blob: 74977476fca10cef105f3450613fec2c3d79ba0c [file] [log] [blame]
Tom Joseph4e57ada2016-08-10 06:51:12 -05001#include "message_parsers.hpp"
2
Tom Joseph4e57ada2016-08-10 06:51:12 -05003#include "endian.hpp"
4#include "main.hpp"
5#include "message.hpp"
6#include "sessions_manager.hpp"
7
Vernon Mauery9e801a22018-10-12 13:20:49 -07008#include <iostream>
9#include <memory>
10
Tom Joseph4e57ada2016-08-10 06:51:12 -050011namespace message
12{
13
14namespace parser
15{
16
Vernon Mauery9e801a22018-10-12 13:20:49 -070017std::tuple<std::unique_ptr<Message>, SessionHeader>
18 unflatten(std::vector<uint8_t>& inPacket)
Tom Joseph4e57ada2016-08-10 06:51:12 -050019{
20 // Check if the packet has atleast the size of the RMCP Header
21 if (inPacket.size() < sizeof(BasicHeader_t))
22 {
23 throw std::runtime_error("RMCP Header missing");
24 }
25
26 auto rmcpHeaderPtr = reinterpret_cast<BasicHeader_t*>(inPacket.data());
27
28 // Verify if the fields in the RMCP header conforms to the specification
29 if ((rmcpHeaderPtr->version != RMCP_VERSION) ||
30 (rmcpHeaderPtr->rmcpSeqNum != RMCP_SEQ) ||
31 (rmcpHeaderPtr->classOfMsg != RMCP_MESSAGE_CLASS_IPMI))
32 {
33 throw std::runtime_error("RMCP Header is invalid");
34 }
35
36 // Read the Session Header and invoke the parser corresponding to the
37 // header type
38 switch (static_cast<SessionHeader>(rmcpHeaderPtr->format.formatType))
39 {
40 case SessionHeader::IPMI15:
41 {
42 return std::make_tuple(ipmi15parser::unflatten(inPacket),
43 SessionHeader::IPMI15);
44 }
45 case SessionHeader::IPMI20:
46 {
47 return std::make_tuple(ipmi20parser::unflatten(inPacket),
48 SessionHeader::IPMI20);
49 }
50 default:
51 {
52 throw std::runtime_error("Invalid Session Header");
53 }
54 }
55}
56
Vernon Mauery9e801a22018-10-12 13:20:49 -070057std::vector<uint8_t> flatten(Message& outMessage, SessionHeader authType,
Tom Joseph4e57ada2016-08-10 06:51:12 -050058 session::Session& session)
59{
60 // Call the flatten routine based on the header type
61 switch (authType)
62 {
63 case SessionHeader::IPMI15:
64 {
65 return ipmi15parser::flatten(outMessage, session);
66 }
67 case SessionHeader::IPMI20:
68 {
69 return ipmi20parser::flatten(outMessage, session);
70 }
71 default:
72 {
73 return {};
74 }
75 }
76}
77
78} // namespace parser
79
80namespace ipmi15parser
81{
82
83std::unique_ptr<Message> unflatten(std::vector<uint8_t>& inPacket)
84{
85 // Check if the packet has atleast the Session Header
86 if (inPacket.size() < sizeof(SessionHeader_t))
87 {
88 throw std::runtime_error("IPMI1.5 Session Header Missing");
89 }
90
91 auto message = std::make_unique<Message>();
92
93 auto header = reinterpret_cast<SessionHeader_t*>(inPacket.data());
94
95 message->payloadType = PayloadType::IPMI;
Tom Joseph6a560762017-01-10 15:30:28 +053096 message->bmcSessionID = endian::from_ipmi(header->sessId);
97 message->sessionSeqNum = endian::from_ipmi(header->sessSeqNum);
Tom Joseph4e57ada2016-08-10 06:51:12 -050098 message->isPacketEncrypted = false;
99 message->isPacketAuthenticated = false;
100
101 auto payloadLen = header->payloadLength;
102
Vernon Mauery9e801a22018-10-12 13:20:49 -0700103 (message->payload)
104 .assign(inPacket.data() + sizeof(SessionHeader_t),
105 inPacket.data() + sizeof(SessionHeader_t) + payloadLen);
Tom Joseph4e57ada2016-08-10 06:51:12 -0500106
107 return message;
108}
109
110std::vector<uint8_t> flatten(Message& outMessage, session::Session& session)
111{
112 std::vector<uint8_t> packet(sizeof(SessionHeader_t));
113
114 // Insert Session Header into the Packet
115 auto header = reinterpret_cast<SessionHeader_t*>(packet.data());
116 header->base.version = parser::RMCP_VERSION;
117 header->base.reserved = 0x00;
118 header->base.rmcpSeqNum = parser::RMCP_SEQ;
119 header->base.classOfMsg = parser::RMCP_MESSAGE_CLASS_IPMI;
120 header->base.format.formatType =
121 static_cast<uint8_t>(parser::SessionHeader::IPMI15);
122 header->sessSeqNum = 0;
Tom Joseph6a560762017-01-10 15:30:28 +0530123 header->sessId = endian::to_ipmi(outMessage.rcSessionID);
Tom Joseph4e57ada2016-08-10 06:51:12 -0500124
125 header->payloadLength = static_cast<uint8_t>(outMessage.payload.size());
126
127 // Insert the Payload into the Packet
128 packet.insert(packet.end(), outMessage.payload.begin(),
129 outMessage.payload.end());
130
131 // Insert the Session Trailer
132 packet.resize(packet.size() + sizeof(SessionTrailer_t));
Vernon Mauery9e801a22018-10-12 13:20:49 -0700133 auto trailer =
134 reinterpret_cast<SessionTrailer_t*>(packet.data() + packet.size());
Tom Joseph4e57ada2016-08-10 06:51:12 -0500135 trailer->legacyPad = 0x00;
136
137 return packet;
138}
139
140} // namespace ipmi15parser
141
142namespace ipmi20parser
143{
144
145std::unique_ptr<Message> unflatten(std::vector<uint8_t>& inPacket)
146{
147 // Check if the packet has atleast the Session Header
148 if (inPacket.size() < sizeof(SessionHeader_t))
149 {
150 throw std::runtime_error("IPMI2.0 Session Header Missing");
151 }
152
153 auto message = std::make_unique<Message>();
154
155 auto header = reinterpret_cast<SessionHeader_t*>(inPacket.data());
156
Vernon Mauery9e801a22018-10-12 13:20:49 -0700157 message->payloadType = static_cast<PayloadType>(header->payloadType & 0x3F);
Tom Joseph6a560762017-01-10 15:30:28 +0530158 message->bmcSessionID = endian::from_ipmi(header->sessId);
159 message->sessionSeqNum = endian::from_ipmi(header->sessSeqNum);
Tom Joseph4e57ada2016-08-10 06:51:12 -0500160 message->isPacketEncrypted =
161 ((header->payloadType & PAYLOAD_ENCRYPT_MASK) ? true : false);
162 message->isPacketAuthenticated =
163 ((header->payloadType & PAYLOAD_AUTH_MASK) ? true : false);
164
Tom Joseph6a560762017-01-10 15:30:28 +0530165 auto payloadLen = endian::from_ipmi(header->payloadLength);
Tom Joseph4e57ada2016-08-10 06:51:12 -0500166
Tom Joseph5fa487c2017-01-20 12:42:39 +0530167 if (message->isPacketAuthenticated)
Tom Joseph64703f42017-01-10 17:03:48 +0530168 {
Vernon Mauery9e801a22018-10-12 13:20:49 -0700169 if (!(internal::verifyPacketIntegrity(inPacket, *(message.get()),
Tom Joseph027dfc22017-01-26 13:30:53 +0530170 payloadLen)))
Tom Joseph64703f42017-01-10 17:03:48 +0530171 {
172 throw std::runtime_error("Packet Integrity check failed");
173 }
174 }
175
Tom Joseph78478a82017-01-26 14:24:29 +0530176 // Decrypt the payload if the payload is encrypted
177 if (message->isPacketEncrypted)
178 {
179 // Assign the decrypted payload to the IPMI Message
Vernon Mauery9e801a22018-10-12 13:20:49 -0700180 message->payload =
181 internal::decryptPayload(inPacket, *(message.get()), payloadLen);
Tom Joseph78478a82017-01-26 14:24:29 +0530182 }
183 else
184 {
185 message->payload.assign(inPacket.begin() + sizeof(SessionHeader_t),
186 inPacket.begin() + sizeof(SessionHeader_t) +
Vernon Mauery9e801a22018-10-12 13:20:49 -0700187 payloadLen);
Tom Joseph78478a82017-01-26 14:24:29 +0530188 }
189
Tom Joseph4e57ada2016-08-10 06:51:12 -0500190 return message;
191}
192
193std::vector<uint8_t> flatten(Message& outMessage, session::Session& session)
194{
195 std::vector<uint8_t> packet(sizeof(SessionHeader_t));
196
197 SessionHeader_t* header = reinterpret_cast<SessionHeader_t*>(packet.data());
198 header->base.version = parser::RMCP_VERSION;
199 header->base.reserved = 0x00;
200 header->base.rmcpSeqNum = parser::RMCP_SEQ;
201 header->base.classOfMsg = parser::RMCP_MESSAGE_CLASS_IPMI;
202 header->base.format.formatType =
203 static_cast<uint8_t>(parser::SessionHeader::IPMI20);
204 header->payloadType = static_cast<uint8_t>(outMessage.payloadType);
Tom Joseph6a560762017-01-10 15:30:28 +0530205 header->sessId = endian::to_ipmi(outMessage.rcSessionID);
Tom Joseph4e57ada2016-08-10 06:51:12 -0500206
207 // Add session sequence number
208 internal::addSequenceNumber(packet, session);
209
Tom Joseph1404bca2017-01-26 14:17:02 +0530210 size_t payloadLen = 0;
211
Tom Joseph75362832017-01-26 15:17:04 +0530212 // Encrypt the payload if needed
213 if (outMessage.isPacketEncrypted)
214 {
215 header->payloadType |= PAYLOAD_ENCRYPT_MASK;
216 auto cipherPayload = internal::encryptPayload(outMessage);
217 payloadLen = cipherPayload.size();
218 header->payloadLength = endian::to_ipmi<uint16_t>(cipherPayload.size());
219
220 // Insert the encrypted payload into the outgoing IPMI packet
221 packet.insert(packet.end(), cipherPayload.begin(), cipherPayload.end());
222 }
223 else
224 {
Vernon Mauery9e801a22018-10-12 13:20:49 -0700225 header->payloadLength =
226 endian::to_ipmi<uint16_t>(outMessage.payload.size());
Tom Joseph75362832017-01-26 15:17:04 +0530227 payloadLen = outMessage.payload.size();
228
229 // Insert the Payload into the Packet
230 packet.insert(packet.end(), outMessage.payload.begin(),
231 outMessage.payload.end());
232 }
Tom Joseph4e57ada2016-08-10 06:51:12 -0500233
Tom Joseph5fa487c2017-01-20 12:42:39 +0530234 if (outMessage.isPacketAuthenticated)
Tom Joseph64703f42017-01-10 17:03:48 +0530235 {
Tom Joseph1404bca2017-01-26 14:17:02 +0530236 internal::addIntegrityData(packet, outMessage, payloadLen);
Tom Joseph64703f42017-01-10 17:03:48 +0530237 }
238
Tom Joseph4e57ada2016-08-10 06:51:12 -0500239 return packet;
240}
241
242namespace internal
243{
244
245void addSequenceNumber(std::vector<uint8_t>& packet, session::Session& session)
246{
247 SessionHeader_t* header = reinterpret_cast<SessionHeader_t*>(packet.data());
248
249 if (header->sessId == session::SESSION_ZERO)
250 {
251 header->sessSeqNum = 0x00;
252 }
253 else
254 {
255 auto seqNum = session.sequenceNums.increment();
Tom Joseph6a560762017-01-10 15:30:28 +0530256 header->sessSeqNum = endian::to_ipmi(seqNum);
Tom Joseph4e57ada2016-08-10 06:51:12 -0500257 }
258}
259
Tom Joseph64703f42017-01-10 17:03:48 +0530260bool verifyPacketIntegrity(const std::vector<uint8_t>& packet,
Vernon Mauery9e801a22018-10-12 13:20:49 -0700261 const Message& message, size_t payloadLen)
Tom Joseph64703f42017-01-10 17:03:48 +0530262{
Tom Joseph64703f42017-01-10 17:03:48 +0530263 /*
264 * Padding bytes are added to cause the number of bytes in the data range
265 * covered by the AuthCode(Integrity Data) field to be a multiple of 4 bytes
266 * .If present each integrity Pad byte is set to FFh. The following logic
267 * calculates the number of padding bytes added in the IPMI packet.
268 */
Tom Joseph5a2d3ce2017-02-01 20:18:37 +0530269 auto paddingLen = 4 - ((payloadLen + 2) & 3);
Tom Joseph64703f42017-01-10 17:03:48 +0530270
271 auto sessTrailerPos = sizeof(SessionHeader_t) + payloadLen + paddingLen;
272
Vernon Mauery9e801a22018-10-12 13:20:49 -0700273 auto trailer = reinterpret_cast<const SessionTrailer_t*>(packet.data() +
274 sessTrailerPos);
Tom Joseph64703f42017-01-10 17:03:48 +0530275
276 // Check trailer->padLength against paddingLen, both should match up,
277 // return false if the lengths don't match
Tom Joseph5fa487c2017-01-20 12:42:39 +0530278 if (trailer->padLength != paddingLen)
Tom Joseph64703f42017-01-10 17:03:48 +0530279 {
280 return false;
281 }
282
Vernon Maueryae1fda42018-10-15 12:55:34 -0700283 auto session = std::get<session::Manager&>(singletonPool)
284 .getSession(message.bmcSessionID);
Tom Joseph64703f42017-01-10 17:03:48 +0530285
286 auto integrityAlgo = session->getIntegrityAlgo();
287
288 // Check if Integrity data length is as expected, check integrity data
289 // length is same as the length expected for the Integrity Algorithm that
290 // was negotiated during the session open process.
Tom Joseph5fa487c2017-01-20 12:42:39 +0530291 if ((packet.size() - sessTrailerPos - sizeof(SessionTrailer_t)) !=
Vernon Mauery9e801a22018-10-12 13:20:49 -0700292 integrityAlgo->authCodeLength)
Tom Joseph64703f42017-01-10 17:03:48 +0530293 {
294 return false;
295 }
296
297 auto integrityIter = packet.cbegin();
298 std::advance(integrityIter, sessTrailerPos + sizeof(SessionTrailer_t));
299
300 // The integrity data is calculated from the AuthType/Format field up to and
301 // including the field that immediately precedes the AuthCode field itself.
302 size_t length = packet.size() - integrityAlgo->authCodeLength -
303 message::parser::RMCP_SESSION_HEADER_SIZE;
304
305 return integrityAlgo->verifyIntegrityData(packet, length, integrityIter);
306}
307
Vernon Mauery9e801a22018-10-12 13:20:49 -0700308void addIntegrityData(std::vector<uint8_t>& packet, const Message& message,
Tom Joseph1404bca2017-01-26 14:17:02 +0530309 size_t payloadLen)
Tom Joseph64703f42017-01-10 17:03:48 +0530310{
Tom Joseph64703f42017-01-10 17:03:48 +0530311 // The following logic calculates the number of padding bytes to be added to
312 // IPMI packet. If needed each integrity Pad byte is set to FFh.
Tom Joseph5a2d3ce2017-02-01 20:18:37 +0530313 auto paddingLen = 4 - ((payloadLen + 2) & 3);
Tom Joseph64703f42017-01-10 17:03:48 +0530314 packet.insert(packet.end(), paddingLen, 0xFF);
315
316 packet.resize(packet.size() + sizeof(SessionTrailer_t));
317
Vernon Mauery9e801a22018-10-12 13:20:49 -0700318 auto trailer = reinterpret_cast<SessionTrailer_t*>(
319 packet.data() + packet.size() - sizeof(SessionTrailer_t));
Tom Joseph64703f42017-01-10 17:03:48 +0530320
321 trailer->padLength = paddingLen;
322 trailer->nextHeader = parser::RMCP_MESSAGE_CLASS_IPMI;
323
Vernon Maueryae1fda42018-10-15 12:55:34 -0700324 auto session = std::get<session::Manager&>(singletonPool)
325 .getSession(message.bmcSessionID);
Tom Joseph64703f42017-01-10 17:03:48 +0530326
Vernon Mauery9e801a22018-10-12 13:20:49 -0700327 auto integrityData =
328 session->getIntegrityAlgo()->generateIntegrityData(packet);
Tom Joseph64703f42017-01-10 17:03:48 +0530329
330 packet.insert(packet.end(), integrityData.begin(), integrityData.end());
331}
332
Tom Joseph78478a82017-01-26 14:24:29 +0530333std::vector<uint8_t> decryptPayload(const std::vector<uint8_t>& packet,
Vernon Mauery9e801a22018-10-12 13:20:49 -0700334 const Message& message, size_t payloadLen)
Tom Joseph78478a82017-01-26 14:24:29 +0530335{
Vernon Maueryae1fda42018-10-15 12:55:34 -0700336 auto session = std::get<session::Manager&>(singletonPool)
337 .getSession(message.bmcSessionID);
Tom Joseph78478a82017-01-26 14:24:29 +0530338
Vernon Mauery9e801a22018-10-12 13:20:49 -0700339 return session->getCryptAlgo()->decryptPayload(
340 packet, sizeof(SessionHeader_t), payloadLen);
Tom Joseph78478a82017-01-26 14:24:29 +0530341}
342
Tom Joseph75362832017-01-26 15:17:04 +0530343std::vector<uint8_t> encryptPayload(Message& message)
344{
Vernon Maueryae1fda42018-10-15 12:55:34 -0700345 auto session = std::get<session::Manager&>(singletonPool)
346 .getSession(message.bmcSessionID);
Tom Joseph75362832017-01-26 15:17:04 +0530347
348 return session->getCryptAlgo()->encryptPayload(message.payload);
349}
350
Tom Joseph4e57ada2016-08-10 06:51:12 -0500351} // namespace internal
352
353} // namespace ipmi20parser
354
355} // namespace message