//go:generate goderive . // // // Copyright (c) 2017 anygone contributors (see AUTHORS file) // All rights reserved. // // Redistribution and use in source and binary forms, with or without // modification, are permitted provided that the following conditions are met: // // * Redistributions of source code must retain the above copyright notice, this // list of conditions and the following disclaimer. // // * Redistributions in binary form must reproduce the above copyright notice, // this list of conditions and the following disclaimer in the documentation // and/or other materials provided with the distribution. // // * Neither the name of anygone nor the names of its // contributors may be used to endorse or promote products derived from // this software without specific prior written permission. // // THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" // AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE // IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE // DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE // FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL // DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR // SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER // CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, // OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE // OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. // package satp import ( "fmt" "net" "sync" "sync/atomic" "unsafe" ) func EndpointsEqual(this, that *net.UDPAddr) bool { return deriveEqual(this, that) } type SecurityAssociation struct { kd KeyDerivation endpoints []*net.UDPAddr nextSeqNr uint32 initialSeqNrInbound uint32 seqWindowSize uint seqWindows *sync.Map } func (sa *SecurityAssociation) KeyGenerate(dir Direction, usage KeyUsage, sequenceNumber uint32, out []byte) error { return sa.kd.Generate(dir, usage, sequenceNumber, out) } func (sa *SecurityAssociation) EndpointUpdate(idx uint, ep *net.UDPAddr) { if idx >= uint(len(sa.endpoints)) { return // panic??? } atomic.StorePointer((*unsafe.Pointer)(unsafe.Pointer(&(sa.endpoints[idx]))), unsafe.Pointer(ep)) } func (sa *SecurityAssociation) EndpointCompareAndUpdate(idx uint, ep *net.UDPAddr) bool { if idx >= uint(len(sa.endpoints)) { return false // panic??? } old := (*net.UDPAddr)(atomic.LoadPointer((*unsafe.Pointer)(unsafe.Pointer(&(sa.endpoints[idx]))))) if !EndpointsEqual(old, ep) { atomic.StorePointer((*unsafe.Pointer)(unsafe.Pointer(&(sa.endpoints[idx]))), unsafe.Pointer(ep)) return true } return false } func (sa *SecurityAssociation) GetEndpointsAndNextSequenceNumber(epsIn []*net.UDPAddr) (seqNum uint32, eps []*net.UDPAddr) { seqNum = atomic.AddUint32(&sa.nextSeqNr, 1) - 1 eps = epsIn if eps == nil { eps = make([]*net.UDPAddr, len(sa.endpoints)) } for i := range sa.endpoints { eps[i] = (*net.UDPAddr)(atomic.LoadPointer((*unsafe.Pointer)(unsafe.Pointer(&(sa.endpoints[i]))))) } return } func (sa *SecurityAssociation) getSequenceWindow(senderID uint16) *SequenceWindow { win, present := sa.seqWindows.Load(senderID) if !present { var err error if win, err = NewSequenceWindow(int(sa.seqWindowSize), sa.initialSeqNrInbound); err != nil { panic(fmt.Sprint("unable to create new sequence window:", err)) // return an error instead??? } sa.seqWindows.Store(senderID, win) } return win.(*SequenceWindow) } func (sa *SecurityAssociation) SequenceNumberCheck(senderID uint16, sequenceNumber uint32) bool { return sa.getSequenceWindow(senderID).Check(sequenceNumber) } func (sa *SecurityAssociation) SequenceNumberCheckAndSet(senderID uint16, sequenceNumber uint32) bool { return sa.getSequenceWindow(senderID).CheckAndSet(sequenceNumber) } func NewSecurityAssociation(kd KeyDerivation, numEndpoints uint, initialSeqNrOutbound, initialSeqNrInbound uint32, seqWindowSize uint) (sa *SecurityAssociation) { sa = &SecurityAssociation{kd: kd} // panic if numEndpoints == 0? sa.endpoints = make([]*net.UDPAddr, numEndpoints) sa.nextSeqNr = initialSeqNrOutbound sa.initialSeqNrInbound = initialSeqNrInbound sa.seqWindowSize = seqWindowSize sa.seqWindows = &sync.Map{} return }