Add features support to eap-tnc plugin
[strongswan.git] / src / libcharon / daemon.c
1 /*
2 * Copyright (C) 2006-2010 Tobias Brunner
3 * Copyright (C) 2005-2009 Martin Willi
4 * Copyright (C) 2006 Daniel Roethlisberger
5 * Copyright (C) 2005 Jan Hutter
6 * Hochschule fuer Technik Rapperswil
7 *
8 * This program is free software; you can redistribute it and/or modify it
9 * under the terms of the GNU General Public License as published by the
10 * Free Software Foundation; either version 2 of the License, or (at your
11 * option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
12 *
13 * This program is distributed in the hope that it will be useful, but
14 * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
15 * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
16 * for more details.
17 */
18
19 #include <stdio.h>
20 #include <sys/types.h>
21 #include <unistd.h>
22 #include <time.h>
23
24 #ifdef CAPABILITIES
25 # ifdef HAVE_SYS_CAPABILITY_H
26 # include <sys/capability.h>
27 # elif defined(CAPABILITIES_NATIVE)
28 # include <linux/capability.h>
29 # endif /* CAPABILITIES_NATIVE */
30 #endif /* CAPABILITIES */
31
32 #define USE_TNC /* for tnccs_manager */
33
34 #include "daemon.h"
35
36 #include <library.h>
37 #include <plugins/plugin.h>
38 #include <config/proposal.h>
39 #include <kernel/kernel_handler.h>
40 #include <processing/jobs/start_action_job.h>
41
42 typedef struct private_daemon_t private_daemon_t;
43
44 /**
45 * Private additions to daemon_t, contains threads and internal functions.
46 */
47 struct private_daemon_t {
48 /**
49 * Public members of daemon_t.
50 */
51 daemon_t public;
52
53 /**
54 * Handler for kernel events
55 */
56 kernel_handler_t *kernel_handler;
57
58 /**
59 * capabilities to keep
60 */
61 #ifdef CAPABILITIES_LIBCAP
62 cap_t caps;
63 #endif /* CAPABILITIES_LIBCAP */
64 #ifdef CAPABILITIES_NATIVE
65 struct __user_cap_data_struct caps[2];
66 #endif /* CAPABILITIES_NATIVE */
67
68 };
69
70 /**
71 * One and only instance of the daemon.
72 */
73 daemon_t *charon;
74
75 /**
76 * hook in library for debugging messages
77 */
78 extern void (*dbg) (debug_t group, level_t level, char *fmt, ...);
79
80 /**
81 * we store the previous debug function so we can reset it
82 */
83 static void (*dbg_old) (debug_t group, level_t level, char *fmt, ...);
84
85 /**
86 * Logging hook for library logs, spreads debug message over bus
87 */
88 static void dbg_bus(debug_t group, level_t level, char *fmt, ...)
89 {
90 va_list args;
91
92 va_start(args, fmt);
93 charon->bus->vlog(charon->bus, group, level, fmt, args);
94 va_end(args);
95 }
96
97 /**
98 * Clean up all daemon resources
99 */
100 static void destroy(private_daemon_t *this)
101 {
102 /* terminate all idle threads */
103 lib->processor->set_threads(lib->processor, 0);
104
105 /* close all IKE_SAs */
106 if (this->public.ike_sa_manager)
107 {
108 this->public.ike_sa_manager->flush(this->public.ike_sa_manager);
109 }
110 if (this->public.traps)
111 {
112 this->public.traps->flush(this->public.traps);
113 }
114 DESTROY_IF(this->public.receiver);
115 DESTROY_IF(this->public.sender);
116 /* unload plugins to release threads */
117 lib->plugins->unload(lib->plugins);
118 #ifdef CAPABILITIES_LIBCAP
119 cap_free(this->caps);
120 #endif /* CAPABILITIES_LIBCAP */
121 DESTROY_IF(this->kernel_handler);
122 DESTROY_IF(this->public.traps);
123 DESTROY_IF(this->public.shunts);
124 DESTROY_IF(this->public.ike_sa_manager);
125 DESTROY_IF(this->public.controller);
126 DESTROY_IF(this->public.eap);
127 DESTROY_IF(this->public.tnccs);
128 #ifdef ME
129 DESTROY_IF(this->public.connect_manager);
130 DESTROY_IF(this->public.mediation_manager);
131 #endif /* ME */
132 DESTROY_IF(this->public.backends);
133 DESTROY_IF(this->public.socket);
134
135 /* rehook library logging, shutdown logging */
136 dbg = dbg_old;
137 DESTROY_IF(this->public.bus);
138 this->public.file_loggers->destroy_offset(this->public.file_loggers,
139 offsetof(file_logger_t, destroy));
140 this->public.sys_loggers->destroy_offset(this->public.sys_loggers,
141 offsetof(sys_logger_t, destroy));
142 free(this);
143 }
144
145 METHOD(daemon_t, keep_cap, void,
146 private_daemon_t *this, u_int cap)
147 {
148 #ifdef CAPABILITIES_LIBCAP
149 cap_set_flag(this->caps, CAP_EFFECTIVE, 1, &cap, CAP_SET);
150 cap_set_flag(this->caps, CAP_INHERITABLE, 1, &cap, CAP_SET);
151 cap_set_flag(this->caps, CAP_PERMITTED, 1, &cap, CAP_SET);
152 #endif /* CAPABILITIES_LIBCAP */
153 #ifdef CAPABILITIES_NATIVE
154 int i = 0;
155
156 if (cap >= 32)
157 {
158 i++;
159 cap -= 32;
160 }
161 this->caps[i].effective |= 1 << cap;
162 this->caps[i].permitted |= 1 << cap;
163 this->caps[i].inheritable |= 1 << cap;
164 #endif /* CAPABILITIES_NATIVE */
165 }
166
167 METHOD(daemon_t, drop_capabilities, bool,
168 private_daemon_t *this)
169 {
170 #ifdef CAPABILITIES_LIBCAP
171 if (cap_set_proc(this->caps) != 0)
172 {
173 return FALSE;
174 }
175 #endif /* CAPABILITIES_LIBCAP */
176 #ifdef CAPABILITIES_NATIVE
177 struct __user_cap_header_struct header = {
178 #if defined(_LINUX_CAPABILITY_VERSION_3)
179 .version = _LINUX_CAPABILITY_VERSION_3,
180 #elif defined(_LINUX_CAPABILITY_VERSION_2)
181 .version = _LINUX_CAPABILITY_VERSION_2,
182 #elif defined(_LINUX_CAPABILITY_VERSION_1)
183 .version = _LINUX_CAPABILITY_VERSION_1,
184 #else
185 .version = _LINUX_CAPABILITY_VERSION,
186 #endif
187 };
188 if (capset(&header, this->caps) != 0)
189 {
190 return FALSE;
191 }
192 #endif /* CAPABILITIES_NATIVE */
193 return TRUE;
194 }
195
196 METHOD(daemon_t, start, void,
197 private_daemon_t *this)
198 {
199 /* start the engine, go multithreaded */
200 lib->processor->set_threads(lib->processor,
201 lib->settings->get_int(lib->settings, "charon.threads",
202 DEFAULT_THREADS));
203 }
204
205 /**
206 * Log loaded plugins
207 */
208 static void print_plugins()
209 {
210 char buf[512];
211 int len = 0;
212 enumerator_t *enumerator;
213 plugin_t *plugin;
214
215 buf[0] = '\0';
216 enumerator = lib->plugins->create_plugin_enumerator(lib->plugins);
217 while (len < sizeof(buf) && enumerator->enumerate(enumerator, &plugin, NULL))
218 {
219 len += snprintf(&buf[len], sizeof(buf)-len, "%s ",
220 plugin->get_name(plugin));
221 }
222 enumerator->destroy(enumerator);
223 DBG1(DBG_DMN, "loaded plugins: %s", buf);
224 }
225
226 METHOD(daemon_t, initialize, bool,
227 private_daemon_t *this)
228 {
229 DBG1(DBG_DMN, "Starting IKEv2 charon daemon (strongSwan "VERSION")");
230
231 if (lib->integrity)
232 {
233 DBG1(DBG_DMN, "integrity tests enabled:");
234 DBG1(DBG_DMN, "lib 'libstrongswan': passed file and segment integrity tests");
235 DBG1(DBG_DMN, "lib 'libhydra': passed file and segment integrity tests");
236 DBG1(DBG_DMN, "lib 'libcharon': passed file and segment integrity tests");
237 DBG1(DBG_DMN, "daemon 'charon': passed file integrity test");
238 }
239
240 /* load plugins, further infrastructure may need it */
241 if (!lib->plugins->load(lib->plugins, NULL,
242 lib->settings->get_str(lib->settings, "charon.load", PLUGINS)))
243 {
244 return FALSE;
245 }
246
247 print_plugins();
248
249 this->public.ike_sa_manager = ike_sa_manager_create();
250 if (this->public.ike_sa_manager == NULL)
251 {
252 return FALSE;
253 }
254 this->public.sender = sender_create();
255 this->public.receiver = receiver_create();
256 if (this->public.receiver == NULL)
257 {
258 return FALSE;
259 }
260
261 /* Queue start_action job */
262 lib->processor->queue_job(lib->processor, (job_t*)start_action_job_create());
263
264 #ifdef ME
265 this->public.connect_manager = connect_manager_create();
266 if (this->public.connect_manager == NULL)
267 {
268 return FALSE;
269 }
270 this->public.mediation_manager = mediation_manager_create();
271 #endif /* ME */
272
273 return TRUE;
274 }
275
276 /**
277 * Create the daemon.
278 */
279 private_daemon_t *daemon_create()
280 {
281 private_daemon_t *this;
282
283 INIT(this,
284 .public = {
285 .keep_cap = _keep_cap,
286 .drop_capabilities = _drop_capabilities,
287 .initialize = _initialize,
288 .start = _start,
289 .bus = bus_create(),
290 .file_loggers = linked_list_create(),
291 .sys_loggers = linked_list_create(),
292 },
293 );
294 charon = &this->public;
295 this->public.controller = controller_create();
296 this->public.eap = eap_manager_create();
297 this->public.tnccs = tnccs_manager_create();
298 this->public.backends = backend_manager_create();
299 this->public.socket = socket_manager_create();
300 this->public.traps = trap_manager_create();
301 this->public.shunts = shunt_manager_create();
302 this->kernel_handler = kernel_handler_create();
303
304 #ifdef CAPABILITIES
305 #ifdef CAPABILITIES_LIBCAP
306 this->caps = cap_init();
307 #endif /* CAPABILITIES_LIBCAP */
308 keep_cap(this, CAP_NET_ADMIN);
309 if (lib->leak_detective)
310 {
311 keep_cap(this, CAP_SYS_NICE);
312 }
313 #endif /* CAPABILITIES */
314
315 return this;
316 }
317
318 /**
319 * Described in header.
320 */
321 void libcharon_deinit()
322 {
323 destroy((private_daemon_t*)charon);
324 charon = NULL;
325 }
326
327 /**
328 * Described in header.
329 */
330 bool libcharon_init()
331 {
332 daemon_create();
333
334 /* for uncritical pseudo random numbers */
335 srandom(time(NULL) + getpid());
336
337 /* set up hook to log dbg message in library via charons message bus */
338 dbg_old = dbg;
339 dbg = dbg_bus;
340
341 lib->printf_hook->add_handler(lib->printf_hook, 'P',
342 proposal_printf_hook,
343 PRINTF_HOOK_ARGTYPE_POINTER,
344 PRINTF_HOOK_ARGTYPE_END);
345
346 if (lib->integrity &&
347 !lib->integrity->check(lib->integrity, "libcharon", libcharon_init))
348 {
349 dbg(DBG_DMN, 1, "integrity check of libcharon failed");
350 return FALSE;
351 }
352
353 return TRUE;
354 }