added second example scenario
[strongswan.git] / src / libcharon / daemon.c
1 /*
2 * Copyright (C) 2006-2010 Tobias Brunner
3 * Copyright (C) 2005-2009 Martin Willi
4 * Copyright (C) 2006 Daniel Roethlisberger
5 * Copyright (C) 2005 Jan Hutter
6 * Hochschule fuer Technik Rapperswil
7 *
8 * This program is free software; you can redistribute it and/or modify it
9 * under the terms of the GNU General Public License as published by the
10 * Free Software Foundation; either version 2 of the License, or (at your
11 * option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
12 *
13 * This program is distributed in the hope that it will be useful, but
14 * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
15 * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
16 * for more details.
17 */
18
19 #include <stdio.h>
20 #include <sys/types.h>
21 #include <unistd.h>
22 #include <syslog.h>
23 #include <time.h>
24 #include <errno.h>
25
26 #ifdef CAPABILITIES
27 #ifdef HAVE_SYS_CAPABILITY_H
28 #include <sys/capability.h>
29 #endif /* HAVE_SYS_CAPABILITY_H */
30 #endif /* CAPABILITIES */
31
32 #include "daemon.h"
33
34 #include <library.h>
35 #include <config/proposal.h>
36
37 #ifndef LOG_AUTHPRIV /* not defined on OpenSolaris */
38 #define LOG_AUTHPRIV LOG_AUTH
39 #endif
40
41 typedef struct private_daemon_t private_daemon_t;
42
43 /**
44 * Private additions to daemon_t, contains threads and internal functions.
45 */
46 struct private_daemon_t {
47 /**
48 * Public members of daemon_t.
49 */
50 daemon_t public;
51
52 /**
53 * capabilities to keep
54 */
55 #ifdef CAPABILITIES_LIBCAP
56 cap_t caps;
57 #endif /* CAPABILITIES_LIBCAP */
58 #ifdef CAPABILITIES_NATIVE
59 struct __user_cap_data_struct caps;
60 #endif /* CAPABILITIES_NATIVE */
61
62 };
63
64 /**
65 * One and only instance of the daemon.
66 */
67 daemon_t *charon;
68
69 /**
70 * hook in library for debugging messages
71 */
72 extern void (*dbg) (debug_t group, level_t level, char *fmt, ...);
73
74 /**
75 * we store the previous debug function so we can reset it
76 */
77 static void (*dbg_old) (debug_t group, level_t level, char *fmt, ...);
78
79 /**
80 * Logging hook for library logs, spreads debug message over bus
81 */
82 static void dbg_bus(debug_t group, level_t level, char *fmt, ...)
83 {
84 va_list args;
85
86 va_start(args, fmt);
87 charon->bus->vlog(charon->bus, group, level, fmt, args);
88 va_end(args);
89 }
90
91 /**
92 * Clean up all daemon resources
93 */
94 static void destroy(private_daemon_t *this)
95 {
96 /* terminate all idle threads */
97 if (this->public.processor)
98 {
99 this->public.processor->set_threads(this->public.processor, 0);
100 }
101 /* close all IKE_SAs */
102 if (this->public.ike_sa_manager)
103 {
104 this->public.ike_sa_manager->flush(this->public.ike_sa_manager);
105 }
106 DESTROY_IF(this->public.receiver);
107 DESTROY_IF(this->public.sender);
108 /* unload plugins to release threads */
109 lib->plugins->unload(lib->plugins);
110 #ifdef CAPABILITIES_LIBCAP
111 cap_free(this->caps);
112 #endif /* CAPABILITIES_LIBCAP */
113 DESTROY_IF(this->public.traps);
114 DESTROY_IF(this->public.ike_sa_manager);
115 DESTROY_IF(this->public.kernel_interface);
116 DESTROY_IF(this->public.scheduler);
117 DESTROY_IF(this->public.controller);
118 DESTROY_IF(this->public.eap);
119 DESTROY_IF(this->public.sim);
120 #ifdef ME
121 DESTROY_IF(this->public.connect_manager);
122 DESTROY_IF(this->public.mediation_manager);
123 #endif /* ME */
124 DESTROY_IF(this->public.backends);
125 DESTROY_IF(this->public.credentials);
126 DESTROY_IF(this->public.socket);
127 /* wait until all threads are gone */
128 DESTROY_IF(this->public.processor);
129
130 /* rehook library logging, shutdown logging */
131 dbg = dbg_old;
132 DESTROY_IF(this->public.bus);
133 this->public.file_loggers->destroy_offset(this->public.file_loggers,
134 offsetof(file_logger_t, destroy));
135 this->public.sys_loggers->destroy_offset(this->public.sys_loggers,
136 offsetof(sys_logger_t, destroy));
137 free(this);
138 }
139
140 METHOD(daemon_t, keep_cap, void,
141 private_daemon_t *this, u_int cap)
142 {
143 #ifdef CAPABILITIES_LIBCAP
144 cap_set_flag(this->caps, CAP_EFFECTIVE, 1, &cap, CAP_SET);
145 cap_set_flag(this->caps, CAP_INHERITABLE, 1, &cap, CAP_SET);
146 cap_set_flag(this->caps, CAP_PERMITTED, 1, &cap, CAP_SET);
147 #endif /* CAPABILITIES_LIBCAP */
148 #ifdef CAPABILITIES_NATIVE
149 this->caps.effective |= 1 << cap;
150 this->caps.permitted |= 1 << cap;
151 this->caps.inheritable |= 1 << cap;
152 #endif /* CAPABILITIES_NATIVE */
153 }
154
155 METHOD(daemon_t, drop_capabilities, bool,
156 private_daemon_t *this)
157 {
158 #ifdef CAPABILITIES_LIBCAP
159 if (cap_set_proc(this->caps) != 0)
160 {
161 return FALSE;
162 }
163 #endif /* CAPABILITIES_LIBCAP */
164 #ifdef CAPABILITIES_NATIVE
165 struct __user_cap_header_struct header = {
166 .version = _LINUX_CAPABILITY_VERSION,
167 };
168 if (capset(&header, &this->caps) != 0)
169 {
170 return FALSE;
171 }
172 #endif /* CAPABILITIES_NATIVE */
173 return TRUE;
174 }
175
176 METHOD(daemon_t, start, void,
177 private_daemon_t *this)
178 {
179 /* start the engine, go multithreaded */
180 charon->processor->set_threads(charon->processor,
181 lib->settings->get_int(lib->settings, "charon.threads",
182 DEFAULT_THREADS));
183 }
184
185 /**
186 * Log loaded plugins
187 */
188 static void print_plugins()
189 {
190 char buf[512], *plugin;
191 int len = 0;
192 enumerator_t *enumerator;
193
194 buf[0] = '\0';
195 enumerator = lib->plugins->create_plugin_enumerator(lib->plugins);
196 while (len < sizeof(buf) && enumerator->enumerate(enumerator, &plugin))
197 {
198 len += snprintf(&buf[len], sizeof(buf)-len, "%s ", plugin);
199 }
200 enumerator->destroy(enumerator);
201 DBG1(DBG_DMN, "loaded plugins: %s", buf);
202 }
203
204 /**
205 * Initialize logging
206 */
207 static void initialize_loggers(private_daemon_t *this, bool use_stderr,
208 level_t levels[])
209 {
210 sys_logger_t *sys_logger;
211 file_logger_t *file_logger;
212 enumerator_t *enumerator;
213 char *facility, *filename;
214 int loggers_defined = 0;
215 debug_t group;
216 level_t def;
217 bool append;
218 FILE *file;
219
220 /* setup sysloggers */
221 enumerator = lib->settings->create_section_enumerator(lib->settings,
222 "charon.syslog");
223 while (enumerator->enumerate(enumerator, &facility))
224 {
225 loggers_defined++;
226 if (streq(facility, "daemon"))
227 {
228 sys_logger = sys_logger_create(LOG_DAEMON);
229 }
230 else if (streq(facility, "auth"))
231 {
232 sys_logger = sys_logger_create(LOG_AUTHPRIV);
233 }
234 else
235 {
236 continue;
237 }
238 def = lib->settings->get_int(lib->settings,
239 "charon.syslog.%s.default", 1, facility);
240 for (group = 0; group < DBG_MAX; group++)
241 {
242 sys_logger->set_level(sys_logger, group,
243 lib->settings->get_int(lib->settings,
244 "charon.syslog.%s.%N", def,
245 facility, debug_lower_names, group));
246 }
247 this->public.sys_loggers->insert_last(this->public.sys_loggers,
248 sys_logger);
249 this->public.bus->add_listener(this->public.bus, &sys_logger->listener);
250 }
251 enumerator->destroy(enumerator);
252
253 /* and file loggers */
254 enumerator = lib->settings->create_section_enumerator(lib->settings,
255 "charon.filelog");
256 while (enumerator->enumerate(enumerator, &filename))
257 {
258 loggers_defined++;
259 if (streq(filename, "stderr"))
260 {
261 file = stderr;
262 }
263 else if (streq(filename, "stdout"))
264 {
265 file = stdout;
266 }
267 else
268 {
269 append = lib->settings->get_bool(lib->settings,
270 "charon.filelog.%s.append", TRUE, filename);
271 file = fopen(filename, append ? "a" : "w");
272 if (file == NULL)
273 {
274 DBG1(DBG_DMN, "opening file %s for logging failed: %s",
275 filename, strerror(errno));
276 continue;
277 }
278 if (lib->settings->get_bool(lib->settings,
279 "charon.filelog.%s.flush_line", FALSE, filename))
280 {
281 setlinebuf(file);
282 }
283 }
284 file_logger = file_logger_create(file,
285 lib->settings->get_str(lib->settings,
286 "charon.filelog.%s.time_format", NULL, filename));
287 def = lib->settings->get_int(lib->settings,
288 "charon.filelog.%s.default", 1, filename);
289 for (group = 0; group < DBG_MAX; group++)
290 {
291 file_logger->set_level(file_logger, group,
292 lib->settings->get_int(lib->settings,
293 "charon.filelog.%s.%N", def,
294 filename, debug_lower_names, group));
295 }
296 this->public.file_loggers->insert_last(this->public.file_loggers,
297 file_logger);
298 this->public.bus->add_listener(this->public.bus, &file_logger->listener);
299
300 }
301 enumerator->destroy(enumerator);
302
303 /* set up legacy style default loggers provided via command-line */
304 if (!loggers_defined)
305 {
306 /* set up default stdout file_logger */
307 file_logger = file_logger_create(stdout, NULL);
308 this->public.bus->add_listener(this->public.bus, &file_logger->listener);
309 this->public.file_loggers->insert_last(this->public.file_loggers,
310 file_logger);
311 /* set up default daemon sys_logger */
312 sys_logger = sys_logger_create(LOG_DAEMON);
313 this->public.bus->add_listener(this->public.bus, &sys_logger->listener);
314 this->public.sys_loggers->insert_last(this->public.sys_loggers,
315 sys_logger);
316 for (group = 0; group < DBG_MAX; group++)
317 {
318 sys_logger->set_level(sys_logger, group, levels[group]);
319 if (use_stderr)
320 {
321 file_logger->set_level(file_logger, group, levels[group]);
322 }
323 }
324
325 /* set up default auth sys_logger */
326 sys_logger = sys_logger_create(LOG_AUTHPRIV);
327 this->public.bus->add_listener(this->public.bus, &sys_logger->listener);
328 this->public.sys_loggers->insert_last(this->public.sys_loggers,
329 sys_logger);
330 sys_logger->set_level(sys_logger, DBG_ANY, LEVEL_AUDIT);
331 }
332 }
333
334 METHOD(daemon_t, initialize, bool,
335 private_daemon_t *this, bool syslog, level_t levels[])
336 {
337 /* for uncritical pseudo random numbers */
338 srandom(time(NULL) + getpid());
339
340 /* setup bus and it's listeners first to enable log output */
341 this->public.bus = bus_create();
342 /* set up hook to log dbg message in library via charons message bus */
343 dbg_old = dbg;
344 dbg = dbg_bus;
345
346 initialize_loggers(this, !syslog, levels);
347
348 DBG1(DBG_DMN, "Starting IKEv2 charon daemon (strongSwan "VERSION")");
349
350 if (lib->integrity)
351 {
352 DBG1(DBG_DMN, "integrity tests enabled:");
353 DBG1(DBG_DMN, "lib 'libstrongswan': passed file and segment integrity tests");
354 DBG1(DBG_DMN, "lib 'libhydra': passed file and segment integrity tests");
355 DBG1(DBG_DMN, "lib 'libcharon': passed file and segment integrity tests");
356 DBG1(DBG_DMN, "daemon 'charon': passed file integrity test");
357 }
358
359 /* load secrets, ca certificates and crls */
360 this->public.processor = processor_create();
361 this->public.scheduler = scheduler_create();
362 this->public.credentials = credential_manager_create();
363 this->public.controller = controller_create();
364 this->public.eap = eap_manager_create();
365 this->public.sim = sim_manager_create();
366 this->public.backends = backend_manager_create();
367 this->public.kernel_interface = kernel_interface_create();
368 this->public.socket = socket_manager_create();
369 this->public.traps = trap_manager_create();
370
371 /* load plugins, further infrastructure may need it */
372 if (!lib->plugins->load(lib->plugins, NULL,
373 lib->settings->get_str(lib->settings, "charon.load", PLUGINS)))
374 {
375 return FALSE;
376 }
377
378 print_plugins();
379
380 this->public.ike_sa_manager = ike_sa_manager_create();
381 if (this->public.ike_sa_manager == NULL)
382 {
383 return FALSE;
384 }
385 this->public.sender = sender_create();
386 this->public.receiver = receiver_create();
387 if (this->public.receiver == NULL)
388 {
389 return FALSE;
390 }
391
392 #ifdef ME
393 this->public.connect_manager = connect_manager_create();
394 if (this->public.connect_manager == NULL)
395 {
396 return FALSE;
397 }
398 this->public.mediation_manager = mediation_manager_create();
399 #endif /* ME */
400
401 return TRUE;
402 }
403
404 /**
405 * Create the daemon.
406 */
407 private_daemon_t *daemon_create()
408 {
409 private_daemon_t *this;
410
411 INIT(this,
412 .public = {
413 .keep_cap = _keep_cap,
414 .drop_capabilities = _drop_capabilities,
415 .initialize = _initialize,
416 .start = _start,
417 .file_loggers = linked_list_create(),
418 .sys_loggers = linked_list_create(),
419 },
420 );
421
422 #ifdef CAPABILITIES
423 #ifdef CAPABILITIES_LIBCAP
424 this->caps = cap_init();
425 #endif /* CAPABILITIES_LIBCAP */
426 keep_cap(this, CAP_NET_ADMIN);
427 if (lib->leak_detective)
428 {
429 keep_cap(this, CAP_SYS_NICE);
430 }
431 #endif /* CAPABILITIES */
432
433 return this;
434 }
435
436 /**
437 * Described in header.
438 */
439 void libcharon_deinit()
440 {
441
442 destroy((private_daemon_t*)charon);
443 charon = NULL;
444 }
445
446 /**
447 * Described in header.
448 */
449 bool libcharon_init()
450 {
451 private_daemon_t *this;
452
453 this = daemon_create();
454 charon = &this->public;
455
456 lib->printf_hook->add_handler(lib->printf_hook, 'P',
457 proposal_printf_hook,
458 PRINTF_HOOK_ARGTYPE_POINTER,
459 PRINTF_HOOK_ARGTYPE_END);
460
461 if (lib->integrity &&
462 !lib->integrity->check(lib->integrity, "libcharon", libcharon_init))
463 {
464 dbg(DBG_DMN, 1, "integrity check of libcharon failed");
465 return FALSE;
466 }
467
468 return TRUE;
469 }