#include <errno.h>
#include <fcntl.h>
#include <priv_utils.h>
#include <signal.h>
#include <stdlib.h>
#include <stdio.h>
#include <strings.h>
#include <sys/param.h>
#include <sys/stat.h>
#include <unistd.h>
#include "ipmgmt_impl.h"
#include <zone.h>
#include <libipadm.h>
#include <libdladm.h>
#include <libdllink.h>
#include <net/route.h>
#include <ipadm_ipmgmt.h>
#include <sys/brand.h>
const char *progname;
pthread_rwlock_t ipmgmt_dbconf_lock = PTHREAD_RWLOCK_INITIALIZER;
ipmgmt_aobjmap_list_t aobjmap;
static int pfds[2];
static int ipmgmt_door_fd = -1;
static void ipmgmt_exit(int);
static int ipmgmt_init();
static int ipmgmt_init_privileges();
static void ipmgmt_ngz_persist_if();
static ipadm_handle_t iph;
typedef struct ipmgmt_pif_s {
struct ipmgmt_pif_s *pif_next;
char pif_ifname[LIFNAMSIZ];
boolean_t pif_v4;
boolean_t pif_v6;
} ipmgmt_pif_t;
static ipmgmt_pif_t *ngz_pifs;
static int
ipmgmt_db_init()
{
int fd, err, scferr;
scf_resources_t res;
boolean_t upgrade = B_TRUE;
if ((scferr = ipmgmt_create_scf_resources(IPMGMTD_FMRI, &res)) == 0)
upgrade = ipmgmt_needs_upgrade(&res);
if (upgrade) {
err = ipmgmt_db_walk(ipmgmt_db_upgrade, NULL, IPADM_DB_WRITE);
if (err != 0) {
ipmgmt_log(LOG_ERR, "could not upgrade the "
"ipadm data-store: %s", strerror(err));
err = 0;
} else {
if (scferr == 0)
ipmgmt_update_dbver(&res);
}
}
if (scferr == 0)
ipmgmt_release_scf_resources(&res);
if ((fd = open(ADDROBJ_MAPPING_DB_FILE, O_CREAT|O_RDONLY,
IPADM_FILE_MODE)) == -1) {
err = errno;
ipmgmt_log(LOG_ERR, "could not open %s: %s",
ADDROBJ_MAPPING_DB_FILE, strerror(err));
return (err);
}
(void) close(fd);
aobjmap.aobjmap_head = NULL;
(void) pthread_rwlock_init(&aobjmap.aobjmap_rwlock, NULL);
if ((err = ipadm_rw_db(ipmgmt_aobjmap_init, NULL,
ADDROBJ_MAPPING_DB_FILE, 0, IPADM_DB_READ)) != 0) {
if (err != ENOENT)
return (err);
err = 0;
}
ipmgmt_ngz_persist_if();
return (err);
}
static int
ipmgmt_door_init()
{
int fd;
int err;
if ((fd = open(IPMGMT_DOOR, O_CREAT|O_RDONLY, IPADM_FILE_MODE)) == -1) {
err = errno;
ipmgmt_log(LOG_ERR, "could not open %s: %s",
IPMGMT_DOOR, strerror(err));
return (err);
}
(void) close(fd);
if ((ipmgmt_door_fd = door_create(ipmgmt_handler, NULL,
DOOR_REFUSE_DESC | DOOR_NO_CANCEL)) == -1) {
err = errno;
ipmgmt_log(LOG_ERR, "failed to create door: %s", strerror(err));
return (err);
}
(void) fdetach(IPMGMT_DOOR);
if (fattach(ipmgmt_door_fd, IPMGMT_DOOR) != 0) {
err = errno;
ipmgmt_log(LOG_ERR, "failed to attach door to %s: %s",
IPMGMT_DOOR, strerror(err));
goto fail;
}
return (0);
fail:
(void) door_revoke(ipmgmt_door_fd);
ipmgmt_door_fd = -1;
return (err);
}
static void
ipmgmt_door_fini()
{
if (ipmgmt_door_fd == -1)
return;
(void) fdetach(IPMGMT_DOOR);
if (door_revoke(ipmgmt_door_fd) == -1) {
ipmgmt_log(LOG_ERR, "failed to revoke access to door %s: %s",
IPMGMT_DOOR, strerror(errno));
}
}
static int
ipmgmt_init()
{
int err;
if (signal(SIGTERM, ipmgmt_exit) == SIG_ERR ||
signal(SIGINT, ipmgmt_exit) == SIG_ERR) {
err = errno;
ipmgmt_log(LOG_ERR, "signal() for SIGTERM/INT failed: %s",
strerror(err));
return (err);
}
if ((err = ipmgmt_db_init()) != 0 || (err = ipmgmt_door_init()) != 0)
return (err);
return (0);
}
static void
ipmgmt_inform_parent_exit(int rv)
{
if (write(pfds[1], &rv, sizeof (int)) != sizeof (int)) {
ipmgmt_log(LOG_WARNING,
"failed to inform parent process of status: %s",
strerror(errno));
(void) close(pfds[1]);
exit(EXIT_FAILURE);
}
(void) close(pfds[1]);
}
static void
ipmgmt_exit(int signo)
{
(void) close(pfds[1]);
ipmgmt_door_fini();
exit(EXIT_FAILURE);
}
static void
ipmgmt_persist_if_cb(char *ifname, boolean_t v4, boolean_t v6)
{
ipmgmt_pif_t *pif;
pif = calloc(1, sizeof (*pif));
if (pif == NULL) {
ipmgmt_log(LOG_WARNING,
"Could not allocate memory to configure %s", ifname);
return;
}
(void) strlcpy(pif->pif_ifname, ifname, sizeof (pif->pif_ifname));
pif->pif_v4 = v4;
pif->pif_v6 = v6;
pif->pif_next = ngz_pifs;
ngz_pifs = pif;
}
static void
ipmgmt_ngz_init()
{
zoneid_t zoneid;
boolean_t firstboot = B_TRUE, s10c = B_FALSE;
char brand[MAXNAMELEN];
ipadm_status_t ipstatus;
zoneid = getzoneid();
if (zoneid != GLOBAL_ZONEID) {
if (zone_getattr(zoneid, ZONE_ATTR_BRAND, brand,
sizeof (brand)) < 0) {
ipmgmt_log(LOG_ERR, "Could not get brand name");
return;
}
if (strcmp(brand, NATIVE_BRAND_NAME) == 0)
firstboot = ipmgmt_ngz_firstboot_postinstall();
else
s10c = B_TRUE;
if (!firstboot)
return;
ipstatus = ipadm_open(&iph, IPH_IPMGMTD);
if (ipstatus != IPADM_SUCCESS) {
ipmgmt_log(LOG_ERR, "could not open ipadm handle",
ipadm_status2str(ipstatus));
return;
}
(void) ipadm_init_net_from_gz(iph, NULL,
(s10c ? NULL : ipmgmt_persist_if_cb));
ipadm_close(iph);
}
}
static int
ipmgmt_init_privileges()
{
struct stat statbuf;
int err;
if (stat(IPADM_TMPFS_DIR, &statbuf) < 0) {
if (mkdir(IPADM_TMPFS_DIR, (mode_t)0755) < 0) {
err = errno;
goto fail;
}
} else {
if ((statbuf.st_mode & S_IFMT) != S_IFDIR) {
err = ENOTDIR;
goto fail;
}
}
if ((chmod(IPADM_TMPFS_DIR, 0755) < 0) ||
(chown(IPADM_TMPFS_DIR, UID_NETADM, GID_NETADM) < 0)) {
err = errno;
goto fail;
}
ipmgmt_ngz_init();
ipmgmt_init_prop();
if (__init_daemon_priv(PU_RESETGROUPS|PU_CLEARLIMITSET, UID_NETADM,
GID_NETADM, NULL) == -1) {
err = EPERM;
goto fail;
}
return (0);
fail:
(void) ipmgmt_log(LOG_ERR, "failed to initialize the daemon: %s",
strerror(err));
return (err);
}
static int
closefunc(void *arg, int fd)
{
if (fd != pfds[1])
(void) close(fd);
return (0);
}
static boolean_t
ipmgmt_daemonize(void)
{
pid_t pid;
int rv;
if (pipe(pfds) < 0) {
(void) fprintf(stderr, "%s: pipe() failed: %s\n",
progname, strerror(errno));
exit(EXIT_FAILURE);
}
if ((pid = fork()) == -1) {
(void) fprintf(stderr, "%s: fork() failed: %s\n",
progname, strerror(errno));
exit(EXIT_FAILURE);
} else if (pid > 0) {
(void) close(pfds[1]);
if (read(pfds[0], &rv, sizeof (int)) != sizeof (int)) {
(void) kill(pid, SIGKILL);
rv = EXIT_FAILURE;
}
(void) close(pfds[0]);
exit(rv);
}
(void) close(pfds[0]);
(void) setsid();
(void) fdwalk(closefunc, NULL);
(void) chdir("/");
openlog(progname, LOG_PID, LOG_DAEMON);
return (B_TRUE);
}
int
main(int argc, char *argv[])
{
int opt;
boolean_t fg = B_FALSE;
progname = strrchr(argv[0], '/');
if (progname != NULL)
progname++;
else
progname = argv[0];
while ((opt = getopt(argc, argv, "f")) != EOF) {
switch (opt) {
case 'f':
fg = B_TRUE;
break;
default:
(void) fprintf(stderr, "Usage: %s [-f]\n", progname);
return (EXIT_FAILURE);
}
}
if (!fg && getenv("SMF_FMRI") == NULL) {
(void) fprintf(stderr,
"ipmgmtd is a smf(7) managed service and cannot be run "
"from the command line.\n");
return (EINVAL);
}
if (!fg && !ipmgmt_daemonize())
return (EXIT_FAILURE);
if (ipmgmt_init_privileges() != 0)
goto child_out;
if (ipmgmt_init() != 0)
goto child_out;
ipmgmt_inform_parent_exit(EXIT_SUCCESS);
for (;;)
(void) pause();
child_out:
ipmgmt_inform_parent_exit(EXIT_FAILURE);
return (EXIT_FAILURE);
}
static void
ipmgmt_ngz_persist_if()
{
ipmgmt_pif_t *pif, *next;
ipmgmt_if_arg_t ifarg;
for (pif = ngz_pifs; pif != NULL; pif = next) {
next = pif->pif_next;
bzero(&ifarg, sizeof (ifarg));
(void) strlcpy(ifarg.ia_ifname, pif->pif_ifname,
sizeof (ifarg.ia_ifname));
ifarg.ia_flags = IPMGMT_PERSIST;
if (pif->pif_v4 &&
!ipmgmt_persist_if_exists(pif->pif_ifname, AF_INET)) {
ifarg.ia_family = AF_INET;
(void) ipmgmt_persist_if(&ifarg);
}
if (pif->pif_v6 &&
!ipmgmt_persist_if_exists(pif->pif_ifname, AF_INET6)) {
ifarg.ia_family = AF_INET6;
(void) ipmgmt_persist_if(&ifarg);
}
free(pif);
}
ngz_pifs = NULL;
}