Implemented IKEv1 attribute encoding in SA payload
[strongswan.git] / src / libcharon / encoding / payloads / transform_attribute.c
1 /*
2 * Copyright (C) 2005-2010 Martin Willi
3 * Copyright (C) 2010 revosec AG
4 * Copyright (C) 2005 Jan Hutter
5 * Hochschule fuer Technik Rapperswil
6 *
7 * This program is free software; you can redistribute it and/or modify it
8 * under the terms of the GNU General Public License as published by the
9 * Free Software Foundation; either version 2 of the License, or (at your
10 * option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
11 *
12 * This program is distributed in the hope that it will be useful, but
13 * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
14 * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
15 * for more details.
16 */
17
18 #include <string.h>
19 #include <stddef.h>
20
21 #include "transform_attribute.h"
22
23 #include <encoding/payloads/encodings.h>
24 #include <library.h>
25
26 ENUM(tattr_ph1_names, TATTR_PH1_ENCRYPTION_ALGORITHM, TATTR_PH1_GROUP_ORDER,
27 "ENCRYPTION_ALGORITHM",
28 "HASH_ALGORITHM",
29 "AUTH_METHOD",
30 "GROUP",
31 "GROUP_TYPE",
32 "GROUP_PRIME",
33 "GROUP_GENONE",
34 "GROUP_GENTWO",
35 "GROUP_CURVE_A",
36 "GROUP_CURVE_B",
37 "LIFE_TYPE",
38 "LIFE_DURATION",
39 "PRF",
40 "KEY_LENGTH",
41 "FIELD_SIZE",
42 "GROUP_ORDER",
43 );
44
45 ENUM(tattr_ph2_names, TATTR_PH2_SA_LIFE_TYPE, TATTR_PH2_EXT_SEQ_NUMBER,
46 "SA_LIFE_TYPE",
47 "SA_LIFE_DURATION",
48 "GROUP",
49 "ENCAP_MODE",
50 "AUTH_ALGORITHM",
51 "KEY_LENGTH",
52 "KEY_ROUNDS",
53 "COMP_DICT_SIZE",
54 "COMP_PRIV_ALGORITHM",
55 "ECN_TUNNEL",
56 "EXT_SEQ_NUMBER",
57 );
58
59 ENUM(tattr_ikev2_names, TATTR_IKEV2_KEY_LENGTH, TATTR_IKEV2_KEY_LENGTH,
60 "KEY_LENGTH",
61 );
62
63
64 typedef struct private_transform_attribute_t private_transform_attribute_t;
65
66 /**
67 * Private data of an transform_attribute_t object.
68 */
69 struct private_transform_attribute_t {
70
71 /**
72 * Public transform_attribute_t interface.
73 */
74 transform_attribute_t public;
75
76 /**
77 * Attribute Format Flag.
78 *
79 * - TRUE means value is stored in attribute_length_or_value
80 * - FALSE means value is stored in attribute_value
81 */
82 bool attribute_format;
83
84 /**
85 * Type of the attribute.
86 */
87 u_int16_t attribute_type;
88
89 /**
90 * Attribute Length if attribute_format is 0, attribute Value otherwise.
91 */
92 u_int16_t attribute_length_or_value;
93
94 /**
95 * Attribute value as chunk if attribute_format is 0 (FALSE).
96 */
97 chunk_t attribute_value;
98
99 /**
100 * Payload type, TRANSFORM_ATTRIBUTE or TRANSFORM_ATTRIBUTE_V1
101 */
102 payload_type_t type;
103 };
104
105 /**
106 * Encoding rules for IKEv1/IKEv2 transform attributes
107 */
108 static encoding_rule_t encodings[] = {
109 /* Flag defining the format of this payload */
110 { ATTRIBUTE_FORMAT, offsetof(private_transform_attribute_t, attribute_format) },
111 /* type of the attribute as 15 bit unsigned integer */
112 { ATTRIBUTE_TYPE, offsetof(private_transform_attribute_t, attribute_type) },
113 /* Length or value, depending on the attribute format flag */
114 { ATTRIBUTE_LENGTH_OR_VALUE,offsetof(private_transform_attribute_t, attribute_length_or_value) },
115 /* Value of attribute if attribute format flag is zero */
116 { ATTRIBUTE_VALUE, offsetof(private_transform_attribute_t, attribute_value) }
117 };
118
119 /*
120 1 2 3
121 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1
122 +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
123 !A! Attribute Type ! AF=0 Attribute Length !
124 !F! ! AF=1 Attribute Value !
125 +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
126 ! AF=0 Attribute Value !
127 ! AF=1 Not Transmitted !
128 +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
129 */
130
131 METHOD(payload_t, verify, status_t,
132 private_transform_attribute_t *this)
133 {
134 return SUCCESS;
135 }
136
137 METHOD(payload_t, get_encoding_rules, int,
138 private_transform_attribute_t *this, encoding_rule_t **rules)
139 {
140 *rules = encodings;
141 return countof(encodings);
142 }
143
144 METHOD(payload_t, get_header_length, int,
145 private_transform_attribute_t *this)
146 {
147 return 0;
148 }
149
150 METHOD(payload_t, get_type, payload_type_t,
151 private_transform_attribute_t *this)
152 {
153 return this->type;
154 }
155
156 METHOD(payload_t, get_next_type, payload_type_t,
157 private_transform_attribute_t *this)
158 {
159 return NO_PAYLOAD;
160 }
161
162 METHOD(payload_t, set_next_type, void,
163 private_transform_attribute_t *this, payload_type_t type)
164 {
165 }
166
167 METHOD(payload_t, get_length, size_t,
168 private_transform_attribute_t *this)
169 {
170 if (this->attribute_format)
171 {
172 return 4;
173 }
174 return this->attribute_length_or_value + 4;
175 }
176
177 METHOD(transform_attribute_t, set_value_chunk, void,
178 private_transform_attribute_t *this, chunk_t value)
179 {
180 chunk_free(&this->attribute_value);
181
182 if (value.len != 2)
183 {
184 this->attribute_value = chunk_clone(value);
185 this->attribute_length_or_value = value.len;
186 this->attribute_format = FALSE;
187 }
188 else
189 {
190 memcpy(&this->attribute_length_or_value, value.ptr, value.len);
191 }
192 }
193
194 METHOD(transform_attribute_t, set_value, void,
195 private_transform_attribute_t *this, u_int16_t value)
196 {
197 chunk_free(&this->attribute_value);
198 this->attribute_length_or_value = value;
199 this->attribute_format = TRUE;
200 }
201
202 METHOD(transform_attribute_t, get_value_chunk, chunk_t,
203 private_transform_attribute_t *this)
204 {
205 if (this->attribute_format)
206 {
207 return chunk_from_thing(this->attribute_length_or_value);
208 }
209 return this->attribute_value;
210 }
211
212 METHOD(transform_attribute_t, get_value, u_int64_t,
213 private_transform_attribute_t *this)
214 {
215 u_int64_t value = 0;
216
217 if (this->attribute_format)
218 {
219 return this->attribute_length_or_value;
220 }
221 if (this->attribute_value.len > sizeof(value))
222 {
223 return UINT64_MAX;
224 }
225 memcpy(((char*)&value) + sizeof(value) - this->attribute_value.len,
226 this->attribute_value.ptr, this->attribute_value.len);
227 return be64toh(value);
228 }
229
230 METHOD(transform_attribute_t, set_attribute_type, void,
231 private_transform_attribute_t *this, u_int16_t type)
232 {
233 this->attribute_type = type & 0x7FFF;
234 }
235
236 METHOD(transform_attribute_t, get_attribute_type, u_int16_t,
237 private_transform_attribute_t *this)
238 {
239 return this->attribute_type;
240 }
241
242 METHOD(transform_attribute_t, clone_, transform_attribute_t*,
243 private_transform_attribute_t *this)
244 {
245 private_transform_attribute_t *new;
246
247 new = (private_transform_attribute_t*)transform_attribute_create(this->type);
248
249 new->attribute_format = this->attribute_format;
250 new->attribute_type = this->attribute_type;
251 new->attribute_length_or_value = this->attribute_length_or_value;
252
253 if (!new->attribute_format)
254 {
255 new->attribute_value = chunk_clone(this->attribute_value);
256 }
257 return &new->public;
258 }
259
260 METHOD2(payload_t, transform_attribute_t, destroy, void,
261 private_transform_attribute_t *this)
262 {
263 free(this->attribute_value.ptr);
264 free(this);
265 }
266
267 /*
268 * Described in header.
269 */
270 transform_attribute_t *transform_attribute_create(payload_type_t type)
271 {
272 private_transform_attribute_t *this;
273
274 INIT(this,
275 .public = {
276 .payload_interface = {
277 .verify = _verify,
278 .get_encoding_rules = _get_encoding_rules,
279 .get_header_length = _get_header_length,
280 .get_length = _get_length,
281 .get_next_type = _get_next_type,
282 .set_next_type = _set_next_type,
283 .get_type = _get_type,
284 .destroy = _destroy,
285 },
286 .set_value_chunk = _set_value_chunk,
287 .set_value = _set_value,
288 .get_value_chunk = _get_value_chunk,
289 .get_value = _get_value,
290 .set_attribute_type = _set_attribute_type,
291 .get_attribute_type = _get_attribute_type,
292 .clone = _clone_,
293 .destroy = _destroy,
294 },
295 .attribute_format = TRUE,
296 .type = type,
297 );
298 return &this->public;
299 }
300
301 /*
302 * Described in header.
303 */
304 transform_attribute_t *transform_attribute_create_value(payload_type_t type,
305 transform_attribute_type_t kind, u_int64_t value)
306 {
307 transform_attribute_t *attribute;
308
309 attribute = transform_attribute_create(type);
310 attribute->set_attribute_type(attribute, kind);
311
312 if (value <= UINT16_MAX)
313 {
314 attribute->set_value(attribute, value);
315 }
316 else if (value <= UINT32_MAX)
317 {
318 u_int32_t val32;
319
320 val32 = htonl(value);
321 attribute->set_value_chunk(attribute, chunk_from_thing(val32));
322 }
323 else
324 {
325 value = htobe64(value);
326 attribute->set_value_chunk(attribute, chunk_from_thing(value));
327 }
328 return attribute;
329 }