ipmgmt_main.c revision 6e91bba0d6c6bdabbba62cefae583715a4a58e2a
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * CDDL HEADER START
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * The contents of this file are subject to the terms of the
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * Common Development and Distribution License (the "License").
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * You may not use this file except in compliance with the License.
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * or http://www.opensolaris.org/os/licensing.
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * See the License for the specific language governing permissions
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * and limitations under the License.
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * When distributing Covered Code, include this CDDL HEADER in each
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * file and include the License file at usr/src/OPENSOLARIS.LICENSE.
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * If applicable, add the following below this CDDL HEADER, with the
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * fields enclosed by brackets "[]" replaced with your own identifying
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * information: Portions Copyright [yyyy] [name of copyright owner]
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * CDDL HEADER END
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * Copyright 2010 Sun Microsystems, Inc. All rights reserved.
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * Use is subject to license terms.
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * The ipmgmtd daemon is started by ip-interface-management SMF service. This
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * daemon is used to manage, mapping of 'address object' to 'interface name' and
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * 'logical interface number', on which the address is created. It also provides
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * a means to update the ipadm persistent data-store.
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * The daemon tracks the <addrobj, lifname> mapping in-memory using a linked
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * list `aobjmap'. Access to this list is synchronized using a readers-writers
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * lock. The active <addrobj, lifname> mapping is kept in
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * /etc/svc/volatile/ipadm/aobjmap.conf cache file, so that the mapping can be
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * recovered when ipmgmtd exits for some reason (e.g., when ipmgmtd is restarted
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * using svcadm or accidentally killed).
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * Today, the persistent configuration of interfaces, addresses and protocol
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * properties is kept in /etc/ipadm/ipadm.conf. The access to the persistent
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * data store is synchronized using reader-writers lock `ipmgmt_dbconf_lock'.
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * The communication between the library, libipadm.so and the daemon, is through
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * doors RPC. The library interacts with the daemon using the commands defined
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * by `ipmgmt_door_cmd_type_t'. Further any 'write' operation would require
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * the `NETWORK_INTERFACE_CONFIG_AUTH' authorization.
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * On reboot, the aforementioned SMF service starts the daemon before any other
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * networking service that configures network IP interfaces is started.
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * Afterwards, the network/physical SMF script instantiates the persisted
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * network interfaces, interface properties and addresses.
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail/* readers-writers lock for reading/writing daemon data store */
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail/* tracks address object to {ifname|logical number|interface id} mapping */
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail/* used to communicate failure to parent process, which spawned the daemon */
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail/* file descriptor to IPMGMT_DOOR */
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbailstatic void ipmgmt_exit(int);
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail /* creates the address object data store, if it doesn't exist */
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail if ((fd = open(ADDROBJ_MAPPING_DB_FILE, O_CREAT|O_RDONLY,
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail ipmgmt_log(LOG_ERR, "could not open %s: %s",
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail (void) pthread_rwlock_init(&aobjmap.aobjmap_rwlock, NULL);
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * If the daemon is recovering from a crash or restart, read the
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * address object to logical interface mapping and build an in-memory
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * representation of the mapping. That is, build `aobjmap' structure
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * from address object data store.
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail if ((err = ipadm_rw_db(ipmgmt_aobjmap_init, NULL,
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail ADDROBJ_MAPPING_DB_FILE, 0, IPADM_DB_READ)) != 0) {
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail /* if there was nothing to initialize, it's fine */
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail (void) pthread_rwlock_init(&ipmgmt_dbconf_lock, NULL);
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail /* create the door file for ipmgmtd */
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail if ((fd = open(IPMGMT_DOOR, O_CREAT|O_RDONLY, IPADM_FILE_MODE)) == -1) {
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail ipmgmt_log(LOG_ERR, "could not open %s: %s",
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail if ((ipmgmt_door_fd = door_create(ipmgmt_handler, NULL,
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail DOOR_REFUSE_DESC | DOOR_NO_CANCEL)) == -1) {
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail ipmgmt_log(LOG_ERR, "failed to create door: %s", strerror(err));
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * fdetach first in case a previous daemon instance exited
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * ungracefully.
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail if (fattach(ipmgmt_door_fd, IPMGMT_DOOR) != 0) {
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail ipmgmt_log(LOG_ERR, "failed to attach door to %s: %s",
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail ipmgmt_log(LOG_ERR, "failed to revoke access to door %s: %s",
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail if (signal(SIGTERM, ipmgmt_exit) == SIG_ERR ||
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail ipmgmt_log(LOG_ERR, "signal() for SIGTERM/INT failed: %s",
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail if ((err = ipmgmt_db_init()) != 0 || (err = ipmgmt_door_init()) != 0)
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * This is called by the child process to inform the parent process to
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * exit with the given return value.
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail if (write(pfds[1], &rv, sizeof (int)) != sizeof (int)) {
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail "failed to inform parent process of status: %s",
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * Set the uid of this daemon to the "ipadm" user. Finish the following
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * operations before setuid() because they need root privileges:
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * - create the /etc/svc/volatile/ipadm directory;
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * - change its uid/gid to "ipadm"/"sys";
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail /* create the IPADM_TMPFS_DIR directory */
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail if (stat(IPADM_TMPFS_DIR, &statbuf) < 0) {
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail if (mkdir(IPADM_TMPFS_DIR, (mode_t)0755) < 0) {
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail if ((statbuf.st_mode & S_IFMT) != S_IFDIR) {
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail (chown(IPADM_TMPFS_DIR, UID_NETADM, GID_NETADM) < 0)) {
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * limit the privileges of this daemon and set the uid of this
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * daemon to UID_NETADM
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail if (__init_daemon_priv(PU_RESETGROUPS|PU_CLEARLIMITSET, UID_NETADM,
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail (void) ipmgmt_log(LOG_ERR, "failed to initialize the daemon: %s",
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * Keep the pfds fd open, close other fds.
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * We cannot use libc's daemon() because the door we create is associated with
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * the process ID. If we create the door before the call to daemon(), it will
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * be associated with the parent and it's incorrect. On the other hand if we
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * create the door later, after the call to daemon(), parent process exits
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * early and gives a false notion to SMF that 'ipmgmtd' is up and running,
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * which is incorrect. So, we have our own daemon() equivalent.
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail (void) fprintf(stderr, "%s: pipe() failed: %s\n",
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail (void) fprintf(stderr, "%s: fork() failed: %s\n",
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * Parent should not exit early, it should wait for the child
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * to return Success/Failure. If the parent exits early, then
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * SMF will think 'ipmgmtd' is up and would start all the
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * depended services.
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail * If the child process exits unexpectedly, read() returns -1.
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail if (read(pfds[0], &rv, sizeof (int)) != sizeof (int)) {
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail /* close all files except pfds[1] */
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail /* Process options */
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail while ((opt = getopt(argc, argv, "f")) != EOF) {
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail (void) fprintf(stderr, "Usage: %s [-f]\n", progname);
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail "ipmgmtd is a smf(5) managed service and cannot be run "
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail "from the command line.\n");
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail /* Inform the parent process that it can successfully exit */
6e91bba0d6c6bdabbba62cefae583715a4a58e2aGirish Moodalbail /* return from main() forcibly exits an MT process */