513d9261894c1a59e5c9e566fbaf488e1616675c
[platform/upstream/connman.git] / vpn / vpn-provider.c
1 /*
2  *
3  *  ConnMan VPN daemon
4  *
5  *  Copyright (C) 2012  Intel Corporation. All rights reserved.
6  *
7  *  This program is free software; you can redistribute it and/or modify
8  *  it under the terms of the GNU General Public License version 2 as
9  *  published by the Free Software Foundation.
10  *
11  *  This program is distributed in the hope that it will be useful,
12  *  but WITHOUT ANY WARRANTY; without even the implied warranty of
13  *  MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
14  *  GNU General Public License for more details.
15  *
16  *  You should have received a copy of the GNU General Public License
17  *  along with this program; if not, write to the Free Software
18  *  Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA  02110-1301  USA
19  *
20  */
21
22 #ifdef HAVE_CONFIG_H
23 #include <config.h>
24 #endif
25
26 #include <errno.h>
27 #include <stdio.h>
28 #include <string.h>
29 #include <stdlib.h>
30 #include <gdbus.h>
31 #include <connman/log.h>
32 #include <gweb/gresolv.h>
33 #include <netdb.h>
34
35 #include "../src/connman.h"
36 #include "connman/agent.h"
37 #include "connman/vpn-dbus.h"
38 #include "vpn-provider.h"
39 #include "vpn.h"
40
41 static DBusConnection *connection;
42 static GHashTable *provider_hash;
43 static GSList *driver_list;
44 static int configuration_count;
45 static gboolean handle_routes;
46
47 struct vpn_route {
48         int family;
49         char *network;
50         char *netmask;
51         char *gateway;
52 };
53
54 struct vpn_setting {
55         gboolean hide_value;
56         gboolean immutable;
57         char *value;
58 };
59
60 struct vpn_provider {
61         int refcount;
62         int index;
63         int fd;
64         enum vpn_provider_state state;
65         char *path;
66         char *identifier;
67         char *name;
68         char *type;
69         char *host;
70         char *domain;
71         int family;
72         GHashTable *routes;
73         struct vpn_provider_driver *driver;
74         void *driver_data;
75         GHashTable *setting_strings;
76         GHashTable *user_routes;
77         GSList *user_networks;
78         GResolv *resolv;
79         char **host_ip;
80         struct vpn_ipconfig *ipconfig_ipv4;
81         struct vpn_ipconfig *ipconfig_ipv6;
82         char **nameservers;
83         guint notify_id;
84         char *config_file;
85         char *config_entry;
86         connman_bool_t immutable;
87 };
88
89 static void append_properties(DBusMessageIter *iter,
90                                 struct vpn_provider *provider);
91
92 static void free_route(gpointer data)
93 {
94         struct vpn_route *route = data;
95
96         g_free(route->network);
97         g_free(route->netmask);
98         g_free(route->gateway);
99
100         g_free(route);
101 }
102
103 static void free_setting(gpointer data)
104 {
105         struct vpn_setting *setting = data;
106
107         g_free(setting->value);
108         g_free(setting);
109 }
110
111 static void append_route(DBusMessageIter *iter, void *user_data)
112 {
113         struct vpn_route *route = user_data;
114         DBusMessageIter item;
115         int family = 0;
116
117         connman_dbus_dict_open(iter, &item);
118
119         if (route == NULL)
120                 goto empty_dict;
121
122         if (route->family == AF_INET)
123                 family = 4;
124         else if (route->family == AF_INET6)
125                 family = 6;
126
127         if (family != 0)
128                 connman_dbus_dict_append_basic(&item, "ProtocolFamily",
129                                         DBUS_TYPE_INT32, &family);
130
131         if (route->network != NULL)
132                 connman_dbus_dict_append_basic(&item, "Network",
133                                         DBUS_TYPE_STRING, &route->network);
134
135         if (route->netmask != NULL)
136                 connman_dbus_dict_append_basic(&item, "Netmask",
137                                         DBUS_TYPE_STRING, &route->netmask);
138
139         if (route->gateway != NULL)
140                 connman_dbus_dict_append_basic(&item, "Gateway",
141                                         DBUS_TYPE_STRING, &route->gateway);
142
143 empty_dict:
144         connman_dbus_dict_close(iter, &item);
145 }
146
147 static void append_routes(DBusMessageIter *iter, void *user_data)
148 {
149         GHashTable *routes = user_data;
150         GHashTableIter hash;
151         gpointer value, key;
152
153         if (routes == NULL) {
154                 append_route(iter, NULL);
155                 return;
156         }
157
158         g_hash_table_iter_init(&hash, routes);
159
160         while (g_hash_table_iter_next(&hash, &key, &value) == TRUE) {
161                 DBusMessageIter dict;
162
163                 dbus_message_iter_open_container(iter, DBUS_TYPE_STRUCT, NULL,
164                                                 &dict);
165                 append_route(&dict, value);
166                 dbus_message_iter_close_container(iter, &dict);
167         }
168 }
169
170 static void send_routes(struct vpn_provider *provider, GHashTable *routes,
171                         const char *name)
172 {
173         connman_dbus_property_changed_array(provider->path,
174                                         VPN_CONNECTION_INTERFACE,
175                                         name,
176                                         DBUS_TYPE_DICT_ENTRY,
177                                         append_routes,
178                                         routes);
179 }
180
181 static int provider_routes_changed(struct vpn_provider *provider)
182 {
183         DBG("provider %p", provider);
184
185         send_routes(provider, provider->routes, "ServerRoutes");
186
187         return 0;
188 }
189
190 static GSList *read_route_dict(GSList *routes, DBusMessageIter *dicts)
191 {
192         DBusMessageIter dict, value, entry;
193         const char *network, *netmask, *gateway;
194         struct vpn_route *route;
195         int family, type;
196         const char *key;
197
198         dbus_message_iter_recurse(dicts, &entry);
199
200         network = netmask = gateway = NULL;
201         family = PF_UNSPEC;
202
203         while (dbus_message_iter_get_arg_type(&entry) == DBUS_TYPE_DICT_ENTRY) {
204
205                 dbus_message_iter_recurse(&entry, &dict);
206                 dbus_message_iter_get_basic(&dict, &key);
207
208                 dbus_message_iter_next(&dict);
209                 dbus_message_iter_recurse(&dict, &value);
210
211                 type = dbus_message_iter_get_arg_type(&value);
212
213                 switch (type) {
214                 case DBUS_TYPE_STRING:
215                         if (g_str_equal(key, "ProtocolFamily") == TRUE)
216                                 dbus_message_iter_get_basic(&value, &family);
217                         else if (g_str_equal(key, "Network") == TRUE)
218                                 dbus_message_iter_get_basic(&value, &network);
219                         else if (g_str_equal(key, "Netmask") == TRUE)
220                                 dbus_message_iter_get_basic(&value, &netmask);
221                         else if (g_str_equal(key, "Gateway") == TRUE)
222                                 dbus_message_iter_get_basic(&value, &gateway);
223                         break;
224                 }
225
226                 dbus_message_iter_next(&entry);
227         }
228
229         DBG("family %d network %s netmask %s gateway %s", family,
230                 network, netmask, gateway);
231
232         if (network == NULL || netmask == NULL) {
233                 DBG("Ignoring route as network/netmask is missing");
234                 return routes;
235         }
236
237         route = g_try_new(struct vpn_route, 1);
238         if (route == NULL) {
239                 g_slist_free_full(routes, free_route);
240                 return NULL;
241         }
242
243         if (family == PF_UNSPEC) {
244                 family = connman_inet_check_ipaddress(network);
245                 if (family < 0) {
246                         DBG("Cannot get address family of %s (%d/%s)", network,
247                                 family, gai_strerror(family));
248
249                         g_free(route);
250                         return routes;
251                 }
252         } else {
253                 switch (family) {
254                 case '4':
255                         family = AF_INET;
256                         break;
257                 case '6':
258                         family = AF_INET6;
259                         break;
260                 default:
261                         family = PF_UNSPEC;
262                         break;
263                 }
264         }
265
266         route->family = family;
267         route->network = g_strdup(network);
268         route->netmask = g_strdup(netmask);
269         route->gateway = g_strdup(gateway);
270
271         routes = g_slist_prepend(routes, route);
272         return routes;
273 }
274
275 static GSList *get_user_networks(DBusMessageIter *array)
276 {
277         DBusMessageIter entry;
278         GSList *list = NULL;
279
280         while (dbus_message_iter_get_arg_type(array) == DBUS_TYPE_ARRAY) {
281
282                 dbus_message_iter_recurse(array, &entry);
283
284                 while (dbus_message_iter_get_arg_type(&entry) ==
285                                                         DBUS_TYPE_STRUCT) {
286                         DBusMessageIter dicts;
287
288                         dbus_message_iter_recurse(&entry, &dicts);
289
290                         while (dbus_message_iter_get_arg_type(&dicts) ==
291                                                         DBUS_TYPE_ARRAY) {
292
293                                 list = read_route_dict(list, &dicts);
294                                 dbus_message_iter_next(&dicts);
295                         }
296
297                         dbus_message_iter_next(&entry);
298                 }
299
300                 dbus_message_iter_next(array);
301         }
302
303         return list;
304 }
305
306 static void set_user_networks(struct vpn_provider *provider, GSList *networks)
307 {
308         GSList *list;
309
310         for (list = networks; list != NULL; list = g_slist_next(list)) {
311                 struct vpn_route *route = list->data;
312
313                 if (__vpn_provider_append_user_route(provider,
314                                         route->family, route->network,
315                                         route->netmask, route->gateway) != 0)
316                         break;
317         }
318 }
319
320 static void del_routes(struct vpn_provider *provider)
321 {
322         GHashTableIter hash;
323         gpointer value, key;
324
325         g_hash_table_iter_init(&hash, provider->user_routes);
326         while (handle_routes == TRUE && g_hash_table_iter_next(&hash,
327                                                 &key, &value) == TRUE) {
328                 struct vpn_route *route = value;
329                 if (route->family == AF_INET6) {
330                         unsigned char prefixlen = atoi(route->netmask);
331                         connman_inet_del_ipv6_network_route(provider->index,
332                                                         route->network,
333                                                         prefixlen);
334                 } else
335                         connman_inet_del_host_route(provider->index,
336                                                 route->network);
337         }
338
339         g_hash_table_remove_all(provider->user_routes);
340         g_slist_free_full(provider->user_networks, free_route);
341         provider->user_networks = NULL;
342 }
343
344 static void send_value(const char *path, const char *key, const char *value)
345 {
346         const char *empty = "";
347         const char *str;
348
349         if (value != NULL)
350                 str = value;
351         else
352                 str = empty;
353
354         connman_dbus_property_changed_basic(path,
355                                         VPN_CONNECTION_INTERFACE,
356                                         key,
357                                         DBUS_TYPE_STRING,
358                                         &str);
359 }
360
361 static gboolean provider_send_changed(gpointer data)
362 {
363         struct vpn_provider *provider = data;
364
365         provider_routes_changed(provider);
366
367         provider->notify_id = 0;
368
369         return FALSE;
370 }
371
372 static void provider_schedule_changed(struct vpn_provider *provider)
373 {
374         if (provider->notify_id != 0)
375                 g_source_remove(provider->notify_id);
376
377         provider->notify_id = g_timeout_add(100, provider_send_changed,
378                                                                 provider);
379 }
380
381 static DBusMessage *get_properties(DBusConnection *conn,
382                                         DBusMessage *msg, void *data)
383 {
384         struct vpn_provider *provider = data;
385         DBusMessage *reply;
386         DBusMessageIter array;
387
388         DBG("provider %p", provider);
389
390         reply = dbus_message_new_method_return(msg);
391         if (reply == NULL)
392                 return NULL;
393
394         dbus_message_iter_init_append(reply, &array);
395
396         append_properties(&array, provider);
397
398         return reply;
399 }
400
401 static DBusMessage *set_property(DBusConnection *conn, DBusMessage *msg,
402                                                                 void *data)
403 {
404         struct vpn_provider *provider = data;
405         DBusMessageIter iter, value;
406         const char *name;
407         int type;
408
409         DBG("conn %p", conn);
410
411         if (provider->immutable == TRUE)
412                 return __connman_error_not_supported(msg);
413
414         if (dbus_message_iter_init(msg, &iter) == FALSE)
415                 return __connman_error_invalid_arguments(msg);
416
417         if (dbus_message_iter_get_arg_type(&iter) != DBUS_TYPE_STRING)
418                 return __connman_error_invalid_arguments(msg);
419
420         dbus_message_iter_get_basic(&iter, &name);
421         dbus_message_iter_next(&iter);
422
423         if (dbus_message_iter_get_arg_type(&iter) != DBUS_TYPE_VARIANT)
424                 return __connman_error_invalid_arguments(msg);
425
426         dbus_message_iter_recurse(&iter, &value);
427
428         type = dbus_message_iter_get_arg_type(&value);
429
430         if (g_str_equal(name, "UserRoutes") == TRUE) {
431                 GSList *networks;
432
433                 if (type != DBUS_TYPE_ARRAY)
434                         return __connman_error_invalid_arguments(msg);
435
436                 networks = get_user_networks(&value);
437                 if (networks != NULL) {
438                         del_routes(provider);
439                         provider->user_networks = networks;
440                         set_user_networks(provider, provider->user_networks);
441
442                         if (handle_routes == FALSE)
443                                 send_routes(provider, provider->user_routes,
444                                                                 "UserRoutes");
445                 }
446         } else {
447                 const char *str;
448
449                 dbus_message_iter_get_basic(&value, &str);
450                 vpn_provider_set_string(provider, name, str);
451         }
452
453         return g_dbus_create_reply(msg, DBUS_TYPE_INVALID);
454 }
455
456 static DBusMessage *clear_property(DBusConnection *conn, DBusMessage *msg,
457                                                                 void *data)
458 {
459         struct vpn_provider *provider = data;
460         const char *name;
461
462         DBG("conn %p", conn);
463
464         if (provider->immutable == TRUE)
465                 return __connman_error_not_supported(msg);
466
467         dbus_message_get_args(msg, NULL, DBUS_TYPE_STRING, &name,
468                                                         DBUS_TYPE_INVALID);
469
470         if (g_str_equal(name, "UserRoutes") == TRUE) {
471                 del_routes(provider);
472
473                 if (handle_routes == FALSE)
474                         send_routes(provider, provider->user_routes, name);
475         } else if (vpn_provider_get_string(provider, name) != NULL) {
476                 vpn_provider_set_string(provider, name, NULL);
477         } else {
478                 return __connman_error_invalid_property(msg);
479         }
480
481         return g_dbus_create_reply(msg, DBUS_TYPE_INVALID);
482 }
483
484 static DBusMessage *do_connect(DBusConnection *conn, DBusMessage *msg,
485                                                                 void *data)
486 {
487         struct vpn_provider *provider = data;
488         int err;
489
490         DBG("conn %p provider %p", conn, provider);
491
492         err = __vpn_provider_connect(provider, msg);
493         if (err < 0)
494                 return __connman_error_failed(msg, -err);
495
496         return NULL;
497 }
498
499 static DBusMessage *do_disconnect(DBusConnection *conn, DBusMessage *msg,
500                                                                 void *data)
501 {
502         struct vpn_provider *provider = data;
503         int err;
504
505         DBG("conn %p provider %p", conn, provider);
506
507         err = __vpn_provider_disconnect(provider);
508         if (err < 0 && err != -EINPROGRESS)
509                 return __connman_error_failed(msg, -err);
510
511         return g_dbus_create_reply(msg, DBUS_TYPE_INVALID);
512 }
513
514 static const GDBusMethodTable connection_methods[] = {
515         { GDBUS_METHOD("GetProperties",
516                         NULL, GDBUS_ARGS({ "properties", "a{sv}" }),
517                         get_properties) },
518         { GDBUS_METHOD("SetProperty",
519                         GDBUS_ARGS({ "name", "s" }, { "value", "v" }),
520                         NULL, set_property) },
521         { GDBUS_METHOD("ClearProperty",
522                         GDBUS_ARGS({ "name", "s" }), NULL,
523                         clear_property) },
524         { GDBUS_ASYNC_METHOD("Connect", NULL, NULL, do_connect) },
525         { GDBUS_METHOD("Disconnect", NULL, NULL, do_disconnect) },
526         { },
527 };
528
529 static const GDBusSignalTable connection_signals[] = {
530         { GDBUS_SIGNAL("PropertyChanged",
531                         GDBUS_ARGS({ "name", "s" }, { "value", "v" })) },
532         { },
533 };
534
535 static void resolv_result(GResolvResultStatus status,
536                                         char **results, gpointer user_data)
537 {
538         struct vpn_provider *provider = user_data;
539
540         DBG("status %d", status);
541
542         if (status == G_RESOLV_RESULT_STATUS_SUCCESS && results != NULL &&
543                                                 g_strv_length(results) > 0)
544                 provider->host_ip = g_strdupv(results);
545
546         vpn_provider_unref(provider);
547 }
548
549 static void provider_resolv_host_addr(struct vpn_provider *provider)
550 {
551         if (provider->host == NULL)
552                 return;
553
554         if (connman_inet_check_ipaddress(provider->host) > 0)
555                 return;
556
557         if (provider->host_ip != NULL)
558                 return;
559
560         /*
561          * If the hostname is not numeric, try to resolv it. We do not wait
562          * the result as it might take some time. We will get the result
563          * before VPN will feed routes to us because VPN client will need
564          * the IP address also before VPN connection can be established.
565          */
566         provider->resolv = g_resolv_new(0);
567         if (provider->resolv == NULL) {
568                 DBG("Cannot resolv %s", provider->host);
569                 return;
570         }
571
572         DBG("Trying to resolv %s", provider->host);
573
574         vpn_provider_ref(provider);
575
576         g_resolv_lookup_hostname(provider->resolv, provider->host,
577                                 resolv_result, provider);
578 }
579
580 void __vpn_provider_append_properties(struct vpn_provider *provider,
581                                                         DBusMessageIter *iter)
582 {
583         if (provider->host != NULL)
584                 connman_dbus_dict_append_basic(iter, "Host",
585                                         DBUS_TYPE_STRING, &provider->host);
586
587         if (provider->domain != NULL)
588                 connman_dbus_dict_append_basic(iter, "Domain",
589                                         DBUS_TYPE_STRING, &provider->domain);
590
591         if (provider->type != NULL)
592                 connman_dbus_dict_append_basic(iter, "Type", DBUS_TYPE_STRING,
593                                                  &provider->type);
594 }
595
596 int __vpn_provider_append_user_route(struct vpn_provider *provider,
597                                 int family, const char *network,
598                                 const char *netmask, const char *gateway)
599 {
600         struct vpn_route *route;
601         char *key = g_strdup_printf("%d/%s/%s/%s", family, network,
602                                 netmask, gateway != NULL ? gateway : "");
603
604         DBG("family %d network %s netmask %s gw %s", family, network,
605                                                         netmask, gateway);
606
607         route = g_hash_table_lookup(provider->user_routes, key);
608         if (route == NULL) {
609                 route = g_try_new0(struct vpn_route, 1);
610                 if (route == NULL) {
611                         connman_error("out of memory");
612                         return -ENOMEM;
613                 }
614
615                 route->family = family;
616                 route->network = g_strdup(network);
617                 route->netmask = g_strdup(netmask);
618                 route->gateway = g_strdup(gateway);
619
620                 g_hash_table_replace(provider->user_routes, key, route);
621         } else
622                 g_free(key);
623
624         return 0;
625 }
626
627 static struct vpn_route *get_route(char *route_str)
628 {
629         char **elems = g_strsplit(route_str, "/", 0);
630         char *network, *netmask, *gateway, *family_str;
631         int family = PF_UNSPEC;
632         struct vpn_route *route = NULL;
633
634         if (elems == NULL)
635                 return NULL;
636
637         family_str = elems[0];
638
639         network = elems[1];
640         if (network == NULL || network[0] == '\0')
641                 goto out;
642
643         netmask = elems[2];
644         if (netmask == NULL || netmask[0] == '\0')
645                 goto out;
646
647         gateway = elems[3];
648
649         route = g_try_new0(struct vpn_route, 1);
650         if (route == NULL)
651                 goto out;
652
653         if (family_str[0] == '\0' || atoi(family_str) == 0) {
654                 family = PF_UNSPEC;
655         } else {
656                 switch (family_str[0]) {
657                 case '4':
658                         family = AF_INET;
659                         break;
660                 case '6':
661                         family = AF_INET6;
662                         break;
663                 }
664         }
665
666         if (g_strrstr(network, ":") != NULL) {
667                 if (family != PF_UNSPEC && family != AF_INET6)
668                         DBG("You have IPv6 address but you have non IPv6 route");
669         } else if (g_strrstr(network, ".") != NULL) {
670                 if (family != PF_UNSPEC && family != AF_INET)
671                         DBG("You have IPv4 address but you have non IPv4 route");
672
673                 if (g_strrstr(netmask, ".") == NULL) {
674                         /* We have netmask length */
675                         in_addr_t addr;
676                         struct in_addr netmask_in;
677                         unsigned char prefix_len = 32;
678
679                         if (netmask != NULL) {
680                                 char *ptr;
681                                 long int value = strtol(netmask, &ptr, 10);
682                                 if (ptr != netmask && *ptr == '\0' &&
683                                                                 value <= 32)
684                                         prefix_len = value;
685                         }
686
687                         addr = 0xffffffff << (32 - prefix_len);
688                         netmask_in.s_addr = htonl(addr);
689                         netmask = inet_ntoa(netmask_in);
690
691                         DBG("network %s netmask %s", network, netmask);
692                 }
693         }
694
695         if (family == PF_UNSPEC) {
696                 family = connman_inet_check_ipaddress(network);
697                 if (family < 0 || family == PF_UNSPEC)
698                         goto out;
699         }
700
701         route->family = family;
702         route->network = g_strdup(network);
703         route->netmask = g_strdup(netmask);
704         route->gateway = g_strdup(gateway);
705
706 out:
707         g_strfreev(elems);
708         return route;
709 }
710
711 static GSList *get_routes(gchar **networks)
712 {
713         struct vpn_route *route;
714         GSList *routes = NULL;
715         int i;
716
717         for (i = 0; networks[i] != NULL; i++) {
718                 route = get_route(networks[i]);
719                 if (route != NULL)
720                         routes = g_slist_prepend(routes, route);
721         }
722
723         return routes;
724 }
725
726 static int provider_load_from_keyfile(struct vpn_provider *provider,
727                 GKeyFile *keyfile)
728 {
729         gsize idx = 0;
730         gchar **settings;
731         gchar *key, *value;
732         gsize length, num_user_networks;
733         gchar **networks = NULL;
734
735         settings = g_key_file_get_keys(keyfile, provider->identifier, &length,
736                                 NULL);
737         if (settings == NULL) {
738                 g_key_file_free(keyfile);
739                 return -ENOENT;
740         }
741
742         while (idx < length) {
743                 key = settings[idx];
744                 if (key != NULL) {
745                         if (g_str_equal(key, "Networks") == TRUE) {
746                                 networks = g_key_file_get_string_list(keyfile,
747                                                 provider->identifier,
748                                                 key,
749                                                 &num_user_networks,
750                                                 NULL);
751                                 provider->user_networks = get_routes(networks);
752
753                         } else {
754                                 value = g_key_file_get_string(keyfile,
755                                                         provider->identifier,
756                                                         key, NULL);
757                                 vpn_provider_set_string(provider, key,
758                                                         value);
759                                 g_free(value);
760                         }
761                 }
762                 idx += 1;
763         }
764         g_strfreev(settings);
765         g_strfreev(networks);
766
767         if (provider->user_networks != NULL)
768                 set_user_networks(provider, provider->user_networks);
769
770         return 0;
771 }
772
773
774 static int vpn_provider_load(struct vpn_provider *provider)
775 {
776         GKeyFile *keyfile;
777
778         DBG("provider %p", provider);
779
780         keyfile = __connman_storage_load_provider(provider->identifier);
781         if (keyfile == NULL)
782                 return -ENOENT;
783
784         provider_load_from_keyfile(provider, keyfile);
785
786         g_key_file_free(keyfile);
787         return 0;
788 }
789
790 static gchar **create_network_list(GSList *networks, gsize *count)
791 {
792         GSList *list;
793         gchar **result = NULL;
794         unsigned int num_elems = 0;
795
796         for (list = networks; list != NULL; list = g_slist_next(list)) {
797                 struct vpn_route *route = list->data;
798                 int family;
799
800                 result = g_try_realloc(result,
801                                 (num_elems + 1) * sizeof(gchar *));
802                 if (result == NULL)
803                         return NULL;
804
805                 switch (route->family) {
806                 case AF_INET:
807                         family = 4;
808                         break;
809                 case AF_INET6:
810                         family = 6;
811                         break;
812                 default:
813                         family = 0;
814                         break;
815                 }
816
817                 result[num_elems] = g_strdup_printf("%d/%s/%s/%s",
818                                 family, route->network, route->netmask,
819                                 route->gateway == NULL ? "" : route->gateway);
820
821                 num_elems++;
822         }
823
824         result = g_try_realloc(result, (num_elems + 1) * sizeof(gchar *));
825         if (result == NULL)
826                 return NULL;
827
828         result[num_elems] = NULL;
829         *count = num_elems;
830         return result;
831 }
832
833 static int vpn_provider_save(struct vpn_provider *provider)
834 {
835         GKeyFile *keyfile;
836
837         DBG("provider %p immutable %s", provider,
838                                         provider->immutable ? "yes" : "no");
839
840         if (provider->immutable == TRUE) {
841                 /*
842                  * Do not save providers that are provisioned via .config
843                  * file.
844                  */
845                 return -EPERM;
846         }
847
848         keyfile = g_key_file_new();
849         if (keyfile == NULL)
850                 return -ENOMEM;
851
852         g_key_file_set_string(keyfile, provider->identifier,
853                         "Name", provider->name);
854         g_key_file_set_string(keyfile, provider->identifier,
855                         "Type", provider->type);
856         g_key_file_set_string(keyfile, provider->identifier,
857                         "Host", provider->host);
858         g_key_file_set_string(keyfile, provider->identifier,
859                         "VPN.Domain", provider->domain);
860         if (provider->user_networks != NULL) {
861                 gchar **networks;
862                 gsize network_count;
863
864                 networks = create_network_list(provider->user_networks,
865                                                         &network_count);
866                 if (networks != NULL) {
867                         g_key_file_set_string_list(keyfile,
868                                                 provider->identifier,
869                                                 "Networks",
870                                                 (const gchar ** const)networks,
871                                                 network_count);
872                         g_strfreev(networks);
873                 }
874         }
875
876         if (provider->config_file != NULL && strlen(provider->config_file) > 0)
877                 g_key_file_set_string(keyfile, provider->identifier,
878                                 "Config.file", provider->config_file);
879
880         if (provider->config_entry != NULL &&
881                                         strlen(provider->config_entry) > 0)
882                 g_key_file_set_string(keyfile, provider->identifier,
883                                 "Config.ident", provider->config_entry);
884
885         if (provider->driver != NULL && provider->driver->save != NULL)
886                 provider->driver->save(provider, keyfile);
887
888         __connman_storage_save_provider(keyfile, provider->identifier);
889         g_key_file_free(keyfile);
890
891         return 0;
892 }
893
894 struct vpn_provider *__vpn_provider_lookup(const char *identifier)
895 {
896         struct vpn_provider *provider = NULL;
897
898         provider = g_hash_table_lookup(provider_hash, identifier);
899
900         return provider;
901 }
902
903 static gboolean match_driver(struct vpn_provider *provider,
904                                 struct vpn_provider_driver *driver)
905 {
906         if (g_strcmp0(driver->name, provider->type) == 0)
907                 return TRUE;
908
909         return FALSE;
910 }
911
912 static int provider_probe(struct vpn_provider *provider)
913 {
914         GSList *list;
915
916         DBG("provider %p driver %p name %s", provider, provider->driver,
917                                                 provider->name);
918
919         if (provider->driver != NULL)
920                 return -EALREADY;
921
922         for (list = driver_list; list; list = list->next) {
923                 struct vpn_provider_driver *driver = list->data;
924
925                 if (match_driver(provider, driver) == FALSE)
926                         continue;
927
928                 DBG("driver %p name %s", driver, driver->name);
929
930                 if (driver->probe != NULL && driver->probe(provider) == 0) {
931                         provider->driver = driver;
932                         break;
933                 }
934         }
935
936         if (provider->driver == NULL)
937                 return -ENODEV;
938
939         return 0;
940 }
941
942 static void provider_remove(struct vpn_provider *provider)
943 {
944         if (provider->driver != NULL) {
945                 provider->driver->remove(provider);
946                 provider->driver = NULL;
947         }
948 }
949
950 static int provider_register(struct vpn_provider *provider)
951 {
952         return provider_probe(provider);
953 }
954
955 static void provider_unregister(struct vpn_provider *provider)
956 {
957         provider_remove(provider);
958 }
959
960 struct vpn_provider *
961 vpn_provider_ref_debug(struct vpn_provider *provider,
962                         const char *file, int line, const char *caller)
963 {
964         DBG("%p ref %d by %s:%d:%s()", provider, provider->refcount + 1,
965                 file, line, caller);
966
967         __sync_fetch_and_add(&provider->refcount, 1);
968
969         return provider;
970 }
971
972 static void provider_destruct(struct vpn_provider *provider)
973 {
974         DBG("provider %p", provider);
975
976         if (provider->notify_id != 0)
977                 g_source_remove(provider->notify_id);
978
979         g_free(provider->name);
980         g_free(provider->type);
981         g_free(provider->host);
982         g_free(provider->domain);
983         g_free(provider->identifier);
984         g_free(provider->path);
985         g_slist_free_full(provider->user_networks, free_route);
986         g_strfreev(provider->nameservers);
987         g_hash_table_destroy(provider->routes);
988         g_hash_table_destroy(provider->user_routes);
989         g_hash_table_destroy(provider->setting_strings);
990         if (provider->resolv != NULL) {
991                 g_resolv_unref(provider->resolv);
992                 provider->resolv = NULL;
993         }
994         __vpn_ipconfig_unref(provider->ipconfig_ipv4);
995         __vpn_ipconfig_unref(provider->ipconfig_ipv6);
996
997         g_strfreev(provider->host_ip);
998         g_free(provider->config_file);
999         g_free(provider->config_entry);
1000         g_free(provider);
1001 }
1002
1003 void vpn_provider_unref_debug(struct vpn_provider *provider,
1004                                 const char *file, int line, const char *caller)
1005 {
1006         DBG("%p ref %d by %s:%d:%s()", provider, provider->refcount - 1,
1007                 file, line, caller);
1008
1009         if (__sync_fetch_and_sub(&provider->refcount, 1) != 1)
1010                 return;
1011
1012         provider_remove(provider);
1013
1014         provider_destruct(provider);
1015 }
1016
1017 static void configuration_count_add(void)
1018 {
1019         DBG("count %d", configuration_count + 1);
1020
1021         __sync_fetch_and_add(&configuration_count, 1);
1022 }
1023
1024 static void configuration_count_del(void)
1025 {
1026         DBG("count %d", configuration_count - 1);
1027
1028         if (__sync_fetch_and_sub(&configuration_count, 1) != 1)
1029                 return;
1030 }
1031
1032 int __vpn_provider_disconnect(struct vpn_provider *provider)
1033 {
1034         int err;
1035
1036         DBG("provider %p", provider);
1037
1038         if (provider->driver != NULL && provider->driver->disconnect != NULL)
1039                 err = provider->driver->disconnect(provider);
1040         else
1041                 return -EOPNOTSUPP;
1042
1043         if (err == -EINPROGRESS)
1044                 vpn_provider_set_state(provider, VPN_PROVIDER_STATE_CONNECT);
1045
1046         return err;
1047 }
1048
1049 static void connect_cb(struct vpn_provider *provider, void *user_data,
1050                                                                 int error)
1051 {
1052         DBusMessage *pending = user_data;
1053
1054         DBG("provider %p user %p error %d", provider, user_data, error);
1055
1056         if (error != 0) {
1057                 DBusMessage *reply = __connman_error_failed(pending, error);
1058                 if (reply != NULL)
1059                         g_dbus_send_message(connection, reply);
1060
1061                 vpn_provider_indicate_error(provider,
1062                                         VPN_PROVIDER_ERROR_CONNECT_FAILED);
1063                 vpn_provider_set_state(provider, VPN_PROVIDER_STATE_FAILURE);
1064         } else
1065                 g_dbus_send_reply(connection, pending, DBUS_TYPE_INVALID);
1066
1067         dbus_message_unref(pending);
1068 }
1069
1070 int __vpn_provider_connect(struct vpn_provider *provider, DBusMessage *msg)
1071 {
1072         int err;
1073
1074         DBG("provider %p", provider);
1075
1076         if (provider->driver != NULL && provider->driver->connect != NULL) {
1077                 dbus_message_ref(msg);
1078                 err = provider->driver->connect(provider, connect_cb, msg);
1079         } else
1080                 return -EOPNOTSUPP;
1081
1082         if (err == -EINPROGRESS)
1083                 vpn_provider_set_state(provider, VPN_PROVIDER_STATE_CONNECT);
1084
1085         return err;
1086 }
1087
1088 static void connection_removed_signal(struct vpn_provider *provider)
1089 {
1090         DBusMessage *signal;
1091         DBusMessageIter iter;
1092
1093         signal = dbus_message_new_signal(VPN_MANAGER_PATH,
1094                         VPN_MANAGER_INTERFACE, "ConnectionRemoved");
1095         if (signal == NULL)
1096                 return;
1097
1098         dbus_message_iter_init_append(signal, &iter);
1099         dbus_message_iter_append_basic(&iter, DBUS_TYPE_OBJECT_PATH,
1100                                                         &provider->path);
1101         dbus_connection_send(connection, signal, NULL);
1102         dbus_message_unref(signal);
1103 }
1104
1105 static char *get_ident(const char *path)
1106 {
1107         char *pos;
1108
1109         if (*path != '/')
1110                 return NULL;
1111
1112         pos = strrchr(path, '/');
1113         if (pos == NULL)
1114                 return NULL;
1115
1116         return pos + 1;
1117 }
1118
1119 int __vpn_provider_remove(const char *path)
1120 {
1121         struct vpn_provider *provider;
1122         char *ident;
1123
1124         DBG("path %s", path);
1125
1126         ident = get_ident(path);
1127
1128         provider = __vpn_provider_lookup(ident);
1129         if (provider != NULL)
1130                 return __vpn_provider_delete(provider);
1131
1132         return -ENXIO;
1133 }
1134
1135 int __vpn_provider_delete(struct vpn_provider *provider)
1136 {
1137         DBG("Deleting VPN %s", provider->identifier);
1138
1139         connection_removed_signal(provider);
1140
1141         provider_unregister(provider);
1142
1143         __connman_storage_remove_provider(provider->identifier);
1144
1145         g_hash_table_remove(provider_hash, provider->identifier);
1146
1147         return 0;
1148 }
1149
1150 static void append_ipv4(DBusMessageIter *iter, void *user_data)
1151 {
1152         struct vpn_provider *provider = user_data;
1153         const char *address, *gateway, *peer;
1154
1155         address = __vpn_ipconfig_get_local(provider->ipconfig_ipv4);
1156         if (address != NULL) {
1157                 in_addr_t addr;
1158                 struct in_addr netmask;
1159                 char *mask;
1160                 int prefixlen;
1161
1162                 prefixlen = __vpn_ipconfig_get_prefixlen(
1163                                                 provider->ipconfig_ipv4);
1164
1165                 addr = 0xffffffff << (32 - prefixlen);
1166                 netmask.s_addr = htonl(addr);
1167                 mask = inet_ntoa(netmask);
1168
1169                 connman_dbus_dict_append_basic(iter, "Address",
1170                                                 DBUS_TYPE_STRING, &address);
1171
1172                 connman_dbus_dict_append_basic(iter, "Netmask",
1173                                                 DBUS_TYPE_STRING, &mask);
1174         }
1175
1176         gateway = __vpn_ipconfig_get_gateway(provider->ipconfig_ipv4);
1177         if (gateway != NULL)
1178                 connman_dbus_dict_append_basic(iter, "Gateway",
1179                                                 DBUS_TYPE_STRING, &gateway);
1180
1181         peer = __vpn_ipconfig_get_peer(provider->ipconfig_ipv4);
1182         if (peer != NULL)
1183                 connman_dbus_dict_append_basic(iter, "Peer",
1184                                                 DBUS_TYPE_STRING, &peer);
1185 }
1186
1187 static void append_ipv6(DBusMessageIter *iter, void *user_data)
1188 {
1189         struct vpn_provider *provider = user_data;
1190         const char *address, *gateway, *peer;
1191
1192         address = __vpn_ipconfig_get_local(provider->ipconfig_ipv6);
1193         if (address != NULL) {
1194                 unsigned char prefixlen;
1195
1196                 connman_dbus_dict_append_basic(iter, "Address",
1197                                                 DBUS_TYPE_STRING, &address);
1198
1199                 prefixlen = __vpn_ipconfig_get_prefixlen(
1200                                                 provider->ipconfig_ipv6);
1201
1202                 connman_dbus_dict_append_basic(iter, "PrefixLength",
1203                                                 DBUS_TYPE_BYTE, &prefixlen);
1204         }
1205
1206         gateway = __vpn_ipconfig_get_gateway(provider->ipconfig_ipv6);
1207         if (gateway != NULL)
1208                 connman_dbus_dict_append_basic(iter, "Gateway",
1209                                                 DBUS_TYPE_STRING, &gateway);
1210
1211         peer = __vpn_ipconfig_get_peer(provider->ipconfig_ipv6);
1212         if (peer != NULL)
1213                 connman_dbus_dict_append_basic(iter, "Peer",
1214                                                 DBUS_TYPE_STRING, &peer);
1215 }
1216
1217 static const char *state2string(enum vpn_provider_state state)
1218 {
1219         switch (state) {
1220         case VPN_PROVIDER_STATE_UNKNOWN:
1221                 break;
1222         case VPN_PROVIDER_STATE_IDLE:
1223                 return "idle";
1224         case VPN_PROVIDER_STATE_CONNECT:
1225                 return "configuration";
1226         case VPN_PROVIDER_STATE_READY:
1227                 return "ready";
1228         case VPN_PROVIDER_STATE_DISCONNECT:
1229                 return "disconnect";
1230         case VPN_PROVIDER_STATE_FAILURE:
1231                 return "failure";
1232         }
1233
1234         return NULL;
1235 }
1236
1237 static void append_nameservers(DBusMessageIter *iter, char **servers)
1238 {
1239         int i;
1240
1241         DBG("%p", servers);
1242
1243         for (i = 0; servers[i] != NULL; i++) {
1244                 DBG("servers[%d] %s", i, servers[i]);
1245                 dbus_message_iter_append_basic(iter,
1246                                         DBUS_TYPE_STRING, &servers[i]);
1247         }
1248 }
1249
1250 static void append_dns(DBusMessageIter *iter, void *user_data)
1251 {
1252         struct vpn_provider *provider = user_data;
1253
1254         if (provider->nameservers != NULL)
1255                 append_nameservers(iter, provider->nameservers);
1256 }
1257
1258 static int provider_indicate_state(struct vpn_provider *provider,
1259                                 enum vpn_provider_state state)
1260 {
1261         const char *str;
1262         enum vpn_provider_state old_state;
1263
1264         str = state2string(state);
1265         DBG("provider %p state %s/%d", provider, str, state);
1266         if (str == NULL)
1267                 return -EINVAL;
1268
1269         old_state = provider->state;
1270         provider->state = state;
1271
1272         if (state == VPN_PROVIDER_STATE_READY) {
1273                 connman_dbus_property_changed_basic(provider->path,
1274                                         VPN_CONNECTION_INTERFACE, "Index",
1275                                         DBUS_TYPE_INT32, &provider->index);
1276
1277                 if (provider->family == AF_INET)
1278                         connman_dbus_property_changed_dict(provider->path,
1279                                         VPN_CONNECTION_INTERFACE, "IPv4",
1280                                         append_ipv4, provider);
1281                 else if (provider->family == AF_INET6)
1282                         connman_dbus_property_changed_dict(provider->path,
1283                                         VPN_CONNECTION_INTERFACE, "IPv6",
1284                                         append_ipv6, provider);
1285
1286                 connman_dbus_property_changed_array(provider->path,
1287                                                 VPN_CONNECTION_INTERFACE,
1288                                                 "Nameservers",
1289                                                 DBUS_TYPE_STRING,
1290                                                 append_dns, provider);
1291
1292                 if (provider->domain != NULL)
1293                         connman_dbus_property_changed_basic(provider->path,
1294                                                 VPN_CONNECTION_INTERFACE,
1295                                                 "Domain",
1296                                                 DBUS_TYPE_STRING,
1297                                                 &provider->domain);
1298         }
1299
1300         if (old_state != state)
1301                 connman_dbus_property_changed_basic(provider->path,
1302                                         VPN_CONNECTION_INTERFACE, "State",
1303                                         DBUS_TYPE_STRING, &str);
1304
1305         /*
1306          * We do not stay in failure state as clients like connmand can
1307          * get confused about our current state.
1308          */
1309         if (provider->state == VPN_PROVIDER_STATE_FAILURE)
1310                 provider->state = VPN_PROVIDER_STATE_IDLE;
1311
1312         return 0;
1313 }
1314
1315 static void append_state(DBusMessageIter *iter,
1316                                         struct vpn_provider *provider)
1317 {
1318         char *str;
1319
1320         switch (provider->state) {
1321         case VPN_PROVIDER_STATE_UNKNOWN:
1322         case VPN_PROVIDER_STATE_IDLE:
1323                 str = "idle";
1324                 break;
1325         case VPN_PROVIDER_STATE_CONNECT:
1326                 str = "configuration";
1327                 break;
1328         case VPN_PROVIDER_STATE_READY:
1329                 str = "ready";
1330                 break;
1331         case VPN_PROVIDER_STATE_DISCONNECT:
1332                 str = "disconnect";
1333                 break;
1334         case VPN_PROVIDER_STATE_FAILURE:
1335                 str = "failure";
1336                 break;
1337         }
1338
1339         connman_dbus_dict_append_basic(iter, "State",
1340                                 DBUS_TYPE_STRING, &str);
1341 }
1342
1343 static void append_properties(DBusMessageIter *iter,
1344                                         struct vpn_provider *provider)
1345 {
1346         DBusMessageIter dict;
1347         GHashTableIter hash;
1348         gpointer value, key;
1349
1350         connman_dbus_dict_open(iter, &dict);
1351
1352         append_state(&dict, provider);
1353
1354         if (provider->type != NULL)
1355                 connman_dbus_dict_append_basic(&dict, "Type",
1356                                         DBUS_TYPE_STRING, &provider->type);
1357
1358         if (provider->name != NULL)
1359                 connman_dbus_dict_append_basic(&dict, "Name",
1360                                         DBUS_TYPE_STRING, &provider->name);
1361
1362         if (provider->host != NULL)
1363                 connman_dbus_dict_append_basic(&dict, "Host",
1364                                         DBUS_TYPE_STRING, &provider->host);
1365         if (provider->index >= 0)
1366                 connman_dbus_dict_append_basic(&dict, "Index",
1367                                         DBUS_TYPE_INT32, &provider->index);
1368         if (provider->domain != NULL)
1369                 connman_dbus_dict_append_basic(&dict, "Domain",
1370                                         DBUS_TYPE_STRING, &provider->domain);
1371
1372         connman_dbus_dict_append_basic(&dict, "Immutable", DBUS_TYPE_BOOLEAN,
1373                                         &provider->immutable);
1374
1375         if (provider->family == AF_INET)
1376                 connman_dbus_dict_append_dict(&dict, "IPv4", append_ipv4,
1377                                                 provider);
1378         else if (provider->family == AF_INET6)
1379                 connman_dbus_dict_append_dict(&dict, "IPv6", append_ipv6,
1380                                                 provider);
1381
1382         connman_dbus_dict_append_array(&dict, "Nameservers",
1383                                 DBUS_TYPE_STRING, append_dns, provider);
1384
1385         connman_dbus_dict_append_array(&dict, "UserRoutes",
1386                                 DBUS_TYPE_DICT_ENTRY, append_routes,
1387                                 provider->user_routes);
1388
1389         connman_dbus_dict_append_array(&dict, "ServerRoutes",
1390                                 DBUS_TYPE_DICT_ENTRY, append_routes,
1391                                 provider->routes);
1392
1393         if (provider->setting_strings != NULL) {
1394                 g_hash_table_iter_init(&hash, provider->setting_strings);
1395
1396                 while (g_hash_table_iter_next(&hash, &key, &value) == TRUE) {
1397                         struct vpn_setting *setting = value;
1398
1399                         if (setting->hide_value == FALSE &&
1400                                                         setting->value != NULL)
1401                                 connman_dbus_dict_append_basic(&dict, key,
1402                                                         DBUS_TYPE_STRING,
1403                                                         &setting->value);
1404                 }
1405         }
1406
1407         connman_dbus_dict_close(iter, &dict);
1408 }
1409
1410 static void connection_added_signal(struct vpn_provider *provider)
1411 {
1412         DBusMessage *signal;
1413         DBusMessageIter iter;
1414
1415         signal = dbus_message_new_signal(VPN_MANAGER_PATH,
1416                         VPN_MANAGER_INTERFACE, "ConnectionAdded");
1417         if (signal == NULL)
1418                 return;
1419
1420         dbus_message_iter_init_append(signal, &iter);
1421         dbus_message_iter_append_basic(&iter, DBUS_TYPE_OBJECT_PATH,
1422                                                         &provider->path);
1423         append_properties(&iter, provider);
1424
1425         dbus_connection_send(connection, signal, NULL);
1426         dbus_message_unref(signal);
1427 }
1428
1429 static connman_bool_t check_host(char **hosts, char *host)
1430 {
1431         int i;
1432
1433         if (hosts == NULL)
1434                 return FALSE;
1435
1436         for (i = 0; hosts[i] != NULL; i++) {
1437                 if (g_strcmp0(hosts[i], host) == 0)
1438                         return TRUE;
1439         }
1440
1441         return FALSE;
1442 }
1443
1444 static void provider_append_routes(gpointer key, gpointer value,
1445                                         gpointer user_data)
1446 {
1447         struct vpn_route *route = value;
1448         struct vpn_provider *provider = user_data;
1449         int index = provider->index;
1450
1451         if (handle_routes == FALSE)
1452                 return;
1453
1454         /*
1455          * If the VPN administrator/user has given a route to
1456          * VPN server, then we must discard that because the
1457          * server cannot be contacted via VPN tunnel.
1458          */
1459         if (check_host(provider->host_ip, route->network) == TRUE) {
1460                 DBG("Discarding VPN route to %s via %s at index %d",
1461                         route->network, route->gateway, index);
1462                 return;
1463         }
1464
1465         if (route->family == AF_INET6) {
1466                 unsigned char prefix_len = atoi(route->netmask);
1467
1468                 connman_inet_add_ipv6_network_route(index, route->network,
1469                                                         route->gateway,
1470                                                         prefix_len);
1471         } else {
1472                 connman_inet_add_network_route(index, route->network,
1473                                                 route->gateway,
1474                                                 route->netmask);
1475         }
1476 }
1477
1478 static int set_connected(struct vpn_provider *provider,
1479                                         connman_bool_t connected)
1480 {
1481         struct vpn_ipconfig *ipconfig;
1482
1483         DBG("provider %p id %s connected %d", provider,
1484                                         provider->identifier, connected);
1485
1486         if (connected == TRUE) {
1487                 if (provider->family == AF_INET6)
1488                         ipconfig = provider->ipconfig_ipv6;
1489                 else
1490                         ipconfig = provider->ipconfig_ipv4;
1491
1492                 __vpn_ipconfig_address_add(ipconfig, provider->family);
1493
1494                 if (handle_routes == TRUE)
1495                         __vpn_ipconfig_gateway_add(ipconfig, provider->family);
1496
1497                 provider_indicate_state(provider,
1498                                         VPN_PROVIDER_STATE_READY);
1499
1500                 g_hash_table_foreach(provider->routes, provider_append_routes,
1501                                         provider);
1502
1503                 g_hash_table_foreach(provider->user_routes,
1504                                         provider_append_routes, provider);
1505
1506         } else {
1507                 provider_indicate_state(provider,
1508                                         VPN_PROVIDER_STATE_DISCONNECT);
1509
1510                 provider_indicate_state(provider,
1511                                         VPN_PROVIDER_STATE_IDLE);
1512         }
1513
1514         return 0;
1515 }
1516
1517 int vpn_provider_set_state(struct vpn_provider *provider,
1518                                         enum vpn_provider_state state)
1519 {
1520         if (provider == NULL)
1521                 return -EINVAL;
1522
1523         switch (state) {
1524         case VPN_PROVIDER_STATE_UNKNOWN:
1525                 return -EINVAL;
1526         case VPN_PROVIDER_STATE_IDLE:
1527                 return set_connected(provider, FALSE);
1528         case VPN_PROVIDER_STATE_CONNECT:
1529                 return provider_indicate_state(provider, state);
1530         case VPN_PROVIDER_STATE_READY:
1531                 return set_connected(provider, TRUE);
1532         case VPN_PROVIDER_STATE_DISCONNECT:
1533                 return provider_indicate_state(provider, state);
1534         case VPN_PROVIDER_STATE_FAILURE:
1535                 return provider_indicate_state(provider, state);
1536         }
1537         return -EINVAL;
1538 }
1539
1540 int vpn_provider_indicate_error(struct vpn_provider *provider,
1541                                         enum vpn_provider_error error)
1542 {
1543         DBG("provider %p id %s error %d", provider, provider->identifier,
1544                                                                         error);
1545
1546         switch (error) {
1547         case VPN_PROVIDER_ERROR_LOGIN_FAILED:
1548                 break;
1549         case VPN_PROVIDER_ERROR_AUTH_FAILED:
1550                 vpn_provider_set_state(provider, VPN_PROVIDER_STATE_FAILURE);
1551                 break;
1552         case VPN_PROVIDER_ERROR_CONNECT_FAILED:
1553                 break;
1554         default:
1555                 break;
1556         }
1557
1558         return 0;
1559 }
1560
1561 static int connection_unregister(struct vpn_provider *provider)
1562 {
1563         DBG("provider %p path %s", provider, provider->path);
1564
1565         if (provider->path == NULL)
1566                 return -EALREADY;
1567
1568         g_dbus_unregister_interface(connection, provider->path,
1569                                 VPN_CONNECTION_INTERFACE);
1570
1571         g_free(provider->path);
1572         provider->path = NULL;
1573
1574         return 0;
1575 }
1576
1577 static int connection_register(struct vpn_provider *provider)
1578 {
1579         DBG("provider %p path %s", provider, provider->path);
1580
1581         if (provider->path != NULL)
1582                 return -EALREADY;
1583
1584         provider->path = g_strdup_printf("%s/connection/%s", VPN_PATH,
1585                                                 provider->identifier);
1586
1587         g_dbus_register_interface(connection, provider->path,
1588                                 VPN_CONNECTION_INTERFACE,
1589                                 connection_methods, connection_signals,
1590                                 NULL, provider, NULL);
1591
1592         return 0;
1593 }
1594
1595 static void unregister_provider(gpointer data)
1596 {
1597         struct vpn_provider *provider = data;
1598
1599         configuration_count_del();
1600
1601         connection_unregister(provider);
1602
1603         vpn_provider_unref(provider);
1604 }
1605
1606 static void provider_initialize(struct vpn_provider *provider)
1607 {
1608         DBG("provider %p", provider);
1609
1610         provider->index = 0;
1611         provider->fd = -1;
1612         provider->name = NULL;
1613         provider->type = NULL;
1614         provider->domain = NULL;
1615         provider->identifier = NULL;
1616         provider->immutable = FALSE;
1617         provider->user_networks = NULL;
1618         provider->routes = g_hash_table_new_full(g_direct_hash, g_direct_equal,
1619                                         NULL, free_route);
1620         provider->user_routes = g_hash_table_new_full(g_str_hash, g_str_equal,
1621                                         g_free, free_route);
1622         provider->setting_strings = g_hash_table_new_full(g_str_hash,
1623                                         g_str_equal, g_free, free_setting);
1624 }
1625
1626 static struct vpn_provider *vpn_provider_new(void)
1627 {
1628         struct vpn_provider *provider;
1629
1630         provider = g_try_new0(struct vpn_provider, 1);
1631         if (provider == NULL)
1632                 return NULL;
1633
1634         provider->refcount = 1;
1635
1636         DBG("provider %p", provider);
1637         provider_initialize(provider);
1638
1639         return provider;
1640 }
1641
1642 static struct vpn_provider *vpn_provider_get(const char *identifier)
1643 {
1644         struct vpn_provider *provider;
1645
1646         provider = g_hash_table_lookup(provider_hash, identifier);
1647         if (provider != NULL)
1648                 return provider;
1649
1650         provider = vpn_provider_new();
1651         if (provider == NULL)
1652                 return NULL;
1653
1654         DBG("provider %p", provider);
1655
1656         provider->identifier = g_strdup(identifier);
1657
1658         g_hash_table_insert(provider_hash, provider->identifier, provider);
1659
1660         configuration_count_add();
1661
1662         return provider;
1663 }
1664
1665 static void provider_dbus_ident(char *ident)
1666 {
1667         int i, len = strlen(ident);
1668
1669         for (i = 0; i < len; i++) {
1670                 if (ident[i] >= '0' && ident[i] <= '9')
1671                         continue;
1672                 if (ident[i] >= 'a' && ident[i] <= 'z')
1673                         continue;
1674                 if (ident[i] >= 'A' && ident[i] <= 'Z')
1675                         continue;
1676                 ident[i] = '_';
1677         }
1678 }
1679
1680 static struct vpn_provider *provider_create_from_keyfile(GKeyFile *keyfile,
1681                 const char *ident)
1682 {
1683         struct vpn_provider *provider;
1684
1685         if (keyfile == NULL || ident == NULL)
1686                 return NULL;
1687
1688         provider = __vpn_provider_lookup(ident);
1689         if (provider == NULL) {
1690                 provider = vpn_provider_get(ident);
1691                 if (provider == NULL) {
1692                         DBG("can not create provider");
1693                         return NULL;
1694                 }
1695
1696                 provider_load_from_keyfile(provider, keyfile);
1697
1698                 if (provider->name == NULL || provider->host == NULL ||
1699                                 provider->domain == NULL) {
1700                         DBG("cannot get name, host or domain");
1701                         vpn_provider_unref(provider);
1702                         return NULL;
1703                 }
1704
1705                 if (provider_register(provider) == 0)
1706                         connection_register(provider);
1707         }
1708         return provider;
1709 }
1710
1711 static void provider_create_all_from_type(const char *provider_type)
1712 {
1713         unsigned int i;
1714         char **providers;
1715         char *id, *type;
1716         GKeyFile *keyfile;
1717
1718         DBG("provider type %s", provider_type);
1719
1720         providers = __connman_storage_get_providers();
1721
1722         if (providers == NULL)
1723                 return;
1724
1725         for (i = 0; providers[i] != NULL; i+=1) {
1726
1727                 if (strncmp(providers[i], "provider_", 9) != 0)
1728                         continue;
1729
1730                 id = providers[i] + 9;
1731                 keyfile = __connman_storage_load_provider(id);
1732
1733                 if (keyfile == NULL)
1734                         continue;
1735
1736                 type = g_key_file_get_string(keyfile, id, "Type", NULL);
1737
1738                 DBG("keyfile %p id %s type %s", keyfile, id, type);
1739
1740                 if (strcmp(provider_type, type) != 0) {
1741                         g_free(type);
1742                         g_key_file_free(keyfile);
1743                         continue;
1744                 }
1745
1746                 if (provider_create_from_keyfile(keyfile, id) == NULL)
1747                         DBG("could not create provider");
1748
1749                 g_free(type);
1750                 g_key_file_free(keyfile);
1751         }
1752         g_strfreev(providers);
1753 }
1754
1755 char *__vpn_provider_create_identifier(const char *host, const char *domain)
1756 {
1757         char *ident;
1758
1759         ident = g_strdup_printf("%s_%s", host, domain);
1760         if (ident == NULL)
1761                 return NULL;
1762
1763         provider_dbus_ident(ident);
1764
1765         return ident;
1766 }
1767
1768 int __vpn_provider_create(DBusMessage *msg)
1769 {
1770         struct vpn_provider *provider;
1771         DBusMessageIter iter, array;
1772         const char *type = NULL, *name = NULL;
1773         const char *host = NULL, *domain = NULL;
1774         GSList *networks = NULL;
1775         char *ident;
1776         int err;
1777
1778         dbus_message_iter_init(msg, &iter);
1779         dbus_message_iter_recurse(&iter, &array);
1780
1781         while (dbus_message_iter_get_arg_type(&array) == DBUS_TYPE_DICT_ENTRY) {
1782                 DBusMessageIter entry, value;
1783                 const char *key;
1784
1785                 dbus_message_iter_recurse(&array, &entry);
1786                 dbus_message_iter_get_basic(&entry, &key);
1787
1788                 dbus_message_iter_next(&entry);
1789                 dbus_message_iter_recurse(&entry, &value);
1790
1791                 switch (dbus_message_iter_get_arg_type(&value)) {
1792                 case DBUS_TYPE_STRING:
1793                         if (g_str_equal(key, "Type") == TRUE)
1794                                 dbus_message_iter_get_basic(&value, &type);
1795                         else if (g_str_equal(key, "Name") == TRUE)
1796                                 dbus_message_iter_get_basic(&value, &name);
1797                         else if (g_str_equal(key, "Host") == TRUE)
1798                                 dbus_message_iter_get_basic(&value, &host);
1799                         else if (g_str_equal(key, "VPN.Domain") == TRUE ||
1800                                         g_str_equal(key, "Domain") == TRUE)
1801                                 dbus_message_iter_get_basic(&value, &domain);
1802                         break;
1803                 case DBUS_TYPE_ARRAY:
1804                         if (g_str_equal(key, "UserRoutes") == TRUE)
1805                                 networks = get_user_networks(&value);
1806                         break;
1807                 }
1808
1809                 dbus_message_iter_next(&array);
1810         }
1811
1812         if (host == NULL || domain == NULL)
1813                 return -EINVAL;
1814
1815         DBG("Type %s name %s networks %p", type, name, networks);
1816
1817         if (type == NULL || name == NULL)
1818                 return -EOPNOTSUPP;
1819
1820         ident = __vpn_provider_create_identifier(host, domain);
1821         DBG("ident %s", ident);
1822
1823         provider = __vpn_provider_lookup(ident);
1824         if (provider == NULL) {
1825                 provider = vpn_provider_get(ident);
1826                 if (provider == NULL) {
1827                         DBG("can not create provider");
1828                         g_free(ident);
1829                         return -EOPNOTSUPP;
1830                 }
1831
1832                 provider->host = g_strdup(host);
1833                 provider->domain = g_strdup(domain);
1834                 provider->name = g_strdup(name);
1835                 provider->type = g_strdup(type);
1836
1837                 if (provider_register(provider) == 0)
1838                         vpn_provider_load(provider);
1839
1840                 provider_resolv_host_addr(provider);
1841         }
1842
1843         if (networks != NULL) {
1844                 g_slist_free_full(provider->user_networks, free_route);
1845                 provider->user_networks = networks;
1846                 set_user_networks(provider, provider->user_networks);
1847         }
1848
1849         dbus_message_iter_init(msg, &iter);
1850         dbus_message_iter_recurse(&iter, &array);
1851
1852         while (dbus_message_iter_get_arg_type(&array) == DBUS_TYPE_DICT_ENTRY) {
1853                 DBusMessageIter entry, value;
1854                 const char *key, *str;
1855
1856                 dbus_message_iter_recurse(&array, &entry);
1857                 dbus_message_iter_get_basic(&entry, &key);
1858
1859                 dbus_message_iter_next(&entry);
1860                 dbus_message_iter_recurse(&entry, &value);
1861
1862                 switch (dbus_message_iter_get_arg_type(&value)) {
1863                 case DBUS_TYPE_STRING:
1864                         dbus_message_iter_get_basic(&value, &str);
1865                         vpn_provider_set_string(provider, key, str);
1866                         break;
1867                 }
1868
1869                 dbus_message_iter_next(&array);
1870         }
1871
1872         g_free(ident);
1873
1874         vpn_provider_save(provider);
1875
1876         err = provider_register(provider);
1877         if (err != 0 && err != -EALREADY)
1878                 return err;
1879
1880         connection_register(provider);
1881
1882         DBG("provider %p index %d path %s", provider, provider->index,
1883                                                         provider->path);
1884
1885         g_dbus_send_reply(connection, msg,
1886                                 DBUS_TYPE_OBJECT_PATH, &provider->path,
1887                                 DBUS_TYPE_INVALID);
1888
1889         connection_added_signal(provider);
1890
1891         return 0;
1892 }
1893
1894 static const char *get_string(GHashTable *settings, const char *key)
1895 {
1896         DBG("settings %p key %s", settings, key);
1897
1898         return g_hash_table_lookup(settings, key);
1899 }
1900
1901 static GSList *parse_user_networks(const char *network_str)
1902 {
1903         GSList *networks = NULL;
1904         char **elems;
1905         int i = 0;
1906
1907         if (network_str == NULL)
1908                 return NULL;
1909
1910         elems = g_strsplit(network_str, ",", 0);
1911         if (elems == NULL)
1912                 return NULL;
1913
1914         while (elems[i] != NULL) {
1915                 struct vpn_route *vpn_route;
1916                 char *network, *netmask, *gateway;
1917                 int family;
1918                 char **route;
1919
1920                 route = g_strsplit(elems[i], "/", 0);
1921                 if (route == NULL)
1922                         goto next;
1923
1924                 network = route[0];
1925                 if (network == NULL || network[0] == '\0')
1926                         goto next;
1927
1928                 family = connman_inet_check_ipaddress(network);
1929                 if (family < 0) {
1930                         DBG("Cannot get address family of %s (%d/%s)", network,
1931                                 family, gai_strerror(family));
1932
1933                         goto next;
1934                 }
1935
1936                 switch (family) {
1937                 case AF_INET:
1938                         break;
1939                 case AF_INET6:
1940                         break;
1941                 default:
1942                         DBG("Unsupported address family %d", family);
1943                         goto next;
1944                 }
1945
1946                 netmask = route[1];
1947                 if (netmask == NULL || netmask[0] == '\0')
1948                         goto next;
1949
1950                 gateway = route[2];
1951
1952                 vpn_route = g_try_new0(struct vpn_route, 1);
1953                 if (vpn_route == NULL) {
1954                         g_strfreev(route);
1955                         break;
1956                 }
1957
1958                 vpn_route->family = family;
1959                 vpn_route->network = g_strdup(network);
1960                 vpn_route->netmask = g_strdup(netmask);
1961                 vpn_route->gateway = g_strdup(gateway);
1962
1963                 DBG("route %s/%s%s%s", network, netmask,
1964                         gateway ? " via " : "", gateway ? gateway : "");
1965
1966                 networks = g_slist_prepend(networks, vpn_route);
1967
1968         next:
1969                 g_strfreev(route);
1970                 i++;
1971         }
1972
1973         g_strfreev(elems);
1974
1975         return g_slist_reverse(networks);
1976 }
1977
1978 int __vpn_provider_create_from_config(GHashTable *settings,
1979                                 const char *config_ident,
1980                                 const char *config_entry)
1981 {
1982         struct vpn_provider *provider;
1983         const char *type, *name, *host, *domain, *networks_str;
1984         GSList *networks;
1985         char *ident = NULL;
1986         GHashTableIter hash;
1987         gpointer value, key;
1988         int err;
1989
1990         type = get_string(settings, "Type");
1991         name = get_string(settings, "Name");
1992         host = get_string(settings, "Host");
1993         domain = get_string(settings, "Domain");
1994         networks_str = get_string(settings, "Networks");
1995         networks = parse_user_networks(networks_str);
1996
1997         if (host == NULL || domain == NULL) {
1998                 err = -EINVAL;
1999                 goto fail;
2000         }
2001
2002         DBG("type %s name %s networks %s", type, name, networks_str);
2003
2004         if (type == NULL || name == NULL) {
2005                 err = -EOPNOTSUPP;
2006                 goto fail;
2007         }
2008
2009         ident = __vpn_provider_create_identifier(host, domain);
2010         DBG("ident %s", ident);
2011
2012         provider = __vpn_provider_lookup(ident);
2013         if (provider == NULL) {
2014                 provider = vpn_provider_get(ident);
2015                 if (provider == NULL) {
2016                         DBG("can not create provider");
2017                         err = -EOPNOTSUPP;
2018                         goto fail;
2019                 }
2020
2021                 provider->host = g_strdup(host);
2022                 provider->domain = g_strdup(domain);
2023                 provider->name = g_strdup(name);
2024                 provider->type = g_ascii_strdown(type, -1);
2025
2026                 provider->config_file = g_strdup(config_ident);
2027                 provider->config_entry = g_strdup(config_entry);
2028
2029                 provider_register(provider);
2030
2031                 provider_resolv_host_addr(provider);
2032         }
2033
2034         if (networks != NULL) {
2035                 g_slist_free_full(provider->user_networks, free_route);
2036                 provider->user_networks = networks;
2037                 set_user_networks(provider, provider->user_networks);
2038         }
2039
2040         g_hash_table_iter_init(&hash, settings);
2041
2042         while (g_hash_table_iter_next(&hash, &key, &value) == TRUE)
2043                 __vpn_provider_set_string_immutable(provider, key, value);
2044
2045         provider->immutable = TRUE;
2046
2047         vpn_provider_save(provider);
2048
2049         err = provider_register(provider);
2050         if (err != 0 && err != -EALREADY)
2051                 goto fail;
2052
2053         connection_register(provider);
2054
2055         DBG("provider %p index %d path %s", provider, provider->index,
2056                                                         provider->path);
2057
2058         connection_added_signal(provider);
2059
2060         g_free(ident);
2061
2062         return 0;
2063
2064 fail:
2065         g_free(ident);
2066         g_slist_free_full(networks, free_route);
2067
2068         return err;
2069 }
2070
2071 static void append_connection_structs(DBusMessageIter *iter, void *user_data)
2072 {
2073         DBusMessageIter entry;
2074         GHashTableIter hash;
2075         gpointer value, key;
2076
2077         g_hash_table_iter_init(&hash, provider_hash);
2078
2079         while (g_hash_table_iter_next(&hash, &key, &value) == TRUE) {
2080                 struct vpn_provider *provider = value;
2081
2082                 DBG("path %s", provider->path);
2083
2084                 if (provider->identifier == NULL)
2085                         continue;
2086
2087                 dbus_message_iter_open_container(iter, DBUS_TYPE_STRUCT,
2088                                 NULL, &entry);
2089                 dbus_message_iter_append_basic(&entry, DBUS_TYPE_OBJECT_PATH,
2090                                 &provider->path);
2091                 append_properties(&entry, provider);
2092                 dbus_message_iter_close_container(iter, &entry);
2093         }
2094 }
2095
2096 DBusMessage *__vpn_provider_get_connections(DBusMessage *msg)
2097 {
2098         DBusMessage *reply;
2099
2100         DBG("");
2101
2102         reply = dbus_message_new_method_return(msg);
2103         if (reply == NULL)
2104                 return NULL;
2105
2106         __connman_dbus_append_objpath_dict_array(reply,
2107                         append_connection_structs, NULL);
2108
2109         return reply;
2110 }
2111
2112 const char * __vpn_provider_get_ident(struct vpn_provider *provider)
2113 {
2114         if (provider == NULL)
2115                 return NULL;
2116
2117         return provider->identifier;
2118 }
2119
2120 static int set_string(struct vpn_provider *provider,
2121                         const char *key, const char *value,
2122                         gboolean hide_value, gboolean immutable)
2123 {
2124         DBG("provider %p key %s immutable %s value %s", provider, key,
2125                 immutable ? "yes" : "no",
2126                 hide_value ? "<not printed>" : value);
2127
2128         if (g_str_equal(key, "Type") == TRUE) {
2129                 g_free(provider->type);
2130                 provider->type = g_ascii_strdown(value, -1);
2131                 send_value(provider->path, "Type", provider->type);
2132         } else if (g_str_equal(key, "Name") == TRUE) {
2133                 g_free(provider->name);
2134                 provider->name = g_strdup(value);
2135                 send_value(provider->path, "Name", provider->name);
2136         } else if (g_str_equal(key, "Host") == TRUE) {
2137                 g_free(provider->host);
2138                 provider->host = g_strdup(value);
2139                 send_value(provider->path, "Host", provider->host);
2140         } else if (g_str_equal(key, "VPN.Domain") == TRUE ||
2141                         g_str_equal(key, "Domain") == TRUE) {
2142                 g_free(provider->domain);
2143                 provider->domain = g_strdup(value);
2144                 send_value(provider->path, "Domain", provider->domain);
2145         } else {
2146                 struct vpn_setting *setting;
2147
2148                 setting = g_hash_table_lookup(provider->setting_strings, key);
2149                 if (setting != NULL && immutable == FALSE &&
2150                                                 setting->immutable == TRUE) {
2151                         DBG("Trying to set immutable variable %s", key);
2152                         return -EPERM;
2153                 }
2154
2155                 setting = g_try_new0(struct vpn_setting, 1);
2156                 if (setting == NULL)
2157                         return -ENOMEM;
2158
2159                 setting->value = g_strdup(value);
2160                 setting->hide_value = hide_value;
2161
2162                 if (immutable == TRUE)
2163                         setting->immutable = TRUE;
2164
2165                 if (hide_value == FALSE)
2166                         send_value(provider->path, key, setting->value);
2167
2168                 g_hash_table_replace(provider->setting_strings,
2169                                 g_strdup(key), setting);
2170         }
2171
2172         return 0;
2173 }
2174
2175 int vpn_provider_set_string(struct vpn_provider *provider,
2176                                         const char *key, const char *value)
2177 {
2178         return set_string(provider, key, value, FALSE, FALSE);
2179 }
2180
2181 int vpn_provider_set_string_hide_value(struct vpn_provider *provider,
2182                                         const char *key, const char *value)
2183 {
2184         return set_string(provider, key, value, TRUE, FALSE);
2185 }
2186
2187 int __vpn_provider_set_string_immutable(struct vpn_provider *provider,
2188                                         const char *key, const char *value)
2189 {
2190         return set_string(provider, key, value, FALSE, TRUE);
2191 }
2192
2193 const char *vpn_provider_get_string(struct vpn_provider *provider,
2194                                                         const char *key)
2195 {
2196         struct vpn_setting *setting;
2197
2198         DBG("provider %p key %s", provider, key);
2199
2200         if (g_str_equal(key, "Type") == TRUE)
2201                 return provider->type;
2202         else if (g_str_equal(key, "Name") == TRUE)
2203                 return provider->name;
2204         else if (g_str_equal(key, "Host") == TRUE)
2205                 return provider->host;
2206         else if (g_str_equal(key, "HostIP") == TRUE) {
2207                 if (provider->host_ip == NULL ||
2208                                 provider->host_ip[0] == NULL)
2209                         return provider->host;
2210                 else
2211                         return provider->host_ip[0];
2212         } else if (g_str_equal(key, "VPN.Domain") == TRUE ||
2213                         g_str_equal(key, "Domain") == TRUE)
2214                 return provider->domain;
2215
2216         setting = g_hash_table_lookup(provider->setting_strings, key);
2217         if (setting == NULL)
2218                 return NULL;
2219
2220         return setting->value;
2221 }
2222
2223 connman_bool_t __vpn_provider_check_routes(struct vpn_provider *provider)
2224 {
2225         if (provider == NULL)
2226                 return FALSE;
2227
2228         if (provider->user_routes != NULL &&
2229                         g_hash_table_size(provider->user_routes) > 0)
2230                 return TRUE;
2231
2232         if (provider->routes != NULL &&
2233                         g_hash_table_size(provider->routes) > 0)
2234                 return TRUE;
2235
2236         return FALSE;
2237 }
2238
2239 void *vpn_provider_get_data(struct vpn_provider *provider)
2240 {
2241         return provider->driver_data;
2242 }
2243
2244 void vpn_provider_set_data(struct vpn_provider *provider, void *data)
2245 {
2246         provider->driver_data = data;
2247 }
2248
2249 void vpn_provider_set_index(struct vpn_provider *provider, int index)
2250 {
2251         DBG("index %d provider %p", index, provider);
2252
2253         if (provider->ipconfig_ipv4 == NULL) {
2254                 provider->ipconfig_ipv4 = __vpn_ipconfig_create(index,
2255                                                                 AF_INET);
2256                 if (provider->ipconfig_ipv4 == NULL) {
2257                         DBG("Couldnt create ipconfig for IPv4");
2258                         goto done;
2259                 }
2260         }
2261
2262         __vpn_ipconfig_set_index(provider->ipconfig_ipv4, index);
2263
2264         if (provider->ipconfig_ipv6 == NULL) {
2265                 provider->ipconfig_ipv6 = __vpn_ipconfig_create(index,
2266                                                                 AF_INET6);
2267                 if (provider->ipconfig_ipv6 == NULL) {
2268                         DBG("Couldnt create ipconfig for IPv6");
2269                         goto done;
2270                 }
2271         }
2272
2273         __vpn_ipconfig_set_index(provider->ipconfig_ipv6, index);
2274
2275 done:
2276         provider->index = index;
2277 }
2278
2279 int vpn_provider_get_index(struct vpn_provider *provider)
2280 {
2281         return provider->index;
2282 }
2283
2284 int vpn_provider_set_ipaddress(struct vpn_provider *provider,
2285                                         struct connman_ipaddress *ipaddress)
2286 {
2287         struct vpn_ipconfig *ipconfig = NULL;
2288
2289         switch (ipaddress->family) {
2290         case AF_INET:
2291                 ipconfig = provider->ipconfig_ipv4;
2292                 break;
2293         case AF_INET6:
2294                 ipconfig = provider->ipconfig_ipv6;
2295                 break;
2296         default:
2297                 break;
2298         }
2299
2300         DBG("provider %p ipconfig %p family %d", provider, ipconfig,
2301                                                         ipaddress->family);
2302
2303         if (ipconfig == NULL)
2304                 return -EINVAL;
2305
2306         provider->family = ipaddress->family;
2307
2308         __vpn_ipconfig_set_local(ipconfig, ipaddress->local);
2309         __vpn_ipconfig_set_peer(ipconfig, ipaddress->peer);
2310         __vpn_ipconfig_set_broadcast(ipconfig, ipaddress->broadcast);
2311         __vpn_ipconfig_set_gateway(ipconfig, ipaddress->gateway);
2312         __vpn_ipconfig_set_prefixlen(ipconfig, ipaddress->prefixlen);
2313
2314         return 0;
2315 }
2316
2317 int vpn_provider_set_pac(struct vpn_provider *provider,
2318                                 const char *pac)
2319 {
2320         DBG("provider %p pac %s", provider, pac);
2321
2322         return 0;
2323 }
2324
2325
2326 int vpn_provider_set_domain(struct vpn_provider *provider,
2327                                         const char *domain)
2328 {
2329         DBG("provider %p domain %s", provider, domain);
2330
2331         g_free(provider->domain);
2332         provider->domain = g_strdup(domain);
2333
2334         return 0;
2335 }
2336
2337 int vpn_provider_set_nameservers(struct vpn_provider *provider,
2338                                         const char *nameservers)
2339 {
2340         DBG("provider %p nameservers %s", provider, nameservers);
2341
2342         g_strfreev(provider->nameservers);
2343         provider->nameservers = NULL;
2344
2345         if (nameservers == NULL)
2346                 return 0;
2347
2348         provider->nameservers = g_strsplit(nameservers, " ", 0);
2349
2350         return 0;
2351 }
2352
2353 enum provider_route_type {
2354         PROVIDER_ROUTE_TYPE_NONE = 0,
2355         PROVIDER_ROUTE_TYPE_MASK = 1,
2356         PROVIDER_ROUTE_TYPE_ADDR = 2,
2357         PROVIDER_ROUTE_TYPE_GW   = 3,
2358 };
2359
2360 static int route_env_parse(struct vpn_provider *provider, const char *key,
2361                                 int *family, unsigned long *idx,
2362                                 enum provider_route_type *type)
2363 {
2364         char *end;
2365         const char *start;
2366
2367         DBG("name %s", provider->name);
2368
2369         if (!strcmp(provider->type, "openvpn")) {
2370                 if (g_str_has_prefix(key, "route_network_") == TRUE) {
2371                         start = key + strlen("route_network_");
2372                         *type = PROVIDER_ROUTE_TYPE_ADDR;
2373                 } else if (g_str_has_prefix(key, "route_netmask_") == TRUE) {
2374                         start = key + strlen("route_netmask_");
2375                         *type = PROVIDER_ROUTE_TYPE_MASK;
2376                 } else if (g_str_has_prefix(key, "route_gateway_") == TRUE) {
2377                         start = key + strlen("route_gateway_");
2378                         *type = PROVIDER_ROUTE_TYPE_GW;
2379                 } else
2380                         return -EINVAL;
2381
2382                 *family = AF_INET;
2383                 *idx = g_ascii_strtoull(start, &end, 10);
2384
2385         } else if (!strcmp(provider->type, "openconnect")) {
2386                 if (g_str_has_prefix(key, "CISCO_SPLIT_INC_") == TRUE) {
2387                         *family = AF_INET;
2388                         start = key + strlen("CISCO_SPLIT_INC_");
2389                 } else if (g_str_has_prefix(key,
2390                                         "CISCO_IPV6_SPLIT_INC_") == TRUE) {
2391                         *family = AF_INET6;
2392                         start = key + strlen("CISCO_IPV6_SPLIT_INC_");
2393                 } else
2394                         return -EINVAL;
2395
2396                 *idx = g_ascii_strtoull(start, &end, 10);
2397
2398                 if (strncmp(end, "_ADDR", 5) == 0)
2399                         *type = PROVIDER_ROUTE_TYPE_ADDR;
2400                 else if (strncmp(end, "_MASK", 5) == 0)
2401                         *type = PROVIDER_ROUTE_TYPE_MASK;
2402                 else if (strncmp(end, "_MASKLEN", 8) == 0 &&
2403                                 *family == AF_INET6) {
2404                         *type = PROVIDER_ROUTE_TYPE_MASK;
2405                 } else
2406                         return -EINVAL;
2407         }
2408
2409         return 0;
2410 }
2411
2412 int vpn_provider_append_route(struct vpn_provider *provider,
2413                                         const char *key, const char *value)
2414 {
2415         struct vpn_route *route;
2416         int ret, family = 0;
2417         unsigned long idx = 0;
2418         enum provider_route_type type = PROVIDER_ROUTE_TYPE_NONE;
2419
2420         DBG("key %s value %s", key, value);
2421
2422         ret = route_env_parse(provider, key, &family, &idx, &type);
2423         if (ret < 0)
2424                 return ret;
2425
2426         DBG("idx %lu family %d type %d", idx, family, type);
2427
2428         route = g_hash_table_lookup(provider->routes, GINT_TO_POINTER(idx));
2429         if (route == NULL) {
2430                 route = g_try_new0(struct vpn_route, 1);
2431                 if (route == NULL) {
2432                         connman_error("out of memory");
2433                         return -ENOMEM;
2434                 }
2435
2436                 route->family = family;
2437
2438                 g_hash_table_replace(provider->routes, GINT_TO_POINTER(idx),
2439                                                 route);
2440         }
2441
2442         switch (type) {
2443         case PROVIDER_ROUTE_TYPE_NONE:
2444                 break;
2445         case PROVIDER_ROUTE_TYPE_MASK:
2446                 route->netmask = g_strdup(value);
2447                 break;
2448         case PROVIDER_ROUTE_TYPE_ADDR:
2449                 route->network = g_strdup(value);
2450                 break;
2451         case PROVIDER_ROUTE_TYPE_GW:
2452                 route->gateway = g_strdup(value);
2453                 break;
2454         }
2455
2456         if (handle_routes == FALSE) {
2457                 if (route->netmask != NULL && route->gateway != NULL &&
2458                                                         route->network != NULL)
2459                         provider_schedule_changed(provider);
2460         }
2461
2462         return 0;
2463 }
2464
2465 const char *vpn_provider_get_driver_name(struct vpn_provider *provider)
2466 {
2467         if (provider->driver == NULL)
2468                 return NULL;
2469
2470         return provider->driver->name;
2471 }
2472
2473 const char *vpn_provider_get_save_group(struct vpn_provider *provider)
2474 {
2475         return provider->identifier;
2476 }
2477
2478 static gint compare_priority(gconstpointer a, gconstpointer b)
2479 {
2480         return 0;
2481 }
2482
2483 static void clean_provider(gpointer key, gpointer value, gpointer user_data)
2484 {
2485         struct vpn_provider *provider = value;
2486
2487         if (provider->driver != NULL && provider->driver->remove)
2488                 provider->driver->remove(provider);
2489
2490         connection_unregister(provider);
2491 }
2492
2493 int vpn_provider_driver_register(struct vpn_provider_driver *driver)
2494 {
2495         DBG("driver %p name %s", driver, driver->name);
2496
2497         driver_list = g_slist_insert_sorted(driver_list, driver,
2498                                                         compare_priority);
2499         provider_create_all_from_type(driver->name);
2500         return 0;
2501 }
2502
2503 void vpn_provider_driver_unregister(struct vpn_provider_driver *driver)
2504 {
2505         GHashTableIter iter;
2506         gpointer value, key;
2507
2508         DBG("driver %p name %s", driver, driver->name);
2509
2510         driver_list = g_slist_remove(driver_list, driver);
2511
2512         g_hash_table_iter_init(&iter, provider_hash);
2513         while (g_hash_table_iter_next(&iter, &key, &value) == TRUE) {
2514                 struct vpn_provider *provider = value;
2515
2516                 if (provider != NULL && provider->driver != NULL &&
2517                                 provider->driver->type == driver->type &&
2518                                 g_strcmp0(provider->driver->name,
2519                                                         driver->name) == 0) {
2520                         provider->driver = NULL;
2521                 }
2522         }
2523 }
2524
2525 const char *vpn_provider_get_name(struct vpn_provider *provider)
2526 {
2527         return provider->name;
2528 }
2529
2530 const char *vpn_provider_get_host(struct vpn_provider *provider)
2531 {
2532         return provider->host;
2533 }
2534
2535 const char *vpn_provider_get_path(struct vpn_provider *provider)
2536 {
2537         return provider->path;
2538 }
2539
2540 static int agent_probe(struct connman_agent *agent)
2541 {
2542         DBG("agent %p", agent);
2543         return 0;
2544 }
2545
2546 static void agent_remove(struct connman_agent *agent)
2547 {
2548         DBG("agent %p", agent);
2549 }
2550
2551 static struct connman_agent_driver agent_driver = {
2552         .name           = "vpn",
2553         .interface      = VPN_AGENT_INTERFACE,
2554         .probe          = agent_probe,
2555         .remove         = agent_remove,
2556 };
2557
2558 static void remove_unprovisioned_providers()
2559 {
2560         gchar **providers;
2561         GKeyFile *keyfile, *configkeyfile;
2562         char *file, *section;
2563         int i = 0;
2564
2565         providers = __connman_storage_get_providers();
2566         if (providers == NULL)
2567                 return;
2568
2569         for (; providers[i] != NULL; i++) {
2570                 char *group = providers[i] + sizeof("provider_") - 1;
2571                 file = section = NULL;
2572                 keyfile = configkeyfile = NULL;
2573
2574                 keyfile = __connman_storage_load_provider(group);
2575                 if (keyfile == NULL)
2576                         continue;
2577
2578                 file = g_key_file_get_string(keyfile, group,
2579                                         "Config.file", NULL);
2580                 if (file == NULL)
2581                         goto next;
2582
2583                 section = g_key_file_get_string(keyfile, group,
2584                                         "Config.ident", NULL);
2585                 if (section == NULL)
2586                         goto next;
2587
2588                 configkeyfile = __connman_storage_load_provider_config(file);
2589                 if (configkeyfile == NULL) {
2590                         /*
2591                          * Config file is missing, remove the provisioned
2592                          * service.
2593                          */
2594                         __connman_storage_remove_provider(group);
2595                         goto next;
2596                 }
2597
2598                 if (g_key_file_has_group(configkeyfile, section) == FALSE)
2599                         /*
2600                          * Config section is missing, remove the provisioned
2601                          * service.
2602                          */
2603                         __connman_storage_remove_provider(group);
2604
2605         next:
2606                 if (keyfile != NULL)
2607                         g_key_file_free(keyfile);
2608
2609                 if (configkeyfile != NULL)
2610                         g_key_file_free(configkeyfile);
2611
2612                 g_free(section);
2613                 g_free(file);
2614         }
2615
2616         g_strfreev(providers);
2617 }
2618
2619 int __vpn_provider_init(gboolean do_routes)
2620 {
2621         int err;
2622
2623         DBG("");
2624
2625         handle_routes = do_routes;
2626
2627         err = connman_agent_driver_register(&agent_driver);
2628         if (err < 0) {
2629                 connman_error("Cannot register agent driver for %s",
2630                                                 agent_driver.name);
2631                 return err;
2632         }
2633
2634         connection = connman_dbus_get_connection();
2635
2636         remove_unprovisioned_providers();
2637
2638         provider_hash = g_hash_table_new_full(g_str_hash, g_str_equal,
2639                                                 NULL, unregister_provider);
2640         return 0;
2641 }
2642
2643 void __vpn_provider_cleanup(void)
2644 {
2645         DBG("");
2646
2647         g_hash_table_foreach(provider_hash, clean_provider, NULL);
2648
2649         g_hash_table_destroy(provider_hash);
2650         provider_hash = NULL;
2651
2652         connman_agent_driver_unregister(&agent_driver);
2653
2654         dbus_connection_unref(connection);
2655 }