charon-xpc: Use DNS non-append/replace mode in osx-attr plugin
[strongswan.git] / src / frontends / osx / charon-xpc / charon-xpc.c
1 /*
2 * Copyright (C) 2013 Martin Willi
3 * Copyright (C) 2013 revosec AG
4 *
5 * This program is free software; you can redistribute it and/or modify it
6 * under the terms of the GNU General Public License as published by the
7 * Free Software Foundation; either version 2 of the License, or (at your
8 * option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
9 *
10 * This program is distributed in the hope that it will be useful, but
11 * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
12 * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
13 * for more details.
14 */
15
16 #include <sys/types.h>
17 #include <sys/utsname.h>
18 #include <unistd.h>
19 #include <stdio.h>
20 #include <signal.h>
21 #include <pthread.h>
22
23 #include <library.h>
24 #include <hydra.h>
25 #include <daemon.h>
26 #include <threading/thread.h>
27 #include <utils/backtrace.h>
28
29 #include "xpc_dispatch.h"
30
31 /**
32 * XPC dispatcher class
33 */
34 static xpc_dispatch_t *dispatcher;
35
36 /**
37 * atexit() cleanup for dispatcher
38 */
39 void dispatcher_cleanup()
40 {
41 DESTROY_IF(dispatcher);
42 }
43
44 /**
45 * Loglevel configuration
46 */
47 static level_t levels[DBG_MAX];
48
49 /**
50 * hook in library for debugging messages
51 */
52 extern void (*dbg) (debug_t group, level_t level, char *fmt, ...);
53
54 /**
55 * Logging hook for library logs, using stderr output
56 */
57 static void dbg_stderr(debug_t group, level_t level, char *fmt, ...)
58 {
59 va_list args;
60
61 if (level <= 1)
62 {
63 va_start(args, fmt);
64 fprintf(stderr, "00[%N] ", debug_names, group);
65 vfprintf(stderr, fmt, args);
66 fprintf(stderr, "\n");
67 va_end(args);
68 }
69 }
70
71 /**
72 * Run the daemon and handle unix signals
73 */
74 static int run()
75 {
76 sigset_t set;
77
78 sigemptyset(&set);
79 sigaddset(&set, SIGINT);
80 sigaddset(&set, SIGTERM);
81 sigprocmask(SIG_BLOCK, &set, NULL);
82
83 while (TRUE)
84 {
85 int sig;
86
87 if (sigwait(&set, &sig))
88 {
89 DBG1(DBG_DMN, "error while waiting for a signal");
90 return 1;
91 }
92 switch (sig)
93 {
94 case SIGINT:
95 DBG1(DBG_DMN, "signal of type SIGINT received. Shutting down");
96 charon->bus->alert(charon->bus, ALERT_SHUTDOWN_SIGNAL, sig);
97 return 0;
98 case SIGTERM:
99 DBG1(DBG_DMN, "signal of type SIGTERM received. Shutting down");
100 charon->bus->alert(charon->bus, ALERT_SHUTDOWN_SIGNAL, sig);
101 return 0;
102 default:
103 DBG1(DBG_DMN, "unknown signal %d received. Ignored", sig);
104 break;
105 }
106 }
107 }
108
109 /**
110 * Handle SIGSEGV/SIGILL signals raised by threads
111 */
112 static void segv_handler(int signal)
113 {
114 backtrace_t *backtrace;
115
116 DBG1(DBG_DMN, "thread %u received %d", thread_current_id(), signal);
117 backtrace = backtrace_create(2);
118 backtrace->log(backtrace, NULL, TRUE);
119 backtrace->destroy(backtrace);
120
121 DBG1(DBG_DMN, "killing ourself, received critical signal");
122 abort();
123 }
124
125 /**
126 * PF_ROUTE for some reason does not send an event for the first address
127 * installed after a fresh boot. Fix this by installing a fake tun address
128 * just to remove it afterwards.
129 */
130 static void fixup_pf_route()
131 {
132 tun_device_t *tun;
133 host_t *host;
134
135 tun = tun_device_create(NULL);
136 if (tun)
137 {
138 if (tun->up(tun))
139 {
140 host = host_create_from_string("127.0.0.99", 0);
141 tun->set_address(tun, host, 32);
142 host->destroy(host);
143 }
144 tun->destroy(tun);
145 }
146 }
147
148 /**
149 * Main function, starts the daemon.
150 */
151 int main(int argc, char *argv[])
152 {
153 struct sigaction action;
154 struct utsname utsname;
155 int group;
156
157 dbg = dbg_stderr;
158 atexit(library_deinit);
159 if (!library_init(NULL, "charon-xpc"))
160 {
161 exit(SS_RC_LIBSTRONGSWAN_INTEGRITY);
162 }
163 if (lib->integrity)
164 {
165 if (!lib->integrity->check_file(lib->integrity, "charon-xpc", argv[0]))
166 {
167 exit(SS_RC_DAEMON_INTEGRITY);
168 }
169 }
170 atexit(libhydra_deinit);
171 if (!libhydra_init())
172 {
173 exit(SS_RC_INITIALIZATION_FAILED);
174 }
175 atexit(libcharon_deinit);
176 if (!libcharon_init())
177 {
178 exit(SS_RC_INITIALIZATION_FAILED);
179 }
180 for (group = 0; group < DBG_MAX; group++)
181 {
182 levels[group] = LEVEL_CTRL;
183 }
184 charon->load_loggers(charon, levels, TRUE);
185
186 lib->settings->set_default_str(lib->settings, "charon-xpc.port", "0");
187 lib->settings->set_default_str(lib->settings, "charon-xpc.port_nat_t", "0");
188 lib->settings->set_default_str(lib->settings,
189 "charon-xpc.close_ike_on_child_failure", "yes");
190 lib->settings->set_default_str(lib->settings,
191 "charon-xpc.plugins.osx-attr.append", "no");
192 if (!charon->initialize(charon,
193 lib->settings->get_str(lib->settings, "charon-xpc.load",
194 "nonce pkcs1 openssl keychain ctr ccm gcm kernel-libipsec "
195 "kernel-pfroute socket-default eap-identity eap-mschapv2 "
196 "eap-md5 xauth-generic osx-attr")))
197 {
198 exit(SS_RC_INITIALIZATION_FAILED);
199 }
200
201 if (uname(&utsname) != 0)
202 {
203 memset(&utsname, 0, sizeof(utsname));
204 }
205 DBG1(DBG_DMN, "Starting charon-xpc IKE daemon (strongSwan %s, %s %s, %s)",
206 VERSION, utsname.sysname, utsname.release, utsname.machine);
207
208 /* add handler for SEGV and ILL,
209 * INT, TERM and HUP are handled by sigwait() in run() */
210 action.sa_handler = segv_handler;
211 action.sa_flags = 0;
212 sigemptyset(&action.sa_mask);
213 sigaddset(&action.sa_mask, SIGINT);
214 sigaddset(&action.sa_mask, SIGTERM);
215 sigaddset(&action.sa_mask, SIGHUP);
216 sigaction(SIGSEGV, &action, NULL);
217 sigaction(SIGILL, &action, NULL);
218 sigaction(SIGBUS, &action, NULL);
219 action.sa_handler = SIG_IGN;
220 sigaction(SIGPIPE, &action, NULL);
221
222 pthread_sigmask(SIG_SETMASK, &action.sa_mask, NULL);
223
224 dispatcher = xpc_dispatch_create();
225 if (!dispatcher)
226 {
227 exit(SS_RC_INITIALIZATION_FAILED);
228 }
229 atexit(dispatcher_cleanup);
230
231 charon->start(charon);
232 fixup_pf_route();
233 return run();
234 }