support of error_offset in PA-TNC INVALID PARAMETER error messages
[strongswan.git] / src / libimcv / plugins / imc_test / imc_test.c
1 /*
2 * Copyright (C) 2011 Andreas Steffen, HSR Hochschule fuer Technik Rapperswil
3 *
4 * This program is free software; you can redistribute it and/or modify it
5 * under the terms of the GNU General Public License as published by the
6 * Free Software Foundation; either version 2 of the License, or (at your
7 * option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
8 *
9 * This program is distributed in the hope that it will be useful, but
10 * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
11 * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
12 * for more details.
13 */
14
15 #include "imc_test_state.h"
16
17 #include <imc/imc_agent.h>
18 #include <pa_tnc/pa_tnc_msg.h>
19 #include <ietf/ietf_attr.h>
20 #include <ietf/ietf_attr_pa_tnc_error.h>
21 #include <ita/ita_attr_command.h>
22
23 #include <tncif_names.h>
24 #include <tncif_pa_subtypes.h>
25
26 #include <pen/pen.h>
27 #include <debug.h>
28
29 /* IMC definitions */
30
31 static const char imc_name[] = "Test";
32
33 #define IMC_VENDOR_ID PEN_ITA
34 #define IMC_SUBTYPE PA_SUBTYPE_ITA_TEST
35
36 static imc_agent_t *imc_test;
37
38 /**
39 * see section 3.7.1 of TCG TNC IF-IMC Specification 1.2
40 */
41 TNC_Result TNC_IMC_Initialize(TNC_IMCID imc_id,
42 TNC_Version min_version,
43 TNC_Version max_version,
44 TNC_Version *actual_version)
45 {
46 if (imc_test)
47 {
48 DBG1(DBG_IMC, "IMC \"%s\" has already been initialized", imc_name);
49 return TNC_RESULT_ALREADY_INITIALIZED;
50 }
51 imc_test = imc_agent_create(imc_name, IMC_VENDOR_ID, IMC_SUBTYPE,
52 imc_id, actual_version);
53 if (!imc_test)
54 {
55 return TNC_RESULT_FATAL;
56 }
57 if (min_version > TNC_IFIMC_VERSION_1 || max_version < TNC_IFIMC_VERSION_1)
58 {
59 DBG1(DBG_IMC, "no common IF-IMC version");
60 return TNC_RESULT_NO_COMMON_VERSION;
61 }
62 return TNC_RESULT_SUCCESS;
63 }
64
65 /**
66 * see section 3.7.2 of TCG TNC IF-IMC Specification 1.2
67 */
68 TNC_Result TNC_IMC_NotifyConnectionChange(TNC_IMCID imc_id,
69 TNC_ConnectionID connection_id,
70 TNC_ConnectionState new_state)
71 {
72 imc_state_t *state;
73 imc_test_state_t *test_state;
74 TNC_Result result;
75 char *command;
76 bool retry;
77
78 if (!imc_test)
79 {
80 DBG1(DBG_IMC, "IMC \"%s\" has not been initialized", imc_name);
81 return TNC_RESULT_NOT_INITIALIZED;
82 }
83 switch (new_state)
84 {
85 case TNC_CONNECTION_STATE_CREATE:
86 command = lib->settings->get_str(lib->settings,
87 "libimcv.plugins.imc-test.command", "none");
88 retry = lib->settings->get_bool(lib->settings,
89 "libimcv.plugins.imc-test.retry", FALSE);
90 state = imc_test_state_create(connection_id, command, retry);
91 return imc_test->create_state(imc_test, state);
92
93 case TNC_CONNECTION_STATE_HANDSHAKE:
94 /* get updated IMC state */
95 result = imc_test->change_state(imc_test, connection_id,
96 new_state, &state);
97 if (result != TNC_RESULT_SUCCESS)
98 {
99 return TNC_RESULT_FATAL;
100 }
101 test_state = (imc_test_state_t*)state;
102
103 /* is it the first handshake or a retry ? */
104 if (!test_state->is_first_handshake(test_state))
105 {
106 command = lib->settings->get_str(lib->settings,
107 "libimcv.plugins.imc-test.retry_command",
108 test_state->get_command(test_state));
109 test_state->set_command(test_state, command);
110 }
111 return TNC_RESULT_SUCCESS;
112
113 case TNC_CONNECTION_STATE_DELETE:
114 return imc_test->delete_state(imc_test, connection_id);
115
116 case TNC_CONNECTION_STATE_ACCESS_ISOLATED:
117 case TNC_CONNECTION_STATE_ACCESS_NONE:
118 /* get updated IMC state */
119 result = imc_test->change_state(imc_test, connection_id,
120 new_state, &state);
121 if (result != TNC_RESULT_SUCCESS)
122 {
123 return TNC_RESULT_FATAL;
124 }
125 test_state = (imc_test_state_t*)state;
126
127 /* do a handshake retry? */
128 if (test_state->do_handshake_retry(test_state))
129 {
130 return imc_test->request_handshake_retry(imc_id, connection_id,
131 TNC_RETRY_REASON_IMC_REMEDIATION_COMPLETE);
132 }
133 return TNC_RESULT_SUCCESS;
134
135 default:
136 return imc_test->change_state(imc_test, connection_id,
137 new_state, NULL);
138 }
139 }
140
141 static TNC_Result send_message(TNC_ConnectionID connection_id)
142 {
143 pa_tnc_msg_t *msg;
144 pa_tnc_attr_t *attr;
145 imc_state_t *state;
146 imc_test_state_t *test_state;
147 TNC_Result result;
148
149 if (!imc_test->get_state(imc_test, connection_id, &state))
150 {
151 return TNC_RESULT_FATAL;
152 }
153 test_state = (imc_test_state_t*)state;
154 attr = ita_attr_command_create(test_state->get_command(test_state));
155 attr->set_noskip_flag(attr, TRUE);
156 msg = pa_tnc_msg_create();
157 msg->add_attribute(msg, attr);
158 msg->build(msg);
159 result = imc_test->send_message(imc_test, connection_id,
160 msg->get_encoding(msg));
161 msg->destroy(msg);
162
163 return result;
164 }
165
166 /**
167 * see section 3.7.3 of TCG TNC IF-IMC Specification 1.2
168 */
169 TNC_Result TNC_IMC_BeginHandshake(TNC_IMCID imc_id,
170 TNC_ConnectionID connection_id)
171 {
172 if (!imc_test)
173 {
174 DBG1(DBG_IMC, "IMC \"%s\" has not been initialized", imc_name);
175 return TNC_RESULT_NOT_INITIALIZED;
176 }
177 return send_message(connection_id);
178 }
179
180 /**
181 * see section 3.7.4 of TCG TNC IF-IMC Specification 1.2
182 */
183 TNC_Result TNC_IMC_ReceiveMessage(TNC_IMCID imc_id,
184 TNC_ConnectionID connection_id,
185 TNC_BufferReference msg,
186 TNC_UInt32 msg_len,
187 TNC_MessageType msg_type)
188 {
189 pa_tnc_msg_t *pa_tnc_msg;
190 pa_tnc_attr_t *attr;
191 enumerator_t *enumerator;
192 TNC_Result result;
193 bool fatal_error = FALSE;
194
195 if (!imc_test)
196 {
197 DBG1(DBG_IMC, "IMC \"%s\" has not been initialized", imc_name);
198 return TNC_RESULT_NOT_INITIALIZED;
199 }
200
201 /* parse received PA-TNC message and automatically handle any errors */
202 result = imc_test->receive_message(imc_test, connection_id,
203 chunk_create(msg, msg_len), msg_type,
204 &pa_tnc_msg);
205
206 /* no parsed PA-TNC attributes available if an error occurred */
207 if (!pa_tnc_msg)
208 {
209 return result;
210 }
211
212 /* analyze PA-TNC attributes */
213 enumerator = pa_tnc_msg->create_attribute_enumerator(pa_tnc_msg);
214 while (enumerator->enumerate(enumerator, &attr))
215 {
216 if (attr->get_vendor_id(attr) == PEN_IETF &&
217 attr->get_type(attr) == IETF_ATTR_PA_TNC_ERROR)
218 {
219 ietf_attr_pa_tnc_error_t *error_attr;
220 pa_tnc_error_code_t error_code;
221 chunk_t msg_info, attr_info;
222 u_int32_t offset;
223
224 error_attr = (ietf_attr_pa_tnc_error_t*)attr;
225 error_code = error_attr->get_error_code(error_attr);
226 msg_info = error_attr->get_msg_info(error_attr);
227
228 DBG1(DBG_IMC, "received PA-TNC error '%N' concerning message %#B",
229 pa_tnc_error_code_names, error_code, &msg_info);
230 switch (error_code)
231 {
232 case PA_ERROR_INVALID_PARAMETER:
233 offset = error_attr->get_offset(error_attr);
234 DBG1(DBG_IMC, " occurred at offset of %u bytes", offset);
235 break;
236 case PA_ERROR_ATTR_TYPE_NOT_SUPPORTED:
237 attr_info = error_attr->get_attr_info(error_attr);
238 DBG1(DBG_IMC, " unsupported attribute %#B", &attr_info);
239 break;
240 default:
241 break;
242 }
243 fatal_error = TRUE;
244 }
245 else if (attr->get_vendor_id(attr) == PEN_ITA &&
246 attr->get_type(attr) == ITA_ATTR_COMMAND)
247 {
248 ita_attr_command_t *ita_attr;
249 char *command;
250
251 ita_attr = (ita_attr_command_t*)attr;
252 command = ita_attr->get_command(ita_attr);
253 }
254 }
255 enumerator->destroy(enumerator);
256 pa_tnc_msg->destroy(pa_tnc_msg);
257
258 /* if no error occurred then always return the same response */
259 return fatal_error ? TNC_RESULT_FATAL : send_message(connection_id);
260 }
261
262 /**
263 * see section 3.7.5 of TCG TNC IF-IMC Specification 1.2
264 */
265 TNC_Result TNC_IMC_BatchEnding(TNC_IMCID imc_id,
266 TNC_ConnectionID connection_id)
267 {
268 if (!imc_test)
269 {
270 DBG1(DBG_IMC, "IMC \"%s\" has not been initialized", imc_name);
271 return TNC_RESULT_NOT_INITIALIZED;
272 }
273 return TNC_RESULT_SUCCESS;
274 }
275
276 /**
277 * see section 3.7.6 of TCG TNC IF-IMC Specification 1.2
278 */
279 TNC_Result TNC_IMC_Terminate(TNC_IMCID imc_id)
280 {
281 if (!imc_test)
282 {
283 DBG1(DBG_IMC, "IMC \"%s\" has not been initialized", imc_name);
284 return TNC_RESULT_NOT_INITIALIZED;
285 }
286 imc_test->destroy(imc_test);
287 imc_test = NULL;
288
289 return TNC_RESULT_SUCCESS;
290 }
291
292 /**
293 * see section 4.2.8.1 of TCG TNC IF-IMC Specification 1.2
294 */
295 TNC_Result TNC_IMC_ProvideBindFunction(TNC_IMCID imc_id,
296 TNC_TNCC_BindFunctionPointer bind_function)
297 {
298 if (!imc_test)
299 {
300 DBG1(DBG_IMC, "IMC \"%s\" has not been initialized", imc_name);
301 return TNC_RESULT_NOT_INITIALIZED;
302 }
303 return imc_test->bind_functions(imc_test, bind_function);
304 }