implemented the right|leftallowany feature
[strongswan.git] / src / charon-nm / nm / nm_backend.c
1 /*
2 * Copyright (C) 2012 Tobias Brunner
3 * Copyright (C) 2008-2009 Martin Willi
4 * Hochschule fuer Technik Rapperswil
5 *
6 * This program is free software; you can redistribute it and/or modify it
7 * under the terms of the GNU General Public License as published by the
8 * Free Software Foundation; either version 2 of the License, or (at your
9 * option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
10 *
11 * This program is distributed in the hope that it will be useful, but
12 * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
13 * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
14 * for more details.
15 */
16
17 #include "nm_service.h"
18 #include "nm_creds.h"
19 #include "nm_handler.h"
20
21 #include <hydra.h>
22 #include <daemon.h>
23 #include <processing/jobs/callback_job.h>
24
25 #define CAP_DAC_OVERRIDE 1
26
27 typedef struct nm_backend_t nm_backend_t;
28
29 /**
30 * Data for the NetworkManager backend.
31 */
32 struct nm_backend_t {
33
34 /**
35 * NetworkManager service (VPNPlugin)
36 */
37 NMStrongswanPlugin *plugin;
38
39 /**
40 * Glib main loop for a thread, handles DBUS calls
41 */
42 GMainLoop *loop;
43
44 /**
45 * credential set registered at the daemon
46 */
47 nm_creds_t *creds;
48
49 /**
50 * attribute handler regeisterd at the daemon
51 */
52 nm_handler_t *handler;
53 };
54
55 /**
56 * Global (but private) instance of the NM backend.
57 */
58 static nm_backend_t *nm_backend = NULL;
59
60 /**
61 * NM plugin processing routine, creates and handles NMVPNPlugin
62 */
63 static job_requeue_t run(nm_backend_t *this)
64 {
65 this->loop = g_main_loop_new(NULL, FALSE);
66 g_main_loop_run(this->loop);
67 return JOB_REQUEUE_NONE;
68 }
69
70 /*
71 * see header file
72 */
73 void nm_backend_deinit()
74 {
75 nm_backend_t *this = nm_backend;
76
77 if (!this)
78 {
79 return;
80 }
81 if (this->loop)
82 {
83 if (g_main_loop_is_running(this->loop))
84 {
85 g_main_loop_quit(this->loop);
86 }
87 g_main_loop_unref(this->loop);
88 }
89 if (this->plugin)
90 {
91 g_object_unref(this->plugin);
92 }
93 lib->credmgr->remove_set(lib->credmgr, &this->creds->set);
94 hydra->attributes->remove_handler(hydra->attributes, &this->handler->handler);
95 this->creds->destroy(this->creds);
96 this->handler->destroy(this->handler);
97 free(this);
98
99 nm_backend = NULL;
100 }
101
102 /*
103 * see header file
104 */
105 bool nm_backend_init()
106 {
107 nm_backend_t *this;
108
109 g_type_init ();
110 if (!g_thread_supported())
111 {
112 g_thread_init(NULL);
113 }
114
115 INIT(this,
116 .creds = nm_creds_create(),
117 .handler = nm_handler_create(),
118 );
119 this->plugin = nm_strongswan_plugin_new(this->creds, this->handler);
120 nm_backend = this;
121
122 hydra->attributes->add_handler(hydra->attributes, &this->handler->handler);
123 lib->credmgr->add_set(lib->credmgr, &this->creds->set);
124 if (!this->plugin)
125 {
126 DBG1(DBG_CFG, "DBUS binding failed");
127 nm_backend_deinit();
128 return FALSE;
129 }
130
131 /* bypass file permissions to read from users ssh-agent */
132 charon->keep_cap(charon, CAP_DAC_OVERRIDE);
133
134 lib->processor->queue_job(lib->processor,
135 (job_t*)callback_job_create_with_prio((callback_job_cb_t)run,
136 this, NULL, NULL, JOB_PRIO_CRITICAL));
137 return TRUE;
138 }
139