1 /*
2 * Copyright (c) 2016, The OpenThread Authors.
3 * All rights reserved.
4 *
5 * Redistribution and use in source and binary forms, with or without
6 * modification, are permitted provided that the following conditions are met:
7 * 1. Redistributions of source code must retain the above copyright
8 * notice, this list of conditions and the following disclaimer.
9 * 2. Redistributions in binary form must reproduce the above copyright
10 * notice, this list of conditions and the following disclaimer in the
11 * documentation and/or other materials provided with the distribution.
12 * 3. Neither the name of the copyright holder nor the
13 * names of its contributors may be used to endorse or promote products
14 * derived from this software without specific prior written permission.
15 *
16 * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS"
17 * AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
18 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
19 * ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE
20 * LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
21 * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
22 * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
23 * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
24 * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
25 * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
26 * POSSIBILITY OF SUCH DAMAGE.
27 */
28
29 /**
30 * @file
31 * This file implements the Joiner Router role.
32 */
33
34 #include "joiner_router.hpp"
35
36 #if OPENTHREAD_FTD
37
38 #include <stdio.h>
39
40 #include "common/as_core_type.hpp"
41 #include "common/code_utils.hpp"
42 #include "common/encoding.hpp"
43 #include "common/locator_getters.hpp"
44 #include "common/log.hpp"
45 #include "instance/instance.hpp"
46 #include "meshcop/meshcop.hpp"
47 #include "meshcop/meshcop_tlvs.hpp"
48 #include "thread/mle.hpp"
49 #include "thread/thread_netif.hpp"
50 #include "thread/uri_paths.hpp"
51
52 namespace ot {
53 namespace MeshCoP {
54
55 RegisterLogModule("JoinerRouter");
56
JoinerRouter(Instance & aInstance)57 JoinerRouter::JoinerRouter(Instance &aInstance)
58 : InstanceLocator(aInstance)
59 , mSocket(aInstance, *this)
60 , mTimer(aInstance)
61 , mJoinerUdpPort(0)
62 , mIsJoinerPortConfigured(false)
63 {
64 }
65
HandleNotifierEvents(Events aEvents)66 void JoinerRouter::HandleNotifierEvents(Events aEvents)
67 {
68 if (aEvents.Contains(kEventThreadNetdataChanged))
69 {
70 Start();
71 }
72 }
73
Start(void)74 void JoinerRouter::Start(void)
75 {
76 VerifyOrExit(Get<Mle::MleRouter>().IsFullThreadDevice());
77
78 if (Get<NetworkData::Leader>().IsJoiningAllowed())
79 {
80 uint16_t port = GetJoinerUdpPort();
81
82 VerifyOrExit(!mSocket.IsBound());
83
84 IgnoreError(mSocket.Open());
85 IgnoreError(mSocket.Bind(port));
86 IgnoreError(Get<Ip6::Filter>().AddUnsecurePort(port));
87 LogInfo("Joiner Router: start");
88 }
89 else
90 {
91 VerifyOrExit(mSocket.IsBound());
92
93 IgnoreError(Get<Ip6::Filter>().RemoveUnsecurePort(mSocket.GetSockName().mPort));
94
95 IgnoreError(mSocket.Close());
96 }
97
98 exit:
99 return;
100 }
101
GetJoinerUdpPort(void) const102 uint16_t JoinerRouter::GetJoinerUdpPort(void) const
103 {
104 uint16_t port;
105
106 if (mIsJoinerPortConfigured)
107 {
108 ExitNow(port = mJoinerUdpPort);
109 }
110
111 if (Get<NetworkData::Leader>().FindJoinerUdpPort(port) == kErrorNone)
112 {
113 ExitNow();
114 }
115
116 port = kDefaultJoinerUdpPort;
117
118 exit:
119 return port;
120 }
121
SetJoinerUdpPort(uint16_t aJoinerUdpPort)122 void JoinerRouter::SetJoinerUdpPort(uint16_t aJoinerUdpPort)
123 {
124 mJoinerUdpPort = aJoinerUdpPort;
125 mIsJoinerPortConfigured = true;
126 Start();
127 }
128
HandleUdpReceive(Message & aMessage,const Ip6::MessageInfo & aMessageInfo)129 void JoinerRouter::HandleUdpReceive(Message &aMessage, const Ip6::MessageInfo &aMessageInfo)
130 {
131 Error error;
132 Coap::Message *message = nullptr;
133 Tmf::MessageInfo messageInfo(GetInstance());
134 ExtendedTlv tlv;
135 uint16_t borderAgentRloc;
136 OffsetRange offsetRange;
137
138 LogInfo("JoinerRouter::HandleUdpReceive");
139
140 SuccessOrExit(error = Get<NetworkData::Leader>().FindBorderAgentRloc(borderAgentRloc));
141
142 message = Get<Tmf::Agent>().NewPriorityNonConfirmablePostMessage(kUriRelayRx);
143 VerifyOrExit(message != nullptr, error = kErrorNoBufs);
144
145 SuccessOrExit(error = Tlv::Append<JoinerUdpPortTlv>(*message, aMessageInfo.GetPeerPort()));
146 SuccessOrExit(error = Tlv::Append<JoinerIidTlv>(*message, aMessageInfo.GetPeerAddr().GetIid()));
147 SuccessOrExit(error = Tlv::Append<JoinerRouterLocatorTlv>(*message, Get<Mle::MleRouter>().GetRloc16()));
148
149 offsetRange.InitFromMessageOffsetToEnd(aMessage);
150
151 tlv.SetType(Tlv::kJoinerDtlsEncapsulation);
152 tlv.SetLength(offsetRange.GetLength());
153 SuccessOrExit(error = message->Append(tlv));
154 SuccessOrExit(error = message->AppendBytesFromMessage(aMessage, offsetRange));
155
156 messageInfo.SetSockAddrToRlocPeerAddrTo(borderAgentRloc);
157
158 SuccessOrExit(error = Get<Tmf::Agent>().SendMessage(*message, messageInfo));
159
160 LogInfo("Sent %s", UriToString<kUriRelayRx>());
161
162 exit:
163 FreeMessageOnError(message, error);
164 }
165
HandleTmf(Coap::Message & aMessage,const Ip6::MessageInfo & aMessageInfo)166 template <> void JoinerRouter::HandleTmf<kUriRelayTx>(Coap::Message &aMessage, const Ip6::MessageInfo &aMessageInfo)
167 {
168 OT_UNUSED_VARIABLE(aMessageInfo);
169
170 Error error;
171 uint16_t joinerPort;
172 Ip6::InterfaceIdentifier joinerIid;
173 Kek kek;
174 OffsetRange offsetRange;
175 Message *message = nullptr;
176 Message::Settings settings(Message::kNoLinkSecurity, Message::kPriorityNet);
177 Ip6::MessageInfo messageInfo;
178
179 VerifyOrExit(aMessage.IsNonConfirmablePostRequest(), error = kErrorDrop);
180
181 LogInfo("Received %s", UriToString<kUriRelayTx>());
182
183 SuccessOrExit(error = Tlv::Find<JoinerUdpPortTlv>(aMessage, joinerPort));
184 SuccessOrExit(error = Tlv::Find<JoinerIidTlv>(aMessage, joinerIid));
185
186 SuccessOrExit(error = Tlv::FindTlvValueOffsetRange(aMessage, Tlv::kJoinerDtlsEncapsulation, offsetRange));
187
188 VerifyOrExit((message = mSocket.NewMessage(0, settings)) != nullptr, error = kErrorNoBufs);
189
190 SuccessOrExit(error = message->AppendBytesFromMessage(aMessage, offsetRange));
191
192 messageInfo.GetPeerAddr().SetToLinkLocalAddress(joinerIid);
193 messageInfo.SetPeerPort(joinerPort);
194
195 SuccessOrExit(error = mSocket.SendTo(*message, messageInfo));
196
197 if (Tlv::Find<JoinerRouterKekTlv>(aMessage, kek) == kErrorNone)
198 {
199 LogInfo("Received kek");
200
201 DelaySendingJoinerEntrust(messageInfo, kek);
202 }
203
204 exit:
205 FreeMessageOnError(message, error);
206 }
207
DelaySendingJoinerEntrust(const Ip6::MessageInfo & aMessageInfo,const Kek & aKek)208 void JoinerRouter::DelaySendingJoinerEntrust(const Ip6::MessageInfo &aMessageInfo, const Kek &aKek)
209 {
210 Error error = kErrorNone;
211 Message *message = Get<MessagePool>().Allocate(Message::kTypeOther);
212 JoinerEntrustMetadata metadata;
213
214 VerifyOrExit(message != nullptr, error = kErrorNoBufs);
215
216 metadata.mMessageInfo = aMessageInfo;
217 metadata.mMessageInfo.SetPeerPort(Tmf::kUdpPort);
218 metadata.mSendTime = TimerMilli::GetNow() + kJoinerEntrustTxDelay;
219 metadata.mKek = aKek;
220
221 SuccessOrExit(error = metadata.AppendTo(*message));
222
223 mDelayedJoinEnts.Enqueue(*message);
224
225 if (!mTimer.IsRunning())
226 {
227 mTimer.FireAt(metadata.mSendTime);
228 }
229
230 exit:
231 FreeMessageOnError(message, error);
232 LogWarnOnError(error, "schedule joiner entrust");
233 }
234
HandleTimer(void)235 void JoinerRouter::HandleTimer(void) { SendDelayedJoinerEntrust(); }
236
SendDelayedJoinerEntrust(void)237 void JoinerRouter::SendDelayedJoinerEntrust(void)
238 {
239 JoinerEntrustMetadata metadata;
240 Message *message = mDelayedJoinEnts.GetHead();
241
242 VerifyOrExit(message != nullptr);
243 VerifyOrExit(!mTimer.IsRunning());
244
245 metadata.ReadFrom(*message);
246
247 if (TimerMilli::GetNow() < metadata.mSendTime)
248 {
249 mTimer.FireAt(metadata.mSendTime);
250 }
251 else
252 {
253 mDelayedJoinEnts.DequeueAndFree(*message);
254
255 Get<KeyManager>().SetKek(metadata.mKek);
256
257 if (SendJoinerEntrust(metadata.mMessageInfo) != kErrorNone)
258 {
259 mTimer.Start(0);
260 }
261 }
262
263 exit:
264 return;
265 }
266
SendJoinerEntrust(const Ip6::MessageInfo & aMessageInfo)267 Error JoinerRouter::SendJoinerEntrust(const Ip6::MessageInfo &aMessageInfo)
268 {
269 Error error = kErrorNone;
270 Coap::Message *message;
271
272 message = PrepareJoinerEntrustMessage();
273 VerifyOrExit(message != nullptr, error = kErrorNoBufs);
274
275 IgnoreError(Get<Tmf::Agent>().AbortTransaction(&JoinerRouter::HandleJoinerEntrustResponse, this));
276
277 SuccessOrExit(error = Get<Tmf::Agent>().SendMessage(*message, aMessageInfo,
278 &JoinerRouter::HandleJoinerEntrustResponse, this));
279
280 LogInfo("Sent %s (len= %d)", UriToString<kUriJoinerEntrust>(), message->GetLength());
281 LogCert("[THCI] direction=send | type=JOIN_ENT.ntf");
282
283 exit:
284 FreeMessageOnError(message, error);
285 return error;
286 }
287
PrepareJoinerEntrustMessage(void)288 Coap::Message *JoinerRouter::PrepareJoinerEntrustMessage(void)
289 {
290 static const Tlv::Type kTlvTypes[] = {
291 Tlv::kNetworkKey, Tlv::kMeshLocalPrefix, Tlv::kExtendedPanId, Tlv::kNetworkName,
292 Tlv::kActiveTimestamp, Tlv::kChannelMask, Tlv::kPskc, Tlv::kSecurityPolicy,
293 };
294
295 Error error = kErrorNone;
296 Coap::Message *message = nullptr;
297 Dataset dataset;
298
299 message = Get<Tmf::Agent>().NewPriorityConfirmablePostMessage(kUriJoinerEntrust);
300 VerifyOrExit(message != nullptr, error = kErrorNoBufs);
301
302 message->SetSubType(Message::kSubTypeJoinerEntrust);
303
304 SuccessOrExit(error = Get<ActiveDatasetManager>().Read(dataset));
305
306 for (Tlv::Type tlvType : kTlvTypes)
307 {
308 const Tlv *tlv = dataset.FindTlv(tlvType);
309
310 VerifyOrExit(tlv != nullptr, error = kErrorInvalidState);
311 SuccessOrExit(error = tlv->AppendTo(*message));
312 }
313
314 SuccessOrExit(error = Tlv::Append<NetworkKeySequenceTlv>(*message, Get<KeyManager>().GetCurrentKeySequence()));
315
316 exit:
317 FreeAndNullMessageOnError(message, error);
318 return message;
319 }
320
HandleJoinerEntrustResponse(void * aContext,otMessage * aMessage,const otMessageInfo * aMessageInfo,Error aResult)321 void JoinerRouter::HandleJoinerEntrustResponse(void *aContext,
322 otMessage *aMessage,
323 const otMessageInfo *aMessageInfo,
324 Error aResult)
325 {
326 static_cast<JoinerRouter *>(aContext)->HandleJoinerEntrustResponse(AsCoapMessagePtr(aMessage),
327 AsCoreTypePtr(aMessageInfo), aResult);
328 }
329
HandleJoinerEntrustResponse(Coap::Message * aMessage,const Ip6::MessageInfo * aMessageInfo,Error aResult)330 void JoinerRouter::HandleJoinerEntrustResponse(Coap::Message *aMessage,
331 const Ip6::MessageInfo *aMessageInfo,
332 Error aResult)
333 {
334 OT_UNUSED_VARIABLE(aMessageInfo);
335
336 SendDelayedJoinerEntrust();
337
338 VerifyOrExit(aResult == kErrorNone && aMessage != nullptr);
339
340 VerifyOrExit(aMessage->GetCode() == Coap::kCodeChanged);
341
342 LogInfo("Receive %s response", UriToString<kUriJoinerEntrust>());
343 LogCert("[THCI] direction=recv | type=JOIN_ENT.rsp");
344
345 exit:
346 return;
347 }
348
ReadFrom(const Message & aMessage)349 void JoinerRouter::JoinerEntrustMetadata::ReadFrom(const Message &aMessage)
350 {
351 uint16_t length = aMessage.GetLength();
352
353 OT_ASSERT(length >= sizeof(*this));
354 IgnoreError(aMessage.Read(length - sizeof(*this), *this));
355 }
356
357 } // namespace MeshCoP
358 } // namespace ot
359
360 #endif // OPENTHREAD_FTD
361