6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail/*
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * CDDL HEADER START
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail *
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * The contents of this file are subject to the terms of the
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * Common Development and Distribution License (the "License").
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * You may not use this file except in compliance with the License.
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail *
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * or http://www.opensolaris.org/os/licensing.
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * See the License for the specific language governing permissions
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * and limitations under the License.
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail *
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * When distributing Covered Code, include this CDDL HEADER in each
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * file and include the License file at usr/src/OPENSOLARIS.LICENSE.
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * If applicable, add the following below this CDDL HEADER, with the
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * fields enclosed by brackets "[]" replaced with your own identifying
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * information: Portions Copyright [yyyy] [name of copyright owner]
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail *
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * CDDL HEADER END
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail */
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail/*
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan * Copyright (c) 2010, Oracle and/or its affiliates. All rights reserved.
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail */
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail/*
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * The ipmgmtd daemon is started by ip-interface-management SMF service. This
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * daemon is used to manage, mapping of 'address object' to 'interface name' and
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * 'logical interface number', on which the address is created. It also provides
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * a means to update the ipadm persistent data-store.
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail *
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * The daemon tracks the <addrobj, lifname> mapping in-memory using a linked
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * list `aobjmap'. Access to this list is synchronized using a readers-writers
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * lock. The active <addrobj, lifname> mapping is kept in
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * /etc/svc/volatile/ipadm/aobjmap.conf cache file, so that the mapping can be
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * recovered when ipmgmtd exits for some reason (e.g., when ipmgmtd is restarted
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * using svcadm or accidentally killed).
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail *
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * Today, the persistent configuration of interfaces, addresses and protocol
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * properties is kept in /etc/ipadm/ipadm.conf. The access to the persistent
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * data store is synchronized using reader-writers lock `ipmgmt_dbconf_lock'.
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail *
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * The communication between the library, libipadm.so and the daemon, is through
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * doors RPC. The library interacts with the daemon using the commands defined
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * by `ipmgmt_door_cmd_type_t'. Further any 'write' operation would require
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * the `NETWORK_INTERFACE_CONFIG_AUTH' authorization.
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail *
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * On reboot, the aforementioned SMF service starts the daemon before any other
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * networking service that configures network IP interfaces is started.
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * Afterwards, the network/physical SMF script instantiates the persisted
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * network interfaces, interface properties and addresses.
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail */
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail#include <errno.h>
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail#include <fcntl.h>
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail#include <priv_utils.h>
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail#include <signal.h>
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail#include <stdlib.h>
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail#include <stdio.h>
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail#include <strings.h>
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail#include <sys/param.h>
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail#include <sys/stat.h>
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail#include <unistd.h>
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail#include "ipmgmt_impl.h"
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan#include <zone.h>
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan#include <libipadm.h>
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan#include <libdladm.h>
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan#include <libdllink.h>
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan#include <net/route.h>
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan#include <ipadm_ipmgmt.h>
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan#include <sys/brand.h>
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbailconst char *progname;
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail/* readers-writers lock for reading/writing daemon data store */
8887b57dc579de11464fc6c74163d2595ce073afGirish Moodalbailpthread_rwlock_t ipmgmt_dbconf_lock = PTHREAD_RWLOCK_INITIALIZER;
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail/* tracks address object to {ifname|logical number|interface id} mapping */
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbailipmgmt_aobjmap_list_t aobjmap;
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail/* used to communicate failure to parent process, which spawned the daemon */
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbailstatic int pfds[2];
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail/* file descriptor to IPMGMT_DOOR */
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbailstatic int ipmgmt_door_fd = -1;
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbailstatic void ipmgmt_exit(int);
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbailstatic int ipmgmt_init();
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbailstatic int ipmgmt_init_privileges();
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhanstatic void ipmgmt_ngz_persist_if();
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhanstatic ipadm_handle_t iph;
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhantypedef struct ipmgmt_pif_s {
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan struct ipmgmt_pif_s *pif_next;
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan char pif_ifname[LIFNAMSIZ];
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan boolean_t pif_v4;
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan boolean_t pif_v6;
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan} ipmgmt_pif_t;
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhanstatic ipmgmt_pif_t *ngz_pifs;
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbailstatic int
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbailipmgmt_db_init()
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail{
8887b57dc579de11464fc6c74163d2595ce073afGirish Moodalbail int fd, err, scferr;
8887b57dc579de11464fc6c74163d2595ce073afGirish Moodalbail scf_resources_t res;
8887b57dc579de11464fc6c74163d2595ce073afGirish Moodalbail boolean_t upgrade = B_TRUE;
8887b57dc579de11464fc6c74163d2595ce073afGirish Moodalbail
8887b57dc579de11464fc6c74163d2595ce073afGirish Moodalbail /*
8887b57dc579de11464fc6c74163d2595ce073afGirish Moodalbail * Check to see if we need to upgrade the data-store. We need to
8887b57dc579de11464fc6c74163d2595ce073afGirish Moodalbail * upgrade, if the version of the data-store does not match with
8887b57dc579de11464fc6c74163d2595ce073afGirish Moodalbail * IPADM_DB_VERSION. Further, if we cannot determine the current
8887b57dc579de11464fc6c74163d2595ce073afGirish Moodalbail * version of the data-store, we always err on the side of caution
8887b57dc579de11464fc6c74163d2595ce073afGirish Moodalbail * and upgrade the data-store to current version.
8887b57dc579de11464fc6c74163d2595ce073afGirish Moodalbail */
8887b57dc579de11464fc6c74163d2595ce073afGirish Moodalbail if ((scferr = ipmgmt_create_scf_resources(IPMGMTD_FMRI, &res)) == 0)
8887b57dc579de11464fc6c74163d2595ce073afGirish Moodalbail upgrade = ipmgmt_needs_upgrade(&res);
8887b57dc579de11464fc6c74163d2595ce073afGirish Moodalbail if (upgrade) {
8887b57dc579de11464fc6c74163d2595ce073afGirish Moodalbail err = ipmgmt_db_walk(ipmgmt_db_upgrade, NULL, IPADM_DB_WRITE);
8887b57dc579de11464fc6c74163d2595ce073afGirish Moodalbail if (err != 0) {
8887b57dc579de11464fc6c74163d2595ce073afGirish Moodalbail ipmgmt_log(LOG_ERR, "could not upgrade the "
8887b57dc579de11464fc6c74163d2595ce073afGirish Moodalbail "ipadm data-store: %s", strerror(err));
8887b57dc579de11464fc6c74163d2595ce073afGirish Moodalbail err = 0;
8887b57dc579de11464fc6c74163d2595ce073afGirish Moodalbail } else {
8887b57dc579de11464fc6c74163d2595ce073afGirish Moodalbail /*
8887b57dc579de11464fc6c74163d2595ce073afGirish Moodalbail * upgrade was success, let's update SCF with the
8887b57dc579de11464fc6c74163d2595ce073afGirish Moodalbail * current data-store version number.
8887b57dc579de11464fc6c74163d2595ce073afGirish Moodalbail */
8887b57dc579de11464fc6c74163d2595ce073afGirish Moodalbail if (scferr == 0)
8887b57dc579de11464fc6c74163d2595ce073afGirish Moodalbail ipmgmt_update_dbver(&res);
8887b57dc579de11464fc6c74163d2595ce073afGirish Moodalbail }
8887b57dc579de11464fc6c74163d2595ce073afGirish Moodalbail }
8887b57dc579de11464fc6c74163d2595ce073afGirish Moodalbail if (scferr == 0)
8887b57dc579de11464fc6c74163d2595ce073afGirish Moodalbail ipmgmt_release_scf_resources(&res);
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail /* creates the address object data store, if it doesn't exist */
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail if ((fd = open(ADDROBJ_MAPPING_DB_FILE, O_CREAT|O_RDONLY,
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail IPADM_FILE_MODE)) == -1) {
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail err = errno;
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail ipmgmt_log(LOG_ERR, "could not open %s: %s",
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail ADDROBJ_MAPPING_DB_FILE, strerror(err));
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail return (err);
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail }
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail (void) close(fd);
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail aobjmap.aobjmap_head = NULL;
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail (void) pthread_rwlock_init(&aobjmap.aobjmap_rwlock, NULL);
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail /*
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * If the daemon is recovering from a crash or restart, read the
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * address object to logical interface mapping and build an in-memory
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * representation of the mapping. That is, build `aobjmap' structure
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * from address object data store.
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail */
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail if ((err = ipadm_rw_db(ipmgmt_aobjmap_init, NULL,
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail ADDROBJ_MAPPING_DB_FILE, 0, IPADM_DB_READ)) != 0) {
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail /* if there was nothing to initialize, it's fine */
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail if (err != ENOENT)
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail return (err);
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail err = 0;
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail }
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan ipmgmt_ngz_persist_if(); /* create persistent interface info for NGZ */
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail return (err);
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail}
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbailstatic int
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbailipmgmt_door_init()
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail{
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail int fd;
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail int err;
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail /* create the door file for ipmgmtd */
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail if ((fd = open(IPMGMT_DOOR, O_CREAT|O_RDONLY, IPADM_FILE_MODE)) == -1) {
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail err = errno;
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail ipmgmt_log(LOG_ERR, "could not open %s: %s",
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail IPMGMT_DOOR, strerror(err));
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail return (err);
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail }
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail (void) close(fd);
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail if ((ipmgmt_door_fd = door_create(ipmgmt_handler, NULL,
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail DOOR_REFUSE_DESC | DOOR_NO_CANCEL)) == -1) {
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail err = errno;
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail ipmgmt_log(LOG_ERR, "failed to create door: %s", strerror(err));
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail return (err);
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail }
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail /*
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * fdetach first in case a previous daemon instance exited
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * ungracefully.
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail */
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail (void) fdetach(IPMGMT_DOOR);
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail if (fattach(ipmgmt_door_fd, IPMGMT_DOOR) != 0) {
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail err = errno;
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail ipmgmt_log(LOG_ERR, "failed to attach door to %s: %s",
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail IPMGMT_DOOR, strerror(err));
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail goto fail;
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail }
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail return (0);
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbailfail:
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail (void) door_revoke(ipmgmt_door_fd);
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail ipmgmt_door_fd = -1;
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail return (err);
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail}
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbailstatic void
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbailipmgmt_door_fini()
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail{
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail if (ipmgmt_door_fd == -1)
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail return;
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail (void) fdetach(IPMGMT_DOOR);
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail if (door_revoke(ipmgmt_door_fd) == -1) {
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail ipmgmt_log(LOG_ERR, "failed to revoke access to door %s: %s",
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail IPMGMT_DOOR, strerror(errno));
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail }
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail}
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbailstatic int
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbailipmgmt_init()
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail{
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail int err;
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail if (signal(SIGTERM, ipmgmt_exit) == SIG_ERR ||
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail signal(SIGINT, ipmgmt_exit) == SIG_ERR) {
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail err = errno;
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail ipmgmt_log(LOG_ERR, "signal() for SIGTERM/INT failed: %s",
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail strerror(err));
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail return (err);
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail }
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail if ((err = ipmgmt_db_init()) != 0 || (err = ipmgmt_door_init()) != 0)
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail return (err);
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail return (0);
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail}
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail/*
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * This is called by the child process to inform the parent process to
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * exit with the given return value.
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail */
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbailstatic void
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbailipmgmt_inform_parent_exit(int rv)
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail{
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail if (write(pfds[1], &rv, sizeof (int)) != sizeof (int)) {
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail ipmgmt_log(LOG_WARNING,
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail "failed to inform parent process of status: %s",
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail strerror(errno));
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail (void) close(pfds[1]);
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail exit(EXIT_FAILURE);
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail }
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail (void) close(pfds[1]);
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail}
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail/*ARGSUSED*/
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbailstatic void
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbailipmgmt_exit(int signo)
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail{
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail (void) close(pfds[1]);
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail ipmgmt_door_fini();
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail exit(EXIT_FAILURE);
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail}
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail/*
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan * On the first reboot after installation of an ipkg zone,
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan * ipmgmt_persist_if_cb() is used in non-global zones to track the interfaces
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan * that have IP address configuration assignments from the global zone.
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan * Persistent configuration for the interfaces is created on the first boot
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan * by ipmgmtd, and the addresses assigned to the interfaces by the GZ
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan * will be subsequently configured when the interface is enabled.
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan * Note that ipmgmt_persist_if_cb() only sets up a list of interfaces
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan * that need to be persisted- the actual update of the ipadm data-store happens
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan * in ipmgmt_persist_if() after the appropriate privs/uid state has been set up.
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan */
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhanstatic void
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhanipmgmt_persist_if_cb(char *ifname, boolean_t v4, boolean_t v6)
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan{
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan ipmgmt_pif_t *pif;
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan pif = calloc(1, sizeof (*pif));
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan if (pif == NULL) {
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan ipmgmt_log(LOG_WARNING,
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan "Could not allocate memory to configure %s", ifname);
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan return;
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan }
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan (void) strlcpy(pif->pif_ifname, ifname, sizeof (pif->pif_ifname));
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan pif->pif_v4 = v4;
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan pif->pif_v6 = v6;
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan pif->pif_next = ngz_pifs;
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan ngz_pifs = pif;
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan}
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan/*
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan * ipmgmt_ngz_init() initializes exclusive-IP stack non-global zones by
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan * extracting configuration that has been saved in the kernel and applying
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan * it at zone boot.
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan */
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhanstatic void
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhanipmgmt_ngz_init()
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan{
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan zoneid_t zoneid;
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan boolean_t firstboot = B_TRUE, s10c = B_FALSE;
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan char brand[MAXNAMELEN];
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan ipadm_status_t ipstatus;
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan zoneid = getzoneid();
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan if (zoneid != GLOBAL_ZONEID) {
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan if (zone_getattr(zoneid, ZONE_ATTR_BRAND, brand,
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan sizeof (brand)) < 0) {
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan ipmgmt_log(LOG_ERR, "Could not get brand name");
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan return;
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan }
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan /*
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan * firstboot is always true for S10C zones, where ipadm is not
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan * available for restoring persistent configuration.
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan */
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan if (strcmp(brand, NATIVE_BRAND_NAME) == 0)
8887b57dc579de11464fc6c74163d2595ce073afGirish Moodalbail firstboot = ipmgmt_ngz_firstboot_postinstall();
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan else
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan s10c = B_TRUE;
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan if (!firstboot)
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan return;
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan ipstatus = ipadm_open(&iph, IPH_IPMGMTD);
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan if (ipstatus != IPADM_SUCCESS) {
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan ipmgmt_log(LOG_ERR, "could not open ipadm handle",
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan ipadm_status2str(ipstatus));
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan return;
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan }
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan /*
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan * Only pass down the callback to persist the interface
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan * for NATIVE (ipkg) zones.
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan */
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan (void) ipadm_init_net_from_gz(iph, NULL,
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan (s10c ? NULL : ipmgmt_persist_if_cb));
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan ipadm_close(iph);
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan }
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan}
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan/*
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan * Set the uid of this daemon to the "netadm" user. Finish the following
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * operations before setuid() because they need root privileges:
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail *
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * - create the /etc/svc/volatile/ipadm directory;
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan * - change its uid/gid to "netadm"/"netadm";
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail */
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbailstatic int
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbailipmgmt_init_privileges()
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail{
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail struct stat statbuf;
8887b57dc579de11464fc6c74163d2595ce073afGirish Moodalbail int err;
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail /* create the IPADM_TMPFS_DIR directory */
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail if (stat(IPADM_TMPFS_DIR, &statbuf) < 0) {
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail if (mkdir(IPADM_TMPFS_DIR, (mode_t)0755) < 0) {
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail err = errno;
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail goto fail;
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail }
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail } else {
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail if ((statbuf.st_mode & S_IFMT) != S_IFDIR) {
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail err = ENOTDIR;
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail goto fail;
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail }
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail }
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail if ((chmod(IPADM_TMPFS_DIR, 0755) < 0) ||
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail (chown(IPADM_TMPFS_DIR, UID_NETADM, GID_NETADM) < 0)) {
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail err = errno;
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail goto fail;
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail }
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan /*
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan * initialize any NGZ specific network information before dropping
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan * privileges. We need these privileges to plumb IP interfaces handed
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan * down from the GZ (for dlpi_open() etc.) and also to configure the
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan * address itself (for any IPI_PRIV ioctls like SLIFADDR)
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan */
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan ipmgmt_ngz_init();
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan
8887b57dc579de11464fc6c74163d2595ce073afGirish Moodalbail /*
8887b57dc579de11464fc6c74163d2595ce073afGirish Moodalbail * Apply all protocol module properties. We need to apply all protocol
8887b57dc579de11464fc6c74163d2595ce073afGirish Moodalbail * properties before we drop root privileges.
8887b57dc579de11464fc6c74163d2595ce073afGirish Moodalbail */
8887b57dc579de11464fc6c74163d2595ce073afGirish Moodalbail ipmgmt_init_prop();
8887b57dc579de11464fc6c74163d2595ce073afGirish Moodalbail
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail /*
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * limit the privileges of this daemon and set the uid of this
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * daemon to UID_NETADM
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail */
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail if (__init_daemon_priv(PU_RESETGROUPS|PU_CLEARLIMITSET, UID_NETADM,
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail GID_NETADM, NULL) == -1) {
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail err = EPERM;
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail goto fail;
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail }
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail return (0);
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbailfail:
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail (void) ipmgmt_log(LOG_ERR, "failed to initialize the daemon: %s",
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail strerror(err));
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail return (err);
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail}
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail/*
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * Keep the pfds fd open, close other fds.
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail */
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail/*ARGSUSED*/
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbailstatic int
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbailclosefunc(void *arg, int fd)
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail{
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail if (fd != pfds[1])
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail (void) close(fd);
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail return (0);
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail}
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail/*
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * We cannot use libc's daemon() because the door we create is associated with
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * the process ID. If we create the door before the call to daemon(), it will
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * be associated with the parent and it's incorrect. On the other hand if we
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * create the door later, after the call to daemon(), parent process exits
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * early and gives a false notion to SMF that 'ipmgmtd' is up and running,
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * which is incorrect. So, we have our own daemon() equivalent.
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail */
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbailstatic boolean_t
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbailipmgmt_daemonize(void)
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail{
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail pid_t pid;
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail int rv;
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail if (pipe(pfds) < 0) {
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail (void) fprintf(stderr, "%s: pipe() failed: %s\n",
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail progname, strerror(errno));
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail exit(EXIT_FAILURE);
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail }
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail if ((pid = fork()) == -1) {
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail (void) fprintf(stderr, "%s: fork() failed: %s\n",
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail progname, strerror(errno));
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail exit(EXIT_FAILURE);
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail } else if (pid > 0) { /* Parent */
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail (void) close(pfds[1]);
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail /*
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * Parent should not exit early, it should wait for the child
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * to return Success/Failure. If the parent exits early, then
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * SMF will think 'ipmgmtd' is up and would start all the
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * depended services.
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail *
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * If the child process exits unexpectedly, read() returns -1.
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail */
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail if (read(pfds[0], &rv, sizeof (int)) != sizeof (int)) {
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail (void) kill(pid, SIGKILL);
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail rv = EXIT_FAILURE;
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail }
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail (void) close(pfds[0]);
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail exit(rv);
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail }
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail /* Child */
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail (void) close(pfds[0]);
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail (void) setsid();
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail /* close all files except pfds[1] */
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail (void) fdwalk(closefunc, NULL);
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail (void) chdir("/");
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail openlog(progname, LOG_PID, LOG_DAEMON);
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail return (B_TRUE);
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail}
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbailint
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbailmain(int argc, char *argv[])
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail{
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail int opt;
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail boolean_t fg = B_FALSE;
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail progname = strrchr(argv[0], '/');
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail if (progname != NULL)
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail progname++;
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail else
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail progname = argv[0];
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail /* Process options */
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail while ((opt = getopt(argc, argv, "f")) != EOF) {
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail switch (opt) {
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail case 'f':
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail fg = B_TRUE;
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail break;
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail default:
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail (void) fprintf(stderr, "Usage: %s [-f]\n", progname);
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail return (EXIT_FAILURE);
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail }
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail }
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail if (!fg && getenv("SMF_FMRI") == NULL) {
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail (void) fprintf(stderr,
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail "ipmgmtd is a smf(5) managed service and cannot be run "
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail "from the command line.\n");
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail return (EINVAL);
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail }
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail if (!fg && !ipmgmt_daemonize())
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail return (EXIT_FAILURE);
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail if (ipmgmt_init_privileges() != 0)
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail goto child_out;
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail if (ipmgmt_init() != 0)
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail goto child_out;
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail /* Inform the parent process that it can successfully exit */
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail ipmgmt_inform_parent_exit(EXIT_SUCCESS);
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail for (;;)
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail (void) pause();
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbailchild_out:
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail /* return from main() forcibly exits an MT process */
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail ipmgmt_inform_parent_exit(EXIT_FAILURE);
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail return (EXIT_FAILURE);
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail}
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan/*
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan * Return TRUE if `ifname' has persistent configuration for the `af' address
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan * family in the datastore
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan */
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhanstatic boolean_t
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhanipmgmt_persist_if_exists(char *ifname, sa_family_t af)
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan{
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan ipmgmt_getif_cbarg_t cbarg;
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan boolean_t exists = B_FALSE;
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan ipadm_if_info_t *ifp;
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan bzero(&cbarg, sizeof (cbarg));
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan cbarg.cb_ifname = ifname;
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan (void) ipmgmt_db_walk(ipmgmt_db_getif, &cbarg, IPADM_DB_READ);
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan if ((ifp = cbarg.cb_ifinfo) != NULL) {
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan if ((af == AF_INET && (ifp->ifi_pflags & IFIF_IPV4)) ||
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan (af == AF_INET6 && (ifp->ifi_pflags & IFIF_IPV6))) {
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan exists = B_TRUE;
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan }
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan }
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan free(ifp);
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan return (exists);
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan}
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan/*
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan * Persist any NGZ interfaces assigned to us from the global zone if they do
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan * not already exist in the persistent db. We need to
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan * do this before any calls to ipadm_enable_if() can succeed (i.e.,
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan * before opening up for door_calls), and after setuid to 'netadm' so that
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan * the persistent db is created with the right permissions.
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan */
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhanstatic void
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhanipmgmt_ngz_persist_if()
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan{
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan ipmgmt_pif_t *pif, *next;
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan ipmgmt_if_arg_t ifarg;
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan for (pif = ngz_pifs; pif != NULL; pif = next) {
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan next = pif->pif_next;
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan bzero(&ifarg, sizeof (ifarg));
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan (void) strlcpy(ifarg.ia_ifname, pif->pif_ifname,
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan sizeof (ifarg.ia_ifname));
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan ifarg.ia_flags = IPMGMT_PERSIST;
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan if (pif->pif_v4 &&
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan !ipmgmt_persist_if_exists(pif->pif_ifname, AF_INET)) {
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan ifarg.ia_family = AF_INET;
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan (void) ipmgmt_persist_if(&ifarg);
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan }
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan if (pif->pif_v6 &&
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan !ipmgmt_persist_if_exists(pif->pif_ifname, AF_INET6)) {
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan ifarg.ia_family = AF_INET6;
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan (void) ipmgmt_persist_if(&ifarg);
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan }
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan free(pif);
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan }
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan ngz_pifs = NULL; /* no red herrings */
550b6e4083768ca350e9e7c3a1ebbf720b23dcadSowmini Varadhan}