vpn-provider: ClearProperty works with all properties
[platform/upstream/connman.git] / vpn / vpn-provider.c
1 /*
2  *
3  *  ConnMan VPN daemon
4  *
5  *  Copyright (C) 2012  Intel Corporation. All rights reserved.
6  *
7  *  This program is free software; you can redistribute it and/or modify
8  *  it under the terms of the GNU General Public License version 2 as
9  *  published by the Free Software Foundation.
10  *
11  *  This program is distributed in the hope that it will be useful,
12  *  but WITHOUT ANY WARRANTY; without even the implied warranty of
13  *  MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
14  *  GNU General Public License for more details.
15  *
16  *  You should have received a copy of the GNU General Public License
17  *  along with this program; if not, write to the Free Software
18  *  Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA  02110-1301  USA
19  *
20  */
21
22 #ifdef HAVE_CONFIG_H
23 #include <config.h>
24 #endif
25
26 #include <errno.h>
27 #include <stdio.h>
28 #include <string.h>
29 #include <stdlib.h>
30 #include <gdbus.h>
31 #include <connman/log.h>
32 #include <gweb/gresolv.h>
33 #include <netdb.h>
34
35 #include "../src/connman.h"
36 #include "connman/agent.h"
37 #include "connman/vpn-dbus.h"
38 #include "vpn-provider.h"
39 #include "vpn.h"
40
41 static DBusConnection *connection;
42 static GHashTable *provider_hash;
43 static GSList *driver_list;
44 static int configuration_count;
45 static gboolean handle_routes;
46
47 struct vpn_route {
48         int family;
49         char *network;
50         char *netmask;
51         char *gateway;
52 };
53
54 struct vpn_setting {
55         gboolean hide_value;
56         char *value;
57 };
58
59 struct vpn_provider {
60         int refcount;
61         int index;
62         int fd;
63         enum vpn_provider_state state;
64         char *path;
65         char *identifier;
66         char *name;
67         char *type;
68         char *host;
69         char *domain;
70         int family;
71         GHashTable *routes;
72         struct vpn_provider_driver *driver;
73         void *driver_data;
74         GHashTable *setting_strings;
75         GHashTable *user_routes;
76         GSList *user_networks;
77         GResolv *resolv;
78         char **host_ip;
79         struct vpn_ipconfig *ipconfig_ipv4;
80         struct vpn_ipconfig *ipconfig_ipv6;
81         char **nameservers;
82         guint notify_id;
83         char *config_file;
84         char *config_entry;
85 };
86
87 static void append_properties(DBusMessageIter *iter,
88                                 struct vpn_provider *provider);
89
90 static void free_route(gpointer data)
91 {
92         struct vpn_route *route = data;
93
94         g_free(route->network);
95         g_free(route->netmask);
96         g_free(route->gateway);
97
98         g_free(route);
99 }
100
101 static void free_setting(gpointer data)
102 {
103         struct vpn_setting *setting = data;
104
105         g_free(setting->value);
106         g_free(setting);
107 }
108
109 static void append_route(DBusMessageIter *iter, void *user_data)
110 {
111         struct vpn_route *route = user_data;
112         DBusMessageIter item;
113         int family = 0;
114
115         connman_dbus_dict_open(iter, &item);
116
117         if (route == NULL)
118                 goto empty_dict;
119
120         if (route->family == AF_INET)
121                 family = 4;
122         else if (route->family == AF_INET6)
123                 family = 6;
124
125         if (family != 0)
126                 connman_dbus_dict_append_basic(&item, "ProtocolFamily",
127                                         DBUS_TYPE_INT32, &family);
128
129         if (route->network != NULL)
130                 connman_dbus_dict_append_basic(&item, "Network",
131                                         DBUS_TYPE_STRING, &route->network);
132
133         if (route->netmask != NULL)
134                 connman_dbus_dict_append_basic(&item, "Netmask",
135                                         DBUS_TYPE_STRING, &route->netmask);
136
137         if (route->gateway != NULL)
138                 connman_dbus_dict_append_basic(&item, "Gateway",
139                                         DBUS_TYPE_STRING, &route->gateway);
140
141 empty_dict:
142         connman_dbus_dict_close(iter, &item);
143 }
144
145 static void append_routes(DBusMessageIter *iter, void *user_data)
146 {
147         GHashTable *routes = user_data;
148         GHashTableIter hash;
149         gpointer value, key;
150
151         if (routes == NULL) {
152                 append_route(iter, NULL);
153                 return;
154         }
155
156         g_hash_table_iter_init(&hash, routes);
157
158         while (g_hash_table_iter_next(&hash, &key, &value) == TRUE) {
159                 DBusMessageIter dict;
160
161                 dbus_message_iter_open_container(iter, DBUS_TYPE_STRUCT, NULL,
162                                                 &dict);
163                 append_route(&dict, value);
164                 dbus_message_iter_close_container(iter, &dict);
165         }
166 }
167
168 static void send_routes(struct vpn_provider *provider, GHashTable *routes,
169                         const char *name)
170 {
171         connman_dbus_property_changed_array(provider->path,
172                                         VPN_CONNECTION_INTERFACE,
173                                         name,
174                                         DBUS_TYPE_DICT_ENTRY,
175                                         append_routes,
176                                         routes);
177 }
178
179 static int provider_routes_changed(struct vpn_provider *provider)
180 {
181         DBG("provider %p", provider);
182
183         send_routes(provider, provider->routes, "ServerRoutes");
184
185         return 0;
186 }
187
188 static GSList *read_route_dict(GSList *routes, DBusMessageIter *dicts)
189 {
190         DBusMessageIter dict, value, entry;
191         const char *network, *netmask, *gateway;
192         struct vpn_route *route;
193         int family, type;
194         const char *key;
195
196         dbus_message_iter_recurse(dicts, &entry);
197
198         network = netmask = gateway = NULL;
199         family = PF_UNSPEC;
200
201         while (dbus_message_iter_get_arg_type(&entry) == DBUS_TYPE_DICT_ENTRY) {
202
203                 dbus_message_iter_recurse(&entry, &dict);
204                 dbus_message_iter_get_basic(&dict, &key);
205
206                 dbus_message_iter_next(&dict);
207                 dbus_message_iter_recurse(&dict, &value);
208
209                 type = dbus_message_iter_get_arg_type(&value);
210
211                 switch (type) {
212                 case DBUS_TYPE_STRING:
213                         if (g_str_equal(key, "ProtocolFamily") == TRUE)
214                                 dbus_message_iter_get_basic(&value, &family);
215                         else if (g_str_equal(key, "Network") == TRUE)
216                                 dbus_message_iter_get_basic(&value, &network);
217                         else if (g_str_equal(key, "Netmask") == TRUE)
218                                 dbus_message_iter_get_basic(&value, &netmask);
219                         else if (g_str_equal(key, "Gateway") == TRUE)
220                                 dbus_message_iter_get_basic(&value, &gateway);
221                         break;
222                 }
223
224                 dbus_message_iter_next(&entry);
225         }
226
227         DBG("family %d network %s netmask %s gateway %s", family,
228                 network, netmask, gateway);
229
230         if (network == NULL || netmask == NULL) {
231                 DBG("Ignoring route as network/netmask is missing");
232                 return routes;
233         }
234
235         route = g_try_new(struct vpn_route, 1);
236         if (route == NULL) {
237                 g_slist_free_full(routes, free_route);
238                 return NULL;
239         }
240
241         if (family == PF_UNSPEC) {
242                 family = connman_inet_check_ipaddress(network);
243                 if (family < 0) {
244                         DBG("Cannot get address family of %s (%d/%s)", network,
245                                 family, gai_strerror(family));
246
247                         g_free(route);
248                         return routes;
249                 }
250         } else {
251                 switch (family) {
252                 case '4':
253                         family = AF_INET;
254                         break;
255                 case '6':
256                         family = AF_INET6;
257                         break;
258                 default:
259                         family = PF_UNSPEC;
260                         break;
261                 }
262         }
263
264         route->family = family;
265         route->network = g_strdup(network);
266         route->netmask = g_strdup(netmask);
267         route->gateway = g_strdup(gateway);
268
269         routes = g_slist_prepend(routes, route);
270         return routes;
271 }
272
273 static GSList *get_user_networks(DBusMessageIter *array)
274 {
275         DBusMessageIter entry;
276         GSList *list = NULL;
277
278         while (dbus_message_iter_get_arg_type(array) == DBUS_TYPE_ARRAY) {
279
280                 dbus_message_iter_recurse(array, &entry);
281
282                 while (dbus_message_iter_get_arg_type(&entry) ==
283                                                         DBUS_TYPE_STRUCT) {
284                         DBusMessageIter dicts;
285
286                         dbus_message_iter_recurse(&entry, &dicts);
287
288                         while (dbus_message_iter_get_arg_type(&dicts) ==
289                                                         DBUS_TYPE_ARRAY) {
290
291                                 list = read_route_dict(list, &dicts);
292                                 dbus_message_iter_next(&dicts);
293                         }
294
295                         dbus_message_iter_next(&entry);
296                 }
297
298                 dbus_message_iter_next(array);
299         }
300
301         return list;
302 }
303
304 static void set_user_networks(struct vpn_provider *provider, GSList *networks)
305 {
306         GSList *list;
307
308         for (list = networks; list != NULL; list = g_slist_next(list)) {
309                 struct vpn_route *route = list->data;
310
311                 if (__vpn_provider_append_user_route(provider,
312                                         route->family, route->network,
313                                         route->netmask, route->gateway) != 0)
314                         break;
315         }
316 }
317
318 static void del_routes(struct vpn_provider *provider)
319 {
320         GHashTableIter hash;
321         gpointer value, key;
322
323         g_hash_table_iter_init(&hash, provider->user_routes);
324         while (handle_routes == TRUE && g_hash_table_iter_next(&hash,
325                                                 &key, &value) == TRUE) {
326                 struct vpn_route *route = value;
327                 if (route->family == AF_INET6) {
328                         unsigned char prefixlen = atoi(route->netmask);
329                         connman_inet_del_ipv6_network_route(provider->index,
330                                                         route->network,
331                                                         prefixlen);
332                 } else
333                         connman_inet_del_host_route(provider->index,
334                                                 route->network);
335         }
336
337         g_hash_table_remove_all(provider->user_routes);
338         g_slist_free_full(provider->user_networks, free_route);
339         provider->user_networks = NULL;
340 }
341
342 static void send_value(const char *path, const char *key, const char *value)
343 {
344         const char *empty = "";
345         const char *str;
346
347         if (value != NULL)
348                 str = value;
349         else
350                 str = empty;
351
352         connman_dbus_property_changed_basic(path,
353                                         VPN_CONNECTION_INTERFACE,
354                                         key,
355                                         DBUS_TYPE_STRING,
356                                         &str);
357 }
358
359 static gboolean provider_send_changed(gpointer data)
360 {
361         struct vpn_provider *provider = data;
362
363         provider_routes_changed(provider);
364
365         provider->notify_id = 0;
366
367         return FALSE;
368 }
369
370 static void provider_schedule_changed(struct vpn_provider *provider)
371 {
372         if (provider->notify_id != 0)
373                 g_source_remove(provider->notify_id);
374
375         provider->notify_id = g_timeout_add(100, provider_send_changed,
376                                                                 provider);
377 }
378
379 static DBusMessage *get_properties(DBusConnection *conn,
380                                         DBusMessage *msg, void *data)
381 {
382         struct vpn_provider *provider = data;
383         DBusMessage *reply;
384         DBusMessageIter array;
385
386         DBG("provider %p", provider);
387
388         reply = dbus_message_new_method_return(msg);
389         if (reply == NULL)
390                 return NULL;
391
392         dbus_message_iter_init_append(reply, &array);
393
394         append_properties(&array, provider);
395
396         return reply;
397 }
398
399 static DBusMessage *set_property(DBusConnection *conn, DBusMessage *msg,
400                                                                 void *data)
401 {
402         struct vpn_provider *provider = data;
403         DBusMessageIter iter, value;
404         const char *name;
405         int type;
406
407         DBG("conn %p", conn);
408
409         if (dbus_message_iter_init(msg, &iter) == FALSE)
410                 return __connman_error_invalid_arguments(msg);
411
412         if (dbus_message_iter_get_arg_type(&iter) != DBUS_TYPE_STRING)
413                 return __connman_error_invalid_arguments(msg);
414
415         dbus_message_iter_get_basic(&iter, &name);
416         dbus_message_iter_next(&iter);
417
418         if (dbus_message_iter_get_arg_type(&iter) != DBUS_TYPE_VARIANT)
419                 return __connman_error_invalid_arguments(msg);
420
421         dbus_message_iter_recurse(&iter, &value);
422
423         type = dbus_message_iter_get_arg_type(&value);
424
425         if (g_str_equal(name, "UserRoutes") == TRUE) {
426                 GSList *networks;
427
428                 if (type != DBUS_TYPE_ARRAY)
429                         return __connman_error_invalid_arguments(msg);
430
431                 networks = get_user_networks(&value);
432                 if (networks != NULL) {
433                         del_routes(provider);
434                         provider->user_networks = networks;
435                         set_user_networks(provider, provider->user_networks);
436
437                         if (handle_routes == FALSE)
438                                 send_routes(provider, provider->user_routes,
439                                                                 "UserRoutes");
440                 }
441         } else
442                 return __connman_error_invalid_property(msg);
443
444         return g_dbus_create_reply(msg, DBUS_TYPE_INVALID);
445 }
446
447 static DBusMessage *clear_property(DBusConnection *conn, DBusMessage *msg,
448                                                                 void *data)
449 {
450         struct vpn_provider *provider = data;
451         const char *name;
452
453         DBG("conn %p", conn);
454
455         dbus_message_get_args(msg, NULL, DBUS_TYPE_STRING, &name,
456                                                         DBUS_TYPE_INVALID);
457
458         if (g_str_equal(name, "UserRoutes") == TRUE) {
459                 del_routes(provider);
460
461                 if (handle_routes == FALSE)
462                         send_routes(provider, provider->user_routes, name);
463         } else if (vpn_provider_get_string(provider, name) != NULL) {
464                 vpn_provider_set_string(provider, name, NULL);
465         } else {
466                 return __connman_error_invalid_property(msg);
467         }
468
469         return g_dbus_create_reply(msg, DBUS_TYPE_INVALID);
470 }
471
472 static DBusMessage *do_connect(DBusConnection *conn, DBusMessage *msg,
473                                                                 void *data)
474 {
475         struct vpn_provider *provider = data;
476         int err;
477
478         DBG("conn %p provider %p", conn, provider);
479
480         err = __vpn_provider_connect(provider, msg);
481         if (err < 0)
482                 return __connman_error_failed(msg, -err);
483
484         return NULL;
485 }
486
487 static DBusMessage *do_disconnect(DBusConnection *conn, DBusMessage *msg,
488                                                                 void *data)
489 {
490         struct vpn_provider *provider = data;
491         int err;
492
493         DBG("conn %p provider %p", conn, provider);
494
495         err = __vpn_provider_disconnect(provider);
496         if (err < 0 && err != -EINPROGRESS)
497                 return __connman_error_failed(msg, -err);
498
499         return g_dbus_create_reply(msg, DBUS_TYPE_INVALID);
500 }
501
502 static const GDBusMethodTable connection_methods[] = {
503         { GDBUS_METHOD("GetProperties",
504                         NULL, GDBUS_ARGS({ "properties", "a{sv}" }),
505                         get_properties) },
506         { GDBUS_METHOD("SetProperty",
507                         GDBUS_ARGS({ "name", "s" }, { "value", "v" }),
508                         NULL, set_property) },
509         { GDBUS_METHOD("ClearProperty",
510                         GDBUS_ARGS({ "name", "s" }), NULL,
511                         clear_property) },
512         { GDBUS_ASYNC_METHOD("Connect", NULL, NULL, do_connect) },
513         { GDBUS_METHOD("Disconnect", NULL, NULL, do_disconnect) },
514         { },
515 };
516
517 static const GDBusSignalTable connection_signals[] = {
518         { GDBUS_SIGNAL("PropertyChanged",
519                         GDBUS_ARGS({ "name", "s" }, { "value", "v" })) },
520         { },
521 };
522
523 static void resolv_result(GResolvResultStatus status,
524                                         char **results, gpointer user_data)
525 {
526         struct vpn_provider *provider = user_data;
527
528         DBG("status %d", status);
529
530         if (status == G_RESOLV_RESULT_STATUS_SUCCESS && results != NULL &&
531                                                 g_strv_length(results) > 0)
532                 provider->host_ip = g_strdupv(results);
533
534         vpn_provider_unref(provider);
535 }
536
537 static void provider_resolv_host_addr(struct vpn_provider *provider)
538 {
539         if (provider->host == NULL)
540                 return;
541
542         if (connman_inet_check_ipaddress(provider->host) > 0)
543                 return;
544
545         if (provider->host_ip != NULL)
546                 return;
547
548         /*
549          * If the hostname is not numeric, try to resolv it. We do not wait
550          * the result as it might take some time. We will get the result
551          * before VPN will feed routes to us because VPN client will need
552          * the IP address also before VPN connection can be established.
553          */
554         provider->resolv = g_resolv_new(0);
555         if (provider->resolv == NULL) {
556                 DBG("Cannot resolv %s", provider->host);
557                 return;
558         }
559
560         DBG("Trying to resolv %s", provider->host);
561
562         vpn_provider_ref(provider);
563
564         g_resolv_lookup_hostname(provider->resolv, provider->host,
565                                 resolv_result, provider);
566 }
567
568 void __vpn_provider_append_properties(struct vpn_provider *provider,
569                                                         DBusMessageIter *iter)
570 {
571         if (provider->host != NULL)
572                 connman_dbus_dict_append_basic(iter, "Host",
573                                         DBUS_TYPE_STRING, &provider->host);
574
575         if (provider->domain != NULL)
576                 connman_dbus_dict_append_basic(iter, "Domain",
577                                         DBUS_TYPE_STRING, &provider->domain);
578
579         if (provider->type != NULL)
580                 connman_dbus_dict_append_basic(iter, "Type", DBUS_TYPE_STRING,
581                                                  &provider->type);
582 }
583
584 int __vpn_provider_append_user_route(struct vpn_provider *provider,
585                                 int family, const char *network,
586                                 const char *netmask, const char *gateway)
587 {
588         struct vpn_route *route;
589         char *key = g_strdup_printf("%d/%s/%s/%s", family, network,
590                                 netmask, gateway != NULL ? gateway : "");
591
592         DBG("family %d network %s netmask %s gw %s", family, network,
593                                                         netmask, gateway);
594
595         route = g_hash_table_lookup(provider->user_routes, key);
596         if (route == NULL) {
597                 route = g_try_new0(struct vpn_route, 1);
598                 if (route == NULL) {
599                         connman_error("out of memory");
600                         return -ENOMEM;
601                 }
602
603                 route->family = family;
604                 route->network = g_strdup(network);
605                 route->netmask = g_strdup(netmask);
606                 route->gateway = g_strdup(gateway);
607
608                 g_hash_table_replace(provider->user_routes, key, route);
609         } else
610                 g_free(key);
611
612         return 0;
613 }
614
615 static struct vpn_route *get_route(char *route_str)
616 {
617         char **elems = g_strsplit(route_str, "/", 0);
618         char *network, *netmask, *gateway, *family_str;
619         int family = PF_UNSPEC;
620         struct vpn_route *route = NULL;
621
622         if (elems == NULL)
623                 return NULL;
624
625         family_str = elems[0];
626
627         network = elems[1];
628         if (network == NULL || network[0] == '\0')
629                 goto out;
630
631         netmask = elems[2];
632         if (netmask == NULL || netmask[0] == '\0')
633                 goto out;
634
635         gateway = elems[3];
636
637         route = g_try_new0(struct vpn_route, 1);
638         if (route == NULL)
639                 goto out;
640
641         if (family_str[0] == '\0' || atoi(family_str) == 0) {
642                 family = PF_UNSPEC;
643         } else {
644                 switch (family_str[0]) {
645                 case '4':
646                         family = AF_INET;
647                         break;
648                 case '6':
649                         family = AF_INET6;
650                         break;
651                 }
652         }
653
654         if (g_strrstr(network, ":") != NULL) {
655                 if (family != PF_UNSPEC && family != AF_INET6)
656                         DBG("You have IPv6 address but you have non IPv6 route");
657         } else if (g_strrstr(network, ".") != NULL) {
658                 if (family != PF_UNSPEC && family != AF_INET)
659                         DBG("You have IPv4 address but you have non IPv4 route");
660
661                 if (g_strrstr(netmask, ".") == NULL) {
662                         /* We have netmask length */
663                         in_addr_t addr;
664                         struct in_addr netmask_in;
665                         unsigned char prefix_len = 32;
666
667                         if (netmask != NULL) {
668                                 char *ptr;
669                                 long int value = strtol(netmask, &ptr, 10);
670                                 if (ptr != netmask && *ptr == '\0' &&
671                                                                 value <= 32)
672                                         prefix_len = value;
673                         }
674
675                         addr = 0xffffffff << (32 - prefix_len);
676                         netmask_in.s_addr = htonl(addr);
677                         netmask = inet_ntoa(netmask_in);
678
679                         DBG("network %s netmask %s", network, netmask);
680                 }
681         }
682
683         if (family == PF_UNSPEC) {
684                 family = connman_inet_check_ipaddress(network);
685                 if (family < 0 || family == PF_UNSPEC)
686                         goto out;
687         }
688
689         route->family = family;
690         route->network = g_strdup(network);
691         route->netmask = g_strdup(netmask);
692         route->gateway = g_strdup(gateway);
693
694 out:
695         g_strfreev(elems);
696         return route;
697 }
698
699 static GSList *get_routes(gchar **networks)
700 {
701         struct vpn_route *route;
702         GSList *routes = NULL;
703         int i;
704
705         for (i = 0; networks[i] != NULL; i++) {
706                 route = get_route(networks[i]);
707                 if (route != NULL)
708                         routes = g_slist_prepend(routes, route);
709         }
710
711         return routes;
712 }
713
714 static int provider_load_from_keyfile(struct vpn_provider *provider,
715                 GKeyFile *keyfile)
716 {
717         gsize idx = 0;
718         gchar **settings;
719         gchar *key, *value;
720         gsize length, num_user_networks;
721         gchar **networks = NULL;
722
723         settings = g_key_file_get_keys(keyfile, provider->identifier, &length,
724                                 NULL);
725         if (settings == NULL) {
726                 g_key_file_free(keyfile);
727                 return -ENOENT;
728         }
729
730         while (idx < length) {
731                 key = settings[idx];
732                 if (key != NULL) {
733                         if (g_str_equal(key, "Networks") == TRUE) {
734                                 networks = g_key_file_get_string_list(keyfile,
735                                                 provider->identifier,
736                                                 key,
737                                                 &num_user_networks,
738                                                 NULL);
739                                 provider->user_networks = get_routes(networks);
740
741                         } else {
742                                 value = g_key_file_get_string(keyfile,
743                                                         provider->identifier,
744                                                         key, NULL);
745                                 vpn_provider_set_string(provider, key,
746                                                         value);
747                                 g_free(value);
748                         }
749                 }
750                 idx += 1;
751         }
752         g_strfreev(settings);
753         g_strfreev(networks);
754
755         if (provider->user_networks != NULL)
756                 set_user_networks(provider, provider->user_networks);
757
758         return 0;
759 }
760
761
762 static int vpn_provider_load(struct vpn_provider *provider)
763 {
764         GKeyFile *keyfile;
765
766         DBG("provider %p", provider);
767
768         keyfile = __connman_storage_load_provider(provider->identifier);
769         if (keyfile == NULL)
770                 return -ENOENT;
771
772         provider_load_from_keyfile(provider, keyfile);
773
774         g_key_file_free(keyfile);
775         return 0;
776 }
777
778 static gchar **create_network_list(GSList *networks, gsize *count)
779 {
780         GSList *list;
781         gchar **result = NULL;
782         unsigned int num_elems = 0;
783
784         for (list = networks; list != NULL; list = g_slist_next(list)) {
785                 struct vpn_route *route = list->data;
786                 int family;
787
788                 result = g_try_realloc(result,
789                                 (num_elems + 1) * sizeof(gchar *));
790                 if (result == NULL)
791                         return NULL;
792
793                 switch (route->family) {
794                 case AF_INET:
795                         family = 4;
796                         break;
797                 case AF_INET6:
798                         family = 6;
799                         break;
800                 default:
801                         family = 0;
802                         break;
803                 }
804
805                 result[num_elems] = g_strdup_printf("%d/%s/%s/%s",
806                                 family, route->network, route->netmask,
807                                 route->gateway == NULL ? "" : route->gateway);
808
809                 num_elems++;
810         }
811
812         result = g_try_realloc(result, (num_elems + 1) * sizeof(gchar *));
813         if (result == NULL)
814                 return NULL;
815
816         result[num_elems] = NULL;
817         *count = num_elems;
818         return result;
819 }
820
821 static int vpn_provider_save(struct vpn_provider *provider)
822 {
823         GKeyFile *keyfile;
824
825         DBG("provider %p", provider);
826
827         keyfile = g_key_file_new();
828         if (keyfile == NULL)
829                 return -ENOMEM;
830
831         g_key_file_set_string(keyfile, provider->identifier,
832                         "Name", provider->name);
833         g_key_file_set_string(keyfile, provider->identifier,
834                         "Type", provider->type);
835         g_key_file_set_string(keyfile, provider->identifier,
836                         "Host", provider->host);
837         g_key_file_set_string(keyfile, provider->identifier,
838                         "VPN.Domain", provider->domain);
839         if (provider->user_networks != NULL) {
840                 gchar **networks;
841                 gsize network_count;
842
843                 networks = create_network_list(provider->user_networks,
844                                                         &network_count);
845                 if (networks != NULL) {
846                         g_key_file_set_string_list(keyfile,
847                                                 provider->identifier,
848                                                 "Networks",
849                                                 (const gchar ** const)networks,
850                                                 network_count);
851                         g_strfreev(networks);
852                 }
853         }
854
855         if (provider->config_file != NULL && strlen(provider->config_file) > 0)
856                 g_key_file_set_string(keyfile, provider->identifier,
857                                 "Config.file", provider->config_file);
858
859         if (provider->config_entry != NULL &&
860                                         strlen(provider->config_entry) > 0)
861                 g_key_file_set_string(keyfile, provider->identifier,
862                                 "Config.ident", provider->config_entry);
863
864         if (provider->driver != NULL && provider->driver->save != NULL)
865                 provider->driver->save(provider, keyfile);
866
867         __connman_storage_save_provider(keyfile, provider->identifier);
868         g_key_file_free(keyfile);
869
870         return 0;
871 }
872
873 struct vpn_provider *__vpn_provider_lookup(const char *identifier)
874 {
875         struct vpn_provider *provider = NULL;
876
877         provider = g_hash_table_lookup(provider_hash, identifier);
878
879         return provider;
880 }
881
882 static gboolean match_driver(struct vpn_provider *provider,
883                                 struct vpn_provider_driver *driver)
884 {
885         if (g_strcmp0(driver->name, provider->type) == 0)
886                 return TRUE;
887
888         return FALSE;
889 }
890
891 static int provider_probe(struct vpn_provider *provider)
892 {
893         GSList *list;
894
895         DBG("provider %p driver %p name %s", provider, provider->driver,
896                                                 provider->name);
897
898         if (provider->driver != NULL)
899                 return -EALREADY;
900
901         for (list = driver_list; list; list = list->next) {
902                 struct vpn_provider_driver *driver = list->data;
903
904                 if (match_driver(provider, driver) == FALSE)
905                         continue;
906
907                 DBG("driver %p name %s", driver, driver->name);
908
909                 if (driver->probe != NULL && driver->probe(provider) == 0) {
910                         provider->driver = driver;
911                         break;
912                 }
913         }
914
915         if (provider->driver == NULL)
916                 return -ENODEV;
917
918         return 0;
919 }
920
921 static void provider_remove(struct vpn_provider *provider)
922 {
923         if (provider->driver != NULL) {
924                 provider->driver->remove(provider);
925                 provider->driver = NULL;
926         }
927 }
928
929 static int provider_register(struct vpn_provider *provider)
930 {
931         return provider_probe(provider);
932 }
933
934 static void provider_unregister(struct vpn_provider *provider)
935 {
936         provider_remove(provider);
937 }
938
939 struct vpn_provider *
940 vpn_provider_ref_debug(struct vpn_provider *provider,
941                         const char *file, int line, const char *caller)
942 {
943         DBG("%p ref %d by %s:%d:%s()", provider, provider->refcount + 1,
944                 file, line, caller);
945
946         __sync_fetch_and_add(&provider->refcount, 1);
947
948         return provider;
949 }
950
951 static void provider_destruct(struct vpn_provider *provider)
952 {
953         DBG("provider %p", provider);
954
955         if (provider->notify_id != 0)
956                 g_source_remove(provider->notify_id);
957
958         g_free(provider->name);
959         g_free(provider->type);
960         g_free(provider->host);
961         g_free(provider->domain);
962         g_free(provider->identifier);
963         g_free(provider->path);
964         g_slist_free_full(provider->user_networks, free_route);
965         g_strfreev(provider->nameservers);
966         g_hash_table_destroy(provider->routes);
967         g_hash_table_destroy(provider->user_routes);
968         g_hash_table_destroy(provider->setting_strings);
969         if (provider->resolv != NULL) {
970                 g_resolv_unref(provider->resolv);
971                 provider->resolv = NULL;
972         }
973         __vpn_ipconfig_unref(provider->ipconfig_ipv4);
974         __vpn_ipconfig_unref(provider->ipconfig_ipv6);
975
976         g_strfreev(provider->host_ip);
977         g_free(provider->config_file);
978         g_free(provider->config_entry);
979         g_free(provider);
980 }
981
982 void vpn_provider_unref_debug(struct vpn_provider *provider,
983                                 const char *file, int line, const char *caller)
984 {
985         DBG("%p ref %d by %s:%d:%s()", provider, provider->refcount - 1,
986                 file, line, caller);
987
988         if (__sync_fetch_and_sub(&provider->refcount, 1) != 1)
989                 return;
990
991         provider_remove(provider);
992
993         provider_destruct(provider);
994 }
995
996 static void configuration_count_add(void)
997 {
998         DBG("count %d", configuration_count + 1);
999
1000         __sync_fetch_and_add(&configuration_count, 1);
1001 }
1002
1003 static void configuration_count_del(void)
1004 {
1005         DBG("count %d", configuration_count - 1);
1006
1007         if (__sync_fetch_and_sub(&configuration_count, 1) != 1)
1008                 return;
1009
1010         raise(SIGTERM);
1011 }
1012
1013 int __vpn_provider_disconnect(struct vpn_provider *provider)
1014 {
1015         int err;
1016
1017         DBG("provider %p", provider);
1018
1019         if (provider->driver != NULL && provider->driver->disconnect != NULL)
1020                 err = provider->driver->disconnect(provider);
1021         else
1022                 return -EOPNOTSUPP;
1023
1024         if (err == -EINPROGRESS)
1025                 vpn_provider_set_state(provider, VPN_PROVIDER_STATE_CONNECT);
1026
1027         return err;
1028 }
1029
1030 static void connect_cb(struct vpn_provider *provider, void *user_data,
1031                                                                 int error)
1032 {
1033         DBusMessage *pending = user_data;
1034
1035         DBG("provider %p user %p error %d", provider, user_data, error);
1036
1037         if (error != 0) {
1038                 DBusMessage *reply = __connman_error_failed(pending, error);
1039                 if (reply != NULL)
1040                         g_dbus_send_message(connection, reply);
1041
1042                 vpn_provider_indicate_error(provider,
1043                                         VPN_PROVIDER_ERROR_CONNECT_FAILED);
1044                 vpn_provider_set_state(provider, VPN_PROVIDER_STATE_FAILURE);
1045         } else
1046                 g_dbus_send_reply(connection, pending, DBUS_TYPE_INVALID);
1047
1048         dbus_message_unref(pending);
1049 }
1050
1051 int __vpn_provider_connect(struct vpn_provider *provider, DBusMessage *msg)
1052 {
1053         int err;
1054
1055         DBG("provider %p", provider);
1056
1057         if (provider->driver != NULL && provider->driver->connect != NULL) {
1058                 dbus_message_ref(msg);
1059                 err = provider->driver->connect(provider, connect_cb, msg);
1060         } else
1061                 return -EOPNOTSUPP;
1062
1063         if (err == -EINPROGRESS)
1064                 vpn_provider_set_state(provider, VPN_PROVIDER_STATE_CONNECT);
1065
1066         return err;
1067 }
1068
1069 static void connection_removed_signal(struct vpn_provider *provider)
1070 {
1071         DBusMessage *signal;
1072         DBusMessageIter iter;
1073
1074         signal = dbus_message_new_signal(VPN_MANAGER_PATH,
1075                         VPN_MANAGER_INTERFACE, "ConnectionRemoved");
1076         if (signal == NULL)
1077                 return;
1078
1079         dbus_message_iter_init_append(signal, &iter);
1080         dbus_message_iter_append_basic(&iter, DBUS_TYPE_OBJECT_PATH,
1081                                                         &provider->path);
1082         dbus_connection_send(connection, signal, NULL);
1083         dbus_message_unref(signal);
1084 }
1085
1086 static char *get_ident(const char *path)
1087 {
1088         char *pos;
1089
1090         if (*path != '/')
1091                 return NULL;
1092
1093         pos = strrchr(path, '/');
1094         if (pos == NULL)
1095                 return NULL;
1096
1097         return pos + 1;
1098 }
1099
1100 int __vpn_provider_remove(const char *path)
1101 {
1102         struct vpn_provider *provider;
1103         char *ident;
1104
1105         DBG("path %s", path);
1106
1107         ident = get_ident(path);
1108
1109         provider = __vpn_provider_lookup(ident);
1110         if (provider != NULL)
1111                 return __vpn_provider_delete(provider);
1112
1113         return -ENXIO;
1114 }
1115
1116 int __vpn_provider_delete(struct vpn_provider *provider)
1117 {
1118         DBG("Deleting VPN %s", provider->identifier);
1119
1120         connection_removed_signal(provider);
1121
1122         provider_unregister(provider);
1123
1124         __connman_storage_remove_provider(provider->identifier);
1125
1126         g_hash_table_remove(provider_hash, provider->identifier);
1127
1128         return 0;
1129 }
1130
1131 static void append_ipv4(DBusMessageIter *iter, void *user_data)
1132 {
1133         struct vpn_provider *provider = user_data;
1134         const char *address, *gateway, *peer;
1135
1136         address = __vpn_ipconfig_get_local(provider->ipconfig_ipv4);
1137         if (address != NULL) {
1138                 in_addr_t addr;
1139                 struct in_addr netmask;
1140                 char *mask;
1141                 int prefixlen;
1142
1143                 prefixlen = __vpn_ipconfig_get_prefixlen(
1144                                                 provider->ipconfig_ipv4);
1145
1146                 addr = 0xffffffff << (32 - prefixlen);
1147                 netmask.s_addr = htonl(addr);
1148                 mask = inet_ntoa(netmask);
1149
1150                 connman_dbus_dict_append_basic(iter, "Address",
1151                                                 DBUS_TYPE_STRING, &address);
1152
1153                 connman_dbus_dict_append_basic(iter, "Netmask",
1154                                                 DBUS_TYPE_STRING, &mask);
1155         }
1156
1157         gateway = __vpn_ipconfig_get_gateway(provider->ipconfig_ipv4);
1158         if (gateway != NULL)
1159                 connman_dbus_dict_append_basic(iter, "Gateway",
1160                                                 DBUS_TYPE_STRING, &gateway);
1161
1162         peer = __vpn_ipconfig_get_peer(provider->ipconfig_ipv4);
1163         if (peer != NULL)
1164                 connman_dbus_dict_append_basic(iter, "Peer",
1165                                                 DBUS_TYPE_STRING, &peer);
1166 }
1167
1168 static void append_ipv6(DBusMessageIter *iter, void *user_data)
1169 {
1170         struct vpn_provider *provider = user_data;
1171         const char *address, *gateway, *peer;
1172
1173         address = __vpn_ipconfig_get_local(provider->ipconfig_ipv6);
1174         if (address != NULL) {
1175                 unsigned char prefixlen;
1176
1177                 connman_dbus_dict_append_basic(iter, "Address",
1178                                                 DBUS_TYPE_STRING, &address);
1179
1180                 prefixlen = __vpn_ipconfig_get_prefixlen(
1181                                                 provider->ipconfig_ipv6);
1182
1183                 connman_dbus_dict_append_basic(iter, "PrefixLength",
1184                                                 DBUS_TYPE_BYTE, &prefixlen);
1185         }
1186
1187         gateway = __vpn_ipconfig_get_gateway(provider->ipconfig_ipv6);
1188         if (gateway != NULL)
1189                 connman_dbus_dict_append_basic(iter, "Gateway",
1190                                                 DBUS_TYPE_STRING, &gateway);
1191
1192         peer = __vpn_ipconfig_get_peer(provider->ipconfig_ipv6);
1193         if (peer != NULL)
1194                 connman_dbus_dict_append_basic(iter, "Peer",
1195                                                 DBUS_TYPE_STRING, &peer);
1196 }
1197
1198 static const char *state2string(enum vpn_provider_state state)
1199 {
1200         switch (state) {
1201         case VPN_PROVIDER_STATE_UNKNOWN:
1202                 break;
1203         case VPN_PROVIDER_STATE_IDLE:
1204                 return "idle";
1205         case VPN_PROVIDER_STATE_CONNECT:
1206                 return "configuration";
1207         case VPN_PROVIDER_STATE_READY:
1208                 return "ready";
1209         case VPN_PROVIDER_STATE_DISCONNECT:
1210                 return "disconnect";
1211         case VPN_PROVIDER_STATE_FAILURE:
1212                 return "failure";
1213         }
1214
1215         return NULL;
1216 }
1217
1218 static int provider_indicate_state(struct vpn_provider *provider,
1219                                 enum vpn_provider_state state)
1220 {
1221         const char *str;
1222         enum vpn_provider_state old_state;
1223
1224         str = state2string(state);
1225         DBG("provider %p state %s/%d", provider, str, state);
1226         if (str == NULL)
1227                 return -EINVAL;
1228
1229         old_state = provider->state;
1230         provider->state = state;
1231
1232         if (state == VPN_PROVIDER_STATE_READY) {
1233                 connman_dbus_property_changed_basic(provider->path,
1234                                         VPN_CONNECTION_INTERFACE, "Index",
1235                                         DBUS_TYPE_INT32, &provider->index);
1236
1237                 if (provider->family == AF_INET)
1238                         connman_dbus_property_changed_dict(provider->path,
1239                                         VPN_CONNECTION_INTERFACE, "IPv4",
1240                                         append_ipv4, provider);
1241                 else if (provider->family == AF_INET6)
1242                         connman_dbus_property_changed_dict(provider->path,
1243                                         VPN_CONNECTION_INTERFACE, "IPv6",
1244                                         append_ipv6, provider);
1245         }
1246
1247         if (old_state != state)
1248                 connman_dbus_property_changed_basic(provider->path,
1249                                         VPN_CONNECTION_INTERFACE, "State",
1250                                         DBUS_TYPE_STRING, &str);
1251
1252         /*
1253          * We do not stay in failure state as clients like connmand can
1254          * get confused about our current state.
1255          */
1256         if (provider->state == VPN_PROVIDER_STATE_FAILURE)
1257                 provider->state = VPN_PROVIDER_STATE_IDLE;
1258
1259         return 0;
1260 }
1261
1262 static void append_nameservers(DBusMessageIter *iter, char **servers)
1263 {
1264         int i;
1265
1266         DBG("%p", servers);
1267
1268         for (i = 0; servers[i] != NULL; i++) {
1269                 DBG("servers[%d] %s", i, servers[i]);
1270                 dbus_message_iter_append_basic(iter,
1271                                         DBUS_TYPE_STRING, &servers[i]);
1272         }
1273 }
1274
1275 static void append_dns(DBusMessageIter *iter, void *user_data)
1276 {
1277         struct vpn_provider *provider = user_data;
1278
1279         if (provider->nameservers != NULL)
1280                 append_nameservers(iter, provider->nameservers);
1281 }
1282
1283 static void append_state(DBusMessageIter *iter,
1284                                         struct vpn_provider *provider)
1285 {
1286         char *str;
1287
1288         switch (provider->state) {
1289         case VPN_PROVIDER_STATE_UNKNOWN:
1290         case VPN_PROVIDER_STATE_IDLE:
1291                 str = "idle";
1292                 break;
1293         case VPN_PROVIDER_STATE_CONNECT:
1294                 str = "configuration";
1295                 break;
1296         case VPN_PROVIDER_STATE_READY:
1297                 str = "ready";
1298                 break;
1299         case VPN_PROVIDER_STATE_DISCONNECT:
1300                 str = "disconnect";
1301                 break;
1302         case VPN_PROVIDER_STATE_FAILURE:
1303                 str = "failure";
1304                 break;
1305         }
1306
1307         connman_dbus_dict_append_basic(iter, "State",
1308                                 DBUS_TYPE_STRING, &str);
1309 }
1310
1311 static void append_properties(DBusMessageIter *iter,
1312                                         struct vpn_provider *provider)
1313 {
1314         DBusMessageIter dict;
1315         GHashTableIter hash;
1316         gpointer value, key;
1317
1318         connman_dbus_dict_open(iter, &dict);
1319
1320         append_state(&dict, provider);
1321
1322         if (provider->type != NULL)
1323                 connman_dbus_dict_append_basic(&dict, "Type",
1324                                         DBUS_TYPE_STRING, &provider->type);
1325
1326         if (provider->name != NULL)
1327                 connman_dbus_dict_append_basic(&dict, "Name",
1328                                         DBUS_TYPE_STRING, &provider->name);
1329
1330         if (provider->host != NULL)
1331                 connman_dbus_dict_append_basic(&dict, "Host",
1332                                         DBUS_TYPE_STRING, &provider->host);
1333         if (provider->index >= 0)
1334                 connman_dbus_dict_append_basic(&dict, "Index",
1335                                         DBUS_TYPE_INT32, &provider->index);
1336         if (provider->domain != NULL)
1337                 connman_dbus_dict_append_basic(&dict, "Domain",
1338                                         DBUS_TYPE_STRING, &provider->domain);
1339
1340         if (provider->family == AF_INET)
1341                 connman_dbus_dict_append_dict(&dict, "IPv4", append_ipv4,
1342                                                 provider);
1343         else if (provider->family == AF_INET6)
1344                 connman_dbus_dict_append_dict(&dict, "IPv6", append_ipv6,
1345                                                 provider);
1346
1347         connman_dbus_dict_append_array(&dict, "Nameservers",
1348                                 DBUS_TYPE_STRING, append_dns, provider);
1349
1350         connman_dbus_dict_append_array(&dict, "UserRoutes",
1351                                 DBUS_TYPE_DICT_ENTRY, append_routes,
1352                                 provider->user_routes);
1353
1354         connman_dbus_dict_append_array(&dict, "ServerRoutes",
1355                                 DBUS_TYPE_DICT_ENTRY, append_routes,
1356                                 provider->routes);
1357
1358         if (provider->setting_strings != NULL) {
1359                 g_hash_table_iter_init(&hash, provider->setting_strings);
1360
1361                 while (g_hash_table_iter_next(&hash, &key, &value) == TRUE) {
1362                         struct vpn_setting *setting = value;
1363
1364                         if (setting->hide_value == FALSE &&
1365                                                         setting->value != NULL)
1366                                 connman_dbus_dict_append_basic(&dict, key,
1367                                                         DBUS_TYPE_STRING,
1368                                                         &setting->value);
1369                 }
1370         }
1371
1372         connman_dbus_dict_close(iter, &dict);
1373 }
1374
1375 static void connection_added_signal(struct vpn_provider *provider)
1376 {
1377         DBusMessage *signal;
1378         DBusMessageIter iter;
1379
1380         signal = dbus_message_new_signal(VPN_MANAGER_PATH,
1381                         VPN_MANAGER_INTERFACE, "ConnectionAdded");
1382         if (signal == NULL)
1383                 return;
1384
1385         dbus_message_iter_init_append(signal, &iter);
1386         dbus_message_iter_append_basic(&iter, DBUS_TYPE_OBJECT_PATH,
1387                                                         &provider->path);
1388         append_properties(&iter, provider);
1389
1390         dbus_connection_send(connection, signal, NULL);
1391         dbus_message_unref(signal);
1392 }
1393
1394 static connman_bool_t check_host(char **hosts, char *host)
1395 {
1396         int i;
1397
1398         if (hosts == NULL)
1399                 return FALSE;
1400
1401         for (i = 0; hosts[i] != NULL; i++) {
1402                 if (g_strcmp0(hosts[i], host) == 0)
1403                         return TRUE;
1404         }
1405
1406         return FALSE;
1407 }
1408
1409 static void provider_append_routes(gpointer key, gpointer value,
1410                                         gpointer user_data)
1411 {
1412         struct vpn_route *route = value;
1413         struct vpn_provider *provider = user_data;
1414         int index = provider->index;
1415
1416         if (handle_routes == FALSE)
1417                 return;
1418
1419         /*
1420          * If the VPN administrator/user has given a route to
1421          * VPN server, then we must discard that because the
1422          * server cannot be contacted via VPN tunnel.
1423          */
1424         if (check_host(provider->host_ip, route->network) == TRUE) {
1425                 DBG("Discarding VPN route to %s via %s at index %d",
1426                         route->network, route->gateway, index);
1427                 return;
1428         }
1429
1430         if (route->family == AF_INET6) {
1431                 unsigned char prefix_len = atoi(route->netmask);
1432
1433                 connman_inet_add_ipv6_network_route(index, route->network,
1434                                                         route->gateway,
1435                                                         prefix_len);
1436         } else {
1437                 connman_inet_add_network_route(index, route->network,
1438                                                 route->gateway,
1439                                                 route->netmask);
1440         }
1441 }
1442
1443 static int set_connected(struct vpn_provider *provider,
1444                                         connman_bool_t connected)
1445 {
1446         struct vpn_ipconfig *ipconfig;
1447
1448         DBG("provider %p id %s connected %d", provider,
1449                                         provider->identifier, connected);
1450
1451         if (connected == TRUE) {
1452                 if (provider->family == AF_INET6)
1453                         ipconfig = provider->ipconfig_ipv6;
1454                 else
1455                         ipconfig = provider->ipconfig_ipv4;
1456
1457                 __vpn_ipconfig_address_add(ipconfig, provider->family);
1458
1459                 if (handle_routes == TRUE)
1460                         __vpn_ipconfig_gateway_add(ipconfig, provider->family);
1461
1462                 provider_indicate_state(provider,
1463                                         VPN_PROVIDER_STATE_READY);
1464
1465                 g_hash_table_foreach(provider->routes, provider_append_routes,
1466                                         provider);
1467
1468                 g_hash_table_foreach(provider->user_routes,
1469                                         provider_append_routes, provider);
1470
1471         } else {
1472                 provider_indicate_state(provider,
1473                                         VPN_PROVIDER_STATE_DISCONNECT);
1474
1475                 provider_indicate_state(provider,
1476                                         VPN_PROVIDER_STATE_IDLE);
1477         }
1478
1479         return 0;
1480 }
1481
1482 int vpn_provider_set_state(struct vpn_provider *provider,
1483                                         enum vpn_provider_state state)
1484 {
1485         if (provider == NULL)
1486                 return -EINVAL;
1487
1488         switch (state) {
1489         case VPN_PROVIDER_STATE_UNKNOWN:
1490                 return -EINVAL;
1491         case VPN_PROVIDER_STATE_IDLE:
1492                 return set_connected(provider, FALSE);
1493         case VPN_PROVIDER_STATE_CONNECT:
1494                 return provider_indicate_state(provider, state);
1495         case VPN_PROVIDER_STATE_READY:
1496                 return set_connected(provider, TRUE);
1497         case VPN_PROVIDER_STATE_DISCONNECT:
1498                 return provider_indicate_state(provider, state);
1499         case VPN_PROVIDER_STATE_FAILURE:
1500                 return provider_indicate_state(provider, state);
1501         }
1502         return -EINVAL;
1503 }
1504
1505 int vpn_provider_indicate_error(struct vpn_provider *provider,
1506                                         enum vpn_provider_error error)
1507 {
1508         DBG("provider %p id %s error %d", provider, provider->identifier,
1509                                                                         error);
1510
1511         switch (error) {
1512         case VPN_PROVIDER_ERROR_LOGIN_FAILED:
1513                 break;
1514         case VPN_PROVIDER_ERROR_AUTH_FAILED:
1515                 vpn_provider_set_state(provider, VPN_PROVIDER_STATE_FAILURE);
1516                 break;
1517         case VPN_PROVIDER_ERROR_CONNECT_FAILED:
1518                 break;
1519         default:
1520                 break;
1521         }
1522
1523         return 0;
1524 }
1525
1526 static int connection_unregister(struct vpn_provider *provider)
1527 {
1528         DBG("provider %p path %s", provider, provider->path);
1529
1530         if (provider->path == NULL)
1531                 return -EALREADY;
1532
1533         g_dbus_unregister_interface(connection, provider->path,
1534                                 VPN_CONNECTION_INTERFACE);
1535
1536         g_free(provider->path);
1537         provider->path = NULL;
1538
1539         return 0;
1540 }
1541
1542 static int connection_register(struct vpn_provider *provider)
1543 {
1544         DBG("provider %p path %s", provider, provider->path);
1545
1546         if (provider->path != NULL)
1547                 return -EALREADY;
1548
1549         provider->path = g_strdup_printf("%s/connection/%s", VPN_PATH,
1550                                                 provider->identifier);
1551
1552         g_dbus_register_interface(connection, provider->path,
1553                                 VPN_CONNECTION_INTERFACE,
1554                                 connection_methods, connection_signals,
1555                                 NULL, provider, NULL);
1556
1557         return 0;
1558 }
1559
1560 static void unregister_provider(gpointer data)
1561 {
1562         struct vpn_provider *provider = data;
1563
1564         configuration_count_del();
1565
1566         connection_unregister(provider);
1567
1568         vpn_provider_unref(provider);
1569 }
1570
1571 static void provider_initialize(struct vpn_provider *provider)
1572 {
1573         DBG("provider %p", provider);
1574
1575         provider->index = 0;
1576         provider->fd = -1;
1577         provider->name = NULL;
1578         provider->type = NULL;
1579         provider->domain = NULL;
1580         provider->identifier = NULL;
1581         provider->user_networks = NULL;
1582         provider->routes = g_hash_table_new_full(g_direct_hash, g_direct_equal,
1583                                         NULL, free_route);
1584         provider->user_routes = g_hash_table_new_full(g_str_hash, g_str_equal,
1585                                         g_free, free_route);
1586         provider->setting_strings = g_hash_table_new_full(g_str_hash,
1587                                         g_str_equal, g_free, free_setting);
1588 }
1589
1590 static struct vpn_provider *vpn_provider_new(void)
1591 {
1592         struct vpn_provider *provider;
1593
1594         provider = g_try_new0(struct vpn_provider, 1);
1595         if (provider == NULL)
1596                 return NULL;
1597
1598         provider->refcount = 1;
1599
1600         DBG("provider %p", provider);
1601         provider_initialize(provider);
1602
1603         return provider;
1604 }
1605
1606 static struct vpn_provider *vpn_provider_get(const char *identifier)
1607 {
1608         struct vpn_provider *provider;
1609
1610         provider = g_hash_table_lookup(provider_hash, identifier);
1611         if (provider != NULL)
1612                 return provider;
1613
1614         provider = vpn_provider_new();
1615         if (provider == NULL)
1616                 return NULL;
1617
1618         DBG("provider %p", provider);
1619
1620         provider->identifier = g_strdup(identifier);
1621
1622         g_hash_table_insert(provider_hash, provider->identifier, provider);
1623
1624         configuration_count_add();
1625
1626         return provider;
1627 }
1628
1629 static void provider_dbus_ident(char *ident)
1630 {
1631         int i, len = strlen(ident);
1632
1633         for (i = 0; i < len; i++) {
1634                 if (ident[i] >= '0' && ident[i] <= '9')
1635                         continue;
1636                 if (ident[i] >= 'a' && ident[i] <= 'z')
1637                         continue;
1638                 if (ident[i] >= 'A' && ident[i] <= 'Z')
1639                         continue;
1640                 ident[i] = '_';
1641         }
1642 }
1643
1644 static struct vpn_provider *provider_create_from_keyfile(GKeyFile *keyfile,
1645                 const char *ident)
1646 {
1647         struct vpn_provider *provider;
1648
1649         if (keyfile == NULL || ident == NULL)
1650                 return NULL;
1651
1652         provider = __vpn_provider_lookup(ident);
1653         if (provider == NULL) {
1654                 provider = vpn_provider_get(ident);
1655                 if (provider == NULL) {
1656                         DBG("can not create provider");
1657                         return NULL;
1658                 }
1659
1660                 provider_load_from_keyfile(provider, keyfile);
1661
1662                 if (provider->name == NULL || provider->host == NULL ||
1663                                 provider->domain == NULL) {
1664                         DBG("cannot get name, host or domain");
1665                         vpn_provider_unref(provider);
1666                         return NULL;
1667                 }
1668
1669                 if (provider_register(provider) == 0)
1670                         connection_register(provider);
1671         }
1672         return provider;
1673 }
1674
1675 static void provider_create_all_from_type(const char *provider_type)
1676 {
1677         unsigned int i;
1678         char **providers;
1679         char *id, *type;
1680         GKeyFile *keyfile;
1681
1682         DBG("provider type %s", provider_type);
1683
1684         providers = __connman_storage_get_providers();
1685
1686         if (providers == NULL)
1687                 return;
1688
1689         for (i = 0; providers[i] != NULL; i+=1) {
1690
1691                 if (strncmp(providers[i], "provider_", 9) != 0)
1692                         continue;
1693
1694                 id = providers[i] + 9;
1695                 keyfile = __connman_storage_load_provider(id);
1696
1697                 if (keyfile == NULL)
1698                         continue;
1699
1700                 type = g_key_file_get_string(keyfile, id, "Type", NULL);
1701
1702                 DBG("keyfile %p id %s type %s", keyfile, id, type);
1703
1704                 if (strcmp(provider_type, type) != 0) {
1705                         g_free(type);
1706                         g_key_file_free(keyfile);
1707                         continue;
1708                 }
1709
1710                 if (provider_create_from_keyfile(keyfile, id) == NULL)
1711                         DBG("could not create provider");
1712
1713                 g_free(type);
1714                 g_key_file_free(keyfile);
1715         }
1716         g_strfreev(providers);
1717 }
1718
1719 char *__vpn_provider_create_identifier(const char *host, const char *domain)
1720 {
1721         char *ident;
1722
1723         ident = g_strdup_printf("%s_%s", host, domain);
1724         if (ident == NULL)
1725                 return NULL;
1726
1727         provider_dbus_ident(ident);
1728
1729         return ident;
1730 }
1731
1732 int __vpn_provider_create(DBusMessage *msg)
1733 {
1734         struct vpn_provider *provider;
1735         DBusMessageIter iter, array;
1736         const char *type = NULL, *name = NULL;
1737         const char *host = NULL, *domain = NULL;
1738         GSList *networks = NULL;
1739         char *ident;
1740         int err;
1741
1742         dbus_message_iter_init(msg, &iter);
1743         dbus_message_iter_recurse(&iter, &array);
1744
1745         while (dbus_message_iter_get_arg_type(&array) == DBUS_TYPE_DICT_ENTRY) {
1746                 DBusMessageIter entry, value;
1747                 const char *key;
1748
1749                 dbus_message_iter_recurse(&array, &entry);
1750                 dbus_message_iter_get_basic(&entry, &key);
1751
1752                 dbus_message_iter_next(&entry);
1753                 dbus_message_iter_recurse(&entry, &value);
1754
1755                 switch (dbus_message_iter_get_arg_type(&value)) {
1756                 case DBUS_TYPE_STRING:
1757                         if (g_str_equal(key, "Type") == TRUE)
1758                                 dbus_message_iter_get_basic(&value, &type);
1759                         else if (g_str_equal(key, "Name") == TRUE)
1760                                 dbus_message_iter_get_basic(&value, &name);
1761                         else if (g_str_equal(key, "Host") == TRUE)
1762                                 dbus_message_iter_get_basic(&value, &host);
1763                         else if (g_str_equal(key, "VPN.Domain") == TRUE ||
1764                                         g_str_equal(key, "Domain") == TRUE)
1765                                 dbus_message_iter_get_basic(&value, &domain);
1766                         break;
1767                 case DBUS_TYPE_ARRAY:
1768                         if (g_str_equal(key, "UserRoutes") == TRUE)
1769                                 networks = get_user_networks(&value);
1770                         break;
1771                 }
1772
1773                 dbus_message_iter_next(&array);
1774         }
1775
1776         if (host == NULL || domain == NULL)
1777                 return -EINVAL;
1778
1779         DBG("Type %s name %s networks %p", type, name, networks);
1780
1781         if (type == NULL || name == NULL)
1782                 return -EOPNOTSUPP;
1783
1784         ident = __vpn_provider_create_identifier(host, domain);
1785         DBG("ident %s", ident);
1786
1787         provider = __vpn_provider_lookup(ident);
1788         if (provider == NULL) {
1789                 provider = vpn_provider_get(ident);
1790                 if (provider == NULL) {
1791                         DBG("can not create provider");
1792                         g_free(ident);
1793                         return -EOPNOTSUPP;
1794                 }
1795
1796                 provider->host = g_strdup(host);
1797                 provider->domain = g_strdup(domain);
1798                 provider->name = g_strdup(name);
1799                 provider->type = g_strdup(type);
1800
1801                 if (provider_register(provider) == 0)
1802                         vpn_provider_load(provider);
1803
1804                 provider_resolv_host_addr(provider);
1805         }
1806
1807         if (networks != NULL) {
1808                 g_slist_free_full(provider->user_networks, free_route);
1809                 provider->user_networks = networks;
1810                 set_user_networks(provider, provider->user_networks);
1811         }
1812
1813         dbus_message_iter_init(msg, &iter);
1814         dbus_message_iter_recurse(&iter, &array);
1815
1816         while (dbus_message_iter_get_arg_type(&array) == DBUS_TYPE_DICT_ENTRY) {
1817                 DBusMessageIter entry, value;
1818                 const char *key, *str;
1819
1820                 dbus_message_iter_recurse(&array, &entry);
1821                 dbus_message_iter_get_basic(&entry, &key);
1822
1823                 dbus_message_iter_next(&entry);
1824                 dbus_message_iter_recurse(&entry, &value);
1825
1826                 switch (dbus_message_iter_get_arg_type(&value)) {
1827                 case DBUS_TYPE_STRING:
1828                         dbus_message_iter_get_basic(&value, &str);
1829                         vpn_provider_set_string(provider, key, str);
1830                         break;
1831                 }
1832
1833                 dbus_message_iter_next(&array);
1834         }
1835
1836         g_free(ident);
1837
1838         vpn_provider_save(provider);
1839
1840         err = provider_register(provider);
1841         if (err != 0 && err != -EALREADY)
1842                 return err;
1843
1844         connection_register(provider);
1845
1846         DBG("provider %p index %d path %s", provider, provider->index,
1847                                                         provider->path);
1848
1849         g_dbus_send_reply(connection, msg,
1850                                 DBUS_TYPE_OBJECT_PATH, &provider->path,
1851                                 DBUS_TYPE_INVALID);
1852
1853         connection_added_signal(provider);
1854
1855         return 0;
1856 }
1857
1858 static const char *get_string(GHashTable *settings, const char *key)
1859 {
1860         DBG("settings %p key %s", settings, key);
1861
1862         return g_hash_table_lookup(settings, key);
1863 }
1864
1865 static GSList *parse_user_networks(const char *network_str)
1866 {
1867         GSList *networks = NULL;
1868         char **elems = g_strsplit(network_str, ",", 0);
1869         int i = 0;
1870
1871         if (elems == NULL)
1872                 return NULL;
1873
1874         while (elems[i] != NULL) {
1875                 struct vpn_route *vpn_route;
1876                 char *network, *netmask, *gateway;
1877                 int family;
1878                 char **route;
1879
1880                 route = g_strsplit(elems[i], "/", 0);
1881                 if (route == NULL)
1882                         goto next;
1883
1884                 network = route[0];
1885                 if (network == NULL || network[0] == '\0')
1886                         goto next;
1887
1888                 family = connman_inet_check_ipaddress(network);
1889                 if (family < 0) {
1890                         DBG("Cannot get address family of %s (%d/%s)", network,
1891                                 family, gai_strerror(family));
1892
1893                         goto next;
1894                 }
1895
1896                 switch (family) {
1897                 case AF_INET:
1898                         break;
1899                 case AF_INET6:
1900                         break;
1901                 default:
1902                         DBG("Unsupported address family %d", family);
1903                         goto next;
1904                 }
1905
1906                 netmask = route[1];
1907                 if (netmask == NULL || netmask[0] == '\0')
1908                         goto next;
1909
1910                 gateway = route[2];
1911
1912                 vpn_route = g_try_new0(struct vpn_route, 1);
1913                 if (vpn_route == NULL) {
1914                         g_strfreev(route);
1915                         break;
1916                 }
1917
1918                 vpn_route->family = family;
1919                 vpn_route->network = g_strdup(network);
1920                 vpn_route->netmask = g_strdup(netmask);
1921                 vpn_route->gateway = g_strdup(gateway);
1922
1923                 DBG("route %s/%s%s%s", network, netmask,
1924                         gateway ? " via " : "", gateway ? gateway : "");
1925
1926                 networks = g_slist_prepend(networks, vpn_route);
1927
1928         next:
1929                 g_strfreev(route);
1930                 i++;
1931         }
1932
1933         g_strfreev(elems);
1934
1935         return g_slist_reverse(networks);
1936 }
1937
1938 int __vpn_provider_create_from_config(GHashTable *settings,
1939                                 const char *config_ident,
1940                                 const char *config_entry)
1941 {
1942         struct vpn_provider *provider;
1943         const char *type, *name, *host, *domain, *networks_str;
1944         GSList *networks;
1945         char *ident = NULL;
1946         GHashTableIter hash;
1947         gpointer value, key;
1948         int err;
1949
1950         type = get_string(settings, "Type");
1951         name = get_string(settings, "Name");
1952         host = get_string(settings, "Host");
1953         domain = get_string(settings, "Domain");
1954         networks_str = get_string(settings, "Networks");
1955         networks = parse_user_networks(networks_str);
1956
1957         if (host == NULL || domain == NULL) {
1958                 err = -EINVAL;
1959                 goto fail;
1960         }
1961
1962         DBG("type %s name %s networks %s", type, name, networks_str);
1963
1964         if (type == NULL || name == NULL) {
1965                 err = -EOPNOTSUPP;
1966                 goto fail;
1967         }
1968
1969         ident = __vpn_provider_create_identifier(host, domain);
1970         DBG("ident %s", ident);
1971
1972         provider = __vpn_provider_lookup(ident);
1973         if (provider == NULL) {
1974                 provider = vpn_provider_get(ident);
1975                 if (provider == NULL) {
1976                         DBG("can not create provider");
1977                         err = -EOPNOTSUPP;
1978                         goto fail;
1979                 }
1980
1981                 provider->host = g_strdup(host);
1982                 provider->domain = g_strdup(domain);
1983                 provider->name = g_strdup(name);
1984                 provider->type = g_ascii_strdown(type, -1);
1985
1986                 provider->config_file = g_strdup(config_ident);
1987                 provider->config_entry = g_strdup(config_entry);
1988
1989                 if (provider_register(provider) == 0)
1990                         vpn_provider_load(provider);
1991
1992                 provider_resolv_host_addr(provider);
1993         }
1994
1995         if (networks != NULL) {
1996                 g_slist_free_full(provider->user_networks, free_route);
1997                 provider->user_networks = networks;
1998                 set_user_networks(provider, provider->user_networks);
1999         }
2000
2001         g_hash_table_iter_init(&hash, settings);
2002
2003         while (g_hash_table_iter_next(&hash, &key, &value) == TRUE)
2004                 vpn_provider_set_string(provider, key, value);
2005
2006         vpn_provider_save(provider);
2007
2008         err = provider_register(provider);
2009         if (err != 0 && err != -EALREADY)
2010                 goto fail;
2011
2012         connection_register(provider);
2013
2014         DBG("provider %p index %d path %s", provider, provider->index,
2015                                                         provider->path);
2016
2017         connection_added_signal(provider);
2018
2019         g_free(ident);
2020
2021         return 0;
2022
2023 fail:
2024         g_free(ident);
2025         g_slist_free_full(networks, free_route);
2026
2027         return err;
2028 }
2029
2030 static void append_connection_structs(DBusMessageIter *iter, void *user_data)
2031 {
2032         DBusMessageIter entry;
2033         GHashTableIter hash;
2034         gpointer value, key;
2035
2036         g_hash_table_iter_init(&hash, provider_hash);
2037
2038         while (g_hash_table_iter_next(&hash, &key, &value) == TRUE) {
2039                 struct vpn_provider *provider = value;
2040
2041                 DBG("path %s", provider->path);
2042
2043                 if (provider->identifier == NULL)
2044                         continue;
2045
2046                 dbus_message_iter_open_container(iter, DBUS_TYPE_STRUCT,
2047                                 NULL, &entry);
2048                 dbus_message_iter_append_basic(&entry, DBUS_TYPE_OBJECT_PATH,
2049                                 &provider->path);
2050                 append_properties(&entry, provider);
2051                 dbus_message_iter_close_container(iter, &entry);
2052         }
2053 }
2054
2055 DBusMessage *__vpn_provider_get_connections(DBusMessage *msg)
2056 {
2057         DBusMessage *reply;
2058
2059         DBG("");
2060
2061         reply = dbus_message_new_method_return(msg);
2062         if (reply == NULL)
2063                 return NULL;
2064
2065         __connman_dbus_append_objpath_dict_array(reply,
2066                         append_connection_structs, NULL);
2067
2068         return reply;
2069 }
2070
2071 const char * __vpn_provider_get_ident(struct vpn_provider *provider)
2072 {
2073         if (provider == NULL)
2074                 return NULL;
2075
2076         return provider->identifier;
2077 }
2078
2079 static int set_string(struct vpn_provider *provider,
2080                 const char *key, const char *value, gboolean hide_value)
2081 {
2082         DBG("provider %p key %s value %s", provider, key,
2083                 hide_value ? "<not printed>" : value);
2084
2085         if (g_str_equal(key, "Type") == TRUE) {
2086                 g_free(provider->type);
2087                 provider->type = g_ascii_strdown(value, -1);
2088                 send_value(provider->path, "Type", provider->type);
2089         } else if (g_str_equal(key, "Name") == TRUE) {
2090                 g_free(provider->name);
2091                 provider->name = g_strdup(value);
2092                 send_value(provider->path, "Name", provider->name);
2093         } else if (g_str_equal(key, "Host") == TRUE) {
2094                 g_free(provider->host);
2095                 provider->host = g_strdup(value);
2096                 send_value(provider->path, "Host", provider->host);
2097         } else if (g_str_equal(key, "VPN.Domain") == TRUE ||
2098                         g_str_equal(key, "Domain") == TRUE) {
2099                 g_free(provider->domain);
2100                 provider->domain = g_strdup(value);
2101                 send_value(provider->path, "Domain", provider->domain);
2102         } else {
2103                 struct vpn_setting *setting;
2104
2105                 setting = g_try_new(struct vpn_setting, 1);
2106                 if (setting == NULL)
2107                         return -ENOMEM;
2108
2109                 setting->value = g_strdup(value);
2110                 setting->hide_value = hide_value;
2111
2112                 if (hide_value == FALSE)
2113                         send_value(provider->path, key, setting->value);
2114
2115                 g_hash_table_replace(provider->setting_strings,
2116                                 g_strdup(key), setting);
2117         }
2118
2119         return 0;
2120 }
2121
2122 int vpn_provider_set_string(struct vpn_provider *provider,
2123                                         const char *key, const char *value)
2124 {
2125         return set_string(provider, key, value, FALSE);
2126 }
2127
2128 int vpn_provider_set_string_hide_value(struct vpn_provider *provider,
2129                                         const char *key, const char *value)
2130 {
2131         return set_string(provider, key, value, TRUE);
2132 }
2133
2134 const char *vpn_provider_get_string(struct vpn_provider *provider,
2135                                                         const char *key)
2136 {
2137         struct vpn_setting *setting;
2138
2139         DBG("provider %p key %s", provider, key);
2140
2141         if (g_str_equal(key, "Type") == TRUE)
2142                 return provider->type;
2143         else if (g_str_equal(key, "Name") == TRUE)
2144                 return provider->name;
2145         else if (g_str_equal(key, "Host") == TRUE)
2146                 return provider->host;
2147         else if (g_str_equal(key, "HostIP") == TRUE) {
2148                 if (provider->host_ip == NULL ||
2149                                 provider->host_ip[0] == NULL)
2150                         return provider->host;
2151                 else
2152                         return provider->host_ip[0];
2153         } else if (g_str_equal(key, "VPN.Domain") == TRUE ||
2154                         g_str_equal(key, "Domain") == TRUE)
2155                 return provider->domain;
2156
2157         setting = g_hash_table_lookup(provider->setting_strings, key);
2158         if (setting == NULL)
2159                 return NULL;
2160
2161         return setting->value;
2162 }
2163
2164 connman_bool_t __vpn_provider_check_routes(struct vpn_provider *provider)
2165 {
2166         if (provider == NULL)
2167                 return FALSE;
2168
2169         if (provider->user_routes != NULL &&
2170                         g_hash_table_size(provider->user_routes) > 0)
2171                 return TRUE;
2172
2173         if (provider->routes != NULL &&
2174                         g_hash_table_size(provider->routes) > 0)
2175                 return TRUE;
2176
2177         return FALSE;
2178 }
2179
2180 void *vpn_provider_get_data(struct vpn_provider *provider)
2181 {
2182         return provider->driver_data;
2183 }
2184
2185 void vpn_provider_set_data(struct vpn_provider *provider, void *data)
2186 {
2187         provider->driver_data = data;
2188 }
2189
2190 void vpn_provider_set_index(struct vpn_provider *provider, int index)
2191 {
2192         DBG("index %d provider %p", index, provider);
2193
2194         if (provider->ipconfig_ipv4 == NULL) {
2195                 provider->ipconfig_ipv4 = __vpn_ipconfig_create(index,
2196                                                                 AF_INET);
2197                 if (provider->ipconfig_ipv4 == NULL) {
2198                         DBG("Couldnt create ipconfig for IPv4");
2199                         goto done;
2200                 }
2201         }
2202
2203         __vpn_ipconfig_set_index(provider->ipconfig_ipv4, index);
2204
2205         if (provider->ipconfig_ipv6 == NULL) {
2206                 provider->ipconfig_ipv6 = __vpn_ipconfig_create(index,
2207                                                                 AF_INET6);
2208                 if (provider->ipconfig_ipv6 == NULL) {
2209                         DBG("Couldnt create ipconfig for IPv6");
2210                         goto done;
2211                 }
2212         }
2213
2214         __vpn_ipconfig_set_index(provider->ipconfig_ipv6, index);
2215
2216 done:
2217         provider->index = index;
2218 }
2219
2220 int vpn_provider_get_index(struct vpn_provider *provider)
2221 {
2222         return provider->index;
2223 }
2224
2225 int vpn_provider_set_ipaddress(struct vpn_provider *provider,
2226                                         struct connman_ipaddress *ipaddress)
2227 {
2228         struct vpn_ipconfig *ipconfig = NULL;
2229
2230         switch (ipaddress->family) {
2231         case AF_INET:
2232                 ipconfig = provider->ipconfig_ipv4;
2233                 break;
2234         case AF_INET6:
2235                 ipconfig = provider->ipconfig_ipv6;
2236                 break;
2237         default:
2238                 break;
2239         }
2240
2241         DBG("provider %p ipconfig %p family %d", provider, ipconfig,
2242                                                         ipaddress->family);
2243
2244         if (ipconfig == NULL)
2245                 return -EINVAL;
2246
2247         provider->family = ipaddress->family;
2248
2249         __vpn_ipconfig_set_local(ipconfig, ipaddress->local);
2250         __vpn_ipconfig_set_peer(ipconfig, ipaddress->peer);
2251         __vpn_ipconfig_set_broadcast(ipconfig, ipaddress->broadcast);
2252         __vpn_ipconfig_set_gateway(ipconfig, ipaddress->gateway);
2253         __vpn_ipconfig_set_prefixlen(ipconfig, ipaddress->prefixlen);
2254
2255         return 0;
2256 }
2257
2258 int vpn_provider_set_pac(struct vpn_provider *provider,
2259                                 const char *pac)
2260 {
2261         DBG("provider %p pac %s", provider, pac);
2262
2263         return 0;
2264 }
2265
2266
2267 int vpn_provider_set_domain(struct vpn_provider *provider,
2268                                         const char *domain)
2269 {
2270         DBG("provider %p domain %s", provider, domain);
2271
2272         g_free(provider->domain);
2273         provider->domain = g_strdup(domain);
2274
2275         return 0;
2276 }
2277
2278 int vpn_provider_set_nameservers(struct vpn_provider *provider,
2279                                         const char *nameservers)
2280 {
2281         DBG("provider %p nameservers %s", provider, nameservers);
2282
2283         g_strfreev(provider->nameservers);
2284         provider->nameservers = NULL;
2285
2286         if (nameservers == NULL)
2287                 return 0;
2288
2289         provider->nameservers = g_strsplit(nameservers, " ", 0);
2290
2291         return 0;
2292 }
2293
2294 enum provider_route_type {
2295         PROVIDER_ROUTE_TYPE_NONE = 0,
2296         PROVIDER_ROUTE_TYPE_MASK = 1,
2297         PROVIDER_ROUTE_TYPE_ADDR = 2,
2298         PROVIDER_ROUTE_TYPE_GW   = 3,
2299 };
2300
2301 static int route_env_parse(struct vpn_provider *provider, const char *key,
2302                                 int *family, unsigned long *idx,
2303                                 enum provider_route_type *type)
2304 {
2305         char *end;
2306         const char *start;
2307
2308         DBG("name %s", provider->name);
2309
2310         if (!strcmp(provider->type, "openvpn")) {
2311                 if (g_str_has_prefix(key, "route_network_") == TRUE) {
2312                         start = key + strlen("route_network_");
2313                         *type = PROVIDER_ROUTE_TYPE_ADDR;
2314                 } else if (g_str_has_prefix(key, "route_netmask_") == TRUE) {
2315                         start = key + strlen("route_netmask_");
2316                         *type = PROVIDER_ROUTE_TYPE_MASK;
2317                 } else if (g_str_has_prefix(key, "route_gateway_") == TRUE) {
2318                         start = key + strlen("route_gateway_");
2319                         *type = PROVIDER_ROUTE_TYPE_GW;
2320                 } else
2321                         return -EINVAL;
2322
2323                 *family = AF_INET;
2324                 *idx = g_ascii_strtoull(start, &end, 10);
2325
2326         } else if (!strcmp(provider->type, "openconnect")) {
2327                 if (g_str_has_prefix(key, "CISCO_SPLIT_INC_") == TRUE) {
2328                         *family = AF_INET;
2329                         start = key + strlen("CISCO_SPLIT_INC_");
2330                 } else if (g_str_has_prefix(key,
2331                                         "CISCO_IPV6_SPLIT_INC_") == TRUE) {
2332                         *family = AF_INET6;
2333                         start = key + strlen("CISCO_IPV6_SPLIT_INC_");
2334                 } else
2335                         return -EINVAL;
2336
2337                 *idx = g_ascii_strtoull(start, &end, 10);
2338
2339                 if (strncmp(end, "_ADDR", 5) == 0)
2340                         *type = PROVIDER_ROUTE_TYPE_ADDR;
2341                 else if (strncmp(end, "_MASK", 5) == 0)
2342                         *type = PROVIDER_ROUTE_TYPE_MASK;
2343                 else if (strncmp(end, "_MASKLEN", 8) == 0 &&
2344                                 *family == AF_INET6) {
2345                         *type = PROVIDER_ROUTE_TYPE_MASK;
2346                 } else
2347                         return -EINVAL;
2348         }
2349
2350         return 0;
2351 }
2352
2353 int vpn_provider_append_route(struct vpn_provider *provider,
2354                                         const char *key, const char *value)
2355 {
2356         struct vpn_route *route;
2357         int ret, family = 0;
2358         unsigned long idx = 0;
2359         enum provider_route_type type = PROVIDER_ROUTE_TYPE_NONE;
2360
2361         DBG("key %s value %s", key, value);
2362
2363         ret = route_env_parse(provider, key, &family, &idx, &type);
2364         if (ret < 0)
2365                 return ret;
2366
2367         DBG("idx %lu family %d type %d", idx, family, type);
2368
2369         route = g_hash_table_lookup(provider->routes, GINT_TO_POINTER(idx));
2370         if (route == NULL) {
2371                 route = g_try_new0(struct vpn_route, 1);
2372                 if (route == NULL) {
2373                         connman_error("out of memory");
2374                         return -ENOMEM;
2375                 }
2376
2377                 route->family = family;
2378
2379                 g_hash_table_replace(provider->routes, GINT_TO_POINTER(idx),
2380                                                 route);
2381         }
2382
2383         switch (type) {
2384         case PROVIDER_ROUTE_TYPE_NONE:
2385                 break;
2386         case PROVIDER_ROUTE_TYPE_MASK:
2387                 route->netmask = g_strdup(value);
2388                 break;
2389         case PROVIDER_ROUTE_TYPE_ADDR:
2390                 route->network = g_strdup(value);
2391                 break;
2392         case PROVIDER_ROUTE_TYPE_GW:
2393                 route->gateway = g_strdup(value);
2394                 break;
2395         }
2396
2397         if (handle_routes == FALSE) {
2398                 if (route->netmask != NULL && route->gateway != NULL &&
2399                                                         route->network != NULL)
2400                         provider_schedule_changed(provider);
2401         }
2402
2403         return 0;
2404 }
2405
2406 const char *vpn_provider_get_driver_name(struct vpn_provider *provider)
2407 {
2408         if (provider->driver == NULL)
2409                 return NULL;
2410
2411         return provider->driver->name;
2412 }
2413
2414 const char *vpn_provider_get_save_group(struct vpn_provider *provider)
2415 {
2416         return provider->identifier;
2417 }
2418
2419 static gint compare_priority(gconstpointer a, gconstpointer b)
2420 {
2421         return 0;
2422 }
2423
2424 static void clean_provider(gpointer key, gpointer value, gpointer user_data)
2425 {
2426         struct vpn_provider *provider = value;
2427
2428         if (provider->driver != NULL && provider->driver->remove)
2429                 provider->driver->remove(provider);
2430
2431         connection_unregister(provider);
2432 }
2433
2434 int vpn_provider_driver_register(struct vpn_provider_driver *driver)
2435 {
2436         DBG("driver %p name %s", driver, driver->name);
2437
2438         driver_list = g_slist_insert_sorted(driver_list, driver,
2439                                                         compare_priority);
2440         provider_create_all_from_type(driver->name);
2441         return 0;
2442 }
2443
2444 void vpn_provider_driver_unregister(struct vpn_provider_driver *driver)
2445 {
2446         GHashTableIter iter;
2447         gpointer value, key;
2448
2449         DBG("driver %p name %s", driver, driver->name);
2450
2451         driver_list = g_slist_remove(driver_list, driver);
2452
2453         g_hash_table_iter_init(&iter, provider_hash);
2454         while (g_hash_table_iter_next(&iter, &key, &value) == TRUE) {
2455                 struct vpn_provider *provider = value;
2456
2457                 if (provider != NULL && provider->driver != NULL &&
2458                                 provider->driver->type == driver->type &&
2459                                 g_strcmp0(provider->driver->name,
2460                                                         driver->name) == 0) {
2461                         provider->driver = NULL;
2462                 }
2463         }
2464 }
2465
2466 static gboolean check_vpn_count(gpointer data)
2467 {
2468         if (configuration_count == 0) {
2469                 connman_info("No VPN configurations found, quitting.");
2470                 raise(SIGTERM);
2471         }
2472
2473         return FALSE;
2474 }
2475
2476 void __vpn_provider_check_connections(void)
2477 {
2478         /*
2479          * If we were started when there is no providers configured,
2480          * then just quit. This happens when connman starts and its
2481          * vpn plugin asks connman-vpnd if it has any connections
2482          * configured. If there are none, then we can stop the vpn
2483          * daemon.
2484          */
2485         g_timeout_add(1000, check_vpn_count, NULL);
2486 }
2487
2488 const char *vpn_provider_get_name(struct vpn_provider *provider)
2489 {
2490         return provider->name;
2491 }
2492
2493 const char *vpn_provider_get_host(struct vpn_provider *provider)
2494 {
2495         return provider->host;
2496 }
2497
2498 const char *vpn_provider_get_path(struct vpn_provider *provider)
2499 {
2500         return provider->path;
2501 }
2502
2503 static int agent_probe(struct connman_agent *agent)
2504 {
2505         DBG("agent %p", agent);
2506         return 0;
2507 }
2508
2509 static void agent_remove(struct connman_agent *agent)
2510 {
2511         DBG("agent %p", agent);
2512 }
2513
2514 static struct connman_agent_driver agent_driver = {
2515         .name           = "vpn",
2516         .interface      = VPN_AGENT_INTERFACE,
2517         .probe          = agent_probe,
2518         .remove         = agent_remove,
2519 };
2520
2521 static void remove_unprovisioned_providers()
2522 {
2523         gchar **providers;
2524         GKeyFile *keyfile, *configkeyfile;
2525         char *file, *section;
2526         int i = 0;
2527
2528         providers = __connman_storage_get_providers();
2529         if (providers == NULL)
2530                 return;
2531
2532         for (; providers[i] != NULL; i++) {
2533                 char *group = providers[i] + sizeof("provider_") - 1;
2534                 file = section = NULL;
2535                 keyfile = configkeyfile = NULL;
2536
2537                 keyfile = __connman_storage_load_provider(group);
2538                 if (keyfile == NULL)
2539                         continue;
2540
2541                 file = g_key_file_get_string(keyfile, group,
2542                                         "Config.file", NULL);
2543                 if (file == NULL)
2544                         goto next;
2545
2546                 section = g_key_file_get_string(keyfile, group,
2547                                         "Config.ident", NULL);
2548                 if (section == NULL)
2549                         goto next;
2550
2551                 configkeyfile = __connman_storage_load_provider_config(file);
2552                 if (configkeyfile == NULL) {
2553                         /*
2554                          * Config file is missing, remove the provisioned
2555                          * service.
2556                          */
2557                         __connman_storage_remove_provider(group);
2558                         goto next;
2559                 }
2560
2561                 if (g_key_file_has_group(configkeyfile, section) == FALSE)
2562                         /*
2563                          * Config section is missing, remove the provisioned
2564                          * service.
2565                          */
2566                         __connman_storage_remove_provider(group);
2567
2568         next:
2569                 if (keyfile != NULL)
2570                         g_key_file_free(keyfile);
2571
2572                 if (configkeyfile != NULL)
2573                         g_key_file_free(configkeyfile);
2574
2575                 g_free(section);
2576                 g_free(file);
2577         }
2578
2579         g_strfreev(providers);
2580 }
2581
2582 int __vpn_provider_init(gboolean do_routes)
2583 {
2584         int err;
2585
2586         DBG("");
2587
2588         handle_routes = do_routes;
2589
2590         err = connman_agent_driver_register(&agent_driver);
2591         if (err < 0) {
2592                 connman_error("Cannot register agent driver for %s",
2593                                                 agent_driver.name);
2594                 return err;
2595         }
2596
2597         connection = connman_dbus_get_connection();
2598
2599         remove_unprovisioned_providers();
2600
2601         provider_hash = g_hash_table_new_full(g_str_hash, g_str_equal,
2602                                                 NULL, unregister_provider);
2603         return 0;
2604 }
2605
2606 void __vpn_provider_cleanup(void)
2607 {
2608         DBG("");
2609
2610         g_hash_table_foreach(provider_hash, clean_provider, NULL);
2611
2612         g_hash_table_destroy(provider_hash);
2613         provider_hash = NULL;
2614
2615         connman_agent_driver_unregister(&agent_driver);
2616
2617         dbus_connection_unref(connection);
2618 }