Use static plugin features in libcharon to define essential dependencies
[strongswan.git] / src / libcharon / daemon.c
1 /*
2 * Copyright (C) 2006-2012 Tobias Brunner
3 * Copyright (C) 2005-2009 Martin Willi
4 * Copyright (C) 2006 Daniel Roethlisberger
5 * Copyright (C) 2005 Jan Hutter
6 * Hochschule fuer Technik Rapperswil
7 *
8 * This program is free software; you can redistribute it and/or modify it
9 * under the terms of the GNU General Public License as published by the
10 * Free Software Foundation; either version 2 of the License, or (at your
11 * option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
12 *
13 * This program is distributed in the hope that it will be useful, but
14 * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
15 * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
16 * for more details.
17 */
18
19 #include <stdio.h>
20 #include <sys/types.h>
21 #include <unistd.h>
22 #include <time.h>
23
24 #ifdef CAPABILITIES
25 # ifdef HAVE_SYS_CAPABILITY_H
26 # include <sys/capability.h>
27 # elif defined(CAPABILITIES_NATIVE)
28 # include <linux/capability.h>
29 # endif /* CAPABILITIES_NATIVE */
30 #endif /* CAPABILITIES */
31
32 #include "daemon.h"
33
34 #include <library.h>
35 #include <plugins/plugin_feature.h>
36 #include <config/proposal.h>
37 #include <kernel/kernel_handler.h>
38 #include <processing/jobs/start_action_job.h>
39
40 typedef struct private_daemon_t private_daemon_t;
41
42 /**
43 * Private additions to daemon_t, contains threads and internal functions.
44 */
45 struct private_daemon_t {
46 /**
47 * Public members of daemon_t.
48 */
49 daemon_t public;
50
51 /**
52 * Handler for kernel events
53 */
54 kernel_handler_t *kernel_handler;
55
56 /**
57 * capabilities to keep
58 */
59 #ifdef CAPABILITIES_LIBCAP
60 cap_t caps;
61 #endif /* CAPABILITIES_LIBCAP */
62 #ifdef CAPABILITIES_NATIVE
63 struct __user_cap_data_struct caps[2];
64 #endif /* CAPABILITIES_NATIVE */
65
66 };
67
68 /**
69 * One and only instance of the daemon.
70 */
71 daemon_t *charon;
72
73 /**
74 * hook in library for debugging messages
75 */
76 extern void (*dbg) (debug_t group, level_t level, char *fmt, ...);
77
78 /**
79 * we store the previous debug function so we can reset it
80 */
81 static void (*dbg_old) (debug_t group, level_t level, char *fmt, ...);
82
83 /**
84 * Logging hook for library logs, spreads debug message over bus
85 */
86 static void dbg_bus(debug_t group, level_t level, char *fmt, ...)
87 {
88 va_list args;
89
90 va_start(args, fmt);
91 charon->bus->vlog(charon->bus, group, level, fmt, args);
92 va_end(args);
93 }
94
95 /**
96 * Clean up all daemon resources
97 */
98 static void destroy(private_daemon_t *this)
99 {
100 /* terminate all idle threads */
101 lib->processor->set_threads(lib->processor, 0);
102
103 /* close all IKE_SAs */
104 if (this->public.ike_sa_manager)
105 {
106 this->public.ike_sa_manager->flush(this->public.ike_sa_manager);
107 }
108 if (this->public.traps)
109 {
110 this->public.traps->flush(this->public.traps);
111 }
112 if (this->public.sender)
113 {
114 this->public.sender->flush(this->public.sender);
115 }
116
117 /* cancel all threads and wait for their termination */
118 lib->processor->cancel(lib->processor);
119
120 DESTROY_IF(this->public.receiver);
121 #ifdef ME
122 DESTROY_IF(this->public.connect_manager);
123 DESTROY_IF(this->public.mediation_manager);
124 #endif /* ME */
125 /* make sure the cache is clear before unloading plugins */
126 lib->credmgr->flush_cache(lib->credmgr, CERT_ANY);
127 lib->plugins->unload(lib->plugins);
128 #ifdef CAPABILITIES_LIBCAP
129 cap_free(this->caps);
130 #endif /* CAPABILITIES_LIBCAP */
131 DESTROY_IF(this->kernel_handler);
132 DESTROY_IF(this->public.traps);
133 DESTROY_IF(this->public.shunts);
134 DESTROY_IF(this->public.ike_sa_manager);
135 DESTROY_IF(this->public.controller);
136 DESTROY_IF(this->public.eap);
137 DESTROY_IF(this->public.xauth);
138 DESTROY_IF(this->public.backends);
139 DESTROY_IF(this->public.sender);
140 DESTROY_IF(this->public.socket);
141
142 /* rehook library logging, shutdown logging */
143 dbg = dbg_old;
144 DESTROY_IF(this->public.bus);
145 this->public.file_loggers->destroy_offset(this->public.file_loggers,
146 offsetof(file_logger_t, destroy));
147 this->public.sys_loggers->destroy_offset(this->public.sys_loggers,
148 offsetof(sys_logger_t, destroy));
149 free((void*)this->public.name);
150 free(this);
151 }
152
153 METHOD(daemon_t, keep_cap, void,
154 private_daemon_t *this, u_int cap)
155 {
156 #ifdef CAPABILITIES_LIBCAP
157 cap_set_flag(this->caps, CAP_EFFECTIVE, 1, &cap, CAP_SET);
158 cap_set_flag(this->caps, CAP_INHERITABLE, 1, &cap, CAP_SET);
159 cap_set_flag(this->caps, CAP_PERMITTED, 1, &cap, CAP_SET);
160 #endif /* CAPABILITIES_LIBCAP */
161 #ifdef CAPABILITIES_NATIVE
162 int i = 0;
163
164 if (cap >= 32)
165 {
166 i++;
167 cap -= 32;
168 }
169 this->caps[i].effective |= 1 << cap;
170 this->caps[i].permitted |= 1 << cap;
171 this->caps[i].inheritable |= 1 << cap;
172 #endif /* CAPABILITIES_NATIVE */
173 }
174
175 METHOD(daemon_t, drop_capabilities, bool,
176 private_daemon_t *this)
177 {
178 #ifdef CAPABILITIES_LIBCAP
179 if (cap_set_proc(this->caps) != 0)
180 {
181 return FALSE;
182 }
183 #endif /* CAPABILITIES_LIBCAP */
184 #ifdef CAPABILITIES_NATIVE
185 struct __user_cap_header_struct header = {
186 #if defined(_LINUX_CAPABILITY_VERSION_3)
187 .version = _LINUX_CAPABILITY_VERSION_3,
188 #elif defined(_LINUX_CAPABILITY_VERSION_2)
189 .version = _LINUX_CAPABILITY_VERSION_2,
190 #elif defined(_LINUX_CAPABILITY_VERSION_1)
191 .version = _LINUX_CAPABILITY_VERSION_1,
192 #else
193 .version = _LINUX_CAPABILITY_VERSION,
194 #endif
195 };
196 if (capset(&header, this->caps) != 0)
197 {
198 return FALSE;
199 }
200 #endif /* CAPABILITIES_NATIVE */
201 return TRUE;
202 }
203
204 METHOD(daemon_t, start, void,
205 private_daemon_t *this)
206 {
207 /* start the engine, go multithreaded */
208 lib->processor->set_threads(lib->processor,
209 lib->settings->get_int(lib->settings, "%s.threads",
210 DEFAULT_THREADS, charon->name));
211 }
212
213 METHOD(daemon_t, initialize, bool,
214 private_daemon_t *this, char *plugins)
215 {
216 static plugin_feature_t features[] = {
217 PLUGIN_PROVIDE(CUSTOM, "libcharon"),
218 PLUGIN_DEPENDS(HASHER, HASH_SHA1),
219 PLUGIN_DEPENDS(RNG, RNG_STRONG),
220 PLUGIN_DEPENDS(NONCE_GEN),
221 };
222 lib->plugins->add_static_features(lib->plugins, charon->name, features,
223 countof(features), TRUE);
224
225 /* load plugins, further infrastructure may need it */
226 if (!lib->plugins->load(lib->plugins, NULL, plugins))
227 {
228 return FALSE;
229 }
230 DBG1(DBG_DMN, "loaded plugins: %s",
231 lib->plugins->loaded_plugins(lib->plugins));
232
233 this->public.ike_sa_manager = ike_sa_manager_create();
234 if (this->public.ike_sa_manager == NULL)
235 {
236 return FALSE;
237 }
238 this->public.sender = sender_create();
239 this->public.receiver = receiver_create();
240 if (this->public.receiver == NULL)
241 {
242 return FALSE;
243 }
244
245 /* Queue start_action job */
246 lib->processor->queue_job(lib->processor, (job_t*)start_action_job_create());
247
248 #ifdef ME
249 this->public.connect_manager = connect_manager_create();
250 if (this->public.connect_manager == NULL)
251 {
252 return FALSE;
253 }
254 this->public.mediation_manager = mediation_manager_create();
255 #endif /* ME */
256
257 return TRUE;
258 }
259
260 /**
261 * Create the daemon.
262 */
263 private_daemon_t *daemon_create(const char *name)
264 {
265 private_daemon_t *this;
266
267 INIT(this,
268 .public = {
269 .keep_cap = _keep_cap,
270 .drop_capabilities = _drop_capabilities,
271 .initialize = _initialize,
272 .start = _start,
273 .bus = bus_create(),
274 .file_loggers = linked_list_create(),
275 .sys_loggers = linked_list_create(),
276 .name = strdup(name ?: "libcharon"),
277 },
278 );
279 charon = &this->public;
280 this->public.controller = controller_create();
281 this->public.eap = eap_manager_create();
282 this->public.xauth = xauth_manager_create();
283 this->public.backends = backend_manager_create();
284 this->public.socket = socket_manager_create();
285 this->public.traps = trap_manager_create();
286 this->public.shunts = shunt_manager_create();
287 this->kernel_handler = kernel_handler_create();
288
289 #ifdef CAPABILITIES
290 #ifdef CAPABILITIES_LIBCAP
291 this->caps = cap_init();
292 #endif /* CAPABILITIES_LIBCAP */
293 keep_cap(this, CAP_NET_ADMIN);
294 if (lib->leak_detective)
295 {
296 keep_cap(this, CAP_SYS_NICE);
297 }
298 #endif /* CAPABILITIES */
299
300 return this;
301 }
302
303 /**
304 * Described in header.
305 */
306 void libcharon_deinit()
307 {
308 destroy((private_daemon_t*)charon);
309 charon = NULL;
310 }
311
312 /**
313 * Described in header.
314 */
315 bool libcharon_init(const char *name)
316 {
317 daemon_create(name);
318
319 /* for uncritical pseudo random numbers */
320 srandom(time(NULL) + getpid());
321
322 /* set up hook to log dbg message in library via charons message bus */
323 dbg_old = dbg;
324 dbg = dbg_bus;
325
326 lib->printf_hook->add_handler(lib->printf_hook, 'P',
327 proposal_printf_hook,
328 PRINTF_HOOK_ARGTYPE_POINTER,
329 PRINTF_HOOK_ARGTYPE_END);
330
331 if (lib->integrity &&
332 !lib->integrity->check(lib->integrity, "libcharon", libcharon_init))
333 {
334 dbg(DBG_DMN, 1, "integrity check of libcharon failed");
335 return FALSE;
336 }
337
338 return TRUE;
339 }