Use newer Linux capability native API, if available
[strongswan.git] / src / libcharon / daemon.c
1 /*
2 * Copyright (C) 2006-2010 Tobias Brunner
3 * Copyright (C) 2005-2009 Martin Willi
4 * Copyright (C) 2006 Daniel Roethlisberger
5 * Copyright (C) 2005 Jan Hutter
6 * Hochschule fuer Technik Rapperswil
7 *
8 * This program is free software; you can redistribute it and/or modify it
9 * under the terms of the GNU General Public License as published by the
10 * Free Software Foundation; either version 2 of the License, or (at your
11 * option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
12 *
13 * This program is distributed in the hope that it will be useful, but
14 * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
15 * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
16 * for more details.
17 */
18
19 #include <stdio.h>
20 #include <sys/types.h>
21 #include <unistd.h>
22 #include <time.h>
23
24 #ifdef CAPABILITIES
25 # ifdef HAVE_SYS_CAPABILITY_H
26 # include <sys/capability.h>
27 # elif defined(CAPABILITIES_NATIVE)
28 # include <linux/capability.h>
29 # endif /* CAPABILITIES_NATIVE */
30 #endif /* CAPABILITIES */
31
32 #include "daemon.h"
33
34 #include <library.h>
35 #include <config/proposal.h>
36 #include <kernel/kernel_handler.h>
37
38 typedef struct private_daemon_t private_daemon_t;
39
40 /**
41 * Private additions to daemon_t, contains threads and internal functions.
42 */
43 struct private_daemon_t {
44 /**
45 * Public members of daemon_t.
46 */
47 daemon_t public;
48
49 /**
50 * Handler for kernel events
51 */
52 kernel_handler_t *kernel_handler;
53
54 /**
55 * capabilities to keep
56 */
57 #ifdef CAPABILITIES_LIBCAP
58 cap_t caps;
59 #endif /* CAPABILITIES_LIBCAP */
60 #ifdef CAPABILITIES_NATIVE
61 struct __user_cap_data_struct caps[2];
62 #endif /* CAPABILITIES_NATIVE */
63
64 };
65
66 /**
67 * One and only instance of the daemon.
68 */
69 daemon_t *charon;
70
71 /**
72 * hook in library for debugging messages
73 */
74 extern void (*dbg) (debug_t group, level_t level, char *fmt, ...);
75
76 /**
77 * we store the previous debug function so we can reset it
78 */
79 static void (*dbg_old) (debug_t group, level_t level, char *fmt, ...);
80
81 /**
82 * Logging hook for library logs, spreads debug message over bus
83 */
84 static void dbg_bus(debug_t group, level_t level, char *fmt, ...)
85 {
86 va_list args;
87
88 va_start(args, fmt);
89 charon->bus->vlog(charon->bus, group, level, fmt, args);
90 va_end(args);
91 }
92
93 /**
94 * Clean up all daemon resources
95 */
96 static void destroy(private_daemon_t *this)
97 {
98 /* terminate all idle threads */
99 lib->processor->set_threads(lib->processor, 0);
100
101 /* close all IKE_SAs */
102 if (this->public.ike_sa_manager)
103 {
104 this->public.ike_sa_manager->flush(this->public.ike_sa_manager);
105 }
106 DESTROY_IF(this->public.receiver);
107 DESTROY_IF(this->public.sender);
108 /* unload plugins to release threads */
109 lib->plugins->unload(lib->plugins);
110 #ifdef CAPABILITIES_LIBCAP
111 cap_free(this->caps);
112 #endif /* CAPABILITIES_LIBCAP */
113 DESTROY_IF(this->kernel_handler);
114 DESTROY_IF(this->public.traps);
115 DESTROY_IF(this->public.ike_sa_manager);
116 DESTROY_IF(this->public.controller);
117 DESTROY_IF(this->public.eap);
118 DESTROY_IF(this->public.sim);
119 DESTROY_IF(this->public.tnccs);
120 #ifdef ME
121 DESTROY_IF(this->public.connect_manager);
122 DESTROY_IF(this->public.mediation_manager);
123 #endif /* ME */
124 DESTROY_IF(this->public.backends);
125 DESTROY_IF(this->public.socket);
126
127 /* rehook library logging, shutdown logging */
128 dbg = dbg_old;
129 DESTROY_IF(this->public.bus);
130 this->public.file_loggers->destroy_offset(this->public.file_loggers,
131 offsetof(file_logger_t, destroy));
132 this->public.sys_loggers->destroy_offset(this->public.sys_loggers,
133 offsetof(sys_logger_t, destroy));
134 free(this);
135 }
136
137 METHOD(daemon_t, keep_cap, void,
138 private_daemon_t *this, u_int cap)
139 {
140 #ifdef CAPABILITIES_LIBCAP
141 cap_set_flag(this->caps, CAP_EFFECTIVE, 1, &cap, CAP_SET);
142 cap_set_flag(this->caps, CAP_INHERITABLE, 1, &cap, CAP_SET);
143 cap_set_flag(this->caps, CAP_PERMITTED, 1, &cap, CAP_SET);
144 #endif /* CAPABILITIES_LIBCAP */
145 #ifdef CAPABILITIES_NATIVE
146 int i = 0;
147
148 if (cap >= 32)
149 {
150 i++;
151 cap -= 32;
152 }
153 this->caps[i].effective |= 1 << cap;
154 this->caps[i].permitted |= 1 << cap;
155 this->caps[i].inheritable |= 1 << cap;
156 #endif /* CAPABILITIES_NATIVE */
157 }
158
159 METHOD(daemon_t, drop_capabilities, bool,
160 private_daemon_t *this)
161 {
162 #ifdef CAPABILITIES_LIBCAP
163 if (cap_set_proc(this->caps) != 0)
164 {
165 return FALSE;
166 }
167 #endif /* CAPABILITIES_LIBCAP */
168 #ifdef CAPABILITIES_NATIVE
169 struct __user_cap_header_struct header = {
170 #if defined(_LINUX_CAPABILITY_VERSION_3)
171 .version = _LINUX_CAPABILITY_VERSION_3,
172 #elif defined(_LINUX_CAPABILITY_VERSION_2)
173 .version = _LINUX_CAPABILITY_VERSION_2,
174 #else
175 .version = _LINUX_CAPABILITY_VERSION_1,
176 #endif
177 };
178 if (capset(&header, this->caps) != 0)
179 {
180 return FALSE;
181 }
182 #endif /* CAPABILITIES_NATIVE */
183 return TRUE;
184 }
185
186 METHOD(daemon_t, start, void,
187 private_daemon_t *this)
188 {
189 /* start the engine, go multithreaded */
190 lib->processor->set_threads(lib->processor,
191 lib->settings->get_int(lib->settings, "charon.threads",
192 DEFAULT_THREADS));
193 }
194
195 /**
196 * Log loaded plugins
197 */
198 static void print_plugins()
199 {
200 char buf[512], *plugin;
201 int len = 0;
202 enumerator_t *enumerator;
203
204 buf[0] = '\0';
205 enumerator = lib->plugins->create_plugin_enumerator(lib->plugins);
206 while (len < sizeof(buf) && enumerator->enumerate(enumerator, &plugin))
207 {
208 len += snprintf(&buf[len], sizeof(buf)-len, "%s ", plugin);
209 }
210 enumerator->destroy(enumerator);
211 DBG1(DBG_DMN, "loaded plugins: %s", buf);
212 }
213
214 METHOD(daemon_t, initialize, bool,
215 private_daemon_t *this)
216 {
217 DBG1(DBG_DMN, "Starting IKEv2 charon daemon (strongSwan "VERSION")");
218
219 if (lib->integrity)
220 {
221 DBG1(DBG_DMN, "integrity tests enabled:");
222 DBG1(DBG_DMN, "lib 'libstrongswan': passed file and segment integrity tests");
223 DBG1(DBG_DMN, "lib 'libhydra': passed file and segment integrity tests");
224 DBG1(DBG_DMN, "lib 'libcharon': passed file and segment integrity tests");
225 DBG1(DBG_DMN, "daemon 'charon': passed file integrity test");
226 }
227
228 /* load plugins, further infrastructure may need it */
229 if (!lib->plugins->load(lib->plugins, NULL,
230 lib->settings->get_str(lib->settings, "charon.load", PLUGINS)))
231 {
232 return FALSE;
233 }
234
235 print_plugins();
236
237 this->public.ike_sa_manager = ike_sa_manager_create();
238 if (this->public.ike_sa_manager == NULL)
239 {
240 return FALSE;
241 }
242 this->public.sender = sender_create();
243 this->public.receiver = receiver_create();
244 if (this->public.receiver == NULL)
245 {
246 return FALSE;
247 }
248
249 #ifdef ME
250 this->public.connect_manager = connect_manager_create();
251 if (this->public.connect_manager == NULL)
252 {
253 return FALSE;
254 }
255 this->public.mediation_manager = mediation_manager_create();
256 #endif /* ME */
257
258 return TRUE;
259 }
260
261 /**
262 * Create the daemon.
263 */
264 private_daemon_t *daemon_create()
265 {
266 private_daemon_t *this;
267
268 INIT(this,
269 .public = {
270 .keep_cap = _keep_cap,
271 .drop_capabilities = _drop_capabilities,
272 .initialize = _initialize,
273 .start = _start,
274 .bus = bus_create(),
275 .file_loggers = linked_list_create(),
276 .sys_loggers = linked_list_create(),
277 },
278 );
279 charon = &this->public;
280 this->public.controller = controller_create();
281 this->public.eap = eap_manager_create();
282 this->public.sim = sim_manager_create();
283 this->public.tnccs = tnccs_manager_create();
284 this->public.backends = backend_manager_create();
285 this->public.socket = socket_manager_create();
286 this->public.traps = trap_manager_create();
287 this->kernel_handler = kernel_handler_create();
288
289 #ifdef CAPABILITIES
290 #ifdef CAPABILITIES_LIBCAP
291 this->caps = cap_init();
292 #endif /* CAPABILITIES_LIBCAP */
293 keep_cap(this, CAP_NET_ADMIN);
294 if (lib->leak_detective)
295 {
296 keep_cap(this, CAP_SYS_NICE);
297 }
298 #endif /* CAPABILITIES */
299
300 return this;
301 }
302
303 /**
304 * Described in header.
305 */
306 void libcharon_deinit()
307 {
308 destroy((private_daemon_t*)charon);
309 charon = NULL;
310 }
311
312 /**
313 * Described in header.
314 */
315 bool libcharon_init()
316 {
317 private_daemon_t *this;
318
319 this = daemon_create();
320
321 /* for uncritical pseudo random numbers */
322 srandom(time(NULL) + getpid());
323
324 /* set up hook to log dbg message in library via charons message bus */
325 dbg_old = dbg;
326 dbg = dbg_bus;
327
328 lib->printf_hook->add_handler(lib->printf_hook, 'P',
329 proposal_printf_hook,
330 PRINTF_HOOK_ARGTYPE_POINTER,
331 PRINTF_HOOK_ARGTYPE_END);
332
333 if (lib->integrity &&
334 !lib->integrity->check(lib->integrity, "libcharon", libcharon_init))
335 {
336 dbg(DBG_DMN, 1, "integrity check of libcharon failed");
337 return FALSE;
338 }
339
340 return TRUE;
341 }