Merge tag 'upstream/1.40' into tizen.
[platform/upstream/connman.git] / vpn / vpn-provider.c
1 /*
2  *
3  *  ConnMan VPN daemon
4  *
5  *  Copyright (C) 2012-2013  Intel Corporation. All rights reserved.
6  *  Copyright (C) 2019  Jolla Ltd. All rights reserved.
7  *
8  *  This program is free software; you can redistribute it and/or modify
9  *  it under the terms of the GNU General Public License version 2 as
10  *  published by the Free Software Foundation.
11  *
12  *  This program is distributed in the hope that it will be useful,
13  *  but WITHOUT ANY WARRANTY; without even the implied warranty of
14  *  MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
15  *  GNU General Public License for more details.
16  *
17  *  You should have received a copy of the GNU General Public License
18  *  along with this program; if not, write to the Free Software
19  *  Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA  02110-1301  USA
20  *
21  */
22
23 #ifdef HAVE_CONFIG_H
24 #include <config.h>
25 #endif
26
27 #include <errno.h>
28 #include <stdio.h>
29 #include <string.h>
30 #include <stdlib.h>
31 #include <gdbus.h>
32 #include <connman/log.h>
33 #include <gweb/gresolv.h>
34 #include <netdb.h>
35
36 #include "../src/connman.h"
37 #include "connman/agent.h"
38 #include "connman/vpn-dbus.h"
39 #include "vpn-provider.h"
40 #include "vpn.h"
41 #include "plugins/vpn.h"
42
43 static DBusConnection *connection;
44 static GHashTable *provider_hash;
45 static GSList *driver_list;
46 static int configuration_count;
47
48 struct vpn_route {
49         int family;
50         char *network;
51         char *netmask;
52         char *gateway;
53 };
54
55 struct vpn_setting {
56         bool hide_value;
57         bool immutable;
58         char *value;
59 };
60
61 struct vpn_provider {
62         int refcount;
63         int index;
64         int fd;
65         enum vpn_provider_state state;
66         char *path;
67         char *identifier;
68         char *name;
69         char *type;
70         char *host;
71         char *domain;
72         int family;
73         bool do_split_routing;
74         GHashTable *routes;
75         struct vpn_provider_driver *driver;
76         void *driver_data;
77         GHashTable *setting_strings;
78         GHashTable *user_routes;
79         GSList *user_networks;
80         GResolv *resolv;
81         char **host_ip;
82         struct vpn_ipconfig *ipconfig_ipv4;
83         struct vpn_ipconfig *ipconfig_ipv6;
84         char **nameservers;
85         guint notify_id;
86         char *config_file;
87         char *config_entry;
88         bool immutable;
89         struct connman_ipaddress *prev_ipv4_addr;
90         struct connman_ipaddress *prev_ipv6_addr;
91         void *plugin_data;
92         unsigned int auth_error_counter;
93         unsigned int conn_error_counter;
94         unsigned int signal_watch;
95 };
96
97 static void append_properties(DBusMessageIter *iter,
98                                 struct vpn_provider *provider);
99 static int vpn_provider_save(struct vpn_provider *provider);
100
101 static void free_route(gpointer data)
102 {
103         struct vpn_route *route = data;
104
105         g_free(route->network);
106         g_free(route->netmask);
107         g_free(route->gateway);
108
109         g_free(route);
110 }
111
112 static void free_setting(gpointer data)
113 {
114         struct vpn_setting *setting = data;
115
116         g_free(setting->value);
117         g_free(setting);
118 }
119
120 static void append_route(DBusMessageIter *iter, void *user_data)
121 {
122         struct vpn_route *route = user_data;
123         DBusMessageIter item;
124         int family = 0;
125
126         connman_dbus_dict_open(iter, &item);
127
128         if (!route)
129                 goto empty_dict;
130
131         if (route->family == AF_INET)
132                 family = 4;
133         else if (route->family == AF_INET6)
134                 family = 6;
135
136         if (family != 0)
137                 connman_dbus_dict_append_basic(&item, "ProtocolFamily",
138                                         DBUS_TYPE_INT32, &family);
139
140         if (route->network)
141                 connman_dbus_dict_append_basic(&item, "Network",
142                                         DBUS_TYPE_STRING, &route->network);
143
144         if (route->netmask)
145                 connman_dbus_dict_append_basic(&item, "Netmask",
146                                         DBUS_TYPE_STRING, &route->netmask);
147
148         if (route->gateway)
149                 connman_dbus_dict_append_basic(&item, "Gateway",
150                                         DBUS_TYPE_STRING, &route->gateway);
151
152 empty_dict:
153         connman_dbus_dict_close(iter, &item);
154 }
155
156 static void append_routes(DBusMessageIter *iter, void *user_data)
157 {
158         GHashTable *routes = user_data;
159         GHashTableIter hash;
160         gpointer value, key;
161
162         if (!routes) {
163                 append_route(iter, NULL);
164                 return;
165         }
166
167         g_hash_table_iter_init(&hash, routes);
168
169         while (g_hash_table_iter_next(&hash, &key, &value)) {
170                 DBusMessageIter dict;
171
172                 dbus_message_iter_open_container(iter, DBUS_TYPE_STRUCT, NULL,
173                                                 &dict);
174                 append_route(&dict, value);
175                 dbus_message_iter_close_container(iter, &dict);
176         }
177 }
178
179 static void send_routes(struct vpn_provider *provider, GHashTable *routes,
180                         const char *name)
181 {
182         connman_dbus_property_changed_array(provider->path,
183                                         VPN_CONNECTION_INTERFACE,
184                                         name,
185                                         DBUS_TYPE_DICT_ENTRY,
186                                         append_routes,
187                                         routes);
188 }
189
190 static int provider_routes_changed(struct vpn_provider *provider)
191 {
192         DBG("provider %p", provider);
193
194         send_routes(provider, provider->routes, "ServerRoutes");
195
196         return 0;
197 }
198
199 /*
200  * Sort vpn_route struct based on (similarly to the route key in hash table):
201  * 1) IP protocol number
202  * 2) Network addresses
203  * 3) Netmask addresses
204  * 4) Gateway addresses
205  */
206 static gint compare_route(gconstpointer a, gconstpointer b)
207 {
208         const struct vpn_route *route_a = a;
209         const struct vpn_route *route_b = b;
210         int difference;
211
212         /* If IP families differ, prefer IPv6 over IPv4 */
213         if (route_a->family != route_b->family) {
214                 if (route_a->family < route_b->family)
215                         return -1;
216
217                 if (route_a->family > route_b->family)
218                         return 1;
219         }
220
221         /* If networks differ, return  */
222         if ((difference = g_strcmp0(route_a->network, route_b->network)))
223                 return difference;
224
225         /* If netmasks differ, return. */
226         if ((difference = g_strcmp0(route_a->netmask, route_b->netmask)))
227                 return difference;
228
229         return g_strcmp0(route_a->gateway, route_b->gateway);
230 }
231
232 static GSList *read_route_dict(GSList *routes, DBusMessageIter *dicts)
233 {
234         DBusMessageIter dict, value, entry;
235         const char *network, *netmask, *gateway;
236         struct vpn_route *route;
237         int family, type;
238         const char *key;
239
240         dbus_message_iter_recurse(dicts, &entry);
241
242         network = netmask = gateway = NULL;
243         family = PF_UNSPEC;
244
245         while (dbus_message_iter_get_arg_type(&entry) == DBUS_TYPE_DICT_ENTRY) {
246
247                 dbus_message_iter_recurse(&entry, &dict);
248                 dbus_message_iter_get_basic(&dict, &key);
249
250                 dbus_message_iter_next(&dict);
251                 dbus_message_iter_recurse(&dict, &value);
252
253                 type = dbus_message_iter_get_arg_type(&value);
254
255                 switch (type) {
256                 case DBUS_TYPE_INT32:
257                         if (g_str_equal(key, "ProtocolFamily"))
258                                 dbus_message_iter_get_basic(&value, &family);
259                         break;
260
261                 case DBUS_TYPE_STRING:
262                         if (g_str_equal(key, "Network"))
263                                 dbus_message_iter_get_basic(&value, &network);
264                         else if (g_str_equal(key, "Netmask"))
265                                 dbus_message_iter_get_basic(&value, &netmask);
266                         else if (g_str_equal(key, "Gateway"))
267                                 dbus_message_iter_get_basic(&value, &gateway);
268                         break;
269                 }
270
271                 dbus_message_iter_next(&entry);
272         }
273
274         DBG("family %d network %s netmask %s gateway %s", family,
275                 network, netmask, gateway);
276
277         if (!network || !netmask) {
278                 DBG("Ignoring route as network/netmask is missing");
279                 return routes;
280         }
281
282         route = g_try_new(struct vpn_route, 1);
283         if (!route) {
284                 g_slist_free_full(routes, free_route);
285                 return NULL;
286         }
287
288         if (family == PF_UNSPEC) {
289                 family = connman_inet_check_ipaddress(network);
290                 if (family < 0) {
291                         DBG("Cannot get address family of %s (%d/%s)", network,
292                                 family, gai_strerror(family));
293
294                         g_free(route);
295                         return routes;
296                 }
297         } else {
298                 switch (family) {
299                 case '4':
300                 case 4:
301                         family = AF_INET;
302                         break;
303                 case '6':
304                 case 6:
305                         family = AF_INET6;
306                         break;
307                 default:
308                         family = PF_UNSPEC;
309                         break;
310                 }
311         }
312
313         route->family = family;
314         route->network = g_strdup(network);
315         route->netmask = g_strdup(netmask);
316         route->gateway = g_strdup(gateway);
317
318         routes = g_slist_insert_sorted(routes, route, compare_route);
319         return routes;
320 }
321
322 static GSList *get_user_networks(DBusMessageIter *array)
323 {
324         DBusMessageIter entry;
325         GSList *list = NULL;
326
327         while (dbus_message_iter_get_arg_type(array) == DBUS_TYPE_ARRAY) {
328
329                 dbus_message_iter_recurse(array, &entry);
330
331                 while (dbus_message_iter_get_arg_type(&entry) ==
332                                                         DBUS_TYPE_STRUCT) {
333                         DBusMessageIter dicts;
334
335                         dbus_message_iter_recurse(&entry, &dicts);
336
337                         while (dbus_message_iter_get_arg_type(&dicts) ==
338                                                         DBUS_TYPE_ARRAY) {
339
340                                 list = read_route_dict(list, &dicts);
341                                 dbus_message_iter_next(&dicts);
342                         }
343
344                         dbus_message_iter_next(&entry);
345                 }
346
347                 dbus_message_iter_next(array);
348         }
349
350         return list;
351 }
352
353 static void set_user_networks(struct vpn_provider *provider, GSList *networks)
354 {
355         GSList *list;
356
357         for (list = networks; list; list = g_slist_next(list)) {
358                 struct vpn_route *route = list->data;
359
360                 if (__vpn_provider_append_user_route(provider,
361                                         route->family, route->network,
362                                         route->netmask, route->gateway) != 0)
363                         break;
364         }
365 }
366
367 static void del_routes(struct vpn_provider *provider)
368 {
369         GHashTableIter hash;
370
371         g_hash_table_iter_init(&hash, provider->user_routes);
372         g_hash_table_remove_all(provider->user_routes);
373         g_slist_free_full(provider->user_networks, free_route);
374         provider->user_networks = NULL;
375 }
376
377 static void send_value(const char *path, const char *key, const char *value)
378 {
379         const char *empty = "";
380         const char *str;
381
382         if (value)
383                 str = value;
384         else
385                 str = empty;
386
387         connman_dbus_property_changed_basic(path,
388                                         VPN_CONNECTION_INTERFACE,
389                                         key,
390                                         DBUS_TYPE_STRING,
391                                         &str);
392 }
393
394 static void send_value_boolean(const char *path, const char *key,
395                                                         dbus_bool_t value)
396 {
397         connman_dbus_property_changed_basic(path,
398                                         VPN_CONNECTION_INTERFACE,
399                                         key,
400                                         DBUS_TYPE_BOOLEAN,
401                                         &value);
402 }
403
404 static gboolean provider_send_changed(gpointer data)
405 {
406         struct vpn_provider *provider = data;
407
408         provider_routes_changed(provider);
409
410         provider->notify_id = 0;
411
412         return FALSE;
413 }
414
415 static void provider_schedule_changed(struct vpn_provider *provider)
416 {
417         if (provider->notify_id != 0)
418                 g_source_remove(provider->notify_id);
419
420         provider->notify_id = g_timeout_add(100, provider_send_changed,
421                                                                 provider);
422 }
423
424 static DBusMessage *get_properties(DBusConnection *conn,
425                                         DBusMessage *msg, void *data)
426 {
427         struct vpn_provider *provider = data;
428         DBusMessage *reply;
429         DBusMessageIter array;
430
431         DBG("provider %p", provider);
432
433         reply = dbus_message_new_method_return(msg);
434         if (!reply)
435                 return NULL;
436
437         dbus_message_iter_init_append(reply, &array);
438
439         append_properties(&array, provider);
440
441         return reply;
442 }
443
444 /* True when lists are equal, false otherwise */
445 static bool compare_network_lists(GSList *a, GSList *b)
446 {
447         struct vpn_route *route_a, *route_b;
448         GSList *iter_a, *iter_b;
449
450         if (!a && !b)
451                 return true;
452
453         /*
454          * If either of lists is NULL or the lists are of different size, the
455          * lists are not equal.
456          */
457         if ((!a || !b) || (g_slist_length(a) != g_slist_length(b)))
458                 return false;
459
460         /* Routes are in sorted list so items can be compared in order. */
461         for (iter_a = a, iter_b = b; iter_a && iter_b;
462                                 iter_a = iter_a->next, iter_b = iter_b->next) {
463
464                 route_a = iter_a->data;
465                 route_b = iter_b->data;
466
467                 if (compare_route(route_a, route_b))
468                         return false;
469         }
470
471         return true;
472 }
473
474 static const char *bool2str(bool value)
475 {
476         return value ? "true" : "false";
477 }
478
479 static int set_provider_property(struct vpn_provider *provider,
480                         const char *name, DBusMessageIter *value, int type)
481 {
482         int err = 0;
483
484         DBG("provider %p", provider);
485
486         if (!provider || !name || !value)
487                 return -EINVAL;
488
489         if (g_str_equal(name, "UserRoutes")) {
490                 GSList *networks;
491
492                 if (type != DBUS_TYPE_ARRAY)
493                         return -EINVAL;
494
495                 networks = get_user_networks(value);
496
497                 if (compare_network_lists(provider->user_networks, networks)) {
498                         g_slist_free_full(networks, free_route);
499                         return -EALREADY;
500                 }
501
502                 del_routes(provider);
503                 provider->user_networks = networks;
504                 set_user_networks(provider, provider->user_networks);
505                 send_routes(provider, provider->user_routes, "UserRoutes");
506         } else if (g_str_equal(name, "SplitRouting")) {
507                 dbus_bool_t split_routing;
508
509                 if (type != DBUS_TYPE_BOOLEAN)
510                         return -EINVAL;
511
512                 dbus_message_iter_get_basic(value, &split_routing);
513
514                 DBG("property %s value %s ", name, bool2str(split_routing));
515                 vpn_provider_set_boolean(provider, name, split_routing, false);
516         } else {
517                 const char *str;
518
519                 if (type != DBUS_TYPE_STRING)
520                         return -EINVAL;
521
522                 dbus_message_iter_get_basic(value, &str);
523
524                 DBG("property %s value %s", name, str);
525
526                 /* Empty string clears the value, similar to ClearProperty. */
527                 err = vpn_provider_set_string(provider, name,
528                                         *str ? str : NULL);
529         }
530
531         return err;
532 }
533
534 static GString *append_to_gstring(GString *str, const char *value)
535 {
536         if (!str)
537                 return g_string_new(value);
538
539         g_string_append_printf(str, ",%s", value);
540
541         return str;
542 }
543
544 static DBusMessage *set_properties(DBusMessageIter *iter, DBusMessage *msg,
545                                                                 void *data)
546 {
547         struct vpn_provider *provider = data;
548         DBusMessageIter dict;
549         const char *key;
550         bool change = false;
551         GString *invalid = NULL;
552         GString *denied = NULL;
553         int type;
554         int err;
555
556         for (dbus_message_iter_recurse(iter, &dict);
557                                 dbus_message_iter_get_arg_type(&dict) ==
558                                 DBUS_TYPE_DICT_ENTRY;
559                                 dbus_message_iter_next(&dict)) {
560                 DBusMessageIter entry, value;
561
562                 dbus_message_iter_recurse(&dict, &entry);
563                 /*
564                  * Ignore invalid types in order to process all values in the
565                  * dict. If there is an invalid type in between the dict there
566                  * may already be changes on some values and breaking out here
567                  *  would have the provider in an inconsistent state, leaving
568                  * the rest, potentially correct property values untouched.
569                  */
570                 if (dbus_message_iter_get_arg_type(&entry) != DBUS_TYPE_STRING)
571                         continue;
572
573                 dbus_message_iter_get_basic(&entry, &key);
574
575                 DBG("key %s", key);
576
577                 dbus_message_iter_next(&entry);
578                 /* Ignore and report back all non variant types. */
579                 if (dbus_message_iter_get_arg_type(&entry)
580                                         != DBUS_TYPE_VARIANT) {
581                         invalid = append_to_gstring(invalid, key);
582                         continue;
583                 }
584
585                 dbus_message_iter_recurse(&entry, &value);
586
587                 type = dbus_message_iter_get_arg_type(&value);
588                 switch (type) {
589                 case DBUS_TYPE_STRING:
590                 case DBUS_TYPE_ARRAY:
591                 case DBUS_TYPE_BOOLEAN:
592                         break;
593                 default:
594                         /* Ignore and report back all invalid property types */
595                         invalid = append_to_gstring(invalid, key);
596                         continue;
597                 }
598
599                 err = set_provider_property(provider, key, &value, type);
600                 switch (err) {
601                 case 0:
602                         change = true;
603                         break;
604                 case -EINVAL:
605                         invalid = append_to_gstring(invalid, key);
606                         break;
607                 case -EPERM:
608                         denied = append_to_gstring(denied, key);
609                         break;
610                 }
611         }
612
613         if (change)
614                 vpn_provider_save(provider);
615
616         if (invalid || denied) {
617                 DBusMessage *error;
618                 char *invalid_str = g_string_free(invalid, FALSE);
619                 char *denied_str = g_string_free(denied, FALSE);
620
621                 /*
622                  * If there are both invalid and denied properties report
623                  * back invalid arguments. Add also the failed properties to
624                  * the error message.
625                  */
626                 error = g_dbus_create_error(msg, (invalid ?
627                                 CONNMAN_ERROR_INTERFACE ".InvalidProperty" :
628                                 CONNMAN_ERROR_INTERFACE ".PermissionDenied"),
629                                 "%s %s%s%s", (invalid ? "Invalid properties" :
630                                 "Permission denied"),
631                                 (invalid ? invalid_str : ""),
632                                 (invalid && denied ? "," : ""),
633                                 (denied ? denied_str : ""));
634
635                 g_free(invalid_str);
636                 g_free(denied_str);
637
638                 return error;
639         }
640
641         return g_dbus_create_reply(msg, DBUS_TYPE_INVALID);
642 }
643
644 static DBusMessage *set_property(DBusConnection *conn, DBusMessage *msg,
645                                                                 void *data)
646 {
647         struct vpn_provider *provider = data;
648         DBusMessageIter iter, value;
649         const char *name;
650         int type;
651         int err;
652
653         DBG("conn %p", conn);
654
655         if (provider->immutable)
656                 return __connman_error_not_supported(msg);
657
658         if (!dbus_message_iter_init(msg, &iter))
659                 return __connman_error_invalid_arguments(msg);
660
661         if (dbus_message_iter_get_arg_type(&iter) != DBUS_TYPE_STRING)
662                 return __connman_error_invalid_arguments(msg);
663
664         dbus_message_iter_get_basic(&iter, &name);
665         dbus_message_iter_next(&iter);
666
667         if (dbus_message_iter_get_arg_type(&iter) != DBUS_TYPE_VARIANT)
668                 return __connman_error_invalid_arguments(msg);
669
670         dbus_message_iter_recurse(&iter, &value);
671
672         type = dbus_message_iter_get_arg_type(&value);
673         if (type == DBUS_TYPE_ARRAY && g_str_equal(name, "Properties"))
674                 return set_properties(&value, msg, data);
675
676         err = set_provider_property(provider, name, &value, type);
677         switch (err) {
678         case 0:
679                 vpn_provider_save(provider);
680                 break;
681         case -EALREADY:
682                 break;
683         case -EINVAL:
684                 return __connman_error_invalid_property(msg);
685         default:
686                 return __connman_error_failed(msg, -err);
687         }
688
689         return g_dbus_create_reply(msg, DBUS_TYPE_INVALID);
690 }
691
692 static DBusMessage *clear_property(DBusConnection *conn, DBusMessage *msg,
693                                                                 void *data)
694 {
695         struct vpn_provider *provider = data;
696         const char *name;
697         bool change = false;
698         int err;
699
700         DBG("conn %p", conn);
701
702         if (provider->immutable)
703                 return __connman_error_not_supported(msg);
704
705         dbus_message_get_args(msg, NULL, DBUS_TYPE_STRING, &name,
706                                                         DBUS_TYPE_INVALID);
707
708         if (g_str_equal(name, "UserRoutes")) {
709                 /*
710                  * If either user_routes or user_networks has any entries
711                  * there is a change that is to be written to settings file.
712                  */
713                 if (g_hash_table_size(provider->user_routes) ||
714                                 provider->user_networks)
715                         change = true;
716
717                 del_routes(provider);
718
719                 send_routes(provider, provider->user_routes, name);
720         } else if (vpn_provider_get_string(provider, name)) {
721                 err = vpn_provider_set_string(provider, name, NULL);
722                 switch (err) {
723                 case 0:
724                         change = true;
725                         /* fall through */
726                 case -EALREADY:
727                         break;
728                 case -EINVAL:
729                         return __connman_error_invalid_property(msg);
730                 default:
731                         return __connman_error_failed(msg, -err);
732                 }
733         } else {
734                 return __connman_error_invalid_property(msg);
735         }
736
737         if (change)
738                 vpn_provider_save(provider);
739
740         return g_dbus_create_reply(msg, DBUS_TYPE_INVALID);
741 }
742
743 static DBusMessage *do_connect(DBusConnection *conn, DBusMessage *msg,
744                                                                 void *data)
745 {
746         struct vpn_provider *provider = data;
747         int err;
748
749         DBG("conn %p provider %p", conn, provider);
750
751         err = __vpn_provider_connect(provider, msg);
752         if (err < 0 && err != -EINPROGRESS)
753                 return __connman_error_failed(msg, -err);
754
755         return NULL;
756 }
757
758 static DBusMessage *do_connect2(DBusConnection *conn, DBusMessage *msg,
759                                                                 void *data)
760 {
761         return do_connect(conn, msg, data);
762 }
763
764 static DBusMessage *do_disconnect(DBusConnection *conn, DBusMessage *msg,
765                                                                 void *data)
766 {
767         struct vpn_provider *provider = data;
768         int err;
769
770         DBG("conn %p provider %p", conn, provider);
771
772         err = __vpn_provider_disconnect(provider);
773         if (err < 0 && err != -EINPROGRESS)
774                 return __connman_error_failed(msg, -err);
775
776         return g_dbus_create_reply(msg, DBUS_TYPE_INVALID);
777 }
778
779 static const GDBusMethodTable connection_methods[] = {
780         { GDBUS_METHOD("GetProperties",
781                         NULL, GDBUS_ARGS({ "properties", "a{sv}" }),
782                         get_properties) },
783         { GDBUS_METHOD("SetProperty",
784                         GDBUS_ARGS({ "name", "s" }, { "value", "v" }),
785                         NULL, set_property) },
786         { GDBUS_METHOD("ClearProperty",
787                         GDBUS_ARGS({ "name", "s" }), NULL,
788                         clear_property) },
789         { GDBUS_ASYNC_METHOD("Connect", NULL, NULL, do_connect) },
790         { GDBUS_ASYNC_METHOD("Connect2",
791                         GDBUS_ARGS({ "dbus_sender", "s" }),
792                         NULL, do_connect2) },
793         { GDBUS_METHOD("Disconnect", NULL, NULL, do_disconnect) },
794         { },
795 };
796
797 static const GDBusSignalTable connection_signals[] = {
798         { GDBUS_SIGNAL("PropertyChanged",
799                         GDBUS_ARGS({ "name", "s" }, { "value", "v" })) },
800         { },
801 };
802
803 static void resolv_result(GResolvResultStatus status,
804                                         char **results, gpointer user_data)
805 {
806         struct vpn_provider *provider = user_data;
807
808         DBG("status %d", status);
809
810         if (status == G_RESOLV_RESULT_STATUS_SUCCESS && results &&
811                                                 g_strv_length(results) > 0)
812                 provider->host_ip = g_strdupv(results);
813
814         vpn_provider_unref(provider);
815
816         /* Remove the resolver here so that it will not be left
817          * hanging around and cause double free in unregister_provider()
818          */
819         g_resolv_unref(provider->resolv);
820         provider->resolv = NULL;
821 }
822
823 static void provider_resolv_host_addr(struct vpn_provider *provider)
824 {
825         if (!provider->host)
826                 return;
827
828         if (connman_inet_check_ipaddress(provider->host) > 0)
829                 return;
830
831         if (provider->host_ip)
832                 return;
833
834         /*
835          * If the hostname is not numeric, try to resolv it. We do not wait
836          * the result as it might take some time. We will get the result
837          * before VPN will feed routes to us because VPN client will need
838          * the IP address also before VPN connection can be established.
839          */
840         provider->resolv = g_resolv_new(0);
841         if (!provider->resolv) {
842                 DBG("Cannot resolv %s", provider->host);
843                 return;
844         }
845
846         DBG("Trying to resolv %s", provider->host);
847
848         vpn_provider_ref(provider);
849
850         g_resolv_lookup_hostname(provider->resolv, provider->host,
851                                 resolv_result, provider);
852 }
853
854 void __vpn_provider_append_properties(struct vpn_provider *provider,
855                                                         DBusMessageIter *iter)
856 {
857         dbus_bool_t split_routing;
858
859         if (provider->host)
860                 connman_dbus_dict_append_basic(iter, "Host",
861                                         DBUS_TYPE_STRING, &provider->host);
862
863         if (provider->domain)
864                 connman_dbus_dict_append_basic(iter, "Domain",
865                                         DBUS_TYPE_STRING, &provider->domain);
866
867         if (provider->type)
868                 connman_dbus_dict_append_basic(iter, "Type", DBUS_TYPE_STRING,
869                                                  &provider->type);
870
871         split_routing = provider->do_split_routing;
872         connman_dbus_dict_append_basic(iter, "SplitRouting", DBUS_TYPE_BOOLEAN,
873                                                         &split_routing);
874 }
875
876 int __vpn_provider_append_user_route(struct vpn_provider *provider,
877                                 int family, const char *network,
878                                 const char *netmask, const char *gateway)
879 {
880         struct vpn_route *route;
881         char *key = g_strdup_printf("%d/%s/%s/%s", family, network,
882                                 netmask, gateway ? gateway : "");
883
884         DBG("family %d network %s netmask %s gw %s", family, network,
885                                                         netmask, gateway);
886
887         route = g_hash_table_lookup(provider->user_routes, key);
888         if (!route) {
889                 route = g_try_new0(struct vpn_route, 1);
890                 if (!route) {
891                         connman_error("out of memory");
892                         return -ENOMEM;
893                 }
894
895                 route->family = family;
896                 route->network = g_strdup(network);
897                 route->netmask = g_strdup(netmask);
898                 route->gateway = g_strdup(gateway);
899
900                 g_hash_table_replace(provider->user_routes, key, route);
901         } else
902                 g_free(key);
903
904         return 0;
905 }
906
907 static struct vpn_route *get_route(char *route_str)
908 {
909         char **elems = g_strsplit(route_str, "/", 0);
910         char *network, *netmask, *gateway, *family_str;
911         int family = PF_UNSPEC;
912         struct vpn_route *route = NULL;
913
914         if (!elems)
915                 return NULL;
916
917         family_str = elems[0];
918
919         network = elems[1];
920         if (!network || network[0] == '\0')
921                 goto out;
922
923         netmask = elems[2];
924         if (!netmask || netmask[0] == '\0')
925                 goto out;
926
927         gateway = elems[3];
928
929         route = g_try_new0(struct vpn_route, 1);
930         if (!route)
931                 goto out;
932
933         if (family_str[0] == '\0' || atoi(family_str) == 0) {
934                 family = PF_UNSPEC;
935         } else {
936                 switch (family_str[0]) {
937                 case '4':
938                         family = AF_INET;
939                         break;
940                 case '6':
941                         family = AF_INET6;
942                         break;
943                 }
944         }
945
946         if (g_strrstr(network, ":")) {
947                 if (family != PF_UNSPEC && family != AF_INET6)
948                         DBG("You have IPv6 address but you have non IPv6 route");
949         } else if (g_strrstr(network, ".")) {
950                 if (family != PF_UNSPEC && family != AF_INET)
951                         DBG("You have IPv4 address but you have non IPv4 route");
952
953                 if (!g_strrstr(netmask, ".")) {
954                         /* We have netmask length */
955                         in_addr_t addr;
956                         struct in_addr netmask_in;
957                         unsigned char prefix_len = 32;
958                         char *ptr;
959                         long int value = strtol(netmask, &ptr, 10);
960
961                         if (ptr != netmask && *ptr == '\0' && value <= 32)
962                                 prefix_len = value;
963
964                         addr = 0xffffffff << (32 - prefix_len);
965                         netmask_in.s_addr = htonl(addr);
966                         netmask = inet_ntoa(netmask_in);
967
968                         DBG("network %s netmask %s", network, netmask);
969                 }
970         }
971
972         if (family == PF_UNSPEC) {
973                 family = connman_inet_check_ipaddress(network);
974                 if (family < 0 || family == PF_UNSPEC)
975                         goto out;
976         }
977
978         route->family = family;
979         route->network = g_strdup(network);
980         route->netmask = g_strdup(netmask);
981         route->gateway = g_strdup(gateway);
982
983 out:
984         g_strfreev(elems);
985         return route;
986 }
987
988 static GSList *get_routes(gchar **networks)
989 {
990         struct vpn_route *route;
991         GSList *routes = NULL;
992         int i;
993
994         for (i = 0; networks[i]; i++) {
995                 route = get_route(networks[i]);
996                 if (route)
997                         routes = g_slist_prepend(routes, route);
998         }
999
1000         return routes;
1001 }
1002
1003 static int provider_load_from_keyfile(struct vpn_provider *provider,
1004                 GKeyFile *keyfile)
1005 {
1006         gsize idx;
1007         gchar **settings;
1008         gchar *key, *value;
1009         gsize length, num_user_networks;
1010         gchar **networks = NULL;
1011
1012         settings = g_key_file_get_keys(keyfile, provider->identifier, &length,
1013                                 NULL);
1014         if (!settings) {
1015                 g_key_file_free(keyfile);
1016                 return -ENOENT;
1017         }
1018
1019         for (idx = 0; idx < length; idx++) {
1020                 key = settings[idx];
1021                 if (!key)
1022                         continue;
1023
1024                 if (g_str_equal(key, "Networks")) {
1025                         networks = __vpn_config_get_string_list(keyfile,
1026                                                 provider->identifier,key,
1027                                                 &num_user_networks, NULL);
1028                         provider->user_networks = get_routes(networks);
1029                 } else {
1030                         value = __vpn_config_get_string(keyfile,
1031                                                 provider->identifier, key,
1032                                                 NULL);
1033
1034                         vpn_provider_set_string(provider, key, value);
1035                         g_free(value);
1036                 }
1037         }
1038
1039         g_strfreev(settings);
1040         g_strfreev(networks);
1041
1042         if (provider->user_networks)
1043                 set_user_networks(provider, provider->user_networks);
1044
1045         return 0;
1046 }
1047
1048
1049 static int vpn_provider_load(struct vpn_provider *provider)
1050 {
1051         GKeyFile *keyfile;
1052
1053         DBG("provider %p", provider);
1054
1055         keyfile = __connman_storage_load_provider(provider->identifier);
1056         if (!keyfile)
1057                 return -ENOENT;
1058
1059         provider_load_from_keyfile(provider, keyfile);
1060
1061         g_key_file_free(keyfile);
1062         return 0;
1063 }
1064
1065 static gchar **create_network_list(GSList *networks, gsize *count)
1066 {
1067         GSList *list;
1068         gchar **result = NULL;
1069         gchar **prev_result;
1070         unsigned int num_elems = 0;
1071
1072         for (list = networks; list; list = g_slist_next(list)) {
1073                 struct vpn_route *route = list->data;
1074                 int family;
1075
1076                 prev_result = result;
1077                 result = g_try_realloc(result,
1078                                 (num_elems + 1) * sizeof(gchar *));
1079                 if (!result) {
1080                         g_free(prev_result);
1081                         return NULL;
1082                 }
1083
1084                 switch (route->family) {
1085                 case AF_INET:
1086                         family = 4;
1087                         break;
1088                 case AF_INET6:
1089                         family = 6;
1090                         break;
1091                 default:
1092                         family = 0;
1093                         break;
1094                 }
1095
1096                 result[num_elems] = g_strdup_printf("%d/%s/%s/%s",
1097                                 family, route->network, route->netmask,
1098                                 !route->gateway ? "" : route->gateway);
1099
1100                 num_elems++;
1101         }
1102
1103         prev_result = result;
1104         result = g_try_realloc(result, (num_elems + 1) * sizeof(gchar *));
1105         if (!result) {
1106                 g_free(prev_result);
1107                 return NULL;
1108         }
1109
1110         result[num_elems] = NULL;
1111         *count = num_elems;
1112         return result;
1113 }
1114
1115 static void reset_error_counters(struct vpn_provider *provider)
1116 {
1117         if (!provider)
1118                 return;
1119
1120         provider->auth_error_counter = provider->conn_error_counter = 0;
1121 }
1122
1123 static int vpn_provider_save(struct vpn_provider *provider)
1124 {
1125         GKeyFile *keyfile;
1126
1127         DBG("provider %p immutable %s", provider,
1128                                         provider->immutable ? "yes" : "no");
1129
1130         reset_error_counters(provider);
1131
1132         if (provider->state == VPN_PROVIDER_STATE_FAILURE)
1133                 vpn_provider_set_state(provider, VPN_PROVIDER_STATE_IDLE);
1134
1135         if (provider->immutable) {
1136                 /*
1137                  * Do not save providers that are provisioned via .config
1138                  * file.
1139                  */
1140                 return -EPERM;
1141         }
1142
1143         keyfile = g_key_file_new();
1144         if (!keyfile)
1145                 return -ENOMEM;
1146
1147         g_key_file_set_string(keyfile, provider->identifier,
1148                         "Name", provider->name);
1149         g_key_file_set_string(keyfile, provider->identifier,
1150                         "Type", provider->type);
1151         g_key_file_set_string(keyfile, provider->identifier,
1152                         "Host", provider->host);
1153         g_key_file_set_string(keyfile, provider->identifier,
1154                         "VPN.Domain", provider->domain);
1155
1156         if (provider->user_networks) {
1157                 gchar **networks;
1158                 gsize network_count;
1159
1160                 networks = create_network_list(provider->user_networks,
1161                                                         &network_count);
1162                 if (networks) {
1163                         g_key_file_set_string_list(keyfile,
1164                                                 provider->identifier,
1165                                                 "Networks",
1166                                                 (const gchar ** const)networks,
1167                                                 network_count);
1168                         g_strfreev(networks);
1169                 }
1170         }
1171
1172         if (provider->config_file && strlen(provider->config_file) > 0)
1173                 g_key_file_set_string(keyfile, provider->identifier,
1174                                 "Config.file", provider->config_file);
1175
1176         if (provider->config_entry &&
1177                                         strlen(provider->config_entry) > 0)
1178                 g_key_file_set_string(keyfile, provider->identifier,
1179                                 "Config.ident", provider->config_entry);
1180
1181         if (provider->driver && provider->driver->save)
1182                 provider->driver->save(provider, keyfile);
1183
1184         __connman_storage_save_provider(keyfile, provider->identifier);
1185         g_key_file_free(keyfile);
1186
1187         return 0;
1188 }
1189
1190 struct vpn_provider *__vpn_provider_lookup(const char *identifier)
1191 {
1192         struct vpn_provider *provider = NULL;
1193
1194         provider = g_hash_table_lookup(provider_hash, identifier);
1195
1196         return provider;
1197 }
1198
1199 static bool match_driver(struct vpn_provider *provider,
1200                                 struct vpn_provider_driver *driver)
1201 {
1202         if (g_strcmp0(driver->name, provider->type) == 0)
1203                 return true;
1204
1205         return false;
1206 }
1207
1208 static int provider_probe(struct vpn_provider *provider)
1209 {
1210         GSList *list;
1211
1212         DBG("provider %p driver %p name %s", provider, provider->driver,
1213                                                 provider->name);
1214
1215         if (provider->driver)
1216                 return -EALREADY;
1217
1218         for (list = driver_list; list; list = list->next) {
1219                 struct vpn_provider_driver *driver = list->data;
1220
1221                 if (!match_driver(provider, driver))
1222                         continue;
1223
1224                 DBG("driver %p name %s", driver, driver->name);
1225
1226                 if (driver->probe && driver->probe(provider) == 0) {
1227                         provider->driver = driver;
1228                         break;
1229                 }
1230         }
1231
1232         if (!provider->driver)
1233                 return -ENODEV;
1234
1235         return 0;
1236 }
1237
1238 static void provider_remove(struct vpn_provider *provider)
1239 {
1240         if (provider->driver) {
1241                 provider->driver->remove(provider);
1242                 provider->driver = NULL;
1243         }
1244 }
1245
1246 static int provider_register(struct vpn_provider *provider)
1247 {
1248         return provider_probe(provider);
1249 }
1250
1251 static void provider_unregister(struct vpn_provider *provider)
1252 {
1253         provider_remove(provider);
1254 }
1255
1256 struct vpn_provider *
1257 vpn_provider_ref_debug(struct vpn_provider *provider,
1258                         const char *file, int line, const char *caller)
1259 {
1260         DBG("%p ref %d by %s:%d:%s()", provider, provider->refcount + 1,
1261                 file, line, caller);
1262
1263         __sync_fetch_and_add(&provider->refcount, 1);
1264
1265         return provider;
1266 }
1267
1268 static void provider_destruct(struct vpn_provider *provider)
1269 {
1270         DBG("provider %p", provider);
1271
1272         if (provider->notify_id != 0)
1273                 g_source_remove(provider->notify_id);
1274
1275         g_free(provider->name);
1276         g_free(provider->type);
1277         g_free(provider->host);
1278         g_free(provider->domain);
1279         g_free(provider->identifier);
1280         g_free(provider->path);
1281         g_slist_free_full(provider->user_networks, free_route);
1282         g_strfreev(provider->nameservers);
1283         g_hash_table_destroy(provider->routes);
1284         g_hash_table_destroy(provider->user_routes);
1285         g_hash_table_destroy(provider->setting_strings);
1286         if (provider->resolv) {
1287                 g_resolv_unref(provider->resolv);
1288                 provider->resolv = NULL;
1289         }
1290         __vpn_ipconfig_unref(provider->ipconfig_ipv4);
1291         __vpn_ipconfig_unref(provider->ipconfig_ipv6);
1292
1293         g_strfreev(provider->host_ip);
1294         g_free(provider->config_file);
1295         g_free(provider->config_entry);
1296         connman_ipaddress_free(provider->prev_ipv4_addr);
1297         connman_ipaddress_free(provider->prev_ipv6_addr);
1298         g_free(provider);
1299 }
1300
1301 void vpn_provider_unref_debug(struct vpn_provider *provider,
1302                                 const char *file, int line, const char *caller)
1303 {
1304         DBG("%p ref %d by %s:%d:%s()", provider, provider->refcount - 1,
1305                 file, line, caller);
1306
1307         if (__sync_fetch_and_sub(&provider->refcount, 1) != 1)
1308                 return;
1309
1310         provider_remove(provider);
1311
1312         provider_destruct(provider);
1313 }
1314
1315 static void configuration_count_add(void)
1316 {
1317         DBG("count %d", configuration_count + 1);
1318
1319         __sync_fetch_and_add(&configuration_count, 1);
1320 }
1321
1322 static void configuration_count_del(void)
1323 {
1324         DBG("count %d", configuration_count - 1);
1325
1326         if (__sync_fetch_and_sub(&configuration_count, 1) != 1)
1327                 return;
1328 }
1329
1330 int __vpn_provider_disconnect(struct vpn_provider *provider)
1331 {
1332         int err;
1333
1334         DBG("provider %p", provider);
1335
1336         if (provider->driver && provider->driver->disconnect)
1337                 err = provider->driver->disconnect(provider);
1338         else
1339                 return -EOPNOTSUPP;
1340
1341         if (err == -EINPROGRESS)
1342                 vpn_provider_set_state(provider, VPN_PROVIDER_STATE_CONNECT);
1343
1344         return err;
1345 }
1346
1347 static void connect_cb(struct vpn_provider *provider, void *user_data,
1348                                                                 int error)
1349 {
1350         DBusMessage *pending = user_data;
1351
1352         DBG("provider %p user %p error %d", provider, user_data, error);
1353
1354         if (error != 0) {
1355                 DBusMessage *reply = __connman_error_failed(pending, error);
1356                 if (reply)
1357                         g_dbus_send_message(connection, reply);
1358
1359                 switch (error) {
1360                 case EACCES:
1361                         vpn_provider_indicate_error(provider,
1362                                                 VPN_PROVIDER_ERROR_AUTH_FAILED);
1363                         break;
1364                 case ENOENT:
1365                         /*
1366                          * No reply, disconnect called by connmand because of
1367                          * connection timeout.
1368                          */
1369                         break;
1370                 case ENOMSG:
1371                         /* fall through */
1372                 case ETIMEDOUT:
1373                         /* No reply or timed out -> cancel the agent request */
1374                         connman_agent_cancel(provider);
1375                         vpn_provider_indicate_error(provider,
1376                                                 VPN_PROVIDER_ERROR_UNKNOWN);
1377                         break;
1378                 case ECANCELED:
1379                         /* fall through */
1380                 case ECONNABORTED:
1381                         /*
1382                          * This can be called in other situations than when
1383                          * VPN agent error checker is called. In such case
1384                          * react to both ECONNABORTED and ECANCELED as if the
1385                          * connection was called to terminate and do full
1386                          * disconnect -> idle cycle when being connected or
1387                          * ready. Setting the state also using the driver
1388                          * callback (vpn_set_state()) ensures that the driver is
1389                          * being disconnected as well and eventually the vpn
1390                          * process gets killed and vpn_died() is called to make
1391                          * the provider back to idle state.
1392                          */
1393                         if (provider->state == VPN_PROVIDER_STATE_CONNECT ||
1394                                                 provider->state ==
1395                                                 VPN_PROVIDER_STATE_READY) {
1396                                 if (provider->driver->set_state)
1397                                         provider->driver->set_state(provider,
1398                                                 VPN_PROVIDER_STATE_DISCONNECT);
1399
1400                                 vpn_provider_set_state(provider,
1401                                                 VPN_PROVIDER_STATE_DISCONNECT);
1402                         }
1403                         break;
1404                 default:
1405                         vpn_provider_indicate_error(provider,
1406                                         VPN_PROVIDER_ERROR_CONNECT_FAILED);
1407                         vpn_provider_set_state(provider,
1408                                         VPN_PROVIDER_STATE_FAILURE);
1409                 }
1410         } else {
1411                 reset_error_counters(provider);
1412                 g_dbus_send_reply(connection, pending, DBUS_TYPE_INVALID);
1413         }
1414
1415         dbus_message_unref(pending);
1416 }
1417
1418 int __vpn_provider_connect(struct vpn_provider *provider, DBusMessage *msg)
1419 {
1420         DBusMessage *reply;
1421         int err;
1422
1423         DBG("provider %p state %d", provider, provider->state);
1424
1425         switch (provider->state) {
1426         /*
1427          * When previous connection has failed change state to idle and let
1428          * the connmand to process this information as well. Return -EINPROGRESS
1429          * to indicate that transition is in progress and next connection
1430          * attempt will continue as normal.
1431          */
1432         case VPN_PROVIDER_STATE_FAILURE:
1433                 if (provider->driver && provider->driver->set_state)
1434                         provider->driver->set_state(provider,
1435                                                 VPN_PROVIDER_STATE_IDLE);
1436
1437                 vpn_provider_set_state(provider, VPN_PROVIDER_STATE_IDLE);
1438                 /* fall through */
1439         /*
1440          * If re-using a provider and it is being disconnected let it finish
1441          * the disconnect process in order to let vpn.c:vpn_died() to get
1442          * processed and everything cleaned up. Otherwise the reference
1443          * counters are not decreased properly causing the previous interface
1444          * being left up and its routes will remain in routing table. Return
1445          * -EINPROGRESS to indicate that transition is in progress.
1446          */
1447         case VPN_PROVIDER_STATE_DISCONNECT:
1448                 /*
1449                  * Failure transition or disconnecting does not yield a
1450                  * message to be sent. Send in progress message to avoid
1451                  * D-Bus LimitsExceeded error message.
1452                  */
1453                 reply = __connman_error_in_progress(msg);
1454                 if (reply)
1455                         g_dbus_send_message(connection, reply);
1456
1457                 return -EINPROGRESS;
1458         case VPN_PROVIDER_STATE_UNKNOWN:
1459         case VPN_PROVIDER_STATE_IDLE:
1460         case VPN_PROVIDER_STATE_CONNECT:
1461         case VPN_PROVIDER_STATE_READY:
1462                 break;
1463         }
1464
1465         if (provider->driver && provider->driver->connect) {
1466                 const char *dbus_sender = dbus_message_get_sender(msg);
1467
1468                 dbus_message_ref(msg);
1469
1470                 if (dbus_message_has_signature(msg,
1471                                                 DBUS_TYPE_STRING_AS_STRING)) {
1472                         const char *sender = NULL;
1473
1474                         dbus_message_get_args(msg, NULL, DBUS_TYPE_STRING,
1475                                         &sender, DBUS_TYPE_INVALID);
1476                         if (sender && sender[0])
1477                                 dbus_sender = sender;
1478                 }
1479
1480                 err = provider->driver->connect(provider, connect_cb,
1481                                                 dbus_sender, msg);
1482         } else
1483                 return -EOPNOTSUPP;
1484
1485         if (err == -EINPROGRESS)
1486                 vpn_provider_set_state(provider, VPN_PROVIDER_STATE_CONNECT);
1487
1488         return err;
1489 }
1490
1491 static void connection_removed_signal(struct vpn_provider *provider)
1492 {
1493         DBusMessage *signal;
1494         DBusMessageIter iter;
1495
1496         signal = dbus_message_new_signal(VPN_MANAGER_PATH,
1497                         VPN_MANAGER_INTERFACE, "ConnectionRemoved");
1498         if (!signal)
1499                 return;
1500
1501         dbus_message_iter_init_append(signal, &iter);
1502         dbus_message_iter_append_basic(&iter, DBUS_TYPE_OBJECT_PATH,
1503                                                         &provider->path);
1504         dbus_connection_send(connection, signal, NULL);
1505         dbus_message_unref(signal);
1506 }
1507
1508 static char *get_ident(const char *path)
1509 {
1510         char *pos;
1511
1512         if (*path != '/')
1513                 return NULL;
1514
1515         pos = strrchr(path, '/');
1516         if (!pos)
1517                 return NULL;
1518
1519         return pos + 1;
1520 }
1521
1522 int __vpn_provider_remove(const char *path)
1523 {
1524         struct vpn_provider *provider;
1525         char *ident;
1526
1527         DBG("path %s", path);
1528
1529         ident = get_ident(path);
1530
1531         provider = __vpn_provider_lookup(ident);
1532         if (provider)
1533                 return __vpn_provider_delete(provider);
1534
1535         return -ENXIO;
1536 }
1537
1538 int __vpn_provider_delete(struct vpn_provider *provider)
1539 {
1540         DBG("Deleting VPN %s", provider->identifier);
1541
1542         connection_removed_signal(provider);
1543
1544         provider_unregister(provider);
1545
1546         __connman_storage_remove_provider(provider->identifier);
1547
1548         g_hash_table_remove(provider_hash, provider->identifier);
1549
1550         return 0;
1551 }
1552
1553 static void append_ipv4(DBusMessageIter *iter, void *user_data)
1554 {
1555         struct vpn_provider *provider = user_data;
1556         const char *address, *gateway, *peer;
1557
1558         address = __vpn_ipconfig_get_local(provider->ipconfig_ipv4);
1559         if (address) {
1560                 in_addr_t addr;
1561                 struct in_addr netmask;
1562                 char *mask;
1563                 int prefixlen;
1564
1565                 prefixlen = __vpn_ipconfig_get_prefixlen(
1566                                                 provider->ipconfig_ipv4);
1567
1568                 addr = 0xffffffff << (32 - prefixlen);
1569                 netmask.s_addr = htonl(addr);
1570                 mask = inet_ntoa(netmask);
1571
1572                 connman_dbus_dict_append_basic(iter, "Address",
1573                                                 DBUS_TYPE_STRING, &address);
1574
1575                 connman_dbus_dict_append_basic(iter, "Netmask",
1576                                                 DBUS_TYPE_STRING, &mask);
1577         }
1578
1579         gateway = __vpn_ipconfig_get_gateway(provider->ipconfig_ipv4);
1580         if (gateway)
1581                 connman_dbus_dict_append_basic(iter, "Gateway",
1582                                                 DBUS_TYPE_STRING, &gateway);
1583
1584         peer = __vpn_ipconfig_get_peer(provider->ipconfig_ipv4);
1585         if (peer)
1586                 connman_dbus_dict_append_basic(iter, "Peer",
1587                                                 DBUS_TYPE_STRING, &peer);
1588 }
1589
1590 static void append_ipv6(DBusMessageIter *iter, void *user_data)
1591 {
1592         struct vpn_provider *provider = user_data;
1593         const char *address, *gateway, *peer;
1594
1595         address = __vpn_ipconfig_get_local(provider->ipconfig_ipv6);
1596         if (address) {
1597                 unsigned char prefixlen;
1598
1599                 connman_dbus_dict_append_basic(iter, "Address",
1600                                                 DBUS_TYPE_STRING, &address);
1601
1602                 prefixlen = __vpn_ipconfig_get_prefixlen(
1603                                                 provider->ipconfig_ipv6);
1604
1605                 connman_dbus_dict_append_basic(iter, "PrefixLength",
1606                                                 DBUS_TYPE_BYTE, &prefixlen);
1607         }
1608
1609         gateway = __vpn_ipconfig_get_gateway(provider->ipconfig_ipv6);
1610         if (gateway)
1611                 connman_dbus_dict_append_basic(iter, "Gateway",
1612                                                 DBUS_TYPE_STRING, &gateway);
1613
1614         peer = __vpn_ipconfig_get_peer(provider->ipconfig_ipv6);
1615         if (peer)
1616                 connman_dbus_dict_append_basic(iter, "Peer",
1617                                                 DBUS_TYPE_STRING, &peer);
1618 }
1619
1620 static const char *state2string(enum vpn_provider_state state)
1621 {
1622         switch (state) {
1623         case VPN_PROVIDER_STATE_UNKNOWN:
1624                 break;
1625         case VPN_PROVIDER_STATE_IDLE:
1626                 return "idle";
1627         case VPN_PROVIDER_STATE_CONNECT:
1628                 return "configuration";
1629         case VPN_PROVIDER_STATE_READY:
1630                 return "ready";
1631         case VPN_PROVIDER_STATE_DISCONNECT:
1632                 return "disconnect";
1633         case VPN_PROVIDER_STATE_FAILURE:
1634                 return "failure";
1635         }
1636
1637         return NULL;
1638 }
1639
1640 static void append_nameservers(DBusMessageIter *iter, char **servers)
1641 {
1642         int i;
1643
1644         DBG("%p", servers);
1645
1646         for (i = 0; servers[i]; i++) {
1647                 DBG("servers[%d] %s", i, servers[i]);
1648                 dbus_message_iter_append_basic(iter,
1649                                         DBUS_TYPE_STRING, &servers[i]);
1650         }
1651 }
1652
1653 static void append_dns(DBusMessageIter *iter, void *user_data)
1654 {
1655         struct vpn_provider *provider = user_data;
1656
1657         if (provider->nameservers)
1658                 append_nameservers(iter, provider->nameservers);
1659 }
1660
1661 static int provider_indicate_state(struct vpn_provider *provider,
1662                                 enum vpn_provider_state state)
1663 {
1664         const char *str;
1665         enum vpn_provider_state old_state;
1666
1667         str = state2string(state);
1668         DBG("provider %p state %s/%d", provider, str, state);
1669         if (!str)
1670                 return -EINVAL;
1671
1672         old_state = provider->state;
1673         provider->state = state;
1674
1675         if (state == VPN_PROVIDER_STATE_READY) {
1676                 connman_dbus_property_changed_basic(provider->path,
1677                                         VPN_CONNECTION_INTERFACE, "Index",
1678                                         DBUS_TYPE_INT32, &provider->index);
1679
1680                 if (provider->family == AF_INET)
1681                         connman_dbus_property_changed_dict(provider->path,
1682                                         VPN_CONNECTION_INTERFACE, "IPv4",
1683                                         append_ipv4, provider);
1684                 else if (provider->family == AF_INET6)
1685                         connman_dbus_property_changed_dict(provider->path,
1686                                         VPN_CONNECTION_INTERFACE, "IPv6",
1687                                         append_ipv6, provider);
1688
1689                 connman_dbus_property_changed_array(provider->path,
1690                                                 VPN_CONNECTION_INTERFACE,
1691                                                 "Nameservers",
1692                                                 DBUS_TYPE_STRING,
1693                                                 append_dns, provider);
1694
1695                 if (provider->domain)
1696                         connman_dbus_property_changed_basic(provider->path,
1697                                                 VPN_CONNECTION_INTERFACE,
1698                                                 "Domain",
1699                                                 DBUS_TYPE_STRING,
1700                                                 &provider->domain);
1701         }
1702
1703         if (old_state != state)
1704                 connman_dbus_property_changed_basic(provider->path,
1705                                         VPN_CONNECTION_INTERFACE, "State",
1706                                         DBUS_TYPE_STRING, &str);
1707
1708         return 0;
1709 }
1710
1711 static void append_state(DBusMessageIter *iter,
1712                                         struct vpn_provider *provider)
1713 {
1714         char *str;
1715
1716         switch (provider->state) {
1717         case VPN_PROVIDER_STATE_UNKNOWN:
1718         case VPN_PROVIDER_STATE_IDLE:
1719                 str = "idle";
1720                 break;
1721         case VPN_PROVIDER_STATE_CONNECT:
1722                 str = "configuration";
1723                 break;
1724         case VPN_PROVIDER_STATE_READY:
1725                 str = "ready";
1726                 break;
1727         case VPN_PROVIDER_STATE_DISCONNECT:
1728                 str = "disconnect";
1729                 break;
1730         case VPN_PROVIDER_STATE_FAILURE:
1731                 str = "failure";
1732                 break;
1733         }
1734
1735         connman_dbus_dict_append_basic(iter, "State",
1736                                 DBUS_TYPE_STRING, &str);
1737 }
1738
1739 static void append_properties(DBusMessageIter *iter,
1740                                         struct vpn_provider *provider)
1741 {
1742         DBusMessageIter dict;
1743         GHashTableIter hash;
1744         gpointer value, key;
1745         dbus_bool_t immutable;
1746         dbus_bool_t split_routing;
1747
1748         connman_dbus_dict_open(iter, &dict);
1749
1750         append_state(&dict, provider);
1751
1752         if (provider->type)
1753                 connman_dbus_dict_append_basic(&dict, "Type",
1754                                         DBUS_TYPE_STRING, &provider->type);
1755
1756         if (provider->name)
1757                 connman_dbus_dict_append_basic(&dict, "Name",
1758                                         DBUS_TYPE_STRING, &provider->name);
1759
1760         if (provider->host)
1761                 connman_dbus_dict_append_basic(&dict, "Host",
1762                                         DBUS_TYPE_STRING, &provider->host);
1763         if (provider->index >= 0)
1764                 connman_dbus_dict_append_basic(&dict, "Index",
1765                                         DBUS_TYPE_INT32, &provider->index);
1766         if (provider->domain)
1767                 connman_dbus_dict_append_basic(&dict, "Domain",
1768                                         DBUS_TYPE_STRING, &provider->domain);
1769
1770         immutable = provider->immutable;
1771         connman_dbus_dict_append_basic(&dict, "Immutable", DBUS_TYPE_BOOLEAN,
1772                                         &immutable);
1773
1774         split_routing = provider->do_split_routing;
1775         connman_dbus_dict_append_basic(&dict, "SplitRouting",
1776                                         DBUS_TYPE_BOOLEAN, &split_routing);
1777
1778         if (provider->family == AF_INET)
1779                 connman_dbus_dict_append_dict(&dict, "IPv4", append_ipv4,
1780                                                 provider);
1781         else if (provider->family == AF_INET6)
1782                 connman_dbus_dict_append_dict(&dict, "IPv6", append_ipv6,
1783                                                 provider);
1784
1785         connman_dbus_dict_append_array(&dict, "Nameservers",
1786                                 DBUS_TYPE_STRING, append_dns, provider);
1787
1788         connman_dbus_dict_append_array(&dict, "UserRoutes",
1789                                 DBUS_TYPE_DICT_ENTRY, append_routes,
1790                                 provider->user_routes);
1791
1792         connman_dbus_dict_append_array(&dict, "ServerRoutes",
1793                                 DBUS_TYPE_DICT_ENTRY, append_routes,
1794                                 provider->routes);
1795
1796         if (provider->setting_strings) {
1797                 g_hash_table_iter_init(&hash, provider->setting_strings);
1798
1799                 while (g_hash_table_iter_next(&hash, &key, &value)) {
1800                         struct vpn_setting *setting = value;
1801
1802                         if (!setting->hide_value && setting->value)
1803                                 connman_dbus_dict_append_basic(&dict, key,
1804                                                         DBUS_TYPE_STRING,
1805                                                         &setting->value);
1806                 }
1807         }
1808
1809         connman_dbus_dict_close(iter, &dict);
1810 }
1811
1812 static void connection_added_signal(struct vpn_provider *provider)
1813 {
1814         DBusMessage *signal;
1815         DBusMessageIter iter;
1816
1817         signal = dbus_message_new_signal(VPN_MANAGER_PATH,
1818                         VPN_MANAGER_INTERFACE, "ConnectionAdded");
1819         if (!signal)
1820                 return;
1821
1822         dbus_message_iter_init_append(signal, &iter);
1823         dbus_message_iter_append_basic(&iter, DBUS_TYPE_OBJECT_PATH,
1824                                                         &provider->path);
1825         append_properties(&iter, provider);
1826
1827         dbus_connection_send(connection, signal, NULL);
1828         dbus_message_unref(signal);
1829 }
1830
1831 static int set_connected(struct vpn_provider *provider,
1832                                         bool connected)
1833 {
1834         struct vpn_ipconfig *ipconfig;
1835
1836         DBG("provider %p id %s connected %d", provider,
1837                                         provider->identifier, connected);
1838
1839         if (connected) {
1840                 if (provider->family == AF_INET6)
1841                         ipconfig = provider->ipconfig_ipv6;
1842                 else
1843                         ipconfig = provider->ipconfig_ipv4;
1844
1845                 __vpn_ipconfig_address_add(ipconfig, provider->family);
1846
1847                 provider_indicate_state(provider,
1848                                         VPN_PROVIDER_STATE_READY);
1849         } else {
1850                 provider_indicate_state(provider,
1851                                         VPN_PROVIDER_STATE_DISCONNECT);
1852
1853                 provider_indicate_state(provider,
1854                                         VPN_PROVIDER_STATE_IDLE);
1855         }
1856
1857         return 0;
1858 }
1859
1860 int vpn_provider_set_state(struct vpn_provider *provider,
1861                                         enum vpn_provider_state state)
1862 {
1863         if (!provider)
1864                 return -EINVAL;
1865
1866         switch (state) {
1867         case VPN_PROVIDER_STATE_UNKNOWN:
1868                 return -EINVAL;
1869         case VPN_PROVIDER_STATE_IDLE:
1870                 return set_connected(provider, false);
1871         case VPN_PROVIDER_STATE_CONNECT:
1872                 return provider_indicate_state(provider, state);
1873         case VPN_PROVIDER_STATE_READY:
1874                 return set_connected(provider, true);
1875         case VPN_PROVIDER_STATE_DISCONNECT:
1876                 return provider_indicate_state(provider, state);
1877         case VPN_PROVIDER_STATE_FAILURE:
1878                 return provider_indicate_state(provider, state);
1879         }
1880         return -EINVAL;
1881 }
1882
1883 void vpn_provider_add_error(struct vpn_provider *provider,
1884                         enum vpn_provider_error error)
1885 {
1886         switch (error) {
1887         case VPN_PROVIDER_ERROR_UNKNOWN:
1888                 break;
1889         case VPN_PROVIDER_ERROR_CONNECT_FAILED:
1890                 ++provider->conn_error_counter;
1891                 break;
1892         case VPN_PROVIDER_ERROR_LOGIN_FAILED:
1893         case VPN_PROVIDER_ERROR_AUTH_FAILED:
1894                 ++provider->auth_error_counter;
1895                 break;
1896         }
1897 }
1898
1899 int vpn_provider_indicate_error(struct vpn_provider *provider,
1900                                         enum vpn_provider_error error)
1901 {
1902         DBG("provider %p id %s error %d", provider, provider->identifier,
1903                                                                         error);
1904
1905         vpn_provider_set_state(provider, VPN_PROVIDER_STATE_FAILURE);
1906
1907         vpn_provider_add_error(provider, error);
1908
1909         if (provider->driver && provider->driver->set_state)
1910                 provider->driver->set_state(provider, provider->state);
1911
1912         return 0;
1913 }
1914
1915 static gboolean provider_property_changed(DBusConnection *conn,
1916                                         DBusMessage *message, void *user_data)
1917 {
1918         DBusMessageIter iter;
1919         DBusMessageIter value;
1920         struct vpn_provider *provider = user_data;
1921         const char *key;
1922
1923         if (!dbus_message_iter_init(message, &iter))
1924                 return TRUE;
1925
1926         dbus_message_iter_get_basic(&iter, &key);
1927
1928         dbus_message_iter_next(&iter);
1929         dbus_message_iter_recurse(&iter, &value);
1930
1931         DBG("provider %p key %s", provider, key);
1932
1933         if (g_str_equal(key, "SplitRouting")) {
1934                 dbus_bool_t split_routing;
1935
1936                 if (dbus_message_iter_get_arg_type(&value) !=
1937                                                         DBUS_TYPE_BOOLEAN)
1938                         goto out;
1939
1940                 dbus_message_iter_get_basic(&value, &split_routing);
1941
1942                 DBG("property %s value %s", key, bool2str(split_routing));
1943
1944                 /*
1945                  * Even though this is coming from connmand, signal the value
1946                  * for other components listening to the changes via VPN API
1947                  * only. provider.c will skip setting the same value in order
1948                  * to avoid signaling loop. This is needed for ensuring that
1949                  * all components using VPN API will be informed about the
1950                  * correct status of SplitRouting. Especially when loading the
1951                  * services after a crash, for instance.
1952                  */
1953                 vpn_provider_set_boolean(provider, "SplitRouting",
1954                                         split_routing, true);
1955         }
1956
1957 out:
1958         return TRUE;
1959 }
1960
1961 static int connection_unregister(struct vpn_provider *provider)
1962 {
1963         DBG("provider %p path %s", provider, provider->path);
1964
1965         if (provider->signal_watch) {
1966                 g_dbus_remove_watch(connection, provider->signal_watch);
1967                 provider->signal_watch = 0;
1968         }
1969
1970         if (!provider->path)
1971                 return -EALREADY;
1972
1973         g_dbus_unregister_interface(connection, provider->path,
1974                                 VPN_CONNECTION_INTERFACE);
1975
1976         g_free(provider->path);
1977         provider->path = NULL;
1978
1979         return 0;
1980 }
1981
1982 static int connection_register(struct vpn_provider *provider)
1983 {
1984         char *connmand_vpn_path;
1985
1986         DBG("provider %p path %s", provider, provider->path);
1987
1988         if (provider->path)
1989                 return -EALREADY;
1990
1991         provider->path = g_strdup_printf("%s/connection/%s", VPN_PATH,
1992                                                 provider->identifier);
1993
1994         g_dbus_register_interface(connection, provider->path,
1995                                 VPN_CONNECTION_INTERFACE,
1996                                 connection_methods, connection_signals,
1997                                 NULL, provider, NULL);
1998
1999         connmand_vpn_path = g_strdup_printf("%s/service/vpn_%s", CONNMAN_PATH,
2000                                                 provider->identifier);
2001
2002         provider->signal_watch = g_dbus_add_signal_watch(connection,
2003                                         CONNMAN_SERVICE, connmand_vpn_path,
2004                                         CONNMAN_SERVICE_INTERFACE,
2005                                         PROPERTY_CHANGED,
2006                                         provider_property_changed,
2007                                         provider, NULL);
2008
2009         g_free(connmand_vpn_path);
2010
2011         return 0;
2012 }
2013
2014 static void unregister_provider(gpointer data)
2015 {
2016         struct vpn_provider *provider = data;
2017
2018         configuration_count_del();
2019
2020         connection_unregister(provider);
2021
2022         /* If the provider has any DNS resolver queries pending,
2023          * they need to be cleared here because the unref will not
2024          * be able to do that (because the provider_resolv_host_addr()
2025          * has increased the ref count by 1). This is quite rare as
2026          * normally the resolving either returns a value or has a
2027          * timeout which clears the memory. Typically resolv_result() will
2028          * unref the provider but in this case that call has not yet
2029          * happened.
2030          */
2031         if (provider->resolv)
2032                 vpn_provider_unref(provider);
2033
2034         vpn_provider_unref(provider);
2035 }
2036
2037 static void provider_initialize(struct vpn_provider *provider)
2038 {
2039         DBG("provider %p", provider);
2040
2041         provider->index = 0;
2042         provider->fd = -1;
2043         provider->name = NULL;
2044         provider->type = NULL;
2045         provider->domain = NULL;
2046         provider->identifier = NULL;
2047         provider->immutable = false;
2048         provider->do_split_routing = false;
2049         provider->user_networks = NULL;
2050         provider->routes = g_hash_table_new_full(g_direct_hash, g_direct_equal,
2051                                         NULL, free_route);
2052         provider->user_routes = g_hash_table_new_full(g_str_hash, g_str_equal,
2053                                         g_free, free_route);
2054         provider->setting_strings = g_hash_table_new_full(g_str_hash,
2055                                         g_str_equal, g_free, free_setting);
2056 }
2057
2058 static struct vpn_provider *vpn_provider_new(void)
2059 {
2060         struct vpn_provider *provider;
2061
2062         provider = g_try_new0(struct vpn_provider, 1);
2063         if (!provider)
2064                 return NULL;
2065
2066         provider->refcount = 1;
2067
2068         DBG("provider %p", provider);
2069         provider_initialize(provider);
2070
2071         return provider;
2072 }
2073
2074 static struct vpn_provider *vpn_provider_get(const char *identifier)
2075 {
2076         struct vpn_provider *provider;
2077
2078         provider = g_hash_table_lookup(provider_hash, identifier);
2079         if (provider)
2080                 return provider;
2081
2082         provider = vpn_provider_new();
2083         if (!provider)
2084                 return NULL;
2085
2086         DBG("provider %p", provider);
2087
2088         provider->identifier = g_strdup(identifier);
2089
2090         g_hash_table_insert(provider_hash, provider->identifier, provider);
2091
2092         configuration_count_add();
2093
2094         return provider;
2095 }
2096
2097 static void vpn_provider_put(const char *identifier)
2098 {
2099         configuration_count_del();
2100
2101         g_hash_table_remove(provider_hash, identifier);
2102 }
2103
2104 static void provider_dbus_ident(char *ident)
2105 {
2106         int i, len = strlen(ident);
2107
2108         for (i = 0; i < len; i++) {
2109                 if (ident[i] >= '0' && ident[i] <= '9')
2110                         continue;
2111                 if (ident[i] >= 'a' && ident[i] <= 'z')
2112                         continue;
2113                 if (ident[i] >= 'A' && ident[i] <= 'Z')
2114                         continue;
2115                 ident[i] = '_';
2116         }
2117 }
2118
2119 static struct vpn_provider *provider_create_from_keyfile(GKeyFile *keyfile,
2120                 const char *ident)
2121 {
2122         struct vpn_provider *provider;
2123
2124         if (!keyfile || !ident)
2125                 return NULL;
2126
2127         provider = __vpn_provider_lookup(ident);
2128         if (!provider) {
2129                 provider = vpn_provider_get(ident);
2130                 if (!provider) {
2131                         DBG("can not create provider");
2132                         return NULL;
2133                 }
2134
2135                 provider_load_from_keyfile(provider, keyfile);
2136
2137                 if (!provider->name || !provider->host ||
2138                                 !provider->domain) {
2139                         DBG("cannot get name, host or domain");
2140                         vpn_provider_unref(provider);
2141                         return NULL;
2142                 }
2143
2144                 if (!provider_register(provider)) {
2145                         connection_register(provider);
2146                         connection_added_signal(provider);
2147                 }
2148         }
2149
2150         return provider;
2151 }
2152
2153 static void provider_create_all_from_type(const char *provider_type)
2154 {
2155         unsigned int i;
2156         char **providers;
2157         char *id, *type;
2158         GKeyFile *keyfile;
2159
2160         DBG("provider type %s", provider_type);
2161
2162         providers = __connman_storage_get_providers();
2163
2164         if (!providers)
2165                 return;
2166
2167         for (i = 0; providers[i]; i += 1) {
2168
2169                 if (strncmp(providers[i], "provider_", 9) != 0)
2170                         continue;
2171
2172                 id = providers[i] + 9;
2173                 keyfile = __connman_storage_load_provider(id);
2174
2175                 if (!keyfile)
2176                         continue;
2177
2178                 type = __vpn_config_get_string(keyfile, id, "Type", NULL);
2179
2180                 DBG("keyfile %p id %s type %s", keyfile, id, type);
2181
2182                 if (strcmp(provider_type, type) != 0) {
2183                         g_free(type);
2184                         g_key_file_free(keyfile);
2185                         continue;
2186                 }
2187
2188                 if (!provider_create_from_keyfile(keyfile, id))
2189                         DBG("could not create provider");
2190
2191                 g_free(type);
2192                 g_key_file_free(keyfile);
2193         }
2194         g_strfreev(providers);
2195 }
2196
2197 #if !defined TIZEN_EXT
2198 char *__vpn_provider_create_identifier(const char *host, const char *domain)
2199 {
2200         char *ident;
2201
2202         if (domain)
2203                 ident = g_strdup_printf("%s_%s", host, domain);
2204         else
2205                 ident = g_strdup_printf("%s", host);
2206
2207         provider_dbus_ident(ident);
2208
2209         return ident;
2210 }
2211 #else
2212 char *__vpn_provider_create_identifier(const char *host, const char *domain, const char *name)
2213 {
2214         char *ident;
2215
2216         if (domain)
2217                 ident = g_strdup_printf("%s_%s_%s", host, domain, name);
2218         else
2219                 ident = g_strdup_printf("%s_%s", host, name);
2220         if (!ident)
2221                 return NULL;
2222
2223         provider_dbus_ident(ident);
2224
2225         return ident;
2226 }
2227 #endif
2228
2229 int __vpn_provider_create(DBusMessage *msg)
2230 {
2231         struct vpn_provider *provider;
2232         DBusMessageIter iter, array;
2233         const char *type = NULL, *name = NULL;
2234         const char *host = NULL, *domain = NULL;
2235         GSList *networks = NULL;
2236         char *ident;
2237         int err;
2238         dbus_bool_t split_routing = false;
2239
2240         dbus_message_iter_init(msg, &iter);
2241         dbus_message_iter_recurse(&iter, &array);
2242
2243         while (dbus_message_iter_get_arg_type(&array) == DBUS_TYPE_DICT_ENTRY) {
2244                 DBusMessageIter entry, value;
2245                 const char *key;
2246
2247                 dbus_message_iter_recurse(&array, &entry);
2248                 dbus_message_iter_get_basic(&entry, &key);
2249
2250                 dbus_message_iter_next(&entry);
2251                 dbus_message_iter_recurse(&entry, &value);
2252
2253                 switch (dbus_message_iter_get_arg_type(&value)) {
2254                 case DBUS_TYPE_STRING:
2255                         if (g_str_equal(key, "Type"))
2256                                 dbus_message_iter_get_basic(&value, &type);
2257                         else if (g_str_equal(key, "Name"))
2258                                 dbus_message_iter_get_basic(&value, &name);
2259                         else if (g_str_equal(key, "Host"))
2260                                 dbus_message_iter_get_basic(&value, &host);
2261                         else if (g_str_equal(key, "VPN.Domain") ||
2262                                         g_str_equal(key, "Domain"))
2263                                 dbus_message_iter_get_basic(&value, &domain);
2264                         break;
2265                 case DBUS_TYPE_BOOLEAN:
2266                         if (g_str_equal(key, "SplitRouting"))
2267                                 dbus_message_iter_get_basic(&value,
2268                                                         &split_routing);
2269                         break;
2270                 case DBUS_TYPE_ARRAY:
2271                         if (g_str_equal(key, "UserRoutes"))
2272                                 networks = get_user_networks(&value);
2273                         break;
2274                 }
2275
2276                 dbus_message_iter_next(&array);
2277         }
2278
2279         if (!host)
2280                 return -EINVAL;
2281
2282         DBG("Type %s name %s networks %p", type, name, networks);
2283
2284         if (!type || !name)
2285                 return -EOPNOTSUPP;
2286
2287 #if !defined TIZEN_EXT
2288         ident = __vpn_provider_create_identifier(host, domain);
2289 #else
2290         ident = __vpn_provider_create_identifier(host, domain, name);
2291 #endif
2292         DBG("ident %s", ident);
2293
2294         provider = __vpn_provider_lookup(ident);
2295         if (!provider) {
2296                 provider = vpn_provider_get(ident);
2297                 if (!provider) {
2298                         DBG("can not create provider");
2299                         g_free(ident);
2300                         return -EOPNOTSUPP;
2301                 }
2302
2303                 provider->host = g_strdup(host);
2304                 provider->domain = g_strdup(domain);
2305                 provider->name = g_strdup(name);
2306                 provider->type = g_strdup(type);
2307                 provider->do_split_routing = split_routing;
2308
2309                 if (provider_register(provider) == 0)
2310                         vpn_provider_load(provider);
2311
2312                 provider_resolv_host_addr(provider);
2313         }
2314
2315         if (networks) {
2316                 g_slist_free_full(provider->user_networks, free_route);
2317                 provider->user_networks = networks;
2318                 set_user_networks(provider, provider->user_networks);
2319         }
2320
2321         dbus_message_iter_init(msg, &iter);
2322         dbus_message_iter_recurse(&iter, &array);
2323
2324         while (dbus_message_iter_get_arg_type(&array) == DBUS_TYPE_DICT_ENTRY) {
2325                 DBusMessageIter entry, value;
2326                 const char *key, *str;
2327
2328                 dbus_message_iter_recurse(&array, &entry);
2329                 dbus_message_iter_get_basic(&entry, &key);
2330
2331                 dbus_message_iter_next(&entry);
2332                 dbus_message_iter_recurse(&entry, &value);
2333
2334                 switch (dbus_message_iter_get_arg_type(&value)) {
2335                 case DBUS_TYPE_STRING:
2336                         dbus_message_iter_get_basic(&value, &str);
2337                         vpn_provider_set_string(provider, key, str);
2338                         break;
2339                 }
2340
2341                 dbus_message_iter_next(&array);
2342         }
2343
2344         g_free(ident);
2345
2346         vpn_provider_save(provider);
2347
2348         err = provider_register(provider);
2349         if (err != 0 && err != -EALREADY)
2350                 return err;
2351
2352         connection_register(provider);
2353
2354         DBG("provider %p index %d path %s", provider, provider->index,
2355                                                         provider->path);
2356
2357         g_dbus_send_reply(connection, msg,
2358                                 DBUS_TYPE_OBJECT_PATH, &provider->path,
2359                                 DBUS_TYPE_INVALID);
2360
2361         connection_added_signal(provider);
2362
2363         return 0;
2364 }
2365
2366 static const char *get_string(GHashTable *settings, const char *key)
2367 {
2368         DBG("settings %p key %s", settings, key);
2369
2370         return g_hash_table_lookup(settings, key);
2371 }
2372
2373 static GSList *parse_user_networks(const char *network_str)
2374 {
2375         GSList *networks = NULL;
2376         char **elems;
2377         int i = 0;
2378
2379         if (!network_str)
2380                 return NULL;
2381
2382         elems = g_strsplit(network_str, ",", 0);
2383         if (!elems)
2384                 return NULL;
2385
2386         while (elems[i]) {
2387                 struct vpn_route *vpn_route;
2388                 char *network, *netmask, *gateway;
2389                 int family;
2390                 char **route;
2391
2392                 route = g_strsplit(elems[i], "/", 0);
2393                 if (!route)
2394                         goto next;
2395
2396                 network = route[0];
2397                 if (!network || network[0] == '\0')
2398                         goto next;
2399
2400                 family = connman_inet_check_ipaddress(network);
2401                 if (family < 0) {
2402                         DBG("Cannot get address family of %s (%d/%s)", network,
2403                                 family, gai_strerror(family));
2404
2405                         goto next;
2406                 }
2407
2408                 switch (family) {
2409                 case AF_INET:
2410                         break;
2411                 case AF_INET6:
2412                         break;
2413                 default:
2414                         DBG("Unsupported address family %d", family);
2415                         goto next;
2416                 }
2417
2418                 netmask = route[1];
2419                 if (!netmask || netmask[0] == '\0')
2420                         goto next;
2421
2422                 gateway = route[2];
2423
2424                 vpn_route = g_try_new0(struct vpn_route, 1);
2425                 if (!vpn_route) {
2426                         g_strfreev(route);
2427                         break;
2428                 }
2429
2430                 vpn_route->family = family;
2431                 vpn_route->network = g_strdup(network);
2432                 vpn_route->netmask = g_strdup(netmask);
2433                 vpn_route->gateway = g_strdup(gateway);
2434
2435                 DBG("route %s/%s%s%s", network, netmask,
2436                         gateway ? " via " : "", gateway ? gateway : "");
2437
2438                 networks = g_slist_prepend(networks, vpn_route);
2439
2440         next:
2441                 g_strfreev(route);
2442                 i++;
2443         }
2444
2445         g_strfreev(elems);
2446
2447         return g_slist_reverse(networks);
2448 }
2449
2450 int __vpn_provider_create_from_config(GHashTable *settings,
2451                                 const char *config_ident,
2452                                 const char *config_entry)
2453 {
2454         struct vpn_provider *provider;
2455         const char *type, *name, *host, *domain, *networks_str;
2456         GSList *networks;
2457         char *ident = NULL;
2458         GHashTableIter hash;
2459         gpointer value, key;
2460         int err;
2461
2462         type = get_string(settings, "Type");
2463         name = get_string(settings, "Name");
2464         host = get_string(settings, "Host");
2465         domain = get_string(settings, "Domain");
2466         networks_str = get_string(settings, "Networks");
2467         networks = parse_user_networks(networks_str);
2468
2469         if (!host) {
2470                 err = -EINVAL;
2471                 goto fail;
2472         }
2473
2474         DBG("type %s name %s networks %s", type, name, networks_str);
2475
2476         if (!type || !name) {
2477                 err = -EOPNOTSUPP;
2478                 goto fail;
2479         }
2480
2481 #if !defined TIZEN_EXT
2482         ident = __vpn_provider_create_identifier(host, domain);
2483 #else
2484         ident = __vpn_provider_create_identifier(host, domain, name);
2485 #endif
2486         DBG("ident %s", ident);
2487
2488         provider = __vpn_provider_lookup(ident);
2489         if (!provider) {
2490                 provider = vpn_provider_get(ident);
2491                 if (!provider) {
2492                         DBG("can not create provider");
2493                         err = -EOPNOTSUPP;
2494                         goto fail;
2495                 }
2496
2497                 provider->host = g_strdup(host);
2498                 provider->domain = g_strdup(domain);
2499                 provider->name = g_strdup(name);
2500                 provider->type = g_ascii_strdown(type, -1);
2501
2502                 provider->config_file = g_strdup(config_ident);
2503                 provider->config_entry = g_strdup(config_entry);
2504
2505                 provider_resolv_host_addr(provider);
2506         }
2507
2508         if (networks) {
2509                 g_slist_free_full(provider->user_networks, free_route);
2510                 provider->user_networks = networks;
2511                 set_user_networks(provider, provider->user_networks);
2512         }
2513
2514         g_hash_table_iter_init(&hash, settings);
2515
2516         while (g_hash_table_iter_next(&hash, &key, &value))
2517                 __vpn_provider_set_string_immutable(provider, key, value);
2518
2519         provider->immutable = true;
2520
2521         vpn_provider_save(provider);
2522
2523         err = provider_register(provider);
2524         if (err != 0 && err != -EALREADY)
2525                 goto fail;
2526
2527         connection_register(provider);
2528
2529         DBG("provider %p index %d path %s", provider, provider->index,
2530                                                         provider->path);
2531
2532         connection_added_signal(provider);
2533
2534         g_free(ident);
2535
2536         return 0;
2537
2538 fail:
2539         vpn_provider_put(ident);
2540         g_free(ident);
2541         g_slist_free_full(networks, free_route);
2542
2543         return err;
2544 }
2545
2546 static void append_connection_structs(DBusMessageIter *iter, void *user_data)
2547 {
2548         DBusMessageIter entry;
2549         GHashTableIter hash;
2550         gpointer value, key;
2551
2552         g_hash_table_iter_init(&hash, provider_hash);
2553
2554         while (g_hash_table_iter_next(&hash, &key, &value)) {
2555                 struct vpn_provider *provider = value;
2556
2557 #if defined TIZEN_EXT
2558                 DBG("provider %p", provider);
2559 #else
2560                 DBG("path %s", provider->path);
2561 #endif
2562
2563                 if (!provider->identifier)
2564                         continue;
2565
2566                 dbus_message_iter_open_container(iter, DBUS_TYPE_STRUCT,
2567                                 NULL, &entry);
2568                 dbus_message_iter_append_basic(&entry, DBUS_TYPE_OBJECT_PATH,
2569                                 &provider->path);
2570                 append_properties(&entry, provider);
2571                 dbus_message_iter_close_container(iter, &entry);
2572         }
2573 }
2574
2575 DBusMessage *__vpn_provider_get_connections(DBusMessage *msg)
2576 {
2577         DBusMessage *reply;
2578
2579         DBG("");
2580
2581         reply = dbus_message_new_method_return(msg);
2582         if (!reply)
2583                 return NULL;
2584
2585         __connman_dbus_append_objpath_dict_array(reply,
2586                         append_connection_structs, NULL);
2587
2588         return reply;
2589 }
2590
2591 const char *vpn_provider_get_ident(struct vpn_provider *provider)
2592 {
2593         if (!provider)
2594                 return NULL;
2595
2596         return provider->identifier;
2597 }
2598
2599 static int set_string(struct vpn_provider *provider,
2600                         const char *key, const char *value,
2601                         bool hide_value, bool immutable)
2602 {
2603         DBG("provider %p key %s immutable %s value %s", provider, key,
2604                 immutable ? "yes" : "no",
2605                 hide_value ? "<not printed>" : value);
2606
2607         if (g_str_equal(key, "Type")) {
2608                 if (!g_strcmp0(provider->type, value))
2609                         return -EALREADY;
2610
2611                 g_free(provider->type);
2612                 provider->type = g_ascii_strdown(value, -1);
2613                 send_value(provider->path, "Type", provider->type);
2614         } else if (g_str_equal(key, "Name")) {
2615                 if (!g_strcmp0(provider->name, value))
2616                         return -EALREADY;
2617
2618                 g_free(provider->name);
2619                 provider->name = g_strdup(value);
2620                 send_value(provider->path, "Name", provider->name);
2621         } else if (g_str_equal(key, "Host")) {
2622                 if (!g_strcmp0(provider->host, value))
2623                         return -EALREADY;
2624
2625                 g_free(provider->host);
2626                 provider->host = g_strdup(value);
2627                 send_value(provider->path, "Host", provider->host);
2628         } else if (g_str_equal(key, "VPN.Domain") ||
2629                         g_str_equal(key, "Domain")) {
2630                 if (!g_strcmp0(provider->domain, value))
2631                         return -EALREADY;
2632
2633                 g_free(provider->domain);
2634                 provider->domain = g_strdup(value);
2635                 send_value(provider->path, "Domain", provider->domain);
2636         } else if (g_str_equal(key, "SplitRouting")) {
2637                 connman_warn("VPN SplitRouting value attempted to set as "
2638                                         "string, is boolean");
2639                 return -EINVAL;
2640         } else {
2641                 struct vpn_setting *setting;
2642                 bool replace = true;
2643
2644                 setting = g_hash_table_lookup(provider->setting_strings, key);
2645                 if (setting) {
2646                         if (!immutable && setting->immutable) {
2647                                 DBG("Trying to set immutable variable %s", key);
2648                                 return -EPERM;
2649                         } else if (!g_strcmp0(setting->value, value)) {
2650                                 return -EALREADY;
2651                         }
2652
2653                         g_free(setting->value);
2654                         replace = false;
2655                 } else {
2656                         setting = g_try_new0(struct vpn_setting, 1);
2657                         if (!setting)
2658                                 return -ENOMEM;
2659                 }
2660
2661                 setting->value = g_strdup(value);
2662                 setting->hide_value = hide_value;
2663
2664                 if (immutable)
2665                         setting->immutable = true;
2666
2667                 if (!hide_value)
2668                         send_value(provider->path, key, setting->value);
2669
2670                 if (replace)
2671                         g_hash_table_replace(provider->setting_strings,
2672                                                 g_strdup(key), setting);
2673         }
2674
2675         return 0;
2676 }
2677
2678 int vpn_provider_set_string(struct vpn_provider *provider,
2679                                         const char *key, const char *value)
2680 {
2681         return set_string(provider, key, value, false, false);
2682 }
2683
2684 int vpn_provider_set_string_hide_value(struct vpn_provider *provider,
2685                                         const char *key, const char *value)
2686 {
2687         return set_string(provider, key, value, true, false);
2688 }
2689
2690 int __vpn_provider_set_string_immutable(struct vpn_provider *provider,
2691                                         const char *key, const char *value)
2692 {
2693         return set_string(provider, key, value, false, true);
2694 }
2695
2696 const char *vpn_provider_get_string(struct vpn_provider *provider,
2697                                                         const char *key)
2698 {
2699         struct vpn_setting *setting;
2700
2701         DBG("provider %p key %s", provider, key);
2702
2703         if (g_str_equal(key, "Type"))
2704                 return provider->type;
2705         else if (g_str_equal(key, "Name"))
2706                 return provider->name;
2707         else if (g_str_equal(key, "Host"))
2708                 return provider->host;
2709         else if (g_str_equal(key, "HostIP")) {
2710                 if (!provider->host_ip ||
2711                                 !provider->host_ip[0])
2712                         return provider->host;
2713                 else
2714                         return provider->host_ip[0];
2715         } else if (g_str_equal(key, "VPN.Domain") ||
2716                         g_str_equal(key, "Domain"))
2717                 return provider->domain;
2718
2719         setting = g_hash_table_lookup(provider->setting_strings, key);
2720         if (!setting)
2721                 return NULL;
2722
2723         return setting->value;
2724 }
2725
2726 int vpn_provider_set_boolean(struct vpn_provider *provider, const char *key,
2727                                                 bool value, bool force_change)
2728 {
2729         DBG("provider %p key %s", provider, key);
2730
2731         if (g_str_equal(key, "SplitRouting")) {
2732                 if (provider->do_split_routing == value && !force_change)
2733                         return -EALREADY;
2734
2735                 DBG("SplitRouting set to %s", bool2str(value));
2736
2737                 provider->do_split_routing = value;
2738                 send_value_boolean(provider->path, key,
2739                                         provider->do_split_routing);
2740         }
2741
2742         return 0;
2743 }
2744
2745 bool vpn_provider_get_boolean(struct vpn_provider *provider, const char *key,
2746                                                         bool default_value)
2747 {
2748         struct vpn_setting *setting;
2749
2750         connman_info("provider %p key %s", provider, key);
2751
2752         setting = g_hash_table_lookup(provider->setting_strings, key);
2753         if (!setting || !setting->value)
2754                 return default_value;
2755
2756         if (!g_strcmp0(setting->value, "true"))
2757                 return true;
2758
2759         if (!g_strcmp0(setting->value, "false"))
2760                 return false;
2761
2762         return default_value;
2763 }
2764
2765 bool vpn_provider_get_string_immutable(struct vpn_provider *provider,
2766                                                         const char *key)
2767 {
2768         struct vpn_setting *setting;
2769
2770         /* These values can be changed if the provider is not immutable */
2771         if (g_str_equal(key, "Type")) {
2772                 return provider->immutable;
2773         } else if (g_str_equal(key, "Name")) {
2774                 return provider->immutable;
2775         } else if (g_str_equal(key, "Host")) {
2776                 return provider->immutable;
2777         } else if (g_str_equal(key, "HostIP")) {
2778                 return provider->immutable;
2779         } else if (g_str_equal(key, "VPN.Domain") ||
2780                         g_str_equal(key, "Domain")) {
2781                 return provider->immutable;
2782         }
2783
2784         setting = g_hash_table_lookup(provider->setting_strings, key);
2785         if (!setting)
2786                 return true; /* Not found, regard as immutable - no changes */
2787
2788         return setting->immutable;
2789 }
2790
2791 bool __vpn_provider_check_routes(struct vpn_provider *provider)
2792 {
2793         if (!provider)
2794                 return false;
2795
2796         if (provider->user_routes &&
2797                         g_hash_table_size(provider->user_routes) > 0)
2798                 return true;
2799
2800         if (provider->routes &&
2801                         g_hash_table_size(provider->routes) > 0)
2802                 return true;
2803
2804         return false;
2805 }
2806
2807 void *vpn_provider_get_data(struct vpn_provider *provider)
2808 {
2809         return provider->driver_data;
2810 }
2811
2812 void vpn_provider_set_data(struct vpn_provider *provider, void *data)
2813 {
2814         provider->driver_data = data;
2815 }
2816
2817 void *vpn_provider_get_plugin_data(struct vpn_provider *provider)
2818 {
2819 #if defined TIZEN_EXT
2820         if (!provider)
2821                 return NULL;
2822 #endif
2823         return provider->plugin_data;
2824 }
2825
2826 void vpn_provider_set_plugin_data(struct vpn_provider *provider, void *data)
2827 {
2828         provider->plugin_data = data;
2829 }
2830
2831 void vpn_provider_set_index(struct vpn_provider *provider, int index)
2832 {
2833         DBG("index %d provider %p", index, provider);
2834
2835         if (!provider->ipconfig_ipv4) {
2836                 provider->ipconfig_ipv4 = __vpn_ipconfig_create(index,
2837                                                                 AF_INET);
2838                 if (!provider->ipconfig_ipv4) {
2839                         DBG("Couldn't create ipconfig for IPv4");
2840                         goto done;
2841                 }
2842         }
2843
2844         __vpn_ipconfig_set_index(provider->ipconfig_ipv4, index);
2845
2846         if (!provider->ipconfig_ipv6) {
2847                 provider->ipconfig_ipv6 = __vpn_ipconfig_create(index,
2848                                                                 AF_INET6);
2849                 if (!provider->ipconfig_ipv6) {
2850                         DBG("Couldn't create ipconfig for IPv6");
2851                         goto done;
2852                 }
2853         }
2854
2855         __vpn_ipconfig_set_index(provider->ipconfig_ipv6, index);
2856
2857 done:
2858         provider->index = index;
2859 }
2860
2861 int vpn_provider_get_index(struct vpn_provider *provider)
2862 {
2863         return provider->index;
2864 }
2865
2866 int vpn_provider_set_ipaddress(struct vpn_provider *provider,
2867                                         struct connman_ipaddress *ipaddress)
2868 {
2869         struct vpn_ipconfig *ipconfig = NULL;
2870
2871         switch (ipaddress->family) {
2872         case AF_INET:
2873                 ipconfig = provider->ipconfig_ipv4;
2874                 break;
2875         case AF_INET6:
2876                 ipconfig = provider->ipconfig_ipv6;
2877                 break;
2878         default:
2879                 break;
2880         }
2881
2882         DBG("provider %p state %d ipconfig %p family %d", provider,
2883                 provider->state, ipconfig, ipaddress->family);
2884
2885         if (!ipconfig)
2886                 return -EINVAL;
2887
2888         provider->family = ipaddress->family;
2889
2890         if (provider->state == VPN_PROVIDER_STATE_CONNECT ||
2891                         provider->state == VPN_PROVIDER_STATE_READY) {
2892                 struct connman_ipaddress *addr =
2893                                         __vpn_ipconfig_get_address(ipconfig);
2894
2895                 /*
2896                  * Remember the old address so that we can remove it in notify
2897                  * function in plugins/vpn.c if we ever restart
2898                  */
2899                 if (ipaddress->family == AF_INET6) {
2900                         connman_ipaddress_free(provider->prev_ipv6_addr);
2901                         provider->prev_ipv6_addr =
2902                                                 connman_ipaddress_copy(addr);
2903                 } else {
2904                         connman_ipaddress_free(provider->prev_ipv4_addr);
2905                         provider->prev_ipv4_addr =
2906                                                 connman_ipaddress_copy(addr);
2907                 }
2908         }
2909
2910         if (ipaddress->local) {
2911                 __vpn_ipconfig_set_local(ipconfig, ipaddress->local);
2912                 __vpn_ipconfig_set_peer(ipconfig, ipaddress->peer);
2913                 __vpn_ipconfig_set_broadcast(ipconfig, ipaddress->broadcast);
2914                 __vpn_ipconfig_set_gateway(ipconfig, ipaddress->gateway);
2915                 __vpn_ipconfig_set_prefixlen(ipconfig, ipaddress->prefixlen);
2916         }
2917
2918         return 0;
2919 }
2920
2921 int vpn_provider_set_pac(struct vpn_provider *provider,
2922                                 const char *pac)
2923 {
2924         DBG("provider %p pac %s", provider, pac);
2925
2926         return 0;
2927 }
2928
2929
2930 int vpn_provider_set_domain(struct vpn_provider *provider,
2931                                         const char *domain)
2932 {
2933         DBG("provider %p domain %s", provider, domain);
2934
2935         g_free(provider->domain);
2936         provider->domain = g_strdup(domain);
2937
2938         return 0;
2939 }
2940
2941 int vpn_provider_set_nameservers(struct vpn_provider *provider,
2942                                         const char *nameservers)
2943 {
2944         DBG("provider %p nameservers %s", provider, nameservers);
2945
2946         g_strfreev(provider->nameservers);
2947         provider->nameservers = NULL;
2948
2949         if (!nameservers)
2950                 return 0;
2951
2952         provider->nameservers = g_strsplit_set(nameservers, ", ", 0);
2953
2954         return 0;
2955 }
2956
2957 static int route_env_parse(struct vpn_provider *provider, const char *key,
2958                                 int *family, unsigned long *idx,
2959                                 enum vpn_provider_route_type *type)
2960 {
2961         if (!provider)
2962                 return -EINVAL;
2963
2964         DBG("name %s", provider->name);
2965
2966         if (provider->driver && provider->driver->route_env_parse)
2967                 return provider->driver->route_env_parse(provider, key, family, idx,
2968                                 type);
2969
2970         return 0;
2971 }
2972
2973 int vpn_provider_append_route(struct vpn_provider *provider,
2974                                         const char *key, const char *value)
2975 {
2976         struct vpn_route *route;
2977         int ret, family = 0;
2978         unsigned long idx = 0;
2979         enum vpn_provider_route_type type = VPN_PROVIDER_ROUTE_TYPE_NONE;
2980
2981         DBG("key %s value %s", key, value);
2982
2983         ret = route_env_parse(provider, key, &family, &idx, &type);
2984         if (ret < 0)
2985                 return ret;
2986
2987         DBG("idx %lu family %d type %d", idx, family, type);
2988
2989         route = g_hash_table_lookup(provider->routes, GINT_TO_POINTER(idx));
2990         if (!route) {
2991                 route = g_try_new0(struct vpn_route, 1);
2992                 if (!route) {
2993                         connman_error("out of memory");
2994                         return -ENOMEM;
2995                 }
2996
2997                 route->family = family;
2998
2999                 g_hash_table_replace(provider->routes, GINT_TO_POINTER(idx),
3000                                                 route);
3001         }
3002
3003         switch (type) {
3004         case VPN_PROVIDER_ROUTE_TYPE_NONE:
3005                 break;
3006         case VPN_PROVIDER_ROUTE_TYPE_MASK:
3007                 route->netmask = g_strdup(value);
3008                 break;
3009         case VPN_PROVIDER_ROUTE_TYPE_ADDR:
3010                 route->network = g_strdup(value);
3011                 break;
3012         case VPN_PROVIDER_ROUTE_TYPE_GW:
3013                 route->gateway = g_strdup(value);
3014                 break;
3015         }
3016
3017         if (route->netmask && route->gateway && route->network)
3018                 provider_schedule_changed(provider);
3019
3020         return 0;
3021 }
3022
3023 const char *vpn_provider_get_driver_name(struct vpn_provider *provider)
3024 {
3025         if (!provider->driver)
3026                 return NULL;
3027
3028         return provider->driver->name;
3029 }
3030
3031 const char *vpn_provider_get_save_group(struct vpn_provider *provider)
3032 {
3033         return provider->identifier;
3034 }
3035
3036 static gint compare_priority(gconstpointer a, gconstpointer b)
3037 {
3038         return 0;
3039 }
3040
3041 static void clean_provider(gpointer key, gpointer value, gpointer user_data)
3042 {
3043         struct vpn_provider *provider = value;
3044
3045         if (provider->driver && provider->driver->remove)
3046                 provider->driver->remove(provider);
3047
3048         connection_unregister(provider);
3049 }
3050
3051 int vpn_provider_driver_register(struct vpn_provider_driver *driver)
3052 {
3053         DBG("driver %p name %s", driver, driver->name);
3054
3055         driver_list = g_slist_insert_sorted(driver_list, driver,
3056                                                         compare_priority);
3057         provider_create_all_from_type(driver->name);
3058         return 0;
3059 }
3060
3061 void vpn_provider_driver_unregister(struct vpn_provider_driver *driver)
3062 {
3063         GHashTableIter iter;
3064         gpointer value, key;
3065
3066         DBG("driver %p name %s", driver, driver->name);
3067
3068         driver_list = g_slist_remove(driver_list, driver);
3069
3070         g_hash_table_iter_init(&iter, provider_hash);
3071         while (g_hash_table_iter_next(&iter, &key, &value)) {
3072                 struct vpn_provider *provider = value;
3073
3074                 if (provider && provider->driver &&
3075                                 g_strcmp0(provider->driver->name,
3076                                                         driver->name) == 0) {
3077                         /*
3078                          * Cancel VPN agent request to avoid segfault at
3079                          * shutdown as the callback, if set can point to a
3080                          * function in the plugin that is to be removed.
3081                          */
3082                         connman_agent_cancel(provider);
3083                         provider->driver = NULL;
3084                 }
3085         }
3086 }
3087
3088 const char *vpn_provider_get_name(struct vpn_provider *provider)
3089 {
3090         return provider->name;
3091 }
3092
3093 const char *vpn_provider_get_host(struct vpn_provider *provider)
3094 {
3095         return provider->host;
3096 }
3097
3098 const char *vpn_provider_get_path(struct vpn_provider *provider)
3099 {
3100         return provider->path;
3101 }
3102
3103 unsigned int vpn_provider_get_authentication_errors(
3104                                                 struct vpn_provider *provider)
3105 {
3106         return provider->auth_error_counter;
3107 }
3108
3109 unsigned int vpn_provider_get_connection_errors(
3110                                                 struct vpn_provider *provider)
3111 {
3112         return provider->conn_error_counter;
3113 }
3114
3115 void vpn_provider_change_address(struct vpn_provider *provider)
3116 {
3117         switch (provider->family) {
3118         case AF_INET:
3119                 connman_inet_set_address(provider->index,
3120                         __vpn_ipconfig_get_address(provider->ipconfig_ipv4));
3121                 break;
3122         case AF_INET6:
3123                 connman_inet_set_ipv6_address(provider->index,
3124                         __vpn_ipconfig_get_address(provider->ipconfig_ipv6));
3125                 break;
3126         default:
3127                 break;
3128         }
3129 }
3130
3131 void vpn_provider_clear_address(struct vpn_provider *provider, int family)
3132 {
3133         const char *address;
3134         unsigned char len;
3135
3136         DBG("provider %p family %d ipv4 %p ipv6 %p", provider, family,
3137                 provider->prev_ipv4_addr, provider->prev_ipv6_addr);
3138
3139         switch (family) {
3140         case AF_INET:
3141                 if (provider->prev_ipv4_addr) {
3142                         connman_ipaddress_get_ip(provider->prev_ipv4_addr,
3143                                                 &address, &len);
3144
3145                         DBG("ipv4 %s/%d", address, len);
3146
3147                         connman_inet_clear_address(provider->index,
3148                                         provider->prev_ipv4_addr);
3149                         connman_ipaddress_free(provider->prev_ipv4_addr);
3150                         provider->prev_ipv4_addr = NULL;
3151                 }
3152                 break;
3153         case AF_INET6:
3154                 if (provider->prev_ipv6_addr) {
3155                         connman_ipaddress_get_ip(provider->prev_ipv6_addr,
3156                                                 &address, &len);
3157
3158                         DBG("ipv6 %s/%d", address, len);
3159
3160                         connman_inet_clear_ipv6_address(provider->index,
3161                                                 provider->prev_ipv6_addr);
3162
3163                         connman_ipaddress_free(provider->prev_ipv6_addr);
3164                         provider->prev_ipv6_addr = NULL;
3165                 }
3166                 break;
3167         default:
3168                 break;
3169         }
3170 }
3171
3172 static int agent_probe(struct connman_agent *agent)
3173 {
3174         DBG("agent %p", agent);
3175         return 0;
3176 }
3177
3178 static void agent_remove(struct connman_agent *agent)
3179 {
3180         DBG("agent %p", agent);
3181 }
3182
3183 static struct connman_agent_driver agent_driver = {
3184         .name           = "vpn",
3185         .interface      = VPN_AGENT_INTERFACE,
3186         .probe          = agent_probe,
3187         .remove         = agent_remove,
3188 };
3189
3190 static void remove_unprovisioned_providers(void)
3191 {
3192         gchar **providers;
3193         GKeyFile *keyfile, *configkeyfile;
3194         char *file, *section;
3195         int i = 0;
3196
3197         providers = __connman_storage_get_providers();
3198         if (!providers)
3199                 return;
3200
3201         for (; providers[i]; i++) {
3202                 char *group = providers[i] + sizeof("provider_") - 1;
3203                 file = section = NULL;
3204                 keyfile = configkeyfile = NULL;
3205
3206                 keyfile = __connman_storage_load_provider(group);
3207                 if (!keyfile)
3208                         continue;
3209
3210                 file = __vpn_config_get_string(keyfile, group,
3211                                         "Config.file", NULL);
3212                 if (!file)
3213                         goto next;
3214
3215                 section = __vpn_config_get_string(keyfile, group,
3216                                         "Config.ident", NULL);
3217                 if (!section)
3218                         goto next;
3219
3220                 configkeyfile = __connman_storage_load_provider_config(file);
3221                 if (!configkeyfile) {
3222                         /*
3223                          * Config file is missing, remove the provisioned
3224                          * service.
3225                          */
3226                         __connman_storage_remove_provider(group);
3227                         goto next;
3228                 }
3229
3230                 if (!g_key_file_has_group(configkeyfile, section))
3231                         /*
3232                          * Config section is missing, remove the provisioned
3233                          * service.
3234                          */
3235                         __connman_storage_remove_provider(group);
3236
3237         next:
3238                 if (keyfile)
3239                         g_key_file_free(keyfile);
3240
3241                 if (configkeyfile)
3242                         g_key_file_free(configkeyfile);
3243
3244                 g_free(section);
3245                 g_free(file);
3246         }
3247
3248         g_strfreev(providers);
3249 }
3250
3251 int __vpn_provider_init(void)
3252 {
3253         int err;
3254
3255         DBG("");
3256
3257         err = connman_agent_driver_register(&agent_driver);
3258         if (err < 0) {
3259                 connman_error("Cannot register agent driver for %s",
3260                                                 agent_driver.name);
3261                 return err;
3262         }
3263
3264         connection = connman_dbus_get_connection();
3265
3266         remove_unprovisioned_providers();
3267
3268         provider_hash = g_hash_table_new_full(g_str_hash, g_str_equal,
3269                                                 NULL, unregister_provider);
3270         return 0;
3271 }
3272
3273 void __vpn_provider_cleanup(void)
3274 {
3275         DBG("");
3276
3277         connman_agent_driver_unregister(&agent_driver);
3278
3279         g_hash_table_foreach(provider_hash, clean_provider, NULL);
3280
3281         g_hash_table_destroy(provider_hash);
3282         provider_hash = NULL;
3283
3284         dbus_connection_unref(connection);
3285 }