Indicate IMV in assessment log statement
[strongswan.git] / src / libimcv / imc / imc_agent.c
1 /*
2 * Copyright (C) 2011-2012 Andreas Steffen
3 * HSR Hochschule fuer Technik Rapperswil
4 *
5 * This program is free software; you can redistribute it and/or modify it
6 * under the terms of the GNU General Public License as published by the
7 * Free Software Foundation; either version 2 of the License, or (at your
8 * option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
9 *
10 * This program is distributed in the hope that it will be useful, but
11 * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
12 * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
13 * for more details.
14 */
15
16 #include "imcv.h"
17 #include "imc_agent.h"
18
19 #include <tncif_names.h>
20
21 #include <utils/debug.h>
22 #include <threading/rwlock.h>
23
24 typedef struct private_imc_agent_t private_imc_agent_t;
25
26 /**
27 * Private data of an imc_agent_t object.
28 */
29 struct private_imc_agent_t {
30
31 /**
32 * Public members of imc_agent_t
33 */
34 imc_agent_t public;
35
36 /**
37 * name of IMC
38 */
39 const char *name;
40
41 /**
42 * message types registered by IMC
43 */
44 pen_type_t *supported_types;
45
46 /**
47 * number of message types registered by IMC
48 */
49 u_int32_t type_count;
50
51 /**
52 * ID of IMC as assigned by TNCC
53 */
54 TNC_IMCID id;
55
56 /**
57 * List of additional IMC IDs assigned by TNCC
58 */
59 linked_list_t *additional_ids;
60
61 /**
62 * list of TNCC connection entries
63 */
64 linked_list_t *connections;
65
66 /**
67 * rwlock to lock TNCC connection entries
68 */
69 rwlock_t *connection_lock;
70
71 /**
72 * Inform a TNCC about the set of message types the IMC is able to receive
73 *
74 * @param imc_id IMC ID assigned by TNCC
75 * @param supported_types list of supported message types
76 * @param type_count number of list elements
77 * @return TNC result code
78 */
79 TNC_Result (*report_message_types)(TNC_IMCID imc_id,
80 TNC_MessageTypeList supported_types,
81 TNC_UInt32 type_count);
82
83 /**
84 * Inform a TNCC about the set of message types the IMC is able to receive
85 *
86 * @param imc_id IMC ID assigned by TNCC
87 * @param supported_vids list of supported message vendor IDs
88 * @param supported_subtypes list of supported message subtypes
89 * @param type_count number of list elements
90 * @return TNC result code
91 */
92 TNC_Result (*report_message_types_long)(TNC_IMCID imc_id,
93 TNC_VendorIDList supported_vids,
94 TNC_MessageSubtypeList supported_subtypes,
95 TNC_UInt32 type_count);
96
97 /**
98 * Get the value of an attribute associated with a connection
99 * or with the TNCC as a whole.
100 *
101 * @param imc_id IMC ID assigned by TNCC
102 * @param connection_id network connection ID assigned by TNCC
103 * @param attribute_id attribute ID
104 * @param buffer_len length of buffer in bytes
105 * @param buffer buffer
106 * @param out_value_len size in bytes of attribute stored in buffer
107 * @return TNC result code
108 */
109 TNC_Result (*get_attribute)(TNC_IMCID imc_id,
110 TNC_ConnectionID connection_id,
111 TNC_AttributeID attribute_id,
112 TNC_UInt32 buffer_len,
113 TNC_BufferReference buffer,
114 TNC_UInt32 *out_value_len);
115
116 /**
117 * Set the value of an attribute associated with a connection
118 * or with the TNCC as a whole.
119 *
120 * @param imc_id IMV ID assigned by TNCC
121 * @param connection_id network connection ID assigned by TNCC
122 * @param attribute_id attribute ID
123 * @param buffer_len length of buffer in bytes
124 * @param buffer buffer
125 * @return TNC result code
126 */
127 TNC_Result (*set_attribute)(TNC_IMCID imc_id,
128 TNC_ConnectionID connection_id,
129 TNC_AttributeID attribute_id,
130 TNC_UInt32 buffer_len,
131 TNC_BufferReference buffer);
132
133 /**
134 * Reserve an additional IMC ID
135 *
136 * @param imc_id primary IMC ID assigned by TNCC
137 * @param out_imc_id additional IMC ID assigned by TNCC
138 * @return TNC result code
139 */
140 TNC_Result (*reserve_additional_id)(TNC_IMCID imc_id,
141 TNC_UInt32 *out_imc_id);
142
143 };
144
145 METHOD(imc_agent_t, bind_functions, TNC_Result,
146 private_imc_agent_t *this, TNC_TNCC_BindFunctionPointer bind_function)
147 {
148 if (!bind_function)
149 {
150 DBG1(DBG_IMC, "TNC client failed to provide bind function");
151 return TNC_RESULT_INVALID_PARAMETER;
152 }
153 if (bind_function(this->id, "TNC_TNCC_ReportMessageTypes",
154 (void**)&this->report_message_types) != TNC_RESULT_SUCCESS)
155 {
156 this->report_message_types = NULL;
157 }
158 if (bind_function(this->id, "TNC_TNCC_ReportMessageTypesLong",
159 (void**)&this->report_message_types_long) != TNC_RESULT_SUCCESS)
160 {
161 this->report_message_types_long = NULL;
162 }
163 if (bind_function(this->id, "TNC_TNCC_RequestHandshakeRetry",
164 (void**)&this->public.request_handshake_retry) != TNC_RESULT_SUCCESS)
165 {
166 this->public.request_handshake_retry = NULL;
167 }
168 if (bind_function(this->id, "TNC_TNCC_SendMessage",
169 (void**)&this->public.send_message) != TNC_RESULT_SUCCESS)
170 {
171 this->public.send_message = NULL;
172 }
173 if (bind_function(this->id, "TNC_TNCC_SendMessageLong",
174 (void**)&this->public.send_message_long) != TNC_RESULT_SUCCESS)
175 {
176 this->public.send_message_long = NULL;
177 }
178 if (bind_function(this->id, "TNC_TNCC_GetAttribute",
179 (void**)&this->get_attribute) != TNC_RESULT_SUCCESS)
180 {
181 this->get_attribute = NULL;
182 }
183 if (bind_function(this->id, "TNC_TNCC_SetAttribute",
184 (void**)&this->set_attribute) != TNC_RESULT_SUCCESS)
185 {
186 this->set_attribute = NULL;
187 }
188 if (bind_function(this->id, "TNC_TNCC_ReserveAdditionalIMCID",
189 (void**)&this->reserve_additional_id) != TNC_RESULT_SUCCESS)
190 {
191 this->reserve_additional_id = NULL;
192 }
193
194 if (this->report_message_types_long)
195 {
196 TNC_VendorIDList vendor_id_list;
197 TNC_MessageSubtypeList subtype_list;
198 int i;
199
200 vendor_id_list = malloc(this->type_count * sizeof(TNC_UInt32));
201 subtype_list = malloc(this->type_count * sizeof(TNC_UInt32));
202
203 for (i = 0; i < this->type_count; i++)
204 {
205 vendor_id_list[i] = this->supported_types[i].vendor_id;
206 subtype_list[i] = this->supported_types[i].type;
207 }
208 this->report_message_types_long(this->id, vendor_id_list, subtype_list,
209 this->type_count);
210 free(vendor_id_list);
211 free(subtype_list);
212 }
213 else if (this->report_message_types)
214 {
215 TNC_MessageTypeList type_list;
216 int i;
217
218 type_list = malloc(this->type_count * sizeof(TNC_UInt32));
219
220 for (i = 0; i < this->type_count; i++)
221 {
222 type_list[i] = (this->supported_types[i].vendor_id << 8) |
223 (this->supported_types[i].type & 0xff);
224 }
225 this->report_message_types(this->id, type_list, this->type_count);
226 free(type_list);
227 }
228 return TNC_RESULT_SUCCESS;
229 }
230
231 /**
232 * finds a connection state based on its Connection ID
233 */
234 static imc_state_t* find_connection(private_imc_agent_t *this,
235 TNC_ConnectionID id)
236 {
237 enumerator_t *enumerator;
238 imc_state_t *state, *found = NULL;
239
240 this->connection_lock->read_lock(this->connection_lock);
241 enumerator = this->connections->create_enumerator(this->connections);
242 while (enumerator->enumerate(enumerator, &state))
243 {
244 if (id == state->get_connection_id(state))
245 {
246 found = state;
247 break;
248 }
249 }
250 enumerator->destroy(enumerator);
251 this->connection_lock->unlock(this->connection_lock);
252
253 return found;
254 }
255
256 /**
257 * delete a connection state with a given Connection ID
258 */
259 static bool delete_connection(private_imc_agent_t *this, TNC_ConnectionID id)
260 {
261 enumerator_t *enumerator;
262 imc_state_t *state;
263 bool found = FALSE;
264
265 this->connection_lock->write_lock(this->connection_lock);
266 enumerator = this->connections->create_enumerator(this->connections);
267 while (enumerator->enumerate(enumerator, &state))
268 {
269 if (id == state->get_connection_id(state))
270 {
271 found = TRUE;
272 state->destroy(state);
273 this->connections->remove_at(this->connections, enumerator);
274 break;
275 }
276 }
277 enumerator->destroy(enumerator);
278 this->connection_lock->unlock(this->connection_lock);
279
280 return found;
281 }
282
283 /**
284 * Read a boolean attribute
285 */
286 static bool get_bool_attribute(private_imc_agent_t *this, TNC_ConnectionID id,
287 TNC_AttributeID attribute_id)
288 {
289 TNC_UInt32 len;
290 char buf[4];
291
292 return this->get_attribute &&
293 this->get_attribute(this->id, id, attribute_id, 4, buf, &len) ==
294 TNC_RESULT_SUCCESS && len == 1 && *buf == 0x01;
295 }
296
297 /**
298 * Read a string attribute
299 */
300 static char* get_str_attribute(private_imc_agent_t *this, TNC_ConnectionID id,
301 TNC_AttributeID attribute_id)
302 {
303 TNC_UInt32 len;
304 char buf[BUF_LEN];
305
306 if (this->get_attribute &&
307 this->get_attribute(this->id, id, attribute_id, BUF_LEN, buf, &len) ==
308 TNC_RESULT_SUCCESS && len <= BUF_LEN)
309 {
310 return strdup(buf);
311 }
312 return NULL;
313 }
314
315 /**
316 * Read an UInt32 attribute
317 */
318 static u_int32_t get_uint_attribute(private_imc_agent_t *this, TNC_ConnectionID id,
319 TNC_AttributeID attribute_id)
320 {
321 TNC_UInt32 len;
322 char buf[4];
323
324 if (this->get_attribute &&
325 this->get_attribute(this->id, id, attribute_id, 4, buf, &len) ==
326 TNC_RESULT_SUCCESS && len == 4)
327 {
328 return untoh32(buf);
329 }
330 return 0;
331 }
332
333 METHOD(imc_agent_t, create_state, TNC_Result,
334 private_imc_agent_t *this, imc_state_t *state)
335 {
336 TNC_ConnectionID conn_id;
337 char *tnccs_p = NULL, *tnccs_v = NULL, *t_p = NULL, *t_v = NULL;
338 bool has_long = FALSE, has_excl = FALSE, has_soh = FALSE;
339 u_int32_t max_msg_len;
340
341 conn_id = state->get_connection_id(state);
342 if (find_connection(this, conn_id))
343 {
344 DBG1(DBG_IMC, "IMC %u \"%s\" already created a state for Connection ID %u",
345 this->id, this->name, conn_id);
346 state->destroy(state);
347 return TNC_RESULT_OTHER;
348 }
349
350 /* Get and display attributes from TNCC via IF-IMC */
351 has_long = get_bool_attribute(this, conn_id, TNC_ATTRIBUTEID_HAS_LONG_TYPES);
352 has_excl = get_bool_attribute(this, conn_id, TNC_ATTRIBUTEID_HAS_EXCLUSIVE);
353 has_soh = get_bool_attribute(this, conn_id, TNC_ATTRIBUTEID_HAS_SOH);
354 tnccs_p = get_str_attribute(this, conn_id, TNC_ATTRIBUTEID_IFTNCCS_PROTOCOL);
355 tnccs_v = get_str_attribute(this, conn_id, TNC_ATTRIBUTEID_IFTNCCS_VERSION);
356 t_p = get_str_attribute(this, conn_id, TNC_ATTRIBUTEID_IFT_PROTOCOL);
357 t_v = get_str_attribute(this, conn_id, TNC_ATTRIBUTEID_IFT_VERSION);
358 max_msg_len = get_uint_attribute(this, conn_id, TNC_ATTRIBUTEID_MAX_MESSAGE_SIZE);
359
360 state->set_flags(state, has_long, has_excl);
361 state->set_max_msg_len(state, max_msg_len);
362
363 DBG2(DBG_IMC, "IMC %u \"%s\" created a state for %s %s Connection ID %u: "
364 "%slong %sexcl %ssoh", this->id, this->name,
365 tnccs_p ? tnccs_p:"?", tnccs_v ? tnccs_v:"?", conn_id,
366 has_long ? "+":"-", has_excl ? "+":"-", has_soh ? "+":"-");
367 DBG2(DBG_IMC, " over %s %s with maximum PA-TNC message size of %u bytes",
368 t_p ? t_p:"?", t_v ? t_v :"?", max_msg_len);
369
370 free(tnccs_p);
371 free(tnccs_v);
372 free(t_p);
373 free(t_v);
374
375 this->connection_lock->write_lock(this->connection_lock);
376 this->connections->insert_last(this->connections, state);
377 this->connection_lock->unlock(this->connection_lock);
378 return TNC_RESULT_SUCCESS;
379 }
380
381 METHOD(imc_agent_t, delete_state, TNC_Result,
382 private_imc_agent_t *this, TNC_ConnectionID connection_id)
383 {
384 if (!delete_connection(this, connection_id))
385 {
386 DBG1(DBG_IMC, "IMC %u \"%s\" has no state for Connection ID %u",
387 this->id, this->name, connection_id);
388 return TNC_RESULT_FATAL;
389 }
390 DBG2(DBG_IMC, "IMC %u \"%s\" deleted the state of Connection ID %u",
391 this->id, this->name, connection_id);
392 return TNC_RESULT_SUCCESS;
393 }
394
395 METHOD(imc_agent_t, change_state, TNC_Result,
396 private_imc_agent_t *this, TNC_ConnectionID connection_id,
397 TNC_ConnectionState new_state,
398 imc_state_t **state_p)
399 {
400 imc_state_t *state;
401
402 switch (new_state)
403 {
404 case TNC_CONNECTION_STATE_HANDSHAKE:
405 case TNC_CONNECTION_STATE_ACCESS_ALLOWED:
406 case TNC_CONNECTION_STATE_ACCESS_ISOLATED:
407 case TNC_CONNECTION_STATE_ACCESS_NONE:
408 state = find_connection(this, connection_id);
409
410 if (!state)
411 {
412 DBG1(DBG_IMC, "IMC %u \"%s\" has no state for Connection ID %u",
413 this->id, this->name, connection_id);
414 return TNC_RESULT_FATAL;
415 }
416 state->change_state(state, new_state);
417 DBG2(DBG_IMC, "IMC %u \"%s\" changed state of Connection ID %u to '%N'",
418 this->id, this->name, connection_id,
419 TNC_Connection_State_names, new_state);
420 if (state_p)
421 {
422 *state_p = state;
423 }
424 break;
425 case TNC_CONNECTION_STATE_CREATE:
426 DBG1(DBG_IMC, "state '%N' should be handled by create_state()",
427 TNC_Connection_State_names, new_state);
428 return TNC_RESULT_FATAL;
429 case TNC_CONNECTION_STATE_DELETE:
430 DBG1(DBG_IMC, "state '%N' should be handled by delete_state()",
431 TNC_Connection_State_names, new_state);
432 return TNC_RESULT_FATAL;
433 default:
434 DBG1(DBG_IMC, "IMC %u \"%s\" was notified of unknown state %u "
435 "for Connection ID %u",
436 this->id, this->name, new_state, connection_id);
437 return TNC_RESULT_INVALID_PARAMETER;
438 }
439 return TNC_RESULT_SUCCESS;
440 }
441
442 METHOD(imc_agent_t, get_state, bool,
443 private_imc_agent_t *this, TNC_ConnectionID connection_id,
444 imc_state_t **state)
445 {
446 *state = find_connection(this, connection_id);
447 if (!*state)
448 {
449 DBG1(DBG_IMC, "IMC %u \"%s\" has no state for Connection ID %u",
450 this->id, this->name, connection_id);
451 return FALSE;
452 }
453 return TRUE;
454 }
455
456 METHOD(imc_agent_t, get_name, const char*,
457 private_imc_agent_t *this)
458 {
459 return this->name;
460 }
461
462 METHOD(imc_agent_t, get_id, TNC_IMCID,
463 private_imc_agent_t *this)
464 {
465 return this->id;
466 }
467
468 METHOD(imc_agent_t, reserve_additional_ids, TNC_Result,
469 private_imc_agent_t *this, int count)
470 {
471 TNC_Result result;
472 TNC_UInt32 id;
473 void *pointer;
474
475 if (!this->reserve_additional_id)
476 {
477 DBG1(DBG_IMC, "IMC %u \"%s\" did not detect the capability to reserve "
478 "additional IMC IDs from the TNCC", this->id, this->name);
479 return TNC_RESULT_ILLEGAL_OPERATION;
480 }
481 while (count > 0)
482 {
483 result = this->reserve_additional_id(this->id, &id);
484 if (result != TNC_RESULT_SUCCESS)
485 {
486 DBG1(DBG_IMC, "IMC %u \"%s\" failed to reserve %d additional IMC IDs",
487 this->id, this->name, count);
488 return result;
489 }
490 count--;
491
492 /* store the scalar value in the pointer */
493 pointer = (void*)id;
494 this->additional_ids->insert_last(this->additional_ids, pointer);
495 DBG2(DBG_IMC, "IMC %u \"%s\" reserved additional ID %u",
496 this->id, this->name, id);
497 }
498 return TNC_RESULT_SUCCESS;
499 }
500
501 METHOD(imc_agent_t, count_additional_ids, int,
502 private_imc_agent_t *this)
503 {
504 return this->additional_ids->get_count(this->additional_ids);
505 }
506
507 METHOD(imc_agent_t, create_id_enumerator, enumerator_t*,
508 private_imc_agent_t *this)
509 {
510 return this->additional_ids->create_enumerator(this->additional_ids);
511 }
512
513 METHOD(imc_agent_t, destroy, void,
514 private_imc_agent_t *this)
515 {
516 DBG1(DBG_IMC, "IMC %u \"%s\" terminated", this->id, this->name);
517 this->additional_ids->destroy(this->additional_ids);
518 this->connections->destroy_function(this->connections, free);
519 this->connection_lock->destroy(this->connection_lock);
520 free(this);
521
522 /* decrease the reference count or terminate */
523 libimcv_deinit();
524 }
525
526 /**
527 * Described in header.
528 */
529 imc_agent_t *imc_agent_create(const char *name,
530 pen_type_t *supported_types, u_int32_t type_count,
531 TNC_IMCID id, TNC_Version *actual_version)
532 {
533 private_imc_agent_t *this;
534
535 /* initialize or increase the reference count */
536 if (!libimcv_init(FALSE))
537 {
538 return NULL;
539 }
540
541 INIT(this,
542 .public = {
543 .bind_functions = _bind_functions,
544 .create_state = _create_state,
545 .delete_state = _delete_state,
546 .change_state = _change_state,
547 .get_state = _get_state,
548 .get_name = _get_name,
549 .get_id = _get_id,
550 .reserve_additional_ids = _reserve_additional_ids,
551 .count_additional_ids = _count_additional_ids,
552 .create_id_enumerator = _create_id_enumerator,
553 .destroy = _destroy,
554 },
555 .name = name,
556 .supported_types = supported_types,
557 .type_count = type_count,
558 .id = id,
559 .additional_ids = linked_list_create(),
560 .connections = linked_list_create(),
561 .connection_lock = rwlock_create(RWLOCK_TYPE_DEFAULT),
562 );
563
564 *actual_version = TNC_IFIMC_VERSION_1;
565 DBG1(DBG_IMC, "IMC %u \"%s\" initialized", this->id, this->name);
566
567 return &this->public;
568 }
569