mirror of
https://github.com/espressif/openthread.git
synced 2026-07-30 07:37:46 +00:00
[border-agent] introduce BorderAgent::EphemeralKeyManager (#11166)
This commit introduces the `BorderAgent::EphemeralKeyManager` class, which manages the use of the ephemeral key by the Border Agent. The `EphemeralKeyManager` uses its own DTLS transport and CoAP secure sessions. This allows the `EphemeralKeyManager` and the `BorderAgent` service (which uses PSKc) to be enabled and used in parallel. Previously, a single transport and session was shared between these functions, requiring the normal BA service (with PSKc) to be stopped before the ephemeral key could be used. This is a fundamental change and improvement to the ephemeral key and Border Agent functionality. Therefore some existing `otBorderAgent` APIs need to be modified. For example, `otBorderAgentGetState()`, which returned the Border Agent state to indicate whether there were any active sessions, is no longer meaningful, as different sessions/transports are now used for PSKc and ephemeral key, and there can be multiple sessions. This commit intentionally renames and changes the `otBorderAgent` public APIs, specifically all those related to ephemeral key use, to highlight the fundamental change in behavior. While this can cause backward incompatibility, it requires app layer code that used the previous APIs to be updated to take into account the new behavior. This commit also updates `nexus/test_border_agent`, adding new tests to validate the new behavior (e.g., BA service and ephemeral key parallel sessions). It also includes and validates the Border Agent counter updates under different scenarios (this enhances and replaces `test_ephemeral_key_counters.py`).
This commit is contained in:
@@ -181,12 +181,6 @@ expect ": InvalidState"
|
||||
send "ba port\n"
|
||||
expect "Done"
|
||||
|
||||
send "ba state\n"
|
||||
expect "Done"
|
||||
|
||||
send "ba disconnect\n"
|
||||
expect "Done"
|
||||
|
||||
send "prefix meshlocal fd00:dead:beef:cafe::/96\n"
|
||||
expect_line "Error 7: InvalidArgs"
|
||||
send "prefix meshlocal fd00:dead:beef:cafe::/64\n"
|
||||
|
||||
@@ -1,123 +0,0 @@
|
||||
#!/usr/bin/env python3
|
||||
#
|
||||
# Copyright (c) 2024, The OpenThread Authors.
|
||||
# All rights reserved.
|
||||
#
|
||||
# Redistribution and use in source and binary forms, with or without
|
||||
# modification, are permitted provided that the following conditions are met:
|
||||
# 1. Redistributions of source code must retain the above copyright
|
||||
# notice, this list of conditions and the following disclaimer.
|
||||
# 2. Redistributions in binary form must reproduce the above copyright
|
||||
# notice, this list of conditions and the following disclaimer in the
|
||||
# documentation and/or other materials provided with the distribution.
|
||||
# 3. Neither the name of the copyright holder nor the
|
||||
# names of its contributors may be used to endorse or promote products
|
||||
# derived from this software without specific prior written permission.
|
||||
#
|
||||
# THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS 'AS IS'
|
||||
# AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
|
||||
# IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
|
||||
# ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE
|
||||
# LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
|
||||
# CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
|
||||
# SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
|
||||
# INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
|
||||
# CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
|
||||
# ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
|
||||
# POSSIBILITY OF SUCH DAMAGE.
|
||||
#
|
||||
import logging
|
||||
import unittest
|
||||
|
||||
import config
|
||||
import thread_cert
|
||||
|
||||
# Test description:
|
||||
# This test verifies the counters of ephemeral key activations/deactivations.
|
||||
#
|
||||
# Topology:
|
||||
# --------------
|
||||
# |
|
||||
# BR1
|
||||
#
|
||||
|
||||
BR1 = 1
|
||||
|
||||
|
||||
class EphemeralKeyCountersTest(thread_cert.TestCase):
|
||||
USE_MESSAGE_FACTORY = False
|
||||
|
||||
TOPOLOGY = {
|
||||
BR1: {
|
||||
'name': 'BR_1',
|
||||
'is_otbr': True,
|
||||
'version': '1.4',
|
||||
'network_name': 'ot-br1',
|
||||
},
|
||||
}
|
||||
|
||||
def test(self):
|
||||
br1 = self.nodes[BR1]
|
||||
|
||||
counters = br1.get_border_agent_counters()
|
||||
self.assertEqual(counters['epskcActivation'], 0)
|
||||
self.assertEqual(counters['epskcApiDeactivation'], 0)
|
||||
self.assertEqual(counters['epskcTimeoutDeactivation'], 0)
|
||||
self.assertEqual(counters['epskcMaxAttemptDeactivation'], 0)
|
||||
self.assertEqual(counters['epskcDisconnectDeactivation'], 0)
|
||||
self.assertEqual(counters['epskcInvalidBaStateError'], 0)
|
||||
self.assertEqual(counters['epskcInvalidArgsError'], 0)
|
||||
self.assertEqual(counters['epskcStartSecureSessionError'], 0)
|
||||
self.assertEqual(counters['epskcSecureSessionSuccess'], 0)
|
||||
self.assertEqual(counters['epskcSecureSessionFailure'], 0)
|
||||
self.assertEqual(counters['epskcCommissionerPetition'], 0)
|
||||
self.assertEqual(counters['pskcSecureSessionSuccess'], 0)
|
||||
self.assertEqual(counters['pskcSecureSessionFailure'], 0)
|
||||
self.assertEqual(counters['pskcCommissionerPetition'], 0)
|
||||
self.assertEqual(counters['mgmtActiveGet'], 0)
|
||||
self.assertEqual(counters['mgmtPendingGet'], 0)
|
||||
|
||||
# activate epskc before border agent is up returns an error
|
||||
br1.set_epskc('123456789')
|
||||
|
||||
counters = br1.get_border_agent_counters()
|
||||
self.assertEqual(counters['epskcActivation'], 0)
|
||||
self.assertEqual(counters['epskcInvalidBaStateError'], 1)
|
||||
|
||||
br1.set_active_dataset(updateExisting=True, network_name='ot-br1')
|
||||
br1.start()
|
||||
self.simulator.go(config.BORDER_ROUTER_STARTUP_DELAY)
|
||||
self.assertEqual('leader', br1.get_state())
|
||||
|
||||
# activate epskc and let it timeout
|
||||
br1.set_epskc('123456789', 10)
|
||||
self.simulator.go(1)
|
||||
|
||||
counters = br1.get_border_agent_counters()
|
||||
self.assertEqual(counters['epskcActivation'], 1)
|
||||
self.assertEqual(counters['epskcApiDeactivation'], 0)
|
||||
self.assertEqual(counters['epskcTimeoutDeactivation'], 1)
|
||||
|
||||
# activate epskc and clear it
|
||||
br1.set_epskc('123456789', 10000)
|
||||
self.simulator.go(1)
|
||||
br1.clear_epskc()
|
||||
|
||||
counters = br1.get_border_agent_counters()
|
||||
self.assertEqual(counters['epskcActivation'], 2)
|
||||
self.assertEqual(counters['epskcApiDeactivation'], 1)
|
||||
self.assertEqual(counters['epskcTimeoutDeactivation'], 1)
|
||||
|
||||
# set epskc with invalid passcode
|
||||
br1.set_epskc('123')
|
||||
self.simulator.go(1)
|
||||
|
||||
counters = br1.get_border_agent_counters()
|
||||
self.assertEqual(counters['epskcActivation'], 2)
|
||||
self.assertEqual(counters['epskcApiDeactivation'], 1)
|
||||
self.assertEqual(counters['epskcTimeoutDeactivation'], 1)
|
||||
self.assertEqual(counters['epskcInvalidArgsError'], 1)
|
||||
|
||||
|
||||
if __name__ == '__main__':
|
||||
unittest.main()
|
||||
@@ -106,13 +106,13 @@ class PublishMeshCopService(thread_cert.TestCase):
|
||||
lifetime = 500_000
|
||||
ephemeral_key = br1.activate_ephemeral_key_mode(lifetime)
|
||||
self.assertEqual(len(ephemeral_key), 9)
|
||||
self.assertEqual(br1.get_ephemeral_key_state(), 'active')
|
||||
self.assertEqual(br1.get_ephemeral_key_state(), 'Started')
|
||||
# check Meshcop-e service
|
||||
self.check_meshcop_e_service(host, True)
|
||||
|
||||
# deactivate ePSKc mode in force
|
||||
br1.deactivate_ephemeral_key_mode(retain_active_session=False)
|
||||
self.assertEqual(br1.get_ephemeral_key_state(), 'inactive')
|
||||
self.assertEqual(br1.get_ephemeral_key_state(), 'Stopped')
|
||||
self.simulator.go(10)
|
||||
# check Meshcop-e service
|
||||
self.check_meshcop_e_service(host, False)
|
||||
@@ -121,13 +121,13 @@ class PublishMeshCopService(thread_cert.TestCase):
|
||||
lifetime = 0
|
||||
ephemeral_key = br1.activate_ephemeral_key_mode(lifetime)
|
||||
self.assertEqual(len(ephemeral_key), 9)
|
||||
self.assertEqual(br1.get_ephemeral_key_state(), 'active')
|
||||
self.assertEqual(br1.get_ephemeral_key_state(), 'Started')
|
||||
# check Meshcop-e service
|
||||
self.check_meshcop_e_service(host, True)
|
||||
|
||||
# deactivate ePSKc mode NOT in force
|
||||
br1.deactivate_ephemeral_key_mode(retain_active_session=True)
|
||||
self.assertEqual(br1.get_ephemeral_key_state(), 'inactive')
|
||||
self.assertEqual(br1.get_ephemeral_key_state(), 'Stopped')
|
||||
self.simulator.go(10)
|
||||
# check Meshcop-e service
|
||||
self.check_meshcop_e_service(host, False)
|
||||
|
||||
@@ -1456,16 +1456,6 @@ class NodeImpl:
|
||||
self.send_command(cmd)
|
||||
return int(self._expect_command_output()[0])
|
||||
|
||||
def set_epskc(self, keystring: str, timeout=120000, port=0):
|
||||
cmd = 'ba ephemeralkey set ' + keystring + ' ' + str(timeout) + ' ' + str(port)
|
||||
self.send_command(cmd)
|
||||
self._expect(r"(Done|Error .*)")
|
||||
|
||||
def clear_epskc(self):
|
||||
cmd = 'ba ephemeralkey clear'
|
||||
self.send_command(cmd)
|
||||
self._expect_done()
|
||||
|
||||
def get_border_agent_counters(self):
|
||||
cmd = 'ba counters'
|
||||
self.send_command(cmd)
|
||||
@@ -1934,7 +1924,7 @@ class NodeImpl:
|
||||
|
||||
def get_ephemeral_key_state(self):
|
||||
cmd = 'ba ephemeralkey'
|
||||
states = [r'inactive', r'active']
|
||||
states = [r'Disabled', r'Stopped', r'Started', r'Connected', r'Accepted']
|
||||
self.send_command(cmd)
|
||||
return self._expect_result(states)
|
||||
|
||||
|
||||
Reference in New Issue
Block a user