Updated connman to version 1.35
[platform/upstream/connman.git] / src / tethering.c
old mode 100644 (file)
new mode 100755 (executable)
index d069fa3..891ee51
@@ -2,7 +2,8 @@
  *
  *  Connection Manager
  *
- *  Copyright (C) 2007-2010  Intel Corporation. All rights reserved.
+ *  Copyright (C) 2007-2013  Intel Corporation. All rights reserved.
+ *  Copyright (C) 2011 ProFUSION embedded systems
  *
  *  This program is free software; you can redistribute it and/or modify
  *  it under the terms of the GNU General Public License version 2 as
 #include <config.h>
 #endif
 
+#include <errno.h>
+#include <sys/types.h>
+#include <sys/stat.h>
 #include <unistd.h>
 #include <stdio.h>
 #include <sys/ioctl.h>
 #include <net/if.h>
 #include <linux/sockios.h>
+#include <string.h>
+#include <fcntl.h>
+#include <linux/if_tun.h>
+#include <netinet/in.h>
+#include <linux/if_bridge.h>
 
 #include "connman.h"
 
 #include <gdhcp/gdhcp.h>
 
+#include <gdbus.h>
+
+#ifndef DBUS_TYPE_UNIX_FD
+#define DBUS_TYPE_UNIX_FD -1
+#endif
+
 #define BRIDGE_NAME "tether"
-#define BRIDGE_IP "192.168.218.1"
-#define BRIDGE_BCAST "192.168.218.255"
-#define BRIDGE_SUBNET "255.255.255.0"
-#define BRIDGE_IP_START "192.168.218.100"
-#define BRIDGE_IP_END "192.168.218.200"
-#define BRIDGE_DNS "8.8.8.8"
-
-static connman_bool_t tethering_status = FALSE;
-static char *default_interface = NULL;
-static volatile gint tethering_enabled;
+
+#define DEFAULT_MTU    1500
+
+#define CONNMAN_STATION_STR_INFO_LEN           64
+#define CONNMAN_STATION_MAC_INFO_LEN           32
+
+static char *private_network_primary_dns = NULL;
+static char *private_network_secondary_dns = NULL;
+
+static volatile int tethering_enabled;
 static GDHCPServer *tethering_dhcp_server = NULL;
+static struct connman_ippool *dhcp_ippool = NULL;
+static DBusConnection *connection;
+static GHashTable *pn_hash;
+static GHashTable *sta_hash;
+
+struct connman_private_network {
+       char *owner;
+       char *path;
+       guint watch;
+       DBusMessage *msg;
+       DBusMessage *reply;
+       int fd;
+       char *interface;
+       int index;
+       guint iface_watch;
+       struct connman_ippool *pool;
+       char *primary_dns;
+       char *secondary_dns;
+};
+
+struct connman_station_info {
+       bool is_connected;
+       char *path;
+       char *type;
+       char ip[CONNMAN_STATION_STR_INFO_LEN];
+       char mac[CONNMAN_STATION_MAC_INFO_LEN];
+       char hostname[CONNMAN_STATION_STR_INFO_LEN];
+};
+
+static void emit_station_signal(char *action_str,
+                       const struct connman_station_info *station_info)
+{
+       char *ip, *mac, *hostname;
+
+       if (station_info->path == NULL || station_info->type == NULL
+               || station_info->ip == NULL || station_info->mac == NULL
+                       || station_info->hostname == NULL)
+               return;
+
+       ip = g_strdup(station_info->ip);
+       mac = g_strdup(station_info->mac);
+       hostname = g_strdup(station_info->hostname);
+
+       g_dbus_emit_signal(connection, station_info->path,
+                       CONNMAN_TECHNOLOGY_INTERFACE, action_str,
+                       DBUS_TYPE_STRING, &station_info->type,
+                       DBUS_TYPE_STRING, &ip,
+                       DBUS_TYPE_STRING, &mac,
+                       DBUS_TYPE_STRING, &hostname,
+                       DBUS_TYPE_INVALID);
+
+       g_free(ip);
+       g_free(mac);
+       g_free(hostname);
+}
+static void destroy_station(gpointer key, gpointer value, gpointer user_data)
+{
+       struct connman_station_info *station_info;
+
+       __sync_synchronize();
+
+       station_info = value;
+
+       if (station_info->is_connected) {
+               station_info->is_connected = FALSE;
+               emit_station_signal("DhcpLeaseDeleted", station_info);
+       }
+
+       g_free(station_info->path);
+       g_free(station_info->type);
+       g_free(station_info);
+}
+
+static void save_dhcp_ack_lease_info(char *hostname,
+                                    unsigned char *mac, unsigned int nip)
+{
+       char *lower_mac;
+       const char *ip;
+       char sta_mac[CONNMAN_STATION_MAC_INFO_LEN];
+       struct connman_station_info *info_found;
+       struct in_addr addr;
+       int str_len;
+
+       __sync_synchronize();
+
+       snprintf(sta_mac, CONNMAN_STATION_MAC_INFO_LEN,
+                "%02x:%02x:%02x:%02x:%02x:%02x",
+                mac[0], mac[1], mac[2], mac[3], mac[4], mac[5]);
+       lower_mac = g_ascii_strdown(sta_mac, -1);
+
+       info_found = g_hash_table_lookup(sta_hash, lower_mac);
+       if (info_found == NULL) {
+               g_free(lower_mac);
+               return;
+       }
 
-connman_bool_t __connman_tethering_get_status(void)
+       /* get the ip */
+       addr.s_addr = nip;
+       ip = inet_ntoa(addr);
+       str_len = strlen(ip) + 1;
+       if (str_len > CONNMAN_STATION_STR_INFO_LEN)
+               str_len = CONNMAN_STATION_STR_INFO_LEN - 1;
+       memcpy(info_found->ip, ip, str_len);
+
+       /* get hostname */
+       str_len = strlen(hostname) + 1;
+       if (str_len > CONNMAN_STATION_STR_INFO_LEN)
+               str_len = CONNMAN_STATION_STR_INFO_LEN - 1;
+       memcpy(info_found->hostname, hostname, str_len);
+
+       /* emit a signal */
+       info_found->is_connected = TRUE;
+       emit_station_signal("DhcpConnected", info_found);
+       g_free(lower_mac);
+}
+
+int connman_technology_tethering_add_station(enum connman_service_type type,
+                                                       const char *mac)
 {
-       return tethering_status;
+       const char *str_type;
+       char *lower_mac;
+       char *path;
+       struct connman_station_info *station_info;
+
+       __sync_synchronize();
+
+       DBG("type %d", type);
+
+       str_type = __connman_service_type2string(type);
+       if (str_type == NULL)
+               return 0;
+
+       path = g_strdup_printf("%s/technology/%s", CONNMAN_PATH, str_type);
+
+       station_info = g_try_new0(struct connman_station_info, 1);
+       if (station_info == NULL)
+               return -ENOMEM;
+
+       lower_mac = g_ascii_strdown(mac, -1);
+
+       memcpy(station_info->mac, lower_mac, strlen(lower_mac) + 1);
+       station_info->path = path;
+       station_info->type = g_strdup(str_type);
+
+       g_hash_table_insert(sta_hash, station_info->mac, station_info);
+
+       g_free(lower_mac);
+       return 0;
 }
 
+int connman_technology_tethering_remove_station(const char *mac)
+{
+       char *lower_mac;
+       struct connman_station_info *info_found;
+
+       __sync_synchronize();
+
+       lower_mac = g_ascii_strdown(mac, -1);
+
+       info_found = g_hash_table_lookup(sta_hash, lower_mac);
+       if (info_found == NULL) {
+               g_free(lower_mac);
+               return -EACCES;
+       }
+
+       if (info_found->is_connected) {
+               info_found->is_connected = FALSE;
+               emit_station_signal("DhcpLeaseDeleted", info_found);
+       }
+       g_free(lower_mac);
+       g_hash_table_remove(sta_hash, info_found->mac);
+       g_free(info_found->path);
+       g_free(info_found->type);
+       g_free(info_found);
+
+       return 0;
+}
+
+const char *__connman_tethering_get_bridge(void)
+{
+       int sk, err;
+       unsigned long args[3];
+
+       sk = socket(AF_INET, SOCK_STREAM, 0);
+       if (sk < 0)
+               return NULL;
+
+       args[0] = BRCTL_GET_VERSION;
+       args[1] = args[2] = 0;
+       err = ioctl(sk, SIOCGIFBR, &args);
+       close(sk);
+       if (err == -1) {
+               connman_error("Missing support for 802.1d ethernet bridging");
+               return NULL;
+       }
+
+       return BRIDGE_NAME;
+}
 
 static void dhcp_server_debug(const char *str, void *data)
 {
@@ -88,7 +295,7 @@ static void dhcp_server_error(GDHCPServerError error)
 }
 
 static GDHCPServer *dhcp_server_start(const char *bridge,
-                               const char *router, const charsubnet,
+                               const char *router, const char *subnet,
                                const char *start_ip, const char *end_ip,
                                unsigned int lease_time, const char *dns)
 {
@@ -103,7 +310,7 @@ static GDHCPServer *dhcp_server_start(const char *bridge,
                return NULL;
 
        dhcp_server = g_dhcp_server_new(G_DHCP_IPV4, index, &error);
-       if (dhcp_server == NULL) {
+       if (!dhcp_server) {
                dhcp_server_error(error);
                return NULL;
        }
@@ -116,6 +323,9 @@ static GDHCPServer *dhcp_server_start(const char *bridge,
        g_dhcp_server_set_option(dhcp_server, G_DHCP_DNS_SERVER, dns);
        g_dhcp_server_set_ip_range(dhcp_server, start_ip, end_ip);
 
+       g_dhcp_server_set_save_ack_lease(dhcp_server,
+                                        save_dhcp_ack_lease_info, NULL);
+
        g_dhcp_server_start(dhcp_server);
 
        return dhcp_server;
@@ -123,262 +333,361 @@ static GDHCPServer *dhcp_server_start(const char *bridge,
 
 static void dhcp_server_stop(GDHCPServer *server)
 {
-       if (server == NULL)
+       if (!server)
                return;
 
        g_dhcp_server_unref(server);
 }
 
-static int set_forward_delay(const char *name, unsigned int delay)
+static void tethering_restart(struct connman_ippool *pool, void *user_data)
 {
-       FILE *f;
-       char *forward_delay_path;
-
-       forward_delay_path =
-               g_strdup_printf("/sys/class/net/%s/bridge/forward_delay", name);
-
-       if (forward_delay_path == NULL)
-               return -ENOMEM;
-
-       f = fopen(forward_delay_path, "r+");
-
-       g_free(forward_delay_path);
-
-       if (f == NULL)
-               return -errno;
-
-       fprintf(f, "%d", delay);
-
-       fclose(f);
-
-       return 0;
+       DBG("pool %p", pool);
+       __connman_tethering_set_disabled();
+       __connman_tethering_set_enabled();
 }
 
-static int create_bridge(const char *name)
+int __connman_tethering_set_enabled(void)
 {
-       int sk, err;
-
-       DBG("name %s", name);
+       int index;
+       int err;
+       const char *gateway;
+       const char *broadcast;
+       const char *subnet_mask;
+       const char *start_ip;
+       const char *end_ip;
+       const char *dns;
+       unsigned char prefixlen;
+       char **ns;
 
-       sk = socket(AF_INET, SOCK_STREAM, 0);
-       if (sk < 0)
-               return -EOPNOTSUPP;
+       DBG("enabled %d", tethering_enabled + 1);
 
-       err = ioctl(sk, SIOCBRADDBR, name);
+       if (__sync_fetch_and_add(&tethering_enabled, 1) != 0)
+               return 0;
 
-       if (err < 0)
+       err = __connman_bridge_create(BRIDGE_NAME);
+       if (err < 0) {
+               __sync_fetch_and_sub(&tethering_enabled, 1);
                return -EOPNOTSUPP;
+       }
 
-       err = set_forward_delay(name, 0);
-
-       if (err < 0)
-               ioctl(sk, SIOCBRDELBR, name);
+       index = connman_inet_ifindex(BRIDGE_NAME);
+       dhcp_ippool = __connman_ippool_create(index, 2, 252,
+                                               tethering_restart, NULL);
+       if (!dhcp_ippool) {
+               connman_error("Fail to create IP pool");
+               __connman_bridge_remove(BRIDGE_NAME);
+               __sync_fetch_and_sub(&tethering_enabled, 1);
+               return -EADDRNOTAVAIL;
+       }
 
-       close(sk);
+       gateway = __connman_ippool_get_gateway(dhcp_ippool);
+       broadcast = __connman_ippool_get_broadcast(dhcp_ippool);
+       subnet_mask = __connman_ippool_get_subnet_mask(dhcp_ippool);
+       start_ip = __connman_ippool_get_start_ip(dhcp_ippool);
+       end_ip = __connman_ippool_get_end_ip(dhcp_ippool);
+
+       err = __connman_bridge_enable(BRIDGE_NAME, gateway,
+                       connman_ipaddress_calc_netmask_len(subnet_mask),
+                       broadcast);
+       if (err < 0 && err != -EALREADY) {
+               __connman_ippool_unref(dhcp_ippool);
+               __connman_bridge_remove(BRIDGE_NAME);
+               __sync_fetch_and_sub(&tethering_enabled, 1);
+               return -EADDRNOTAVAIL;
+       }
 
-       return err;
-}
+       ns = connman_setting_get_string_list("FallbackNameservers");
+       if (ns) {
+               if (ns[0]) {
+                       g_free(private_network_primary_dns);
+                       private_network_primary_dns = g_strdup(ns[0]);
+               }
+               if (ns[1]) {
+                       g_free(private_network_secondary_dns);
+                       private_network_secondary_dns = g_strdup(ns[1]);
+               }
 
-static int remove_bridge(const char *name)
-{
-       int sk, err;
+               DBG("Fallback ns primary %s secondary %s",
+                       private_network_primary_dns,
+                       private_network_secondary_dns);
+       }
 
-       DBG("name %s", name);
+       dns = gateway;
+       if (__connman_dnsproxy_add_listener(index) < 0) {
+               connman_error("Can't add listener %s to DNS proxy",
+                                                               BRIDGE_NAME);
+               dns = private_network_primary_dns;
+               DBG("Serving %s nameserver to clients", dns);
+       }
 
-       sk = socket(AF_INET, SOCK_STREAM, 0);
-       if (sk < 0)
+       tethering_dhcp_server = dhcp_server_start(BRIDGE_NAME,
+                                               gateway, subnet_mask,
+                                               start_ip, end_ip,
+                                               24 * 3600, dns);
+       if (!tethering_dhcp_server) {
+               __connman_bridge_disable(BRIDGE_NAME);
+               __connman_ippool_unref(dhcp_ippool);
+               __connman_bridge_remove(BRIDGE_NAME);
+               __sync_fetch_and_sub(&tethering_enabled, 1);
                return -EOPNOTSUPP;
+       }
 
-       err = ioctl(sk, SIOCBRDELBR, name);
+       prefixlen = connman_ipaddress_calc_netmask_len(subnet_mask);
+       err = __connman_nat_enable(BRIDGE_NAME, start_ip, prefixlen);
+       if (err < 0) {
+               connman_error("Cannot enable NAT %d/%s", err, strerror(-err));
+               dhcp_server_stop(tethering_dhcp_server);
+               __connman_bridge_disable(BRIDGE_NAME);
+               __connman_ippool_unref(dhcp_ippool);
+               __connman_bridge_remove(BRIDGE_NAME);
+               __sync_fetch_and_sub(&tethering_enabled, 1);
+               return -EOPNOTSUPP;
+       }
 
-       close(sk);
+       err = __connman_ipv6pd_setup(BRIDGE_NAME);
+       if (err < 0 && err != -EINPROGRESS)
+               DBG("Cannot setup IPv6 prefix delegation %d/%s", err,
+                       strerror(-err));
 
-       if (err < 0)
-               return -EOPNOTSUPP;
+       DBG("tethering started");
 
        return 0;
 }
 
-static int enable_bridge(const char *name)
+void __connman_tethering_set_disabled(void)
 {
-       int err, index;
+       int index;
 
-       index = connman_inet_ifindex(name);
-       if (index < 0)
-               return index;
+       DBG("enabled %d", tethering_enabled - 1);
 
-       err = __connman_inet_modify_address(RTM_NEWADDR,
-                       NLM_F_REPLACE | NLM_F_ACK, index, AF_INET,
-                                       BRIDGE_IP, NULL, 24, BRIDGE_BCAST);
-       if (err < 0)
-               return err;
+       if (__sync_fetch_and_sub(&tethering_enabled, 1) != 1)
+               return;
 
-       return connman_inet_ifup(index);
-}
+       __connman_ipv6pd_cleanup();
 
-static int disable_bridge(const char *name)
-{
-       int index;
+       index = connman_inet_ifindex(BRIDGE_NAME);
+       __connman_dnsproxy_remove_listener(index);
 
-       index = connman_inet_ifindex(name);
-       if (index < 0)
-               return index;
+       __connman_nat_disable(BRIDGE_NAME);
 
-       return connman_inet_ifdown(index);
-}
+       dhcp_server_stop(tethering_dhcp_server);
 
-static int enable_ip_forward(connman_bool_t enable)
-{
+       tethering_dhcp_server = NULL;
 
-       FILE *f;
+       __connman_bridge_disable(BRIDGE_NAME);
 
-       f = fopen("/proc/sys/net/ipv4/ip_forward", "r+");
-       if (f == NULL)
-               return -errno;
+       __connman_ippool_unref(dhcp_ippool);
 
-       if (enable == TRUE)
-               fprintf(f, "1");
-       else
-               fprintf(f, "0");
+       __connman_bridge_remove(BRIDGE_NAME);
 
-       fclose(f);
+       g_free(private_network_primary_dns);
+       private_network_primary_dns = NULL;
+       g_free(private_network_secondary_dns);
+       private_network_secondary_dns = NULL;
 
-       return 0;
+       DBG("tethering stopped");
 }
 
-static int enable_nat(const char *interface)
+static void setup_tun_interface(unsigned int flags, unsigned change,
+               void *data)
 {
+       struct connman_private_network *pn = data;
+       unsigned char prefixlen;
+       DBusMessageIter array, dict;
+       const char *server_ip;
+       const char *peer_ip;
+       const char *subnet_mask;
        int err;
 
-       if (interface == NULL)
-               return 0;
+       DBG("index %d flags %d change %d", pn->index,  flags, change);
 
-       /* Enable IPv4 forwarding */
-       err = enable_ip_forward(TRUE);
-       if (err < 0)
-               return err;
+       if (flags & IFF_UP)
+               return;
 
-       /* POSTROUTING flush */
-       err = __connman_iptables_command("-t nat -F POSTROUTING");
-       if (err < 0)
-               return err;
+       subnet_mask = __connman_ippool_get_subnet_mask(pn->pool);
+       server_ip = __connman_ippool_get_start_ip(pn->pool);
+       peer_ip = __connman_ippool_get_end_ip(pn->pool);
+       prefixlen = connman_ipaddress_calc_netmask_len(subnet_mask);
 
-       /* Enable masquerading */
-       err = __connman_iptables_command("-t nat -A POSTROUTING "
-                                       "-o %s -j MASQUERADE", interface);
-       if (err < 0)
-               return err;
+       if ((__connman_inet_modify_address(RTM_NEWADDR,
+                               NLM_F_REPLACE | NLM_F_ACK, pn->index, AF_INET,
+                               server_ip, peer_ip, prefixlen, NULL)) < 0) {
+               DBG("address setting failed");
+               return;
+       }
 
-       return __connman_iptables_commit("nat");
-}
+       connman_inet_ifup(pn->index);
 
-static void disable_nat(const char *interface)
-{
-       int err;
+       err = __connman_nat_enable(BRIDGE_NAME, server_ip, prefixlen);
+       if (err < 0) {
+               connman_error("failed to enable NAT");
+               goto error;
+       }
 
-       /* Disable IPv4 forwarding */
-       enable_ip_forward(FALSE);
+       dbus_message_iter_init_append(pn->reply, &array);
 
-       /* POSTROUTING flush */
-       err = __connman_iptables_command("-t nat -F POSTROUTING");
-       if (err < 0)
-               return;
+       dbus_message_iter_append_basic(&array, DBUS_TYPE_OBJECT_PATH,
+                                               &pn->path);
 
-       __connman_iptables_commit("nat");
-}
+       connman_dbus_dict_open(&array, &dict);
 
-void __connman_tethering_set_enabled(void)
-{
-       int err;
+       connman_dbus_dict_append_basic(&dict, "ServerIPv4",
+                                       DBUS_TYPE_STRING, &server_ip);
+       connman_dbus_dict_append_basic(&dict, "PeerIPv4",
+                                       DBUS_TYPE_STRING, &peer_ip);
+       if (pn->primary_dns)
+               connman_dbus_dict_append_basic(&dict, "PrimaryDNS",
+                                       DBUS_TYPE_STRING, &pn->primary_dns);
 
-       if (tethering_status == FALSE)
-               return;
+       if (pn->secondary_dns)
+               connman_dbus_dict_append_basic(&dict, "SecondaryDNS",
+                                       DBUS_TYPE_STRING, &pn->secondary_dns);
 
-       DBG("enabled %d", tethering_enabled + 1);
+       connman_dbus_dict_close(&array, &dict);
 
-       if (g_atomic_int_exchange_and_add(&tethering_enabled, 1) == 0) {
-               err = create_bridge(BRIDGE_NAME);
-               if (err < 0)
-                       return;
+       dbus_message_iter_append_basic(&array, DBUS_TYPE_UNIX_FD, &pn->fd);
 
-               err = enable_bridge(BRIDGE_NAME);
-               if (err < 0) {
-                       remove_bridge(BRIDGE_NAME);
-                       return;
-               }
+       g_dbus_send_message(connection, pn->reply);
 
-               tethering_dhcp_server =
-                       dhcp_server_start(BRIDGE_NAME,
-                                               BRIDGE_IP, BRIDGE_SUBNET,
-                                               BRIDGE_IP_START, BRIDGE_IP_END,
-                                                       24 * 3600, BRIDGE_DNS);
-               if (tethering_dhcp_server == NULL) {
-                       disable_bridge(BRIDGE_NAME);
-                       remove_bridge(BRIDGE_NAME);
-                       return;
-               }
+       return;
 
-               enable_nat(default_interface);
+error:
+       pn->reply = __connman_error_failed(pn->msg, -err);
+       g_dbus_send_message(connection, pn->reply);
 
-               DBG("tethering started");
-       }
+       g_hash_table_remove(pn_hash, pn->path);
 }
 
-void __connman_tethering_set_disabled(void)
+static void remove_private_network(gpointer user_data)
 {
-       if (tethering_status == TRUE)
-               return;
+       struct connman_private_network *pn = user_data;
 
-       DBG("enabled %d", tethering_enabled - 1);
+       __connman_nat_disable(BRIDGE_NAME);
+       connman_rtnl_remove_watch(pn->iface_watch);
+       __connman_ippool_unref(pn->pool);
 
-       if (g_atomic_int_dec_and_test(&tethering_enabled) == TRUE) {
-               disable_nat(default_interface);
+       if (pn->watch > 0) {
+               g_dbus_remove_watch(connection, pn->watch);
+               pn->watch = 0;
+       }
 
-               dhcp_server_stop(tethering_dhcp_server);
+       close(pn->fd);
 
-               disable_bridge(BRIDGE_NAME);
+       g_free(pn->interface);
+       g_free(pn->owner);
+       g_free(pn->path);
+       g_free(pn->primary_dns);
+       g_free(pn->secondary_dns);
+       g_free(pn);
+}
 
-               remove_bridge(BRIDGE_NAME);
+static void owner_disconnect(DBusConnection *conn, void *user_data)
+{
+       struct connman_private_network *pn = user_data;
 
-               DBG("tethering stopped");
-       }
+       DBG("%s died", pn->owner);
+
+       pn->watch = 0;
+
+       g_hash_table_remove(pn_hash, pn->path);
 }
 
-int __connman_tethering_set_status(connman_bool_t status)
+static void ippool_disconnect(struct connman_ippool *pool, void *user_data)
 {
-       if (status == tethering_status)
-               return -EALREADY;
+       struct connman_private_network *pn = user_data;
 
-       tethering_status = status;
+       DBG("block used externally");
 
-       if (status == TRUE)
-               __connman_technology_enable_tethering(BRIDGE_NAME);
-       else
-               __connman_technology_disable_tethering(BRIDGE_NAME);
-
-       return 0;
+       g_hash_table_remove(pn_hash, pn->path);
 }
 
-void __connman_tethering_update_interface(const char *interface)
+int __connman_private_network_request(DBusMessage *msg, const char *owner)
 {
-       DBG("interface %s", interface);
+       struct connman_private_network *pn;
+       char *iface = NULL;
+       char *path = NULL;
+       int index, fd, err;
+
+       if (DBUS_TYPE_UNIX_FD < 0)
+               return -EINVAL;
+
+       fd = connman_inet_create_tunnel(&iface);
+       if (fd < 0)
+               return fd;
+
+       path = g_strdup_printf("/tethering/%s", iface);
+
+       pn = g_hash_table_lookup(pn_hash, path);
+       if (pn) {
+               g_free(path);
+               g_free(iface);
+               close(fd);
+               return -EEXIST;
+       }
 
-       g_free(default_interface);
+       index = connman_inet_ifindex(iface);
+       if (index < 0) {
+               err = -ENODEV;
+               goto error;
+       }
+       DBG("interface %s", iface);
 
-       if (interface == NULL) {
-               disable_nat(interface);
-               default_interface = NULL;
+       err = connman_inet_set_mtu(index, DEFAULT_MTU);
 
-               return;
+       pn = g_try_new0(struct connman_private_network, 1);
+       if (!pn) {
+               err = -ENOMEM;
+               goto error;
        }
 
-       default_interface = g_strdup(interface);
+       pn->owner = g_strdup(owner);
+       pn->path = path;
+       pn->watch = g_dbus_add_disconnect_watch(connection, pn->owner,
+                                       owner_disconnect, pn, NULL);
+       pn->msg = msg;
+       pn->reply = dbus_message_new_method_return(pn->msg);
+       if (!pn->reply)
+               goto error;
+
+       pn->fd = fd;
+       pn->interface = iface;
+       pn->index = index;
+       pn->pool = __connman_ippool_create(pn->index, 1, 1, ippool_disconnect, pn);
+       if (!pn->pool) {
+               errno = -ENOMEM;
+               goto error;
+       }
 
-       if (tethering_status == FALSE ||
-                       !g_atomic_int_get(&tethering_enabled))
-               return;
+       pn->primary_dns = g_strdup(private_network_primary_dns);
+       pn->secondary_dns = g_strdup(private_network_secondary_dns);
+
+       pn->iface_watch = connman_rtnl_add_newlink_watch(index,
+                                               setup_tun_interface, pn);
+
+       g_hash_table_insert(pn_hash, pn->path, pn);
+
+       return 0;
+
+error:
+       close(fd);
+       g_free(iface);
+       g_free(path);
+       if (pn)
+               g_free(pn->owner);
+       g_free(pn);
+       return err;
+}
+
+int __connman_private_network_release(const char *path)
+{
+       struct connman_private_network *pn;
+
+       pn = g_hash_table_lookup(pn_hash, path);
+       if (!pn)
+               return -EACCES;
 
-       enable_nat(interface);
+       g_hash_table_remove(pn_hash, path);
+       return 0;
 }
 
 int __connman_tethering_init(void)
@@ -387,17 +696,37 @@ int __connman_tethering_init(void)
 
        tethering_enabled = 0;
 
+       connection = connman_dbus_get_connection();
+       if (!connection)
+               return -EFAULT;
+
+       pn_hash = g_hash_table_new_full(g_str_hash, g_str_equal,
+                                               NULL, remove_private_network);
+
+       sta_hash = g_hash_table_new_full(g_str_hash,
+                                        g_str_equal, NULL, NULL);
+
        return 0;
 }
 
 void __connman_tethering_cleanup(void)
 {
-       DBG("");
+       DBG("enabled %d", tethering_enabled);
 
-       if (tethering_status == TRUE) {
+       __sync_synchronize();
+       if (tethering_enabled > 0) {
                if (tethering_dhcp_server)
                        dhcp_server_stop(tethering_dhcp_server);
-               disable_bridge(BRIDGE_NAME);
-               remove_bridge(BRIDGE_NAME);
+               __connman_bridge_disable(BRIDGE_NAME);
+               __connman_bridge_remove(BRIDGE_NAME);
+               __connman_nat_disable(BRIDGE_NAME);
        }
+
+       if (!connection)
+               return;
+
+       g_hash_table_destroy(pn_hash);
+       g_hash_table_foreach(sta_hash, destroy_station, NULL);
+       g_hash_table_destroy(sta_hash);
+       dbus_connection_unref(connection);
 }