refactoring of change_state()
[strongswan.git] / src / libimcv / plugins / imv_test / imv_test.c
1 /*
2 * Copyright (C) 2011 Andreas Steffen, HSR Hochschule fuer Technik Rapperswil
3 *
4 * This program is free software; you can redistribute it and/or modify it
5 * under the terms of the GNU General Public License as published by the
6 * Free Software Foundation; either version 2 of the License, or (at your
7 * option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
8 *
9 * This program is distributed in the hope that it will be useful, but
10 * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
11 * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
12 * for more details.
13 */
14
15 #include "imv_test_state.h"
16
17 #include <imv/imv_agent.h>
18 #include <pa_tnc/pa_tnc_msg.h>
19 #include <ietf/ietf_attr.h>
20 #include <ietf/ietf_attr_pa_tnc_error.h>
21 #include <ita/ita_attr_command.h>
22
23 #include <tncif_names.h>
24
25 #include <pen/pen.h>
26 #include <debug.h>
27
28 /* IMV definitions */
29
30 static const char imv_name[] = "Test";
31
32 #define IMV_VENDOR_ID PEN_ITA
33 #define IMV_SUBTYPE 0x01
34
35 static imv_agent_t *imv_test;
36
37 /**
38 * see section 3.7.1 of TCG TNC IF-IMV Specification 1.2
39 */
40 TNC_Result TNC_IMV_Initialize(TNC_IMVID imv_id,
41 TNC_Version min_version,
42 TNC_Version max_version,
43 TNC_Version *actual_version)
44 {
45 if (imv_test)
46 {
47 DBG1(DBG_IMV, "IMV \"%s\" has already been initialized", imv_name);
48 return TNC_RESULT_ALREADY_INITIALIZED;
49 }
50 imv_test = imv_agent_create(imv_name, IMV_VENDOR_ID, IMV_SUBTYPE,
51 imv_id, actual_version);
52 if (!imv_test)
53 {
54 return TNC_RESULT_FATAL;
55 }
56 if (min_version > TNC_IFIMV_VERSION_1 || max_version < TNC_IFIMV_VERSION_1)
57 {
58 DBG1(DBG_IMV, "no common IF-IMV version");
59 return TNC_RESULT_NO_COMMON_VERSION;
60 }
61 return TNC_RESULT_SUCCESS;
62 }
63
64 /**
65 * see section 3.7.2 of TCG TNC IF-IMV Specification 1.2
66 */
67 TNC_Result TNC_IMV_NotifyConnectionChange(TNC_IMVID imv_id,
68 TNC_ConnectionID connection_id,
69 TNC_ConnectionState new_state)
70 {
71 imv_state_t *state;
72 imv_test_state_t *test_state;
73 TNC_Result result;
74 int rounds;
75
76 if (!imv_test)
77 {
78 DBG1(DBG_IMV, "IMV \"%s\" has not been initialized", imv_name);
79 return TNC_RESULT_NOT_INITIALIZED;
80 }
81 switch (new_state)
82 {
83 case TNC_CONNECTION_STATE_CREATE:
84 state = imv_test_state_create(connection_id);
85 return imv_test->create_state(imv_test, state);
86 case TNC_CONNECTION_STATE_DELETE:
87 return imv_test->delete_state(imv_test, connection_id);
88 case TNC_CONNECTION_STATE_HANDSHAKE:
89 /* get updated IMV state */
90 result = imv_test->change_state(imv_test, connection_id,
91 new_state, &state);
92 if (result != TNC_RESULT_SUCCESS)
93 {
94 return TNC_RESULT_FATAL;
95 }
96 test_state = (imv_test_state_t*)state;
97
98 /* set the number of measurement rounds */
99 rounds = lib->settings->get_int(lib->settings,
100 "libimcv.plugins.imv-test.rounds", 0);
101 test_state->set_rounds(test_state, rounds);
102 return TNC_RESULT_SUCCESS;
103 default:
104 return imv_test->change_state(imv_test, connection_id,
105 new_state, NULL);
106 }
107 }
108
109 static TNC_Result send_message(TNC_ConnectionID connection_id)
110 {
111 pa_tnc_msg_t *msg;
112 pa_tnc_attr_t *attr;
113 TNC_Result result;
114
115 attr = ita_attr_command_create("repeat");
116 msg = pa_tnc_msg_create();
117 msg->add_attribute(msg, attr);
118 msg->build(msg);
119 result = imv_test->send_message(imv_test, connection_id,
120 msg->get_encoding(msg));
121 msg->destroy(msg);
122
123 return result;
124 }
125
126 /**
127 * see section 3.7.3 of TCG TNC IF-IMV Specification 1.2
128 */
129 TNC_Result TNC_IMV_ReceiveMessage(TNC_IMVID imv_id,
130 TNC_ConnectionID connection_id,
131 TNC_BufferReference msg,
132 TNC_UInt32 msg_len,
133 TNC_MessageType msg_type)
134 {
135 pa_tnc_msg_t *pa_tnc_msg;
136 pa_tnc_attr_t *attr;
137 imv_state_t *state;
138 imv_test_state_t *imv_test_state;
139 enumerator_t *enumerator;
140 TNC_Result result;
141 bool fatal_error = FALSE, retry = FALSE;
142
143 if (!imv_test)
144 {
145 DBG1(DBG_IMV, "IMV \"%s\" has not been initialized", imv_name);
146 return TNC_RESULT_NOT_INITIALIZED;
147 }
148
149 /* get current IMV state */
150 if (!imv_test->get_state(imv_test, connection_id, &state))
151 {
152 return TNC_RESULT_FATAL;
153 }
154
155 /* parse received PA-TNC message and automatically handle any errors */
156 result = imv_test->receive_message(imv_test, connection_id,
157 chunk_create(msg, msg_len), msg_type,
158 &pa_tnc_msg);
159
160 /* no parsed PA-TNC attributes available if an error occurred */
161 if (!pa_tnc_msg)
162 {
163 return result;
164 }
165
166 /* analyze PA-TNC attributes */
167 enumerator = pa_tnc_msg->create_attribute_enumerator(pa_tnc_msg);
168 while (enumerator->enumerate(enumerator, &attr))
169 {
170 if (attr->get_vendor_id(attr) == PEN_IETF &&
171 attr->get_type(attr) == IETF_ATTR_PA_TNC_ERROR)
172 {
173 ietf_attr_pa_tnc_error_t *error_attr;
174 pa_tnc_error_code_t error_code;
175 chunk_t msg_info, attr_info;
176
177 error_attr = (ietf_attr_pa_tnc_error_t*)attr;
178 error_code = error_attr->get_error_code(error_attr);
179 msg_info = error_attr->get_msg_info(error_attr);
180
181 DBG1(DBG_IMV, "received PA-TNC error '%N' concerning message %#B",
182 pa_tnc_error_code_names, error_code, &msg_info);
183 switch (error_code)
184 {
185 case PA_ERROR_ATTR_TYPE_NOT_SUPPORTED:
186 attr_info = error_attr->get_attr_info(error_attr);
187 DBG1(DBG_IMV, " unsupported attribute %#B", &attr_info);
188 break;
189 default:
190 break;
191 }
192 fatal_error = TRUE;
193 }
194 else if (attr->get_vendor_id(attr) == PEN_ITA &&
195 attr->get_type(attr) == ITA_ATTR_COMMAND)
196 {
197 ita_attr_command_t *ita_attr;
198 char *command;
199
200 ita_attr = (ita_attr_command_t*)attr;
201 command = ita_attr->get_command(ita_attr);
202
203 if (streq(command, "allow"))
204 {
205 state->set_recommendation(state,
206 TNC_IMV_ACTION_RECOMMENDATION_ALLOW,
207 TNC_IMV_EVALUATION_RESULT_COMPLIANT);
208 }
209 else if (streq(command, "isolate"))
210 {
211 state->set_recommendation(state,
212 TNC_IMV_ACTION_RECOMMENDATION_ISOLATE,
213 TNC_IMV_EVALUATION_RESULT_NONCOMPLIANT_MINOR);
214 }
215 else if (streq(command, "block") || streq(command, "none"))
216 {
217 state->set_recommendation(state,
218 TNC_IMV_ACTION_RECOMMENDATION_NO_ACCESS,
219 TNC_IMV_EVALUATION_RESULT_NONCOMPLIANT_MAJOR);
220 }
221 else if (streq(command, "retry"))
222 {
223 retry = TRUE;
224 }
225 else
226 {
227 DBG1(DBG_IMV, "unsupported ITA Command '%s'", command);
228 state->set_recommendation(state,
229 TNC_IMV_ACTION_RECOMMENDATION_NO_RECOMMENDATION,
230 TNC_IMV_EVALUATION_RESULT_ERROR);
231 }
232 }
233 }
234 enumerator->destroy(enumerator);
235 pa_tnc_msg->destroy(pa_tnc_msg);
236
237 if (fatal_error)
238 {
239 state->set_recommendation(state,
240 TNC_IMV_ACTION_RECOMMENDATION_NO_RECOMMENDATION,
241 TNC_IMV_EVALUATION_RESULT_ERROR);
242 return imv_test->provide_recommendation(imv_test, connection_id);
243 }
244
245 /* request a handshake retry ? */
246 if (retry)
247 {
248 return imv_test->request_handshake_retry(imv_id, connection_id,
249 TNC_RETRY_REASON_IMV_SERIOUS_EVENT);
250 }
251
252 /* repeat the measurement ? */
253 imv_test_state = (imv_test_state_t*)state;
254 if (imv_test_state->another_round(imv_test_state))
255 {
256 return send_message(connection_id);
257 }
258
259 return imv_test->provide_recommendation(imv_test, connection_id);
260 }
261
262 /**
263 * see section 3.7.4 of TCG TNC IF-IMV Specification 1.2
264 */
265 TNC_Result TNC_IMV_SolicitRecommendation(TNC_IMVID imv_id,
266 TNC_ConnectionID connection_id)
267 {
268 if (!imv_test)
269 {
270 DBG1(DBG_IMV, "IMV \"%s\" has not been initialized", imv_name);
271 return TNC_RESULT_NOT_INITIALIZED;
272 }
273 return imv_test->provide_recommendation(imv_test, connection_id);
274 }
275
276 /**
277 * see section 3.7.5 of TCG TNC IF-IMV Specification 1.2
278 */
279 TNC_Result TNC_IMV_BatchEnding(TNC_IMVID imv_id,
280 TNC_ConnectionID connection_id)
281 {
282 if (!imv_test)
283 {
284 DBG1(DBG_IMV, "IMV \"%s\" has not been initialized", imv_name);
285 return TNC_RESULT_NOT_INITIALIZED;
286 }
287 return TNC_RESULT_SUCCESS;
288 }
289
290 /**
291 * see section 3.7.6 of TCG TNC IF-IMV Specification 1.2
292 */
293 TNC_Result TNC_IMV_Terminate(TNC_IMVID imv_id)
294 {
295 if (!imv_test)
296 {
297 DBG1(DBG_IMV, "IMV \"%s\" has not been initialized", imv_name);
298 return TNC_RESULT_NOT_INITIALIZED;
299 }
300 imv_test->destroy(imv_test);
301 imv_test = NULL;
302
303 return TNC_RESULT_SUCCESS;
304 }
305
306 /**
307 * see section 4.2.8.1 of TCG TNC IF-IMV Specification 1.2
308 */
309 TNC_Result TNC_IMV_ProvideBindFunction(TNC_IMVID imv_id,
310 TNC_TNCS_BindFunctionPointer bind_function)
311 {
312 if (!imv_test)
313 {
314 DBG1(DBG_IMV, "IMV \"%s\" has not been initialized", imv_name);
315 return TNC_RESULT_NOT_INITIALIZED;
316 }
317 return imv_test->bind_functions(imv_test, bind_function);
318 }