vpn: Make VPN plugin connection function async
[platform/upstream/connman.git] / vpn / vpn-provider.c
1 /*
2  *
3  *  ConnMan VPN daemon
4  *
5  *  Copyright (C) 2012  Intel Corporation. All rights reserved.
6  *
7  *  This program is free software; you can redistribute it and/or modify
8  *  it under the terms of the GNU General Public License version 2 as
9  *  published by the Free Software Foundation.
10  *
11  *  This program is distributed in the hope that it will be useful,
12  *  but WITHOUT ANY WARRANTY; without even the implied warranty of
13  *  MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
14  *  GNU General Public License for more details.
15  *
16  *  You should have received a copy of the GNU General Public License
17  *  along with this program; if not, write to the Free Software
18  *  Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA  02110-1301  USA
19  *
20  */
21
22 #ifdef HAVE_CONFIG_H
23 #include <config.h>
24 #endif
25
26 #include <errno.h>
27 #include <stdio.h>
28 #include <string.h>
29 #include <stdlib.h>
30 #include <gdbus.h>
31 #include <connman/log.h>
32 #include <gweb/gresolv.h>
33 #include <netdb.h>
34
35 #include "../src/connman.h"
36 #include "connman/vpn-dbus.h"
37 #include "vpn-provider.h"
38 #include "vpn.h"
39
40 enum {
41         USER_ROUTES_CHANGED = 0x01,
42         SERVER_ROUTES_CHANGED = 0x02,
43 };
44
45 static DBusConnection *connection;
46 static GHashTable *provider_hash;
47 static GSList *driver_list;
48 static int configuration_count;
49 static gboolean handle_routes;
50
51 struct vpn_route {
52         int family;
53         char *network;
54         char *netmask;
55         char *gateway;
56 };
57
58 struct vpn_provider {
59         int refcount;
60         int index;
61         int fd;
62         enum vpn_provider_state state;
63         char *path;
64         char *identifier;
65         char *name;
66         char *type;
67         char *host;
68         char *domain;
69         int family;
70         GHashTable *routes;
71         struct vpn_provider_driver *driver;
72         void *driver_data;
73         GHashTable *setting_strings;
74         GHashTable *user_routes;
75         GSList *user_networks;
76         GResolv *resolv;
77         char **host_ip;
78         struct vpn_ipconfig *ipconfig_ipv4;
79         struct vpn_ipconfig *ipconfig_ipv6;
80         char **nameservers;
81         int what_changed;
82         guint notify_id;
83 };
84
85 static void free_route(gpointer data)
86 {
87         struct vpn_route *route = data;
88
89         g_free(route->network);
90         g_free(route->netmask);
91         g_free(route->gateway);
92
93         g_free(route);
94 }
95
96 static void append_route(DBusMessageIter *iter, void *user_data)
97 {
98         struct vpn_route *route = user_data;
99         DBusMessageIter item;
100         int family = 0;
101
102         connman_dbus_dict_open(iter, &item);
103
104         if (route == NULL)
105                 goto empty_dict;
106
107         if (route->family == AF_INET)
108                 family = 4;
109         else if (route->family == AF_INET6)
110                 family = 6;
111
112         if (family != 0)
113                 connman_dbus_dict_append_basic(&item, "ProtocolFamily",
114                                         DBUS_TYPE_INT32, &family);
115
116         if (route->network != NULL)
117                 connman_dbus_dict_append_basic(&item, "Network",
118                                         DBUS_TYPE_STRING, &route->network);
119
120         if (route->netmask != NULL)
121                 connman_dbus_dict_append_basic(&item, "Netmask",
122                                         DBUS_TYPE_STRING, &route->netmask);
123
124         if (route->gateway != NULL)
125                 connman_dbus_dict_append_basic(&item, "Gateway",
126                                         DBUS_TYPE_STRING, &route->gateway);
127
128 empty_dict:
129         connman_dbus_dict_close(iter, &item);
130 }
131
132 static void append_routes(DBusMessageIter *iter, void *user_data)
133 {
134         GHashTable *routes = user_data;
135         GHashTableIter hash;
136         gpointer value, key;
137
138         if (routes == NULL) {
139                 append_route(iter, NULL);
140                 return;
141         }
142
143         g_hash_table_iter_init(&hash, routes);
144
145         while (g_hash_table_iter_next(&hash, &key, &value) == TRUE) {
146                 DBusMessageIter dict;
147
148                 dbus_message_iter_open_container(iter, DBUS_TYPE_STRUCT, NULL,
149                                                 &dict);
150                 append_route(&dict, value);
151                 dbus_message_iter_close_container(iter, &dict);
152         }
153 }
154
155 static void send_routes(struct vpn_provider *provider, GHashTable *routes,
156                         const char *name)
157 {
158         connman_dbus_property_changed_array(provider->path,
159                                         VPN_CONNECTION_INTERFACE,
160                                         name,
161                                         DBUS_TYPE_DICT_ENTRY,
162                                         append_routes,
163                                         routes);
164 }
165
166 static int provider_property_changed(struct vpn_provider *provider,
167                                 const char *name)
168 {
169         DBG("provider %p name %s", provider, name);
170
171         if (g_str_equal(name, "UserRoutes") == TRUE)
172                 send_routes(provider, provider->user_routes, name);
173         else if (g_str_equal(name, "ServerRoutes") == TRUE)
174                 send_routes(provider, provider->routes, name);
175
176         return 0;
177 }
178
179 static GSList *read_route_dict(GSList *routes, DBusMessageIter *dicts)
180 {
181         DBusMessageIter dict, value, entry;
182         const char *network, *netmask, *gateway;
183         struct vpn_route *route;
184         int family, type;
185         const char *key;
186
187         dbus_message_iter_recurse(dicts, &entry);
188
189         network = netmask = gateway = NULL;
190         family = PF_UNSPEC;
191
192         while (dbus_message_iter_get_arg_type(&entry) == DBUS_TYPE_DICT_ENTRY) {
193
194                 dbus_message_iter_recurse(&entry, &dict);
195                 dbus_message_iter_get_basic(&dict, &key);
196
197                 dbus_message_iter_next(&dict);
198                 dbus_message_iter_recurse(&dict, &value);
199
200                 type = dbus_message_iter_get_arg_type(&value);
201
202                 switch (type) {
203                 case DBUS_TYPE_STRING:
204                         if (g_str_equal(key, "ProtocolFamily") == TRUE)
205                                 dbus_message_iter_get_basic(&value, &family);
206                         else if (g_str_equal(key, "Network") == TRUE)
207                                 dbus_message_iter_get_basic(&value, &network);
208                         else if (g_str_equal(key, "Netmask") == TRUE)
209                                 dbus_message_iter_get_basic(&value, &netmask);
210                         else if (g_str_equal(key, "Gateway") == TRUE)
211                                 dbus_message_iter_get_basic(&value, &gateway);
212                         break;
213                 }
214
215                 dbus_message_iter_next(&entry);
216         }
217
218         DBG("family %d network %s netmask %s gateway %s", family,
219                 network, netmask, gateway);
220
221         if (network == NULL || netmask == NULL) {
222                 DBG("Ignoring route as network/netmask is missing");
223                 return routes;
224         }
225
226         route = g_try_new(struct vpn_route, 1);
227         if (route == NULL) {
228                 g_slist_free_full(routes, free_route);
229                 return NULL;
230         }
231
232         if (family == PF_UNSPEC) {
233                 family = connman_inet_check_ipaddress(network);
234                 if (family < 0) {
235                         DBG("Cannot get address family of %s (%d/%s)", network,
236                                 family, gai_strerror(family));
237                         if (strstr(network, ":") != NULL) {
238                                 DBG("Guessing it is IPv6");
239                                 family = AF_INET6;
240                         } else {
241                                 DBG("Guessing it is IPv4");
242                                 family = AF_INET;
243                         }
244                 }
245         } else {
246                 switch (family) {
247                 case '4':
248                         family = AF_INET;
249                         break;
250                 case '6':
251                         family = AF_INET6;
252                         break;
253                 default:
254                         family = PF_UNSPEC;
255                         break;
256                 }
257         }
258
259         route->family = family;
260         route->network = g_strdup(network);
261         route->netmask = g_strdup(netmask);
262         route->gateway = g_strdup(gateway);
263
264         routes = g_slist_prepend(routes, route);
265         return routes;
266 }
267
268 static GSList *get_user_networks(DBusMessageIter *array)
269 {
270         DBusMessageIter entry;
271         GSList *list = NULL;
272
273         while (dbus_message_iter_get_arg_type(array) == DBUS_TYPE_ARRAY) {
274
275                 dbus_message_iter_recurse(array, &entry);
276
277                 while (dbus_message_iter_get_arg_type(&entry) ==
278                                                         DBUS_TYPE_STRUCT) {
279                         DBusMessageIter dicts;
280
281                         dbus_message_iter_recurse(&entry, &dicts);
282
283                         while (dbus_message_iter_get_arg_type(&dicts) ==
284                                                         DBUS_TYPE_ARRAY) {
285
286                                 list = read_route_dict(list, &dicts);
287                                 dbus_message_iter_next(&dicts);
288                         }
289
290                         dbus_message_iter_next(&entry);
291                 }
292
293                 dbus_message_iter_next(array);
294         }
295
296         return list;
297 }
298
299 static void set_user_networks(struct vpn_provider *provider, GSList *networks)
300 {
301         GSList *list;
302
303         for (list = networks; list != NULL; list = g_slist_next(list)) {
304                 struct vpn_route *route= list->data;
305
306                 if (__vpn_provider_append_user_route(provider,
307                                         route->family, route->network,
308                                         route->netmask) != 0)
309                         break;
310         }
311 }
312
313 static void del_routes(struct vpn_provider *provider)
314 {
315         GHashTableIter hash;
316         gpointer value, key;
317
318         g_hash_table_iter_init(&hash, provider->user_routes);
319         while (handle_routes == TRUE && g_hash_table_iter_next(&hash,
320                                                 &key, &value) == TRUE) {
321                 struct vpn_route *route = value;
322                 if (route->family == AF_INET6) {
323                         unsigned char prefixlen = atoi(route->netmask);
324                         connman_inet_del_ipv6_network_route(provider->index,
325                                                         route->network,
326                                                         prefixlen);
327                 } else
328                         connman_inet_del_host_route(provider->index,
329                                                 route->network);
330         }
331
332         g_hash_table_remove_all(provider->user_routes);
333         g_slist_free_full(provider->user_networks, free_route);
334         provider->user_networks = NULL;
335 }
336
337 static gboolean provider_send_changed(gpointer data)
338 {
339         struct vpn_provider *provider = data;
340
341         if (provider->what_changed & USER_ROUTES_CHANGED)
342                 provider_property_changed(provider, "UserRoutes");
343
344         if (provider->what_changed & SERVER_ROUTES_CHANGED)
345                 provider_property_changed(provider, "ServerRoutes");
346
347         provider->what_changed = 0;
348         provider->notify_id = 0;
349
350         return FALSE;
351 }
352
353 static void provider_schedule_changed(struct vpn_provider *provider, int flag)
354 {
355         if (provider->notify_id != 0)
356                 g_source_remove(provider->notify_id);
357
358         provider->what_changed |= flag;
359
360         provider->notify_id = g_timeout_add(100, provider_send_changed,
361                                                                 provider);
362 }
363
364 static DBusMessage *set_property(DBusConnection *conn, DBusMessage *msg,
365                                                                 void *data)
366 {
367         struct vpn_provider *provider = data;
368         DBusMessageIter iter, value;
369         const char *name;
370         int type;
371
372         DBG("conn %p", conn);
373
374         if (dbus_message_iter_init(msg, &iter) == FALSE)
375                 return __connman_error_invalid_arguments(msg);
376
377         if (dbus_message_iter_get_arg_type(&iter) != DBUS_TYPE_STRING)
378                 return __connman_error_invalid_arguments(msg);
379
380         dbus_message_iter_get_basic(&iter, &name);
381         dbus_message_iter_next(&iter);
382
383         if (dbus_message_iter_get_arg_type(&iter) != DBUS_TYPE_VARIANT)
384                 return __connman_error_invalid_arguments(msg);
385
386         dbus_message_iter_recurse(&iter, &value);
387
388         type = dbus_message_iter_get_arg_type(&value);
389
390         if (g_str_equal(name, "UserRoutes") == TRUE) {
391                 GSList *networks;
392
393                 if (type != DBUS_TYPE_ARRAY)
394                         return __connman_error_invalid_arguments(msg);
395
396                 networks = get_user_networks(&value);
397                 if (networks != NULL) {
398                         del_routes(provider);
399                         provider->user_networks = networks;
400                         set_user_networks(provider, provider->user_networks);
401
402                         if (handle_routes == FALSE)
403                                 provider_schedule_changed(provider,
404                                                         USER_ROUTES_CHANGED);
405                 }
406         } else
407                 return __connman_error_invalid_property(msg);
408
409         return g_dbus_create_reply(msg, DBUS_TYPE_INVALID);
410 }
411
412 static DBusMessage *clear_property(DBusConnection *conn, DBusMessage *msg,
413                                                                 void *data)
414 {
415         struct vpn_provider *provider = data;
416         const char *name;
417
418         DBG("conn %p", conn);
419
420         dbus_message_get_args(msg, NULL, DBUS_TYPE_STRING, &name,
421                                                         DBUS_TYPE_INVALID);
422
423         if (g_str_equal(name, "UserRoutes") == TRUE) {
424                 del_routes(provider);
425
426                 if (handle_routes == FALSE)
427                         provider_property_changed(provider, name);
428         } else {
429                 return __connman_error_invalid_property(msg);
430         }
431
432         return g_dbus_create_reply(msg, DBUS_TYPE_INVALID);
433 }
434
435 static DBusMessage *do_connect(DBusConnection *conn, DBusMessage *msg,
436                                                                 void *data)
437 {
438         struct vpn_provider *provider = data;
439         int err;
440
441         DBG("conn %p provider %p", conn, provider);
442
443         err = __vpn_provider_connect(provider, msg);
444         if (err < 0)
445                 return __connman_error_failed(msg, -err);
446
447         return NULL;
448 }
449
450 static DBusMessage *do_disconnect(DBusConnection *conn, DBusMessage *msg,
451                                                                 void *data)
452 {
453         struct vpn_provider *provider = data;
454         int err;
455
456         DBG("conn %p provider %p", conn, provider);
457
458         err = __vpn_provider_disconnect(provider);
459         if (err < 0)
460                 return __connman_error_failed(msg, -err);
461         else
462                 return g_dbus_create_reply(msg, DBUS_TYPE_INVALID);
463 }
464
465 static const GDBusMethodTable connection_methods[] = {
466         { GDBUS_METHOD("SetProperty",
467                         GDBUS_ARGS({ "name", "s" }, { "value", "v" }),
468                         NULL, set_property) },
469         { GDBUS_METHOD("ClearProperty",
470                         GDBUS_ARGS({ "name", "s" }), NULL,
471                         clear_property) },
472         { GDBUS_ASYNC_METHOD("Connect", NULL, NULL, do_connect) },
473         { GDBUS_METHOD("Disconnect", NULL, NULL, do_disconnect) },
474         { },
475 };
476
477 static const GDBusSignalTable connection_signals[] = {
478         { GDBUS_SIGNAL("PropertyChanged",
479                         GDBUS_ARGS({ "name", "s" }, { "value", "v" })) },
480         { },
481 };
482
483 static void resolv_result(GResolvResultStatus status,
484                                         char **results, gpointer user_data)
485 {
486         struct vpn_provider *provider = user_data;
487
488         DBG("status %d", status);
489
490         if (status == G_RESOLV_RESULT_STATUS_SUCCESS && results != NULL &&
491                                                 g_strv_length(results) > 0)
492                 provider->host_ip = g_strdupv(results);
493
494         vpn_provider_unref(provider);
495 }
496
497 static void provider_resolv_host_addr(struct vpn_provider *provider)
498 {
499         if (provider->host == NULL)
500                 return;
501
502         if (connman_inet_check_ipaddress(provider->host) > 0)
503                 return;
504
505         if (provider->host_ip != NULL)
506                 return;
507
508         /*
509          * If the hostname is not numeric, try to resolv it. We do not wait
510          * the result as it might take some time. We will get the result
511          * before VPN will feed routes to us because VPN client will need
512          * the IP address also before VPN connection can be established.
513          */
514         provider->resolv = g_resolv_new(0);
515         if (provider->resolv == NULL) {
516                 DBG("Cannot resolv %s", provider->host);
517                 return;
518         }
519
520         DBG("Trying to resolv %s", provider->host);
521
522         vpn_provider_ref(provider);
523
524         g_resolv_lookup_hostname(provider->resolv, provider->host,
525                                 resolv_result, provider);
526 }
527
528 void __vpn_provider_append_properties(struct vpn_provider *provider,
529                                                         DBusMessageIter *iter)
530 {
531         if (provider->host != NULL)
532                 connman_dbus_dict_append_basic(iter, "Host",
533                                         DBUS_TYPE_STRING, &provider->host);
534
535         if (provider->domain != NULL)
536                 connman_dbus_dict_append_basic(iter, "Domain",
537                                         DBUS_TYPE_STRING, &provider->domain);
538
539         if (provider->type != NULL)
540                 connman_dbus_dict_append_basic(iter, "Type", DBUS_TYPE_STRING,
541                                                  &provider->type);
542 }
543
544 int __vpn_provider_append_user_route(struct vpn_provider *provider,
545                         int family, const char *network, const char *netmask)
546 {
547         struct vpn_route *route;
548         char *key = g_strdup_printf("%d/%s/%s", family, network, netmask);
549
550         DBG("family %d network %s netmask %s", family, network, netmask);
551
552         route = g_hash_table_lookup(provider->user_routes, key);
553         if (route == NULL) {
554                 route = g_try_new0(struct vpn_route, 1);
555                 if (route == NULL) {
556                         connman_error("out of memory");
557                         return -ENOMEM;
558                 }
559
560                 route->family = family;
561                 route->network = g_strdup(network);
562                 route->netmask = g_strdup(netmask);
563
564                 g_hash_table_replace(provider->user_routes, key, route);
565         } else
566                 g_free(key);
567
568         return 0;
569 }
570
571 static struct vpn_route *get_route(char *route_str)
572 {
573         char **elems = g_strsplit(route_str, "/", 0);
574         char *network, *netmask, *gateway, *family_str;
575         int family = PF_UNSPEC;
576         struct vpn_route *route = NULL;
577
578         if (elems == NULL)
579                 return NULL;
580
581         family_str = elems[0];
582
583         network = elems[1];
584         if (network == NULL || network[0] == '\0')
585                 goto out;
586
587         netmask = elems[2];
588         if (netmask == NULL || netmask[0] == '\0')
589                 goto out;
590
591         gateway = elems[3];
592
593         route = g_try_new0(struct vpn_route, 1);
594         if (route == NULL)
595                 goto out;
596
597         if (family_str[0] == '\0' || atoi(family_str) == 0) {
598                 family = PF_UNSPEC;
599         } else {
600                 switch (family_str[0]) {
601                 case '4':
602                         family = AF_INET;
603                         break;
604                 case '6':
605                         family = AF_INET6;
606                         break;
607                 }
608         }
609
610         if (g_strrstr(network, ":") != NULL) {
611                 if (family != PF_UNSPEC && family != AF_INET6)
612                         DBG("You have IPv6 address but you have non IPv6 route");
613         } else if (g_strrstr(network, ".") != NULL) {
614                 if (family != PF_UNSPEC && family != AF_INET)
615                         DBG("You have IPv4 address but you have non IPv4 route");
616
617                 if (g_strrstr(netmask, ".") == NULL) {
618                         /* We have netmask length */
619                         in_addr_t addr;
620                         struct in_addr netmask_in;
621                         unsigned char prefix_len = 32;
622
623                         if (netmask != NULL) {
624                                 char *ptr;
625                                 long int value = strtol(netmask, &ptr, 10);
626                                 if (ptr != netmask && *ptr == '\0' &&
627                                                                 value <= 32)
628                                         prefix_len = value;
629                         }
630
631                         addr = 0xffffffff << (32 - prefix_len);
632                         netmask_in.s_addr = htonl(addr);
633                         netmask = inet_ntoa(netmask_in);
634
635                         DBG("network %s netmask %s", network, netmask);
636                 }
637         }
638
639         if (family == PF_UNSPEC) {
640                 family = connman_inet_check_ipaddress(network);
641                 if (family < 0 || family == PF_UNSPEC)
642                         goto out;
643         }
644
645         route->family = family;
646         route->network = g_strdup(network);
647         route->netmask = g_strdup(netmask);
648         route->gateway = g_strdup(gateway);
649
650 out:
651         g_strfreev(elems);
652         return route;
653 }
654
655 static GSList *get_routes(gchar **networks)
656 {
657         struct vpn_route *route;
658         GSList *routes = NULL;
659         int i;
660
661         for (i = 0; networks[i] != NULL; i++) {
662                 route = get_route(networks[i]);
663                 if (route != NULL)
664                         routes = g_slist_prepend(routes, route);
665         }
666
667         return routes;
668 }
669
670 static int provider_load_from_keyfile(struct vpn_provider *provider,
671                 GKeyFile *keyfile)
672 {
673         gsize idx = 0;
674         gchar **settings;
675         gchar *key, *value;
676         gsize length, num_user_networks;
677         gchar **networks = NULL;
678
679         settings = g_key_file_get_keys(keyfile, provider->identifier, &length,
680                                 NULL);
681         if (settings == NULL) {
682                 g_key_file_free(keyfile);
683                 return -ENOENT;
684         }
685
686         while (idx < length) {
687                 key = settings[idx];
688                 if (key != NULL) {
689                         if (g_str_equal(key, "Networks") == TRUE) {
690                                 networks = g_key_file_get_string_list(keyfile,
691                                                 provider->identifier,
692                                                 key,
693                                                 &num_user_networks,
694                                                 NULL);
695                                 provider->user_networks = get_routes(networks);
696
697                         } else {
698                                 value = g_key_file_get_string(keyfile,
699                                                         provider->identifier,
700                                                         key, NULL);
701                                 vpn_provider_set_string(provider, key,
702                                                         value);
703                                 g_free(value);
704                         }
705                 }
706                 idx += 1;
707         }
708         g_strfreev(settings);
709         g_strfreev(networks);
710
711         if (provider->user_networks != NULL)
712                 set_user_networks(provider, provider->user_networks);
713
714         return 0;
715 }
716
717
718 static int vpn_provider_load(struct vpn_provider *provider)
719 {
720         GKeyFile *keyfile;
721
722         DBG("provider %p", provider);
723
724         keyfile = __connman_storage_load_provider(provider->identifier);
725         if (keyfile == NULL)
726                 return -ENOENT;
727
728         provider_load_from_keyfile(provider, keyfile);
729
730         g_key_file_free(keyfile);
731         return 0;
732 }
733
734 static gchar **create_network_list(GSList *networks, gsize *count)
735 {
736         GSList *list;
737         gchar **result = NULL;
738         unsigned int num_elems = 0;
739
740         for (list = networks; list != NULL; list = g_slist_next(list)) {
741                 struct vpn_route *route = list->data;
742                 int family;
743
744                 result = g_try_realloc(result,
745                                 (num_elems + 1) * sizeof(gchar *));
746                 if (result == NULL)
747                         return NULL;
748
749                 switch (route->family) {
750                 case AF_INET:
751                         family = 4;
752                         break;
753                 case AF_INET6:
754                         family = 6;
755                         break;
756                 default:
757                         family = 0;
758                         break;
759                 }
760
761                 result[num_elems] = g_strdup_printf("%d/%s/%s/%s",
762                                 family, route->network, route->netmask,
763                                 route->gateway == NULL ? "" : route->gateway);
764
765                 num_elems++;
766         }
767
768         result = g_try_realloc(result, (num_elems + 1) * sizeof(gchar *));
769         if (result == NULL)
770                 return NULL;
771
772         result[num_elems] = NULL;
773         *count = num_elems;
774         return result;
775 }
776
777 static int vpn_provider_save(struct vpn_provider *provider)
778 {
779         GKeyFile *keyfile;
780
781         DBG("provider %p", provider);
782
783         keyfile = g_key_file_new();
784         if (keyfile == NULL)
785                 return -ENOMEM;
786
787         g_key_file_set_string(keyfile, provider->identifier,
788                         "Name", provider->name);
789         g_key_file_set_string(keyfile, provider->identifier,
790                         "Type", provider->type);
791         g_key_file_set_string(keyfile, provider->identifier,
792                         "Host", provider->host);
793         g_key_file_set_string(keyfile, provider->identifier,
794                         "VPN.Domain", provider->domain);
795         if (provider->user_networks != NULL) {
796                 gchar **networks;
797                 gsize network_count;
798
799                 networks = create_network_list(provider->user_networks,
800                                                         &network_count);
801                 if (networks != NULL) {
802                         g_key_file_set_string_list(keyfile,
803                                                 provider->identifier,
804                                                 "Networks",
805                                                 (const gchar ** const)networks,
806                                                 network_count);
807                         g_strfreev(networks);
808                 }
809         }
810
811         if (provider->driver != NULL && provider->driver->save != NULL)
812                 provider->driver->save(provider, keyfile);
813
814         __connman_storage_save_provider(keyfile, provider->identifier);
815         g_key_file_free(keyfile);
816
817         return 0;
818 }
819
820 static struct vpn_provider *vpn_provider_lookup(const char *identifier)
821 {
822         struct vpn_provider *provider = NULL;
823
824         provider = g_hash_table_lookup(provider_hash, identifier);
825
826         return provider;
827 }
828
829 static gboolean match_driver(struct vpn_provider *provider,
830                                 struct vpn_provider_driver *driver)
831 {
832         if (g_strcmp0(driver->name, provider->type) == 0)
833                 return TRUE;
834
835         return FALSE;
836 }
837
838 static int provider_probe(struct vpn_provider *provider)
839 {
840         GSList *list;
841
842         DBG("provider %p name %s", provider, provider->name);
843
844         if (provider->driver != NULL)
845                 return -EALREADY;
846
847         for (list = driver_list; list; list = list->next) {
848                 struct vpn_provider_driver *driver = list->data;
849
850                 if (match_driver(provider, driver) == FALSE)
851                         continue;
852
853                 DBG("driver %p name %s", driver, driver->name);
854
855                 if (driver->probe != NULL && driver->probe(provider) == 0) {
856                         provider->driver = driver;
857                         break;
858                 }
859         }
860
861         if (provider->driver == NULL)
862                 return -ENODEV;
863
864         return 0;
865 }
866
867 static void provider_remove(struct vpn_provider *provider)
868 {
869         if (provider->driver != NULL) {
870                 provider->driver->remove(provider);
871                 provider->driver = NULL;
872         }
873 }
874
875 static int provider_register(struct vpn_provider *provider)
876 {
877         return provider_probe(provider);
878 }
879
880 static void provider_unregister(struct vpn_provider *provider)
881 {
882         provider_remove(provider);
883 }
884
885 struct vpn_provider *
886 vpn_provider_ref_debug(struct vpn_provider *provider,
887                         const char *file, int line, const char *caller)
888 {
889         DBG("%p ref %d by %s:%d:%s()", provider, provider->refcount + 1,
890                 file, line, caller);
891
892         __sync_fetch_and_add(&provider->refcount, 1);
893
894         return provider;
895 }
896
897 static void provider_destruct(struct vpn_provider *provider)
898 {
899         DBG("provider %p", provider);
900
901         if (provider->notify_id != 0)
902                 g_source_remove(provider->notify_id);
903
904         g_free(provider->name);
905         g_free(provider->type);
906         g_free(provider->host);
907         g_free(provider->domain);
908         g_free(provider->identifier);
909         g_free(provider->path);
910         g_slist_free_full(provider->user_networks, free_route);
911         g_strfreev(provider->nameservers);
912         g_hash_table_destroy(provider->routes);
913         g_hash_table_destroy(provider->user_routes);
914         g_hash_table_destroy(provider->setting_strings);
915         if (provider->resolv != NULL) {
916                 g_resolv_unref(provider->resolv);
917                 provider->resolv = NULL;
918         }
919         __vpn_ipconfig_unref(provider->ipconfig_ipv4);
920         __vpn_ipconfig_unref(provider->ipconfig_ipv6);
921
922         g_strfreev(provider->host_ip);
923         g_free(provider);
924 }
925
926 void vpn_provider_unref_debug(struct vpn_provider *provider,
927                                 const char *file, int line, const char *caller)
928 {
929         DBG("%p ref %d by %s:%d:%s()", provider, provider->refcount - 1,
930                 file, line, caller);
931
932         if (__sync_fetch_and_sub(&provider->refcount, 1) != 1)
933                 return;
934
935         provider_remove(provider);
936
937         provider_destruct(provider);
938 }
939
940 static void configuration_count_add(void)
941 {
942         DBG("count %d", configuration_count + 1);
943
944         __sync_fetch_and_add(&configuration_count, 1);
945 }
946
947 static void configuration_count_del(void)
948 {
949         DBG("count %d", configuration_count - 1);
950
951         if (__sync_fetch_and_sub(&configuration_count, 1) != 1)
952                 return;
953
954         raise(SIGTERM);
955 }
956
957 int __vpn_provider_disconnect(struct vpn_provider *provider)
958 {
959         int err;
960
961         DBG("provider %p", provider);
962
963         if (provider->driver != NULL && provider->driver->disconnect != NULL)
964                 err = provider->driver->disconnect(provider);
965         else
966                 return -EOPNOTSUPP;
967
968         if (err < 0) {
969                 if (err != -EINPROGRESS)
970                         return err;
971
972                 return -EINPROGRESS;
973         }
974
975         return 0;
976 }
977
978 static void connect_cb(struct vpn_provider *provider, void *user_data,
979                                                                 int error)
980 {
981         DBusMessage *pending = user_data;
982
983         DBG("provider %p user %p error %d", provider, user_data, error);
984
985         if (error != 0) {
986                 DBusMessage *reply = __connman_error_failed(pending, error);
987                 if (reply != NULL)
988                         g_dbus_send_message(connection, reply);
989
990                 vpn_provider_indicate_error(provider,
991                                         VPN_PROVIDER_ERROR_CONNECT_FAILED);
992                 vpn_provider_set_state(provider, VPN_PROVIDER_STATE_FAILURE);
993         } else
994                 g_dbus_send_reply(connection, pending, DBUS_TYPE_INVALID);
995
996         dbus_message_unref(pending);
997 }
998
999 int __vpn_provider_connect(struct vpn_provider *provider, DBusMessage *msg)
1000 {
1001         int err;
1002
1003         DBG("provider %p", provider);
1004
1005         if (provider->driver != NULL && provider->driver->connect != NULL) {
1006                 dbus_message_ref(msg);
1007                 err = provider->driver->connect(provider, connect_cb, msg);
1008         } else
1009                 return -EOPNOTSUPP;
1010
1011         return err;
1012 }
1013
1014 static void connection_removed_signal(struct vpn_provider *provider)
1015 {
1016         DBusMessage *signal;
1017         DBusMessageIter iter;
1018
1019         signal = dbus_message_new_signal(VPN_MANAGER_PATH,
1020                         VPN_MANAGER_INTERFACE, "ConnectionRemoved");
1021         if (signal == NULL)
1022                 return;
1023
1024         dbus_message_iter_init_append(signal, &iter);
1025         dbus_message_iter_append_basic(&iter, DBUS_TYPE_OBJECT_PATH,
1026                                                         &provider->path);
1027         dbus_connection_send(connection, signal, NULL);
1028         dbus_message_unref(signal);
1029 }
1030
1031 static char *get_ident(const char *path)
1032 {
1033         char *pos;
1034
1035         if (*path != '/')
1036                 return NULL;
1037
1038         pos = strrchr(path, '/');
1039         if (pos == NULL)
1040                 return NULL;
1041
1042         return pos + 1;
1043 }
1044
1045 int __vpn_provider_remove(const char *path)
1046 {
1047         struct vpn_provider *provider;
1048         char *ident;
1049
1050         DBG("path %s", path);
1051
1052         ident = get_ident(path);
1053
1054         provider = vpn_provider_lookup(ident);
1055         if (provider != NULL) {
1056                 DBG("Removing VPN %s", provider->identifier);
1057
1058                 connection_removed_signal(provider);
1059
1060                 provider_unregister(provider);
1061                 g_hash_table_remove(provider_hash, provider->identifier);
1062
1063                 __connman_storage_remove_provider(ident);
1064                 return 0;
1065         }
1066
1067         return -ENXIO;
1068 }
1069
1070 static void append_ipv4(DBusMessageIter *iter, void *user_data)
1071 {
1072         struct vpn_provider *provider = user_data;
1073         const char *address, *gateway, *peer;
1074
1075         address = __vpn_ipconfig_get_local(provider->ipconfig_ipv4);
1076         if (address != NULL) {
1077                 in_addr_t addr;
1078                 struct in_addr netmask;
1079                 char *mask;
1080                 int prefixlen;
1081
1082                 prefixlen = __vpn_ipconfig_get_prefixlen(
1083                                                 provider->ipconfig_ipv4);
1084
1085                 addr = 0xffffffff << (32 - prefixlen);
1086                 netmask.s_addr = htonl(addr);
1087                 mask = inet_ntoa(netmask);
1088
1089                 connman_dbus_dict_append_basic(iter, "Address",
1090                                                 DBUS_TYPE_STRING, &address);
1091
1092                 connman_dbus_dict_append_basic(iter, "Netmask",
1093                                                 DBUS_TYPE_STRING, &mask);
1094         }
1095
1096         gateway = __vpn_ipconfig_get_gateway(provider->ipconfig_ipv4);
1097         if (gateway != NULL)
1098                 connman_dbus_dict_append_basic(iter, "Gateway",
1099                                                 DBUS_TYPE_STRING, &gateway);
1100
1101         peer = __vpn_ipconfig_get_peer(provider->ipconfig_ipv4);
1102         if (peer != NULL)
1103                 connman_dbus_dict_append_basic(iter, "Peer",
1104                                                 DBUS_TYPE_STRING, &peer);
1105 }
1106
1107 static void append_ipv6(DBusMessageIter *iter, void *user_data)
1108 {
1109         struct vpn_provider *provider = user_data;
1110         const char *address, *gateway, *peer;
1111
1112         address = __vpn_ipconfig_get_local(provider->ipconfig_ipv6);
1113         if (address != NULL) {
1114                 unsigned char prefixlen;
1115
1116                 connman_dbus_dict_append_basic(iter, "Address",
1117                                                 DBUS_TYPE_STRING, &address);
1118
1119                 prefixlen = __vpn_ipconfig_get_prefixlen(
1120                                                 provider->ipconfig_ipv6);
1121
1122                 connman_dbus_dict_append_basic(iter, "PrefixLength",
1123                                                 DBUS_TYPE_BYTE, &prefixlen);
1124         }
1125
1126         gateway = __vpn_ipconfig_get_gateway(provider->ipconfig_ipv6);
1127         if (gateway != NULL)
1128                 connman_dbus_dict_append_basic(iter, "Gateway",
1129                                                 DBUS_TYPE_STRING, &gateway);
1130
1131         peer = __vpn_ipconfig_get_peer(provider->ipconfig_ipv6);
1132         if (peer != NULL)
1133                 connman_dbus_dict_append_basic(iter, "Peer",
1134                                                 DBUS_TYPE_STRING, &peer);
1135 }
1136
1137 static const char *state2string(enum vpn_provider_state state)
1138 {
1139         switch (state) {
1140         case VPN_PROVIDER_STATE_UNKNOWN:
1141                 break;
1142         case VPN_PROVIDER_STATE_IDLE:
1143                 return "idle";
1144         case VPN_PROVIDER_STATE_CONNECT:
1145                 return "configuration";
1146         case VPN_PROVIDER_STATE_READY:
1147                 return "ready";
1148         case VPN_PROVIDER_STATE_DISCONNECT:
1149                 return "disconnect";
1150         case VPN_PROVIDER_STATE_FAILURE:
1151                 return "failure";
1152         }
1153
1154         return NULL;
1155 }
1156
1157 static int provider_indicate_state(struct vpn_provider *provider,
1158                                 enum vpn_provider_state state)
1159 {
1160         const char *str;
1161
1162         DBG("provider %p state %d", provider, state);
1163
1164         str = state2string(state);
1165         if (str == NULL)
1166                 return -EINVAL;
1167
1168         provider->state = state;
1169
1170         if (state == VPN_PROVIDER_STATE_READY) {
1171                 connman_dbus_property_changed_basic(provider->path,
1172                                         VPN_CONNECTION_INTERFACE, "Index",
1173                                         DBUS_TYPE_INT32, &provider->index);
1174
1175                 if (provider->family == AF_INET)
1176                         connman_dbus_property_changed_dict(provider->path,
1177                                         VPN_CONNECTION_INTERFACE, "IPv4",
1178                                         append_ipv4, provider);
1179                 else if (provider->family == AF_INET6)
1180                         connman_dbus_property_changed_dict(provider->path,
1181                                         VPN_CONNECTION_INTERFACE, "IPv6",
1182                                         append_ipv6, provider);
1183         }
1184
1185         connman_dbus_property_changed_basic(provider->path,
1186                                         VPN_CONNECTION_INTERFACE, "State",
1187                                         DBUS_TYPE_STRING, &str);
1188         return 0;
1189 }
1190
1191 static void append_nameservers(DBusMessageIter *iter, char **servers)
1192 {
1193         int i;
1194
1195         DBG("%p", servers);
1196
1197         for (i = 0; servers[i] != NULL; i++) {
1198                 DBG("servers[%d] %s", i, servers[i]);
1199                 dbus_message_iter_append_basic(iter,
1200                                         DBUS_TYPE_STRING, &servers[i]);
1201         }
1202 }
1203
1204 static void append_dns(DBusMessageIter *iter, void *user_data)
1205 {
1206         struct vpn_provider *provider = user_data;
1207
1208         if (provider->nameservers != NULL)
1209                 append_nameservers(iter, provider->nameservers);
1210 }
1211
1212 static void append_state(DBusMessageIter *iter,
1213                                         struct vpn_provider *provider)
1214 {
1215         char *str;
1216
1217         switch (provider->state) {
1218         case VPN_PROVIDER_STATE_UNKNOWN:
1219         case VPN_PROVIDER_STATE_IDLE:
1220                 str = "idle";
1221                 break;
1222         case VPN_PROVIDER_STATE_CONNECT:
1223                 str = "configuration";
1224                 break;
1225         case VPN_PROVIDER_STATE_READY:
1226                 str = "ready";
1227                 break;
1228         case VPN_PROVIDER_STATE_DISCONNECT:
1229                 str = "disconnect";
1230                 break;
1231         case VPN_PROVIDER_STATE_FAILURE:
1232                 str = "failure";
1233                 break;
1234         }
1235
1236         connman_dbus_dict_append_basic(iter, "State",
1237                                 DBUS_TYPE_STRING, &str);
1238 }
1239
1240 static void append_properties(DBusMessageIter *iter,
1241                                         struct vpn_provider *provider)
1242 {
1243         DBusMessageIter dict;
1244
1245         connman_dbus_dict_open(iter, &dict);
1246
1247         append_state(&dict, provider);
1248
1249         if (provider->type != NULL)
1250                 connman_dbus_dict_append_basic(&dict, "Type",
1251                                         DBUS_TYPE_STRING, &provider->type);
1252
1253         if (provider->name != NULL)
1254                 connman_dbus_dict_append_basic(&dict, "Name",
1255                                         DBUS_TYPE_STRING, &provider->name);
1256
1257         if (provider->host != NULL)
1258                 connman_dbus_dict_append_basic(&dict, "Host",
1259                                         DBUS_TYPE_STRING, &provider->host);
1260         if (provider->index >= 0)
1261                 connman_dbus_dict_append_basic(&dict, "Index",
1262                                         DBUS_TYPE_INT32, &provider->index);
1263         if (provider->domain != NULL)
1264                 connman_dbus_dict_append_basic(&dict, "Domain",
1265                                         DBUS_TYPE_STRING, &provider->domain);
1266
1267         if (provider->family == AF_INET)
1268                 connman_dbus_dict_append_dict(&dict, "IPv4", append_ipv4,
1269                                                 provider);
1270         else if (provider->family == AF_INET6)
1271                 connman_dbus_dict_append_dict(&dict, "IPv6", append_ipv6,
1272                                                 provider);
1273
1274         connman_dbus_dict_append_array(&dict, "Nameservers",
1275                                 DBUS_TYPE_STRING, append_dns, provider);
1276
1277         connman_dbus_dict_append_array(&dict, "UserRoutes",
1278                                 DBUS_TYPE_DICT_ENTRY, append_routes,
1279                                 provider->user_routes);
1280
1281         connman_dbus_dict_append_array(&dict, "ServerRoutes",
1282                                 DBUS_TYPE_DICT_ENTRY, append_routes,
1283                                 provider->routes);
1284
1285         connman_dbus_dict_close(iter, &dict);
1286 }
1287
1288 static void connection_added_signal(struct vpn_provider *provider)
1289 {
1290         DBusMessage *signal;
1291         DBusMessageIter iter;
1292
1293         signal = dbus_message_new_signal(VPN_MANAGER_PATH,
1294                         VPN_MANAGER_INTERFACE, "ConnectionAdded");
1295         if (signal == NULL)
1296                 return;
1297
1298         dbus_message_iter_init_append(signal, &iter);
1299         dbus_message_iter_append_basic(&iter, DBUS_TYPE_OBJECT_PATH,
1300                                                         &provider->path);
1301         append_properties(&iter, provider);
1302
1303         dbus_connection_send(connection, signal, NULL);
1304         dbus_message_unref(signal);
1305 }
1306
1307 static connman_bool_t check_host(char **hosts, char *host)
1308 {
1309         int i;
1310
1311         if (hosts == NULL)
1312                 return FALSE;
1313
1314         for (i = 0; hosts[i] != NULL; i++) {
1315                 if (g_strcmp0(hosts[i], host) == 0)
1316                         return TRUE;
1317         }
1318
1319         return FALSE;
1320 }
1321
1322 static void provider_append_routes(gpointer key, gpointer value,
1323                                         gpointer user_data)
1324 {
1325         struct vpn_route *route = value;
1326         struct vpn_provider *provider = user_data;
1327         int index = provider->index;
1328
1329         if (handle_routes == FALSE)
1330                 return;
1331
1332         /*
1333          * If the VPN administrator/user has given a route to
1334          * VPN server, then we must discard that because the
1335          * server cannot be contacted via VPN tunnel.
1336          */
1337         if (check_host(provider->host_ip, route->network) == TRUE) {
1338                 DBG("Discarding VPN route to %s via %s at index %d",
1339                         route->network, route->gateway, index);
1340                 return;
1341         }
1342
1343         if (route->family == AF_INET6) {
1344                 unsigned char prefix_len = atoi(route->netmask);
1345
1346                 connman_inet_add_ipv6_network_route(index, route->network,
1347                                                         route->gateway,
1348                                                         prefix_len);
1349         } else {
1350                 connman_inet_add_network_route(index, route->network,
1351                                                 route->gateway,
1352                                                 route->netmask);
1353         }
1354 }
1355
1356 static int set_connected(struct vpn_provider *provider,
1357                                         connman_bool_t connected)
1358 {
1359         struct vpn_ipconfig *ipconfig;
1360
1361         DBG("provider %p id %s connected %d", provider,
1362                                         provider->identifier, connected);
1363
1364         if (connected == TRUE) {
1365                 if (provider->family == AF_INET6)
1366                         ipconfig = provider->ipconfig_ipv6;
1367                 else
1368                         ipconfig = provider->ipconfig_ipv4;
1369
1370                 __vpn_ipconfig_address_add(ipconfig, provider->family);
1371
1372                 if (handle_routes == TRUE)
1373                         __vpn_ipconfig_gateway_add(ipconfig, provider->family);
1374
1375                 provider_indicate_state(provider,
1376                                         VPN_PROVIDER_STATE_READY);
1377
1378                 g_hash_table_foreach(provider->routes, provider_append_routes,
1379                                         provider);
1380
1381                 g_hash_table_foreach(provider->user_routes,
1382                                         provider_append_routes, provider);
1383
1384         } else {
1385                 provider_indicate_state(provider,
1386                                         VPN_PROVIDER_STATE_DISCONNECT);
1387
1388                 provider_indicate_state(provider,
1389                                         VPN_PROVIDER_STATE_IDLE);
1390         }
1391
1392         return 0;
1393 }
1394
1395 int vpn_provider_set_state(struct vpn_provider *provider,
1396                                         enum vpn_provider_state state)
1397 {
1398         if (provider == NULL)
1399                 return -EINVAL;
1400
1401         switch (state) {
1402         case VPN_PROVIDER_STATE_UNKNOWN:
1403                 return -EINVAL;
1404         case VPN_PROVIDER_STATE_IDLE:
1405                 return set_connected(provider, FALSE);
1406         case VPN_PROVIDER_STATE_CONNECT:
1407                 return provider_indicate_state(provider, state);
1408         case VPN_PROVIDER_STATE_READY:
1409                 return set_connected(provider, TRUE);
1410         case VPN_PROVIDER_STATE_DISCONNECT:
1411                 return provider_indicate_state(provider, state);
1412         case VPN_PROVIDER_STATE_FAILURE:
1413                 return provider_indicate_state(provider, state);
1414         }
1415         return -EINVAL;
1416 }
1417
1418 int vpn_provider_indicate_error(struct vpn_provider *provider,
1419                                         enum vpn_provider_error error)
1420 {
1421         DBG("provider %p id %s error %d", provider, provider->identifier,
1422                                                                         error);
1423
1424         switch (error) {
1425         case VPN_PROVIDER_ERROR_LOGIN_FAILED:
1426                 break;
1427         case VPN_PROVIDER_ERROR_AUTH_FAILED:
1428                 break;
1429         case VPN_PROVIDER_ERROR_CONNECT_FAILED:
1430                 break;
1431         default:
1432                 break;
1433         }
1434
1435         return 0;
1436 }
1437
1438 static void unregister_provider(gpointer data)
1439 {
1440         struct vpn_provider *provider = data;
1441
1442         configuration_count_del();
1443
1444         vpn_provider_unref(provider);
1445 }
1446
1447 static void provider_initialize(struct vpn_provider *provider)
1448 {
1449         DBG("provider %p", provider);
1450
1451         provider->index = 0;
1452         provider->fd = -1;
1453         provider->name = NULL;
1454         provider->type = NULL;
1455         provider->domain = NULL;
1456         provider->identifier = NULL;
1457         provider->user_networks = NULL;
1458         provider->routes = g_hash_table_new_full(g_direct_hash, g_direct_equal,
1459                                         NULL, free_route);
1460         provider->user_routes = g_hash_table_new_full(g_str_hash, g_str_equal,
1461                                         g_free, free_route);
1462         provider->setting_strings = g_hash_table_new_full(g_str_hash,
1463                                                 g_str_equal, g_free, g_free);
1464 }
1465
1466 static struct vpn_provider *vpn_provider_new(void)
1467 {
1468         struct vpn_provider *provider;
1469
1470         provider = g_try_new0(struct vpn_provider, 1);
1471         if (provider == NULL)
1472                 return NULL;
1473
1474         provider->refcount = 1;
1475
1476         DBG("provider %p", provider);
1477         provider_initialize(provider);
1478
1479         return provider;
1480 }
1481
1482 static struct vpn_provider *vpn_provider_get(const char *identifier)
1483 {
1484         struct vpn_provider *provider;
1485
1486         provider = g_hash_table_lookup(provider_hash, identifier);
1487         if (provider != NULL)
1488                 return provider;
1489
1490         provider = vpn_provider_new();
1491         if (provider == NULL)
1492                 return NULL;
1493
1494         DBG("provider %p", provider);
1495
1496         provider->identifier = g_strdup(identifier);
1497
1498         g_hash_table_insert(provider_hash, provider->identifier, provider);
1499
1500         configuration_count_add();
1501
1502         return provider;
1503 }
1504
1505 static void provider_dbus_ident(char *ident)
1506 {
1507         int i, len = strlen(ident);
1508
1509         for (i = 0; i < len; i++) {
1510                 if (ident[i] >= '0' && ident[i] <= '9')
1511                         continue;
1512                 if (ident[i] >= 'a' && ident[i] <= 'z')
1513                         continue;
1514                 if (ident[i] >= 'A' && ident[i] <= 'Z')
1515                         continue;
1516                 ident[i] = '_';
1517         }
1518 }
1519
1520 static int connection_unregister(struct vpn_provider *provider)
1521 {
1522         if (provider->path == NULL)
1523                 return -EALREADY;
1524
1525         g_dbus_unregister_interface(connection, provider->path,
1526                                 VPN_CONNECTION_INTERFACE);
1527
1528         g_free(provider->path);
1529         provider->path = NULL;
1530
1531         return 0;
1532 }
1533
1534 static int connection_register(struct vpn_provider *provider)
1535 {
1536         DBG("provider %p path %s", provider, provider->path);
1537
1538         if (provider->path != NULL)
1539                 return -EALREADY;
1540
1541         provider->path = g_strdup_printf("%s/connection/%s", VPN_PATH,
1542                                                 provider->identifier);
1543
1544         g_dbus_register_interface(connection, provider->path,
1545                                 VPN_CONNECTION_INTERFACE,
1546                                 connection_methods, connection_signals,
1547                                 NULL, provider, NULL);
1548
1549         return 0;
1550 }
1551
1552 static struct vpn_provider *provider_create_from_keyfile(GKeyFile *keyfile,
1553                 const char *ident)
1554 {
1555         struct vpn_provider *provider;
1556
1557         if (keyfile == NULL || ident == NULL)
1558                 return NULL;
1559
1560         provider = vpn_provider_lookup(ident);
1561         if (provider == NULL) {
1562                 provider = vpn_provider_get(ident);
1563                 if (provider == NULL) {
1564                         DBG("can not create provider");
1565                         return NULL;
1566                 }
1567
1568                 provider_load_from_keyfile(provider, keyfile);
1569
1570                 if (provider->name == NULL || provider->host == NULL ||
1571                                 provider->domain == NULL) {
1572                         DBG("cannot get name, host or domain");
1573                         vpn_provider_unref(provider);
1574                         return NULL;
1575                 }
1576
1577                 if (provider_register(provider) == 0)
1578                         connection_register(provider);
1579         }
1580         return provider;
1581 }
1582
1583 static void provider_create_all_from_type(const char *provider_type)
1584 {
1585         unsigned int i;
1586         char **providers;
1587         char *id, *type;
1588         GKeyFile *keyfile;
1589
1590         DBG("provider type %s", provider_type);
1591
1592         providers = __connman_storage_get_providers();
1593
1594         for (i = 0; providers[i] != NULL; i+=1) {
1595
1596                 if (strncmp(providers[i], "provider_", 9) != 0)
1597                         continue;
1598
1599                 id = providers[i] + 9;
1600                 keyfile = __connman_storage_load_provider(id);
1601
1602                 if (keyfile == NULL)
1603                         continue;
1604
1605                 type = g_key_file_get_string(keyfile, id, "Type", NULL);
1606
1607                 DBG("keyfile %p id %s type %s", keyfile, id, type);
1608
1609                 if (strcmp(provider_type, type) != 0) {
1610                         g_free(type);
1611                         g_key_file_free(keyfile);
1612                         continue;
1613                 }
1614
1615                 if (provider_create_from_keyfile(keyfile, id) == NULL)
1616                         DBG("could not create provider");
1617
1618                 g_free(type);
1619                 g_key_file_free(keyfile);
1620         }
1621         g_strfreev(providers);
1622 }
1623
1624 int __vpn_provider_create(DBusMessage *msg)
1625 {
1626         struct vpn_provider *provider;
1627         DBusMessageIter iter, array;
1628         const char *type = NULL, *name = NULL;
1629         const char *host = NULL, *domain = NULL;
1630         GSList *networks = NULL;
1631         char *ident;
1632         int err;
1633
1634         dbus_message_iter_init(msg, &iter);
1635         dbus_message_iter_recurse(&iter, &array);
1636
1637         while (dbus_message_iter_get_arg_type(&array) == DBUS_TYPE_DICT_ENTRY) {
1638                 DBusMessageIter entry, value;
1639                 const char *key;
1640
1641                 dbus_message_iter_recurse(&array, &entry);
1642                 dbus_message_iter_get_basic(&entry, &key);
1643
1644                 dbus_message_iter_next(&entry);
1645                 dbus_message_iter_recurse(&entry, &value);
1646
1647                 switch (dbus_message_iter_get_arg_type(&value)) {
1648                 case DBUS_TYPE_STRING:
1649                         if (g_str_equal(key, "Type") == TRUE)
1650                                 dbus_message_iter_get_basic(&value, &type);
1651                         else if (g_str_equal(key, "Name") == TRUE)
1652                                 dbus_message_iter_get_basic(&value, &name);
1653                         else if (g_str_equal(key, "Host") == TRUE)
1654                                 dbus_message_iter_get_basic(&value, &host);
1655                         else if (g_str_equal(key, "VPN.Domain") == TRUE)
1656                                 dbus_message_iter_get_basic(&value, &domain);
1657                         break;
1658                 case DBUS_TYPE_ARRAY:
1659                         if (g_str_equal(key, "UserRoutes") == TRUE)
1660                                 networks = get_user_networks(&value);
1661                         break;
1662                 }
1663
1664                 dbus_message_iter_next(&array);
1665         }
1666
1667         if (host == NULL || domain == NULL)
1668                 return -EINVAL;
1669
1670         DBG("Type %s name %s networks %p", type, name, networks);
1671
1672         if (type == NULL || name == NULL)
1673                 return -EOPNOTSUPP;
1674
1675         ident = g_strdup_printf("%s_%s", host, domain);
1676         provider_dbus_ident(ident);
1677
1678         DBG("ident %s", ident);
1679
1680         provider = vpn_provider_lookup(ident);
1681         if (provider == NULL) {
1682                 provider = vpn_provider_get(ident);
1683                 if (provider == NULL) {
1684                         DBG("can not create provider");
1685                         g_free(ident);
1686                         return -EOPNOTSUPP;
1687                 }
1688
1689                 provider->host = g_strdup(host);
1690                 provider->domain = g_strdup(domain);
1691                 provider->name = g_strdup(name);
1692                 provider->type = g_strdup(type);
1693
1694                 if (provider_register(provider) == 0)
1695                         vpn_provider_load(provider);
1696
1697                 provider_resolv_host_addr(provider);
1698         }
1699
1700         if (networks != NULL) {
1701                 g_slist_free_full(provider->user_networks, free_route);
1702                 provider->user_networks = networks;
1703                 set_user_networks(provider, provider->user_networks);
1704         }
1705
1706         dbus_message_iter_init(msg, &iter);
1707         dbus_message_iter_recurse(&iter, &array);
1708
1709         while (dbus_message_iter_get_arg_type(&array) == DBUS_TYPE_DICT_ENTRY) {
1710                 DBusMessageIter entry, value;
1711                 const char *key, *str;
1712
1713                 dbus_message_iter_recurse(&array, &entry);
1714                 dbus_message_iter_get_basic(&entry, &key);
1715
1716                 dbus_message_iter_next(&entry);
1717                 dbus_message_iter_recurse(&entry, &value);
1718
1719                 switch (dbus_message_iter_get_arg_type(&value)) {
1720                 case DBUS_TYPE_STRING:
1721                         dbus_message_iter_get_basic(&value, &str);
1722                         vpn_provider_set_string(provider, key, str);
1723                         break;
1724                 }
1725
1726                 dbus_message_iter_next(&array);
1727         }
1728
1729         g_free(ident);
1730
1731         vpn_provider_save(provider);
1732
1733         err = provider_register(provider);
1734         if (err != 0 && err != -EALREADY)
1735                 return err;
1736
1737         connection_register(provider);
1738
1739         DBG("provider %p index %d path %s", provider, provider->index,
1740                                                         provider->path);
1741
1742         g_dbus_send_reply(connection, msg,
1743                                 DBUS_TYPE_OBJECT_PATH, &provider->path,
1744                                 DBUS_TYPE_INVALID);
1745
1746         connection_added_signal(provider);
1747
1748         return 0;
1749 }
1750
1751 static void append_connection_structs(DBusMessageIter *iter, void *user_data)
1752 {
1753         DBusMessageIter entry;
1754         GHashTableIter hash;
1755         gpointer value, key;
1756
1757         g_hash_table_iter_init(&hash, provider_hash);
1758
1759         while (g_hash_table_iter_next(&hash, &key, &value) == TRUE) {
1760                 struct vpn_provider *provider = value;
1761
1762                 DBG("path %s", provider->path);
1763
1764                 if (provider->identifier == NULL)
1765                         continue;
1766
1767                 dbus_message_iter_open_container(iter, DBUS_TYPE_STRUCT,
1768                                 NULL, &entry);
1769                 dbus_message_iter_append_basic(&entry, DBUS_TYPE_OBJECT_PATH,
1770                                 &provider->path);
1771                 append_properties(&entry, provider);
1772                 dbus_message_iter_close_container(iter, &entry);
1773         }
1774 }
1775
1776 DBusMessage *__vpn_provider_get_connections(DBusMessage *msg)
1777 {
1778         DBusMessage *reply;
1779
1780         DBG("");
1781
1782         reply = dbus_message_new_method_return(msg);
1783         if (reply == NULL)
1784                 return NULL;
1785
1786         __connman_dbus_append_objpath_dict_array(reply,
1787                         append_connection_structs, NULL);
1788
1789         return reply;
1790 }
1791
1792 const char * __vpn_provider_get_ident(struct vpn_provider *provider)
1793 {
1794         if (provider == NULL)
1795                 return NULL;
1796
1797         return provider->identifier;
1798 }
1799
1800 int vpn_provider_set_string(struct vpn_provider *provider,
1801                                         const char *key, const char *value)
1802 {
1803         DBG("provider %p key %s value %s", provider, key, value);
1804
1805         if (g_str_equal(key, "Type") == TRUE) {
1806                 g_free(provider->type);
1807                 provider->type = g_strdup(value);
1808         } else if (g_str_equal(key, "Name") == TRUE) {
1809                 g_free(provider->name);
1810                 provider->name = g_strdup(value);
1811         } else if (g_str_equal(key, "Host") == TRUE) {
1812                 g_free(provider->host);
1813                 provider->host = g_strdup(value);
1814         } else if (g_str_equal(key, "VPN.Domain") == TRUE) {
1815                 g_free(provider->domain);
1816                 provider->domain = g_strdup(value);
1817         } else
1818                 g_hash_table_replace(provider->setting_strings,
1819                                 g_strdup(key), g_strdup(value));
1820         return 0;
1821 }
1822
1823 const char *vpn_provider_get_string(struct vpn_provider *provider,
1824                                                         const char *key)
1825 {
1826         DBG("provider %p key %s", provider, key);
1827
1828         if (g_str_equal(key, "Type") == TRUE)
1829                 return provider->type;
1830         else if (g_str_equal(key, "Name") == TRUE)
1831                 return provider->name;
1832         else if (g_str_equal(key, "Host") == TRUE)
1833                 return provider->host;
1834         else if (g_str_equal(key, "HostIP") == TRUE) {
1835                 if (provider->host_ip == NULL ||
1836                                 provider->host_ip[0] == NULL)
1837                         return provider->host;
1838                 else
1839                         return provider->host_ip[0];
1840         } else if (g_str_equal(key, "VPN.Domain") == TRUE)
1841                 return provider->domain;
1842
1843         return g_hash_table_lookup(provider->setting_strings, key);
1844 }
1845
1846 connman_bool_t __vpn_provider_check_routes(struct vpn_provider *provider)
1847 {
1848         if (provider == NULL)
1849                 return FALSE;
1850
1851         if (provider->user_routes != NULL &&
1852                         g_hash_table_size(provider->user_routes) > 0)
1853                 return TRUE;
1854
1855         if (provider->routes != NULL &&
1856                         g_hash_table_size(provider->routes) > 0)
1857                 return TRUE;
1858
1859         return FALSE;
1860 }
1861
1862 void *vpn_provider_get_data(struct vpn_provider *provider)
1863 {
1864         return provider->driver_data;
1865 }
1866
1867 void vpn_provider_set_data(struct vpn_provider *provider, void *data)
1868 {
1869         provider->driver_data = data;
1870 }
1871
1872 void vpn_provider_set_index(struct vpn_provider *provider, int index)
1873 {
1874         DBG("index %d provider %p", index, provider);
1875
1876         if (provider->ipconfig_ipv4 == NULL) {
1877                 provider->ipconfig_ipv4 = __vpn_ipconfig_create(index,
1878                                                                 AF_INET);
1879                 if (provider->ipconfig_ipv4 == NULL) {
1880                         DBG("Couldnt create ipconfig for IPv4");
1881                         goto done;
1882                 }
1883         }
1884
1885         __vpn_ipconfig_set_index(provider->ipconfig_ipv4, index);
1886
1887         if (provider->ipconfig_ipv6 == NULL) {
1888                 provider->ipconfig_ipv6 = __vpn_ipconfig_create(index,
1889                                                                 AF_INET6);
1890                 if (provider->ipconfig_ipv6 == NULL) {
1891                         DBG("Couldnt create ipconfig for IPv6");
1892                         goto done;
1893                 }
1894         }
1895
1896         __vpn_ipconfig_set_index(provider->ipconfig_ipv6, index);
1897
1898 done:
1899         provider->index = index;
1900 }
1901
1902 int vpn_provider_get_index(struct vpn_provider *provider)
1903 {
1904         return provider->index;
1905 }
1906
1907 int vpn_provider_set_ipaddress(struct vpn_provider *provider,
1908                                         struct connman_ipaddress *ipaddress)
1909 {
1910         struct vpn_ipconfig *ipconfig = NULL;
1911
1912         switch (ipaddress->family) {
1913         case AF_INET:
1914                 ipconfig = provider->ipconfig_ipv4;
1915                 break;
1916         case AF_INET6:
1917                 ipconfig = provider->ipconfig_ipv6;
1918                 break;
1919         default:
1920                 break;
1921         }
1922
1923         DBG("provider %p ipconfig %p family %d", provider, ipconfig,
1924                                                         ipaddress->family);
1925
1926         if (ipconfig == NULL)
1927                 return -EINVAL;
1928
1929         provider->family = ipaddress->family;
1930
1931         __vpn_ipconfig_set_local(ipconfig, ipaddress->local);
1932         __vpn_ipconfig_set_peer(ipconfig, ipaddress->peer);
1933         __vpn_ipconfig_set_broadcast(ipconfig, ipaddress->broadcast);
1934         __vpn_ipconfig_set_gateway(ipconfig, ipaddress->gateway);
1935         __vpn_ipconfig_set_prefixlen(ipconfig, ipaddress->prefixlen);
1936
1937         return 0;
1938 }
1939
1940 int vpn_provider_set_pac(struct vpn_provider *provider,
1941                                 const char *pac)
1942 {
1943         DBG("provider %p pac %s", provider, pac);
1944
1945         return 0;
1946 }
1947
1948
1949 int vpn_provider_set_domain(struct vpn_provider *provider,
1950                                         const char *domain)
1951 {
1952         DBG("provider %p domain %s", provider, domain);
1953
1954         g_free(provider->domain);
1955         provider->domain = g_strdup(domain);
1956
1957         return 0;
1958 }
1959
1960 int vpn_provider_set_nameservers(struct vpn_provider *provider,
1961                                         const char *nameservers)
1962 {
1963         DBG("provider %p nameservers %s", provider, nameservers);
1964
1965         g_strfreev(provider->nameservers);
1966         provider->nameservers = NULL;
1967
1968         if (nameservers == NULL)
1969                 return 0;
1970
1971         provider->nameservers = g_strsplit(nameservers, " ", 0);
1972
1973         return 0;
1974 }
1975
1976 enum provider_route_type {
1977         PROVIDER_ROUTE_TYPE_NONE = 0,
1978         PROVIDER_ROUTE_TYPE_MASK = 1,
1979         PROVIDER_ROUTE_TYPE_ADDR = 2,
1980         PROVIDER_ROUTE_TYPE_GW   = 3,
1981 };
1982
1983 static int route_env_parse(struct vpn_provider *provider, const char *key,
1984                                 int *family, unsigned long *idx,
1985                                 enum provider_route_type *type)
1986 {
1987         char *end;
1988         const char *start;
1989
1990         DBG("name %s", provider->name);
1991
1992         if (!strcmp(provider->type, "openvpn")) {
1993                 if (g_str_has_prefix(key, "route_network_") == TRUE) {
1994                         start = key + strlen("route_network_");
1995                         *type = PROVIDER_ROUTE_TYPE_ADDR;
1996                 } else if (g_str_has_prefix(key, "route_netmask_") == TRUE) {
1997                         start = key + strlen("route_netmask_");
1998                         *type = PROVIDER_ROUTE_TYPE_MASK;
1999                 } else if (g_str_has_prefix(key, "route_gateway_") == TRUE) {
2000                         start = key + strlen("route_gateway_");
2001                         *type = PROVIDER_ROUTE_TYPE_GW;
2002                 } else
2003                         return -EINVAL;
2004
2005                 *family = AF_INET;
2006                 *idx = g_ascii_strtoull(start, &end, 10);
2007
2008         } else if (!strcmp(provider->type, "openconnect")) {
2009                 if (g_str_has_prefix(key, "CISCO_SPLIT_INC_") == TRUE) {
2010                         *family = AF_INET;
2011                         start = key + strlen("CISCO_SPLIT_INC_");
2012                 } else if (g_str_has_prefix(key,
2013                                         "CISCO_IPV6_SPLIT_INC_") == TRUE) {
2014                         *family = AF_INET6;
2015                         start = key + strlen("CISCO_IPV6_SPLIT_INC_");
2016                 } else
2017                         return -EINVAL;
2018
2019                 *idx = g_ascii_strtoull(start, &end, 10);
2020
2021                 if (strncmp(end, "_ADDR", 5) == 0)
2022                         *type = PROVIDER_ROUTE_TYPE_ADDR;
2023                 else if (strncmp(end, "_MASK", 5) == 0)
2024                         *type = PROVIDER_ROUTE_TYPE_MASK;
2025                 else if (strncmp(end, "_MASKLEN", 8) == 0 &&
2026                                 *family == AF_INET6) {
2027                         *type = PROVIDER_ROUTE_TYPE_MASK;
2028                 } else
2029                         return -EINVAL;
2030         }
2031
2032         return 0;
2033 }
2034
2035 int vpn_provider_append_route(struct vpn_provider *provider,
2036                                         const char *key, const char *value)
2037 {
2038         struct vpn_route *route;
2039         int ret, family = 0;
2040         unsigned long idx = 0;
2041         enum provider_route_type type = PROVIDER_ROUTE_TYPE_NONE;
2042
2043         DBG("key %s value %s", key, value);
2044
2045         ret = route_env_parse(provider, key, &family, &idx, &type);
2046         if (ret < 0)
2047                 return ret;
2048
2049         DBG("idx %lu family %d type %d", idx, family, type);
2050
2051         route = g_hash_table_lookup(provider->routes, GINT_TO_POINTER(idx));
2052         if (route == NULL) {
2053                 route = g_try_new0(struct vpn_route, 1);
2054                 if (route == NULL) {
2055                         connman_error("out of memory");
2056                         return -ENOMEM;
2057                 }
2058
2059                 route->family = family;
2060
2061                 g_hash_table_replace(provider->routes, GINT_TO_POINTER(idx),
2062                                                 route);
2063         }
2064
2065         switch (type) {
2066         case PROVIDER_ROUTE_TYPE_NONE:
2067                 break;
2068         case PROVIDER_ROUTE_TYPE_MASK:
2069                 route->netmask = g_strdup(value);
2070                 break;
2071         case PROVIDER_ROUTE_TYPE_ADDR:
2072                 route->network = g_strdup(value);
2073                 break;
2074         case PROVIDER_ROUTE_TYPE_GW:
2075                 route->gateway = g_strdup(value);
2076                 break;
2077         }
2078
2079         if (handle_routes == FALSE) {
2080                 if (route->netmask != NULL && route->gateway != NULL &&
2081                                                         route->network != NULL)
2082                         provider_schedule_changed(provider,
2083                                                 SERVER_ROUTES_CHANGED);
2084         }
2085
2086         return 0;
2087 }
2088
2089 const char *vpn_provider_get_driver_name(struct vpn_provider *provider)
2090 {
2091         if (provider->driver == NULL)
2092                 return NULL;
2093
2094         return provider->driver->name;
2095 }
2096
2097 const char *vpn_provider_get_save_group(struct vpn_provider *provider)
2098 {
2099         return provider->identifier;
2100 }
2101
2102 static gint compare_priority(gconstpointer a, gconstpointer b)
2103 {
2104         return 0;
2105 }
2106
2107 static void clean_provider(gpointer key, gpointer value, gpointer user_data)
2108 {
2109         struct vpn_provider *provider = value;
2110
2111         if (provider->driver != NULL && provider->driver->remove)
2112                 provider->driver->remove(provider);
2113
2114         connection_unregister(provider);
2115 }
2116
2117 int vpn_provider_driver_register(struct vpn_provider_driver *driver)
2118 {
2119         DBG("driver %p name %s", driver, driver->name);
2120
2121         driver_list = g_slist_insert_sorted(driver_list, driver,
2122                                                         compare_priority);
2123         provider_create_all_from_type(driver->name);
2124         return 0;
2125 }
2126
2127 void vpn_provider_driver_unregister(struct vpn_provider_driver *driver)
2128 {
2129         GHashTableIter iter;
2130         gpointer value, key;
2131
2132         DBG("driver %p name %s", driver, driver->name);
2133
2134         driver_list = g_slist_remove(driver_list, driver);
2135
2136         g_hash_table_iter_init(&iter, provider_hash);
2137         while (g_hash_table_iter_next(&iter, &key, &value) == TRUE) {
2138                 struct vpn_provider *provider = value;
2139
2140                 if (provider != NULL && provider->driver != NULL &&
2141                                 provider->driver->type == driver->type &&
2142                                 g_strcmp0(provider->driver->name,
2143                                                         driver->name) == 0) {
2144                         provider->driver = NULL;
2145                 }
2146         }
2147 }
2148
2149 static gboolean check_vpn_count(gpointer data)
2150 {
2151         if (configuration_count == 0) {
2152                 connman_info("No VPN configurations found, quitting.");
2153                 raise(SIGTERM);
2154         }
2155
2156         return FALSE;
2157 }
2158
2159 void __vpn_provider_check_connections(void)
2160 {
2161         /*
2162          * If we were started when there is no providers configured,
2163          * then just quit. This happens when connman starts and its
2164          * vpn plugin asks connman-vpnd if it has any connections
2165          * configured. If there are none, then we can stop the vpn
2166          * daemon.
2167          */
2168         g_timeout_add(1000, check_vpn_count, NULL);
2169 }
2170
2171 const char *vpn_provider_get_name(struct vpn_provider *provider)
2172 {
2173         return provider->name;
2174 }
2175
2176 const char *vpn_provider_get_host(struct vpn_provider *provider)
2177 {
2178         return provider->host;
2179 }
2180
2181 const char *vpn_provider_get_path(struct vpn_provider *provider)
2182 {
2183         return provider->path;
2184 }
2185
2186 int __vpn_provider_init(gboolean do_routes)
2187 {
2188         DBG("");
2189
2190         handle_routes = do_routes;
2191
2192         connection = connman_dbus_get_connection();
2193
2194         provider_hash = g_hash_table_new_full(g_str_hash, g_str_equal,
2195                                                 NULL, unregister_provider);
2196
2197         return 0;
2198 }
2199
2200 void __vpn_provider_cleanup(void)
2201 {
2202         DBG("");
2203
2204         g_hash_table_foreach(provider_hash, clean_provider, NULL);
2205
2206         g_hash_table_destroy(provider_hash);
2207         provider_hash = NULL;
2208
2209         dbus_connection_unref(connection);
2210 }