blob: 5eff3c932b3dd8f5454e0c45ca21d990bf07bf7e [file] [log] [blame]
zstein398c3fd2017-07-19 13:38:02 -07001/*
2 * Copyright 2017 The WebRTC project authors. All Rights Reserved.
3 *
4 * Use of this source code is governed by a BSD-style license
5 * that can be found in the LICENSE file in the root of the source
6 * tree. An additional intellectual property rights grant can be found
7 * in the file PATENTS. All contributing project authors may
8 * be found in the AUTHORS file in the root of the source tree.
9 */
10
Mirko Bonadei92ea95e2017-09-15 06:47:31 +020011#include "pc/srtptransport.h"
zstein398c3fd2017-07-19 13:38:02 -070012
13#include <string>
Steve Anton36b29d12017-10-30 09:57:42 -070014#include <vector>
zstein398c3fd2017-07-19 13:38:02 -070015
Mirko Bonadei92ea95e2017-09-15 06:47:31 +020016#include "media/base/rtputils.h"
17#include "pc/rtptransport.h"
18#include "pc/srtpsession.h"
19#include "rtc_base/asyncpacketsocket.h"
Zhi Huangcf990f52017-09-22 12:12:30 -070020#include "rtc_base/base64.h"
Mirko Bonadei92ea95e2017-09-15 06:47:31 +020021#include "rtc_base/copyonwritebuffer.h"
22#include "rtc_base/ptr_util.h"
23#include "rtc_base/trace_event.h"
zstein398c3fd2017-07-19 13:38:02 -070024
25namespace webrtc {
26
Zhi Huang2dfc42d2017-12-04 13:38:48 -080027SrtpTransport::SrtpTransport(bool rtcp_mux_enabled)
Zhi Huang95e7dbb2018-03-29 00:08:03 +000028 : RtpTransportInternalAdapter(new RtpTransport(rtcp_mux_enabled)) {
29 // Own the raw pointer |transport| from the base class.
30 rtp_transport_.reset(transport_);
31 RTC_DCHECK(rtp_transport_);
32 ConnectToRtpTransport();
33}
34
35SrtpTransport::SrtpTransport(
36 std::unique_ptr<RtpTransportInternal> rtp_transport)
37 : RtpTransportInternalAdapter(rtp_transport.get()),
38 rtp_transport_(std::move(rtp_transport)) {
39 RTC_DCHECK(rtp_transport_);
40 ConnectToRtpTransport();
41}
42
43void SrtpTransport::ConnectToRtpTransport() {
44 rtp_transport_->SignalPacketReceived.connect(
45 this, &SrtpTransport::OnPacketReceived);
46 rtp_transport_->SignalReadyToSend.connect(this,
47 &SrtpTransport::OnReadyToSend);
48 rtp_transport_->SignalNetworkRouteChanged.connect(
49 this, &SrtpTransport::OnNetworkRouteChanged);
50 rtp_transport_->SignalWritableState.connect(this,
51 &SrtpTransport::OnWritableState);
52 rtp_transport_->SignalSentPacket.connect(this, &SrtpTransport::OnSentPacket);
53}
zstein398c3fd2017-07-19 13:38:02 -070054
Zhi Huangcf990f52017-09-22 12:12:30 -070055bool SrtpTransport::SendRtpPacket(rtc::CopyOnWriteBuffer* packet,
56 const rtc::PacketOptions& options,
57 int flags) {
Zhi Huang95e7dbb2018-03-29 00:08:03 +000058 return SendPacket(false, packet, options, flags);
59}
60
61bool SrtpTransport::SendRtcpPacket(rtc::CopyOnWriteBuffer* packet,
62 const rtc::PacketOptions& options,
63 int flags) {
64 return SendPacket(true, packet, options, flags);
65}
66
67bool SrtpTransport::SendPacket(bool rtcp,
68 rtc::CopyOnWriteBuffer* packet,
69 const rtc::PacketOptions& options,
70 int flags) {
Zhi Huangcf990f52017-09-22 12:12:30 -070071 if (!IsActive()) {
Mirko Bonadei675513b2017-11-09 11:09:25 +010072 RTC_LOG(LS_ERROR)
Zhi Huangcf990f52017-09-22 12:12:30 -070073 << "Failed to send the packet because SRTP transport is inactive.";
74 return false;
75 }
Zhi Huang95e7dbb2018-03-29 00:08:03 +000076
Zhi Huangcf990f52017-09-22 12:12:30 -070077 rtc::PacketOptions updated_options = options;
Zhi Huang95e7dbb2018-03-29 00:08:03 +000078 rtc::CopyOnWriteBuffer cp = *packet;
Zhi Huangcf990f52017-09-22 12:12:30 -070079 TRACE_EVENT0("webrtc", "SRTP Encode");
80 bool res;
81 uint8_t* data = packet->data();
82 int len = static_cast<int>(packet->size());
Zhi Huang95e7dbb2018-03-29 00:08:03 +000083 if (!rtcp) {
Zhi Huangcf990f52017-09-22 12:12:30 -070084// If ENABLE_EXTERNAL_AUTH flag is on then packet authentication is not done
85// inside libsrtp for a RTP packet. A external HMAC module will be writing
86// a fake HMAC value. This is ONLY done for a RTP packet.
87// Socket layer will update rtp sendtime extension header if present in
88// packet with current time before updating the HMAC.
89#if !defined(ENABLE_EXTERNAL_AUTH)
Zhi Huang27f3bf52018-03-26 21:37:23 -070090 res = ProtectRtp(data, len, static_cast<int>(packet->capacity()), &len);
Zhi Huang95e7dbb2018-03-29 00:08:03 +000091#else
92 if (!IsExternalAuthActive()) {
93 res = ProtectRtp(data, len, static_cast<int>(packet->capacity()), &len);
94 } else {
95 updated_options.packet_time_params.rtp_sendtime_extension_id =
96 rtp_abs_sendtime_extn_id_;
97 res = ProtectRtp(data, len, static_cast<int>(packet->capacity()), &len,
98 &updated_options.packet_time_params.srtp_packet_index);
99 // If protection succeeds, let's get auth params from srtp.
Zhi Huangcf990f52017-09-22 12:12:30 -0700100 if (res) {
Zhi Huang95e7dbb2018-03-29 00:08:03 +0000101 uint8_t* auth_key = NULL;
102 int key_len;
103 res = GetRtpAuthParams(
104 &auth_key, &key_len,
105 &updated_options.packet_time_params.srtp_auth_tag_len);
106 if (res) {
107 updated_options.packet_time_params.srtp_auth_key.resize(key_len);
108 updated_options.packet_time_params.srtp_auth_key.assign(
109 auth_key, auth_key + key_len);
110 }
Zhi Huangcf990f52017-09-22 12:12:30 -0700111 }
112 }
113#endif
Zhi Huang95e7dbb2018-03-29 00:08:03 +0000114 if (!res) {
115 int seq_num = -1;
116 uint32_t ssrc = 0;
117 cricket::GetRtpSeqNum(data, len, &seq_num);
118 cricket::GetRtpSsrc(data, len, &ssrc);
119 RTC_LOG(LS_ERROR) << "Failed to protect RTP packet: size=" << len
120 << ", seqnum=" << seq_num << ", SSRC=" << ssrc;
121 return false;
122 }
123 } else {
124 res = ProtectRtcp(data, len, static_cast<int>(packet->capacity()), &len);
125 if (!res) {
126 int type = -1;
127 cricket::GetRtcpType(data, len, &type);
128 RTC_LOG(LS_ERROR) << "Failed to protect RTCP packet: size=" << len
129 << ", type=" << type;
130 return false;
131 }
Zhi Huangcf990f52017-09-22 12:12:30 -0700132 }
133
134 // Update the length of the packet now that we've added the auth tag.
135 packet->SetSize(len);
Zhi Huang95e7dbb2018-03-29 00:08:03 +0000136 return rtcp ? rtp_transport_->SendRtcpPacket(packet, updated_options, flags)
137 : rtp_transport_->SendRtpPacket(packet, updated_options, flags);
zstein398c3fd2017-07-19 13:38:02 -0700138}
139
Zhi Huang95e7dbb2018-03-29 00:08:03 +0000140void SrtpTransport::OnPacketReceived(bool rtcp,
141 rtc::CopyOnWriteBuffer* packet,
142 const rtc::PacketTime& packet_time) {
Zhi Huang27f3bf52018-03-26 21:37:23 -0700143 if (!IsActive()) {
144 RTC_LOG(LS_WARNING)
Zhi Huang95e7dbb2018-03-29 00:08:03 +0000145 << "Inactive SRTP transport received a packet. Drop it.";
Zhi Huang27f3bf52018-03-26 21:37:23 -0700146 return;
147 }
Zhi Huang95e7dbb2018-03-29 00:08:03 +0000148
Zhi Huangcf990f52017-09-22 12:12:30 -0700149 TRACE_EVENT0("webrtc", "SRTP Decode");
150 char* data = packet->data<char>();
151 int len = static_cast<int>(packet->size());
Zhi Huang95e7dbb2018-03-29 00:08:03 +0000152 bool res;
153 if (!rtcp) {
154 res = UnprotectRtp(data, len, &len);
155 if (!res) {
156 int seq_num = -1;
157 uint32_t ssrc = 0;
158 cricket::GetRtpSeqNum(data, len, &seq_num);
159 cricket::GetRtpSsrc(data, len, &ssrc);
160 RTC_LOG(LS_ERROR) << "Failed to unprotect RTP packet: size=" << len
161 << ", seqnum=" << seq_num << ", SSRC=" << ssrc;
162 return;
163 }
164 } else {
165 res = UnprotectRtcp(data, len, &len);
166 if (!res) {
167 int type = -1;
168 cricket::GetRtcpType(data, len, &type);
169 RTC_LOG(LS_ERROR) << "Failed to unprotect RTCP packet: size=" << len
170 << ", type=" << type;
171 return;
172 }
Zhi Huangcf990f52017-09-22 12:12:30 -0700173 }
Zhi Huang27f3bf52018-03-26 21:37:23 -0700174
Zhi Huang27f3bf52018-03-26 21:37:23 -0700175 packet->SetSize(len);
Zhi Huang95e7dbb2018-03-29 00:08:03 +0000176 SignalPacketReceived(rtcp, packet, packet_time);
zstein398c3fd2017-07-19 13:38:02 -0700177}
178
Zhi Huang942bc2e2017-11-13 13:26:07 -0800179void SrtpTransport::OnNetworkRouteChanged(
Zhi Huang942bc2e2017-11-13 13:26:07 -0800180 rtc::Optional<rtc::NetworkRoute> network_route) {
181 // Only append the SRTP overhead when there is a selected network route.
182 if (network_route) {
183 int srtp_overhead = 0;
184 if (IsActive()) {
185 GetSrtpOverhead(&srtp_overhead);
186 }
187 network_route->packet_overhead += srtp_overhead;
188 }
189 SignalNetworkRouteChanged(network_route);
190}
191
Zhi Huangcf990f52017-09-22 12:12:30 -0700192bool SrtpTransport::SetRtpParams(int send_cs,
193 const uint8_t* send_key,
194 int send_key_len,
Zhi Huangc99b6c72017-11-10 16:44:46 -0800195 const std::vector<int>& send_extension_ids,
Zhi Huangcf990f52017-09-22 12:12:30 -0700196 int recv_cs,
197 const uint8_t* recv_key,
Zhi Huangc99b6c72017-11-10 16:44:46 -0800198 int recv_key_len,
199 const std::vector<int>& recv_extension_ids) {
Zhi Huangcf990f52017-09-22 12:12:30 -0700200 // If parameters are being set for the first time, we should create new SRTP
201 // sessions and call "SetSend/SetRecv". Otherwise we should call
202 // "UpdateSend"/"UpdateRecv" on the existing sessions, which will internally
203 // call "srtp_update".
204 bool new_sessions = false;
205 if (!send_session_) {
206 RTC_DCHECK(!recv_session_);
207 CreateSrtpSessions();
208 new_sessions = true;
209 }
Zhi Huangcf990f52017-09-22 12:12:30 -0700210 bool ret = new_sessions
Zhi Huangc99b6c72017-11-10 16:44:46 -0800211 ? send_session_->SetSend(send_cs, send_key, send_key_len,
212 send_extension_ids)
213 : send_session_->UpdateSend(send_cs, send_key, send_key_len,
214 send_extension_ids);
Zhi Huangcf990f52017-09-22 12:12:30 -0700215 if (!ret) {
216 ResetParams();
217 return false;
218 }
219
Zhi Huangc99b6c72017-11-10 16:44:46 -0800220 ret = new_sessions ? recv_session_->SetRecv(recv_cs, recv_key, recv_key_len,
221 recv_extension_ids)
222 : recv_session_->UpdateRecv(
223 recv_cs, recv_key, recv_key_len, recv_extension_ids);
Zhi Huangcf990f52017-09-22 12:12:30 -0700224 if (!ret) {
225 ResetParams();
226 return false;
227 }
228
Mirko Bonadei675513b2017-11-09 11:09:25 +0100229 RTC_LOG(LS_INFO) << "SRTP " << (new_sessions ? "activated" : "updated")
Jonas Olsson45cc8902018-02-13 10:37:07 +0100230 << " with negotiated parameters: send cipher_suite "
231 << send_cs << " recv cipher_suite " << recv_cs;
Zhi Huangcf990f52017-09-22 12:12:30 -0700232 return true;
233}
234
235bool SrtpTransport::SetRtcpParams(int send_cs,
236 const uint8_t* send_key,
237 int send_key_len,
Zhi Huangc99b6c72017-11-10 16:44:46 -0800238 const std::vector<int>& send_extension_ids,
Zhi Huangcf990f52017-09-22 12:12:30 -0700239 int recv_cs,
240 const uint8_t* recv_key,
Zhi Huangc99b6c72017-11-10 16:44:46 -0800241 int recv_key_len,
242 const std::vector<int>& recv_extension_ids) {
Zhi Huangcf990f52017-09-22 12:12:30 -0700243 // This can only be called once, but can be safely called after
244 // SetRtpParams
245 if (send_rtcp_session_ || recv_rtcp_session_) {
Mirko Bonadei675513b2017-11-09 11:09:25 +0100246 RTC_LOG(LS_ERROR) << "Tried to set SRTCP Params when filter already active";
Zhi Huangcf990f52017-09-22 12:12:30 -0700247 return false;
248 }
249
250 send_rtcp_session_.reset(new cricket::SrtpSession());
Zhi Huangc99b6c72017-11-10 16:44:46 -0800251 if (!send_rtcp_session_->SetSend(send_cs, send_key, send_key_len,
252 send_extension_ids)) {
Zhi Huangcf990f52017-09-22 12:12:30 -0700253 return false;
254 }
255
256 recv_rtcp_session_.reset(new cricket::SrtpSession());
Zhi Huangc99b6c72017-11-10 16:44:46 -0800257 if (!recv_rtcp_session_->SetRecv(recv_cs, recv_key, recv_key_len,
258 recv_extension_ids)) {
Zhi Huangcf990f52017-09-22 12:12:30 -0700259 return false;
260 }
261
Steve Antondb67ba12018-03-19 17:41:42 -0700262 if (metrics_observer_) {
263 send_rtcp_session_->SetMetricsObserver(metrics_observer_);
264 recv_rtcp_session_->SetMetricsObserver(metrics_observer_);
265 }
266
Mirko Bonadei675513b2017-11-09 11:09:25 +0100267 RTC_LOG(LS_INFO) << "SRTCP activated with negotiated parameters:"
Jonas Olsson45cc8902018-02-13 10:37:07 +0100268 " send cipher_suite "
269 << send_cs << " recv cipher_suite " << recv_cs;
Zhi Huangcf990f52017-09-22 12:12:30 -0700270
271 return true;
272}
273
274bool SrtpTransport::IsActive() const {
275 return send_session_ && recv_session_;
276}
277
278void SrtpTransport::ResetParams() {
279 send_session_ = nullptr;
280 recv_session_ = nullptr;
281 send_rtcp_session_ = nullptr;
282 recv_rtcp_session_ = nullptr;
Mirko Bonadei675513b2017-11-09 11:09:25 +0100283 RTC_LOG(LS_INFO) << "The params in SRTP transport are reset.";
Zhi Huangcf990f52017-09-22 12:12:30 -0700284}
285
Zhi Huangcf990f52017-09-22 12:12:30 -0700286void SrtpTransport::CreateSrtpSessions() {
287 send_session_.reset(new cricket::SrtpSession());
288 recv_session_.reset(new cricket::SrtpSession());
Steve Antondb67ba12018-03-19 17:41:42 -0700289 if (metrics_observer_) {
290 send_session_->SetMetricsObserver(metrics_observer_);
291 recv_session_->SetMetricsObserver(metrics_observer_);
292 }
Zhi Huangcf990f52017-09-22 12:12:30 -0700293
294 if (external_auth_enabled_) {
295 send_session_->EnableExternalAuth();
296 }
297}
298
299bool SrtpTransport::ProtectRtp(void* p, int in_len, int max_len, int* out_len) {
300 if (!IsActive()) {
Mirko Bonadei675513b2017-11-09 11:09:25 +0100301 RTC_LOG(LS_WARNING) << "Failed to ProtectRtp: SRTP not active";
Zhi Huangcf990f52017-09-22 12:12:30 -0700302 return false;
303 }
304 RTC_CHECK(send_session_);
305 return send_session_->ProtectRtp(p, in_len, max_len, out_len);
306}
307
308bool SrtpTransport::ProtectRtp(void* p,
309 int in_len,
310 int max_len,
311 int* out_len,
312 int64_t* index) {
313 if (!IsActive()) {
Mirko Bonadei675513b2017-11-09 11:09:25 +0100314 RTC_LOG(LS_WARNING) << "Failed to ProtectRtp: SRTP not active";
Zhi Huangcf990f52017-09-22 12:12:30 -0700315 return false;
316 }
317 RTC_CHECK(send_session_);
318 return send_session_->ProtectRtp(p, in_len, max_len, out_len, index);
319}
320
321bool SrtpTransport::ProtectRtcp(void* p,
322 int in_len,
323 int max_len,
324 int* out_len) {
325 if (!IsActive()) {
Mirko Bonadei675513b2017-11-09 11:09:25 +0100326 RTC_LOG(LS_WARNING) << "Failed to ProtectRtcp: SRTP not active";
Zhi Huangcf990f52017-09-22 12:12:30 -0700327 return false;
328 }
329 if (send_rtcp_session_) {
330 return send_rtcp_session_->ProtectRtcp(p, in_len, max_len, out_len);
331 } else {
332 RTC_CHECK(send_session_);
333 return send_session_->ProtectRtcp(p, in_len, max_len, out_len);
334 }
335}
336
337bool SrtpTransport::UnprotectRtp(void* p, int in_len, int* out_len) {
338 if (!IsActive()) {
Mirko Bonadei675513b2017-11-09 11:09:25 +0100339 RTC_LOG(LS_WARNING) << "Failed to UnprotectRtp: SRTP not active";
Zhi Huangcf990f52017-09-22 12:12:30 -0700340 return false;
341 }
342 RTC_CHECK(recv_session_);
343 return recv_session_->UnprotectRtp(p, in_len, out_len);
344}
345
346bool SrtpTransport::UnprotectRtcp(void* p, int in_len, int* out_len) {
347 if (!IsActive()) {
Mirko Bonadei675513b2017-11-09 11:09:25 +0100348 RTC_LOG(LS_WARNING) << "Failed to UnprotectRtcp: SRTP not active";
Zhi Huangcf990f52017-09-22 12:12:30 -0700349 return false;
350 }
351 if (recv_rtcp_session_) {
352 return recv_rtcp_session_->UnprotectRtcp(p, in_len, out_len);
353 } else {
354 RTC_CHECK(recv_session_);
355 return recv_session_->UnprotectRtcp(p, in_len, out_len);
356 }
357}
358
359bool SrtpTransport::GetRtpAuthParams(uint8_t** key,
360 int* key_len,
361 int* tag_len) {
362 if (!IsActive()) {
Mirko Bonadei675513b2017-11-09 11:09:25 +0100363 RTC_LOG(LS_WARNING) << "Failed to GetRtpAuthParams: SRTP not active";
Zhi Huangcf990f52017-09-22 12:12:30 -0700364 return false;
365 }
366
367 RTC_CHECK(send_session_);
368 return send_session_->GetRtpAuthParams(key, key_len, tag_len);
369}
370
371bool SrtpTransport::GetSrtpOverhead(int* srtp_overhead) const {
372 if (!IsActive()) {
Mirko Bonadei675513b2017-11-09 11:09:25 +0100373 RTC_LOG(LS_WARNING) << "Failed to GetSrtpOverhead: SRTP not active";
Zhi Huangcf990f52017-09-22 12:12:30 -0700374 return false;
375 }
376
377 RTC_CHECK(send_session_);
378 *srtp_overhead = send_session_->GetSrtpOverhead();
379 return true;
380}
381
382void SrtpTransport::EnableExternalAuth() {
383 RTC_DCHECK(!IsActive());
384 external_auth_enabled_ = true;
385}
386
387bool SrtpTransport::IsExternalAuthEnabled() const {
388 return external_auth_enabled_;
389}
390
391bool SrtpTransport::IsExternalAuthActive() const {
392 if (!IsActive()) {
Mirko Bonadei675513b2017-11-09 11:09:25 +0100393 RTC_LOG(LS_WARNING)
394 << "Failed to check IsExternalAuthActive: SRTP not active";
Zhi Huangcf990f52017-09-22 12:12:30 -0700395 return false;
396 }
397
398 RTC_CHECK(send_session_);
399 return send_session_->IsExternalAuthActive();
400}
401
Steve Antondb67ba12018-03-19 17:41:42 -0700402void SrtpTransport::SetMetricsObserver(
403 rtc::scoped_refptr<MetricsObserverInterface> metrics_observer) {
404 metrics_observer_ = metrics_observer;
405 if (send_session_) {
406 send_session_->SetMetricsObserver(metrics_observer_);
407 }
408 if (recv_session_) {
409 recv_session_->SetMetricsObserver(metrics_observer_);
410 }
411 if (send_rtcp_session_) {
412 send_rtcp_session_->SetMetricsObserver(metrics_observer_);
413 }
414 if (recv_rtcp_session_) {
415 recv_rtcp_session_->SetMetricsObserver(metrics_observer_);
416 }
Zhi Huang95e7dbb2018-03-29 00:08:03 +0000417 rtp_transport_->SetMetricsObserver(metrics_observer);
Steve Antondb67ba12018-03-19 17:41:42 -0700418}
419
zstein398c3fd2017-07-19 13:38:02 -0700420} // namespace webrtc