/*
* CDDL HEADER START
*
* The contents of this file are subject to the terms of the
* Common Development and Distribution License (the "License").
* You may not use this file except in compliance with the License.
*
* You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE
* See the License for the specific language governing permissions
* and limitations under the License.
*
* When distributing Covered Code, include this CDDL HEADER in each
* file and include the License file at usr/src/OPENSOLARIS.LICENSE.
* If applicable, add the following below this CDDL HEADER, with the
* fields enclosed by brackets "[]" replaced with your own identifying
* information: Portions Copyright [yyyy] [name of copyright owner]
*
* CDDL HEADER END
*/
/*
*/
/*
* The ipmgmtd daemon is started by ip-interface-management SMF service. This
* daemon is used to manage, mapping of 'address object' to 'interface name' and
* 'logical interface number', on which the address is created. It also provides
* a means to update the ipadm persistent data-store.
*
* The daemon tracks the <addrobj, lifname> mapping in-memory using a linked
* list `aobjmap'. Access to this list is synchronized using a readers-writers
* lock. The active <addrobj, lifname> mapping is kept in
* /etc/svc/volatile/ipadm/aobjmap.conf cache file, so that the mapping can be
* recovered when ipmgmtd exits for some reason (e.g., when ipmgmtd is restarted
* using svcadm or accidentally killed).
*
* Today, the persistent configuration of interfaces, addresses and protocol
* properties is kept in /etc/ipadm/ipadm.conf. The access to the persistent
* data store is synchronized using reader-writers lock `ipmgmt_dbconf_lock'.
*
* The communication between the library, libipadm.so and the daemon, is through
* doors RPC. The library interacts with the daemon using the commands defined
* by `ipmgmt_door_cmd_type_t'. Further any 'write' operation would require
* the `NETWORK_INTERFACE_CONFIG_AUTH' authorization.
*
* On reboot, the aforementioned SMF service starts the daemon before any other
* networking service that configures network IP interfaces is started.
* network interfaces, interface properties and addresses.
*/
#include <errno.h>
#include <fcntl.h>
#include <priv_utils.h>
#include <signal.h>
#include <stdlib.h>
#include <stdio.h>
#include <strings.h>
#include <unistd.h>
#include "ipmgmt_impl.h"
#include <zone.h>
#include <libipadm.h>
#include <libdladm.h>
#include <libdllink.h>
#include <ipadm_ipmgmt.h>
const char *progname;
/* tracks address object to {ifname|logical number|interface id} mapping */
/* used to communicate failure to parent process, which spawned the daemon */
/* file descriptor to IPMGMT_DOOR */
static void ipmgmt_exit(int);
static int ipmgmt_init();
static int ipmgmt_init_privileges();
static void ipmgmt_ngz_persist_if();
typedef struct ipmgmt_pif_s {
} ipmgmt_pif_t;
static int
{
/*
* Check to see if we need to upgrade the data-store. We need to
* upgrade, if the version of the data-store does not match with
* IPADM_DB_VERSION. Further, if we cannot determine the current
* version of the data-store, we always err on the side of caution
* and upgrade the data-store to current version.
*/
if (upgrade) {
if (err != 0) {
err = 0;
} else {
/*
* upgrade was success, let's update SCF with the
* current data-store version number.
*/
if (scferr == 0)
}
}
if (scferr == 0)
/* creates the address object data store, if it doesn't exist */
IPADM_FILE_MODE)) == -1) {
return (err);
}
/*
* If the daemon is recovering from a crash or restart, read the
* address object to logical interface mapping and build an in-memory
* representation of the mapping. That is, build `aobjmap' structure
* from address object data store.
*/
ADDROBJ_MAPPING_DB_FILE, 0, IPADM_DB_READ)) != 0) {
/* if there was nothing to initialize, it's fine */
return (err);
err = 0;
}
ipmgmt_ngz_persist_if(); /* create persistent interface info for NGZ */
return (err);
}
static int
{
int fd;
int err;
/* create the door file for ipmgmtd */
return (err);
}
return (err);
}
/*
* fdetach first in case a previous daemon instance exited
* ungracefully.
*/
(void) fdetach(IPMGMT_DOOR);
goto fail;
}
return (0);
fail:
(void) door_revoke(ipmgmt_door_fd);
ipmgmt_door_fd = -1;
return (err);
}
static void
{
if (ipmgmt_door_fd == -1)
return;
(void) fdetach(IPMGMT_DOOR);
}
}
static int
{
int err;
return (err);
}
return (err);
return (0);
}
/*
* This is called by the child process to inform the parent process to
* exit with the given return value.
*/
static void
{
"failed to inform parent process of status: %s",
}
}
/*ARGSUSED*/
static void
{
}
/*
* On the first reboot after installation of an ipkg zone,
* ipmgmt_persist_if_cb() is used in non-global zones to track the interfaces
* that have IP address configuration assignments from the global zone.
* Persistent configuration for the interfaces is created on the first boot
* by ipmgmtd, and the addresses assigned to the interfaces by the GZ
* will be subsequently configured when the interface is enabled.
* Note that ipmgmt_persist_if_cb() only sets up a list of interfaces
* that need to be persisted- the actual update of the ipadm data-store happens
*/
static void
{
"Could not allocate memory to configure %s", ifname);
return;
}
}
/*
* ipmgmt_ngz_init() initializes exclusive-IP stack non-global zones by
* extracting configuration that has been saved in the kernel and applying
* it at zone boot.
*/
static void
{
if (zoneid != GLOBAL_ZONEID) {
sizeof (brand)) < 0) {
return;
}
/*
* firstboot is always true for S10C zones, where ipadm is not
* available for restoring persistent configuration.
*/
else
if (!firstboot)
return;
if (ipstatus != IPADM_SUCCESS) {
return;
}
/*
* Only pass down the callback to persist the interface
* for NATIVE (ipkg) zones.
*/
}
}
/*
* Set the uid of this daemon to the "netadm" user. Finish the following
* operations before setuid() because they need root privileges:
*
*/
static int
{
int err;
/* create the IPADM_TMPFS_DIR directory */
goto fail;
}
} else {
goto fail;
}
}
goto fail;
}
/*
* initialize any NGZ specific network information before dropping
* privileges. We need these privileges to plumb IP interfaces handed
* down from the GZ (for dlpi_open() etc.) and also to configure the
* address itself (for any IPI_PRIV ioctls like SLIFADDR)
*/
/*
* Apply all protocol module properties. We need to apply all protocol
* properties before we drop root privileges.
*/
/*
* limit the privileges of this daemon and set the uid of this
* daemon to UID_NETADM
*/
goto fail;
}
return (0);
fail:
return (err);
}
/*
* Keep the pfds fd open, close other fds.
*/
/*ARGSUSED*/
static int
{
return (0);
}
/*
* We cannot use libc's daemon() because the door we create is associated with
* the process ID. If we create the door before the call to daemon(), it will
* be associated with the parent and it's incorrect. On the other hand if we
* create the door later, after the call to daemon(), parent process exits
* early and gives a false notion to SMF that 'ipmgmtd' is up and running,
* which is incorrect. So, we have our own daemon() equivalent.
*/
static boolean_t
ipmgmt_daemonize(void)
{
int rv;
}
} else if (pid > 0) { /* Parent */
/*
* Parent should not exit early, it should wait for the child
* SMF will think 'ipmgmtd' is up and would start all the
* depended services.
*
* If the child process exits unexpectedly, read() returns -1.
*/
rv = EXIT_FAILURE;
}
}
/* Child */
(void) setsid();
/* close all files except pfds[1] */
(void) chdir("/");
return (B_TRUE);
}
int
{
int opt;
progname++;
else
/* Process options */
switch (opt) {
case 'f':
break;
default:
return (EXIT_FAILURE);
}
}
"ipmgmtd is a smf(5) managed service and cannot be run "
"from the command line.\n");
return (EINVAL);
}
if (!fg && !ipmgmt_daemonize())
return (EXIT_FAILURE);
if (ipmgmt_init_privileges() != 0)
goto child_out;
if (ipmgmt_init() != 0)
goto child_out;
/* Inform the parent process that it can successfully exit */
for (;;)
(void) pause();
/* return from main() forcibly exits an MT process */
return (EXIT_FAILURE);
}
/*
* Return TRUE if `ifname' has persistent configuration for the `af' address
* family in the datastore
*/
static boolean_t
{
}
}
return (exists);
}
/*
* Persist any NGZ interfaces assigned to us from the global zone if they do
* not already exist in the persistent db. We need to
* do this before any calls to ipadm_enable_if() can succeed (i.e.,
* before opening up for door_calls), and after setuid to 'netadm' so that
* the persistent db is created with the right permissions.
*/
static void
{
(void) ipmgmt_persist_if(&ifarg);
}
(void) ipmgmt_persist_if(&ifarg);
}
}
}