vpn-provider: Send domain name to connman when connection is ready
[platform/upstream/connman.git] / vpn / vpn-provider.c
index a69b458..513d926 100644 (file)
 #include <netdb.h>
 
 #include "../src/connman.h"
+#include "connman/agent.h"
 #include "connman/vpn-dbus.h"
 #include "vpn-provider.h"
 #include "vpn.h"
 
-enum {
-       USER_ROUTES_CHANGED = 0x01,
-       SERVER_ROUTES_CHANGED = 0x02,
-};
-
 static DBusConnection *connection;
 static GHashTable *provider_hash;
 static GSList *driver_list;
@@ -55,6 +51,12 @@ struct vpn_route {
        char *gateway;
 };
 
+struct vpn_setting {
+       gboolean hide_value;
+       gboolean immutable;
+       char *value;
+};
+
 struct vpn_provider {
        int refcount;
        int index;
@@ -78,10 +80,15 @@ struct vpn_provider {
        struct vpn_ipconfig *ipconfig_ipv4;
        struct vpn_ipconfig *ipconfig_ipv6;
        char **nameservers;
-       int what_changed;
        guint notify_id;
+       char *config_file;
+       char *config_entry;
+       connman_bool_t immutable;
 };
 
+static void append_properties(DBusMessageIter *iter,
+                               struct vpn_provider *provider);
+
 static void free_route(gpointer data)
 {
        struct vpn_route *route = data;
@@ -93,6 +100,14 @@ static void free_route(gpointer data)
        g_free(route);
 }
 
+static void free_setting(gpointer data)
+{
+       struct vpn_setting *setting = data;
+
+       g_free(setting->value);
+       g_free(setting);
+}
+
 static void append_route(DBusMessageIter *iter, void *user_data)
 {
        struct vpn_route *route = user_data;
@@ -163,15 +178,11 @@ static void send_routes(struct vpn_provider *provider, GHashTable *routes,
                                        routes);
 }
 
-static int provider_property_changed(struct vpn_provider *provider,
-                               const char *name)
+static int provider_routes_changed(struct vpn_provider *provider)
 {
-       DBG("provider %p name %s", provider, name);
+       DBG("provider %p", provider);
 
-       if (g_str_equal(name, "UserRoutes") == TRUE)
-               send_routes(provider, provider->user_routes, name);
-       else if (g_str_equal(name, "ServerRoutes") == TRUE)
-               send_routes(provider, provider->routes, name);
+       send_routes(provider, provider->routes, "ServerRoutes");
 
        return 0;
 }
@@ -234,13 +245,9 @@ static GSList *read_route_dict(GSList *routes, DBusMessageIter *dicts)
                if (family < 0) {
                        DBG("Cannot get address family of %s (%d/%s)", network,
                                family, gai_strerror(family));
-                       if (strstr(network, ":") != NULL) {
-                               DBG("Guessing it is IPv6");
-                               family = AF_INET6;
-                       } else {
-                               DBG("Guessing it is IPv4");
-                               family = AF_INET;
-                       }
+
+                       g_free(route);
+                       return routes;
                }
        } else {
                switch (family) {
@@ -301,11 +308,11 @@ static void set_user_networks(struct vpn_provider *provider, GSList *networks)
        GSList *list;
 
        for (list = networks; list != NULL; list = g_slist_next(list)) {
-               struct vpn_route *route= list->data;
+               struct vpn_route *route = list->data;
 
                if (__vpn_provider_append_user_route(provider,
                                        route->family, route->network,
-                                       route->netmask) != 0)
+                                       route->netmask, route->gateway) != 0)
                        break;
        }
 }
@@ -334,33 +341,63 @@ static void del_routes(struct vpn_provider *provider)
        provider->user_networks = NULL;
 }
 
+static void send_value(const char *path, const char *key, const char *value)
+{
+       const char *empty = "";
+       const char *str;
+
+       if (value != NULL)
+               str = value;
+       else
+               str = empty;
+
+       connman_dbus_property_changed_basic(path,
+                                       VPN_CONNECTION_INTERFACE,
+                                       key,
+                                       DBUS_TYPE_STRING,
+                                       &str);
+}
+
 static gboolean provider_send_changed(gpointer data)
 {
        struct vpn_provider *provider = data;
 
-       if (provider->what_changed & USER_ROUTES_CHANGED)
-               provider_property_changed(provider, "UserRoutes");
+       provider_routes_changed(provider);
 
-       if (provider->what_changed & SERVER_ROUTES_CHANGED)
-               provider_property_changed(provider, "ServerRoutes");
-
-       provider->what_changed = 0;
        provider->notify_id = 0;
 
        return FALSE;
 }
 
-static void provider_schedule_changed(struct vpn_provider *provider, int flag)
+static void provider_schedule_changed(struct vpn_provider *provider)
 {
        if (provider->notify_id != 0)
                g_source_remove(provider->notify_id);
 
-       provider->what_changed |= flag;
-
        provider->notify_id = g_timeout_add(100, provider_send_changed,
                                                                provider);
 }
 
+static DBusMessage *get_properties(DBusConnection *conn,
+                                       DBusMessage *msg, void *data)
+{
+       struct vpn_provider *provider = data;
+       DBusMessage *reply;
+       DBusMessageIter array;
+
+       DBG("provider %p", provider);
+
+       reply = dbus_message_new_method_return(msg);
+       if (reply == NULL)
+               return NULL;
+
+       dbus_message_iter_init_append(reply, &array);
+
+       append_properties(&array, provider);
+
+       return reply;
+}
+
 static DBusMessage *set_property(DBusConnection *conn, DBusMessage *msg,
                                                                void *data)
 {
@@ -371,6 +408,9 @@ static DBusMessage *set_property(DBusConnection *conn, DBusMessage *msg,
 
        DBG("conn %p", conn);
 
+       if (provider->immutable == TRUE)
+               return __connman_error_not_supported(msg);
+
        if (dbus_message_iter_init(msg, &iter) == FALSE)
                return __connman_error_invalid_arguments(msg);
 
@@ -400,11 +440,15 @@ static DBusMessage *set_property(DBusConnection *conn, DBusMessage *msg,
                        set_user_networks(provider, provider->user_networks);
 
                        if (handle_routes == FALSE)
-                               provider_schedule_changed(provider,
-                                                       USER_ROUTES_CHANGED);
+                               send_routes(provider, provider->user_routes,
+                                                               "UserRoutes");
                }
-       } else
-               return __connman_error_invalid_property(msg);
+       } else {
+               const char *str;
+
+               dbus_message_iter_get_basic(&value, &str);
+               vpn_provider_set_string(provider, name, str);
+       }
 
        return g_dbus_create_reply(msg, DBUS_TYPE_INVALID);
 }
@@ -417,6 +461,9 @@ static DBusMessage *clear_property(DBusConnection *conn, DBusMessage *msg,
 
        DBG("conn %p", conn);
 
+       if (provider->immutable == TRUE)
+               return __connman_error_not_supported(msg);
+
        dbus_message_get_args(msg, NULL, DBUS_TYPE_STRING, &name,
                                                        DBUS_TYPE_INVALID);
 
@@ -424,7 +471,9 @@ static DBusMessage *clear_property(DBusConnection *conn, DBusMessage *msg,
                del_routes(provider);
 
                if (handle_routes == FALSE)
-                       provider_property_changed(provider, name);
+                       send_routes(provider, provider->user_routes, name);
+       } else if (vpn_provider_get_string(provider, name) != NULL) {
+               vpn_provider_set_string(provider, name, NULL);
        } else {
                return __connman_error_invalid_property(msg);
        }
@@ -440,11 +489,11 @@ static DBusMessage *do_connect(DBusConnection *conn, DBusMessage *msg,
 
        DBG("conn %p provider %p", conn, provider);
 
-       err = __vpn_provider_connect(provider);
+       err = __vpn_provider_connect(provider, msg);
        if (err < 0)
                return __connman_error_failed(msg, -err);
 
-       return g_dbus_create_reply(msg, DBUS_TYPE_INVALID);
+       return NULL;
 }
 
 static DBusMessage *do_disconnect(DBusConnection *conn, DBusMessage *msg,
@@ -456,13 +505,16 @@ static DBusMessage *do_disconnect(DBusConnection *conn, DBusMessage *msg,
        DBG("conn %p provider %p", conn, provider);
 
        err = __vpn_provider_disconnect(provider);
-       if (err < 0)
+       if (err < 0 && err != -EINPROGRESS)
                return __connman_error_failed(msg, -err);
-       else
-               return g_dbus_create_reply(msg, DBUS_TYPE_INVALID);
+
+       return g_dbus_create_reply(msg, DBUS_TYPE_INVALID);
 }
 
 static const GDBusMethodTable connection_methods[] = {
+       { GDBUS_METHOD("GetProperties",
+                       NULL, GDBUS_ARGS({ "properties", "a{sv}" }),
+                       get_properties) },
        { GDBUS_METHOD("SetProperty",
                        GDBUS_ARGS({ "name", "s" }, { "value", "v" }),
                        NULL, set_property) },
@@ -542,12 +594,15 @@ void __vpn_provider_append_properties(struct vpn_provider *provider,
 }
 
 int __vpn_provider_append_user_route(struct vpn_provider *provider,
-                       int family, const char *network, const char *netmask)
+                               int family, const char *network,
+                               const char *netmask, const char *gateway)
 {
        struct vpn_route *route;
-       char *key = g_strdup_printf("%d/%s/%s", family, network, netmask);
+       char *key = g_strdup_printf("%d/%s/%s/%s", family, network,
+                               netmask, gateway != NULL ? gateway : "");
 
-       DBG("family %d network %s netmask %s", family, network, netmask);
+       DBG("family %d network %s netmask %s gw %s", family, network,
+                                                       netmask, gateway);
 
        route = g_hash_table_lookup(provider->user_routes, key);
        if (route == NULL) {
@@ -560,6 +615,7 @@ int __vpn_provider_append_user_route(struct vpn_provider *provider,
                route->family = family;
                route->network = g_strdup(network);
                route->netmask = g_strdup(netmask);
+               route->gateway = g_strdup(gateway);
 
                g_hash_table_replace(provider->user_routes, key, route);
        } else
@@ -778,7 +834,16 @@ static int vpn_provider_save(struct vpn_provider *provider)
 {
        GKeyFile *keyfile;
 
-       DBG("provider %p", provider);
+       DBG("provider %p immutable %s", provider,
+                                       provider->immutable ? "yes" : "no");
+
+       if (provider->immutable == TRUE) {
+               /*
+                * Do not save providers that are provisioned via .config
+                * file.
+                */
+               return -EPERM;
+       }
 
        keyfile = g_key_file_new();
        if (keyfile == NULL)
@@ -808,6 +873,15 @@ static int vpn_provider_save(struct vpn_provider *provider)
                }
        }
 
+       if (provider->config_file != NULL && strlen(provider->config_file) > 0)
+               g_key_file_set_string(keyfile, provider->identifier,
+                               "Config.file", provider->config_file);
+
+       if (provider->config_entry != NULL &&
+                                       strlen(provider->config_entry) > 0)
+               g_key_file_set_string(keyfile, provider->identifier,
+                               "Config.ident", provider->config_entry);
+
        if (provider->driver != NULL && provider->driver->save != NULL)
                provider->driver->save(provider, keyfile);
 
@@ -817,7 +891,7 @@ static int vpn_provider_save(struct vpn_provider *provider)
        return 0;
 }
 
-static struct vpn_provider *vpn_provider_lookup(const char *identifier)
+struct vpn_provider *__vpn_provider_lookup(const char *identifier)
 {
        struct vpn_provider *provider = NULL;
 
@@ -839,7 +913,8 @@ static int provider_probe(struct vpn_provider *provider)
 {
        GSList *list;
 
-       DBG("provider %p name %s", provider, provider->name);
+       DBG("provider %p driver %p name %s", provider, provider->driver,
+                                               provider->name);
 
        if (provider->driver != NULL)
                return -EALREADY;
@@ -920,6 +995,8 @@ static void provider_destruct(struct vpn_provider *provider)
        __vpn_ipconfig_unref(provider->ipconfig_ipv6);
 
        g_strfreev(provider->host_ip);
+       g_free(provider->config_file);
+       g_free(provider->config_entry);
        g_free(provider);
 }
 
@@ -950,8 +1027,6 @@ static void configuration_count_del(void)
 
        if (__sync_fetch_and_sub(&configuration_count, 1) != 1)
                return;
-
-       raise(SIGTERM);
 }
 
 int __vpn_provider_disconnect(struct vpn_provider *provider)
@@ -965,27 +1040,48 @@ int __vpn_provider_disconnect(struct vpn_provider *provider)
        else
                return -EOPNOTSUPP;
 
-       if (err < 0) {
-               if (err != -EINPROGRESS)
-                       return err;
+       if (err == -EINPROGRESS)
+               vpn_provider_set_state(provider, VPN_PROVIDER_STATE_CONNECT);
 
-               return -EINPROGRESS;
-       }
+       return err;
+}
 
-       return 0;
+static void connect_cb(struct vpn_provider *provider, void *user_data,
+                                                               int error)
+{
+       DBusMessage *pending = user_data;
+
+       DBG("provider %p user %p error %d", provider, user_data, error);
+
+       if (error != 0) {
+               DBusMessage *reply = __connman_error_failed(pending, error);
+               if (reply != NULL)
+                       g_dbus_send_message(connection, reply);
+
+               vpn_provider_indicate_error(provider,
+                                       VPN_PROVIDER_ERROR_CONNECT_FAILED);
+               vpn_provider_set_state(provider, VPN_PROVIDER_STATE_FAILURE);
+       } else
+               g_dbus_send_reply(connection, pending, DBUS_TYPE_INVALID);
+
+       dbus_message_unref(pending);
 }
 
-int __vpn_provider_connect(struct vpn_provider *provider)
+int __vpn_provider_connect(struct vpn_provider *provider, DBusMessage *msg)
 {
        int err;
 
        DBG("provider %p", provider);
 
-       if (provider->driver != NULL && provider->driver->connect != NULL)
-               err = provider->driver->connect(provider);
-       else
+       if (provider->driver != NULL && provider->driver->connect != NULL) {
+               dbus_message_ref(msg);
+               err = provider->driver->connect(provider, connect_cb, msg);
+       } else
                return -EOPNOTSUPP;
 
+       if (err == -EINPROGRESS)
+               vpn_provider_set_state(provider, VPN_PROVIDER_STATE_CONNECT);
+
        return err;
 }
 
@@ -1029,20 +1125,26 @@ int __vpn_provider_remove(const char *path)
 
        ident = get_ident(path);
 
-       provider = vpn_provider_lookup(ident);
-       if (provider != NULL) {
-               DBG("Removing VPN %s", provider->identifier);
+       provider = __vpn_provider_lookup(ident);
+       if (provider != NULL)
+               return __vpn_provider_delete(provider);
 
-               connection_removed_signal(provider);
+       return -ENXIO;
+}
 
-               provider_unregister(provider);
-               g_hash_table_remove(provider_hash, provider->identifier);
+int __vpn_provider_delete(struct vpn_provider *provider)
+{
+       DBG("Deleting VPN %s", provider->identifier);
 
-               __connman_storage_remove_provider(ident);
-               return 0;
-       }
+       connection_removed_signal(provider);
 
-       return -ENXIO;
+       provider_unregister(provider);
+
+       __connman_storage_remove_provider(provider->identifier);
+
+       g_hash_table_remove(provider_hash, provider->identifier);
+
+       return 0;
 }
 
 static void append_ipv4(DBusMessageIter *iter, void *user_data)
@@ -1132,17 +1234,39 @@ static const char *state2string(enum vpn_provider_state state)
        return NULL;
 }
 
+static void append_nameservers(DBusMessageIter *iter, char **servers)
+{
+       int i;
+
+       DBG("%p", servers);
+
+       for (i = 0; servers[i] != NULL; i++) {
+               DBG("servers[%d] %s", i, servers[i]);
+               dbus_message_iter_append_basic(iter,
+                                       DBUS_TYPE_STRING, &servers[i]);
+       }
+}
+
+static void append_dns(DBusMessageIter *iter, void *user_data)
+{
+       struct vpn_provider *provider = user_data;
+
+       if (provider->nameservers != NULL)
+               append_nameservers(iter, provider->nameservers);
+}
+
 static int provider_indicate_state(struct vpn_provider *provider,
                                enum vpn_provider_state state)
 {
        const char *str;
-
-       DBG("provider %p state %d", provider, state);
+       enum vpn_provider_state old_state;
 
        str = state2string(state);
+       DBG("provider %p state %s/%d", provider, str, state);
        if (str == NULL)
                return -EINVAL;
 
+       old_state = provider->state;
        provider->state = state;
 
        if (state == VPN_PROVIDER_STATE_READY) {
@@ -1158,33 +1282,34 @@ static int provider_indicate_state(struct vpn_provider *provider,
                        connman_dbus_property_changed_dict(provider->path,
                                        VPN_CONNECTION_INTERFACE, "IPv6",
                                        append_ipv6, provider);
+
+               connman_dbus_property_changed_array(provider->path,
+                                               VPN_CONNECTION_INTERFACE,
+                                               "Nameservers",
+                                               DBUS_TYPE_STRING,
+                                               append_dns, provider);
+
+               if (provider->domain != NULL)
+                       connman_dbus_property_changed_basic(provider->path,
+                                               VPN_CONNECTION_INTERFACE,
+                                               "Domain",
+                                               DBUS_TYPE_STRING,
+                                               &provider->domain);
        }
 
-       connman_dbus_property_changed_basic(provider->path,
+       if (old_state != state)
+               connman_dbus_property_changed_basic(provider->path,
                                        VPN_CONNECTION_INTERFACE, "State",
                                        DBUS_TYPE_STRING, &str);
-       return 0;
-}
-
-static void append_nameservers(DBusMessageIter *iter, char **servers)
-{
-       int i;
-
-       DBG("%p", servers);
 
-       for (i = 0; servers[i] != NULL; i++) {
-               DBG("servers[%d] %s", i, servers[i]);
-               dbus_message_iter_append_basic(iter,
-                                       DBUS_TYPE_STRING, &servers[i]);
-       }
-}
-
-static void append_dns(DBusMessageIter *iter, void *user_data)
-{
-       struct vpn_provider *provider = user_data;
+       /*
+        * We do not stay in failure state as clients like connmand can
+        * get confused about our current state.
+        */
+       if (provider->state == VPN_PROVIDER_STATE_FAILURE)
+               provider->state = VPN_PROVIDER_STATE_IDLE;
 
-       if (provider->nameservers != NULL)
-               append_nameservers(iter, provider->nameservers);
+       return 0;
 }
 
 static void append_state(DBusMessageIter *iter,
@@ -1219,6 +1344,8 @@ static void append_properties(DBusMessageIter *iter,
                                        struct vpn_provider *provider)
 {
        DBusMessageIter dict;
+       GHashTableIter hash;
+       gpointer value, key;
 
        connman_dbus_dict_open(iter, &dict);
 
@@ -1242,6 +1369,9 @@ static void append_properties(DBusMessageIter *iter,
                connman_dbus_dict_append_basic(&dict, "Domain",
                                        DBUS_TYPE_STRING, &provider->domain);
 
+       connman_dbus_dict_append_basic(&dict, "Immutable", DBUS_TYPE_BOOLEAN,
+                                       &provider->immutable);
+
        if (provider->family == AF_INET)
                connman_dbus_dict_append_dict(&dict, "IPv4", append_ipv4,
                                                provider);
@@ -1260,6 +1390,20 @@ static void append_properties(DBusMessageIter *iter,
                                DBUS_TYPE_DICT_ENTRY, append_routes,
                                provider->routes);
 
+       if (provider->setting_strings != NULL) {
+               g_hash_table_iter_init(&hash, provider->setting_strings);
+
+               while (g_hash_table_iter_next(&hash, &key, &value) == TRUE) {
+                       struct vpn_setting *setting = value;
+
+                       if (setting->hide_value == FALSE &&
+                                                       setting->value != NULL)
+                               connman_dbus_dict_append_basic(&dict, key,
+                                                       DBUS_TYPE_STRING,
+                                                       &setting->value);
+               }
+       }
+
        connman_dbus_dict_close(iter, &dict);
 }
 
@@ -1403,6 +1547,7 @@ int vpn_provider_indicate_error(struct vpn_provider *provider,
        case VPN_PROVIDER_ERROR_LOGIN_FAILED:
                break;
        case VPN_PROVIDER_ERROR_AUTH_FAILED:
+               vpn_provider_set_state(provider, VPN_PROVIDER_STATE_FAILURE);
                break;
        case VPN_PROVIDER_ERROR_CONNECT_FAILED:
                break;
@@ -1413,12 +1558,48 @@ int vpn_provider_indicate_error(struct vpn_provider *provider,
        return 0;
 }
 
+static int connection_unregister(struct vpn_provider *provider)
+{
+       DBG("provider %p path %s", provider, provider->path);
+
+       if (provider->path == NULL)
+               return -EALREADY;
+
+       g_dbus_unregister_interface(connection, provider->path,
+                               VPN_CONNECTION_INTERFACE);
+
+       g_free(provider->path);
+       provider->path = NULL;
+
+       return 0;
+}
+
+static int connection_register(struct vpn_provider *provider)
+{
+       DBG("provider %p path %s", provider, provider->path);
+
+       if (provider->path != NULL)
+               return -EALREADY;
+
+       provider->path = g_strdup_printf("%s/connection/%s", VPN_PATH,
+                                               provider->identifier);
+
+       g_dbus_register_interface(connection, provider->path,
+                               VPN_CONNECTION_INTERFACE,
+                               connection_methods, connection_signals,
+                               NULL, provider, NULL);
+
+       return 0;
+}
+
 static void unregister_provider(gpointer data)
 {
        struct vpn_provider *provider = data;
 
        configuration_count_del();
 
+       connection_unregister(provider);
+
        vpn_provider_unref(provider);
 }
 
@@ -1432,13 +1613,14 @@ static void provider_initialize(struct vpn_provider *provider)
        provider->type = NULL;
        provider->domain = NULL;
        provider->identifier = NULL;
+       provider->immutable = FALSE;
        provider->user_networks = NULL;
        provider->routes = g_hash_table_new_full(g_direct_hash, g_direct_equal,
                                        NULL, free_route);
        provider->user_routes = g_hash_table_new_full(g_str_hash, g_str_equal,
                                        g_free, free_route);
        provider->setting_strings = g_hash_table_new_full(g_str_hash,
-                                               g_str_equal, g_free, g_free);
+                                       g_str_equal, g_free, free_setting);
 }
 
 static struct vpn_provider *vpn_provider_new(void)
@@ -1495,38 +1677,6 @@ static void provider_dbus_ident(char *ident)
        }
 }
 
-static int connection_unregister(struct vpn_provider *provider)
-{
-       if (provider->path == NULL)
-               return -EALREADY;
-
-       g_dbus_unregister_interface(connection, provider->path,
-                               VPN_CONNECTION_INTERFACE);
-
-       g_free(provider->path);
-       provider->path = NULL;
-
-       return 0;
-}
-
-static int connection_register(struct vpn_provider *provider)
-{
-       DBG("provider %p path %s", provider, provider->path);
-
-       if (provider->path != NULL)
-               return -EALREADY;
-
-       provider->path = g_strdup_printf("%s/connection/%s", VPN_PATH,
-                                               provider->identifier);
-
-       g_dbus_register_interface(connection, provider->path,
-                               VPN_CONNECTION_INTERFACE,
-                               connection_methods, connection_signals,
-                               NULL, provider, NULL);
-
-       return 0;
-}
-
 static struct vpn_provider *provider_create_from_keyfile(GKeyFile *keyfile,
                const char *ident)
 {
@@ -1535,7 +1685,7 @@ static struct vpn_provider *provider_create_from_keyfile(GKeyFile *keyfile,
        if (keyfile == NULL || ident == NULL)
                return NULL;
 
-       provider = vpn_provider_lookup(ident);
+       provider = __vpn_provider_lookup(ident);
        if (provider == NULL) {
                provider = vpn_provider_get(ident);
                if (provider == NULL) {
@@ -1569,6 +1719,9 @@ static void provider_create_all_from_type(const char *provider_type)
 
        providers = __connman_storage_get_providers();
 
+       if (providers == NULL)
+               return;
+
        for (i = 0; providers[i] != NULL; i+=1) {
 
                if (strncmp(providers[i], "provider_", 9) != 0)
@@ -1599,6 +1752,19 @@ static void provider_create_all_from_type(const char *provider_type)
        g_strfreev(providers);
 }
 
+char *__vpn_provider_create_identifier(const char *host, const char *domain)
+{
+       char *ident;
+
+       ident = g_strdup_printf("%s_%s", host, domain);
+       if (ident == NULL)
+               return NULL;
+
+       provider_dbus_ident(ident);
+
+       return ident;
+}
+
 int __vpn_provider_create(DBusMessage *msg)
 {
        struct vpn_provider *provider;
@@ -1630,7 +1796,8 @@ int __vpn_provider_create(DBusMessage *msg)
                                dbus_message_iter_get_basic(&value, &name);
                        else if (g_str_equal(key, "Host") == TRUE)
                                dbus_message_iter_get_basic(&value, &host);
-                       else if (g_str_equal(key, "VPN.Domain") == TRUE)
+                       else if (g_str_equal(key, "VPN.Domain") == TRUE ||
+                                       g_str_equal(key, "Domain") == TRUE)
                                dbus_message_iter_get_basic(&value, &domain);
                        break;
                case DBUS_TYPE_ARRAY:
@@ -1650,12 +1817,10 @@ int __vpn_provider_create(DBusMessage *msg)
        if (type == NULL || name == NULL)
                return -EOPNOTSUPP;
 
-       ident = g_strdup_printf("%s_%s", host, domain);
-       provider_dbus_ident(ident);
-
+       ident = __vpn_provider_create_identifier(host, domain);
        DBG("ident %s", ident);
 
-       provider = vpn_provider_lookup(ident);
+       provider = __vpn_provider_lookup(ident);
        if (provider == NULL) {
                provider = vpn_provider_get(ident);
                if (provider == NULL) {
@@ -1726,6 +1891,183 @@ int __vpn_provider_create(DBusMessage *msg)
        return 0;
 }
 
+static const char *get_string(GHashTable *settings, const char *key)
+{
+       DBG("settings %p key %s", settings, key);
+
+       return g_hash_table_lookup(settings, key);
+}
+
+static GSList *parse_user_networks(const char *network_str)
+{
+       GSList *networks = NULL;
+       char **elems;
+       int i = 0;
+
+       if (network_str == NULL)
+               return NULL;
+
+       elems = g_strsplit(network_str, ",", 0);
+       if (elems == NULL)
+               return NULL;
+
+       while (elems[i] != NULL) {
+               struct vpn_route *vpn_route;
+               char *network, *netmask, *gateway;
+               int family;
+               char **route;
+
+               route = g_strsplit(elems[i], "/", 0);
+               if (route == NULL)
+                       goto next;
+
+               network = route[0];
+               if (network == NULL || network[0] == '\0')
+                       goto next;
+
+               family = connman_inet_check_ipaddress(network);
+               if (family < 0) {
+                       DBG("Cannot get address family of %s (%d/%s)", network,
+                               family, gai_strerror(family));
+
+                       goto next;
+               }
+
+               switch (family) {
+               case AF_INET:
+                       break;
+               case AF_INET6:
+                       break;
+               default:
+                       DBG("Unsupported address family %d", family);
+                       goto next;
+               }
+
+               netmask = route[1];
+               if (netmask == NULL || netmask[0] == '\0')
+                       goto next;
+
+               gateway = route[2];
+
+               vpn_route = g_try_new0(struct vpn_route, 1);
+               if (vpn_route == NULL) {
+                       g_strfreev(route);
+                       break;
+               }
+
+               vpn_route->family = family;
+               vpn_route->network = g_strdup(network);
+               vpn_route->netmask = g_strdup(netmask);
+               vpn_route->gateway = g_strdup(gateway);
+
+               DBG("route %s/%s%s%s", network, netmask,
+                       gateway ? " via " : "", gateway ? gateway : "");
+
+               networks = g_slist_prepend(networks, vpn_route);
+
+       next:
+               g_strfreev(route);
+               i++;
+       }
+
+       g_strfreev(elems);
+
+       return g_slist_reverse(networks);
+}
+
+int __vpn_provider_create_from_config(GHashTable *settings,
+                               const char *config_ident,
+                               const char *config_entry)
+{
+       struct vpn_provider *provider;
+       const char *type, *name, *host, *domain, *networks_str;
+       GSList *networks;
+       char *ident = NULL;
+       GHashTableIter hash;
+       gpointer value, key;
+       int err;
+
+       type = get_string(settings, "Type");
+       name = get_string(settings, "Name");
+       host = get_string(settings, "Host");
+       domain = get_string(settings, "Domain");
+       networks_str = get_string(settings, "Networks");
+       networks = parse_user_networks(networks_str);
+
+       if (host == NULL || domain == NULL) {
+               err = -EINVAL;
+               goto fail;
+       }
+
+       DBG("type %s name %s networks %s", type, name, networks_str);
+
+       if (type == NULL || name == NULL) {
+               err = -EOPNOTSUPP;
+               goto fail;
+       }
+
+       ident = __vpn_provider_create_identifier(host, domain);
+       DBG("ident %s", ident);
+
+       provider = __vpn_provider_lookup(ident);
+       if (provider == NULL) {
+               provider = vpn_provider_get(ident);
+               if (provider == NULL) {
+                       DBG("can not create provider");
+                       err = -EOPNOTSUPP;
+                       goto fail;
+               }
+
+               provider->host = g_strdup(host);
+               provider->domain = g_strdup(domain);
+               provider->name = g_strdup(name);
+               provider->type = g_ascii_strdown(type, -1);
+
+               provider->config_file = g_strdup(config_ident);
+               provider->config_entry = g_strdup(config_entry);
+
+               provider_register(provider);
+
+               provider_resolv_host_addr(provider);
+       }
+
+       if (networks != NULL) {
+               g_slist_free_full(provider->user_networks, free_route);
+               provider->user_networks = networks;
+               set_user_networks(provider, provider->user_networks);
+       }
+
+       g_hash_table_iter_init(&hash, settings);
+
+       while (g_hash_table_iter_next(&hash, &key, &value) == TRUE)
+               __vpn_provider_set_string_immutable(provider, key, value);
+
+       provider->immutable = TRUE;
+
+       vpn_provider_save(provider);
+
+       err = provider_register(provider);
+       if (err != 0 && err != -EALREADY)
+               goto fail;
+
+       connection_register(provider);
+
+       DBG("provider %p index %d path %s", provider, provider->index,
+                                                       provider->path);
+
+       connection_added_signal(provider);
+
+       g_free(ident);
+
+       return 0;
+
+fail:
+       g_free(ident);
+       g_slist_free_full(networks, free_route);
+
+       return err;
+}
+
 static void append_connection_structs(DBusMessageIter *iter, void *user_data)
 {
        DBusMessageIter entry;
@@ -1775,32 +2117,84 @@ const char * __vpn_provider_get_ident(struct vpn_provider *provider)
        return provider->identifier;
 }
 
-int vpn_provider_set_string(struct vpn_provider *provider,
-                                       const char *key, const char *value)
+static int set_string(struct vpn_provider *provider,
+                       const char *key, const char *value,
+                       gboolean hide_value, gboolean immutable)
 {
-       DBG("provider %p key %s value %s", provider, key, value);
+       DBG("provider %p key %s immutable %s value %s", provider, key,
+               immutable ? "yes" : "no",
+               hide_value ? "<not printed>" : value);
 
        if (g_str_equal(key, "Type") == TRUE) {
                g_free(provider->type);
-               provider->type = g_strdup(value);
+               provider->type = g_ascii_strdown(value, -1);
+               send_value(provider->path, "Type", provider->type);
        } else if (g_str_equal(key, "Name") == TRUE) {
                g_free(provider->name);
                provider->name = g_strdup(value);
+               send_value(provider->path, "Name", provider->name);
        } else if (g_str_equal(key, "Host") == TRUE) {
                g_free(provider->host);
                provider->host = g_strdup(value);
-       } else if (g_str_equal(key, "VPN.Domain") == TRUE) {
+               send_value(provider->path, "Host", provider->host);
+       } else if (g_str_equal(key, "VPN.Domain") == TRUE ||
+                       g_str_equal(key, "Domain") == TRUE) {
                g_free(provider->domain);
                provider->domain = g_strdup(value);
-       } else
+               send_value(provider->path, "Domain", provider->domain);
+       } else {
+               struct vpn_setting *setting;
+
+               setting = g_hash_table_lookup(provider->setting_strings, key);
+               if (setting != NULL && immutable == FALSE &&
+                                               setting->immutable == TRUE) {
+                       DBG("Trying to set immutable variable %s", key);
+                       return -EPERM;
+               }
+
+               setting = g_try_new0(struct vpn_setting, 1);
+               if (setting == NULL)
+                       return -ENOMEM;
+
+               setting->value = g_strdup(value);
+               setting->hide_value = hide_value;
+
+               if (immutable == TRUE)
+                       setting->immutable = TRUE;
+
+               if (hide_value == FALSE)
+                       send_value(provider->path, key, setting->value);
+
                g_hash_table_replace(provider->setting_strings,
-                               g_strdup(key), g_strdup(value));
+                               g_strdup(key), setting);
+       }
+
        return 0;
 }
 
+int vpn_provider_set_string(struct vpn_provider *provider,
+                                       const char *key, const char *value)
+{
+       return set_string(provider, key, value, FALSE, FALSE);
+}
+
+int vpn_provider_set_string_hide_value(struct vpn_provider *provider,
+                                       const char *key, const char *value)
+{
+       return set_string(provider, key, value, TRUE, FALSE);
+}
+
+int __vpn_provider_set_string_immutable(struct vpn_provider *provider,
+                                       const char *key, const char *value)
+{
+       return set_string(provider, key, value, FALSE, TRUE);
+}
+
 const char *vpn_provider_get_string(struct vpn_provider *provider,
                                                        const char *key)
 {
+       struct vpn_setting *setting;
+
        DBG("provider %p key %s", provider, key);
 
        if (g_str_equal(key, "Type") == TRUE)
@@ -1815,10 +2209,15 @@ const char *vpn_provider_get_string(struct vpn_provider *provider,
                        return provider->host;
                else
                        return provider->host_ip[0];
-       } else if (g_str_equal(key, "VPN.Domain") == TRUE)
+       } else if (g_str_equal(key, "VPN.Domain") == TRUE ||
+                       g_str_equal(key, "Domain") == TRUE)
                return provider->domain;
 
-       return g_hash_table_lookup(provider->setting_strings, key);
+       setting = g_hash_table_lookup(provider->setting_strings, key);
+       if (setting == NULL)
+               return NULL;
+
+       return setting->value;
 }
 
 connman_bool_t __vpn_provider_check_routes(struct vpn_provider *provider)
@@ -2057,8 +2456,7 @@ int vpn_provider_append_route(struct vpn_provider *provider,
        if (handle_routes == FALSE) {
                if (route->netmask != NULL && route->gateway != NULL &&
                                                        route->network != NULL)
-                       provider_schedule_changed(provider,
-                                               SERVER_ROUTES_CHANGED);
+                       provider_schedule_changed(provider);
        }
 
        return 0;
@@ -2104,44 +2502,141 @@ int vpn_provider_driver_register(struct vpn_provider_driver *driver)
 
 void vpn_provider_driver_unregister(struct vpn_provider_driver *driver)
 {
+       GHashTableIter iter;
+       gpointer value, key;
+
        DBG("driver %p name %s", driver, driver->name);
 
        driver_list = g_slist_remove(driver_list, driver);
+
+       g_hash_table_iter_init(&iter, provider_hash);
+       while (g_hash_table_iter_next(&iter, &key, &value) == TRUE) {
+               struct vpn_provider *provider = value;
+
+               if (provider != NULL && provider->driver != NULL &&
+                               provider->driver->type == driver->type &&
+                               g_strcmp0(provider->driver->name,
+                                                       driver->name) == 0) {
+                       provider->driver = NULL;
+               }
+       }
 }
 
-static gboolean check_vpn_count(gpointer data)
+const char *vpn_provider_get_name(struct vpn_provider *provider)
 {
-       if (configuration_count == 0) {
-               connman_info("No VPN configurations found, quitting.");
-               raise(SIGTERM);
-       }
+       return provider->name;
+}
 
-       return FALSE;
+const char *vpn_provider_get_host(struct vpn_provider *provider)
+{
+       return provider->host;
 }
 
-void __vpn_provider_check_connections(void)
+const char *vpn_provider_get_path(struct vpn_provider *provider)
 {
-       /*
-        * If we were started when there is no providers configured,
-        * then just quit. This happens when connman starts and its
-        * vpn plugin asks connman-vpnd if it has any connections
-        * configured. If there are none, then we can stop the vpn
-        * daemon.
-        */
-       g_timeout_add(1000, check_vpn_count, NULL);
+       return provider->path;
+}
+
+static int agent_probe(struct connman_agent *agent)
+{
+       DBG("agent %p", agent);
+       return 0;
+}
+
+static void agent_remove(struct connman_agent *agent)
+{
+       DBG("agent %p", agent);
+}
+
+static struct connman_agent_driver agent_driver = {
+       .name           = "vpn",
+       .interface      = VPN_AGENT_INTERFACE,
+       .probe          = agent_probe,
+       .remove         = agent_remove,
+};
+
+static void remove_unprovisioned_providers()
+{
+       gchar **providers;
+       GKeyFile *keyfile, *configkeyfile;
+       char *file, *section;
+       int i = 0;
+
+       providers = __connman_storage_get_providers();
+       if (providers == NULL)
+               return;
+
+       for (; providers[i] != NULL; i++) {
+               char *group = providers[i] + sizeof("provider_") - 1;
+               file = section = NULL;
+               keyfile = configkeyfile = NULL;
+
+               keyfile = __connman_storage_load_provider(group);
+               if (keyfile == NULL)
+                       continue;
+
+               file = g_key_file_get_string(keyfile, group,
+                                       "Config.file", NULL);
+               if (file == NULL)
+                       goto next;
+
+               section = g_key_file_get_string(keyfile, group,
+                                       "Config.ident", NULL);
+               if (section == NULL)
+                       goto next;
+
+               configkeyfile = __connman_storage_load_provider_config(file);
+               if (configkeyfile == NULL) {
+                       /*
+                        * Config file is missing, remove the provisioned
+                        * service.
+                        */
+                       __connman_storage_remove_provider(group);
+                       goto next;
+               }
+
+               if (g_key_file_has_group(configkeyfile, section) == FALSE)
+                       /*
+                        * Config section is missing, remove the provisioned
+                        * service.
+                        */
+                       __connman_storage_remove_provider(group);
+
+       next:
+               if (keyfile != NULL)
+                       g_key_file_free(keyfile);
+
+               if (configkeyfile != NULL)
+                       g_key_file_free(configkeyfile);
+
+               g_free(section);
+               g_free(file);
+       }
+
+       g_strfreev(providers);
 }
 
 int __vpn_provider_init(gboolean do_routes)
 {
+       int err;
+
        DBG("");
 
        handle_routes = do_routes;
 
+       err = connman_agent_driver_register(&agent_driver);
+       if (err < 0) {
+               connman_error("Cannot register agent driver for %s",
+                                               agent_driver.name);
+               return err;
+       }
+
        connection = connman_dbus_get_connection();
 
+       remove_unprovisioned_providers();
+
        provider_hash = g_hash_table_new_full(g_str_hash, g_str_equal,
                                                NULL, unregister_provider);
-
        return 0;
 }
 
@@ -2154,5 +2649,7 @@ void __vpn_provider_cleanup(void)
        g_hash_table_destroy(provider_hash);
        provider_hash = NULL;
 
+       connman_agent_driver_unregister(&agent_driver);
+
        dbus_connection_unref(connection);
 }