Migrated send_dpd_job_t to INIT/METHOD macros
[strongswan.git] / src / libcharon / daemon.c
1 /*
2 * Copyright (C) 2006-2010 Tobias Brunner
3 * Copyright (C) 2005-2009 Martin Willi
4 * Copyright (C) 2006 Daniel Roethlisberger
5 * Copyright (C) 2005 Jan Hutter
6 * Hochschule fuer Technik Rapperswil
7 *
8 * This program is free software; you can redistribute it and/or modify it
9 * under the terms of the GNU General Public License as published by the
10 * Free Software Foundation; either version 2 of the License, or (at your
11 * option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
12 *
13 * This program is distributed in the hope that it will be useful, but
14 * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
15 * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
16 * for more details.
17 */
18
19 #include <stdio.h>
20 #include <sys/types.h>
21 #include <unistd.h>
22 #include <time.h>
23
24 #ifdef CAPABILITIES
25 # ifdef HAVE_SYS_CAPABILITY_H
26 # include <sys/capability.h>
27 # elif defined(CAPABILITIES_NATIVE)
28 # include <linux/capability.h>
29 # endif /* CAPABILITIES_NATIVE */
30 #endif /* CAPABILITIES */
31
32 #include "daemon.h"
33
34 #include <library.h>
35 #include <config/proposal.h>
36 #include <kernel/kernel_handler.h>
37 #include <processing/jobs/start_action_job.h>
38
39 typedef struct private_daemon_t private_daemon_t;
40
41 /**
42 * Private additions to daemon_t, contains threads and internal functions.
43 */
44 struct private_daemon_t {
45 /**
46 * Public members of daemon_t.
47 */
48 daemon_t public;
49
50 /**
51 * Handler for kernel events
52 */
53 kernel_handler_t *kernel_handler;
54
55 /**
56 * capabilities to keep
57 */
58 #ifdef CAPABILITIES_LIBCAP
59 cap_t caps;
60 #endif /* CAPABILITIES_LIBCAP */
61 #ifdef CAPABILITIES_NATIVE
62 struct __user_cap_data_struct caps[2];
63 #endif /* CAPABILITIES_NATIVE */
64
65 };
66
67 /**
68 * One and only instance of the daemon.
69 */
70 daemon_t *charon;
71
72 /**
73 * hook in library for debugging messages
74 */
75 extern void (*dbg) (debug_t group, level_t level, char *fmt, ...);
76
77 /**
78 * we store the previous debug function so we can reset it
79 */
80 static void (*dbg_old) (debug_t group, level_t level, char *fmt, ...);
81
82 /**
83 * Logging hook for library logs, spreads debug message over bus
84 */
85 static void dbg_bus(debug_t group, level_t level, char *fmt, ...)
86 {
87 va_list args;
88
89 va_start(args, fmt);
90 charon->bus->vlog(charon->bus, group, level, fmt, args);
91 va_end(args);
92 }
93
94 /**
95 * Clean up all daemon resources
96 */
97 static void destroy(private_daemon_t *this)
98 {
99 /* terminate all idle threads */
100 lib->processor->set_threads(lib->processor, 0);
101
102 /* close all IKE_SAs */
103 if (this->public.ike_sa_manager)
104 {
105 this->public.ike_sa_manager->flush(this->public.ike_sa_manager);
106 }
107 DESTROY_IF(this->public.receiver);
108 DESTROY_IF(this->public.sender);
109 /* unload plugins to release threads */
110 lib->plugins->unload(lib->plugins);
111 #ifdef CAPABILITIES_LIBCAP
112 cap_free(this->caps);
113 #endif /* CAPABILITIES_LIBCAP */
114 DESTROY_IF(this->kernel_handler);
115 DESTROY_IF(this->public.traps);
116 DESTROY_IF(this->public.ike_sa_manager);
117 DESTROY_IF(this->public.controller);
118 DESTROY_IF(this->public.eap);
119 DESTROY_IF(this->public.sim);
120 DESTROY_IF(this->public.tnccs);
121 #ifdef ME
122 DESTROY_IF(this->public.connect_manager);
123 DESTROY_IF(this->public.mediation_manager);
124 #endif /* ME */
125 DESTROY_IF(this->public.backends);
126 DESTROY_IF(this->public.socket);
127
128 /* rehook library logging, shutdown logging */
129 dbg = dbg_old;
130 DESTROY_IF(this->public.bus);
131 this->public.file_loggers->destroy_offset(this->public.file_loggers,
132 offsetof(file_logger_t, destroy));
133 this->public.sys_loggers->destroy_offset(this->public.sys_loggers,
134 offsetof(sys_logger_t, destroy));
135 free(this);
136 }
137
138 METHOD(daemon_t, keep_cap, void,
139 private_daemon_t *this, u_int cap)
140 {
141 #ifdef CAPABILITIES_LIBCAP
142 cap_set_flag(this->caps, CAP_EFFECTIVE, 1, &cap, CAP_SET);
143 cap_set_flag(this->caps, CAP_INHERITABLE, 1, &cap, CAP_SET);
144 cap_set_flag(this->caps, CAP_PERMITTED, 1, &cap, CAP_SET);
145 #endif /* CAPABILITIES_LIBCAP */
146 #ifdef CAPABILITIES_NATIVE
147 int i = 0;
148
149 if (cap >= 32)
150 {
151 i++;
152 cap -= 32;
153 }
154 this->caps[i].effective |= 1 << cap;
155 this->caps[i].permitted |= 1 << cap;
156 this->caps[i].inheritable |= 1 << cap;
157 #endif /* CAPABILITIES_NATIVE */
158 }
159
160 METHOD(daemon_t, drop_capabilities, bool,
161 private_daemon_t *this)
162 {
163 #ifdef CAPABILITIES_LIBCAP
164 if (cap_set_proc(this->caps) != 0)
165 {
166 return FALSE;
167 }
168 #endif /* CAPABILITIES_LIBCAP */
169 #ifdef CAPABILITIES_NATIVE
170 struct __user_cap_header_struct header = {
171 #if defined(_LINUX_CAPABILITY_VERSION_3)
172 .version = _LINUX_CAPABILITY_VERSION_3,
173 #elif defined(_LINUX_CAPABILITY_VERSION_2)
174 .version = _LINUX_CAPABILITY_VERSION_2,
175 #else
176 .version = _LINUX_CAPABILITY_VERSION_1,
177 #endif
178 };
179 if (capset(&header, this->caps) != 0)
180 {
181 return FALSE;
182 }
183 #endif /* CAPABILITIES_NATIVE */
184 return TRUE;
185 }
186
187 METHOD(daemon_t, start, void,
188 private_daemon_t *this)
189 {
190 /* start the engine, go multithreaded */
191 lib->processor->set_threads(lib->processor,
192 lib->settings->get_int(lib->settings, "charon.threads",
193 DEFAULT_THREADS));
194 }
195
196 /**
197 * Log loaded plugins
198 */
199 static void print_plugins()
200 {
201 char buf[512], *plugin;
202 int len = 0;
203 enumerator_t *enumerator;
204
205 buf[0] = '\0';
206 enumerator = lib->plugins->create_plugin_enumerator(lib->plugins);
207 while (len < sizeof(buf) && enumerator->enumerate(enumerator, &plugin))
208 {
209 len += snprintf(&buf[len], sizeof(buf)-len, "%s ", plugin);
210 }
211 enumerator->destroy(enumerator);
212 DBG1(DBG_DMN, "loaded plugins: %s", buf);
213 }
214
215 METHOD(daemon_t, initialize, bool,
216 private_daemon_t *this)
217 {
218 DBG1(DBG_DMN, "Starting IKEv2 charon daemon (strongSwan "VERSION")");
219
220 if (lib->integrity)
221 {
222 DBG1(DBG_DMN, "integrity tests enabled:");
223 DBG1(DBG_DMN, "lib 'libstrongswan': passed file and segment integrity tests");
224 DBG1(DBG_DMN, "lib 'libhydra': passed file and segment integrity tests");
225 DBG1(DBG_DMN, "lib 'libcharon': passed file and segment integrity tests");
226 DBG1(DBG_DMN, "daemon 'charon': passed file integrity test");
227 }
228
229 /* load plugins, further infrastructure may need it */
230 if (!lib->plugins->load(lib->plugins, NULL,
231 lib->settings->get_str(lib->settings, "charon.load", PLUGINS)))
232 {
233 return FALSE;
234 }
235
236 print_plugins();
237
238 this->public.ike_sa_manager = ike_sa_manager_create();
239 if (this->public.ike_sa_manager == NULL)
240 {
241 return FALSE;
242 }
243 this->public.sender = sender_create();
244 this->public.receiver = receiver_create();
245 if (this->public.receiver == NULL)
246 {
247 return FALSE;
248 }
249
250 /* Queue start_action job */
251 lib->processor->queue_job(lib->processor, (job_t*)start_action_job_create());
252
253 #ifdef ME
254 this->public.connect_manager = connect_manager_create();
255 if (this->public.connect_manager == NULL)
256 {
257 return FALSE;
258 }
259 this->public.mediation_manager = mediation_manager_create();
260 #endif /* ME */
261
262 return TRUE;
263 }
264
265 /**
266 * Create the daemon.
267 */
268 private_daemon_t *daemon_create()
269 {
270 private_daemon_t *this;
271
272 INIT(this,
273 .public = {
274 .keep_cap = _keep_cap,
275 .drop_capabilities = _drop_capabilities,
276 .initialize = _initialize,
277 .start = _start,
278 .bus = bus_create(),
279 .file_loggers = linked_list_create(),
280 .sys_loggers = linked_list_create(),
281 },
282 );
283 charon = &this->public;
284 this->public.controller = controller_create();
285 this->public.eap = eap_manager_create();
286 this->public.sim = sim_manager_create();
287 this->public.tnccs = tnccs_manager_create();
288 this->public.backends = backend_manager_create();
289 this->public.socket = socket_manager_create();
290 this->public.traps = trap_manager_create();
291 this->kernel_handler = kernel_handler_create();
292
293 #ifdef CAPABILITIES
294 #ifdef CAPABILITIES_LIBCAP
295 this->caps = cap_init();
296 #endif /* CAPABILITIES_LIBCAP */
297 keep_cap(this, CAP_NET_ADMIN);
298 if (lib->leak_detective)
299 {
300 keep_cap(this, CAP_SYS_NICE);
301 }
302 #endif /* CAPABILITIES */
303
304 return this;
305 }
306
307 /**
308 * Described in header.
309 */
310 void libcharon_deinit()
311 {
312 destroy((private_daemon_t*)charon);
313 charon = NULL;
314 }
315
316 /**
317 * Described in header.
318 */
319 bool libcharon_init()
320 {
321 private_daemon_t *this;
322
323 this = daemon_create();
324
325 /* for uncritical pseudo random numbers */
326 srandom(time(NULL) + getpid());
327
328 /* set up hook to log dbg message in library via charons message bus */
329 dbg_old = dbg;
330 dbg = dbg_bus;
331
332 lib->printf_hook->add_handler(lib->printf_hook, 'P',
333 proposal_printf_hook,
334 PRINTF_HOOK_ARGTYPE_POINTER,
335 PRINTF_HOOK_ARGTYPE_END);
336
337 if (lib->integrity &&
338 !lib->integrity->check(lib->integrity, "libcharon", libcharon_init))
339 {
340 dbg(DBG_DMN, 1, "integrity check of libcharon failed");
341 return FALSE;
342 }
343
344 return TRUE;
345 }