vpn-provider: Allow use of Domain property name
[platform/upstream/connman.git] / vpn / vpn-provider.c
1 /*
2  *
3  *  ConnMan VPN daemon
4  *
5  *  Copyright (C) 2012  Intel Corporation. All rights reserved.
6  *
7  *  This program is free software; you can redistribute it and/or modify
8  *  it under the terms of the GNU General Public License version 2 as
9  *  published by the Free Software Foundation.
10  *
11  *  This program is distributed in the hope that it will be useful,
12  *  but WITHOUT ANY WARRANTY; without even the implied warranty of
13  *  MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
14  *  GNU General Public License for more details.
15  *
16  *  You should have received a copy of the GNU General Public License
17  *  along with this program; if not, write to the Free Software
18  *  Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA  02110-1301  USA
19  *
20  */
21
22 #ifdef HAVE_CONFIG_H
23 #include <config.h>
24 #endif
25
26 #include <errno.h>
27 #include <stdio.h>
28 #include <string.h>
29 #include <stdlib.h>
30 #include <gdbus.h>
31 #include <connman/log.h>
32 #include <gweb/gresolv.h>
33 #include <netdb.h>
34
35 #include "../src/connman.h"
36 #include "connman/agent.h"
37 #include "connman/vpn-dbus.h"
38 #include "vpn-provider.h"
39 #include "vpn.h"
40
41 static DBusConnection *connection;
42 static GHashTable *provider_hash;
43 static GSList *driver_list;
44 static int configuration_count;
45 static gboolean handle_routes;
46
47 struct vpn_route {
48         int family;
49         char *network;
50         char *netmask;
51         char *gateway;
52 };
53
54 struct vpn_setting {
55         gboolean hide_value;
56         char *value;
57 };
58
59 struct vpn_provider {
60         int refcount;
61         int index;
62         int fd;
63         enum vpn_provider_state state;
64         char *path;
65         char *identifier;
66         char *name;
67         char *type;
68         char *host;
69         char *domain;
70         int family;
71         GHashTable *routes;
72         struct vpn_provider_driver *driver;
73         void *driver_data;
74         GHashTable *setting_strings;
75         GHashTable *user_routes;
76         GSList *user_networks;
77         GResolv *resolv;
78         char **host_ip;
79         struct vpn_ipconfig *ipconfig_ipv4;
80         struct vpn_ipconfig *ipconfig_ipv6;
81         char **nameservers;
82         guint notify_id;
83         char *config_file;
84         char *config_entry;
85 };
86
87 static void append_properties(DBusMessageIter *iter,
88                                 struct vpn_provider *provider);
89
90 static void free_route(gpointer data)
91 {
92         struct vpn_route *route = data;
93
94         g_free(route->network);
95         g_free(route->netmask);
96         g_free(route->gateway);
97
98         g_free(route);
99 }
100
101 static void free_setting(gpointer data)
102 {
103         struct vpn_setting *setting = data;
104
105         g_free(setting->value);
106         g_free(setting);
107 }
108
109 static void append_route(DBusMessageIter *iter, void *user_data)
110 {
111         struct vpn_route *route = user_data;
112         DBusMessageIter item;
113         int family = 0;
114
115         connman_dbus_dict_open(iter, &item);
116
117         if (route == NULL)
118                 goto empty_dict;
119
120         if (route->family == AF_INET)
121                 family = 4;
122         else if (route->family == AF_INET6)
123                 family = 6;
124
125         if (family != 0)
126                 connman_dbus_dict_append_basic(&item, "ProtocolFamily",
127                                         DBUS_TYPE_INT32, &family);
128
129         if (route->network != NULL)
130                 connman_dbus_dict_append_basic(&item, "Network",
131                                         DBUS_TYPE_STRING, &route->network);
132
133         if (route->netmask != NULL)
134                 connman_dbus_dict_append_basic(&item, "Netmask",
135                                         DBUS_TYPE_STRING, &route->netmask);
136
137         if (route->gateway != NULL)
138                 connman_dbus_dict_append_basic(&item, "Gateway",
139                                         DBUS_TYPE_STRING, &route->gateway);
140
141 empty_dict:
142         connman_dbus_dict_close(iter, &item);
143 }
144
145 static void append_routes(DBusMessageIter *iter, void *user_data)
146 {
147         GHashTable *routes = user_data;
148         GHashTableIter hash;
149         gpointer value, key;
150
151         if (routes == NULL) {
152                 append_route(iter, NULL);
153                 return;
154         }
155
156         g_hash_table_iter_init(&hash, routes);
157
158         while (g_hash_table_iter_next(&hash, &key, &value) == TRUE) {
159                 DBusMessageIter dict;
160
161                 dbus_message_iter_open_container(iter, DBUS_TYPE_STRUCT, NULL,
162                                                 &dict);
163                 append_route(&dict, value);
164                 dbus_message_iter_close_container(iter, &dict);
165         }
166 }
167
168 static void send_routes(struct vpn_provider *provider, GHashTable *routes,
169                         const char *name)
170 {
171         connman_dbus_property_changed_array(provider->path,
172                                         VPN_CONNECTION_INTERFACE,
173                                         name,
174                                         DBUS_TYPE_DICT_ENTRY,
175                                         append_routes,
176                                         routes);
177 }
178
179 static int provider_routes_changed(struct vpn_provider *provider)
180 {
181         DBG("provider %p", provider);
182
183         send_routes(provider, provider->routes, "ServerRoutes");
184
185         return 0;
186 }
187
188 static GSList *read_route_dict(GSList *routes, DBusMessageIter *dicts)
189 {
190         DBusMessageIter dict, value, entry;
191         const char *network, *netmask, *gateway;
192         struct vpn_route *route;
193         int family, type;
194         const char *key;
195
196         dbus_message_iter_recurse(dicts, &entry);
197
198         network = netmask = gateway = NULL;
199         family = PF_UNSPEC;
200
201         while (dbus_message_iter_get_arg_type(&entry) == DBUS_TYPE_DICT_ENTRY) {
202
203                 dbus_message_iter_recurse(&entry, &dict);
204                 dbus_message_iter_get_basic(&dict, &key);
205
206                 dbus_message_iter_next(&dict);
207                 dbus_message_iter_recurse(&dict, &value);
208
209                 type = dbus_message_iter_get_arg_type(&value);
210
211                 switch (type) {
212                 case DBUS_TYPE_STRING:
213                         if (g_str_equal(key, "ProtocolFamily") == TRUE)
214                                 dbus_message_iter_get_basic(&value, &family);
215                         else if (g_str_equal(key, "Network") == TRUE)
216                                 dbus_message_iter_get_basic(&value, &network);
217                         else if (g_str_equal(key, "Netmask") == TRUE)
218                                 dbus_message_iter_get_basic(&value, &netmask);
219                         else if (g_str_equal(key, "Gateway") == TRUE)
220                                 dbus_message_iter_get_basic(&value, &gateway);
221                         break;
222                 }
223
224                 dbus_message_iter_next(&entry);
225         }
226
227         DBG("family %d network %s netmask %s gateway %s", family,
228                 network, netmask, gateway);
229
230         if (network == NULL || netmask == NULL) {
231                 DBG("Ignoring route as network/netmask is missing");
232                 return routes;
233         }
234
235         route = g_try_new(struct vpn_route, 1);
236         if (route == NULL) {
237                 g_slist_free_full(routes, free_route);
238                 return NULL;
239         }
240
241         if (family == PF_UNSPEC) {
242                 family = connman_inet_check_ipaddress(network);
243                 if (family < 0) {
244                         DBG("Cannot get address family of %s (%d/%s)", network,
245                                 family, gai_strerror(family));
246
247                         g_free(route);
248                         return routes;
249                 }
250         } else {
251                 switch (family) {
252                 case '4':
253                         family = AF_INET;
254                         break;
255                 case '6':
256                         family = AF_INET6;
257                         break;
258                 default:
259                         family = PF_UNSPEC;
260                         break;
261                 }
262         }
263
264         route->family = family;
265         route->network = g_strdup(network);
266         route->netmask = g_strdup(netmask);
267         route->gateway = g_strdup(gateway);
268
269         routes = g_slist_prepend(routes, route);
270         return routes;
271 }
272
273 static GSList *get_user_networks(DBusMessageIter *array)
274 {
275         DBusMessageIter entry;
276         GSList *list = NULL;
277
278         while (dbus_message_iter_get_arg_type(array) == DBUS_TYPE_ARRAY) {
279
280                 dbus_message_iter_recurse(array, &entry);
281
282                 while (dbus_message_iter_get_arg_type(&entry) ==
283                                                         DBUS_TYPE_STRUCT) {
284                         DBusMessageIter dicts;
285
286                         dbus_message_iter_recurse(&entry, &dicts);
287
288                         while (dbus_message_iter_get_arg_type(&dicts) ==
289                                                         DBUS_TYPE_ARRAY) {
290
291                                 list = read_route_dict(list, &dicts);
292                                 dbus_message_iter_next(&dicts);
293                         }
294
295                         dbus_message_iter_next(&entry);
296                 }
297
298                 dbus_message_iter_next(array);
299         }
300
301         return list;
302 }
303
304 static void set_user_networks(struct vpn_provider *provider, GSList *networks)
305 {
306         GSList *list;
307
308         for (list = networks; list != NULL; list = g_slist_next(list)) {
309                 struct vpn_route *route = list->data;
310
311                 if (__vpn_provider_append_user_route(provider,
312                                         route->family, route->network,
313                                         route->netmask, route->gateway) != 0)
314                         break;
315         }
316 }
317
318 static void del_routes(struct vpn_provider *provider)
319 {
320         GHashTableIter hash;
321         gpointer value, key;
322
323         g_hash_table_iter_init(&hash, provider->user_routes);
324         while (handle_routes == TRUE && g_hash_table_iter_next(&hash,
325                                                 &key, &value) == TRUE) {
326                 struct vpn_route *route = value;
327                 if (route->family == AF_INET6) {
328                         unsigned char prefixlen = atoi(route->netmask);
329                         connman_inet_del_ipv6_network_route(provider->index,
330                                                         route->network,
331                                                         prefixlen);
332                 } else
333                         connman_inet_del_host_route(provider->index,
334                                                 route->network);
335         }
336
337         g_hash_table_remove_all(provider->user_routes);
338         g_slist_free_full(provider->user_networks, free_route);
339         provider->user_networks = NULL;
340 }
341
342 static void send_value(const char *path, const char *key, const char *value)
343 {
344         const char *empty = "";
345         const char *str;
346
347         if (value != NULL)
348                 str = value;
349         else
350                 str = empty;
351
352         connman_dbus_property_changed_basic(path,
353                                         VPN_CONNECTION_INTERFACE,
354                                         key,
355                                         DBUS_TYPE_STRING,
356                                         &str);
357 }
358
359 static gboolean provider_send_changed(gpointer data)
360 {
361         struct vpn_provider *provider = data;
362
363         provider_routes_changed(provider);
364
365         provider->notify_id = 0;
366
367         return FALSE;
368 }
369
370 static void provider_schedule_changed(struct vpn_provider *provider)
371 {
372         if (provider->notify_id != 0)
373                 g_source_remove(provider->notify_id);
374
375         provider->notify_id = g_timeout_add(100, provider_send_changed,
376                                                                 provider);
377 }
378
379 static DBusMessage *get_properties(DBusConnection *conn,
380                                         DBusMessage *msg, void *data)
381 {
382         struct vpn_provider *provider = data;
383         DBusMessage *reply;
384         DBusMessageIter array;
385
386         DBG("provider %p", provider);
387
388         reply = dbus_message_new_method_return(msg);
389         if (reply == NULL)
390                 return NULL;
391
392         dbus_message_iter_init_append(reply, &array);
393
394         append_properties(&array, provider);
395
396         return reply;
397 }
398
399 static DBusMessage *set_property(DBusConnection *conn, DBusMessage *msg,
400                                                                 void *data)
401 {
402         struct vpn_provider *provider = data;
403         DBusMessageIter iter, value;
404         const char *name;
405         int type;
406
407         DBG("conn %p", conn);
408
409         if (dbus_message_iter_init(msg, &iter) == FALSE)
410                 return __connman_error_invalid_arguments(msg);
411
412         if (dbus_message_iter_get_arg_type(&iter) != DBUS_TYPE_STRING)
413                 return __connman_error_invalid_arguments(msg);
414
415         dbus_message_iter_get_basic(&iter, &name);
416         dbus_message_iter_next(&iter);
417
418         if (dbus_message_iter_get_arg_type(&iter) != DBUS_TYPE_VARIANT)
419                 return __connman_error_invalid_arguments(msg);
420
421         dbus_message_iter_recurse(&iter, &value);
422
423         type = dbus_message_iter_get_arg_type(&value);
424
425         if (g_str_equal(name, "UserRoutes") == TRUE) {
426                 GSList *networks;
427
428                 if (type != DBUS_TYPE_ARRAY)
429                         return __connman_error_invalid_arguments(msg);
430
431                 networks = get_user_networks(&value);
432                 if (networks != NULL) {
433                         del_routes(provider);
434                         provider->user_networks = networks;
435                         set_user_networks(provider, provider->user_networks);
436
437                         if (handle_routes == FALSE)
438                                 send_routes(provider, provider->user_routes,
439                                                                 "UserRoutes");
440                 }
441         } else
442                 return __connman_error_invalid_property(msg);
443
444         return g_dbus_create_reply(msg, DBUS_TYPE_INVALID);
445 }
446
447 static DBusMessage *clear_property(DBusConnection *conn, DBusMessage *msg,
448                                                                 void *data)
449 {
450         struct vpn_provider *provider = data;
451         const char *name;
452
453         DBG("conn %p", conn);
454
455         dbus_message_get_args(msg, NULL, DBUS_TYPE_STRING, &name,
456                                                         DBUS_TYPE_INVALID);
457
458         if (g_str_equal(name, "UserRoutes") == TRUE) {
459                 del_routes(provider);
460
461                 if (handle_routes == FALSE)
462                         send_routes(provider, provider->user_routes, name);
463         } else {
464                 return __connman_error_invalid_property(msg);
465         }
466
467         return g_dbus_create_reply(msg, DBUS_TYPE_INVALID);
468 }
469
470 static DBusMessage *do_connect(DBusConnection *conn, DBusMessage *msg,
471                                                                 void *data)
472 {
473         struct vpn_provider *provider = data;
474         int err;
475
476         DBG("conn %p provider %p", conn, provider);
477
478         err = __vpn_provider_connect(provider, msg);
479         if (err < 0)
480                 return __connman_error_failed(msg, -err);
481
482         return NULL;
483 }
484
485 static DBusMessage *do_disconnect(DBusConnection *conn, DBusMessage *msg,
486                                                                 void *data)
487 {
488         struct vpn_provider *provider = data;
489         int err;
490
491         DBG("conn %p provider %p", conn, provider);
492
493         err = __vpn_provider_disconnect(provider);
494         if (err < 0 && err != -EINPROGRESS)
495                 return __connman_error_failed(msg, -err);
496
497         return g_dbus_create_reply(msg, DBUS_TYPE_INVALID);
498 }
499
500 static const GDBusMethodTable connection_methods[] = {
501         { GDBUS_METHOD("GetProperties",
502                         NULL, GDBUS_ARGS({ "properties", "a{sv}" }),
503                         get_properties) },
504         { GDBUS_METHOD("SetProperty",
505                         GDBUS_ARGS({ "name", "s" }, { "value", "v" }),
506                         NULL, set_property) },
507         { GDBUS_METHOD("ClearProperty",
508                         GDBUS_ARGS({ "name", "s" }), NULL,
509                         clear_property) },
510         { GDBUS_ASYNC_METHOD("Connect", NULL, NULL, do_connect) },
511         { GDBUS_METHOD("Disconnect", NULL, NULL, do_disconnect) },
512         { },
513 };
514
515 static const GDBusSignalTable connection_signals[] = {
516         { GDBUS_SIGNAL("PropertyChanged",
517                         GDBUS_ARGS({ "name", "s" }, { "value", "v" })) },
518         { },
519 };
520
521 static void resolv_result(GResolvResultStatus status,
522                                         char **results, gpointer user_data)
523 {
524         struct vpn_provider *provider = user_data;
525
526         DBG("status %d", status);
527
528         if (status == G_RESOLV_RESULT_STATUS_SUCCESS && results != NULL &&
529                                                 g_strv_length(results) > 0)
530                 provider->host_ip = g_strdupv(results);
531
532         vpn_provider_unref(provider);
533 }
534
535 static void provider_resolv_host_addr(struct vpn_provider *provider)
536 {
537         if (provider->host == NULL)
538                 return;
539
540         if (connman_inet_check_ipaddress(provider->host) > 0)
541                 return;
542
543         if (provider->host_ip != NULL)
544                 return;
545
546         /*
547          * If the hostname is not numeric, try to resolv it. We do not wait
548          * the result as it might take some time. We will get the result
549          * before VPN will feed routes to us because VPN client will need
550          * the IP address also before VPN connection can be established.
551          */
552         provider->resolv = g_resolv_new(0);
553         if (provider->resolv == NULL) {
554                 DBG("Cannot resolv %s", provider->host);
555                 return;
556         }
557
558         DBG("Trying to resolv %s", provider->host);
559
560         vpn_provider_ref(provider);
561
562         g_resolv_lookup_hostname(provider->resolv, provider->host,
563                                 resolv_result, provider);
564 }
565
566 void __vpn_provider_append_properties(struct vpn_provider *provider,
567                                                         DBusMessageIter *iter)
568 {
569         if (provider->host != NULL)
570                 connman_dbus_dict_append_basic(iter, "Host",
571                                         DBUS_TYPE_STRING, &provider->host);
572
573         if (provider->domain != NULL)
574                 connman_dbus_dict_append_basic(iter, "Domain",
575                                         DBUS_TYPE_STRING, &provider->domain);
576
577         if (provider->type != NULL)
578                 connman_dbus_dict_append_basic(iter, "Type", DBUS_TYPE_STRING,
579                                                  &provider->type);
580 }
581
582 int __vpn_provider_append_user_route(struct vpn_provider *provider,
583                                 int family, const char *network,
584                                 const char *netmask, const char *gateway)
585 {
586         struct vpn_route *route;
587         char *key = g_strdup_printf("%d/%s/%s/%s", family, network,
588                                 netmask, gateway != NULL ? gateway : "");
589
590         DBG("family %d network %s netmask %s gw %s", family, network,
591                                                         netmask, gateway);
592
593         route = g_hash_table_lookup(provider->user_routes, key);
594         if (route == NULL) {
595                 route = g_try_new0(struct vpn_route, 1);
596                 if (route == NULL) {
597                         connman_error("out of memory");
598                         return -ENOMEM;
599                 }
600
601                 route->family = family;
602                 route->network = g_strdup(network);
603                 route->netmask = g_strdup(netmask);
604                 route->gateway = g_strdup(gateway);
605
606                 g_hash_table_replace(provider->user_routes, key, route);
607         } else
608                 g_free(key);
609
610         return 0;
611 }
612
613 static struct vpn_route *get_route(char *route_str)
614 {
615         char **elems = g_strsplit(route_str, "/", 0);
616         char *network, *netmask, *gateway, *family_str;
617         int family = PF_UNSPEC;
618         struct vpn_route *route = NULL;
619
620         if (elems == NULL)
621                 return NULL;
622
623         family_str = elems[0];
624
625         network = elems[1];
626         if (network == NULL || network[0] == '\0')
627                 goto out;
628
629         netmask = elems[2];
630         if (netmask == NULL || netmask[0] == '\0')
631                 goto out;
632
633         gateway = elems[3];
634
635         route = g_try_new0(struct vpn_route, 1);
636         if (route == NULL)
637                 goto out;
638
639         if (family_str[0] == '\0' || atoi(family_str) == 0) {
640                 family = PF_UNSPEC;
641         } else {
642                 switch (family_str[0]) {
643                 case '4':
644                         family = AF_INET;
645                         break;
646                 case '6':
647                         family = AF_INET6;
648                         break;
649                 }
650         }
651
652         if (g_strrstr(network, ":") != NULL) {
653                 if (family != PF_UNSPEC && family != AF_INET6)
654                         DBG("You have IPv6 address but you have non IPv6 route");
655         } else if (g_strrstr(network, ".") != NULL) {
656                 if (family != PF_UNSPEC && family != AF_INET)
657                         DBG("You have IPv4 address but you have non IPv4 route");
658
659                 if (g_strrstr(netmask, ".") == NULL) {
660                         /* We have netmask length */
661                         in_addr_t addr;
662                         struct in_addr netmask_in;
663                         unsigned char prefix_len = 32;
664
665                         if (netmask != NULL) {
666                                 char *ptr;
667                                 long int value = strtol(netmask, &ptr, 10);
668                                 if (ptr != netmask && *ptr == '\0' &&
669                                                                 value <= 32)
670                                         prefix_len = value;
671                         }
672
673                         addr = 0xffffffff << (32 - prefix_len);
674                         netmask_in.s_addr = htonl(addr);
675                         netmask = inet_ntoa(netmask_in);
676
677                         DBG("network %s netmask %s", network, netmask);
678                 }
679         }
680
681         if (family == PF_UNSPEC) {
682                 family = connman_inet_check_ipaddress(network);
683                 if (family < 0 || family == PF_UNSPEC)
684                         goto out;
685         }
686
687         route->family = family;
688         route->network = g_strdup(network);
689         route->netmask = g_strdup(netmask);
690         route->gateway = g_strdup(gateway);
691
692 out:
693         g_strfreev(elems);
694         return route;
695 }
696
697 static GSList *get_routes(gchar **networks)
698 {
699         struct vpn_route *route;
700         GSList *routes = NULL;
701         int i;
702
703         for (i = 0; networks[i] != NULL; i++) {
704                 route = get_route(networks[i]);
705                 if (route != NULL)
706                         routes = g_slist_prepend(routes, route);
707         }
708
709         return routes;
710 }
711
712 static int provider_load_from_keyfile(struct vpn_provider *provider,
713                 GKeyFile *keyfile)
714 {
715         gsize idx = 0;
716         gchar **settings;
717         gchar *key, *value;
718         gsize length, num_user_networks;
719         gchar **networks = NULL;
720
721         settings = g_key_file_get_keys(keyfile, provider->identifier, &length,
722                                 NULL);
723         if (settings == NULL) {
724                 g_key_file_free(keyfile);
725                 return -ENOENT;
726         }
727
728         while (idx < length) {
729                 key = settings[idx];
730                 if (key != NULL) {
731                         if (g_str_equal(key, "Networks") == TRUE) {
732                                 networks = g_key_file_get_string_list(keyfile,
733                                                 provider->identifier,
734                                                 key,
735                                                 &num_user_networks,
736                                                 NULL);
737                                 provider->user_networks = get_routes(networks);
738
739                         } else {
740                                 value = g_key_file_get_string(keyfile,
741                                                         provider->identifier,
742                                                         key, NULL);
743                                 vpn_provider_set_string(provider, key,
744                                                         value);
745                                 g_free(value);
746                         }
747                 }
748                 idx += 1;
749         }
750         g_strfreev(settings);
751         g_strfreev(networks);
752
753         if (provider->user_networks != NULL)
754                 set_user_networks(provider, provider->user_networks);
755
756         return 0;
757 }
758
759
760 static int vpn_provider_load(struct vpn_provider *provider)
761 {
762         GKeyFile *keyfile;
763
764         DBG("provider %p", provider);
765
766         keyfile = __connman_storage_load_provider(provider->identifier);
767         if (keyfile == NULL)
768                 return -ENOENT;
769
770         provider_load_from_keyfile(provider, keyfile);
771
772         g_key_file_free(keyfile);
773         return 0;
774 }
775
776 static gchar **create_network_list(GSList *networks, gsize *count)
777 {
778         GSList *list;
779         gchar **result = NULL;
780         unsigned int num_elems = 0;
781
782         for (list = networks; list != NULL; list = g_slist_next(list)) {
783                 struct vpn_route *route = list->data;
784                 int family;
785
786                 result = g_try_realloc(result,
787                                 (num_elems + 1) * sizeof(gchar *));
788                 if (result == NULL)
789                         return NULL;
790
791                 switch (route->family) {
792                 case AF_INET:
793                         family = 4;
794                         break;
795                 case AF_INET6:
796                         family = 6;
797                         break;
798                 default:
799                         family = 0;
800                         break;
801                 }
802
803                 result[num_elems] = g_strdup_printf("%d/%s/%s/%s",
804                                 family, route->network, route->netmask,
805                                 route->gateway == NULL ? "" : route->gateway);
806
807                 num_elems++;
808         }
809
810         result = g_try_realloc(result, (num_elems + 1) * sizeof(gchar *));
811         if (result == NULL)
812                 return NULL;
813
814         result[num_elems] = NULL;
815         *count = num_elems;
816         return result;
817 }
818
819 static int vpn_provider_save(struct vpn_provider *provider)
820 {
821         GKeyFile *keyfile;
822
823         DBG("provider %p", provider);
824
825         keyfile = g_key_file_new();
826         if (keyfile == NULL)
827                 return -ENOMEM;
828
829         g_key_file_set_string(keyfile, provider->identifier,
830                         "Name", provider->name);
831         g_key_file_set_string(keyfile, provider->identifier,
832                         "Type", provider->type);
833         g_key_file_set_string(keyfile, provider->identifier,
834                         "Host", provider->host);
835         g_key_file_set_string(keyfile, provider->identifier,
836                         "VPN.Domain", provider->domain);
837         if (provider->user_networks != NULL) {
838                 gchar **networks;
839                 gsize network_count;
840
841                 networks = create_network_list(provider->user_networks,
842                                                         &network_count);
843                 if (networks != NULL) {
844                         g_key_file_set_string_list(keyfile,
845                                                 provider->identifier,
846                                                 "Networks",
847                                                 (const gchar ** const)networks,
848                                                 network_count);
849                         g_strfreev(networks);
850                 }
851         }
852
853         if (provider->config_file != NULL && strlen(provider->config_file) > 0)
854                 g_key_file_set_string(keyfile, provider->identifier,
855                                 "Config.file", provider->config_file);
856
857         if (provider->config_entry != NULL &&
858                                         strlen(provider->config_entry) > 0)
859                 g_key_file_set_string(keyfile, provider->identifier,
860                                 "Config.ident", provider->config_entry);
861
862         if (provider->driver != NULL && provider->driver->save != NULL)
863                 provider->driver->save(provider, keyfile);
864
865         __connman_storage_save_provider(keyfile, provider->identifier);
866         g_key_file_free(keyfile);
867
868         return 0;
869 }
870
871 struct vpn_provider *__vpn_provider_lookup(const char *identifier)
872 {
873         struct vpn_provider *provider = NULL;
874
875         provider = g_hash_table_lookup(provider_hash, identifier);
876
877         return provider;
878 }
879
880 static gboolean match_driver(struct vpn_provider *provider,
881                                 struct vpn_provider_driver *driver)
882 {
883         if (g_strcmp0(driver->name, provider->type) == 0)
884                 return TRUE;
885
886         return FALSE;
887 }
888
889 static int provider_probe(struct vpn_provider *provider)
890 {
891         GSList *list;
892
893         DBG("provider %p driver %p name %s", provider, provider->driver,
894                                                 provider->name);
895
896         if (provider->driver != NULL)
897                 return -EALREADY;
898
899         for (list = driver_list; list; list = list->next) {
900                 struct vpn_provider_driver *driver = list->data;
901
902                 if (match_driver(provider, driver) == FALSE)
903                         continue;
904
905                 DBG("driver %p name %s", driver, driver->name);
906
907                 if (driver->probe != NULL && driver->probe(provider) == 0) {
908                         provider->driver = driver;
909                         break;
910                 }
911         }
912
913         if (provider->driver == NULL)
914                 return -ENODEV;
915
916         return 0;
917 }
918
919 static void provider_remove(struct vpn_provider *provider)
920 {
921         if (provider->driver != NULL) {
922                 provider->driver->remove(provider);
923                 provider->driver = NULL;
924         }
925 }
926
927 static int provider_register(struct vpn_provider *provider)
928 {
929         return provider_probe(provider);
930 }
931
932 static void provider_unregister(struct vpn_provider *provider)
933 {
934         provider_remove(provider);
935 }
936
937 struct vpn_provider *
938 vpn_provider_ref_debug(struct vpn_provider *provider,
939                         const char *file, int line, const char *caller)
940 {
941         DBG("%p ref %d by %s:%d:%s()", provider, provider->refcount + 1,
942                 file, line, caller);
943
944         __sync_fetch_and_add(&provider->refcount, 1);
945
946         return provider;
947 }
948
949 static void provider_destruct(struct vpn_provider *provider)
950 {
951         DBG("provider %p", provider);
952
953         if (provider->notify_id != 0)
954                 g_source_remove(provider->notify_id);
955
956         g_free(provider->name);
957         g_free(provider->type);
958         g_free(provider->host);
959         g_free(provider->domain);
960         g_free(provider->identifier);
961         g_free(provider->path);
962         g_slist_free_full(provider->user_networks, free_route);
963         g_strfreev(provider->nameservers);
964         g_hash_table_destroy(provider->routes);
965         g_hash_table_destroy(provider->user_routes);
966         g_hash_table_destroy(provider->setting_strings);
967         if (provider->resolv != NULL) {
968                 g_resolv_unref(provider->resolv);
969                 provider->resolv = NULL;
970         }
971         __vpn_ipconfig_unref(provider->ipconfig_ipv4);
972         __vpn_ipconfig_unref(provider->ipconfig_ipv6);
973
974         g_strfreev(provider->host_ip);
975         g_free(provider->config_file);
976         g_free(provider->config_entry);
977         g_free(provider);
978 }
979
980 void vpn_provider_unref_debug(struct vpn_provider *provider,
981                                 const char *file, int line, const char *caller)
982 {
983         DBG("%p ref %d by %s:%d:%s()", provider, provider->refcount - 1,
984                 file, line, caller);
985
986         if (__sync_fetch_and_sub(&provider->refcount, 1) != 1)
987                 return;
988
989         provider_remove(provider);
990
991         provider_destruct(provider);
992 }
993
994 static void configuration_count_add(void)
995 {
996         DBG("count %d", configuration_count + 1);
997
998         __sync_fetch_and_add(&configuration_count, 1);
999 }
1000
1001 static void configuration_count_del(void)
1002 {
1003         DBG("count %d", configuration_count - 1);
1004
1005         if (__sync_fetch_and_sub(&configuration_count, 1) != 1)
1006                 return;
1007
1008         raise(SIGTERM);
1009 }
1010
1011 int __vpn_provider_disconnect(struct vpn_provider *provider)
1012 {
1013         int err;
1014
1015         DBG("provider %p", provider);
1016
1017         if (provider->driver != NULL && provider->driver->disconnect != NULL)
1018                 err = provider->driver->disconnect(provider);
1019         else
1020                 return -EOPNOTSUPP;
1021
1022         if (err == -EINPROGRESS)
1023                 vpn_provider_set_state(provider, VPN_PROVIDER_STATE_CONNECT);
1024
1025         return err;
1026 }
1027
1028 static void connect_cb(struct vpn_provider *provider, void *user_data,
1029                                                                 int error)
1030 {
1031         DBusMessage *pending = user_data;
1032
1033         DBG("provider %p user %p error %d", provider, user_data, error);
1034
1035         if (error != 0) {
1036                 DBusMessage *reply = __connman_error_failed(pending, error);
1037                 if (reply != NULL)
1038                         g_dbus_send_message(connection, reply);
1039
1040                 vpn_provider_indicate_error(provider,
1041                                         VPN_PROVIDER_ERROR_CONNECT_FAILED);
1042                 vpn_provider_set_state(provider, VPN_PROVIDER_STATE_FAILURE);
1043         } else
1044                 g_dbus_send_reply(connection, pending, DBUS_TYPE_INVALID);
1045
1046         dbus_message_unref(pending);
1047 }
1048
1049 int __vpn_provider_connect(struct vpn_provider *provider, DBusMessage *msg)
1050 {
1051         int err;
1052
1053         DBG("provider %p", provider);
1054
1055         if (provider->driver != NULL && provider->driver->connect != NULL) {
1056                 dbus_message_ref(msg);
1057                 err = provider->driver->connect(provider, connect_cb, msg);
1058         } else
1059                 return -EOPNOTSUPP;
1060
1061         if (err == -EINPROGRESS)
1062                 vpn_provider_set_state(provider, VPN_PROVIDER_STATE_CONNECT);
1063
1064         return err;
1065 }
1066
1067 static void connection_removed_signal(struct vpn_provider *provider)
1068 {
1069         DBusMessage *signal;
1070         DBusMessageIter iter;
1071
1072         signal = dbus_message_new_signal(VPN_MANAGER_PATH,
1073                         VPN_MANAGER_INTERFACE, "ConnectionRemoved");
1074         if (signal == NULL)
1075                 return;
1076
1077         dbus_message_iter_init_append(signal, &iter);
1078         dbus_message_iter_append_basic(&iter, DBUS_TYPE_OBJECT_PATH,
1079                                                         &provider->path);
1080         dbus_connection_send(connection, signal, NULL);
1081         dbus_message_unref(signal);
1082 }
1083
1084 static char *get_ident(const char *path)
1085 {
1086         char *pos;
1087
1088         if (*path != '/')
1089                 return NULL;
1090
1091         pos = strrchr(path, '/');
1092         if (pos == NULL)
1093                 return NULL;
1094
1095         return pos + 1;
1096 }
1097
1098 int __vpn_provider_remove(const char *path)
1099 {
1100         struct vpn_provider *provider;
1101         char *ident;
1102
1103         DBG("path %s", path);
1104
1105         ident = get_ident(path);
1106
1107         provider = __vpn_provider_lookup(ident);
1108         if (provider != NULL)
1109                 return __vpn_provider_delete(provider);
1110
1111         return -ENXIO;
1112 }
1113
1114 int __vpn_provider_delete(struct vpn_provider *provider)
1115 {
1116         DBG("Deleting VPN %s", provider->identifier);
1117
1118         connection_removed_signal(provider);
1119
1120         provider_unregister(provider);
1121
1122         __connman_storage_remove_provider(provider->identifier);
1123
1124         g_hash_table_remove(provider_hash, provider->identifier);
1125
1126         return 0;
1127 }
1128
1129 static void append_ipv4(DBusMessageIter *iter, void *user_data)
1130 {
1131         struct vpn_provider *provider = user_data;
1132         const char *address, *gateway, *peer;
1133
1134         address = __vpn_ipconfig_get_local(provider->ipconfig_ipv4);
1135         if (address != NULL) {
1136                 in_addr_t addr;
1137                 struct in_addr netmask;
1138                 char *mask;
1139                 int prefixlen;
1140
1141                 prefixlen = __vpn_ipconfig_get_prefixlen(
1142                                                 provider->ipconfig_ipv4);
1143
1144                 addr = 0xffffffff << (32 - prefixlen);
1145                 netmask.s_addr = htonl(addr);
1146                 mask = inet_ntoa(netmask);
1147
1148                 connman_dbus_dict_append_basic(iter, "Address",
1149                                                 DBUS_TYPE_STRING, &address);
1150
1151                 connman_dbus_dict_append_basic(iter, "Netmask",
1152                                                 DBUS_TYPE_STRING, &mask);
1153         }
1154
1155         gateway = __vpn_ipconfig_get_gateway(provider->ipconfig_ipv4);
1156         if (gateway != NULL)
1157                 connman_dbus_dict_append_basic(iter, "Gateway",
1158                                                 DBUS_TYPE_STRING, &gateway);
1159
1160         peer = __vpn_ipconfig_get_peer(provider->ipconfig_ipv4);
1161         if (peer != NULL)
1162                 connman_dbus_dict_append_basic(iter, "Peer",
1163                                                 DBUS_TYPE_STRING, &peer);
1164 }
1165
1166 static void append_ipv6(DBusMessageIter *iter, void *user_data)
1167 {
1168         struct vpn_provider *provider = user_data;
1169         const char *address, *gateway, *peer;
1170
1171         address = __vpn_ipconfig_get_local(provider->ipconfig_ipv6);
1172         if (address != NULL) {
1173                 unsigned char prefixlen;
1174
1175                 connman_dbus_dict_append_basic(iter, "Address",
1176                                                 DBUS_TYPE_STRING, &address);
1177
1178                 prefixlen = __vpn_ipconfig_get_prefixlen(
1179                                                 provider->ipconfig_ipv6);
1180
1181                 connman_dbus_dict_append_basic(iter, "PrefixLength",
1182                                                 DBUS_TYPE_BYTE, &prefixlen);
1183         }
1184
1185         gateway = __vpn_ipconfig_get_gateway(provider->ipconfig_ipv6);
1186         if (gateway != NULL)
1187                 connman_dbus_dict_append_basic(iter, "Gateway",
1188                                                 DBUS_TYPE_STRING, &gateway);
1189
1190         peer = __vpn_ipconfig_get_peer(provider->ipconfig_ipv6);
1191         if (peer != NULL)
1192                 connman_dbus_dict_append_basic(iter, "Peer",
1193                                                 DBUS_TYPE_STRING, &peer);
1194 }
1195
1196 static const char *state2string(enum vpn_provider_state state)
1197 {
1198         switch (state) {
1199         case VPN_PROVIDER_STATE_UNKNOWN:
1200                 break;
1201         case VPN_PROVIDER_STATE_IDLE:
1202                 return "idle";
1203         case VPN_PROVIDER_STATE_CONNECT:
1204                 return "configuration";
1205         case VPN_PROVIDER_STATE_READY:
1206                 return "ready";
1207         case VPN_PROVIDER_STATE_DISCONNECT:
1208                 return "disconnect";
1209         case VPN_PROVIDER_STATE_FAILURE:
1210                 return "failure";
1211         }
1212
1213         return NULL;
1214 }
1215
1216 static int provider_indicate_state(struct vpn_provider *provider,
1217                                 enum vpn_provider_state state)
1218 {
1219         const char *str;
1220         enum vpn_provider_state old_state;
1221
1222         str = state2string(state);
1223         DBG("provider %p state %s/%d", provider, str, state);
1224         if (str == NULL)
1225                 return -EINVAL;
1226
1227         old_state = provider->state;
1228         provider->state = state;
1229
1230         if (state == VPN_PROVIDER_STATE_READY) {
1231                 connman_dbus_property_changed_basic(provider->path,
1232                                         VPN_CONNECTION_INTERFACE, "Index",
1233                                         DBUS_TYPE_INT32, &provider->index);
1234
1235                 if (provider->family == AF_INET)
1236                         connman_dbus_property_changed_dict(provider->path,
1237                                         VPN_CONNECTION_INTERFACE, "IPv4",
1238                                         append_ipv4, provider);
1239                 else if (provider->family == AF_INET6)
1240                         connman_dbus_property_changed_dict(provider->path,
1241                                         VPN_CONNECTION_INTERFACE, "IPv6",
1242                                         append_ipv6, provider);
1243         }
1244
1245         if (old_state != state)
1246                 connman_dbus_property_changed_basic(provider->path,
1247                                         VPN_CONNECTION_INTERFACE, "State",
1248                                         DBUS_TYPE_STRING, &str);
1249
1250         /*
1251          * We do not stay in failure state as clients like connmand can
1252          * get confused about our current state.
1253          */
1254         if (provider->state == VPN_PROVIDER_STATE_FAILURE)
1255                 provider->state = VPN_PROVIDER_STATE_IDLE;
1256
1257         return 0;
1258 }
1259
1260 static void append_nameservers(DBusMessageIter *iter, char **servers)
1261 {
1262         int i;
1263
1264         DBG("%p", servers);
1265
1266         for (i = 0; servers[i] != NULL; i++) {
1267                 DBG("servers[%d] %s", i, servers[i]);
1268                 dbus_message_iter_append_basic(iter,
1269                                         DBUS_TYPE_STRING, &servers[i]);
1270         }
1271 }
1272
1273 static void append_dns(DBusMessageIter *iter, void *user_data)
1274 {
1275         struct vpn_provider *provider = user_data;
1276
1277         if (provider->nameservers != NULL)
1278                 append_nameservers(iter, provider->nameservers);
1279 }
1280
1281 static void append_state(DBusMessageIter *iter,
1282                                         struct vpn_provider *provider)
1283 {
1284         char *str;
1285
1286         switch (provider->state) {
1287         case VPN_PROVIDER_STATE_UNKNOWN:
1288         case VPN_PROVIDER_STATE_IDLE:
1289                 str = "idle";
1290                 break;
1291         case VPN_PROVIDER_STATE_CONNECT:
1292                 str = "configuration";
1293                 break;
1294         case VPN_PROVIDER_STATE_READY:
1295                 str = "ready";
1296                 break;
1297         case VPN_PROVIDER_STATE_DISCONNECT:
1298                 str = "disconnect";
1299                 break;
1300         case VPN_PROVIDER_STATE_FAILURE:
1301                 str = "failure";
1302                 break;
1303         }
1304
1305         connman_dbus_dict_append_basic(iter, "State",
1306                                 DBUS_TYPE_STRING, &str);
1307 }
1308
1309 static void append_properties(DBusMessageIter *iter,
1310                                         struct vpn_provider *provider)
1311 {
1312         DBusMessageIter dict;
1313         GHashTableIter hash;
1314         gpointer value, key;
1315
1316         connman_dbus_dict_open(iter, &dict);
1317
1318         append_state(&dict, provider);
1319
1320         if (provider->type != NULL)
1321                 connman_dbus_dict_append_basic(&dict, "Type",
1322                                         DBUS_TYPE_STRING, &provider->type);
1323
1324         if (provider->name != NULL)
1325                 connman_dbus_dict_append_basic(&dict, "Name",
1326                                         DBUS_TYPE_STRING, &provider->name);
1327
1328         if (provider->host != NULL)
1329                 connman_dbus_dict_append_basic(&dict, "Host",
1330                                         DBUS_TYPE_STRING, &provider->host);
1331         if (provider->index >= 0)
1332                 connman_dbus_dict_append_basic(&dict, "Index",
1333                                         DBUS_TYPE_INT32, &provider->index);
1334         if (provider->domain != NULL)
1335                 connman_dbus_dict_append_basic(&dict, "Domain",
1336                                         DBUS_TYPE_STRING, &provider->domain);
1337
1338         if (provider->family == AF_INET)
1339                 connman_dbus_dict_append_dict(&dict, "IPv4", append_ipv4,
1340                                                 provider);
1341         else if (provider->family == AF_INET6)
1342                 connman_dbus_dict_append_dict(&dict, "IPv6", append_ipv6,
1343                                                 provider);
1344
1345         connman_dbus_dict_append_array(&dict, "Nameservers",
1346                                 DBUS_TYPE_STRING, append_dns, provider);
1347
1348         connman_dbus_dict_append_array(&dict, "UserRoutes",
1349                                 DBUS_TYPE_DICT_ENTRY, append_routes,
1350                                 provider->user_routes);
1351
1352         connman_dbus_dict_append_array(&dict, "ServerRoutes",
1353                                 DBUS_TYPE_DICT_ENTRY, append_routes,
1354                                 provider->routes);
1355
1356         if (provider->setting_strings != NULL) {
1357                 g_hash_table_iter_init(&hash, provider->setting_strings);
1358
1359                 while (g_hash_table_iter_next(&hash, &key, &value) == TRUE) {
1360                         struct vpn_setting *setting = value;
1361
1362                         if (setting->hide_value == FALSE &&
1363                                                         setting->value != NULL)
1364                                 connman_dbus_dict_append_basic(&dict, key,
1365                                                         DBUS_TYPE_STRING,
1366                                                         &setting->value);
1367                 }
1368         }
1369
1370         connman_dbus_dict_close(iter, &dict);
1371 }
1372
1373 static void connection_added_signal(struct vpn_provider *provider)
1374 {
1375         DBusMessage *signal;
1376         DBusMessageIter iter;
1377
1378         signal = dbus_message_new_signal(VPN_MANAGER_PATH,
1379                         VPN_MANAGER_INTERFACE, "ConnectionAdded");
1380         if (signal == NULL)
1381                 return;
1382
1383         dbus_message_iter_init_append(signal, &iter);
1384         dbus_message_iter_append_basic(&iter, DBUS_TYPE_OBJECT_PATH,
1385                                                         &provider->path);
1386         append_properties(&iter, provider);
1387
1388         dbus_connection_send(connection, signal, NULL);
1389         dbus_message_unref(signal);
1390 }
1391
1392 static connman_bool_t check_host(char **hosts, char *host)
1393 {
1394         int i;
1395
1396         if (hosts == NULL)
1397                 return FALSE;
1398
1399         for (i = 0; hosts[i] != NULL; i++) {
1400                 if (g_strcmp0(hosts[i], host) == 0)
1401                         return TRUE;
1402         }
1403
1404         return FALSE;
1405 }
1406
1407 static void provider_append_routes(gpointer key, gpointer value,
1408                                         gpointer user_data)
1409 {
1410         struct vpn_route *route = value;
1411         struct vpn_provider *provider = user_data;
1412         int index = provider->index;
1413
1414         if (handle_routes == FALSE)
1415                 return;
1416
1417         /*
1418          * If the VPN administrator/user has given a route to
1419          * VPN server, then we must discard that because the
1420          * server cannot be contacted via VPN tunnel.
1421          */
1422         if (check_host(provider->host_ip, route->network) == TRUE) {
1423                 DBG("Discarding VPN route to %s via %s at index %d",
1424                         route->network, route->gateway, index);
1425                 return;
1426         }
1427
1428         if (route->family == AF_INET6) {
1429                 unsigned char prefix_len = atoi(route->netmask);
1430
1431                 connman_inet_add_ipv6_network_route(index, route->network,
1432                                                         route->gateway,
1433                                                         prefix_len);
1434         } else {
1435                 connman_inet_add_network_route(index, route->network,
1436                                                 route->gateway,
1437                                                 route->netmask);
1438         }
1439 }
1440
1441 static int set_connected(struct vpn_provider *provider,
1442                                         connman_bool_t connected)
1443 {
1444         struct vpn_ipconfig *ipconfig;
1445
1446         DBG("provider %p id %s connected %d", provider,
1447                                         provider->identifier, connected);
1448
1449         if (connected == TRUE) {
1450                 if (provider->family == AF_INET6)
1451                         ipconfig = provider->ipconfig_ipv6;
1452                 else
1453                         ipconfig = provider->ipconfig_ipv4;
1454
1455                 __vpn_ipconfig_address_add(ipconfig, provider->family);
1456
1457                 if (handle_routes == TRUE)
1458                         __vpn_ipconfig_gateway_add(ipconfig, provider->family);
1459
1460                 provider_indicate_state(provider,
1461                                         VPN_PROVIDER_STATE_READY);
1462
1463                 g_hash_table_foreach(provider->routes, provider_append_routes,
1464                                         provider);
1465
1466                 g_hash_table_foreach(provider->user_routes,
1467                                         provider_append_routes, provider);
1468
1469         } else {
1470                 provider_indicate_state(provider,
1471                                         VPN_PROVIDER_STATE_DISCONNECT);
1472
1473                 provider_indicate_state(provider,
1474                                         VPN_PROVIDER_STATE_IDLE);
1475         }
1476
1477         return 0;
1478 }
1479
1480 int vpn_provider_set_state(struct vpn_provider *provider,
1481                                         enum vpn_provider_state state)
1482 {
1483         if (provider == NULL)
1484                 return -EINVAL;
1485
1486         switch (state) {
1487         case VPN_PROVIDER_STATE_UNKNOWN:
1488                 return -EINVAL;
1489         case VPN_PROVIDER_STATE_IDLE:
1490                 return set_connected(provider, FALSE);
1491         case VPN_PROVIDER_STATE_CONNECT:
1492                 return provider_indicate_state(provider, state);
1493         case VPN_PROVIDER_STATE_READY:
1494                 return set_connected(provider, TRUE);
1495         case VPN_PROVIDER_STATE_DISCONNECT:
1496                 return provider_indicate_state(provider, state);
1497         case VPN_PROVIDER_STATE_FAILURE:
1498                 return provider_indicate_state(provider, state);
1499         }
1500         return -EINVAL;
1501 }
1502
1503 int vpn_provider_indicate_error(struct vpn_provider *provider,
1504                                         enum vpn_provider_error error)
1505 {
1506         DBG("provider %p id %s error %d", provider, provider->identifier,
1507                                                                         error);
1508
1509         switch (error) {
1510         case VPN_PROVIDER_ERROR_LOGIN_FAILED:
1511                 break;
1512         case VPN_PROVIDER_ERROR_AUTH_FAILED:
1513                 vpn_provider_set_state(provider, VPN_PROVIDER_STATE_FAILURE);
1514                 break;
1515         case VPN_PROVIDER_ERROR_CONNECT_FAILED:
1516                 break;
1517         default:
1518                 break;
1519         }
1520
1521         return 0;
1522 }
1523
1524 static int connection_unregister(struct vpn_provider *provider)
1525 {
1526         DBG("provider %p path %s", provider, provider->path);
1527
1528         if (provider->path == NULL)
1529                 return -EALREADY;
1530
1531         g_dbus_unregister_interface(connection, provider->path,
1532                                 VPN_CONNECTION_INTERFACE);
1533
1534         g_free(provider->path);
1535         provider->path = NULL;
1536
1537         return 0;
1538 }
1539
1540 static int connection_register(struct vpn_provider *provider)
1541 {
1542         DBG("provider %p path %s", provider, provider->path);
1543
1544         if (provider->path != NULL)
1545                 return -EALREADY;
1546
1547         provider->path = g_strdup_printf("%s/connection/%s", VPN_PATH,
1548                                                 provider->identifier);
1549
1550         g_dbus_register_interface(connection, provider->path,
1551                                 VPN_CONNECTION_INTERFACE,
1552                                 connection_methods, connection_signals,
1553                                 NULL, provider, NULL);
1554
1555         return 0;
1556 }
1557
1558 static void unregister_provider(gpointer data)
1559 {
1560         struct vpn_provider *provider = data;
1561
1562         configuration_count_del();
1563
1564         connection_unregister(provider);
1565
1566         vpn_provider_unref(provider);
1567 }
1568
1569 static void provider_initialize(struct vpn_provider *provider)
1570 {
1571         DBG("provider %p", provider);
1572
1573         provider->index = 0;
1574         provider->fd = -1;
1575         provider->name = NULL;
1576         provider->type = NULL;
1577         provider->domain = NULL;
1578         provider->identifier = NULL;
1579         provider->user_networks = NULL;
1580         provider->routes = g_hash_table_new_full(g_direct_hash, g_direct_equal,
1581                                         NULL, free_route);
1582         provider->user_routes = g_hash_table_new_full(g_str_hash, g_str_equal,
1583                                         g_free, free_route);
1584         provider->setting_strings = g_hash_table_new_full(g_str_hash,
1585                                         g_str_equal, g_free, free_setting);
1586 }
1587
1588 static struct vpn_provider *vpn_provider_new(void)
1589 {
1590         struct vpn_provider *provider;
1591
1592         provider = g_try_new0(struct vpn_provider, 1);
1593         if (provider == NULL)
1594                 return NULL;
1595
1596         provider->refcount = 1;
1597
1598         DBG("provider %p", provider);
1599         provider_initialize(provider);
1600
1601         return provider;
1602 }
1603
1604 static struct vpn_provider *vpn_provider_get(const char *identifier)
1605 {
1606         struct vpn_provider *provider;
1607
1608         provider = g_hash_table_lookup(provider_hash, identifier);
1609         if (provider != NULL)
1610                 return provider;
1611
1612         provider = vpn_provider_new();
1613         if (provider == NULL)
1614                 return NULL;
1615
1616         DBG("provider %p", provider);
1617
1618         provider->identifier = g_strdup(identifier);
1619
1620         g_hash_table_insert(provider_hash, provider->identifier, provider);
1621
1622         configuration_count_add();
1623
1624         return provider;
1625 }
1626
1627 static void provider_dbus_ident(char *ident)
1628 {
1629         int i, len = strlen(ident);
1630
1631         for (i = 0; i < len; i++) {
1632                 if (ident[i] >= '0' && ident[i] <= '9')
1633                         continue;
1634                 if (ident[i] >= 'a' && ident[i] <= 'z')
1635                         continue;
1636                 if (ident[i] >= 'A' && ident[i] <= 'Z')
1637                         continue;
1638                 ident[i] = '_';
1639         }
1640 }
1641
1642 static struct vpn_provider *provider_create_from_keyfile(GKeyFile *keyfile,
1643                 const char *ident)
1644 {
1645         struct vpn_provider *provider;
1646
1647         if (keyfile == NULL || ident == NULL)
1648                 return NULL;
1649
1650         provider = __vpn_provider_lookup(ident);
1651         if (provider == NULL) {
1652                 provider = vpn_provider_get(ident);
1653                 if (provider == NULL) {
1654                         DBG("can not create provider");
1655                         return NULL;
1656                 }
1657
1658                 provider_load_from_keyfile(provider, keyfile);
1659
1660                 if (provider->name == NULL || provider->host == NULL ||
1661                                 provider->domain == NULL) {
1662                         DBG("cannot get name, host or domain");
1663                         vpn_provider_unref(provider);
1664                         return NULL;
1665                 }
1666
1667                 if (provider_register(provider) == 0)
1668                         connection_register(provider);
1669         }
1670         return provider;
1671 }
1672
1673 static void provider_create_all_from_type(const char *provider_type)
1674 {
1675         unsigned int i;
1676         char **providers;
1677         char *id, *type;
1678         GKeyFile *keyfile;
1679
1680         DBG("provider type %s", provider_type);
1681
1682         providers = __connman_storage_get_providers();
1683
1684         if (providers == NULL)
1685                 return;
1686
1687         for (i = 0; providers[i] != NULL; i+=1) {
1688
1689                 if (strncmp(providers[i], "provider_", 9) != 0)
1690                         continue;
1691
1692                 id = providers[i] + 9;
1693                 keyfile = __connman_storage_load_provider(id);
1694
1695                 if (keyfile == NULL)
1696                         continue;
1697
1698                 type = g_key_file_get_string(keyfile, id, "Type", NULL);
1699
1700                 DBG("keyfile %p id %s type %s", keyfile, id, type);
1701
1702                 if (strcmp(provider_type, type) != 0) {
1703                         g_free(type);
1704                         g_key_file_free(keyfile);
1705                         continue;
1706                 }
1707
1708                 if (provider_create_from_keyfile(keyfile, id) == NULL)
1709                         DBG("could not create provider");
1710
1711                 g_free(type);
1712                 g_key_file_free(keyfile);
1713         }
1714         g_strfreev(providers);
1715 }
1716
1717 char *__vpn_provider_create_identifier(const char *host, const char *domain)
1718 {
1719         char *ident;
1720
1721         ident = g_strdup_printf("%s_%s", host, domain);
1722         if (ident == NULL)
1723                 return NULL;
1724
1725         provider_dbus_ident(ident);
1726
1727         return ident;
1728 }
1729
1730 int __vpn_provider_create(DBusMessage *msg)
1731 {
1732         struct vpn_provider *provider;
1733         DBusMessageIter iter, array;
1734         const char *type = NULL, *name = NULL;
1735         const char *host = NULL, *domain = NULL;
1736         GSList *networks = NULL;
1737         char *ident;
1738         int err;
1739
1740         dbus_message_iter_init(msg, &iter);
1741         dbus_message_iter_recurse(&iter, &array);
1742
1743         while (dbus_message_iter_get_arg_type(&array) == DBUS_TYPE_DICT_ENTRY) {
1744                 DBusMessageIter entry, value;
1745                 const char *key;
1746
1747                 dbus_message_iter_recurse(&array, &entry);
1748                 dbus_message_iter_get_basic(&entry, &key);
1749
1750                 dbus_message_iter_next(&entry);
1751                 dbus_message_iter_recurse(&entry, &value);
1752
1753                 switch (dbus_message_iter_get_arg_type(&value)) {
1754                 case DBUS_TYPE_STRING:
1755                         if (g_str_equal(key, "Type") == TRUE)
1756                                 dbus_message_iter_get_basic(&value, &type);
1757                         else if (g_str_equal(key, "Name") == TRUE)
1758                                 dbus_message_iter_get_basic(&value, &name);
1759                         else if (g_str_equal(key, "Host") == TRUE)
1760                                 dbus_message_iter_get_basic(&value, &host);
1761                         else if (g_str_equal(key, "VPN.Domain") == TRUE ||
1762                                         g_str_equal(key, "Domain") == TRUE)
1763                                 dbus_message_iter_get_basic(&value, &domain);
1764                         break;
1765                 case DBUS_TYPE_ARRAY:
1766                         if (g_str_equal(key, "UserRoutes") == TRUE)
1767                                 networks = get_user_networks(&value);
1768                         break;
1769                 }
1770
1771                 dbus_message_iter_next(&array);
1772         }
1773
1774         if (host == NULL || domain == NULL)
1775                 return -EINVAL;
1776
1777         DBG("Type %s name %s networks %p", type, name, networks);
1778
1779         if (type == NULL || name == NULL)
1780                 return -EOPNOTSUPP;
1781
1782         ident = __vpn_provider_create_identifier(host, domain);
1783         DBG("ident %s", ident);
1784
1785         provider = __vpn_provider_lookup(ident);
1786         if (provider == NULL) {
1787                 provider = vpn_provider_get(ident);
1788                 if (provider == NULL) {
1789                         DBG("can not create provider");
1790                         g_free(ident);
1791                         return -EOPNOTSUPP;
1792                 }
1793
1794                 provider->host = g_strdup(host);
1795                 provider->domain = g_strdup(domain);
1796                 provider->name = g_strdup(name);
1797                 provider->type = g_strdup(type);
1798
1799                 if (provider_register(provider) == 0)
1800                         vpn_provider_load(provider);
1801
1802                 provider_resolv_host_addr(provider);
1803         }
1804
1805         if (networks != NULL) {
1806                 g_slist_free_full(provider->user_networks, free_route);
1807                 provider->user_networks = networks;
1808                 set_user_networks(provider, provider->user_networks);
1809         }
1810
1811         dbus_message_iter_init(msg, &iter);
1812         dbus_message_iter_recurse(&iter, &array);
1813
1814         while (dbus_message_iter_get_arg_type(&array) == DBUS_TYPE_DICT_ENTRY) {
1815                 DBusMessageIter entry, value;
1816                 const char *key, *str;
1817
1818                 dbus_message_iter_recurse(&array, &entry);
1819                 dbus_message_iter_get_basic(&entry, &key);
1820
1821                 dbus_message_iter_next(&entry);
1822                 dbus_message_iter_recurse(&entry, &value);
1823
1824                 switch (dbus_message_iter_get_arg_type(&value)) {
1825                 case DBUS_TYPE_STRING:
1826                         dbus_message_iter_get_basic(&value, &str);
1827                         vpn_provider_set_string(provider, key, str);
1828                         break;
1829                 }
1830
1831                 dbus_message_iter_next(&array);
1832         }
1833
1834         g_free(ident);
1835
1836         vpn_provider_save(provider);
1837
1838         err = provider_register(provider);
1839         if (err != 0 && err != -EALREADY)
1840                 return err;
1841
1842         connection_register(provider);
1843
1844         DBG("provider %p index %d path %s", provider, provider->index,
1845                                                         provider->path);
1846
1847         g_dbus_send_reply(connection, msg,
1848                                 DBUS_TYPE_OBJECT_PATH, &provider->path,
1849                                 DBUS_TYPE_INVALID);
1850
1851         connection_added_signal(provider);
1852
1853         return 0;
1854 }
1855
1856 static const char *get_string(GHashTable *settings, const char *key)
1857 {
1858         DBG("settings %p key %s", settings, key);
1859
1860         return g_hash_table_lookup(settings, key);
1861 }
1862
1863 static GSList *parse_user_networks(const char *network_str)
1864 {
1865         GSList *networks = NULL;
1866         char **elems = g_strsplit(network_str, ",", 0);
1867         int i = 0;
1868
1869         if (elems == NULL)
1870                 return NULL;
1871
1872         while (elems[i] != NULL) {
1873                 struct vpn_route *vpn_route;
1874                 char *network, *netmask, *gateway;
1875                 int family;
1876                 char **route;
1877
1878                 route = g_strsplit(elems[i], "/", 0);
1879                 if (route == NULL)
1880                         goto next;
1881
1882                 network = route[0];
1883                 if (network == NULL || network[0] == '\0')
1884                         goto next;
1885
1886                 family = connman_inet_check_ipaddress(network);
1887                 if (family < 0) {
1888                         DBG("Cannot get address family of %s (%d/%s)", network,
1889                                 family, gai_strerror(family));
1890
1891                         goto next;
1892                 }
1893
1894                 switch (family) {
1895                 case AF_INET:
1896                         break;
1897                 case AF_INET6:
1898                         break;
1899                 default:
1900                         DBG("Unsupported address family %d", family);
1901                         goto next;
1902                 }
1903
1904                 netmask = route[1];
1905                 if (netmask == NULL || netmask[0] == '\0')
1906                         goto next;
1907
1908                 gateway = route[2];
1909
1910                 vpn_route = g_try_new0(struct vpn_route, 1);
1911                 if (vpn_route == NULL) {
1912                         g_strfreev(route);
1913                         break;
1914                 }
1915
1916                 vpn_route->family = family;
1917                 vpn_route->network = g_strdup(network);
1918                 vpn_route->netmask = g_strdup(netmask);
1919                 vpn_route->gateway = g_strdup(gateway);
1920
1921                 DBG("route %s/%s%s%s", network, netmask,
1922                         gateway ? " via " : "", gateway ? gateway : "");
1923
1924                 networks = g_slist_prepend(networks, vpn_route);
1925
1926         next:
1927                 g_strfreev(route);
1928                 i++;
1929         }
1930
1931         g_strfreev(elems);
1932
1933         return g_slist_reverse(networks);
1934 }
1935
1936 int __vpn_provider_create_from_config(GHashTable *settings,
1937                                 const char *config_ident,
1938                                 const char *config_entry)
1939 {
1940         struct vpn_provider *provider;
1941         const char *type, *name, *host, *domain, *networks_str;
1942         GSList *networks;
1943         char *ident = NULL;
1944         GHashTableIter hash;
1945         gpointer value, key;
1946         int err;
1947
1948         type = get_string(settings, "Type");
1949         name = get_string(settings, "Name");
1950         host = get_string(settings, "Host");
1951         domain = get_string(settings, "Domain");
1952         networks_str = get_string(settings, "Networks");
1953         networks = parse_user_networks(networks_str);
1954
1955         if (host == NULL || domain == NULL) {
1956                 err = -EINVAL;
1957                 goto fail;
1958         }
1959
1960         DBG("type %s name %s networks %s", type, name, networks_str);
1961
1962         if (type == NULL || name == NULL) {
1963                 err = -EOPNOTSUPP;
1964                 goto fail;
1965         }
1966
1967         ident = __vpn_provider_create_identifier(host, domain);
1968         DBG("ident %s", ident);
1969
1970         provider = __vpn_provider_lookup(ident);
1971         if (provider == NULL) {
1972                 provider = vpn_provider_get(ident);
1973                 if (provider == NULL) {
1974                         DBG("can not create provider");
1975                         err = -EOPNOTSUPP;
1976                         goto fail;
1977                 }
1978
1979                 provider->host = g_strdup(host);
1980                 provider->domain = g_strdup(domain);
1981                 provider->name = g_strdup(name);
1982                 provider->type = g_ascii_strdown(type, -1);
1983
1984                 provider->config_file = g_strdup(config_ident);
1985                 provider->config_entry = g_strdup(config_entry);
1986
1987                 if (provider_register(provider) == 0)
1988                         vpn_provider_load(provider);
1989
1990                 provider_resolv_host_addr(provider);
1991         }
1992
1993         if (networks != NULL) {
1994                 g_slist_free_full(provider->user_networks, free_route);
1995                 provider->user_networks = networks;
1996                 set_user_networks(provider, provider->user_networks);
1997         }
1998
1999         g_hash_table_iter_init(&hash, settings);
2000
2001         while (g_hash_table_iter_next(&hash, &key, &value) == TRUE)
2002                 vpn_provider_set_string(provider, key, value);
2003
2004         vpn_provider_save(provider);
2005
2006         err = provider_register(provider);
2007         if (err != 0 && err != -EALREADY)
2008                 goto fail;
2009
2010         connection_register(provider);
2011
2012         DBG("provider %p index %d path %s", provider, provider->index,
2013                                                         provider->path);
2014
2015         connection_added_signal(provider);
2016
2017         g_free(ident);
2018
2019         return 0;
2020
2021 fail:
2022         g_free(ident);
2023         g_slist_free_full(networks, free_route);
2024
2025         return err;
2026 }
2027
2028 static void append_connection_structs(DBusMessageIter *iter, void *user_data)
2029 {
2030         DBusMessageIter entry;
2031         GHashTableIter hash;
2032         gpointer value, key;
2033
2034         g_hash_table_iter_init(&hash, provider_hash);
2035
2036         while (g_hash_table_iter_next(&hash, &key, &value) == TRUE) {
2037                 struct vpn_provider *provider = value;
2038
2039                 DBG("path %s", provider->path);
2040
2041                 if (provider->identifier == NULL)
2042                         continue;
2043
2044                 dbus_message_iter_open_container(iter, DBUS_TYPE_STRUCT,
2045                                 NULL, &entry);
2046                 dbus_message_iter_append_basic(&entry, DBUS_TYPE_OBJECT_PATH,
2047                                 &provider->path);
2048                 append_properties(&entry, provider);
2049                 dbus_message_iter_close_container(iter, &entry);
2050         }
2051 }
2052
2053 DBusMessage *__vpn_provider_get_connections(DBusMessage *msg)
2054 {
2055         DBusMessage *reply;
2056
2057         DBG("");
2058
2059         reply = dbus_message_new_method_return(msg);
2060         if (reply == NULL)
2061                 return NULL;
2062
2063         __connman_dbus_append_objpath_dict_array(reply,
2064                         append_connection_structs, NULL);
2065
2066         return reply;
2067 }
2068
2069 const char * __vpn_provider_get_ident(struct vpn_provider *provider)
2070 {
2071         if (provider == NULL)
2072                 return NULL;
2073
2074         return provider->identifier;
2075 }
2076
2077 static int set_string(struct vpn_provider *provider,
2078                 const char *key, const char *value, gboolean hide_value)
2079 {
2080         DBG("provider %p key %s value %s", provider, key,
2081                 hide_value ? "<not printed>" : value);
2082
2083         if (g_str_equal(key, "Type") == TRUE) {
2084                 g_free(provider->type);
2085                 provider->type = g_ascii_strdown(value, -1);
2086                 send_value(provider->path, "Type", provider->type);
2087         } else if (g_str_equal(key, "Name") == TRUE) {
2088                 g_free(provider->name);
2089                 provider->name = g_strdup(value);
2090                 send_value(provider->path, "Name", provider->name);
2091         } else if (g_str_equal(key, "Host") == TRUE) {
2092                 g_free(provider->host);
2093                 provider->host = g_strdup(value);
2094                 send_value(provider->path, "Host", provider->host);
2095         } else if (g_str_equal(key, "VPN.Domain") == TRUE ||
2096                         g_str_equal(key, "Domain") == TRUE) {
2097                 g_free(provider->domain);
2098                 provider->domain = g_strdup(value);
2099                 send_value(provider->path, "Domain", provider->domain);
2100         } else {
2101                 struct vpn_setting *setting;
2102
2103                 setting = g_try_new(struct vpn_setting, 1);
2104                 if (setting == NULL)
2105                         return -ENOMEM;
2106
2107                 setting->value = g_strdup(value);
2108                 setting->hide_value = hide_value;
2109
2110                 if (hide_value == FALSE)
2111                         send_value(provider->path, key, setting->value);
2112
2113                 g_hash_table_replace(provider->setting_strings,
2114                                 g_strdup(key), setting);
2115         }
2116
2117         return 0;
2118 }
2119
2120 int vpn_provider_set_string(struct vpn_provider *provider,
2121                                         const char *key, const char *value)
2122 {
2123         return set_string(provider, key, value, FALSE);
2124 }
2125
2126 int vpn_provider_set_string_hide_value(struct vpn_provider *provider,
2127                                         const char *key, const char *value)
2128 {
2129         return set_string(provider, key, value, TRUE);
2130 }
2131
2132 const char *vpn_provider_get_string(struct vpn_provider *provider,
2133                                                         const char *key)
2134 {
2135         struct vpn_setting *setting;
2136
2137         DBG("provider %p key %s", provider, key);
2138
2139         if (g_str_equal(key, "Type") == TRUE)
2140                 return provider->type;
2141         else if (g_str_equal(key, "Name") == TRUE)
2142                 return provider->name;
2143         else if (g_str_equal(key, "Host") == TRUE)
2144                 return provider->host;
2145         else if (g_str_equal(key, "HostIP") == TRUE) {
2146                 if (provider->host_ip == NULL ||
2147                                 provider->host_ip[0] == NULL)
2148                         return provider->host;
2149                 else
2150                         return provider->host_ip[0];
2151         } else if (g_str_equal(key, "VPN.Domain") == TRUE ||
2152                         g_str_equal(key, "Domain") == TRUE)
2153                 return provider->domain;
2154
2155         setting = g_hash_table_lookup(provider->setting_strings, key);
2156         if (setting == NULL)
2157                 return NULL;
2158
2159         return setting->value;
2160 }
2161
2162 connman_bool_t __vpn_provider_check_routes(struct vpn_provider *provider)
2163 {
2164         if (provider == NULL)
2165                 return FALSE;
2166
2167         if (provider->user_routes != NULL &&
2168                         g_hash_table_size(provider->user_routes) > 0)
2169                 return TRUE;
2170
2171         if (provider->routes != NULL &&
2172                         g_hash_table_size(provider->routes) > 0)
2173                 return TRUE;
2174
2175         return FALSE;
2176 }
2177
2178 void *vpn_provider_get_data(struct vpn_provider *provider)
2179 {
2180         return provider->driver_data;
2181 }
2182
2183 void vpn_provider_set_data(struct vpn_provider *provider, void *data)
2184 {
2185         provider->driver_data = data;
2186 }
2187
2188 void vpn_provider_set_index(struct vpn_provider *provider, int index)
2189 {
2190         DBG("index %d provider %p", index, provider);
2191
2192         if (provider->ipconfig_ipv4 == NULL) {
2193                 provider->ipconfig_ipv4 = __vpn_ipconfig_create(index,
2194                                                                 AF_INET);
2195                 if (provider->ipconfig_ipv4 == NULL) {
2196                         DBG("Couldnt create ipconfig for IPv4");
2197                         goto done;
2198                 }
2199         }
2200
2201         __vpn_ipconfig_set_index(provider->ipconfig_ipv4, index);
2202
2203         if (provider->ipconfig_ipv6 == NULL) {
2204                 provider->ipconfig_ipv6 = __vpn_ipconfig_create(index,
2205                                                                 AF_INET6);
2206                 if (provider->ipconfig_ipv6 == NULL) {
2207                         DBG("Couldnt create ipconfig for IPv6");
2208                         goto done;
2209                 }
2210         }
2211
2212         __vpn_ipconfig_set_index(provider->ipconfig_ipv6, index);
2213
2214 done:
2215         provider->index = index;
2216 }
2217
2218 int vpn_provider_get_index(struct vpn_provider *provider)
2219 {
2220         return provider->index;
2221 }
2222
2223 int vpn_provider_set_ipaddress(struct vpn_provider *provider,
2224                                         struct connman_ipaddress *ipaddress)
2225 {
2226         struct vpn_ipconfig *ipconfig = NULL;
2227
2228         switch (ipaddress->family) {
2229         case AF_INET:
2230                 ipconfig = provider->ipconfig_ipv4;
2231                 break;
2232         case AF_INET6:
2233                 ipconfig = provider->ipconfig_ipv6;
2234                 break;
2235         default:
2236                 break;
2237         }
2238
2239         DBG("provider %p ipconfig %p family %d", provider, ipconfig,
2240                                                         ipaddress->family);
2241
2242         if (ipconfig == NULL)
2243                 return -EINVAL;
2244
2245         provider->family = ipaddress->family;
2246
2247         __vpn_ipconfig_set_local(ipconfig, ipaddress->local);
2248         __vpn_ipconfig_set_peer(ipconfig, ipaddress->peer);
2249         __vpn_ipconfig_set_broadcast(ipconfig, ipaddress->broadcast);
2250         __vpn_ipconfig_set_gateway(ipconfig, ipaddress->gateway);
2251         __vpn_ipconfig_set_prefixlen(ipconfig, ipaddress->prefixlen);
2252
2253         return 0;
2254 }
2255
2256 int vpn_provider_set_pac(struct vpn_provider *provider,
2257                                 const char *pac)
2258 {
2259         DBG("provider %p pac %s", provider, pac);
2260
2261         return 0;
2262 }
2263
2264
2265 int vpn_provider_set_domain(struct vpn_provider *provider,
2266                                         const char *domain)
2267 {
2268         DBG("provider %p domain %s", provider, domain);
2269
2270         g_free(provider->domain);
2271         provider->domain = g_strdup(domain);
2272
2273         return 0;
2274 }
2275
2276 int vpn_provider_set_nameservers(struct vpn_provider *provider,
2277                                         const char *nameservers)
2278 {
2279         DBG("provider %p nameservers %s", provider, nameservers);
2280
2281         g_strfreev(provider->nameservers);
2282         provider->nameservers = NULL;
2283
2284         if (nameservers == NULL)
2285                 return 0;
2286
2287         provider->nameservers = g_strsplit(nameservers, " ", 0);
2288
2289         return 0;
2290 }
2291
2292 enum provider_route_type {
2293         PROVIDER_ROUTE_TYPE_NONE = 0,
2294         PROVIDER_ROUTE_TYPE_MASK = 1,
2295         PROVIDER_ROUTE_TYPE_ADDR = 2,
2296         PROVIDER_ROUTE_TYPE_GW   = 3,
2297 };
2298
2299 static int route_env_parse(struct vpn_provider *provider, const char *key,
2300                                 int *family, unsigned long *idx,
2301                                 enum provider_route_type *type)
2302 {
2303         char *end;
2304         const char *start;
2305
2306         DBG("name %s", provider->name);
2307
2308         if (!strcmp(provider->type, "openvpn")) {
2309                 if (g_str_has_prefix(key, "route_network_") == TRUE) {
2310                         start = key + strlen("route_network_");
2311                         *type = PROVIDER_ROUTE_TYPE_ADDR;
2312                 } else if (g_str_has_prefix(key, "route_netmask_") == TRUE) {
2313                         start = key + strlen("route_netmask_");
2314                         *type = PROVIDER_ROUTE_TYPE_MASK;
2315                 } else if (g_str_has_prefix(key, "route_gateway_") == TRUE) {
2316                         start = key + strlen("route_gateway_");
2317                         *type = PROVIDER_ROUTE_TYPE_GW;
2318                 } else
2319                         return -EINVAL;
2320
2321                 *family = AF_INET;
2322                 *idx = g_ascii_strtoull(start, &end, 10);
2323
2324         } else if (!strcmp(provider->type, "openconnect")) {
2325                 if (g_str_has_prefix(key, "CISCO_SPLIT_INC_") == TRUE) {
2326                         *family = AF_INET;
2327                         start = key + strlen("CISCO_SPLIT_INC_");
2328                 } else if (g_str_has_prefix(key,
2329                                         "CISCO_IPV6_SPLIT_INC_") == TRUE) {
2330                         *family = AF_INET6;
2331                         start = key + strlen("CISCO_IPV6_SPLIT_INC_");
2332                 } else
2333                         return -EINVAL;
2334
2335                 *idx = g_ascii_strtoull(start, &end, 10);
2336
2337                 if (strncmp(end, "_ADDR", 5) == 0)
2338                         *type = PROVIDER_ROUTE_TYPE_ADDR;
2339                 else if (strncmp(end, "_MASK", 5) == 0)
2340                         *type = PROVIDER_ROUTE_TYPE_MASK;
2341                 else if (strncmp(end, "_MASKLEN", 8) == 0 &&
2342                                 *family == AF_INET6) {
2343                         *type = PROVIDER_ROUTE_TYPE_MASK;
2344                 } else
2345                         return -EINVAL;
2346         }
2347
2348         return 0;
2349 }
2350
2351 int vpn_provider_append_route(struct vpn_provider *provider,
2352                                         const char *key, const char *value)
2353 {
2354         struct vpn_route *route;
2355         int ret, family = 0;
2356         unsigned long idx = 0;
2357         enum provider_route_type type = PROVIDER_ROUTE_TYPE_NONE;
2358
2359         DBG("key %s value %s", key, value);
2360
2361         ret = route_env_parse(provider, key, &family, &idx, &type);
2362         if (ret < 0)
2363                 return ret;
2364
2365         DBG("idx %lu family %d type %d", idx, family, type);
2366
2367         route = g_hash_table_lookup(provider->routes, GINT_TO_POINTER(idx));
2368         if (route == NULL) {
2369                 route = g_try_new0(struct vpn_route, 1);
2370                 if (route == NULL) {
2371                         connman_error("out of memory");
2372                         return -ENOMEM;
2373                 }
2374
2375                 route->family = family;
2376
2377                 g_hash_table_replace(provider->routes, GINT_TO_POINTER(idx),
2378                                                 route);
2379         }
2380
2381         switch (type) {
2382         case PROVIDER_ROUTE_TYPE_NONE:
2383                 break;
2384         case PROVIDER_ROUTE_TYPE_MASK:
2385                 route->netmask = g_strdup(value);
2386                 break;
2387         case PROVIDER_ROUTE_TYPE_ADDR:
2388                 route->network = g_strdup(value);
2389                 break;
2390         case PROVIDER_ROUTE_TYPE_GW:
2391                 route->gateway = g_strdup(value);
2392                 break;
2393         }
2394
2395         if (handle_routes == FALSE) {
2396                 if (route->netmask != NULL && route->gateway != NULL &&
2397                                                         route->network != NULL)
2398                         provider_schedule_changed(provider);
2399         }
2400
2401         return 0;
2402 }
2403
2404 const char *vpn_provider_get_driver_name(struct vpn_provider *provider)
2405 {
2406         if (provider->driver == NULL)
2407                 return NULL;
2408
2409         return provider->driver->name;
2410 }
2411
2412 const char *vpn_provider_get_save_group(struct vpn_provider *provider)
2413 {
2414         return provider->identifier;
2415 }
2416
2417 static gint compare_priority(gconstpointer a, gconstpointer b)
2418 {
2419         return 0;
2420 }
2421
2422 static void clean_provider(gpointer key, gpointer value, gpointer user_data)
2423 {
2424         struct vpn_provider *provider = value;
2425
2426         if (provider->driver != NULL && provider->driver->remove)
2427                 provider->driver->remove(provider);
2428
2429         connection_unregister(provider);
2430 }
2431
2432 int vpn_provider_driver_register(struct vpn_provider_driver *driver)
2433 {
2434         DBG("driver %p name %s", driver, driver->name);
2435
2436         driver_list = g_slist_insert_sorted(driver_list, driver,
2437                                                         compare_priority);
2438         provider_create_all_from_type(driver->name);
2439         return 0;
2440 }
2441
2442 void vpn_provider_driver_unregister(struct vpn_provider_driver *driver)
2443 {
2444         GHashTableIter iter;
2445         gpointer value, key;
2446
2447         DBG("driver %p name %s", driver, driver->name);
2448
2449         driver_list = g_slist_remove(driver_list, driver);
2450
2451         g_hash_table_iter_init(&iter, provider_hash);
2452         while (g_hash_table_iter_next(&iter, &key, &value) == TRUE) {
2453                 struct vpn_provider *provider = value;
2454
2455                 if (provider != NULL && provider->driver != NULL &&
2456                                 provider->driver->type == driver->type &&
2457                                 g_strcmp0(provider->driver->name,
2458                                                         driver->name) == 0) {
2459                         provider->driver = NULL;
2460                 }
2461         }
2462 }
2463
2464 static gboolean check_vpn_count(gpointer data)
2465 {
2466         if (configuration_count == 0) {
2467                 connman_info("No VPN configurations found, quitting.");
2468                 raise(SIGTERM);
2469         }
2470
2471         return FALSE;
2472 }
2473
2474 void __vpn_provider_check_connections(void)
2475 {
2476         /*
2477          * If we were started when there is no providers configured,
2478          * then just quit. This happens when connman starts and its
2479          * vpn plugin asks connman-vpnd if it has any connections
2480          * configured. If there are none, then we can stop the vpn
2481          * daemon.
2482          */
2483         g_timeout_add(1000, check_vpn_count, NULL);
2484 }
2485
2486 const char *vpn_provider_get_name(struct vpn_provider *provider)
2487 {
2488         return provider->name;
2489 }
2490
2491 const char *vpn_provider_get_host(struct vpn_provider *provider)
2492 {
2493         return provider->host;
2494 }
2495
2496 const char *vpn_provider_get_path(struct vpn_provider *provider)
2497 {
2498         return provider->path;
2499 }
2500
2501 static int agent_probe(struct connman_agent *agent)
2502 {
2503         DBG("agent %p", agent);
2504         return 0;
2505 }
2506
2507 static void agent_remove(struct connman_agent *agent)
2508 {
2509         DBG("agent %p", agent);
2510 }
2511
2512 static struct connman_agent_driver agent_driver = {
2513         .name           = "vpn",
2514         .interface      = VPN_AGENT_INTERFACE,
2515         .probe          = agent_probe,
2516         .remove         = agent_remove,
2517 };
2518
2519 static void remove_unprovisioned_providers()
2520 {
2521         gchar **providers;
2522         GKeyFile *keyfile, *configkeyfile;
2523         char *file, *section;
2524         int i = 0;
2525
2526         providers = __connman_storage_get_providers();
2527         if (providers == NULL)
2528                 return;
2529
2530         for (; providers[i] != NULL; i++) {
2531                 char *group = providers[i] + sizeof("provider_") - 1;
2532                 file = section = NULL;
2533                 keyfile = configkeyfile = NULL;
2534
2535                 keyfile = __connman_storage_load_provider(group);
2536                 if (keyfile == NULL)
2537                         continue;
2538
2539                 file = g_key_file_get_string(keyfile, group,
2540                                         "Config.file", NULL);
2541                 if (file == NULL)
2542                         goto next;
2543
2544                 section = g_key_file_get_string(keyfile, group,
2545                                         "Config.ident", NULL);
2546                 if (section == NULL)
2547                         goto next;
2548
2549                 configkeyfile = __connman_storage_load_provider_config(file);
2550                 if (configkeyfile == NULL) {
2551                         /*
2552                          * Config file is missing, remove the provisioned
2553                          * service.
2554                          */
2555                         __connman_storage_remove_provider(group);
2556                         goto next;
2557                 }
2558
2559                 if (g_key_file_has_group(configkeyfile, section) == FALSE)
2560                         /*
2561                          * Config section is missing, remove the provisioned
2562                          * service.
2563                          */
2564                         __connman_storage_remove_provider(group);
2565
2566         next:
2567                 if (keyfile != NULL)
2568                         g_key_file_free(keyfile);
2569
2570                 if (configkeyfile != NULL)
2571                         g_key_file_free(configkeyfile);
2572
2573                 g_free(section);
2574                 g_free(file);
2575         }
2576
2577         g_strfreev(providers);
2578 }
2579
2580 int __vpn_provider_init(gboolean do_routes)
2581 {
2582         int err;
2583
2584         DBG("");
2585
2586         handle_routes = do_routes;
2587
2588         err = connman_agent_driver_register(&agent_driver);
2589         if (err < 0) {
2590                 connman_error("Cannot register agent driver for %s",
2591                                                 agent_driver.name);
2592                 return err;
2593         }
2594
2595         connection = connman_dbus_get_connection();
2596
2597         remove_unprovisioned_providers();
2598
2599         provider_hash = g_hash_table_new_full(g_str_hash, g_str_equal,
2600                                                 NULL, unregister_provider);
2601         return 0;
2602 }
2603
2604 void __vpn_provider_cleanup(void)
2605 {
2606         DBG("");
2607
2608         g_hash_table_foreach(provider_hash, clean_provider, NULL);
2609
2610         g_hash_table_destroy(provider_hash);
2611         provider_hash = NULL;
2612
2613         connman_agent_driver_unregister(&agent_driver);
2614
2615         dbus_connection_unref(connection);
2616 }