1 /*
2  *  Copyright (c) 2016, The OpenThread Authors.
3  *  All rights reserved.
4  *
5  *  Redistribution and use in source and binary forms, with or without
6  *  modification, are permitted provided that the following conditions are met:
7  *  1. Redistributions of source code must retain the above copyright
8  *     notice, this list of conditions and the following disclaimer.
9  *  2. Redistributions in binary form must reproduce the above copyright
10  *     notice, this list of conditions and the following disclaimer in the
11  *     documentation and/or other materials provided with the distribution.
12  *  3. Neither the name of the copyright holder nor the
13  *     names of its contributors may be used to endorse or promote products
14  *     derived from this software without specific prior written permission.
15  *
16  *  THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS"
17  *  AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
18  *  IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
19  *  ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE
20  *  LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
21  *  CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
22  *  SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
23  *  INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
24  *  CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
25  *  ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
26  *  POSSIBILITY OF SUCH DAMAGE.
27  */
28 
29 /**
30  * @file
31  *   This file implements the Joiner Router role.
32  */
33 
34 #include "joiner_router.hpp"
35 
36 #if OPENTHREAD_FTD
37 
38 #include <stdio.h>
39 
40 #include "common/as_core_type.hpp"
41 #include "common/code_utils.hpp"
42 #include "common/encoding.hpp"
43 #include "common/locator_getters.hpp"
44 #include "common/log.hpp"
45 #include "instance/instance.hpp"
46 #include "meshcop/meshcop.hpp"
47 #include "meshcop/meshcop_tlvs.hpp"
48 #include "thread/mle.hpp"
49 #include "thread/thread_netif.hpp"
50 #include "thread/uri_paths.hpp"
51 
52 namespace ot {
53 namespace MeshCoP {
54 
55 RegisterLogModule("JoinerRouter");
56 
JoinerRouter(Instance & aInstance)57 JoinerRouter::JoinerRouter(Instance &aInstance)
58     : InstanceLocator(aInstance)
59     , mSocket(aInstance, *this)
60     , mTimer(aInstance)
61     , mJoinerUdpPort(0)
62     , mIsJoinerPortConfigured(false)
63 {
64 }
65 
HandleNotifierEvents(Events aEvents)66 void JoinerRouter::HandleNotifierEvents(Events aEvents)
67 {
68     if (aEvents.Contains(kEventThreadNetdataChanged))
69     {
70         Start();
71     }
72 }
73 
Start(void)74 void JoinerRouter::Start(void)
75 {
76     VerifyOrExit(Get<Mle::MleRouter>().IsFullThreadDevice());
77 
78     if (Get<NetworkData::Leader>().IsJoiningAllowed())
79     {
80         uint16_t port = GetJoinerUdpPort();
81 
82         VerifyOrExit(!mSocket.IsBound());
83 
84         IgnoreError(mSocket.Open());
85         IgnoreError(mSocket.Bind(port));
86         IgnoreError(Get<Ip6::Filter>().AddUnsecurePort(port));
87         LogInfo("Joiner Router: start");
88     }
89     else
90     {
91         VerifyOrExit(mSocket.IsBound());
92 
93         IgnoreError(Get<Ip6::Filter>().RemoveUnsecurePort(mSocket.GetSockName().mPort));
94 
95         IgnoreError(mSocket.Close());
96     }
97 
98 exit:
99     return;
100 }
101 
GetJoinerUdpPort(void) const102 uint16_t JoinerRouter::GetJoinerUdpPort(void) const
103 {
104     uint16_t port;
105 
106     if (mIsJoinerPortConfigured)
107     {
108         ExitNow(port = mJoinerUdpPort);
109     }
110 
111     if (Get<NetworkData::Leader>().FindJoinerUdpPort(port) == kErrorNone)
112     {
113         ExitNow();
114     }
115 
116     port = kDefaultJoinerUdpPort;
117 
118 exit:
119     return port;
120 }
121 
SetJoinerUdpPort(uint16_t aJoinerUdpPort)122 void JoinerRouter::SetJoinerUdpPort(uint16_t aJoinerUdpPort)
123 {
124     mJoinerUdpPort          = aJoinerUdpPort;
125     mIsJoinerPortConfigured = true;
126     Start();
127 }
128 
HandleUdpReceive(Message & aMessage,const Ip6::MessageInfo & aMessageInfo)129 void JoinerRouter::HandleUdpReceive(Message &aMessage, const Ip6::MessageInfo &aMessageInfo)
130 {
131     Error            error;
132     Coap::Message   *message = nullptr;
133     Tmf::MessageInfo messageInfo(GetInstance());
134     ExtendedTlv      tlv;
135     uint16_t         borderAgentRloc;
136     OffsetRange      offsetRange;
137 
138     LogInfo("JoinerRouter::HandleUdpReceive");
139 
140     SuccessOrExit(error = Get<NetworkData::Leader>().FindBorderAgentRloc(borderAgentRloc));
141 
142     message = Get<Tmf::Agent>().NewPriorityNonConfirmablePostMessage(kUriRelayRx);
143     VerifyOrExit(message != nullptr, error = kErrorNoBufs);
144 
145     SuccessOrExit(error = Tlv::Append<JoinerUdpPortTlv>(*message, aMessageInfo.GetPeerPort()));
146     SuccessOrExit(error = Tlv::Append<JoinerIidTlv>(*message, aMessageInfo.GetPeerAddr().GetIid()));
147     SuccessOrExit(error = Tlv::Append<JoinerRouterLocatorTlv>(*message, Get<Mle::MleRouter>().GetRloc16()));
148 
149     offsetRange.InitFromMessageOffsetToEnd(aMessage);
150 
151     tlv.SetType(Tlv::kJoinerDtlsEncapsulation);
152     tlv.SetLength(offsetRange.GetLength());
153     SuccessOrExit(error = message->Append(tlv));
154     SuccessOrExit(error = message->AppendBytesFromMessage(aMessage, offsetRange));
155 
156     messageInfo.SetSockAddrToRlocPeerAddrTo(borderAgentRloc);
157 
158     SuccessOrExit(error = Get<Tmf::Agent>().SendMessage(*message, messageInfo));
159 
160     LogInfo("Sent %s", UriToString<kUriRelayRx>());
161 
162 exit:
163     FreeMessageOnError(message, error);
164 }
165 
HandleTmf(Coap::Message & aMessage,const Ip6::MessageInfo & aMessageInfo)166 template <> void JoinerRouter::HandleTmf<kUriRelayTx>(Coap::Message &aMessage, const Ip6::MessageInfo &aMessageInfo)
167 {
168     OT_UNUSED_VARIABLE(aMessageInfo);
169 
170     Error                    error;
171     uint16_t                 joinerPort;
172     Ip6::InterfaceIdentifier joinerIid;
173     Kek                      kek;
174     OffsetRange              offsetRange;
175     Message                 *message = nullptr;
176     Message::Settings        settings(Message::kNoLinkSecurity, Message::kPriorityNet);
177     Ip6::MessageInfo         messageInfo;
178 
179     VerifyOrExit(aMessage.IsNonConfirmablePostRequest(), error = kErrorDrop);
180 
181     LogInfo("Received %s", UriToString<kUriRelayTx>());
182 
183     SuccessOrExit(error = Tlv::Find<JoinerUdpPortTlv>(aMessage, joinerPort));
184     SuccessOrExit(error = Tlv::Find<JoinerIidTlv>(aMessage, joinerIid));
185 
186     SuccessOrExit(error = Tlv::FindTlvValueOffsetRange(aMessage, Tlv::kJoinerDtlsEncapsulation, offsetRange));
187 
188     VerifyOrExit((message = mSocket.NewMessage(0, settings)) != nullptr, error = kErrorNoBufs);
189 
190     SuccessOrExit(error = message->AppendBytesFromMessage(aMessage, offsetRange));
191 
192     messageInfo.GetPeerAddr().SetToLinkLocalAddress(joinerIid);
193     messageInfo.SetPeerPort(joinerPort);
194 
195     SuccessOrExit(error = mSocket.SendTo(*message, messageInfo));
196 
197     if (Tlv::Find<JoinerRouterKekTlv>(aMessage, kek) == kErrorNone)
198     {
199         LogInfo("Received kek");
200 
201         DelaySendingJoinerEntrust(messageInfo, kek);
202     }
203 
204 exit:
205     FreeMessageOnError(message, error);
206 }
207 
DelaySendingJoinerEntrust(const Ip6::MessageInfo & aMessageInfo,const Kek & aKek)208 void JoinerRouter::DelaySendingJoinerEntrust(const Ip6::MessageInfo &aMessageInfo, const Kek &aKek)
209 {
210     Error                 error   = kErrorNone;
211     Message              *message = Get<MessagePool>().Allocate(Message::kTypeOther);
212     JoinerEntrustMetadata metadata;
213 
214     VerifyOrExit(message != nullptr, error = kErrorNoBufs);
215 
216     metadata.mMessageInfo = aMessageInfo;
217     metadata.mMessageInfo.SetPeerPort(Tmf::kUdpPort);
218     metadata.mSendTime = TimerMilli::GetNow() + kJoinerEntrustTxDelay;
219     metadata.mKek      = aKek;
220 
221     SuccessOrExit(error = metadata.AppendTo(*message));
222 
223     mDelayedJoinEnts.Enqueue(*message);
224 
225     if (!mTimer.IsRunning())
226     {
227         mTimer.FireAt(metadata.mSendTime);
228     }
229 
230 exit:
231     FreeMessageOnError(message, error);
232     LogWarnOnError(error, "schedule joiner entrust");
233 }
234 
HandleTimer(void)235 void JoinerRouter::HandleTimer(void) { SendDelayedJoinerEntrust(); }
236 
SendDelayedJoinerEntrust(void)237 void JoinerRouter::SendDelayedJoinerEntrust(void)
238 {
239     JoinerEntrustMetadata metadata;
240     Message              *message = mDelayedJoinEnts.GetHead();
241 
242     VerifyOrExit(message != nullptr);
243     VerifyOrExit(!mTimer.IsRunning());
244 
245     metadata.ReadFrom(*message);
246 
247     if (TimerMilli::GetNow() < metadata.mSendTime)
248     {
249         mTimer.FireAt(metadata.mSendTime);
250     }
251     else
252     {
253         mDelayedJoinEnts.DequeueAndFree(*message);
254 
255         Get<KeyManager>().SetKek(metadata.mKek);
256 
257         if (SendJoinerEntrust(metadata.mMessageInfo) != kErrorNone)
258         {
259             mTimer.Start(0);
260         }
261     }
262 
263 exit:
264     return;
265 }
266 
SendJoinerEntrust(const Ip6::MessageInfo & aMessageInfo)267 Error JoinerRouter::SendJoinerEntrust(const Ip6::MessageInfo &aMessageInfo)
268 {
269     Error          error = kErrorNone;
270     Coap::Message *message;
271 
272     message = PrepareJoinerEntrustMessage();
273     VerifyOrExit(message != nullptr, error = kErrorNoBufs);
274 
275     IgnoreError(Get<Tmf::Agent>().AbortTransaction(&JoinerRouter::HandleJoinerEntrustResponse, this));
276 
277     SuccessOrExit(error = Get<Tmf::Agent>().SendMessage(*message, aMessageInfo,
278                                                         &JoinerRouter::HandleJoinerEntrustResponse, this));
279 
280     LogInfo("Sent %s (len= %d)", UriToString<kUriJoinerEntrust>(), message->GetLength());
281     LogCert("[THCI] direction=send | type=JOIN_ENT.ntf");
282 
283 exit:
284     FreeMessageOnError(message, error);
285     return error;
286 }
287 
PrepareJoinerEntrustMessage(void)288 Coap::Message *JoinerRouter::PrepareJoinerEntrustMessage(void)
289 {
290     static const Tlv::Type kTlvTypes[] = {
291         Tlv::kNetworkKey,      Tlv::kMeshLocalPrefix, Tlv::kExtendedPanId, Tlv::kNetworkName,
292         Tlv::kActiveTimestamp, Tlv::kChannelMask,     Tlv::kPskc,          Tlv::kSecurityPolicy,
293     };
294 
295     Error          error   = kErrorNone;
296     Coap::Message *message = nullptr;
297     Dataset        dataset;
298 
299     message = Get<Tmf::Agent>().NewPriorityConfirmablePostMessage(kUriJoinerEntrust);
300     VerifyOrExit(message != nullptr, error = kErrorNoBufs);
301 
302     message->SetSubType(Message::kSubTypeJoinerEntrust);
303 
304     SuccessOrExit(error = Get<ActiveDatasetManager>().Read(dataset));
305 
306     for (Tlv::Type tlvType : kTlvTypes)
307     {
308         const Tlv *tlv = dataset.FindTlv(tlvType);
309 
310         VerifyOrExit(tlv != nullptr, error = kErrorInvalidState);
311         SuccessOrExit(error = tlv->AppendTo(*message));
312     }
313 
314     SuccessOrExit(error = Tlv::Append<NetworkKeySequenceTlv>(*message, Get<KeyManager>().GetCurrentKeySequence()));
315 
316 exit:
317     FreeAndNullMessageOnError(message, error);
318     return message;
319 }
320 
HandleJoinerEntrustResponse(void * aContext,otMessage * aMessage,const otMessageInfo * aMessageInfo,Error aResult)321 void JoinerRouter::HandleJoinerEntrustResponse(void                *aContext,
322                                                otMessage           *aMessage,
323                                                const otMessageInfo *aMessageInfo,
324                                                Error                aResult)
325 {
326     static_cast<JoinerRouter *>(aContext)->HandleJoinerEntrustResponse(AsCoapMessagePtr(aMessage),
327                                                                        AsCoreTypePtr(aMessageInfo), aResult);
328 }
329 
HandleJoinerEntrustResponse(Coap::Message * aMessage,const Ip6::MessageInfo * aMessageInfo,Error aResult)330 void JoinerRouter::HandleJoinerEntrustResponse(Coap::Message          *aMessage,
331                                                const Ip6::MessageInfo *aMessageInfo,
332                                                Error                   aResult)
333 {
334     OT_UNUSED_VARIABLE(aMessageInfo);
335 
336     SendDelayedJoinerEntrust();
337 
338     VerifyOrExit(aResult == kErrorNone && aMessage != nullptr);
339 
340     VerifyOrExit(aMessage->GetCode() == Coap::kCodeChanged);
341 
342     LogInfo("Receive %s response", UriToString<kUriJoinerEntrust>());
343     LogCert("[THCI] direction=recv | type=JOIN_ENT.rsp");
344 
345 exit:
346     return;
347 }
348 
ReadFrom(const Message & aMessage)349 void JoinerRouter::JoinerEntrustMetadata::ReadFrom(const Message &aMessage)
350 {
351     uint16_t length = aMessage.GetLength();
352 
353     OT_ASSERT(length >= sizeof(*this));
354     IgnoreError(aMessage.Read(length - sizeof(*this), *this));
355 }
356 
357 } // namespace MeshCoP
358 } // namespace ot
359 
360 #endif // OPENTHREAD_FTD
361