) {
1190                 connman_dbus_property_changed_basic(provider->path,
1191                                         VPN_CONNECTION_INTERFACE, "Index",
1192                                         DBUS_TYPE_INT32, &provider->index);
1193
1194                 if (provider->family == AF_INET)
1195                         connman_dbus_property_changed_dict(provider->path,
1196                                         VPN_CONNECTION_INTERFACE, "IPv4",
1197                                         append_ipv4, provider);
1198                 else if (provider->family == AF_INET6)
1199                         connman_dbus_property_changed_dict(provider->path,
1200                                         VPN_CONNECTION_INTERFACE, "IPv6",
1201                                         append_ipv6, provider);
1202         }
1203
1204         connman_dbus_property_changed_basic(provider->path,
1205                                         VPN_CONNECTION_INTERFACE, "State",
1206                                         DBUS_TYPE_STRING, &str);
1207         /*
1208          * We do not stay in failure state as clients like connmand can
1209          * get confused about our current state.
1210          */
1211         if (provider->state == VPN_PROVIDER_STATE_FAILURE)
1212                 provider->state = VPN_PROVIDER_STATE_IDLE;
1213
1214         return 0;
1215 }
1216
1217 static void append_nameservers(DBusMessageIter *iter, char **servers)
1218 {
1219         int i;
1220
1221         DBG("%p", servers);
1222
1223         for (i = 0; servers[i] != NULL; i++) {
1224                 DBG("servers[%d] %s", i, servers[i]);
1225                 dbus_message_iter_append_basic(iter,
1226                                         DBUS_TYPE_STRING, &servers[i]);
1227         }
1228 }
1229
1230 static void append_dns(DBusMessageIter *iter, void *user_data)
1231 {
1232         struct vpn_provider *provider = user_data;
1233
1234         if (provider->nameservers != NULL)
1235                 append_nameservers(iter, provider->nameservers);
1236 }
1237
1238 static void append_state(DBusMessageIter *iter,
1239                                         struct vpn_provider *provider)
1240 {
1241         char *str;
1242
1243         switch (provider->state) {
1244         case VPN_PROVIDER_STATE_UNKNOWN:
1245         case VPN_PROVIDER_STATE_IDLE:
1246                 str = "idle";
1247                 break;
1248         case VPN_PROVIDER_STATE_CONNECT:
1249                 str = "configuration";
1250                 break;
1251         case VPN_PROVIDER_STATE_READY:
1252                 str = "ready";
1253                 break;
1254         case VPN_PROVIDER_STATE_DISCONNECT:
1255                 str = "disconnect";
1256                 break;
1257         case VPN_PROVIDER_STATE_FAILURE:
1258                 str = "failure";
1259                 break;
1260         }
1261
1262         connman_dbus_dict_append_basic(iter, "State",
1263                                 DBUS_TYPE_STRING, &str);
1264 }
1265
1266 static void append_properties(DBusMessageIter *iter,
1267                                         struct vpn_provider *provider)
1268 {
1269         DBusMessageIter dict;
1270
1271         connman_dbus_dict_open(iter, &dict);
1272
1273         append_state(&dict, provider);
1274
1275         if (provider->type != NULL)
1276                 connman_dbus_dict_append_basic(&dict, "Type",
1277                                         DBUS_TYPE_STRING, &provider->type);
1278
1279         if (provider->name != NULL)
1280                 connman_dbus_dict_append_basic(&dict, "Name",
1281                                         DBUS_TYPE_STRING, &provider->name);
1282
1283         if (provider->host != NULL)
1284                 connman_dbus_dict_append_basic(&dict, "Host",
1285                                         DBUS_TYPE_STRING, &provider->host);
1286         if (provider->index >= 0)
1287                 connman_dbus_dict_append_basic(&dict, "Index",
1288                                         DBUS_TYPE_INT32, &provider->index);
1289         if (provider->domain != NULL)
1290                 connman_dbus_dict_append_basic(&dict, "Domain",
1291                                         DBUS_TYPE_STRING, &provider->domain);
1292
1293         if (provider->family == AF_INET)
1294                 connman_dbus_dict_append_dict(&dict, "IPv4", append_ipv4,
1295                                                 provider);
1296         else if (provider->family == AF_INET6)
1297                 connman_dbus_dict_append_dict(&dict, "IPv6", append_ipv6,
1298                                                 provider);
1299
1300         connman_dbus_dict_append_array(&dict, "Nameservers",
1301                                 DBUS_TYPE_STRING, append_dns, provider);
1302
1303         connman_dbus_dict_append_array(&dict, "UserRoutes",
1304                                 DBUS_TYPE_DICT_ENTRY, append_routes,
1305                                 provider->user_routes);
1306
1307         connman_dbus_dict_append_array(&dict, "ServerRoutes",
1308                                 DBUS_TYPE_DICT_ENTRY, append_routes,
1309                                 provider->routes);
1310
1311         connman_dbus_dict_close(iter, &dict);
1312 }
1313
1314 static void connection_added_signal(struct vpn_provider *provider)
1315 {
1316         DBusMessage *signal;
1317         DBusMessageIter iter;
1318
1319         signal = dbus_message_new_signal(VPN_MANAGER_PATH,
1320                         VPN_MANAGER_INTERFACE, "ConnectionAdded");
1321         if (signal == NULL)
1322                 return;
1323
1324         dbus_message_iter_init_append(signal, &iter);
1325         dbus_message_iter_append_basic(&iter, DBUS_TYPE_OBJECT_PATH,
1326                                                         &provider->path);
1327         append_properties(&iter, provider);
1328
1329         dbus_connection_send(connection, signal, NULL);
1330         dbus_message_unref(signal);
1331 }
1332
1333 static connman_bool_t check_host(char **hosts, char *host)
1334 {
1335         int i;
1336
1337         if (hosts == NULL)
1338                 return FALSE;
1339
1340         for (i = 0; hosts[i] != NULL; i++) {
1341                 if (g_strcmp0(hosts[i], host) == 0)
1342                         return TRUE;
1343         }
1344
1345         return FALSE;
1346 }
1347
1348 static void provider_append_routes(gpointer key, gpointer value,
1349                                         gpointer user_data)
1350 {
1351         struct vpn_route *route = value;
1352         struct vpn_provider *provider = user_data;
1353         int index = provider->index;
1354
1355         if (handle_routes == FALSE)
1356                 return;
1357
1358         /*
1359          * If the VPN administrator/user has given a route to
1360          * VPN server, then we must discard that because the
1361          * server cannot be contacted via VPN tunnel.
1362          */
1363         if (check_host(provider->host_ip, route->network) == TRUE) {
1364                 DBG("Discarding VPN route to %s via %s at index %d",
1365                         route->network, route->gateway, index);
1366                 return;
1367         }
1368
1369         if (route->family == AF_INET6) {
1370                 unsigned char prefix_len = atoi(route->netmask);
1371
1372                 connman_inet_add_ipv6_network_route(index, route->network,
1373                                                         route->gateway,
1374                                                         prefix_len);
1375         } else {
1376                 connman_inet_add_network_route(index, route->network,
1377                                                 route->gateway,
1378                                                 route->netmask);
1379         }
1380 }
1381
1382 static int set_connected(struct vpn_provider *provider,
1383                                         connman_bool_t connected)
1384 {
1385         struct vpn_ipconfig *ipconfig;
1386
1387         DBG("provider %p id %s connected %d", provider,
1388                                         provider->identifier, connected);
1389
1390         if (connected == TRUE) {
1391                 if (provider->family == AF_INET6)
1392                         ipconfig = provider->ipconfig_ipv6;
1393                 else
1394                         ipconfig = provider->ipconfig_ipv4;
1395
1396                 __vpn_ipconfig_address_add(ipconfig, provider->family);
1397
1398                 if (handle_routes == TRUE)
1399                         __vpn_ipconfig_gateway_add(ipconfig, provider->family);
1400
1401                 provider_indicate_state(provider,
1402                                         VPN_PROVIDER_STATE_READY);
1403
1404                 g_hash_table_foreach(provider->routes, provider_append_routes,
1405                                         provider);
1406
1407                 g_hash_table_foreach(provider->user_routes,
1408                                         provider_append_routes, provider);
1409
1410         } else {
1411                 provider_indicate_state(provider,
1412                                         VPN_PROVIDER_STATE_DISCONNECT);
1413
1414                 provider_indicate_state(provider,
1415                                         VPN_PROVIDER_STATE_IDLE);
1416         }
1417
1418         return 0;
1419 }
1420
1421 int vpn_provider_set_state(struct vpn_provider *provider,
1422                                         enum vpn_provider_state state)
1423 {
1424         if (provider == NULL)
1425                 return -EINVAL;
1426
1427         switch (state) {
1428         case VPN_PROVIDER_STATE_UNKNOWN:
1429                 return -EINVAL;
1430         case VPN_PROVIDER_STATE_IDLE:
1431                 return set_connected(provider, FALSE);
1432         case VPN_PROVIDER_STATE_CONNECT:
1433                 return provider_indicate_state(provider, state);
1434         case VPN_PROVIDER_STATE_READY:
1435                 return set_connected(provider, TRUE);
1436         case VPN_PROVIDER_STATE_DISCONNECT:
1437                 return provider_indicate_state(provider, state);
1438         case VPN_PROVIDER_STATE_FAILURE:
1439                 return provider_indicate_state(provider, state);
1440         }
1441         return -EINVAL;
1442 }
1443
1444 int vpn_provider_indicate_error(struct vpn_provider *provider,
1445                                         enum vpn_provider_error error)
1446 {
1447         DBG("provider %p id %s error %d", provider, provider->identifier,
1448                                                                         error);
1449
1450         switch (error) {
1451         case VPN_PROVIDER_ERROR_LOGIN_FAILED:
1452                 break;
1453         case VPN_PROVIDER_ERROR_AUTH_FAILED:
1454                 vpn_provider_set_state(provider, VPN_PROVIDER_STATE_FAILURE);
1455                 break;
1456         case VPN_PROVIDER_ERROR_CONNECT_FAILED:
1457                 break;
1458         default:
1459                 break;
1460         }
1461
1462         return 0;
1463 }
1464
1465 static int connection_unregister(struct vpn_provider *provider)
1466 {
1467         DBG("provider %p path %s", provider, provider->path);
1468
1469         if (provider->path == NULL)
1470                 return -EALREADY;
1471
1472         g_dbus_unregister_interface(connection, provider->path,
1473                                 VPN_CONNECTION_INTERFACE);
1474
1475         g_free(provider->path);
1476         provider->path = NULL;
1477
1478         return 0;
1479 }
1480
1481 static int connection_register(struct vpn_provider *provider)
1482 {
1483         DBG("provider %p path %s", provider, provider->path);
1484
1485         if (provider->path != NULL)
1486                 return -EALREADY;
1487
1488         provider->path = g_strdup_printf("%s/connection/%s", VPN_PATH,
1489                                                 provider->identifier);
1490
1491         g_dbus_register_interface(connection, provider->path,
1492                                 VPN_CONNECTION_INTERFACE,
1493                                 connection_methods, connection_signals,
1494                                 NULL, provider, NULL);
1495
1496         return 0;
1497 }
1498
1499 static void unregister_provider(gpointer data)
1500 {
1501         struct vpn_provider *provider = data;
1502
1503         configuration_count_del();
1504
1505         connection_unregister(provider);
1506
1507         vpn_provider_unref(provider);
1508 }
1509
1510 static void provider_initialize(struct vpn_provider *provider)
1511 {
1512         DBG("provider %p", provider);
1513
1514         provider->index = 0;
1515         provider->fd = -1;
1516         provider->name = NULL;
1517         provider->type = NULL;
1518         provider->domain = NULL;
1519         provider->identifier = NULL;
1520         provider->user_networks = NULL;
1521         provider->routes = g_hash_table_new_full(g_direct_hash, g_direct_equal,
1522                                         NULL, free_route);
1523         provider->user_routes = g_hash_table_new_full(g_str_hash, g_str_equal,
1524                                         g_free, free_route);
1525         provider->setting_strings = g_hash_table_new_full(g_str_hash,
1526                                                 g_str_equal, g_free, g_free);
1527 }
1528
1529 static struct vpn_provider *vpn_provider_new(void)
1530 {
1531         struct vpn_provider *provider;
1532
1533         provider = g_try_new0(struct vpn_provider, 1);
1534         if (provider == NULL)
1535                 return NULL;
1536
1537         provider->refcount = 1;
1538
1539         DBG("provider %p", provider);
1540         provider_initialize(provider);
1541
1542         return provider;
1543 }
1544
1545 static struct vpn_provider *vpn_provider_get(const char *identifier)
1546 {
1547         struct vpn_provider *provider;
1548
1549         provider = g_hash_table_lookup(provider_hash, identifier);
1550         if (provider != NULL)
1551                 return provider;
1552
1553         provider = vpn_provider_new();
1554         if (provider == NULL)
1555                 return NULL;
1556
1557         DBG("provider %p", provider);
1558
1559         provider->identifier = g_strdup(identifier);
1560
1561         g_hash_table_insert(provider_hash, provider->identifier, provider);
1562
1563         configuration_count_add();
1564
1565         return provider;
1566 }
1567
1568 static void provider_dbus_ident(char *ident)
1569 {
1570         int i, len = strlen(ident);
1571
1572         for (i = 0; i < len; i++) {
1573                 if (ident[i] >= '0' && ident[i] <= '9')
1574                         continue;
1575                 if (ident[i] >= 'a' && ident[i] <= 'z')
1576                         continue;
1577                 if (ident[i] >= 'A' && ident[i] <= 'Z')
1578                         continue;
1579                 ident[i] = '_';
1580         }
1581 }
1582
1583 static struct vpn_provider *provider_create_from_keyfile(GKeyFile *keyfile,
1584                 const char *ident)
1585 {
1586         struct vpn_provider *provider;
1587
1588         if (keyfile == NULL || ident == NULL)
1589                 return NULL;
1590
1591         provider = __vpn_provider_lookup(ident);
1592         if (provider == NULL) {
1593                 provider = vpn_provider_get(ident);
1594                 if (provider == NULL) {
1595                         DBG("can not create provider");
1596                         return NULL;
1597                 }
1598
1599                 provider_load_from_keyfile(provider, keyfile);
1600
1601                 if (provider->name == NULL || provider->host == NULL ||
1602                                 provider->domain == NULL) {
1603                         DBG("cannot get name, host or domain");
1604                         vpn_provider_unref(provider);
1605                         return NULL;
1606                 }
1607
1608                 if (provider_register(provider) == 0)
1609                         connection_register(provider);
1610         }
1611         return provider;
1612 }
1613
1614 static void provider_create_all_from_type(const char *provider_type)
1615 {
1616         unsigned int i;
1617         char **providers;
1618         char *id, *type;
1619         GKeyFile *keyfile;
1620
1621         DBG("provider type %s", provider_type);
1622
1623         providers = __connman_storage_get_providers();
1624
1625         if (providers == NULL)
1626                 return;
1627
1628         for (i = 0; providers[i] != NULL; i+=1) {
1629
1630                 if (strncmp(providers[i], "provider_", 9) != 0)
1631                         continue;
1632
1633                 id = providers[i] + 9;
1634                 keyfile = __connman_storage_load_provider(id);
1635
1636                 if (keyfile == NULL)
1637                         continue;
1638
1639                 type = g_key_file_get_string(keyfile, id, "Type", NULL);
1640
1641                 DBG("keyfile %p id %s type %s", keyfile, id, type);
1642
1643                 if (strcmp(provider_type, type) != 0) {
1644                         g_free(type);
1645                         g_key_file_free(keyfile);
1646                         continue;
1647                 }
1648
1649                 if (provider_create_from_keyfile(keyfile, id) == NULL)
1650                         DBG("could not create provider");
1651
1652                 g_free(type);
1653                 g_key_file_free(keyfile);
1654         }
1655         g_strfreev(providers);
1656 }
1657
1658 char *__vpn_provider_create_identifier(const char *host, const char *domain)
1659 {
1660         char *ident;
1661
1662         ident = g_strdup_printf("%s_%s", host, domain);
1663         if (ident == NULL)
1664                 return NULL;
1665
1666         provider_dbus_ident(ident);
1667
1668         return ident;
1669 }
1670
1671 int __vpn_provider_create(DBusMessage *msg)
1672 {
1673         struct vpn_provider *provider;
1674         DBusMessageIter iter, array;
1675         const char *type = NULL, *name = NULL;
1676         const char *host = NULL, *domain = NULL;
1677         GSList *networks = NULL;
1678         char *ident;
1679         int err;
1680
1681         dbus_message_iter_init(msg, &iter);
1682         dbus_message_iter_recurse(&iter, &array);
1683
1684         while (dbus_message_iter_get_arg_type(&array) == DBUS_TYPE_DICT_ENTRY) {
1685                 DBusMessageIter entry, value;
1686                 const char *key;
1687
1688                 dbus_message_iter_recurse(&array, &entry);
1689                 dbus_message_iter_get_basic(&entry, &key);
1690
1691                 dbus_message_iter_next(&entry);
1692                 dbus_message_iter_recurse(&entry, &value);
1693
1694                 switch (dbus_message_iter_get_arg_type(&value)) {
1695                 case DBUS_TYPE_STRING:
1696                         if (g_str_equal(key, "Type") == TRUE)
1697                                 dbus_message_iter_get_basic(&value, &type);
1698                         else if (g_str_equal(key, "Name") == TRUE)
1699                                 dbus_message_iter_get_basic(&value, &name);
1700                         else if (g_str_equal(key, "Host") == TRUE)
1701                                 dbus_message_iter_get_basic(&value, &host);
1702                         else if (g_str_equal(key, "VPN.Domain") == TRUE)
1703                                 dbus_message_iter_get_basic(&value, &domain);
1704                         break;
1705                 case DBUS_TYPE_ARRAY:
1706                         if (g_str_equal(key, "UserRoutes") == TRUE)
1707                                 networks = get_user_networks(&value);
1708                         break;
1709                 }
1710
1711                 dbus_message_iter_next(&array);
1712         }
1713
1714         if (host == NULL || domain == NULL)
1715                 return -EINVAL;
1716
1717         DBG("Type %s name %s networks %p", type, name, networks);
1718
1719         if (type == NULL || name == NULL)
1720                 return -EOPNOTSUPP;
1721
1722         ident = __vpn_provider_create_identifier(host, domain);
1723         DBG("ident %s", ident);
1724
1725         provider = __vpn_provider_lookup(ident);
1726         if (provider == NULL) {
1727                 provider = vpn_provider_get(ident);
1728                 if (provider == NULL) {
1729                         DBG("can not create provider");
1730                         g_free(ident);
1731                         return -EOPNOTSUPP;
1732                 }
1733
1734                 provider->host = g_strdup(host);
1735                 provider->domain = g_strdup(domain);
1736                 provider->name = g_strdup(name);
1737                 provider->type = g_strdup(type);
1738
1739                 if (provider_register(provider) == 0)
1740                         vpn_provider_load(provider);
1741
1742                 provider_resolv_host_addr(provider);
1743         }
1744
1745         if (networks != NULL) {
1746                 g_slist_free_full(provider->user_networks, free_route);
1747                 provider->user_networks = networks;
1748                 set_user_networks(provider, provider->user_networks);
1749         }
1750
1751         dbus_message_iter_init(msg, &iter);
1752         dbus_message_iter_recurse(&iter, &array);
1753
1754         while (dbus_message_iter_get_arg_type(&array) == DBUS_TYPE_DICT_ENTRY) {
1755                 DBusMessageIter entry, value;
1756                 const char *key, *str;
1757
1758                 dbus_message_iter_recurse(&array, &entry);
1759                 dbus_message_iter_get_basic(&entry, &key);
1760
1761                 dbus_message_iter_next(&entry);
1762                 dbus_message_iter_recurse(&entry, &value);
1763
1764                 switch (dbus_message_iter_get_arg_type(&value)) {
1765                 case DBUS_TYPE_STRING:
1766                         dbus_message_iter_get_basic(&value, &str);
1767                         vpn_provider_set_string(provider, key, str);
1768                         break;
1769                 }
1770
1771                 dbus_message_iter_next(&array);
1772         }
1773
1774         g_free(ident);
1775
1776         vpn_provider_save(provider);
1777
1778         err = provider_register(provider);
1779         if (err != 0 && err != -EALREADY)
1780                 return err;
1781
1782         connection_register(provider);
1783
1784         DBG("provider %p index %d path %s", provider, provider->index,
1785                                                         provider->path);
1786
1787         g_dbus_send_reply(connection, msg,
1788                                 DBUS_TYPE_OBJECT_PATH, &provider->path,
1789                                 DBUS_TYPE_INVALID);
1790
1791         connection_added_signal(provider);
1792
1793         return 0;
1794 }
1795
1796 static const char *get_string(GHashTable *settings, const char *key)
1797 {
1798         DBG("settings %p key %s", settings, key);
1799
1800         return g_hash_table_lookup(settings, key);
1801 }
1802
1803 static GSList *parse_user_networks(const char *network_str)
1804 {
1805         GSList *networks = NULL;
1806         char **elems = g_strsplit(network_str, ",", 0);
1807         int i = 0;
1808
1809         if (elems == NULL)
1810                 return NULL;
1811
1812         while (elems[i] != NULL) {
1813                 struct vpn_route *vpn_route;
1814                 char *network, *netmask, *gateway;
1815                 int family;
1816                 char **route;
1817
1818                 route = g_strsplit(elems[i], "/", 0);
1819                 if (route == NULL)
1820                         goto next;
1821
1822                 network = route[0];
1823                 if (network == NULL || network[0] == '\0')
1824                         goto next;
1825
1826                 family = connman_inet_check_ipaddress(network);
1827                 if (family < 0) {
1828                         DBG("Cannot get address family of %s (%d/%s)", network,
1829                                 family, gai_strerror(family));
1830
1831                         goto next;
1832                 }
1833
1834                 switch (family) {
1835                 case AF_INET:
1836                         break;
1837                 case AF_INET6:
1838                         break;
1839                 default:
1840                         DBG("Unsupported address family %d", family);
1841                         goto next;
1842                 }
1843
1844                 netmask = route[1];
1845                 if (netmask == NULL || netmask[0] == '\0')
1846                         goto next;
1847
1848                 gateway = route[2];
1849
1850                 vpn_route = g_try_new0(struct vpn_route, 1);
1851                 if (vpn_route == NULL) {
1852                         g_strfreev(route);
1853                         break;
1854                 }
1855
1856                 vpn_route->family = family;
1857                 vpn_route->network = g_strdup(network);
1858                 vpn_route->netmask = g_strdup(netmask);
1859                 vpn_route->gateway = g_strdup(gateway);
1860
1861                 DBG("route %s/%s%s%s", network, netmask,
1862                         gateway ? " via " : "", gateway ? gateway : "");
1863
1864                 networks = g_slist_prepend(networks, vpn_route);
1865
1866         next:
1867                 g_strfreev(route);
1868                 i++;
1869         }
1870
1871         g_strfreev(elems);
1872
1873         return g_slist_reverse(networks);
1874 }
1875
1876 int __vpn_provider_create_from_config(GHashTable *settings,
1877                                 const char *config_ident,
1878                                 const char *config_entry)
1879 {
1880         struct vpn_provider *provider;
1881         const char *type, *name, *host, *domain, *networks_str;
1882         GSList *networks;
1883         char *ident = NULL;
1884         GHashTableIter hash;
1885         gpointer value, key;
1886         int err;
1887
1888         type = get_string(settings, "Type");
1889         name = get_string(settings, "Name");
1890         host = get_string(settings, "Host");
1891         domain = get_string(settings, "Domain");
1892         networks_str = get_string(settings, "Networks");
1893         networks = parse_user_networks(networks_str);
1894
1895         if (host == NULL || domain == NULL) {
1896                 err = -EINVAL;
1897                 goto fail;
1898         }
1899
1900         DBG("type %s name %s networks %s", type, name, networks_str);
1901
1902         if (type == NULL || name == NULL) {
1903                 err = -EOPNOTSUPP;
1904                 goto fail;
1905         }
1906
1907         ident = __vpn_provider_create_identifier(host, domain);
1908         DBG("ident %s", ident);
1909
1910         provider = __vpn_provider_lookup(ident);
1911         if (provider == NULL) {
1912                 provider = vpn_provider_get(ident);
1913                 if (provider == NULL) {
1914                         DBG("can not create provider");
1915                         err = -EOPNOTSUPP;
1916                         goto fail;
1917                 }
1918
1919                 provider->host = g_strdup(host);
1920                 provider->domain = g_strdup(domain);
1921                 provider->name = g_strdup(name);
1922                 provider->type = g_ascii_strdown(type, -1);
1923
1924                 provider->config_file = g_strdup(config_ident);
1925                 provider->config_entry = g_strdup(config_entry);
1926
1927                 if (provider_register(provider) == 0)
1928                         vpn_provider_load(provider);
1929
1930                 provider_resolv_host_addr(provider);
1931         }
1932
1933         if (networks != NULL) {
1934                 g_slist_free_full(provider->user_networks, free_route);
1935                 provider->user_networks = networks;
1936                 set_user_networks(provider, provider->user_networks);
1937         }
1938
1939         g_hash_table_iter_init(&hash, settings);
1940
1941         while (g_hash_table_iter_next(&hash, &key, &value) == TRUE)
1942                 vpn_provider_set_string(provider, key, value);
1943
1944         vpn_provider_save(provider);
1945
1946         err = provider_register(provider);
1947         if (err != 0 && err != -EALREADY)
1948                 goto fail;
1949
1950         connection_register(provider);
1951
1952         DBG("provider %p index %d path %s", provider, provider->index,
1953                                                         provider->path);
1954
1955         connection_added_signal(provider);
1956
1957         g_free(ident);
1958
1959         return 0;
1960
1961 fail:
1962         g_free(ident);
1963         g_slist_free_full(networks, free_route);
1964
1965         return err;
1966 }
1967
1968 static void append_connection_structs(DBusMessageIter *iter, void *user_data)
1969 {
1970         DBusMessageIter entry;
1971         GHashTableIter hash;
1972         gpointer value, key;
1973
1974         g_hash_table_iter_init(&hash, provider_hash);
1975
1976         while (g_hash_table_iter_next(&hash, &key, &value) == TRUE) {
1977                 struct vpn_provider *provider = value;
1978
1979                 DBG("path %s", provider->path);
1980
1981                 if (provider->identifier == NULL)
1982                         continue;
1983
1984                 dbus_message_iter_open_container(iter, DBUS_TYPE_STRUCT,
1985                                 NULL, &entry);
1986                 dbus_message_iter_append_basic(&entry, DBUS_TYPE_OBJECT_PATH,
1987                                 &provider->path);
1988                 append_properties(&entry, provider);
1989                 dbus_message_iter_close_container(iter, &entry);
1990         }
1991 }
1992
1993 DBusMessage *__vpn_provider_get_connections(DBusMessage *msg)
1994 {
1995         DBusMessage *reply;
1996
1997         DBG("");
1998
1999         reply = dbus_message_new_method_return(msg);
2000         if (reply == NULL)
2001                 return NULL;
2002
2003         __connman_dbus_append_objpath_dict_array(reply,
2004                         append_connection_structs, NULL);
2005
2006         return reply;
2007 }
2008
2009 const char * __vpn_provider_get_ident(struct vpn_provider *provider)
2010 {
2011         if (provider == NULL)
2012                 return NULL;
2013
2014         return provider->identifier;
2015 }
2016
2017 static int set_string(struct vpn_provider *provider,
2018                 const char *key, const char *value, gboolean hide_value)
2019 {
2020         DBG("provider %p key %s value %s", provider, key,
2021                 hide_value ? "<not printed>" : value);
2022
2023         if (g_str_equal(key, "Type") == TRUE) {
2024                 g_free(provider->type);
2025                 provider->type = g_ascii_strdown(value, -1);
2026         } else if (g_str_equal(key, "Name") == TRUE) {
2027                 g_free(provider->name);
2028                 provider->name = g_strdup(value);
2029         } else if (g_str_equal(key, "Host") == TRUE) {
2030                 g_free(provider->host);
2031                 provider->host = g_strdup(value);
2032         } else if (g_str_equal(key, "VPN.Domain") == TRUE) {
2033                 g_free(provider->domain);
2034                 provider->domain = g_strdup(value);
2035         } else
2036                 g_hash_table_replace(provider->setting_strings,
2037                                 g_strdup(key), g_strdup(value));
2038         return 0;
2039 }
2040
2041 int vpn_provider_set_string(struct vpn_provider *provider,
2042                                         const char *key, const char *value)
2043 {
2044         return set_string(provider, key, value, FALSE);
2045 }
2046
2047 int vpn_provider_set_string_hide_value(struct vpn_provider *provider,
2048                                         const char *key, const char *value)
2049 {
2050         return set_string(provider, key, value, TRUE);
2051 }
2052
2053 const char *vpn_provider_get_string(struct vpn_provider *provider,
2054                                                         const char *key)
2055 {
2056         DBG("provider %p key %s", provider, key);
2057
2058         if (g_str_equal(key, "Type") == TRUE)
2059                 return provider->type;
2060         else if (g_str_equal(key, "Name") == TRUE)
2061                 return provider->name;
2062         else if (g_str_equal(key, "Host") == TRUE)
2063                 return provider->host;
2064         else if (g_str_equal(key, "HostIP") == TRUE) {
2065                 if (provider->host_ip == NULL ||
2066                                 provider->host_ip[0] == NULL)
2067                         return provider->host;
2068                 else
2069                         return provider->host_ip[0];
2070         } else if (g_str_equal(key, "VPN.Domain") == TRUE)
2071                 return provider->domain;
2072
2073         return g_hash_table_lookup(provider->setting_strings, key);
2074 }
2075
2076 connman_bool_t __vpn_provider_check_routes(struct vpn_provider *provider)
2077 {
2078         if (provider == NULL)
2079                 return FALSE;
2080
2081         if (provider->user_routes != NULL &&
2082                         g_hash_table_size(provider->user_routes) > 0)
2083                 return TRUE;
2084
2085         if (provider->routes != NULL &&
2086                         g_hash_table_size(provider->routes) > 0)
2087                 return TRUE;
2088
2089         return FALSE;
2090 }
2091
2092 void *vpn_provider_get_data(struct vpn_provider *provider)
2093 {
2094         return provider->driver_data;
2095 }
2096
2097 void vpn_provider_set_data(struct vpn_provider *provider, void *data)
2098 {
2099         provider->driver_data = data;
2100 }
2101
2102 void vpn_provider_set_index(struct vpn_provider *provider, int index)
2103 {
2104         DBG("index %d provider %p", index, provider);
2105
2106         if (provider->ipconfig_ipv4 == NULL) {
2107                 provider->ipconfig_ipv4 = __vpn_ipconfig_create(index,
2108                                                                 AF_INET);
2109                 if (provider->ipconfig_ipv4 == NULL) {
2110                         DBG("Couldnt create ipconfig for IPv4");
2111                         goto done;
2112                 }
2113         }
2114
2115         __vpn_ipconfig_set_index(provider->ipconfig_ipv4, index);
2116
2117         if (provider->ipconfig_ipv6 == NULL) {
2118                 provider->ipconfig_ipv6 = __vpn_ipconfig_create(index,
2119                                                                 AF_INET6);
2120                 if (provider->ipconfig_ipv6 == NULL) {
2121                         DBG("Couldnt create ipconfig for IPv6");
2122                         goto done;
2123                 }
2124         }
2125
2126         __vpn_ipconfig_set_index(provider->ipconfig_ipv6, index);
2127
2128 done:
2129         provider->index = index;
2130 }
2131
2132 int vpn_provider_get_index(struct vpn_provider *provider)
2133 {
2134         return provider->index;
2135 }
2136
2137 int vpn_provider_set_ipaddress(struct vpn_provider *provider,
2138                                         struct connman_ipaddress *ipaddress)
2139 {
2140         struct vpn_ipconfig *ipconfig = NULL;
2141
2142         switch (ipaddress->family) {
2143         case AF_INET:
2144                 ipconfig = provider->ipconfig_ipv4;
2145                 break;
2146         case AF_INET6:
2147                 ipconfig = provider->ipconfig_ipv6;
2148                 break;
2149         default:
2150                 break;
2151         }
2152
2153         DBG("provider %p ipconfig %p family %d", provider, ipconfig,
2154                                                         ipaddress->family);
2155
2156         if (ipconfig == NULL)
2157                 return -EINVAL;
2158
2159         provider->family = ipaddress->family;
2160
2161         __vpn_ipconfig_set_local(ipconfig, ipaddress->local);
2162         __vpn_ipconfig_set_peer(ipconfig, ipaddress->peer);
2163         __vpn_ipconfig_set_broadcast(ipconfig, ipaddress->broadcast);
2164         __vpn_ipconfig_set_gateway(ipconfig, ipaddress->gateway);
2165         __vpn_ipconfig_set_prefixlen(ipconfig, ipaddress->prefixlen);
2166
2167         return 0;
2168 }
2169
2170 int vpn_provider_set_pac(struct vpn_provider *provider,
2171                                 const char *pac)
2172 {
2173         DBG("provider %p pac %s", provider, pac);
2174
2175         return 0;
2176 }
2177
2178
2179 int vpn_provider_set_domain(struct vpn_provider *provider,
2180                                         const char *domain)
2181 {
2182         DBG("provider %p domain %s", provider, domain);
2183
2184         g_free(provider->domain);
2185         provider->domain = g_strdup(domain);
2186
2187         return 0;
2188 }
2189
2190 int vpn_provider_set_nameservers(struct vpn_provider *provider,
2191                                         const char *nameservers)
2192 {
2193         DBG("provider %p nameservers %s", provider, nameservers);
2194
2195         g_strfreev(provider->nameservers);
2196         provider->nameservers = NULL;
2197
2198         if (nameservers == NULL)
2199                 return 0;
2200
2201         provider->nameservers = g_strsplit(nameservers, " ", 0);
2202
2203         return 0;
2204 }
2205
2206 enum provider_route_type {
2207         PROVIDER_ROUTE_TYPE_NONE = 0,
2208         PROVIDER_ROUTE_TYPE_MASK = 1,
2209         PROVIDER_ROUTE_TYPE_ADDR = 2,
2210         PROVIDER_ROUTE_TYPE_GW   = 3,
2211 };
2212
2213 static int route_env_parse(struct vpn_provider *provider, const char *key,
2214                                 int *family, unsigned long *idx,
2215                                 enum provider_route_type *type)
2216 {
2217         char *end;
2218         const char *start;
2219
2220         DBG("name %s", provider->name);
2221
2222         if (!strcmp(provider->type, "openvpn")) {
2223                 if (g_str_has_prefix(key, "route_network_") == TRUE) {
2224                         start = key + strlen("route_network_");
2225                         *type = PROVIDER_ROUTE_TYPE_ADDR;
2226                 } else if (g_str_has_prefix(key, "route_netmask_") == TRUE) {
2227                         start = key + strlen("route_netmask_");
2228                         *type = PROVIDER_ROUTE_TYPE_MASK;
2229                 } else if (g_str_has_prefix(key, "route_gateway_") == TRUE) {
2230                         start = key + strlen("route_gateway_");
2231                         *type = PROVIDER_ROUTE_TYPE_GW;
2232                 } else
2233                         return -EINVAL;
2234
2235                 *family = AF_INET;
2236                 *idx = g_ascii_strtoull(start, &end, 10);
2237
2238         } else if (!strcmp(provider->type, "openconnect")) {
2239                 if (g_str_has_prefix(key, "CISCO_SPLIT_INC_") == TRUE) {
2240                         *family = AF_INET;
2241                         start = key + strlen("CISCO_SPLIT_INC_");
2242                 } else if (g_str_has_prefix(key,
2243                                         "CISCO_IPV6_SPLIT_INC_") == TRUE) {
2244                         *family = AF_INET6;
2245                         start = key + strlen("CISCO_IPV6_SPLIT_INC_");
2246                 } else
2247                         return -EINVAL;
2248
2249                 *idx = g_ascii_strtoull(start, &end, 10);
2250
2251                 if (strncmp(end, "_ADDR", 5) == 0)
2252                         *type = PROVIDER_ROUTE_TYPE_ADDR;
2253                 else if (strncmp(end, "_MASK", 5) == 0)
2254                         *type = PROVIDER_ROUTE_TYPE_MASK;
2255                 else if (strncmp(end, "_MASKLEN", 8) == 0 &&
2256                                 *family == AF_INET6) {
2257                         *type = PROVIDER_ROUTE_TYPE_MASK;
2258                 } else
2259                         return -EINVAL;
2260         }
2261
2262         return 0;
2263 }
2264
2265 int vpn_provider_append_route(struct vpn_provider *provider,
2266                                         const char *key, const char *value)
2267 {
2268         struct vpn_route *route;
2269         int ret, family = 0;
2270         unsigned long idx = 0;
2271         enum provider_route_type type = PROVIDER_ROUTE_TYPE_NONE;
2272
2273         DBG("key %s value %s", key, value);
2274
2275         ret = route_env_parse(provider, key, &family, &idx, &type);
2276         if (ret < 0)
2277                 return ret;
2278
2279         DBG("idx %lu family %d type %d", idx, family, type);
2280
2281         route = g_hash_table_lookup(provider->routes, GINT_TO_POINTER(idx));
2282         if (route == NULL) {
2283                 route = g_try_new0(struct vpn_route, 1);
2284                 if (route == NULL) {
2285                         connman_error("out of memory");
2286                         return -ENOMEM;
2287                 }
2288
2289                 route->family = family;
2290
2291                 g_hash_table_replace(provider->routes, GINT_TO_POINTER(idx),
2292                                                 route);
2293         }
2294
2295         switch (type) {
2296         case PROVIDER_ROUTE_TYPE_NONE:
2297                 break;
2298         case PROVIDER_ROUTE_TYPE_MASK:
2299                 route->netmask = g_strdup(value);
2300                 break;
2301         case PROVIDER_ROUTE_TYPE_ADDR:
2302                 route->network = g_strdup(value);
2303                 break;
2304         case PROVIDER_ROUTE_TYPE_GW:
2305                 route->gateway = g_strdup(value);
2306                 break;
2307         }
2308
2309         if (handle_routes == FALSE) {
2310                 if (route->netmask != NULL && route->gateway != NULL &&
2311                                                         route->network != NULL)
2312                         provider_schedule_changed(provider,
2313                                                 SERVER_ROUTES_CHANGED);
2314         }
2315
2316         return 0;
2317 }
2318
2319 const char *vpn_provider_get_driver_name(struct vpn_provider *provider)
2320 {
2321         if (provider->driver == NULL)
2322                 return NULL;
2323
2324         return provider->driver->name;
2325 }
2326
2327 const char *vpn_provider_get_save_group(struct vpn_provider *provider)
2328 {
2329         return provider->identifier;
2330 }
2331
2332 static gint compare_priority(gconstpointer a, gconstpointer b)
2333 {
2334         return 0;
2335 }
2336
2337 static void clean_provider(gpointer key, gpointer value, gpointer user_data)
2338 {
2339         struct vpn_provider *provider = value;
2340
2341         if (provider->driver != NULL && provider->driver->remove)
2342                 provider->driver->remove(provider);
2343
2344         connection_unregister(provider);
2345 }
2346
2347 int vpn_provider_driver_register(struct vpn_provider_driver *driver)
2348 {
2349         DBG("driver %p name %s", driver, driver->name);
2350
2351         driver_list = g_slist_insert_sorted(driver_list, driver,
2352                                                         compare_priority);
2353         provider_create_all_from_type(driver->name);
2354         return 0;
2355 }
2356
2357 void vpn_provider_driver_unregister(struct vpn_provider_driver *driver)
2358 {
2359         GHashTableIter iter;
2360         gpointer value, key;
2361
2362         DBG("driver %p name %s", driver, driver->name);
2363
2364         driver_list = g_slist_remove(driver_list, driver);
2365
2366         g_hash_table_iter_init(&iter, provider_hash);
2367         while (g_hash_table_iter_next(&iter, &key, &value) == TRUE) {
2368                 struct vpn_provider *provider = value;
2369
2370                 if (provider != NULL && provider->driver != NULL &&
2371                                 provider->driver->type == driver->type &&
2372                                 g_strcmp0(provider->driver->name,
2373                                                         driver->name) == 0) {
2374                         provider->driver = NULL;
2375                 }
2376         }
2377 }
2378
2379 static gboolean check_vpn_count(gpointer data)
2380 {
2381         if (configuration_count == 0) {
2382                 connman_info("No VPN configurations found, quitting.");
2383                 raise(SIGTERM);
2384         }
2385
2386         return FALSE;
2387 }
2388
2389 void __vpn_provider_check_connections(void)
2390 {
2391         /*
2392          * If we were started when there is no providers configured,
2393          * then just quit. This happens when connman starts and its
2394          * vpn plugin asks connman-vpnd if it has any connections
2395          * configured. If there are none, then we can stop the vpn
2396          * daemon.
2397          */
2398         g_timeout_add(1000, check_vpn_count, NULL);
2399 }
2400
2401 const char *vpn_provider_get_name(struct vpn_provider *provider)
2402 {
2403         return provider->name;
2404 }
2405
2406 const char *vpn_provider_get_host(struct vpn_provider *provider)
2407 {
2408         return provider->host;
2409 }
2410
2411 const char *vpn_provider_get_path(struct vpn_provider *provider)
2412 {
2413         return provider->path;
2414 }
2415
2416 static int agent_probe(struct connman_agent *agent)
2417 {
2418         DBG("agent %p", agent);
2419         return 0;
2420 }
2421
2422 static void agent_remove(struct connman_agent *agent)
2423 {
2424         DBG("agent %p", agent);
2425 }
2426
2427 static struct connman_agent_driver agent_driver = {
2428         .name           = "vpn",
2429         .interface      = VPN_AGENT_INTERFACE,
2430         .probe          = agent_probe,
2431         .remove         = agent_remove,
2432 };
2433
2434 static void remove_unprovisioned_providers()
2435 {
2436         gchar **providers;
2437         GKeyFile *keyfile, *configkeyfile;
2438         char *file, *section;
2439         int i = 0;
2440
2441         providers = __connman_storage_get_providers();
2442         if (providers == NULL)
2443                 return;
2444
2445         for (; providers[i] != NULL; i++) {
2446                 char *group = providers[i] + sizeof("provider_") - 1;
2447                 file = section = NULL;
2448                 keyfile = configkeyfile = NULL;
2449
2450                 keyfile = __connman_storage_load_provider(group);
2451                 if (keyfile == NULL)
2452                         continue;
2453
2454                 file = g_key_file_get_string(keyfile, group,
2455                                         "Config.file", NULL);
2456                 if (file == NULL)
2457                         goto next;
2458
2459                 section = g_key_file_get_string(keyfile, group,
2460                                         "Config.ident", NULL);
2461                 if (section == NULL)
2462                         goto next;
2463
2464                 configkeyfile = __connman_storage_load_provider_config(file);
2465                 if (configkeyfile == NULL) {
2466                         /*
2467                          * Config file is missing, remove the provisioned
2468                          * service.
2469                          */
2470                         __connman_storage_remove_provider(group);
2471                         goto next;
2472                 }
2473
2474                 if (g_key_file_has_group(configkeyfile, section) == FALSE)
2475                         /*
2476                          * Config section is missing, remove the provisioned
2477                          * service.
2478                          */
2479                         __connman_storage_remove_provider(group);
2480
2481         next:
2482                 if (keyfile != NULL)
2483                         g_key_file_free(keyfile);
2484
2485                 if (configkeyfile != NULL)
2486                         g_key_file_free(configkeyfile);
2487
2488                 g_free(section);
2489                 g_free(file);
2490         }
2491
2492         g_strfreev(providers);
2493 }
2494
2495 int __vpn_provider_init(gboolean do_routes)
2496 {
2497         int err;
2498
2499         DBG("");
2500
2501         handle_routes = do_routes;
2502
2503         err = connman_agent_driver_register(&agent_driver);
2504         if (err < 0) {
2505                 connman_error("Cannot register agent driver for %s",
2506                                                 agent_driver.name);
2507                 return err;
2508         }
2509
2510         connection = connman_dbus_get_connection();
2511
2512         remove_unprovisioned_providers();
2513
2514         provider_hash = g_hash_table_new_full(g_str_hash, g_str_equal,
2515                                                 NULL, unregister_provider);
2516         return 0;
2517 }
2518
2519 void __vpn_provider_cleanup(void)
2520 {
2521         DBG("");
2522
2523         g_hash_table_foreach(provider_hash, clean_provider, NULL);
2524
2525         g_hash_table_destroy(provider_hash);
2526         provider_hash = NULL;
2527
2528         connman_agent_driver_unregister(&agent_driver);
2529
2530         dbus_connection_unref(connection);
2531 }