Merge "Modified logic to process each VSIE of all vendors." into tizen
[platform/upstream/connman.git] / vpn / vpn-provider.c
1 /*
2  *
3  *  ConnMan VPN daemon
4  *
5  *  Copyright (C) 2012-2013  Intel Corporation. All rights reserved.
6  *
7  *  This program is free software; you can redistribute it and/or modify
8  *  it under the terms of the GNU General Public License version 2 as
9  *  published by the Free Software Foundation.
10  *
11  *  This program is distributed in the hope that it will be useful,
12  *  but WITHOUT ANY WARRANTY; without even the implied warranty of
13  *  MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
14  *  GNU General Public License for more details.
15  *
16  *  You should have received a copy of the GNU General Public License
17  *  along with this program; if not, write to the Free Software
18  *  Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA  02110-1301  USA
19  *
20  */
21
22 #ifdef HAVE_CONFIG_H
23 #include <config.h>
24 #endif
25
26 #include <errno.h>
27 #include <stdio.h>
28 #include <string.h>
29 #include <stdlib.h>
30 #include <gdbus.h>
31 #include <connman/log.h>
32 #include <gweb/gresolv.h>
33 #include <netdb.h>
34
35 #include "../src/connman.h"
36 #include "connman/agent.h"
37 #include "connman/vpn-dbus.h"
38 #include "vpn-provider.h"
39 #include "vpn.h"
40
41 static DBusConnection *connection;
42 static GHashTable *provider_hash;
43 static GSList *driver_list;
44 static int configuration_count;
45 static bool handle_routes;
46
47 struct vpn_route {
48         int family;
49         char *network;
50         char *netmask;
51         char *gateway;
52 };
53
54 struct vpn_setting {
55         bool hide_value;
56         bool immutable;
57         char *value;
58 };
59
60 struct vpn_provider {
61         int refcount;
62         int index;
63         int fd;
64         enum vpn_provider_state state;
65         char *path;
66         char *identifier;
67         char *name;
68         char *type;
69         char *host;
70         char *domain;
71         int family;
72         GHashTable *routes;
73         struct vpn_provider_driver *driver;
74         void *driver_data;
75         GHashTable *setting_strings;
76         GHashTable *user_routes;
77         GSList *user_networks;
78         GResolv *resolv;
79         char **host_ip;
80         struct vpn_ipconfig *ipconfig_ipv4;
81         struct vpn_ipconfig *ipconfig_ipv6;
82         char **nameservers;
83         guint notify_id;
84         char *config_file;
85         char *config_entry;
86         bool immutable;
87         struct connman_ipaddress *prev_ipv4_addr;
88         struct connman_ipaddress *prev_ipv6_addr;
89 };
90
91 static void append_properties(DBusMessageIter *iter,
92                                 struct vpn_provider *provider);
93
94 static void free_route(gpointer data)
95 {
96         struct vpn_route *route = data;
97
98         g_free(route->network);
99         g_free(route->netmask);
100         g_free(route->gateway);
101
102         g_free(route);
103 }
104
105 static void free_setting(gpointer data)
106 {
107         struct vpn_setting *setting = data;
108
109         g_free(setting->value);
110         g_free(setting);
111 }
112
113 static void append_route(DBusMessageIter *iter, void *user_data)
114 {
115         struct vpn_route *route = user_data;
116         DBusMessageIter item;
117         int family = 0;
118
119         connman_dbus_dict_open(iter, &item);
120
121         if (!route)
122                 goto empty_dict;
123
124         if (route->family == AF_INET)
125                 family = 4;
126         else if (route->family == AF_INET6)
127                 family = 6;
128
129         if (family != 0)
130                 connman_dbus_dict_append_basic(&item, "ProtocolFamily",
131                                         DBUS_TYPE_INT32, &family);
132
133         if (route->network)
134                 connman_dbus_dict_append_basic(&item, "Network",
135                                         DBUS_TYPE_STRING, &route->network);
136
137         if (route->netmask)
138                 connman_dbus_dict_append_basic(&item, "Netmask",
139                                         DBUS_TYPE_STRING, &route->netmask);
140
141         if (route->gateway)
142                 connman_dbus_dict_append_basic(&item, "Gateway",
143                                         DBUS_TYPE_STRING, &route->gateway);
144
145 empty_dict:
146         connman_dbus_dict_close(iter, &item);
147 }
148
149 static void append_routes(DBusMessageIter *iter, void *user_data)
150 {
151         GHashTable *routes = user_data;
152         GHashTableIter hash;
153         gpointer value, key;
154
155         if (!routes) {
156                 append_route(iter, NULL);
157                 return;
158         }
159
160         g_hash_table_iter_init(&hash, routes);
161
162         while (g_hash_table_iter_next(&hash, &key, &value)) {
163                 DBusMessageIter dict;
164
165                 dbus_message_iter_open_container(iter, DBUS_TYPE_STRUCT, NULL,
166                                                 &dict);
167                 append_route(&dict, value);
168                 dbus_message_iter_close_container(iter, &dict);
169         }
170 }
171
172 static void send_routes(struct vpn_provider *provider, GHashTable *routes,
173                         const char *name)
174 {
175         connman_dbus_property_changed_array(provider->path,
176                                         VPN_CONNECTION_INTERFACE,
177                                         name,
178                                         DBUS_TYPE_DICT_ENTRY,
179                                         append_routes,
180                                         routes);
181 }
182
183 static int provider_routes_changed(struct vpn_provider *provider)
184 {
185         DBG("provider %p", provider);
186
187         send_routes(provider, provider->routes, "ServerRoutes");
188
189         return 0;
190 }
191
192 static GSList *read_route_dict(GSList *routes, DBusMessageIter *dicts)
193 {
194         DBusMessageIter dict, value, entry;
195         const char *network, *netmask, *gateway;
196         struct vpn_route *route;
197         int family, type;
198         const char *key;
199
200         dbus_message_iter_recurse(dicts, &entry);
201
202         network = netmask = gateway = NULL;
203         family = PF_UNSPEC;
204
205         while (dbus_message_iter_get_arg_type(&entry) == DBUS_TYPE_DICT_ENTRY) {
206
207                 dbus_message_iter_recurse(&entry, &dict);
208                 dbus_message_iter_get_basic(&dict, &key);
209
210                 dbus_message_iter_next(&dict);
211                 dbus_message_iter_recurse(&dict, &value);
212
213                 type = dbus_message_iter_get_arg_type(&value);
214
215                 switch (type) {
216                 case DBUS_TYPE_INT32:
217                         if (g_str_equal(key, "ProtocolFamily"))
218                                 dbus_message_iter_get_basic(&value, &family);
219                         break;
220
221                 case DBUS_TYPE_STRING:
222                         if (g_str_equal(key, "Network"))
223                                 dbus_message_iter_get_basic(&value, &network);
224                         else if (g_str_equal(key, "Netmask"))
225                                 dbus_message_iter_get_basic(&value, &netmask);
226                         else if (g_str_equal(key, "Gateway"))
227                                 dbus_message_iter_get_basic(&value, &gateway);
228                         break;
229                 }
230
231                 dbus_message_iter_next(&entry);
232         }
233
234         DBG("family %d network %s netmask %s gateway %s", family,
235                 network, netmask, gateway);
236
237         if (!network || !netmask) {
238                 DBG("Ignoring route as network/netmask is missing");
239                 return routes;
240         }
241
242         route = g_try_new(struct vpn_route, 1);
243         if (!route) {
244                 g_slist_free_full(routes, free_route);
245                 return NULL;
246         }
247
248         if (family == PF_UNSPEC) {
249                 family = connman_inet_check_ipaddress(network);
250                 if (family < 0) {
251                         DBG("Cannot get address family of %s (%d/%s)", network,
252                                 family, gai_strerror(family));
253
254                         g_free(route);
255                         return routes;
256                 }
257         } else {
258                 switch (family) {
259                 case '4':
260                         family = AF_INET;
261                         break;
262                 case '6':
263                         family = AF_INET6;
264                         break;
265                 default:
266                         family = PF_UNSPEC;
267                         break;
268                 }
269         }
270
271         route->family = family;
272         route->network = g_strdup(network);
273         route->netmask = g_strdup(netmask);
274         route->gateway = g_strdup(gateway);
275
276         routes = g_slist_prepend(routes, route);
277         return routes;
278 }
279
280 static GSList *get_user_networks(DBusMessageIter *array)
281 {
282         DBusMessageIter entry;
283         GSList *list = NULL;
284
285         while (dbus_message_iter_get_arg_type(array) == DBUS_TYPE_ARRAY) {
286
287                 dbus_message_iter_recurse(array, &entry);
288
289                 while (dbus_message_iter_get_arg_type(&entry) ==
290                                                         DBUS_TYPE_STRUCT) {
291                         DBusMessageIter dicts;
292
293                         dbus_message_iter_recurse(&entry, &dicts);
294
295                         while (dbus_message_iter_get_arg_type(&dicts) ==
296                                                         DBUS_TYPE_ARRAY) {
297
298                                 list = read_route_dict(list, &dicts);
299                                 dbus_message_iter_next(&dicts);
300                         }
301
302                         dbus_message_iter_next(&entry);
303                 }
304
305                 dbus_message_iter_next(array);
306         }
307
308         return list;
309 }
310
311 static void set_user_networks(struct vpn_provider *provider, GSList *networks)
312 {
313         GSList *list;
314
315         for (list = networks; list; list = g_slist_next(list)) {
316                 struct vpn_route *route = list->data;
317
318                 if (__vpn_provider_append_user_route(provider,
319                                         route->family, route->network,
320                                         route->netmask, route->gateway) != 0)
321                         break;
322         }
323 }
324
325 static void del_routes(struct vpn_provider *provider)
326 {
327         GHashTableIter hash;
328         gpointer value, key;
329
330         g_hash_table_iter_init(&hash, provider->user_routes);
331         while (handle_routes && g_hash_table_iter_next(&hash,
332                                                 &key, &value)) {
333                 struct vpn_route *route = value;
334                 if (route->family == AF_INET6) {
335                         unsigned char prefixlen = atoi(route->netmask);
336                         connman_inet_del_ipv6_network_route(provider->index,
337                                                         route->network,
338                                                         prefixlen);
339                 } else
340                         connman_inet_del_host_route(provider->index,
341                                                 route->network);
342         }
343
344         g_hash_table_remove_all(provider->user_routes);
345         g_slist_free_full(provider->user_networks, free_route);
346         provider->user_networks = NULL;
347 }
348
349 static void send_value(const char *path, const char *key, const char *value)
350 {
351         const char *empty = "";
352         const char *str;
353
354         if (value)
355                 str = value;
356         else
357                 str = empty;
358
359         connman_dbus_property_changed_basic(path,
360                                         VPN_CONNECTION_INTERFACE,
361                                         key,
362                                         DBUS_TYPE_STRING,
363                                         &str);
364 }
365
366 static gboolean provider_send_changed(gpointer data)
367 {
368         struct vpn_provider *provider = data;
369
370         provider_routes_changed(provider);
371
372         provider->notify_id = 0;
373
374         return FALSE;
375 }
376
377 static void provider_schedule_changed(struct vpn_provider *provider)
378 {
379         if (provider->notify_id != 0)
380                 g_source_remove(provider->notify_id);
381
382         provider->notify_id = g_timeout_add(100, provider_send_changed,
383                                                                 provider);
384 }
385
386 static DBusMessage *get_properties(DBusConnection *conn,
387                                         DBusMessage *msg, void *data)
388 {
389         struct vpn_provider *provider = data;
390         DBusMessage *reply;
391         DBusMessageIter array;
392
393         DBG("provider %p", provider);
394
395         reply = dbus_message_new_method_return(msg);
396         if (!reply)
397                 return NULL;
398
399         dbus_message_iter_init_append(reply, &array);
400
401         append_properties(&array, provider);
402
403         return reply;
404 }
405
406 static DBusMessage *set_property(DBusConnection *conn, DBusMessage *msg,
407                                                                 void *data)
408 {
409         struct vpn_provider *provider = data;
410         DBusMessageIter iter, value;
411         const char *name;
412         int type;
413
414         DBG("conn %p", conn);
415
416         if (provider->immutable)
417                 return __connman_error_not_supported(msg);
418
419         if (!dbus_message_iter_init(msg, &iter))
420                 return __connman_error_invalid_arguments(msg);
421
422         if (dbus_message_iter_get_arg_type(&iter) != DBUS_TYPE_STRING)
423                 return __connman_error_invalid_arguments(msg);
424
425         dbus_message_iter_get_basic(&iter, &name);
426         dbus_message_iter_next(&iter);
427
428         if (dbus_message_iter_get_arg_type(&iter) != DBUS_TYPE_VARIANT)
429                 return __connman_error_invalid_arguments(msg);
430
431         dbus_message_iter_recurse(&iter, &value);
432
433         type = dbus_message_iter_get_arg_type(&value);
434
435         if (g_str_equal(name, "UserRoutes")) {
436                 GSList *networks;
437
438                 if (type != DBUS_TYPE_ARRAY)
439                         return __connman_error_invalid_arguments(msg);
440
441                 networks = get_user_networks(&value);
442                 if (networks) {
443                         del_routes(provider);
444                         provider->user_networks = networks;
445                         set_user_networks(provider, provider->user_networks);
446
447                         if (!handle_routes)
448                                 send_routes(provider, provider->user_routes,
449                                                                 "UserRoutes");
450                 }
451         } else {
452                 const char *str;
453
454                 dbus_message_iter_get_basic(&value, &str);
455                 vpn_provider_set_string(provider, name, str);
456         }
457
458         return g_dbus_create_reply(msg, DBUS_TYPE_INVALID);
459 }
460
461 static DBusMessage *clear_property(DBusConnection *conn, DBusMessage *msg,
462                                                                 void *data)
463 {
464         struct vpn_provider *provider = data;
465         const char *name;
466
467         DBG("conn %p", conn);
468
469         if (provider->immutable)
470                 return __connman_error_not_supported(msg);
471
472         dbus_message_get_args(msg, NULL, DBUS_TYPE_STRING, &name,
473                                                         DBUS_TYPE_INVALID);
474
475         if (g_str_equal(name, "UserRoutes")) {
476                 del_routes(provider);
477
478                 if (!handle_routes)
479                         send_routes(provider, provider->user_routes, name);
480         } else if (vpn_provider_get_string(provider, name)) {
481                 vpn_provider_set_string(provider, name, NULL);
482         } else {
483                 return __connman_error_invalid_property(msg);
484         }
485
486         return g_dbus_create_reply(msg, DBUS_TYPE_INVALID);
487 }
488
489 static DBusMessage *do_connect(DBusConnection *conn, DBusMessage *msg,
490                                                                 void *data)
491 {
492         struct vpn_provider *provider = data;
493         int err;
494
495         DBG("conn %p provider %p", conn, provider);
496
497         err = __vpn_provider_connect(provider, msg);
498         if (err < 0)
499                 return __connman_error_failed(msg, -err);
500
501         return NULL;
502 }
503
504 static DBusMessage *do_disconnect(DBusConnection *conn, DBusMessage *msg,
505                                                                 void *data)
506 {
507         struct vpn_provider *provider = data;
508         int err;
509
510         DBG("conn %p provider %p", conn, provider);
511
512         err = __vpn_provider_disconnect(provider);
513         if (err < 0 && err != -EINPROGRESS)
514                 return __connman_error_failed(msg, -err);
515
516         return g_dbus_create_reply(msg, DBUS_TYPE_INVALID);
517 }
518
519 static const GDBusMethodTable connection_methods[] = {
520         { GDBUS_METHOD("GetProperties",
521                         NULL, GDBUS_ARGS({ "properties", "a{sv}" }),
522                         get_properties) },
523         { GDBUS_METHOD("SetProperty",
524                         GDBUS_ARGS({ "name", "s" }, { "value", "v" }),
525                         NULL, set_property) },
526         { GDBUS_METHOD("ClearProperty",
527                         GDBUS_ARGS({ "name", "s" }), NULL,
528                         clear_property) },
529         { GDBUS_ASYNC_METHOD("Connect", NULL, NULL, do_connect) },
530         { GDBUS_METHOD("Disconnect", NULL, NULL, do_disconnect) },
531         { },
532 };
533
534 static const GDBusSignalTable connection_signals[] = {
535         { GDBUS_SIGNAL("PropertyChanged",
536                         GDBUS_ARGS({ "name", "s" }, { "value", "v" })) },
537         { },
538 };
539
540 static void resolv_result(GResolvResultStatus status,
541                                         char **results, gpointer user_data)
542 {
543         struct vpn_provider *provider = user_data;
544
545         DBG("status %d", status);
546
547         if (status == G_RESOLV_RESULT_STATUS_SUCCESS && results &&
548                                                 g_strv_length(results) > 0)
549                 provider->host_ip = g_strdupv(results);
550
551         vpn_provider_unref(provider);
552 }
553
554 static void provider_resolv_host_addr(struct vpn_provider *provider)
555 {
556         if (!provider->host)
557                 return;
558
559         if (connman_inet_check_ipaddress(provider->host) > 0)
560                 return;
561
562         if (provider->host_ip)
563                 return;
564
565         /*
566          * If the hostname is not numeric, try to resolv it. We do not wait
567          * the result as it might take some time. We will get the result
568          * before VPN will feed routes to us because VPN client will need
569          * the IP address also before VPN connection can be established.
570          */
571         provider->resolv = g_resolv_new(0);
572         if (!provider->resolv) {
573                 DBG("Cannot resolv %s", provider->host);
574                 return;
575         }
576
577         DBG("Trying to resolv %s", provider->host);
578
579         vpn_provider_ref(provider);
580
581         g_resolv_lookup_hostname(provider->resolv, provider->host,
582                                 resolv_result, provider);
583 }
584
585 void __vpn_provider_append_properties(struct vpn_provider *provider,
586                                                         DBusMessageIter *iter)
587 {
588         if (provider->host)
589                 connman_dbus_dict_append_basic(iter, "Host",
590                                         DBUS_TYPE_STRING, &provider->host);
591
592         if (provider->domain)
593                 connman_dbus_dict_append_basic(iter, "Domain",
594                                         DBUS_TYPE_STRING, &provider->domain);
595
596         if (provider->type)
597                 connman_dbus_dict_append_basic(iter, "Type", DBUS_TYPE_STRING,
598                                                  &provider->type);
599 }
600
601 int __vpn_provider_append_user_route(struct vpn_provider *provider,
602                                 int family, const char *network,
603                                 const char *netmask, const char *gateway)
604 {
605         struct vpn_route *route;
606         char *key = g_strdup_printf("%d/%s/%s/%s", family, network,
607                                 netmask, gateway ? gateway : "");
608
609         DBG("family %d network %s netmask %s gw %s", family, network,
610                                                         netmask, gateway);
611
612         route = g_hash_table_lookup(provider->user_routes, key);
613         if (!route) {
614                 route = g_try_new0(struct vpn_route, 1);
615                 if (!route) {
616                         connman_error("out of memory");
617                         return -ENOMEM;
618                 }
619
620                 route->family = family;
621                 route->network = g_strdup(network);
622                 route->netmask = g_strdup(netmask);
623                 route->gateway = g_strdup(gateway);
624
625                 g_hash_table_replace(provider->user_routes, key, route);
626         } else
627                 g_free(key);
628
629         return 0;
630 }
631
632 static struct vpn_route *get_route(char *route_str)
633 {
634         char **elems = g_strsplit(route_str, "/", 0);
635         char *network, *netmask, *gateway, *family_str;
636         int family = PF_UNSPEC;
637         struct vpn_route *route = NULL;
638
639         if (!elems)
640                 return NULL;
641
642         family_str = elems[0];
643
644         network = elems[1];
645         if (!network || network[0] == '\0')
646                 goto out;
647
648         netmask = elems[2];
649         if (!netmask || netmask[0] == '\0')
650                 goto out;
651
652         gateway = elems[3];
653
654         route = g_try_new0(struct vpn_route, 1);
655         if (!route)
656                 goto out;
657
658         if (family_str[0] == '\0' || atoi(family_str) == 0) {
659                 family = PF_UNSPEC;
660         } else {
661                 switch (family_str[0]) {
662                 case '4':
663                         family = AF_INET;
664                         break;
665                 case '6':
666                         family = AF_INET6;
667                         break;
668                 }
669         }
670
671         if (g_strrstr(network, ":")) {
672                 if (family != PF_UNSPEC && family != AF_INET6)
673                         DBG("You have IPv6 address but you have non IPv6 route");
674         } else if (g_strrstr(network, ".")) {
675                 if (family != PF_UNSPEC && family != AF_INET)
676                         DBG("You have IPv4 address but you have non IPv4 route");
677
678                 if (!g_strrstr(netmask, ".")) {
679                         /* We have netmask length */
680                         in_addr_t addr;
681                         struct in_addr netmask_in;
682                         unsigned char prefix_len = 32;
683
684                         if (netmask) {
685                                 char *ptr;
686                                 long int value = strtol(netmask, &ptr, 10);
687                                 if (ptr != netmask && *ptr == '\0' &&
688                                                                 value <= 32)
689                                         prefix_len = value;
690                         }
691
692                         addr = 0xffffffff << (32 - prefix_len);
693                         netmask_in.s_addr = htonl(addr);
694                         netmask = inet_ntoa(netmask_in);
695
696                         DBG("network %s netmask %s", network, netmask);
697                 }
698         }
699
700         if (family == PF_UNSPEC) {
701                 family = connman_inet_check_ipaddress(network);
702                 if (family < 0 || family == PF_UNSPEC)
703                         goto out;
704         }
705
706         route->family = family;
707         route->network = g_strdup(network);
708         route->netmask = g_strdup(netmask);
709         route->gateway = g_strdup(gateway);
710
711 out:
712         g_strfreev(elems);
713         return route;
714 }
715
716 static GSList *get_routes(gchar **networks)
717 {
718         struct vpn_route *route;
719         GSList *routes = NULL;
720         int i;
721
722         for (i = 0; networks[i]; i++) {
723                 route = get_route(networks[i]);
724                 if (route)
725                         routes = g_slist_prepend(routes, route);
726         }
727
728         return routes;
729 }
730
731 static int provider_load_from_keyfile(struct vpn_provider *provider,
732                 GKeyFile *keyfile)
733 {
734         gsize idx = 0;
735         gchar **settings;
736         gchar *key, *value;
737         gsize length, num_user_networks;
738         gchar **networks = NULL;
739
740         settings = g_key_file_get_keys(keyfile, provider->identifier, &length,
741                                 NULL);
742         if (!settings) {
743                 g_key_file_free(keyfile);
744                 return -ENOENT;
745         }
746
747         while (idx < length) {
748                 key = settings[idx];
749                 if (key) {
750                         if (g_str_equal(key, "Networks")) {
751                                 networks = __vpn_config_get_string_list(keyfile,
752                                                 provider->identifier,
753                                                 key,
754                                                 &num_user_networks,
755                                                 NULL);
756                                 provider->user_networks = get_routes(networks);
757
758                         } else {
759                                 value = __vpn_config_get_string(keyfile,
760                                                         provider->identifier,
761                                                         key, NULL);
762                                 vpn_provider_set_string(provider, key,
763                                                         value);
764                                 g_free(value);
765                         }
766                 }
767                 idx += 1;
768         }
769         g_strfreev(settings);
770         g_strfreev(networks);
771
772         if (provider->user_networks)
773                 set_user_networks(provider, provider->user_networks);
774
775         return 0;
776 }
777
778
779 static int vpn_provider_load(struct vpn_provider *provider)
780 {
781         GKeyFile *keyfile;
782
783         DBG("provider %p", provider);
784
785         keyfile = __connman_storage_load_provider(provider->identifier);
786         if (!keyfile)
787                 return -ENOENT;
788
789         provider_load_from_keyfile(provider, keyfile);
790
791         g_key_file_free(keyfile);
792         return 0;
793 }
794
795 static gchar **create_network_list(GSList *networks, gsize *count)
796 {
797         GSList *list;
798         gchar **result = NULL;
799         unsigned int num_elems = 0;
800
801         for (list = networks; list; list = g_slist_next(list)) {
802                 struct vpn_route *route = list->data;
803                 int family;
804
805                 result = g_try_realloc(result,
806                                 (num_elems + 1) * sizeof(gchar *));
807                 if (!result)
808                         return NULL;
809
810                 switch (route->family) {
811                 case AF_INET:
812                         family = 4;
813                         break;
814                 case AF_INET6:
815                         family = 6;
816                         break;
817                 default:
818                         family = 0;
819                         break;
820                 }
821
822                 result[num_elems] = g_strdup_printf("%d/%s/%s/%s",
823                                 family, route->network, route->netmask,
824                                 !route->gateway ? "" : route->gateway);
825
826                 num_elems++;
827         }
828
829         result = g_try_realloc(result, (num_elems + 1) * sizeof(gchar *));
830         if (!result)
831                 return NULL;
832
833         result[num_elems] = NULL;
834         *count = num_elems;
835         return result;
836 }
837
838 static int vpn_provider_save(struct vpn_provider *provider)
839 {
840         GKeyFile *keyfile;
841
842         DBG("provider %p immutable %s", provider,
843                                         provider->immutable ? "yes" : "no");
844
845         if (provider->immutable) {
846                 /*
847                  * Do not save providers that are provisioned via .config
848                  * file.
849                  */
850                 return -EPERM;
851         }
852
853         keyfile = g_key_file_new();
854         if (!keyfile)
855                 return -ENOMEM;
856
857         g_key_file_set_string(keyfile, provider->identifier,
858                         "Name", provider->name);
859         g_key_file_set_string(keyfile, provider->identifier,
860                         "Type", provider->type);
861         g_key_file_set_string(keyfile, provider->identifier,
862                         "Host", provider->host);
863         g_key_file_set_string(keyfile, provider->identifier,
864                         "VPN.Domain", provider->domain);
865         if (provider->user_networks) {
866                 gchar **networks;
867                 gsize network_count;
868
869                 networks = create_network_list(provider->user_networks,
870                                                         &network_count);
871                 if (networks) {
872                         g_key_file_set_string_list(keyfile,
873                                                 provider->identifier,
874                                                 "Networks",
875                                                 (const gchar ** const)networks,
876                                                 network_count);
877                         g_strfreev(networks);
878                 }
879         }
880
881         if (provider->config_file && strlen(provider->config_file) > 0)
882                 g_key_file_set_string(keyfile, provider->identifier,
883                                 "Config.file", provider->config_file);
884
885         if (provider->config_entry &&
886                                         strlen(provider->config_entry) > 0)
887                 g_key_file_set_string(keyfile, provider->identifier,
888                                 "Config.ident", provider->config_entry);
889
890         if (provider->driver && provider->driver->save)
891                 provider->driver->save(provider, keyfile);
892
893         __connman_storage_save_provider(keyfile, provider->identifier);
894         g_key_file_free(keyfile);
895
896         return 0;
897 }
898
899 struct vpn_provider *__vpn_provider_lookup(const char *identifier)
900 {
901         struct vpn_provider *provider = NULL;
902
903         provider = g_hash_table_lookup(provider_hash, identifier);
904
905         return provider;
906 }
907
908 static bool match_driver(struct vpn_provider *provider,
909                                 struct vpn_provider_driver *driver)
910 {
911         if (g_strcmp0(driver->name, provider->type) == 0)
912                 return true;
913
914         return false;
915 }
916
917 static int provider_probe(struct vpn_provider *provider)
918 {
919         GSList *list;
920
921         DBG("provider %p driver %p name %s", provider, provider->driver,
922                                                 provider->name);
923
924         if (provider->driver)
925                 return -EALREADY;
926
927         for (list = driver_list; list; list = list->next) {
928                 struct vpn_provider_driver *driver = list->data;
929
930                 if (!match_driver(provider, driver))
931                         continue;
932
933                 DBG("driver %p name %s", driver, driver->name);
934
935                 if (driver->probe && driver->probe(provider) == 0) {
936                         provider->driver = driver;
937                         break;
938                 }
939         }
940
941         if (!provider->driver)
942                 return -ENODEV;
943
944         return 0;
945 }
946
947 static void provider_remove(struct vpn_provider *provider)
948 {
949         if (provider->driver) {
950                 provider->driver->remove(provider);
951                 provider->driver = NULL;
952         }
953 }
954
955 static int provider_register(struct vpn_provider *provider)
956 {
957         return provider_probe(provider);
958 }
959
960 static void provider_unregister(struct vpn_provider *provider)
961 {
962         provider_remove(provider);
963 }
964
965 struct vpn_provider *
966 vpn_provider_ref_debug(struct vpn_provider *provider,
967                         const char *file, int line, const char *caller)
968 {
969         DBG("%p ref %d by %s:%d:%s()", provider, provider->refcount + 1,
970                 file, line, caller);
971
972         __sync_fetch_and_add(&provider->refcount, 1);
973
974         return provider;
975 }
976
977 static void provider_destruct(struct vpn_provider *provider)
978 {
979         DBG("provider %p", provider);
980
981         if (provider->notify_id != 0)
982                 g_source_remove(provider->notify_id);
983
984         g_free(provider->name);
985         g_free(provider->type);
986         g_free(provider->host);
987         g_free(provider->domain);
988         g_free(provider->identifier);
989         g_free(provider->path);
990         g_slist_free_full(provider->user_networks, free_route);
991         g_strfreev(provider->nameservers);
992         g_hash_table_destroy(provider->routes);
993         g_hash_table_destroy(provider->user_routes);
994         g_hash_table_destroy(provider->setting_strings);
995         if (provider->resolv) {
996                 g_resolv_unref(provider->resolv);
997                 provider->resolv = NULL;
998         }
999         __vpn_ipconfig_unref(provider->ipconfig_ipv4);
1000         __vpn_ipconfig_unref(provider->ipconfig_ipv6);
1001
1002         g_strfreev(provider->host_ip);
1003         g_free(provider->config_file);
1004         g_free(provider->config_entry);
1005         connman_ipaddress_free(provider->prev_ipv4_addr);
1006         connman_ipaddress_free(provider->prev_ipv6_addr);
1007         g_free(provider);
1008 }
1009
1010 void vpn_provider_unref_debug(struct vpn_provider *provider,
1011                                 const char *file, int line, const char *caller)
1012 {
1013         DBG("%p ref %d by %s:%d:%s()", provider, provider->refcount - 1,
1014                 file, line, caller);
1015
1016         if (__sync_fetch_and_sub(&provider->refcount, 1) != 1)
1017                 return;
1018
1019         provider_remove(provider);
1020
1021         provider_destruct(provider);
1022 }
1023
1024 static void configuration_count_add(void)
1025 {
1026         DBG("count %d", configuration_count + 1);
1027
1028         __sync_fetch_and_add(&configuration_count, 1);
1029 }
1030
1031 static void configuration_count_del(void)
1032 {
1033         DBG("count %d", configuration_count - 1);
1034
1035         if (__sync_fetch_and_sub(&configuration_count, 1) != 1)
1036                 return;
1037 }
1038
1039 int __vpn_provider_disconnect(struct vpn_provider *provider)
1040 {
1041         int err;
1042
1043         DBG("provider %p", provider);
1044
1045         if (provider->driver && provider->driver->disconnect)
1046                 err = provider->driver->disconnect(provider);
1047         else
1048                 return -EOPNOTSUPP;
1049
1050         if (err == -EINPROGRESS)
1051                 vpn_provider_set_state(provider, VPN_PROVIDER_STATE_CONNECT);
1052
1053         return err;
1054 }
1055
1056 static void connect_cb(struct vpn_provider *provider, void *user_data,
1057                                                                 int error)
1058 {
1059         DBusMessage *pending = user_data;
1060
1061         DBG("provider %p user %p error %d", provider, user_data, error);
1062
1063         if (error != 0) {
1064                 DBusMessage *reply = __connman_error_failed(pending, error);
1065                 if (reply)
1066                         g_dbus_send_message(connection, reply);
1067
1068                 vpn_provider_indicate_error(provider,
1069                                         VPN_PROVIDER_ERROR_CONNECT_FAILED);
1070                 vpn_provider_set_state(provider, VPN_PROVIDER_STATE_FAILURE);
1071         } else
1072                 g_dbus_send_reply(connection, pending, DBUS_TYPE_INVALID);
1073
1074         dbus_message_unref(pending);
1075 }
1076
1077 int __vpn_provider_connect(struct vpn_provider *provider, DBusMessage *msg)
1078 {
1079         int err;
1080
1081         DBG("provider %p", provider);
1082
1083         if (provider->driver && provider->driver->connect) {
1084                 dbus_message_ref(msg);
1085                 err = provider->driver->connect(provider, connect_cb,
1086                                                 dbus_message_get_sender(msg),
1087                                                 msg);
1088         } else
1089                 return -EOPNOTSUPP;
1090
1091         if (err == -EINPROGRESS)
1092                 vpn_provider_set_state(provider, VPN_PROVIDER_STATE_CONNECT);
1093
1094         return err;
1095 }
1096
1097 static void connection_removed_signal(struct vpn_provider *provider)
1098 {
1099         DBusMessage *signal;
1100         DBusMessageIter iter;
1101
1102         signal = dbus_message_new_signal(VPN_MANAGER_PATH,
1103                         VPN_MANAGER_INTERFACE, "ConnectionRemoved");
1104         if (!signal)
1105                 return;
1106
1107         dbus_message_iter_init_append(signal, &iter);
1108         dbus_message_iter_append_basic(&iter, DBUS_TYPE_OBJECT_PATH,
1109                                                         &provider->path);
1110         dbus_connection_send(connection, signal, NULL);
1111         dbus_message_unref(signal);
1112 }
1113
1114 static char *get_ident(const char *path)
1115 {
1116         char *pos;
1117
1118         if (*path != '/')
1119                 return NULL;
1120
1121         pos = strrchr(path, '/');
1122         if (!pos)
1123                 return NULL;
1124
1125         return pos + 1;
1126 }
1127
1128 int __vpn_provider_remove(const char *path)
1129 {
1130         struct vpn_provider *provider;
1131         char *ident;
1132
1133         DBG("path %s", path);
1134
1135         ident = get_ident(path);
1136
1137         provider = __vpn_provider_lookup(ident);
1138         if (provider)
1139                 return __vpn_provider_delete(provider);
1140
1141         return -ENXIO;
1142 }
1143
1144 int __vpn_provider_delete(struct vpn_provider *provider)
1145 {
1146         DBG("Deleting VPN %s", provider->identifier);
1147
1148         connection_removed_signal(provider);
1149
1150         provider_unregister(provider);
1151
1152         __connman_storage_remove_provider(provider->identifier);
1153
1154         g_hash_table_remove(provider_hash, provider->identifier);
1155
1156         return 0;
1157 }
1158
1159 static void append_ipv4(DBusMessageIter *iter, void *user_data)
1160 {
1161         struct vpn_provider *provider = user_data;
1162         const char *address, *gateway, *peer;
1163
1164         address = __vpn_ipconfig_get_local(provider->ipconfig_ipv4);
1165         if (address) {
1166                 in_addr_t addr;
1167                 struct in_addr netmask;
1168                 char *mask;
1169                 int prefixlen;
1170
1171                 prefixlen = __vpn_ipconfig_get_prefixlen(
1172                                                 provider->ipconfig_ipv4);
1173
1174                 addr = 0xffffffff << (32 - prefixlen);
1175                 netmask.s_addr = htonl(addr);
1176                 mask = inet_ntoa(netmask);
1177
1178                 connman_dbus_dict_append_basic(iter, "Address",
1179                                                 DBUS_TYPE_STRING, &address);
1180
1181                 connman_dbus_dict_append_basic(iter, "Netmask",
1182                                                 DBUS_TYPE_STRING, &mask);
1183         }
1184
1185         gateway = __vpn_ipconfig_get_gateway(provider->ipconfig_ipv4);
1186         if (gateway)
1187                 connman_dbus_dict_append_basic(iter, "Gateway",
1188                                                 DBUS_TYPE_STRING, &gateway);
1189
1190         peer = __vpn_ipconfig_get_peer(provider->ipconfig_ipv4);
1191         if (peer)
1192                 connman_dbus_dict_append_basic(iter, "Peer",
1193                                                 DBUS_TYPE_STRING, &peer);
1194 }
1195
1196 static void append_ipv6(DBusMessageIter *iter, void *user_data)
1197 {
1198         struct vpn_provider *provider = user_data;
1199         const char *address, *gateway, *peer;
1200
1201         address = __vpn_ipconfig_get_local(provider->ipconfig_ipv6);
1202         if (address) {
1203                 unsigned char prefixlen;
1204
1205                 connman_dbus_dict_append_basic(iter, "Address",
1206                                                 DBUS_TYPE_STRING, &address);
1207
1208                 prefixlen = __vpn_ipconfig_get_prefixlen(
1209                                                 provider->ipconfig_ipv6);
1210
1211                 connman_dbus_dict_append_basic(iter, "PrefixLength",
1212                                                 DBUS_TYPE_BYTE, &prefixlen);
1213         }
1214
1215         gateway = __vpn_ipconfig_get_gateway(provider->ipconfig_ipv6);
1216         if (gateway)
1217                 connman_dbus_dict_append_basic(iter, "Gateway",
1218                                                 DBUS_TYPE_STRING, &gateway);
1219
1220         peer = __vpn_ipconfig_get_peer(provider->ipconfig_ipv6);
1221         if (peer)
1222                 connman_dbus_dict_append_basic(iter, "Peer",
1223                                                 DBUS_TYPE_STRING, &peer);
1224 }
1225
1226 static const char *state2string(enum vpn_provider_state state)
1227 {
1228         switch (state) {
1229         case VPN_PROVIDER_STATE_UNKNOWN:
1230                 break;
1231         case VPN_PROVIDER_STATE_IDLE:
1232                 return "idle";
1233         case VPN_PROVIDER_STATE_CONNECT:
1234                 return "configuration";
1235         case VPN_PROVIDER_STATE_READY:
1236                 return "ready";
1237         case VPN_PROVIDER_STATE_DISCONNECT:
1238                 return "disconnect";
1239         case VPN_PROVIDER_STATE_FAILURE:
1240                 return "failure";
1241         }
1242
1243         return NULL;
1244 }
1245
1246 static void append_nameservers(DBusMessageIter *iter, char **servers)
1247 {
1248         int i;
1249
1250         DBG("%p", servers);
1251
1252         for (i = 0; servers[i]; i++) {
1253                 DBG("servers[%d] %s", i, servers[i]);
1254                 dbus_message_iter_append_basic(iter,
1255                                         DBUS_TYPE_STRING, &servers[i]);
1256         }
1257 }
1258
1259 static void append_dns(DBusMessageIter *iter, void *user_data)
1260 {
1261         struct vpn_provider *provider = user_data;
1262
1263         if (provider->nameservers)
1264                 append_nameservers(iter, provider->nameservers);
1265 }
1266
1267 static int provider_indicate_state(struct vpn_provider *provider,
1268                                 enum vpn_provider_state state)
1269 {
1270         const char *str;
1271         enum vpn_provider_state old_state;
1272
1273         str = state2string(state);
1274         DBG("provider %p state %s/%d", provider, str, state);
1275         if (!str)
1276                 return -EINVAL;
1277
1278         old_state = provider->state;
1279         provider->state = state;
1280
1281         if (state == VPN_PROVIDER_STATE_READY) {
1282                 connman_dbus_property_changed_basic(provider->path,
1283                                         VPN_CONNECTION_INTERFACE, "Index",
1284                                         DBUS_TYPE_INT32, &provider->index);
1285
1286                 if (provider->family == AF_INET)
1287                         connman_dbus_property_changed_dict(provider->path,
1288                                         VPN_CONNECTION_INTERFACE, "IPv4",
1289                                         append_ipv4, provider);
1290                 else if (provider->family == AF_INET6)
1291                         connman_dbus_property_changed_dict(provider->path,
1292                                         VPN_CONNECTION_INTERFACE, "IPv6",
1293                                         append_ipv6, provider);
1294
1295                 connman_dbus_property_changed_array(provider->path,
1296                                                 VPN_CONNECTION_INTERFACE,
1297                                                 "Nameservers",
1298                                                 DBUS_TYPE_STRING,
1299                                                 append_dns, provider);
1300
1301                 if (provider->domain)
1302                         connman_dbus_property_changed_basic(provider->path,
1303                                                 VPN_CONNECTION_INTERFACE,
1304                                                 "Domain",
1305                                                 DBUS_TYPE_STRING,
1306                                                 &provider->domain);
1307         }
1308
1309         if (old_state != state)
1310                 connman_dbus_property_changed_basic(provider->path,
1311                                         VPN_CONNECTION_INTERFACE, "State",
1312                                         DBUS_TYPE_STRING, &str);
1313
1314         return 0;
1315 }
1316
1317 static void append_state(DBusMessageIter *iter,
1318                                         struct vpn_provider *provider)
1319 {
1320         char *str;
1321
1322         switch (provider->state) {
1323         case VPN_PROVIDER_STATE_UNKNOWN:
1324         case VPN_PROVIDER_STATE_IDLE:
1325                 str = "idle";
1326                 break;
1327         case VPN_PROVIDER_STATE_CONNECT:
1328                 str = "configuration";
1329                 break;
1330         case VPN_PROVIDER_STATE_READY:
1331                 str = "ready";
1332                 break;
1333         case VPN_PROVIDER_STATE_DISCONNECT:
1334                 str = "disconnect";
1335                 break;
1336         case VPN_PROVIDER_STATE_FAILURE:
1337                 str = "failure";
1338                 break;
1339         }
1340
1341         connman_dbus_dict_append_basic(iter, "State",
1342                                 DBUS_TYPE_STRING, &str);
1343 }
1344
1345 static void append_properties(DBusMessageIter *iter,
1346                                         struct vpn_provider *provider)
1347 {
1348         DBusMessageIter dict;
1349         GHashTableIter hash;
1350         gpointer value, key;
1351         dbus_bool_t immutable;
1352
1353         connman_dbus_dict_open(iter, &dict);
1354
1355         append_state(&dict, provider);
1356
1357         if (provider->type)
1358                 connman_dbus_dict_append_basic(&dict, "Type",
1359                                         DBUS_TYPE_STRING, &provider->type);
1360
1361         if (provider->name)
1362                 connman_dbus_dict_append_basic(&dict, "Name",
1363                                         DBUS_TYPE_STRING, &provider->name);
1364
1365         if (provider->host)
1366                 connman_dbus_dict_append_basic(&dict, "Host",
1367                                         DBUS_TYPE_STRING, &provider->host);
1368         if (provider->index >= 0)
1369                 connman_dbus_dict_append_basic(&dict, "Index",
1370                                         DBUS_TYPE_INT32, &provider->index);
1371         if (provider->domain)
1372                 connman_dbus_dict_append_basic(&dict, "Domain",
1373                                         DBUS_TYPE_STRING, &provider->domain);
1374
1375         immutable = provider->immutable;
1376         connman_dbus_dict_append_basic(&dict, "Immutable", DBUS_TYPE_BOOLEAN,
1377                                         &immutable);
1378
1379         if (provider->family == AF_INET)
1380                 connman_dbus_dict_append_dict(&dict, "IPv4", append_ipv4,
1381                                                 provider);
1382         else if (provider->family == AF_INET6)
1383                 connman_dbus_dict_append_dict(&dict, "IPv6", append_ipv6,
1384                                                 provider);
1385
1386         connman_dbus_dict_append_array(&dict, "Nameservers",
1387                                 DBUS_TYPE_STRING, append_dns, provider);
1388
1389         connman_dbus_dict_append_array(&dict, "UserRoutes",
1390                                 DBUS_TYPE_DICT_ENTRY, append_routes,
1391                                 provider->user_routes);
1392
1393         connman_dbus_dict_append_array(&dict, "ServerRoutes",
1394                                 DBUS_TYPE_DICT_ENTRY, append_routes,
1395                                 provider->routes);
1396
1397         if (provider->setting_strings) {
1398                 g_hash_table_iter_init(&hash, provider->setting_strings);
1399
1400                 while (g_hash_table_iter_next(&hash, &key, &value)) {
1401                         struct vpn_setting *setting = value;
1402
1403                         if (!setting->hide_value &&
1404                                                         setting->value)
1405                                 connman_dbus_dict_append_basic(&dict, key,
1406                                                         DBUS_TYPE_STRING,
1407                                                         &setting->value);
1408                 }
1409         }
1410
1411         connman_dbus_dict_close(iter, &dict);
1412 }
1413
1414 static void connection_added_signal(struct vpn_provider *provider)
1415 {
1416         DBusMessage *signal;
1417         DBusMessageIter iter;
1418
1419         signal = dbus_message_new_signal(VPN_MANAGER_PATH,
1420                         VPN_MANAGER_INTERFACE, "ConnectionAdded");
1421         if (!signal)
1422                 return;
1423
1424         dbus_message_iter_init_append(signal, &iter);
1425         dbus_message_iter_append_basic(&iter, DBUS_TYPE_OBJECT_PATH,
1426                                                         &provider->path);
1427         append_properties(&iter, provider);
1428
1429         dbus_connection_send(connection, signal, NULL);
1430         dbus_message_unref(signal);
1431 }
1432
1433 static bool check_host(char **hosts, char *host)
1434 {
1435         int i;
1436
1437         if (!hosts)
1438                 return false;
1439
1440         for (i = 0; hosts[i]; i++) {
1441                 if (g_strcmp0(hosts[i], host) == 0)
1442                         return true;
1443         }
1444
1445         return false;
1446 }
1447
1448 static void provider_append_routes(gpointer key, gpointer value,
1449                                         gpointer user_data)
1450 {
1451         struct vpn_route *route = value;
1452         struct vpn_provider *provider = user_data;
1453         int index = provider->index;
1454
1455         if (!handle_routes)
1456                 return;
1457
1458         /*
1459          * If the VPN administrator/user has given a route to
1460          * VPN server, then we must discard that because the
1461          * server cannot be contacted via VPN tunnel.
1462          */
1463         if (check_host(provider->host_ip, route->network)) {
1464                 DBG("Discarding VPN route to %s via %s at index %d",
1465                         route->network, route->gateway, index);
1466                 return;
1467         }
1468
1469         if (route->family == AF_INET6) {
1470                 unsigned char prefix_len = atoi(route->netmask);
1471
1472                 connman_inet_add_ipv6_network_route(index, route->network,
1473                                                         route->gateway,
1474                                                         prefix_len);
1475         } else {
1476                 connman_inet_add_network_route(index, route->network,
1477                                                 route->gateway,
1478                                                 route->netmask);
1479         }
1480 }
1481
1482 static int set_connected(struct vpn_provider *provider,
1483                                         bool connected)
1484 {
1485         struct vpn_ipconfig *ipconfig;
1486
1487         DBG("provider %p id %s connected %d", provider,
1488                                         provider->identifier, connected);
1489
1490         if (connected) {
1491                 if (provider->family == AF_INET6)
1492                         ipconfig = provider->ipconfig_ipv6;
1493                 else
1494                         ipconfig = provider->ipconfig_ipv4;
1495
1496                 __vpn_ipconfig_address_add(ipconfig, provider->family);
1497
1498                 if (handle_routes)
1499                         __vpn_ipconfig_gateway_add(ipconfig, provider->family);
1500
1501                 provider_indicate_state(provider,
1502                                         VPN_PROVIDER_STATE_READY);
1503
1504                 g_hash_table_foreach(provider->routes, provider_append_routes,
1505                                         provider);
1506
1507                 g_hash_table_foreach(provider->user_routes,
1508                                         provider_append_routes, provider);
1509
1510         } else {
1511                 provider_indicate_state(provider,
1512                                         VPN_PROVIDER_STATE_DISCONNECT);
1513
1514                 provider_indicate_state(provider,
1515                                         VPN_PROVIDER_STATE_IDLE);
1516         }
1517
1518         return 0;
1519 }
1520
1521 int vpn_provider_set_state(struct vpn_provider *provider,
1522                                         enum vpn_provider_state state)
1523 {
1524         if (!provider)
1525                 return -EINVAL;
1526
1527         switch (state) {
1528         case VPN_PROVIDER_STATE_UNKNOWN:
1529                 return -EINVAL;
1530         case VPN_PROVIDER_STATE_IDLE:
1531                 return set_connected(provider, false);
1532         case VPN_PROVIDER_STATE_CONNECT:
1533                 return provider_indicate_state(provider, state);
1534         case VPN_PROVIDER_STATE_READY:
1535                 return set_connected(provider, true);
1536         case VPN_PROVIDER_STATE_DISCONNECT:
1537                 return provider_indicate_state(provider, state);
1538         case VPN_PROVIDER_STATE_FAILURE:
1539                 return provider_indicate_state(provider, state);
1540         }
1541         return -EINVAL;
1542 }
1543
1544 int vpn_provider_indicate_error(struct vpn_provider *provider,
1545                                         enum vpn_provider_error error)
1546 {
1547         DBG("provider %p id %s error %d", provider, provider->identifier,
1548                                                                         error);
1549
1550         vpn_provider_set_state(provider, VPN_PROVIDER_STATE_FAILURE);
1551
1552         switch (error) {
1553         case VPN_PROVIDER_ERROR_UNKNOWN:
1554         case VPN_PROVIDER_ERROR_CONNECT_FAILED:
1555                 break;
1556
1557         case VPN_PROVIDER_ERROR_LOGIN_FAILED:
1558         case VPN_PROVIDER_ERROR_AUTH_FAILED:
1559                 vpn_provider_set_state(provider, VPN_PROVIDER_STATE_IDLE);
1560                 break;
1561         }
1562
1563         return 0;
1564 }
1565
1566 static int connection_unregister(struct vpn_provider *provider)
1567 {
1568         DBG("provider %p path %s", provider, provider->path);
1569
1570         if (!provider->path)
1571                 return -EALREADY;
1572
1573         g_dbus_unregister_interface(connection, provider->path,
1574                                 VPN_CONNECTION_INTERFACE);
1575
1576         g_free(provider->path);
1577         provider->path = NULL;
1578
1579         return 0;
1580 }
1581
1582 static int connection_register(struct vpn_provider *provider)
1583 {
1584         DBG("provider %p path %s", provider, provider->path);
1585
1586         if (provider->path)
1587                 return -EALREADY;
1588
1589         provider->path = g_strdup_printf("%s/connection/%s", VPN_PATH,
1590                                                 provider->identifier);
1591
1592         g_dbus_register_interface(connection, provider->path,
1593                                 VPN_CONNECTION_INTERFACE,
1594                                 connection_methods, connection_signals,
1595                                 NULL, provider, NULL);
1596
1597         return 0;
1598 }
1599
1600 static void unregister_provider(gpointer data)
1601 {
1602         struct vpn_provider *provider = data;
1603
1604         configuration_count_del();
1605
1606         connection_unregister(provider);
1607
1608         vpn_provider_unref(provider);
1609 }
1610
1611 static void provider_initialize(struct vpn_provider *provider)
1612 {
1613         DBG("provider %p", provider);
1614
1615         provider->index = 0;
1616         provider->fd = -1;
1617         provider->name = NULL;
1618         provider->type = NULL;
1619         provider->domain = NULL;
1620         provider->identifier = NULL;
1621         provider->immutable = false;
1622         provider->user_networks = NULL;
1623         provider->routes = g_hash_table_new_full(g_direct_hash, g_direct_equal,
1624                                         NULL, free_route);
1625         provider->user_routes = g_hash_table_new_full(g_str_hash, g_str_equal,
1626                                         g_free, free_route);
1627         provider->setting_strings = g_hash_table_new_full(g_str_hash,
1628                                         g_str_equal, g_free, free_setting);
1629 }
1630
1631 static struct vpn_provider *vpn_provider_new(void)
1632 {
1633         struct vpn_provider *provider;
1634
1635         provider = g_try_new0(struct vpn_provider, 1);
1636         if (!provider)
1637                 return NULL;
1638
1639         provider->refcount = 1;
1640
1641         DBG("provider %p", provider);
1642         provider_initialize(provider);
1643
1644         return provider;
1645 }
1646
1647 static struct vpn_provider *vpn_provider_get(const char *identifier)
1648 {
1649         struct vpn_provider *provider;
1650
1651         provider = g_hash_table_lookup(provider_hash, identifier);
1652         if (provider)
1653                 return provider;
1654
1655         provider = vpn_provider_new();
1656         if (!provider)
1657                 return NULL;
1658
1659         DBG("provider %p", provider);
1660
1661         provider->identifier = g_strdup(identifier);
1662
1663         g_hash_table_insert(provider_hash, provider->identifier, provider);
1664
1665         configuration_count_add();
1666
1667         return provider;
1668 }
1669
1670 static void provider_dbus_ident(char *ident)
1671 {
1672         int i, len = strlen(ident);
1673
1674         for (i = 0; i < len; i++) {
1675                 if (ident[i] >= '0' && ident[i] <= '9')
1676                         continue;
1677                 if (ident[i] >= 'a' && ident[i] <= 'z')
1678                         continue;
1679                 if (ident[i] >= 'A' && ident[i] <= 'Z')
1680                         continue;
1681                 ident[i] = '_';
1682         }
1683 }
1684
1685 static struct vpn_provider *provider_create_from_keyfile(GKeyFile *keyfile,
1686                 const char *ident)
1687 {
1688         struct vpn_provider *provider;
1689
1690         if (!keyfile || !ident)
1691                 return NULL;
1692
1693         provider = __vpn_provider_lookup(ident);
1694         if (!provider) {
1695                 provider = vpn_provider_get(ident);
1696                 if (!provider) {
1697                         DBG("can not create provider");
1698                         return NULL;
1699                 }
1700
1701                 provider_load_from_keyfile(provider, keyfile);
1702
1703                 if (!provider->name || !provider->host ||
1704                                 !provider->domain) {
1705                         DBG("cannot get name, host or domain");
1706                         vpn_provider_unref(provider);
1707                         return NULL;
1708                 }
1709
1710                 if (provider_register(provider) == 0)
1711                         connection_register(provider);
1712         }
1713         return provider;
1714 }
1715
1716 static void provider_create_all_from_type(const char *provider_type)
1717 {
1718         unsigned int i;
1719         char **providers;
1720         char *id, *type;
1721         GKeyFile *keyfile;
1722
1723         DBG("provider type %s", provider_type);
1724
1725         providers = __connman_storage_get_providers();
1726
1727         if (!providers)
1728                 return;
1729
1730         for (i = 0; providers[i]; i += 1) {
1731
1732                 if (strncmp(providers[i], "provider_", 9) != 0)
1733                         continue;
1734
1735                 id = providers[i] + 9;
1736                 keyfile = __connman_storage_load_provider(id);
1737
1738                 if (!keyfile)
1739                         continue;
1740
1741                 type = __vpn_config_get_string(keyfile, id, "Type", NULL);
1742
1743                 DBG("keyfile %p id %s type %s", keyfile, id, type);
1744
1745                 if (strcmp(provider_type, type) != 0) {
1746                         g_free(type);
1747                         g_key_file_free(keyfile);
1748                         continue;
1749                 }
1750
1751                 if (!provider_create_from_keyfile(keyfile, id))
1752                         DBG("could not create provider");
1753
1754                 g_free(type);
1755                 g_key_file_free(keyfile);
1756         }
1757         g_strfreev(providers);
1758 }
1759
1760 #if !defined TIZEN_EXT
1761 char *__vpn_provider_create_identifier(const char *host, const char *domain)
1762 {
1763         char *ident;
1764
1765         ident = g_strdup_printf("%s_%s", host, domain);
1766         if (!ident)
1767                 return NULL;
1768
1769         provider_dbus_ident(ident);
1770
1771         return ident;
1772 }
1773 #else
1774 char *__vpn_provider_create_identifier(const char *host, const char *domain, const char *name)
1775 {
1776         char *ident;
1777
1778         ident = g_strdup_printf("%s_%s_%s", host, domain, name);
1779         if (!ident)
1780                 return NULL;
1781
1782         provider_dbus_ident(ident);
1783
1784         return ident;
1785 }
1786 #endif
1787
1788 int __vpn_provider_create(DBusMessage *msg)
1789 {
1790         struct vpn_provider *provider;
1791         DBusMessageIter iter, array;
1792         const char *type = NULL, *name = NULL;
1793         const char *host = NULL, *domain = NULL;
1794         GSList *networks = NULL;
1795         char *ident;
1796         int err;
1797
1798         dbus_message_iter_init(msg, &iter);
1799         dbus_message_iter_recurse(&iter, &array);
1800
1801         while (dbus_message_iter_get_arg_type(&array) == DBUS_TYPE_DICT_ENTRY) {
1802                 DBusMessageIter entry, value;
1803                 const char *key;
1804
1805                 dbus_message_iter_recurse(&array, &entry);
1806                 dbus_message_iter_get_basic(&entry, &key);
1807
1808                 dbus_message_iter_next(&entry);
1809                 dbus_message_iter_recurse(&entry, &value);
1810
1811                 switch (dbus_message_iter_get_arg_type(&value)) {
1812                 case DBUS_TYPE_STRING:
1813                         if (g_str_equal(key, "Type"))
1814                                 dbus_message_iter_get_basic(&value, &type);
1815                         else if (g_str_equal(key, "Name"))
1816                                 dbus_message_iter_get_basic(&value, &name);
1817                         else if (g_str_equal(key, "Host"))
1818                                 dbus_message_iter_get_basic(&value, &host);
1819                         else if (g_str_equal(key, "VPN.Domain") ||
1820                                         g_str_equal(key, "Domain"))
1821                                 dbus_message_iter_get_basic(&value, &domain);
1822                         break;
1823                 case DBUS_TYPE_ARRAY:
1824                         if (g_str_equal(key, "UserRoutes"))
1825                                 networks = get_user_networks(&value);
1826                         break;
1827                 }
1828
1829                 dbus_message_iter_next(&array);
1830         }
1831
1832         if (!host || !domain)
1833                 return -EINVAL;
1834
1835         DBG("Type %s name %s networks %p", type, name, networks);
1836
1837         if (!type || !name)
1838                 return -EOPNOTSUPP;
1839
1840 #if !defined TIZEN_EXT
1841         ident = __vpn_provider_create_identifier(host, domain);
1842 #else
1843         ident = __vpn_provider_create_identifier(host, domain, name);
1844 #endif
1845         DBG("ident %s", ident);
1846
1847         provider = __vpn_provider_lookup(ident);
1848         if (!provider) {
1849                 provider = vpn_provider_get(ident);
1850                 if (!provider) {
1851                         DBG("can not create provider");
1852                         g_free(ident);
1853                         return -EOPNOTSUPP;
1854                 }
1855
1856                 provider->host = g_strdup(host);
1857                 provider->domain = g_strdup(domain);
1858                 provider->name = g_strdup(name);
1859                 provider->type = g_strdup(type);
1860
1861                 if (provider_register(provider) == 0)
1862                         vpn_provider_load(provider);
1863
1864                 provider_resolv_host_addr(provider);
1865         }
1866
1867         if (networks) {
1868                 g_slist_free_full(provider->user_networks, free_route);
1869                 provider->user_networks = networks;
1870                 set_user_networks(provider, provider->user_networks);
1871         }
1872
1873         dbus_message_iter_init(msg, &iter);
1874         dbus_message_iter_recurse(&iter, &array);
1875
1876         while (dbus_message_iter_get_arg_type(&array) == DBUS_TYPE_DICT_ENTRY) {
1877                 DBusMessageIter entry, value;
1878                 const char *key, *str;
1879
1880                 dbus_message_iter_recurse(&array, &entry);
1881                 dbus_message_iter_get_basic(&entry, &key);
1882
1883                 dbus_message_iter_next(&entry);
1884                 dbus_message_iter_recurse(&entry, &value);
1885
1886                 switch (dbus_message_iter_get_arg_type(&value)) {
1887                 case DBUS_TYPE_STRING:
1888                         dbus_message_iter_get_basic(&value, &str);
1889                         vpn_provider_set_string(provider, key, str);
1890                         break;
1891                 }
1892
1893                 dbus_message_iter_next(&array);
1894         }
1895
1896         g_free(ident);
1897
1898         vpn_provider_save(provider);
1899
1900         err = provider_register(provider);
1901         if (err != 0 && err != -EALREADY)
1902                 return err;
1903
1904         connection_register(provider);
1905
1906         DBG("provider %p index %d path %s", provider, provider->index,
1907                                                         provider->path);
1908
1909         g_dbus_send_reply(connection, msg,
1910                                 DBUS_TYPE_OBJECT_PATH, &provider->path,
1911                                 DBUS_TYPE_INVALID);
1912
1913         connection_added_signal(provider);
1914
1915         return 0;
1916 }
1917
1918 static const char *get_string(GHashTable *settings, const char *key)
1919 {
1920         DBG("settings %p key %s", settings, key);
1921
1922         return g_hash_table_lookup(settings, key);
1923 }
1924
1925 static GSList *parse_user_networks(const char *network_str)
1926 {
1927         GSList *networks = NULL;
1928         char **elems;
1929         int i = 0;
1930
1931         if (!network_str)
1932                 return NULL;
1933
1934         elems = g_strsplit(network_str, ",", 0);
1935         if (!elems)
1936                 return NULL;
1937
1938         while (elems[i]) {
1939                 struct vpn_route *vpn_route;
1940                 char *network, *netmask, *gateway;
1941                 int family;
1942                 char **route;
1943
1944                 route = g_strsplit(elems[i], "/", 0);
1945                 if (!route)
1946                         goto next;
1947
1948                 network = route[0];
1949                 if (!network || network[0] == '\0')
1950                         goto next;
1951
1952                 family = connman_inet_check_ipaddress(network);
1953                 if (family < 0) {
1954                         DBG("Cannot get address family of %s (%d/%s)", network,
1955                                 family, gai_strerror(family));
1956
1957                         goto next;
1958                 }
1959
1960                 switch (family) {
1961                 case AF_INET:
1962                         break;
1963                 case AF_INET6:
1964                         break;
1965                 default:
1966                         DBG("Unsupported address family %d", family);
1967                         goto next;
1968                 }
1969
1970                 netmask = route[1];
1971                 if (!netmask || netmask[0] == '\0')
1972                         goto next;
1973
1974                 gateway = route[2];
1975
1976                 vpn_route = g_try_new0(struct vpn_route, 1);
1977                 if (!vpn_route) {
1978                         g_strfreev(route);
1979                         break;
1980                 }
1981
1982                 vpn_route->family = family;
1983                 vpn_route->network = g_strdup(network);
1984                 vpn_route->netmask = g_strdup(netmask);
1985                 vpn_route->gateway = g_strdup(gateway);
1986
1987                 DBG("route %s/%s%s%s", network, netmask,
1988                         gateway ? " via " : "", gateway ? gateway : "");
1989
1990                 networks = g_slist_prepend(networks, vpn_route);
1991
1992         next:
1993                 g_strfreev(route);
1994                 i++;
1995         }
1996
1997         g_strfreev(elems);
1998
1999         return g_slist_reverse(networks);
2000 }
2001
2002 int __vpn_provider_create_from_config(GHashTable *settings,
2003                                 const char *config_ident,
2004                                 const char *config_entry)
2005 {
2006         struct vpn_provider *provider;
2007         const char *type, *name, *host, *domain, *networks_str;
2008         GSList *networks;
2009         char *ident = NULL;
2010         GHashTableIter hash;
2011         gpointer value, key;
2012         int err;
2013
2014         type = get_string(settings, "Type");
2015         name = get_string(settings, "Name");
2016         host = get_string(settings, "Host");
2017         domain = get_string(settings, "Domain");
2018         networks_str = get_string(settings, "Networks");
2019         networks = parse_user_networks(networks_str);
2020
2021         if (!host || !domain) {
2022                 err = -EINVAL;
2023                 goto fail;
2024         }
2025
2026         DBG("type %s name %s networks %s", type, name, networks_str);
2027
2028         if (!type || !name) {
2029                 err = -EOPNOTSUPP;
2030                 goto fail;
2031         }
2032
2033 #if !defined TIZEN_EXT
2034         ident = __vpn_provider_create_identifier(host, domain);
2035 #else
2036         ident = __vpn_provider_create_identifier(host, domain, name);
2037 #endif
2038         DBG("ident %s", ident);
2039
2040         provider = __vpn_provider_lookup(ident);
2041         if (!provider) {
2042                 provider = vpn_provider_get(ident);
2043                 if (!provider) {
2044                         DBG("can not create provider");
2045                         err = -EOPNOTSUPP;
2046                         goto fail;
2047                 }
2048
2049                 provider->host = g_strdup(host);
2050                 provider->domain = g_strdup(domain);
2051                 provider->name = g_strdup(name);
2052                 provider->type = g_ascii_strdown(type, -1);
2053
2054                 provider->config_file = g_strdup(config_ident);
2055                 provider->config_entry = g_strdup(config_entry);
2056
2057                 provider_register(provider);
2058
2059                 provider_resolv_host_addr(provider);
2060         }
2061
2062         if (networks) {
2063                 g_slist_free_full(provider->user_networks, free_route);
2064                 provider->user_networks = networks;
2065                 set_user_networks(provider, provider->user_networks);
2066         }
2067
2068         g_hash_table_iter_init(&hash, settings);
2069
2070         while (g_hash_table_iter_next(&hash, &key, &value))
2071                 __vpn_provider_set_string_immutable(provider, key, value);
2072
2073         provider->immutable = true;
2074
2075         vpn_provider_save(provider);
2076
2077         err = provider_register(provider);
2078         if (err != 0 && err != -EALREADY)
2079                 goto fail;
2080
2081         connection_register(provider);
2082
2083         DBG("provider %p index %d path %s", provider, provider->index,
2084                                                         provider->path);
2085
2086         connection_added_signal(provider);
2087
2088         g_free(ident);
2089
2090         return 0;
2091
2092 fail:
2093         g_free(ident);
2094         g_slist_free_full(networks, free_route);
2095
2096         return err;
2097 }
2098
2099 static void append_connection_structs(DBusMessageIter *iter, void *user_data)
2100 {
2101         DBusMessageIter entry;
2102         GHashTableIter hash;
2103         gpointer value, key;
2104
2105         g_hash_table_iter_init(&hash, provider_hash);
2106
2107         while (g_hash_table_iter_next(&hash, &key, &value)) {
2108                 struct vpn_provider *provider = value;
2109
2110                 DBG("path %s", provider->path);
2111
2112                 if (!provider->identifier)
2113                         continue;
2114
2115                 dbus_message_iter_open_container(iter, DBUS_TYPE_STRUCT,
2116                                 NULL, &entry);
2117                 dbus_message_iter_append_basic(&entry, DBUS_TYPE_OBJECT_PATH,
2118                                 &provider->path);
2119                 append_properties(&entry, provider);
2120                 dbus_message_iter_close_container(iter, &entry);
2121         }
2122 }
2123
2124 DBusMessage *__vpn_provider_get_connections(DBusMessage *msg)
2125 {
2126         DBusMessage *reply;
2127
2128         DBG("");
2129
2130         reply = dbus_message_new_method_return(msg);
2131         if (!reply)
2132                 return NULL;
2133
2134         __connman_dbus_append_objpath_dict_array(reply,
2135                         append_connection_structs, NULL);
2136
2137         return reply;
2138 }
2139
2140 const char *__vpn_provider_get_ident(struct vpn_provider *provider)
2141 {
2142         if (!provider)
2143                 return NULL;
2144
2145         return provider->identifier;
2146 }
2147
2148 static int set_string(struct vpn_provider *provider,
2149                         const char *key, const char *value,
2150                         bool hide_value, bool immutable)
2151 {
2152         DBG("provider %p key %s immutable %s value %s", provider, key,
2153                 immutable ? "yes" : "no",
2154                 hide_value ? "<not printed>" : value);
2155
2156         if (g_str_equal(key, "Type")) {
2157                 g_free(provider->type);
2158                 provider->type = g_ascii_strdown(value, -1);
2159                 send_value(provider->path, "Type", provider->type);
2160         } else if (g_str_equal(key, "Name")) {
2161                 g_free(provider->name);
2162                 provider->name = g_strdup(value);
2163                 send_value(provider->path, "Name", provider->name);
2164         } else if (g_str_equal(key, "Host")) {
2165                 g_free(provider->host);
2166                 provider->host = g_strdup(value);
2167                 send_value(provider->path, "Host", provider->host);
2168         } else if (g_str_equal(key, "VPN.Domain") ||
2169                         g_str_equal(key, "Domain")) {
2170                 g_free(provider->domain);
2171                 provider->domain = g_strdup(value);
2172                 send_value(provider->path, "Domain", provider->domain);
2173         } else {
2174                 struct vpn_setting *setting;
2175
2176                 setting = g_hash_table_lookup(provider->setting_strings, key);
2177                 if (setting && !immutable &&
2178                                                 setting->immutable) {
2179                         DBG("Trying to set immutable variable %s", key);
2180                         return -EPERM;
2181                 }
2182
2183                 setting = g_try_new0(struct vpn_setting, 1);
2184                 if (!setting)
2185                         return -ENOMEM;
2186
2187                 setting->value = g_strdup(value);
2188                 setting->hide_value = hide_value;
2189
2190                 if (immutable)
2191                         setting->immutable = true;
2192
2193                 if (!hide_value)
2194                         send_value(provider->path, key, setting->value);
2195
2196                 g_hash_table_replace(provider->setting_strings,
2197                                 g_strdup(key), setting);
2198         }
2199
2200         return 0;
2201 }
2202
2203 int vpn_provider_set_string(struct vpn_provider *provider,
2204                                         const char *key, const char *value)
2205 {
2206         return set_string(provider, key, value, false, false);
2207 }
2208
2209 int vpn_provider_set_string_hide_value(struct vpn_provider *provider,
2210                                         const char *key, const char *value)
2211 {
2212         return set_string(provider, key, value, true, false);
2213 }
2214
2215 int __vpn_provider_set_string_immutable(struct vpn_provider *provider,
2216                                         const char *key, const char *value)
2217 {
2218         return set_string(provider, key, value, false, true);
2219 }
2220
2221 const char *vpn_provider_get_string(struct vpn_provider *provider,
2222                                                         const char *key)
2223 {
2224         struct vpn_setting *setting;
2225
2226         DBG("provider %p key %s", provider, key);
2227
2228         if (g_str_equal(key, "Type"))
2229                 return provider->type;
2230         else if (g_str_equal(key, "Name"))
2231                 return provider->name;
2232         else if (g_str_equal(key, "Host"))
2233                 return provider->host;
2234         else if (g_str_equal(key, "HostIP")) {
2235                 if (!provider->host_ip ||
2236                                 !provider->host_ip[0])
2237                         return provider->host;
2238                 else
2239                         return provider->host_ip[0];
2240         } else if (g_str_equal(key, "VPN.Domain") ||
2241                         g_str_equal(key, "Domain"))
2242                 return provider->domain;
2243
2244         setting = g_hash_table_lookup(provider->setting_strings, key);
2245         if (!setting)
2246                 return NULL;
2247
2248         return setting->value;
2249 }
2250
2251 bool __vpn_provider_check_routes(struct vpn_provider *provider)
2252 {
2253         if (!provider)
2254                 return false;
2255
2256         if (provider->user_routes &&
2257                         g_hash_table_size(provider->user_routes) > 0)
2258                 return true;
2259
2260         if (provider->routes &&
2261                         g_hash_table_size(provider->routes) > 0)
2262                 return true;
2263
2264         return false;
2265 }
2266
2267 void *vpn_provider_get_data(struct vpn_provider *provider)
2268 {
2269         return provider->driver_data;
2270 }
2271
2272 void vpn_provider_set_data(struct vpn_provider *provider, void *data)
2273 {
2274         provider->driver_data = data;
2275 }
2276
2277 void vpn_provider_set_index(struct vpn_provider *provider, int index)
2278 {
2279         DBG("index %d provider %p", index, provider);
2280
2281         if (!provider->ipconfig_ipv4) {
2282                 provider->ipconfig_ipv4 = __vpn_ipconfig_create(index,
2283                                                                 AF_INET);
2284                 if (!provider->ipconfig_ipv4) {
2285                         DBG("Couldnt create ipconfig for IPv4");
2286                         goto done;
2287                 }
2288         }
2289
2290         __vpn_ipconfig_set_index(provider->ipconfig_ipv4, index);
2291
2292         if (!provider->ipconfig_ipv6) {
2293                 provider->ipconfig_ipv6 = __vpn_ipconfig_create(index,
2294                                                                 AF_INET6);
2295                 if (!provider->ipconfig_ipv6) {
2296                         DBG("Couldnt create ipconfig for IPv6");
2297                         goto done;
2298                 }
2299         }
2300
2301         __vpn_ipconfig_set_index(provider->ipconfig_ipv6, index);
2302
2303 done:
2304         provider->index = index;
2305 }
2306
2307 int vpn_provider_get_index(struct vpn_provider *provider)
2308 {
2309         return provider->index;
2310 }
2311
2312 int vpn_provider_set_ipaddress(struct vpn_provider *provider,
2313                                         struct connman_ipaddress *ipaddress)
2314 {
2315         struct vpn_ipconfig *ipconfig = NULL;
2316
2317         switch (ipaddress->family) {
2318         case AF_INET:
2319                 ipconfig = provider->ipconfig_ipv4;
2320                 break;
2321         case AF_INET6:
2322                 ipconfig = provider->ipconfig_ipv6;
2323                 break;
2324         default:
2325                 break;
2326         }
2327
2328         DBG("provider %p state %d ipconfig %p family %d", provider,
2329                 provider->state, ipconfig, ipaddress->family);
2330
2331         if (!ipconfig)
2332                 return -EINVAL;
2333
2334         provider->family = ipaddress->family;
2335
2336         if (provider->state == VPN_PROVIDER_STATE_CONNECT ||
2337                         provider->state == VPN_PROVIDER_STATE_READY) {
2338                 struct connman_ipaddress *addr =
2339                                         __vpn_ipconfig_get_address(ipconfig);
2340
2341                 /*
2342                  * Remember the old address so that we can remove it in notify
2343                  * function in plugins/vpn.c if we ever restart
2344                  */
2345                 if (ipaddress->family == AF_INET6) {
2346                         connman_ipaddress_free(provider->prev_ipv6_addr);
2347                         provider->prev_ipv6_addr =
2348                                                 connman_ipaddress_copy(addr);
2349                 } else {
2350                         connman_ipaddress_free(provider->prev_ipv4_addr);
2351                         provider->prev_ipv4_addr =
2352                                                 connman_ipaddress_copy(addr);
2353                 }
2354         }
2355
2356         if (ipaddress->local) {
2357                 __vpn_ipconfig_set_local(ipconfig, ipaddress->local);
2358                 __vpn_ipconfig_set_peer(ipconfig, ipaddress->peer);
2359                 __vpn_ipconfig_set_broadcast(ipconfig, ipaddress->broadcast);
2360                 __vpn_ipconfig_set_gateway(ipconfig, ipaddress->gateway);
2361                 __vpn_ipconfig_set_prefixlen(ipconfig, ipaddress->prefixlen);
2362         }
2363
2364         return 0;
2365 }
2366
2367 int vpn_provider_set_pac(struct vpn_provider *provider,
2368                                 const char *pac)
2369 {
2370         DBG("provider %p pac %s", provider, pac);
2371
2372         return 0;
2373 }
2374
2375
2376 int vpn_provider_set_domain(struct vpn_provider *provider,
2377                                         const char *domain)
2378 {
2379         DBG("provider %p domain %s", provider, domain);
2380
2381         g_free(provider->domain);
2382         provider->domain = g_strdup(domain);
2383
2384         return 0;
2385 }
2386
2387 int vpn_provider_set_nameservers(struct vpn_provider *provider,
2388                                         const char *nameservers)
2389 {
2390         DBG("provider %p nameservers %s", provider, nameservers);
2391
2392         g_strfreev(provider->nameservers);
2393         provider->nameservers = NULL;
2394
2395         if (!nameservers)
2396                 return 0;
2397
2398         provider->nameservers = g_strsplit(nameservers, " ", 0);
2399
2400         return 0;
2401 }
2402
2403 enum provider_route_type {
2404         PROVIDER_ROUTE_TYPE_NONE = 0,
2405         PROVIDER_ROUTE_TYPE_MASK = 1,
2406         PROVIDER_ROUTE_TYPE_ADDR = 2,
2407         PROVIDER_ROUTE_TYPE_GW   = 3,
2408 };
2409
2410 static int route_env_parse(struct vpn_provider *provider, const char *key,
2411                                 int *family, unsigned long *idx,
2412                                 enum provider_route_type *type)
2413 {
2414         char *end;
2415         const char *start;
2416
2417         DBG("name %s", provider->name);
2418
2419         if (!strcmp(provider->type, "openvpn")) {
2420                 if (g_str_has_prefix(key, "route_network_")) {
2421                         start = key + strlen("route_network_");
2422                         *type = PROVIDER_ROUTE_TYPE_ADDR;
2423                 } else if (g_str_has_prefix(key, "route_netmask_")) {
2424                         start = key + strlen("route_netmask_");
2425                         *type = PROVIDER_ROUTE_TYPE_MASK;
2426                 } else if (g_str_has_prefix(key, "route_gateway_")) {
2427                         start = key + strlen("route_gateway_");
2428                         *type = PROVIDER_ROUTE_TYPE_GW;
2429                 } else
2430                         return -EINVAL;
2431
2432                 *family = AF_INET;
2433                 *idx = g_ascii_strtoull(start, &end, 10);
2434
2435         } else if (!strcmp(provider->type, "openconnect")) {
2436                 if (g_str_has_prefix(key, "CISCO_SPLIT_INC_")) {
2437                         *family = AF_INET;
2438                         start = key + strlen("CISCO_SPLIT_INC_");
2439                 } else if (g_str_has_prefix(key,
2440                                         "CISCO_IPV6_SPLIT_INC_")) {
2441                         *family = AF_INET6;
2442                         start = key + strlen("CISCO_IPV6_SPLIT_INC_");
2443                 } else
2444                         return -EINVAL;
2445
2446                 *idx = g_ascii_strtoull(start, &end, 10);
2447
2448                 if (strncmp(end, "_ADDR", 5) == 0)
2449                         *type = PROVIDER_ROUTE_TYPE_ADDR;
2450                 else if (strncmp(end, "_MASK", 5) == 0)
2451                         *type = PROVIDER_ROUTE_TYPE_MASK;
2452                 else if (strncmp(end, "_MASKLEN", 8) == 0 &&
2453                                 *family == AF_INET6) {
2454                         *type = PROVIDER_ROUTE_TYPE_MASK;
2455                 } else
2456                         return -EINVAL;
2457         }
2458
2459         return 0;
2460 }
2461
2462 int vpn_provider_append_route(struct vpn_provider *provider,
2463                                         const char *key, const char *value)
2464 {
2465         struct vpn_route *route;
2466         int ret, family = 0;
2467         unsigned long idx = 0;
2468         enum provider_route_type type = PROVIDER_ROUTE_TYPE_NONE;
2469
2470         DBG("key %s value %s", key, value);
2471
2472         ret = route_env_parse(provider, key, &family, &idx, &type);
2473         if (ret < 0)
2474                 return ret;
2475
2476         DBG("idx %lu family %d type %d", idx, family, type);
2477
2478         route = g_hash_table_lookup(provider->routes, GINT_TO_POINTER(idx));
2479         if (!route) {
2480                 route = g_try_new0(struct vpn_route, 1);
2481                 if (!route) {
2482                         connman_error("out of memory");
2483                         return -ENOMEM;
2484                 }
2485
2486                 route->family = family;
2487
2488                 g_hash_table_replace(provider->routes, GINT_TO_POINTER(idx),
2489                                                 route);
2490         }
2491
2492         switch (type) {
2493         case PROVIDER_ROUTE_TYPE_NONE:
2494                 break;
2495         case PROVIDER_ROUTE_TYPE_MASK:
2496                 route->netmask = g_strdup(value);
2497                 break;
2498         case PROVIDER_ROUTE_TYPE_ADDR:
2499                 route->network = g_strdup(value);
2500                 break;
2501         case PROVIDER_ROUTE_TYPE_GW:
2502                 route->gateway = g_strdup(value);
2503                 break;
2504         }
2505
2506         if (!handle_routes) {
2507                 if (route->netmask && route->gateway &&
2508                                                         route->network)
2509                         provider_schedule_changed(provider);
2510         }
2511
2512         return 0;
2513 }
2514
2515 const char *vpn_provider_get_driver_name(struct vpn_provider *provider)
2516 {
2517         if (!provider->driver)
2518                 return NULL;
2519
2520         return provider->driver->name;
2521 }
2522
2523 const char *vpn_provider_get_save_group(struct vpn_provider *provider)
2524 {
2525         return provider->identifier;
2526 }
2527
2528 static gint compare_priority(gconstpointer a, gconstpointer b)
2529 {
2530         return 0;
2531 }
2532
2533 static void clean_provider(gpointer key, gpointer value, gpointer user_data)
2534 {
2535         struct vpn_provider *provider = value;
2536
2537         if (provider->driver && provider->driver->remove)
2538                 provider->driver->remove(provider);
2539
2540         connection_unregister(provider);
2541 }
2542
2543 int vpn_provider_driver_register(struct vpn_provider_driver *driver)
2544 {
2545         DBG("driver %p name %s", driver, driver->name);
2546
2547         driver_list = g_slist_insert_sorted(driver_list, driver,
2548                                                         compare_priority);
2549         provider_create_all_from_type(driver->name);
2550         return 0;
2551 }
2552
2553 void vpn_provider_driver_unregister(struct vpn_provider_driver *driver)
2554 {
2555         GHashTableIter iter;
2556         gpointer value, key;
2557
2558         DBG("driver %p name %s", driver, driver->name);
2559
2560         driver_list = g_slist_remove(driver_list, driver);
2561
2562         g_hash_table_iter_init(&iter, provider_hash);
2563         while (g_hash_table_iter_next(&iter, &key, &value)) {
2564                 struct vpn_provider *provider = value;
2565
2566                 if (provider && provider->driver &&
2567                                 provider->driver->type == driver->type &&
2568                                 g_strcmp0(provider->driver->name,
2569                                                         driver->name) == 0) {
2570                         provider->driver = NULL;
2571                 }
2572         }
2573 }
2574
2575 const char *vpn_provider_get_name(struct vpn_provider *provider)
2576 {
2577         return provider->name;
2578 }
2579
2580 const char *vpn_provider_get_host(struct vpn_provider *provider)
2581 {
2582         return provider->host;
2583 }
2584
2585 const char *vpn_provider_get_path(struct vpn_provider *provider)
2586 {
2587         return provider->path;
2588 }
2589
2590 void vpn_provider_change_address(struct vpn_provider *provider)
2591 {
2592         switch (provider->family) {
2593         case AF_INET:
2594                 connman_inet_set_address(provider->index,
2595                         __vpn_ipconfig_get_address(provider->ipconfig_ipv4));
2596                 break;
2597         case AF_INET6:
2598                 connman_inet_set_ipv6_address(provider->index,
2599                         __vpn_ipconfig_get_address(provider->ipconfig_ipv6));
2600                 break;
2601         default:
2602                 break;
2603         }
2604 }
2605
2606 void vpn_provider_clear_address(struct vpn_provider *provider, int family)
2607 {
2608         const char *address;
2609         unsigned char len;
2610
2611         DBG("provider %p family %d ipv4 %p ipv6 %p", provider, family,
2612                 provider->prev_ipv4_addr, provider->prev_ipv6_addr);
2613
2614         switch (family) {
2615         case AF_INET:
2616                 if (provider->prev_ipv4_addr) {
2617                         connman_ipaddress_get_ip(provider->prev_ipv4_addr,
2618                                                 &address, &len);
2619
2620                         DBG("ipv4 %s/%d", address, len);
2621
2622                         connman_inet_clear_address(provider->index,
2623                                         provider->prev_ipv4_addr);
2624                         connman_ipaddress_free(provider->prev_ipv4_addr);
2625                         provider->prev_ipv4_addr = NULL;
2626                 }
2627                 break;
2628         case AF_INET6:
2629                 if (provider->prev_ipv6_addr) {
2630                         connman_ipaddress_get_ip(provider->prev_ipv6_addr,
2631                                                 &address, &len);
2632
2633                         DBG("ipv6 %s/%d", address, len);
2634
2635                         connman_inet_clear_ipv6_address(provider->index,
2636                                                         address, len);
2637
2638                         connman_ipaddress_free(provider->prev_ipv6_addr);
2639                         provider->prev_ipv6_addr = NULL;
2640                 }
2641                 break;
2642         default:
2643                 break;
2644         }
2645 }
2646
2647 static int agent_probe(struct connman_agent *agent)
2648 {
2649         DBG("agent %p", agent);
2650         return 0;
2651 }
2652
2653 static void agent_remove(struct connman_agent *agent)
2654 {
2655         DBG("agent %p", agent);
2656 }
2657
2658 static struct connman_agent_driver agent_driver = {
2659         .name           = "vpn",
2660         .interface      = VPN_AGENT_INTERFACE,
2661         .probe          = agent_probe,
2662         .remove         = agent_remove,
2663 };
2664
2665 static void remove_unprovisioned_providers(void)
2666 {
2667         gchar **providers;
2668         GKeyFile *keyfile, *configkeyfile;
2669         char *file, *section;
2670         int i = 0;
2671
2672         providers = __connman_storage_get_providers();
2673         if (!providers)
2674                 return;
2675
2676         for (; providers[i]; i++) {
2677                 char *group = providers[i] + sizeof("provider_") - 1;
2678                 file = section = NULL;
2679                 keyfile = configkeyfile = NULL;
2680
2681                 keyfile = __connman_storage_load_provider(group);
2682                 if (!keyfile)
2683                         continue;
2684
2685                 file = __vpn_config_get_string(keyfile, group,
2686                                         "Config.file", NULL);
2687                 if (!file)
2688                         goto next;
2689
2690                 section = __vpn_config_get_string(keyfile, group,
2691                                         "Config.ident", NULL);
2692                 if (!section)
2693                         goto next;
2694
2695                 configkeyfile = __connman_storage_load_provider_config(file);
2696                 if (!configkeyfile) {
2697                         /*
2698                          * Config file is missing, remove the provisioned
2699                          * service.
2700                          */
2701                         __connman_storage_remove_provider(group);
2702                         goto next;
2703                 }
2704
2705                 if (!g_key_file_has_group(configkeyfile, section))
2706                         /*
2707                          * Config section is missing, remove the provisioned
2708                          * service.
2709                          */
2710                         __connman_storage_remove_provider(group);
2711
2712         next:
2713                 if (keyfile)
2714                         g_key_file_free(keyfile);
2715
2716                 if (configkeyfile)
2717                         g_key_file_free(configkeyfile);
2718
2719                 g_free(section);
2720                 g_free(file);
2721         }
2722
2723         g_strfreev(providers);
2724 }
2725
2726 int __vpn_provider_init(bool do_routes)
2727 {
2728         int err;
2729
2730         DBG("");
2731
2732         handle_routes = do_routes;
2733
2734         err = connman_agent_driver_register(&agent_driver);
2735         if (err < 0) {
2736                 connman_error("Cannot register agent driver for %s",
2737                                                 agent_driver.name);
2738                 return err;
2739         }
2740
2741         connection = connman_dbus_get_connection();
2742
2743         remove_unprovisioned_providers();
2744
2745         provider_hash = g_hash_table_new_full(g_str_hash, g_str_equal,
2746                                                 NULL, unregister_provider);
2747         return 0;
2748 }
2749
2750 void __vpn_provider_cleanup(void)
2751 {
2752         DBG("");
2753
2754         connman_agent_driver_unregister(&agent_driver);
2755
2756         g_hash_table_foreach(provider_hash, clean_provider, NULL);
2757
2758         g_hash_table_destroy(provider_hash);
2759         provider_hash = NULL;
2760
2761         dbus_connection_unref(connection);
2762 }