capabilities: CAP_CHOWN might be required by many plugins opening UNIX sockets
[strongswan.git] / src / libcharon / plugins / whitelist / whitelist_plugin.c
index f2ed7ba..4f397d7 100644 (file)
@@ -16,6 +16,7 @@
 #include "whitelist_plugin.h"
 
 #include "whitelist_listener.h"
+#include "whitelist_control.h"
 
 #include <daemon.h>
 
@@ -35,13 +36,52 @@ struct private_whitelist_plugin_t {
         * Listener checking whitelist entries during authorization
         */
        whitelist_listener_t *listener;
+
+       /**
+        * Whitelist control socket
+        */
+       whitelist_control_t *control;
 };
 
+METHOD(plugin_t, get_name, char*,
+       private_whitelist_plugin_t *this)
+{
+       return "whitelist";
+}
+
+/**
+ * Register listener
+ */
+static bool plugin_cb(private_whitelist_plugin_t *this,
+                                         plugin_feature_t *feature, bool reg, void *cb_data)
+{
+       if (reg)
+       {
+               charon->bus->add_listener(charon->bus, &this->listener->listener);
+       }
+       else
+       {
+               charon->bus->remove_listener(charon->bus, &this->listener->listener);
+       }
+       return TRUE;
+}
+
+METHOD(plugin_t, get_features, int,
+       private_whitelist_plugin_t *this, plugin_feature_t *features[])
+{
+       static plugin_feature_t f[] = {
+               PLUGIN_CALLBACK((plugin_feature_callback_t)plugin_cb, NULL),
+                       PLUGIN_PROVIDE(CUSTOM, "whitelist"),
+       };
+       *features = f;
+       return countof(f);
+}
+
 METHOD(plugin_t, destroy, void,
        private_whitelist_plugin_t *this)
 {
-       charon->bus->remove_listener(charon->bus, &this->listener->listener);
        this->listener->destroy(this->listener);
+       DESTROY_IF(this->control);
        free(this);
 }
 
@@ -52,16 +92,23 @@ plugin_t *whitelist_plugin_create()
 {
        private_whitelist_plugin_t *this;
 
+       if (!lib->caps->keep(lib->caps, CAP_CHOWN))
+       {       /* required to chown(2) control socket */
+               DBG1(DBG_CFG, "whitelist plugin requires CAP_CHOWN capability");
+               return NULL;
+       }
+
        INIT(this,
                .public = {
                        .plugin = {
+                               .get_name = _get_name,
+                               .get_features = _get_features,
                                .destroy = _destroy,
                        },
                },
                .listener = whitelist_listener_create(),
        );
-
-       charon->bus->add_listener(charon->bus, &this->listener->listener);
+       this->control = whitelist_control_create(this->listener);
 
        return &this->public.plugin;
 }