summaryrefslogtreecommitdiff
path: root/satp/security-association.go
blob: efe581e1e7cde208497a2df7094c687ca21c7af6 (plain) (blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
//go:generate goderive .
//
//
// Copyright (c) 2017 anygone contributors (see AUTHORS file)
// All rights reserved.
//
// Redistribution and use in source and binary forms, with or without
// modification, are permitted provided that the following conditions are met:
//
// * Redistributions of source code must retain the above copyright notice, this
//   list of conditions and the following disclaimer.
//
// * Redistributions in binary form must reproduce the above copyright notice,
//   this list of conditions and the following disclaimer in the documentation
//   and/or other materials provided with the distribution.
//
// * Neither the name of anygone nor the names of its
//   contributors may be used to endorse or promote products derived from
//   this software without specific prior written permission.
//
// THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS"
// AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
// IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE
// DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE
// FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
// DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR
// SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER
// CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY,
// OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE
// OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
//

package satp

import (
	"fmt"
	"net"
	"sync"
	"sync/atomic"
	"unsafe"
)

func EndpointsEqual(this, that *net.UDPAddr) bool {
	return deriveEqual(this, that)
}

type SecurityAssociation struct {
	kd                  KeyDerivation
	endpoints           []*net.UDPAddr
	nextSeqNr           uint32
	initialSeqNrInbound uint32
	seqWindowSize       uint
	seqWindows          *sync.Map
}

func (sa *SecurityAssociation) KeyGenerate(dir Direction, usage KeyUsage, sequenceNumber uint32, out []byte) error {
	return sa.kd.Generate(dir, usage, sequenceNumber, out)
}

func (sa *SecurityAssociation) EndpointUpdate(idx uint, ep *net.UDPAddr) {
	if idx >= uint(len(sa.endpoints)) {
		return // panic???
	}
	atomic.StorePointer((*unsafe.Pointer)(unsafe.Pointer(&(sa.endpoints[idx]))), unsafe.Pointer(ep))
}

func (sa *SecurityAssociation) EndpointCompareAndUpdate(idx uint, ep *net.UDPAddr) bool {
	if idx >= uint(len(sa.endpoints)) {
		return false // panic???
	}
	old := (*net.UDPAddr)(atomic.LoadPointer((*unsafe.Pointer)(unsafe.Pointer(&(sa.endpoints[idx])))))
	if !EndpointsEqual(old, ep) {
		atomic.StorePointer((*unsafe.Pointer)(unsafe.Pointer(&(sa.endpoints[idx]))), unsafe.Pointer(ep))
		return true
	}
	return false
}

func (sa *SecurityAssociation) GetEndpointsAndNextSequenceNumber(epsIn []*net.UDPAddr) (seqNum uint32, eps []*net.UDPAddr) {
	seqNum = atomic.AddUint32(&sa.nextSeqNr, 1) - 1
	eps = epsIn
	if eps == nil {
		eps = make([]*net.UDPAddr, len(sa.endpoints))
	}
	for i := range sa.endpoints {
		eps[i] = (*net.UDPAddr)(atomic.LoadPointer((*unsafe.Pointer)(unsafe.Pointer(&(sa.endpoints[i])))))
	}
	return
}

func (sa *SecurityAssociation) getSequenceWindow(senderID uint16) *SequenceWindow {
	win, present := sa.seqWindows.Load(senderID)
	if !present {
		var err error
		if win, err = NewSequenceWindow(int(sa.seqWindowSize), sa.initialSeqNrInbound); err != nil {
			panic(fmt.Sprint("unable to create new sequence window:", err)) // return an error instead???
		}
		sa.seqWindows.Store(senderID, win)
	}
	return win.(*SequenceWindow)
}

func (sa *SecurityAssociation) SequenceNumberCheck(senderID uint16, sequenceNumber uint32) bool {
	return sa.getSequenceWindow(senderID).Check(sequenceNumber)
}

func (sa *SecurityAssociation) SequenceNumberCheckAndSet(senderID uint16, sequenceNumber uint32) bool {
	return sa.getSequenceWindow(senderID).CheckAndSet(sequenceNumber)
}

func NewSecurityAssociation(kd KeyDerivation, numEndpoints uint, initialSeqNrOutbound, initialSeqNrInbound uint32, seqWindowSize uint) (sa *SecurityAssociation) {
	sa = &SecurityAssociation{kd: kd}
	// panic if numEndpoints == 0?
	sa.endpoints = make([]*net.UDPAddr, numEndpoints)
	sa.nextSeqNr = initialSeqNrOutbound
	sa.initialSeqNrInbound = initialSeqNrInbound
	sa.seqWindowSize = seqWindowSize
	sa.seqWindows = &sync.Map{}
	return
}