Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 1 | /* |
| 2 | * Copyright 2018 The WebRTC Project Authors. All rights reserved. |
| 3 | * |
| 4 | * Use of this source code is governed by a BSD-style license |
| 5 | * that can be found in the LICENSE file in the root of the source |
| 6 | * tree. An additional intellectual property rights grant can be found |
| 7 | * in the file PATENTS. All contributing project authors may |
| 8 | * be found in the AUTHORS file in the root of the source tree. |
| 9 | */ |
| 10 | |
Steve Anton | 10542f2 | 2019-01-11 17:11:00 | [diff] [blame] | 11 | #include "pc/jsep_transport.h" |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 12 | |
Yves Gerey | 3e70781 | 2018-11-28 15:47:49 | [diff] [blame] | 13 | #include <stddef.h> |
| 14 | #include <stdint.h> |
Jonas Olsson | a4d8737 | 2019-07-05 17:08:33 | [diff] [blame] | 15 | |
Mirko Bonadei | 96dca92 | 2021-07-10 20:37:40 | [diff] [blame] | 16 | #include <functional> |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 17 | #include <memory> |
Harald Alvestrand | c24a218 | 2022-02-23 13:44:59 | [diff] [blame] | 18 | #include <string> |
Mirko Bonadei | 96dca92 | 2021-07-10 20:37:40 | [diff] [blame] | 19 | #include <utility> |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 20 | |
Yves Gerey | 3e70781 | 2018-11-28 15:47:49 | [diff] [blame] | 21 | #include "api/array_view.h" |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 22 | #include "api/candidate.h" |
Steve Anton | 10542f2 | 2019-01-11 17:11:00 | [diff] [blame] | 23 | #include "p2p/base/p2p_constants.h" |
| 24 | #include "p2p/base/p2p_transport_channel.h" |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 25 | #include "rtc_base/checks.h" |
Steve Anton | 10542f2 | 2019-01-11 17:11:00 | [diff] [blame] | 26 | #include "rtc_base/copy_on_write_buffer.h" |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 27 | #include "rtc_base/logging.h" |
Zhi Huang | 365381f | 2018-04-13 23:44:34 | [diff] [blame] | 28 | #include "rtc_base/strings/string_builder.h" |
Markus Handell | 518669d | 2021-06-07 11:30:46 | [diff] [blame] | 29 | #include "rtc_base/trace_event.h" |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 30 | |
| 31 | using webrtc::SdpType; |
| 32 | |
| 33 | namespace cricket { |
| 34 | |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 35 | JsepTransportDescription::JsepTransportDescription() {} |
| 36 | |
| 37 | JsepTransportDescription::JsepTransportDescription( |
| 38 | bool rtcp_mux_enabled, |
Harald Alvestrand | 0d01841 | 2021-11-04 13:52:31 | [diff] [blame] | 39 | const std::vector<CryptoParams>& cryptos, |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 40 | const std::vector<int>& encrypted_header_extension_ids, |
Zhi Huang | e830e68 | 2018-03-30 17:48:35 | [diff] [blame] | 41 | int rtp_abs_sendtime_extn_id, |
Niels Möller | dc80aaf | 2020-06-18 08:10:17 | [diff] [blame] | 42 | const TransportDescription& transport_desc) |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 43 | : rtcp_mux_enabled(rtcp_mux_enabled), |
Harald Alvestrand | 0d01841 | 2021-11-04 13:52:31 | [diff] [blame] | 44 | cryptos(cryptos), |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 45 | encrypted_header_extension_ids(encrypted_header_extension_ids), |
Zhi Huang | e830e68 | 2018-03-30 17:48:35 | [diff] [blame] | 46 | rtp_abs_sendtime_extn_id(rtp_abs_sendtime_extn_id), |
Niels Möller | dc80aaf | 2020-06-18 08:10:17 | [diff] [blame] | 47 | transport_desc(transport_desc) {} |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 48 | |
| 49 | JsepTransportDescription::JsepTransportDescription( |
| 50 | const JsepTransportDescription& from) |
| 51 | : rtcp_mux_enabled(from.rtcp_mux_enabled), |
Harald Alvestrand | 0d01841 | 2021-11-04 13:52:31 | [diff] [blame] | 52 | cryptos(from.cryptos), |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 53 | encrypted_header_extension_ids(from.encrypted_header_extension_ids), |
Zhi Huang | e830e68 | 2018-03-30 17:48:35 | [diff] [blame] | 54 | rtp_abs_sendtime_extn_id(from.rtp_abs_sendtime_extn_id), |
Niels Möller | dc80aaf | 2020-06-18 08:10:17 | [diff] [blame] | 55 | transport_desc(from.transport_desc) {} |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 56 | |
| 57 | JsepTransportDescription::~JsepTransportDescription() = default; |
| 58 | |
| 59 | JsepTransportDescription& JsepTransportDescription::operator=( |
| 60 | const JsepTransportDescription& from) { |
| 61 | if (this == &from) { |
| 62 | return *this; |
| 63 | } |
| 64 | rtcp_mux_enabled = from.rtcp_mux_enabled; |
Harald Alvestrand | 0d01841 | 2021-11-04 13:52:31 | [diff] [blame] | 65 | cryptos = from.cryptos; |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 66 | encrypted_header_extension_ids = from.encrypted_header_extension_ids; |
Zhi Huang | e830e68 | 2018-03-30 17:48:35 | [diff] [blame] | 67 | rtp_abs_sendtime_extn_id = from.rtp_abs_sendtime_extn_id; |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 68 | transport_desc = from.transport_desc; |
| 69 | |
| 70 | return *this; |
| 71 | } |
| 72 | |
Zhi Huang | 365381f | 2018-04-13 23:44:34 | [diff] [blame] | 73 | JsepTransport::JsepTransport( |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 74 | const std::string& mid, |
| 75 | const rtc::scoped_refptr<rtc::RTCCertificate>& local_certificate, |
Qingsi Wang | 25ec888 | 2019-11-15 20:33:05 | [diff] [blame] | 76 | rtc::scoped_refptr<webrtc::IceTransportInterface> ice_transport, |
| 77 | rtc::scoped_refptr<webrtc::IceTransportInterface> rtcp_ice_transport, |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 78 | std::unique_ptr<webrtc::RtpTransport> unencrypted_rtp_transport, |
| 79 | std::unique_ptr<webrtc::SrtpTransport> sdes_transport, |
| 80 | std::unique_ptr<webrtc::DtlsSrtpTransport> dtls_srtp_transport, |
| 81 | std::unique_ptr<DtlsTransportInternal> rtp_dtls_transport, |
Anton Sukhanov | 7940da0 | 2018-10-10 17:34:49 | [diff] [blame] | 82 | std::unique_ptr<DtlsTransportInternal> rtcp_dtls_transport, |
Mirko Bonadei | 96dca92 | 2021-07-10 20:37:40 | [diff] [blame] | 83 | std::unique_ptr<SctpTransportInternal> sctp_transport, |
| 84 | std::function<void()> rtcp_mux_active_callback) |
Harald Alvestrand | 78a5e96 | 2019-04-03 08:42:39 | [diff] [blame] | 85 | : network_thread_(rtc::Thread::Current()), |
| 86 | mid_(mid), |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 87 | local_certificate_(local_certificate), |
Bjorn A Mellem | 0c1c1b4 | 2019-05-30 00:34:13 | [diff] [blame] | 88 | ice_transport_(std::move(ice_transport)), |
| 89 | rtcp_ice_transport_(std::move(rtcp_ice_transport)), |
Harald Alvestrand | 78a5e96 | 2019-04-03 08:42:39 | [diff] [blame] | 90 | unencrypted_rtp_transport_(std::move(unencrypted_rtp_transport)), |
Harald Alvestrand | 0d01841 | 2021-11-04 13:52:31 | [diff] [blame] | 91 | sdes_transport_(std::move(sdes_transport)), |
Harald Alvestrand | 78a5e96 | 2019-04-03 08:42:39 | [diff] [blame] | 92 | dtls_srtp_transport_(std::move(dtls_srtp_transport)), |
Tommi | 87f7090 | 2021-04-27 12:43:08 | [diff] [blame] | 93 | rtp_dtls_transport_(rtp_dtls_transport |
| 94 | ? rtc::make_ref_counted<webrtc::DtlsTransport>( |
| 95 | std::move(rtp_dtls_transport)) |
| 96 | : nullptr), |
| 97 | rtcp_dtls_transport_(rtcp_dtls_transport |
| 98 | ? rtc::make_ref_counted<webrtc::DtlsTransport>( |
| 99 | std::move(rtcp_dtls_transport)) |
| 100 | : nullptr), |
Bjorn A Mellem | bc3eebc | 2019-09-23 21:53:54 | [diff] [blame] | 101 | sctp_transport_(sctp_transport |
Tommi | 87f7090 | 2021-04-27 12:43:08 | [diff] [blame] | 102 | ? rtc::make_ref_counted<webrtc::SctpTransport>( |
Bjorn A Mellem | bc3eebc | 2019-09-23 21:53:54 | [diff] [blame] | 103 | std::move(sctp_transport)) |
Mirko Bonadei | 96dca92 | 2021-07-10 20:37:40 | [diff] [blame] | 104 | : nullptr), |
| 105 | rtcp_mux_active_callback_(std::move(rtcp_mux_active_callback)) { |
Markus Handell | 518669d | 2021-06-07 11:30:46 | [diff] [blame] | 106 | TRACE_EVENT0("webrtc", "JsepTransport::JsepTransport"); |
Bjorn A Mellem | 0c1c1b4 | 2019-05-30 00:34:13 | [diff] [blame] | 107 | RTC_DCHECK(ice_transport_); |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 108 | RTC_DCHECK(rtp_dtls_transport_); |
Artem Titov | 880fa81 | 2021-07-30 20:30:23 | [diff] [blame] | 109 | // `rtcp_ice_transport_` must be present iff `rtcp_dtls_transport_` is |
Bjorn A Mellem | 0c1c1b4 | 2019-05-30 00:34:13 | [diff] [blame] | 110 | // present. |
| 111 | RTC_DCHECK_EQ((rtcp_ice_transport_ != nullptr), |
| 112 | (rtcp_dtls_transport_ != nullptr)); |
Harald Alvestrand | 78a5e96 | 2019-04-03 08:42:39 | [diff] [blame] | 113 | // Verify the "only one out of these three can be set" invariant. |
| 114 | if (unencrypted_rtp_transport_) { |
Harald Alvestrand | 0d01841 | 2021-11-04 13:52:31 | [diff] [blame] | 115 | RTC_DCHECK(!sdes_transport); |
| 116 | RTC_DCHECK(!dtls_srtp_transport); |
| 117 | } else if (sdes_transport_) { |
| 118 | RTC_DCHECK(!unencrypted_rtp_transport); |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 119 | RTC_DCHECK(!dtls_srtp_transport); |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 120 | } else { |
Harald Alvestrand | 78a5e96 | 2019-04-03 08:42:39 | [diff] [blame] | 121 | RTC_DCHECK(dtls_srtp_transport_); |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 122 | RTC_DCHECK(!unencrypted_rtp_transport); |
Harald Alvestrand | 0d01841 | 2021-11-04 13:52:31 | [diff] [blame] | 123 | RTC_DCHECK(!sdes_transport); |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 124 | } |
Piotr (Peter) Slatala | 4eb4112 | 2018-11-01 14:26:03 | [diff] [blame] | 125 | |
Bjorn A Mellem | bc3eebc | 2019-09-23 21:53:54 | [diff] [blame] | 126 | if (sctp_transport_) { |
| 127 | sctp_transport_->SetDtlsTransport(rtp_dtls_transport_); |
| 128 | } |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 129 | } |
| 130 | |
Piotr (Peter) Slatala | 4eb4112 | 2018-11-01 14:26:03 | [diff] [blame] | 131 | JsepTransport::~JsepTransport() { |
Markus Handell | 518669d | 2021-06-07 11:30:46 | [diff] [blame] | 132 | TRACE_EVENT0("webrtc", "JsepTransport::~JsepTransport"); |
Bjorn A Mellem | bc3eebc | 2019-09-23 21:53:54 | [diff] [blame] | 133 | if (sctp_transport_) { |
| 134 | sctp_transport_->Clear(); |
| 135 | } |
| 136 | |
Harald Alvestrand | 628f37a | 2018-12-06 09:55:20 | [diff] [blame] | 137 | // Clear all DtlsTransports. There may be pointers to these from |
| 138 | // other places, so we can't assume they'll be deleted by the destructor. |
Harald Alvestrand | d02541e | 2019-01-03 11:43:28 | [diff] [blame] | 139 | rtp_dtls_transport_->Clear(); |
Harald Alvestrand | 628f37a | 2018-12-06 09:55:20 | [diff] [blame] | 140 | if (rtcp_dtls_transport_) { |
Harald Alvestrand | d02541e | 2019-01-03 11:43:28 | [diff] [blame] | 141 | rtcp_dtls_transport_->Clear(); |
Harald Alvestrand | 628f37a | 2018-12-06 09:55:20 | [diff] [blame] | 142 | } |
Anton Sukhanov | 292ce4e | 2019-06-03 20:00:24 | [diff] [blame] | 143 | |
Anton Sukhanov | 292ce4e | 2019-06-03 20:00:24 | [diff] [blame] | 144 | // ICE will be the last transport to be deleted. |
Piotr (Peter) Slatala | 4eb4112 | 2018-11-01 14:26:03 | [diff] [blame] | 145 | } |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 146 | |
Zhi Huang | 365381f | 2018-04-13 23:44:34 | [diff] [blame] | 147 | webrtc::RTCError JsepTransport::SetLocalJsepTransportDescription( |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 148 | const JsepTransportDescription& jsep_description, |
| 149 | SdpType type) { |
| 150 | webrtc::RTCError error; |
Markus Handell | 518669d | 2021-06-07 11:30:46 | [diff] [blame] | 151 | TRACE_EVENT0("webrtc", "JsepTransport::SetLocalJsepTransportDescription"); |
Harald Alvestrand | 78a5e96 | 2019-04-03 08:42:39 | [diff] [blame] | 152 | RTC_DCHECK_RUN_ON(network_thread_); |
Steve Anton | 71ff073 | 2020-01-25 00:28:15 | [diff] [blame] | 153 | |
Jonas Oreland | 52aea5d | 2020-03-03 12:21:30 | [diff] [blame] | 154 | IceParameters ice_parameters = |
| 155 | jsep_description.transport_desc.GetIceParameters(); |
| 156 | webrtc::RTCError ice_parameters_result = ice_parameters.Validate(); |
Steve Anton | 71ff073 | 2020-01-25 00:28:15 | [diff] [blame] | 157 | if (!ice_parameters_result.ok()) { |
| 158 | rtc::StringBuilder sb; |
Jonas Oreland | 52aea5d | 2020-03-03 12:21:30 | [diff] [blame] | 159 | sb << "Invalid ICE parameters: " << ice_parameters_result.message(); |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 160 | return webrtc::RTCError(webrtc::RTCErrorType::INVALID_PARAMETER, |
Steve Anton | 71ff073 | 2020-01-25 00:28:15 | [diff] [blame] | 161 | sb.Release()); |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 162 | } |
| 163 | |
| 164 | if (!SetRtcpMux(jsep_description.rtcp_mux_enabled, type, |
| 165 | ContentSource::CS_LOCAL)) { |
| 166 | return webrtc::RTCError(webrtc::RTCErrorType::INVALID_PARAMETER, |
| 167 | "Failed to setup RTCP mux."); |
| 168 | } |
| 169 | |
Harald Alvestrand | 0d01841 | 2021-11-04 13:52:31 | [diff] [blame] | 170 | // If doing SDES, setup the SDES crypto parameters. |
| 171 | if (sdes_transport_) { |
Niels Möller | 6a48a1d | 2021-02-05 11:34:14 | [diff] [blame] | 172 | RTC_DCHECK(!unencrypted_rtp_transport_); |
Harald Alvestrand | 0d01841 | 2021-11-04 13:52:31 | [diff] [blame] | 173 | RTC_DCHECK(!dtls_srtp_transport_); |
| 174 | if (!SetSdes(jsep_description.cryptos, |
| 175 | jsep_description.encrypted_header_extension_ids, type, |
| 176 | ContentSource::CS_LOCAL)) { |
| 177 | return webrtc::RTCError(webrtc::RTCErrorType::INVALID_PARAMETER, |
| 178 | "Failed to setup SDES crypto parameters."); |
| 179 | } |
| 180 | } else if (dtls_srtp_transport_) { |
| 181 | RTC_DCHECK(!unencrypted_rtp_transport_); |
| 182 | RTC_DCHECK(!sdes_transport_); |
Niels Möller | 6a48a1d | 2021-02-05 11:34:14 | [diff] [blame] | 183 | dtls_srtp_transport_->UpdateRecvEncryptedHeaderExtensionIds( |
| 184 | jsep_description.encrypted_header_extension_ids); |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 185 | } |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 186 | bool ice_restarting = |
| 187 | local_description_ != nullptr && |
| 188 | IceCredentialsChanged(local_description_->transport_desc.ice_ufrag, |
| 189 | local_description_->transport_desc.ice_pwd, |
Steve Anton | 71ff073 | 2020-01-25 00:28:15 | [diff] [blame] | 190 | ice_parameters.ufrag, ice_parameters.pwd); |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 191 | local_description_.reset(new JsepTransportDescription(jsep_description)); |
| 192 | |
| 193 | rtc::SSLFingerprint* local_fp = |
| 194 | local_description_->transport_desc.identity_fingerprint.get(); |
| 195 | |
| 196 | if (!local_fp) { |
| 197 | local_certificate_ = nullptr; |
| 198 | } else { |
Niels Möller | afb246b | 2022-04-20 12:26:50 | [diff] [blame] | 199 | error = VerifyCertificateFingerprint(local_certificate_.get(), local_fp); |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 200 | if (!error.ok()) { |
| 201 | local_description_.reset(); |
| 202 | return error; |
| 203 | } |
| 204 | } |
Yaowen Guo | 9e13860 | 2022-01-05 09:48:33 | [diff] [blame] | 205 | RTC_DCHECK(rtp_dtls_transport_->internal()); |
| 206 | rtp_dtls_transport_->internal()->ice_transport()->SetIceParameters( |
| 207 | ice_parameters); |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 208 | |
Yaowen Guo | 9e13860 | 2022-01-05 09:48:33 | [diff] [blame] | 209 | if (rtcp_dtls_transport_) { |
| 210 | RTC_DCHECK(rtcp_dtls_transport_->internal()); |
| 211 | rtcp_dtls_transport_->internal()->ice_transport()->SetIceParameters( |
| 212 | ice_parameters); |
| 213 | } |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 214 | // If PRANSWER/ANSWER is set, we should decide transport protocol type. |
| 215 | if (type == SdpType::kPrAnswer || type == SdpType::kAnswer) { |
| 216 | error = NegotiateAndSetDtlsParameters(type); |
| 217 | } |
| 218 | if (!error.ok()) { |
| 219 | local_description_.reset(); |
| 220 | return error; |
| 221 | } |
Tomas Gunnarsson | 20f7456 | 2021-02-04 09:22:50 | [diff] [blame] | 222 | |
| 223 | if (needs_ice_restart_ && ice_restarting) { |
| 224 | needs_ice_restart_ = false; |
| 225 | RTC_LOG(LS_VERBOSE) << "needs-ice-restart flag cleared for transport " |
| 226 | << mid(); |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 227 | } |
| 228 | |
| 229 | return webrtc::RTCError::OK(); |
| 230 | } |
| 231 | |
Zhi Huang | 365381f | 2018-04-13 23:44:34 | [diff] [blame] | 232 | webrtc::RTCError JsepTransport::SetRemoteJsepTransportDescription( |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 233 | const JsepTransportDescription& jsep_description, |
| 234 | webrtc::SdpType type) { |
Markus Handell | 518669d | 2021-06-07 11:30:46 | [diff] [blame] | 235 | TRACE_EVENT0("webrtc", "JsepTransport::SetLocalJsepTransportDescription"); |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 236 | webrtc::RTCError error; |
| 237 | |
Harald Alvestrand | 78a5e96 | 2019-04-03 08:42:39 | [diff] [blame] | 238 | RTC_DCHECK_RUN_ON(network_thread_); |
Steve Anton | 71ff073 | 2020-01-25 00:28:15 | [diff] [blame] | 239 | |
Jonas Oreland | 52aea5d | 2020-03-03 12:21:30 | [diff] [blame] | 240 | IceParameters ice_parameters = |
| 241 | jsep_description.transport_desc.GetIceParameters(); |
| 242 | webrtc::RTCError ice_parameters_result = ice_parameters.Validate(); |
Steve Anton | 71ff073 | 2020-01-25 00:28:15 | [diff] [blame] | 243 | if (!ice_parameters_result.ok()) { |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 244 | remote_description_.reset(); |
Steve Anton | 71ff073 | 2020-01-25 00:28:15 | [diff] [blame] | 245 | rtc::StringBuilder sb; |
Jonas Oreland | 52aea5d | 2020-03-03 12:21:30 | [diff] [blame] | 246 | sb << "Invalid ICE parameters: " << ice_parameters_result.message(); |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 247 | return webrtc::RTCError(webrtc::RTCErrorType::INVALID_PARAMETER, |
Steve Anton | 71ff073 | 2020-01-25 00:28:15 | [diff] [blame] | 248 | sb.Release()); |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 249 | } |
| 250 | |
| 251 | if (!SetRtcpMux(jsep_description.rtcp_mux_enabled, type, |
| 252 | ContentSource::CS_REMOTE)) { |
| 253 | return webrtc::RTCError(webrtc::RTCErrorType::INVALID_PARAMETER, |
| 254 | "Failed to setup RTCP mux."); |
| 255 | } |
| 256 | |
Harald Alvestrand | 0d01841 | 2021-11-04 13:52:31 | [diff] [blame] | 257 | // If doing SDES, setup the SDES crypto parameters. |
| 258 | if (sdes_transport_) { |
Niels Möller | 6a48a1d | 2021-02-05 11:34:14 | [diff] [blame] | 259 | RTC_DCHECK(!unencrypted_rtp_transport_); |
Harald Alvestrand | 0d01841 | 2021-11-04 13:52:31 | [diff] [blame] | 260 | RTC_DCHECK(!dtls_srtp_transport_); |
| 261 | if (!SetSdes(jsep_description.cryptos, |
| 262 | jsep_description.encrypted_header_extension_ids, type, |
| 263 | ContentSource::CS_REMOTE)) { |
| 264 | return webrtc::RTCError(webrtc::RTCErrorType::INVALID_PARAMETER, |
| 265 | "Failed to setup SDES crypto parameters."); |
| 266 | } |
| 267 | sdes_transport_->CacheRtpAbsSendTimeHeaderExtension( |
| 268 | jsep_description.rtp_abs_sendtime_extn_id); |
| 269 | } else if (dtls_srtp_transport_) { |
| 270 | RTC_DCHECK(!unencrypted_rtp_transport_); |
| 271 | RTC_DCHECK(!sdes_transport_); |
Niels Möller | 6a48a1d | 2021-02-05 11:34:14 | [diff] [blame] | 272 | dtls_srtp_transport_->UpdateSendEncryptedHeaderExtensionIds( |
| 273 | jsep_description.encrypted_header_extension_ids); |
| 274 | dtls_srtp_transport_->CacheRtpAbsSendTimeHeaderExtension( |
| 275 | jsep_description.rtp_abs_sendtime_extn_id); |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 276 | } |
| 277 | |
| 278 | remote_description_.reset(new JsepTransportDescription(jsep_description)); |
Harald Alvestrand | 78a5e96 | 2019-04-03 08:42:39 | [diff] [blame] | 279 | RTC_DCHECK(rtp_dtls_transport()); |
Steve Anton | 71ff073 | 2020-01-25 00:28:15 | [diff] [blame] | 280 | SetRemoteIceParameters(ice_parameters, rtp_dtls_transport()->ice_transport()); |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 281 | |
Harald Alvestrand | 78a5e96 | 2019-04-03 08:42:39 | [diff] [blame] | 282 | if (rtcp_dtls_transport()) { |
Steve Anton | 71ff073 | 2020-01-25 00:28:15 | [diff] [blame] | 283 | SetRemoteIceParameters(ice_parameters, |
| 284 | rtcp_dtls_transport()->ice_transport()); |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 285 | } |
| 286 | |
| 287 | // If PRANSWER/ANSWER is set, we should decide transport protocol type. |
| 288 | if (type == SdpType::kPrAnswer || type == SdpType::kAnswer) { |
| 289 | error = NegotiateAndSetDtlsParameters(SdpType::kOffer); |
| 290 | } |
| 291 | if (!error.ok()) { |
| 292 | remote_description_.reset(); |
| 293 | return error; |
| 294 | } |
| 295 | return webrtc::RTCError::OK(); |
| 296 | } |
| 297 | |
Zhi Huang | 365381f | 2018-04-13 23:44:34 | [diff] [blame] | 298 | webrtc::RTCError JsepTransport::AddRemoteCandidates( |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 299 | const Candidates& candidates) { |
Harald Alvestrand | 78a5e96 | 2019-04-03 08:42:39 | [diff] [blame] | 300 | RTC_DCHECK_RUN_ON(network_thread_); |
Henrik Boström | 5d8f8fa | 2018-04-13 15:22:50 | [diff] [blame] | 301 | if (!local_description_ || !remote_description_) { |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 302 | return webrtc::RTCError(webrtc::RTCErrorType::INVALID_STATE, |
| 303 | mid() + |
| 304 | " is not ready to use the remote candidate " |
Henrik Boström | 5d8f8fa | 2018-04-13 15:22:50 | [diff] [blame] | 305 | "because the local or remote description is " |
| 306 | "not set."); |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 307 | } |
| 308 | |
| 309 | for (const cricket::Candidate& candidate : candidates) { |
| 310 | auto transport = |
| 311 | candidate.component() == cricket::ICE_CANDIDATE_COMPONENT_RTP |
Harald Alvestrand | ad88c88 | 2018-11-28 15:47:46 | [diff] [blame] | 312 | ? rtp_dtls_transport_ |
| 313 | : rtcp_dtls_transport_; |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 314 | if (!transport) { |
| 315 | return webrtc::RTCError(webrtc::RTCErrorType::INVALID_PARAMETER, |
| 316 | "Candidate has an unknown component: " + |
Qingsi Wang | 20232a9 | 2019-09-06 19:51:17 | [diff] [blame] | 317 | candidate.ToSensitiveString() + " for mid " + |
| 318 | mid()); |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 319 | } |
Harald Alvestrand | 628f37a | 2018-12-06 09:55:20 | [diff] [blame] | 320 | RTC_DCHECK(transport->internal() && transport->internal()->ice_transport()); |
Harald Alvestrand | ad88c88 | 2018-11-28 15:47:46 | [diff] [blame] | 321 | transport->internal()->ice_transport()->AddRemoteCandidate(candidate); |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 322 | } |
| 323 | return webrtc::RTCError::OK(); |
| 324 | } |
| 325 | |
Zhi Huang | 365381f | 2018-04-13 23:44:34 | [diff] [blame] | 326 | void JsepTransport::SetNeedsIceRestartFlag() { |
Tomas Gunnarsson | 20f7456 | 2021-02-04 09:22:50 | [diff] [blame] | 327 | RTC_DCHECK_RUN_ON(network_thread_); |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 328 | if (!needs_ice_restart_) { |
| 329 | needs_ice_restart_ = true; |
| 330 | RTC_LOG(LS_VERBOSE) << "needs-ice-restart flag set for transport " << mid(); |
| 331 | } |
| 332 | } |
| 333 | |
Danil Chapovalov | 66cadcc | 2018-06-19 14:47:43 | [diff] [blame] | 334 | absl::optional<rtc::SSLRole> JsepTransport::GetDtlsRole() const { |
Harald Alvestrand | 78a5e96 | 2019-04-03 08:42:39 | [diff] [blame] | 335 | RTC_DCHECK_RUN_ON(network_thread_); |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 336 | RTC_DCHECK(rtp_dtls_transport_); |
Harald Alvestrand | 628f37a | 2018-12-06 09:55:20 | [diff] [blame] | 337 | RTC_DCHECK(rtp_dtls_transport_->internal()); |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 338 | rtc::SSLRole dtls_role; |
Harald Alvestrand | ad88c88 | 2018-11-28 15:47:46 | [diff] [blame] | 339 | if (!rtp_dtls_transport_->internal()->GetDtlsRole(&dtls_role)) { |
Danil Chapovalov | 66cadcc | 2018-06-19 14:47:43 | [diff] [blame] | 340 | return absl::optional<rtc::SSLRole>(); |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 341 | } |
| 342 | |
Danil Chapovalov | 66cadcc | 2018-06-19 14:47:43 | [diff] [blame] | 343 | return absl::optional<rtc::SSLRole>(dtls_role); |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 344 | } |
| 345 | |
Zhi Huang | 365381f | 2018-04-13 23:44:34 | [diff] [blame] | 346 | bool JsepTransport::GetStats(TransportStats* stats) { |
Markus Handell | 518669d | 2021-06-07 11:30:46 | [diff] [blame] | 347 | TRACE_EVENT0("webrtc", "JsepTransport::GetStats"); |
Harald Alvestrand | 78a5e96 | 2019-04-03 08:42:39 | [diff] [blame] | 348 | RTC_DCHECK_RUN_ON(network_thread_); |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 349 | stats->transport_name = mid(); |
| 350 | stats->channel_stats.clear(); |
Harald Alvestrand | 628f37a | 2018-12-06 09:55:20 | [diff] [blame] | 351 | RTC_DCHECK(rtp_dtls_transport_->internal()); |
Niels Möller | 6a48a1d | 2021-02-05 11:34:14 | [diff] [blame] | 352 | bool ret = GetTransportStats(rtp_dtls_transport_->internal(), |
| 353 | ICE_CANDIDATE_COMPONENT_RTP, stats); |
| 354 | |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 355 | if (rtcp_dtls_transport_) { |
Harald Alvestrand | 628f37a | 2018-12-06 09:55:20 | [diff] [blame] | 356 | RTC_DCHECK(rtcp_dtls_transport_->internal()); |
Niels Möller | 6a48a1d | 2021-02-05 11:34:14 | [diff] [blame] | 357 | ret &= GetTransportStats(rtcp_dtls_transport_->internal(), |
| 358 | ICE_CANDIDATE_COMPONENT_RTCP, stats); |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 359 | } |
| 360 | return ret; |
| 361 | } |
| 362 | |
Zhi Huang | 365381f | 2018-04-13 23:44:34 | [diff] [blame] | 363 | webrtc::RTCError JsepTransport::VerifyCertificateFingerprint( |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 364 | const rtc::RTCCertificate* certificate, |
| 365 | const rtc::SSLFingerprint* fingerprint) const { |
Markus Handell | 518669d | 2021-06-07 11:30:46 | [diff] [blame] | 366 | TRACE_EVENT0("webrtc", "JsepTransport::VerifyCertificateFingerprint"); |
Harald Alvestrand | 78a5e96 | 2019-04-03 08:42:39 | [diff] [blame] | 367 | RTC_DCHECK_RUN_ON(network_thread_); |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 368 | if (!fingerprint) { |
| 369 | return webrtc::RTCError(webrtc::RTCErrorType::INVALID_PARAMETER, |
| 370 | "No fingerprint"); |
| 371 | } |
| 372 | if (!certificate) { |
| 373 | return webrtc::RTCError(webrtc::RTCErrorType::INVALID_PARAMETER, |
| 374 | "Fingerprint provided but no identity available."); |
| 375 | } |
Steve Anton | 4905edb | 2018-10-16 02:27:44 | [diff] [blame] | 376 | std::unique_ptr<rtc::SSLFingerprint> fp_tmp = |
| 377 | rtc::SSLFingerprint::CreateUnique(fingerprint->algorithm, |
| 378 | *certificate->identity()); |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 379 | RTC_DCHECK(fp_tmp.get() != NULL); |
| 380 | if (*fp_tmp == *fingerprint) { |
| 381 | return webrtc::RTCError::OK(); |
| 382 | } |
Zhi Huang | 365381f | 2018-04-13 23:44:34 | [diff] [blame] | 383 | char ss_buf[1024]; |
| 384 | rtc::SimpleStringBuilder desc(ss_buf); |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 385 | desc << "Local fingerprint does not match identity. Expected: "; |
| 386 | desc << fp_tmp->ToString(); |
| 387 | desc << " Got: " << fingerprint->ToString(); |
Zhi Huang | 365381f | 2018-04-13 23:44:34 | [diff] [blame] | 388 | return webrtc::RTCError(webrtc::RTCErrorType::INVALID_PARAMETER, |
| 389 | std::string(desc.str())); |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 390 | } |
| 391 | |
Zhi Huang | b57e169 | 2018-06-12 18:41:11 | [diff] [blame] | 392 | void JsepTransport::SetActiveResetSrtpParams(bool active_reset_srtp_params) { |
Harald Alvestrand | 78a5e96 | 2019-04-03 08:42:39 | [diff] [blame] | 393 | RTC_DCHECK_RUN_ON(network_thread_); |
Zhi Huang | b57e169 | 2018-06-12 18:41:11 | [diff] [blame] | 394 | if (dtls_srtp_transport_) { |
Harald Alvestrand | 97597c0 | 2021-11-04 12:01:23 | [diff] [blame] | 395 | RTC_LOG(LS_INFO) |
Zhi Huang | b57e169 | 2018-06-12 18:41:11 | [diff] [blame] | 396 | << "Setting active_reset_srtp_params of DtlsSrtpTransport to: " |
| 397 | << active_reset_srtp_params; |
| 398 | dtls_srtp_transport_->SetActiveResetSrtpParams(active_reset_srtp_params); |
| 399 | } |
| 400 | } |
| 401 | |
Zhi Huang | 365381f | 2018-04-13 23:44:34 | [diff] [blame] | 402 | void JsepTransport::SetRemoteIceParameters( |
Steve Anton | 71ff073 | 2020-01-25 00:28:15 | [diff] [blame] | 403 | const IceParameters& ice_parameters, |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 404 | IceTransportInternal* ice_transport) { |
Markus Handell | 518669d | 2021-06-07 11:30:46 | [diff] [blame] | 405 | TRACE_EVENT0("webrtc", "JsepTransport::SetRemoteIceParameters"); |
Harald Alvestrand | 78a5e96 | 2019-04-03 08:42:39 | [diff] [blame] | 406 | RTC_DCHECK_RUN_ON(network_thread_); |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 407 | RTC_DCHECK(ice_transport); |
| 408 | RTC_DCHECK(remote_description_); |
Steve Anton | 71ff073 | 2020-01-25 00:28:15 | [diff] [blame] | 409 | ice_transport->SetRemoteIceParameters(ice_parameters); |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 410 | ice_transport->SetRemoteIceMode(remote_description_->transport_desc.ice_mode); |
| 411 | } |
| 412 | |
Zhi Huang | 365381f | 2018-04-13 23:44:34 | [diff] [blame] | 413 | webrtc::RTCError JsepTransport::SetNegotiatedDtlsParameters( |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 414 | DtlsTransportInternal* dtls_transport, |
Danil Chapovalov | 66cadcc | 2018-06-19 14:47:43 | [diff] [blame] | 415 | absl::optional<rtc::SSLRole> dtls_role, |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 416 | rtc::SSLFingerprint* remote_fingerprint) { |
| 417 | RTC_DCHECK(dtls_transport); |
Philipp Hancke | 4a3b5cc | 2022-08-18 12:48:21 | [diff] [blame] | 418 | return dtls_transport->SetRemoteParameters( |
| 419 | remote_fingerprint->algorithm, remote_fingerprint->digest.cdata(), |
| 420 | remote_fingerprint->digest.size(), dtls_role); |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 421 | } |
| 422 | |
Zhi Huang | 365381f | 2018-04-13 23:44:34 | [diff] [blame] | 423 | bool JsepTransport::SetRtcpMux(bool enable, |
| 424 | webrtc::SdpType type, |
| 425 | ContentSource source) { |
Harald Alvestrand | 78a5e96 | 2019-04-03 08:42:39 | [diff] [blame] | 426 | RTC_DCHECK_RUN_ON(network_thread_); |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 427 | bool ret = false; |
| 428 | switch (type) { |
| 429 | case SdpType::kOffer: |
| 430 | ret = rtcp_mux_negotiator_.SetOffer(enable, source); |
| 431 | break; |
| 432 | case SdpType::kPrAnswer: |
| 433 | // This may activate RTCP muxing, but we don't yet destroy the transport |
| 434 | // because the final answer may deactivate it. |
| 435 | ret = rtcp_mux_negotiator_.SetProvisionalAnswer(enable, source); |
| 436 | break; |
| 437 | case SdpType::kAnswer: |
| 438 | ret = rtcp_mux_negotiator_.SetAnswer(enable, source); |
| 439 | if (ret && rtcp_mux_negotiator_.IsActive()) { |
| 440 | ActivateRtcpMux(); |
| 441 | } |
| 442 | break; |
| 443 | default: |
Artem Titov | d325196 | 2021-11-15 15:57:07 | [diff] [blame] | 444 | RTC_DCHECK_NOTREACHED(); |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 445 | } |
| 446 | |
| 447 | if (!ret) { |
| 448 | return false; |
| 449 | } |
| 450 | |
| 451 | auto transport = rtp_transport(); |
| 452 | transport->SetRtcpMuxEnabled(rtcp_mux_negotiator_.IsActive()); |
| 453 | return ret; |
| 454 | } |
| 455 | |
Zhi Huang | 365381f | 2018-04-13 23:44:34 | [diff] [blame] | 456 | void JsepTransport::ActivateRtcpMux() { |
Niels Möller | 6a48a1d | 2021-02-05 11:34:14 | [diff] [blame] | 457 | if (unencrypted_rtp_transport_) { |
Harald Alvestrand | 0d01841 | 2021-11-04 13:52:31 | [diff] [blame] | 458 | RTC_DCHECK(!sdes_transport_); |
Niels Möller | 6a48a1d | 2021-02-05 11:34:14 | [diff] [blame] | 459 | RTC_DCHECK(!dtls_srtp_transport_); |
| 460 | unencrypted_rtp_transport_->SetRtcpPacketTransport(nullptr); |
Harald Alvestrand | 0d01841 | 2021-11-04 13:52:31 | [diff] [blame] | 461 | } else if (sdes_transport_) { |
| 462 | RTC_DCHECK(!unencrypted_rtp_transport_); |
| 463 | RTC_DCHECK(!dtls_srtp_transport_); |
| 464 | sdes_transport_->SetRtcpPacketTransport(nullptr); |
Niels Möller | 6a48a1d | 2021-02-05 11:34:14 | [diff] [blame] | 465 | } else if (dtls_srtp_transport_) { |
| 466 | RTC_DCHECK(dtls_srtp_transport_); |
| 467 | RTC_DCHECK(!unencrypted_rtp_transport_); |
Harald Alvestrand | 0d01841 | 2021-11-04 13:52:31 | [diff] [blame] | 468 | RTC_DCHECK(!sdes_transport_); |
Niels Möller | 6a48a1d | 2021-02-05 11:34:14 | [diff] [blame] | 469 | dtls_srtp_transport_->SetDtlsTransports(rtp_dtls_transport(), |
| 470 | /*rtcp_dtls_transport=*/nullptr); |
Harald Alvestrand | 78a5e96 | 2019-04-03 08:42:39 | [diff] [blame] | 471 | } |
Harald Alvestrand | d4ad2ef | 2021-02-05 23:36:39 | [diff] [blame] | 472 | rtcp_dtls_transport_ = nullptr; // Destroy this reference. |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 473 | // Notify the JsepTransportController to update the aggregate states. |
Mirko Bonadei | 96dca92 | 2021-07-10 20:37:40 | [diff] [blame] | 474 | rtcp_mux_active_callback_(); |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 475 | } |
| 476 | |
Harald Alvestrand | 0d01841 | 2021-11-04 13:52:31 | [diff] [blame] | 477 | bool JsepTransport::SetSdes(const std::vector<CryptoParams>& cryptos, |
| 478 | const std::vector<int>& encrypted_extension_ids, |
| 479 | webrtc::SdpType type, |
| 480 | ContentSource source) { |
| 481 | RTC_DCHECK_RUN_ON(network_thread_); |
| 482 | bool ret = false; |
| 483 | ret = sdes_negotiator_.Process(cryptos, type, source); |
| 484 | if (!ret) { |
| 485 | return ret; |
| 486 | } |
| 487 | |
| 488 | if (source == ContentSource::CS_LOCAL) { |
| 489 | recv_extension_ids_ = encrypted_extension_ids; |
| 490 | } else { |
| 491 | send_extension_ids_ = encrypted_extension_ids; |
| 492 | } |
| 493 | |
| 494 | // If setting an SDES answer succeeded, apply the negotiated parameters |
| 495 | // to the SRTP transport. |
| 496 | if ((type == SdpType::kPrAnswer || type == SdpType::kAnswer) && ret) { |
Philipp Hancke | 55b89a8 | 2023-08-01 09:34:05 | [diff] [blame] | 497 | if (sdes_negotiator_.send_crypto_suite() && |
| 498 | sdes_negotiator_.recv_crypto_suite()) { |
Harald Alvestrand | 0d01841 | 2021-11-04 13:52:31 | [diff] [blame] | 499 | RTC_DCHECK(send_extension_ids_); |
| 500 | RTC_DCHECK(recv_extension_ids_); |
| 501 | ret = sdes_transport_->SetRtpParams( |
Philipp Hancke | 55b89a8 | 2023-08-01 09:34:05 | [diff] [blame] | 502 | *(sdes_negotiator_.send_crypto_suite()), |
Harald Alvestrand | 0d01841 | 2021-11-04 13:52:31 | [diff] [blame] | 503 | sdes_negotiator_.send_key().data(), |
| 504 | static_cast<int>(sdes_negotiator_.send_key().size()), |
Philipp Hancke | 55b89a8 | 2023-08-01 09:34:05 | [diff] [blame] | 505 | *(send_extension_ids_), *(sdes_negotiator_.recv_crypto_suite()), |
Harald Alvestrand | 0d01841 | 2021-11-04 13:52:31 | [diff] [blame] | 506 | sdes_negotiator_.recv_key().data(), |
| 507 | static_cast<int>(sdes_negotiator_.recv_key().size()), |
| 508 | *(recv_extension_ids_)); |
| 509 | } else { |
| 510 | RTC_LOG(LS_INFO) << "No crypto keys are provided for SDES."; |
| 511 | if (type == SdpType::kAnswer) { |
| 512 | // Explicitly reset the `sdes_transport_` if no crypto param is |
| 513 | // provided in the answer. No need to call `ResetParams()` for |
| 514 | // `sdes_negotiator_` because it resets the params inside `SetAnswer`. |
| 515 | sdes_transport_->ResetParams(); |
| 516 | } |
| 517 | } |
| 518 | } |
| 519 | return ret; |
| 520 | } |
| 521 | |
Zhi Huang | 365381f | 2018-04-13 23:44:34 | [diff] [blame] | 522 | webrtc::RTCError JsepTransport::NegotiateAndSetDtlsParameters( |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 523 | SdpType local_description_type) { |
Harald Alvestrand | 78a5e96 | 2019-04-03 08:42:39 | [diff] [blame] | 524 | RTC_DCHECK_RUN_ON(network_thread_); |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 525 | if (!local_description_ || !remote_description_) { |
| 526 | return webrtc::RTCError(webrtc::RTCErrorType::INVALID_STATE, |
| 527 | "Applying an answer transport description " |
| 528 | "without applying any offer."); |
| 529 | } |
| 530 | std::unique_ptr<rtc::SSLFingerprint> remote_fingerprint; |
Danil Chapovalov | 66cadcc | 2018-06-19 14:47:43 | [diff] [blame] | 531 | absl::optional<rtc::SSLRole> negotiated_dtls_role; |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 532 | |
| 533 | rtc::SSLFingerprint* local_fp = |
| 534 | local_description_->transport_desc.identity_fingerprint.get(); |
| 535 | rtc::SSLFingerprint* remote_fp = |
| 536 | remote_description_->transport_desc.identity_fingerprint.get(); |
| 537 | if (remote_fp && local_fp) { |
Mirko Bonadei | 317a1f0 | 2019-09-17 15:06:18 | [diff] [blame] | 538 | remote_fingerprint = std::make_unique<rtc::SSLFingerprint>(*remote_fp); |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 539 | webrtc::RTCError error = |
| 540 | NegotiateDtlsRole(local_description_type, |
| 541 | local_description_->transport_desc.connection_role, |
| 542 | remote_description_->transport_desc.connection_role, |
| 543 | &negotiated_dtls_role); |
| 544 | if (!error.ok()) { |
| 545 | return error; |
| 546 | } |
| 547 | } else if (local_fp && (local_description_type == SdpType::kAnswer)) { |
| 548 | return webrtc::RTCError( |
| 549 | webrtc::RTCErrorType::INVALID_PARAMETER, |
| 550 | "Local fingerprint supplied when caller didn't offer DTLS."); |
| 551 | } else { |
| 552 | // We are not doing DTLS |
Mirko Bonadei | 317a1f0 | 2019-09-17 15:06:18 | [diff] [blame] | 553 | remote_fingerprint = std::make_unique<rtc::SSLFingerprint>( |
Steve Anton | 4905edb | 2018-10-16 02:27:44 | [diff] [blame] | 554 | "", rtc::ArrayView<const uint8_t>()); |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 555 | } |
| 556 | // Now that we have negotiated everything, push it downward. |
| 557 | // Note that we cache the result so that if we have race conditions |
| 558 | // between future SetRemote/SetLocal invocations and new transport |
| 559 | // creation, we have the negotiation state saved until a new |
| 560 | // negotiation happens. |
Harald Alvestrand | 78a5e96 | 2019-04-03 08:42:39 | [diff] [blame] | 561 | RTC_DCHECK(rtp_dtls_transport()); |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 562 | webrtc::RTCError error = SetNegotiatedDtlsParameters( |
Harald Alvestrand | 78a5e96 | 2019-04-03 08:42:39 | [diff] [blame] | 563 | rtp_dtls_transport(), negotiated_dtls_role, remote_fingerprint.get()); |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 564 | if (!error.ok()) { |
| 565 | return error; |
| 566 | } |
| 567 | |
Harald Alvestrand | 78a5e96 | 2019-04-03 08:42:39 | [diff] [blame] | 568 | if (rtcp_dtls_transport()) { |
| 569 | error = SetNegotiatedDtlsParameters( |
| 570 | rtcp_dtls_transport(), negotiated_dtls_role, remote_fingerprint.get()); |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 571 | } |
| 572 | return error; |
| 573 | } |
| 574 | |
Zhi Huang | 365381f | 2018-04-13 23:44:34 | [diff] [blame] | 575 | webrtc::RTCError JsepTransport::NegotiateDtlsRole( |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 576 | SdpType local_description_type, |
| 577 | ConnectionRole local_connection_role, |
| 578 | ConnectionRole remote_connection_role, |
Danil Chapovalov | 66cadcc | 2018-06-19 14:47:43 | [diff] [blame] | 579 | absl::optional<rtc::SSLRole>* negotiated_dtls_role) { |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 580 | // From RFC 4145, section-4.1, The following are the values that the |
| 581 | // 'setup' attribute can take in an offer/answer exchange: |
| 582 | // Offer Answer |
| 583 | // ________________ |
| 584 | // active passive / holdconn |
| 585 | // passive active / holdconn |
| 586 | // actpass active / passive / holdconn |
| 587 | // holdconn holdconn |
| 588 | // |
| 589 | // Set the role that is most conformant with RFC 5763, Section 5, bullet 1 |
| 590 | // The endpoint MUST use the setup attribute defined in [RFC4145]. |
| 591 | // The endpoint that is the offerer MUST use the setup attribute |
| 592 | // value of setup:actpass and be prepared to receive a client_hello |
| 593 | // before it receives the answer. The answerer MUST use either a |
| 594 | // setup attribute value of setup:active or setup:passive. Note that |
| 595 | // if the answerer uses setup:passive, then the DTLS handshake will |
| 596 | // not begin until the answerer is received, which adds additional |
| 597 | // latency. setup:active allows the answer and the DTLS handshake to |
| 598 | // occur in parallel. Thus, setup:active is RECOMMENDED. Whichever |
| 599 | // party is active MUST initiate a DTLS handshake by sending a |
| 600 | // ClientHello over each flow (host/port quartet). |
| 601 | // IOW - actpass and passive modes should be treated as server and |
| 602 | // active as client. |
Harald Alvestrand | efece42 | 2021-08-19 09:12:51 | [diff] [blame] | 603 | // RFC 8842 section 5.3 updates this text, so that it is mandated |
| 604 | // for the responder to handle offers with "active" and "passive" |
| 605 | // as well as "actpass" |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 606 | bool is_remote_server = false; |
| 607 | if (local_description_type == SdpType::kOffer) { |
| 608 | if (local_connection_role != CONNECTIONROLE_ACTPASS) { |
| 609 | return webrtc::RTCError( |
| 610 | webrtc::RTCErrorType::INVALID_PARAMETER, |
| 611 | "Offerer must use actpass value for setup attribute."); |
| 612 | } |
| 613 | |
| 614 | if (remote_connection_role == CONNECTIONROLE_ACTIVE || |
| 615 | remote_connection_role == CONNECTIONROLE_PASSIVE || |
| 616 | remote_connection_role == CONNECTIONROLE_NONE) { |
| 617 | is_remote_server = (remote_connection_role == CONNECTIONROLE_PASSIVE); |
| 618 | } else { |
| 619 | return webrtc::RTCError( |
| 620 | webrtc::RTCErrorType::INVALID_PARAMETER, |
| 621 | "Answerer must use either active or passive value " |
| 622 | "for setup attribute."); |
| 623 | } |
| 624 | // If remote is NONE or ACTIVE it will act as client. |
| 625 | } else { |
| 626 | if (remote_connection_role != CONNECTIONROLE_ACTPASS && |
| 627 | remote_connection_role != CONNECTIONROLE_NONE) { |
| 628 | // Accept a remote role attribute that's not "actpass", but matches the |
| 629 | // current negotiated role. This is allowed by dtls-sdp, though our |
| 630 | // implementation will never generate such an offer as it's not |
| 631 | // recommended. |
| 632 | // |
| 633 | // See https://datatracker.ietf.org/doc/html/draft-ietf-mmusic-dtls-sdp, |
| 634 | // section 5.5. |
| 635 | auto current_dtls_role = GetDtlsRole(); |
Harald Alvestrand | efece42 | 2021-08-19 09:12:51 | [diff] [blame] | 636 | if (!current_dtls_role) { |
| 637 | // Role not assigned yet. Verify that local role fits with remote role. |
| 638 | switch (remote_connection_role) { |
| 639 | case CONNECTIONROLE_ACTIVE: |
| 640 | if (local_connection_role != CONNECTIONROLE_PASSIVE) { |
| 641 | return webrtc::RTCError( |
| 642 | webrtc::RTCErrorType::INVALID_PARAMETER, |
| 643 | "Answerer must be passive when offerer is active"); |
| 644 | } |
| 645 | break; |
| 646 | case CONNECTIONROLE_PASSIVE: |
| 647 | if (local_connection_role != CONNECTIONROLE_ACTIVE) { |
| 648 | return webrtc::RTCError( |
| 649 | webrtc::RTCErrorType::INVALID_PARAMETER, |
| 650 | "Answerer must be active when offerer is passive"); |
| 651 | } |
| 652 | break; |
| 653 | default: |
Artem Titov | d325196 | 2021-11-15 15:57:07 | [diff] [blame] | 654 | RTC_DCHECK_NOTREACHED(); |
Harald Alvestrand | efece42 | 2021-08-19 09:12:51 | [diff] [blame] | 655 | break; |
| 656 | } |
| 657 | } else { |
| 658 | if ((*current_dtls_role == rtc::SSL_CLIENT && |
| 659 | remote_connection_role == CONNECTIONROLE_ACTIVE) || |
| 660 | (*current_dtls_role == rtc::SSL_SERVER && |
| 661 | remote_connection_role == CONNECTIONROLE_PASSIVE)) { |
| 662 | return webrtc::RTCError( |
| 663 | webrtc::RTCErrorType::INVALID_PARAMETER, |
| 664 | "Offerer must use current negotiated role for " |
| 665 | "setup attribute."); |
| 666 | } |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 667 | } |
| 668 | } |
| 669 | |
| 670 | if (local_connection_role == CONNECTIONROLE_ACTIVE || |
| 671 | local_connection_role == CONNECTIONROLE_PASSIVE) { |
| 672 | is_remote_server = (local_connection_role == CONNECTIONROLE_ACTIVE); |
| 673 | } else { |
| 674 | return webrtc::RTCError( |
| 675 | webrtc::RTCErrorType::INVALID_PARAMETER, |
| 676 | "Answerer must use either active or passive value " |
| 677 | "for setup attribute."); |
| 678 | } |
| 679 | |
| 680 | // If local is passive, local will act as server. |
| 681 | } |
| 682 | |
Mirko Bonadei | 05cf6be | 2019-01-31 20:38:12 | [diff] [blame] | 683 | *negotiated_dtls_role = |
| 684 | (is_remote_server ? rtc::SSL_CLIENT : rtc::SSL_SERVER); |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 685 | return webrtc::RTCError::OK(); |
| 686 | } |
| 687 | |
Zhi Huang | 365381f | 2018-04-13 23:44:34 | [diff] [blame] | 688 | bool JsepTransport::GetTransportStats(DtlsTransportInternal* dtls_transport, |
Niels Möller | 6a48a1d | 2021-02-05 11:34:14 | [diff] [blame] | 689 | int component, |
Zhi Huang | 365381f | 2018-04-13 23:44:34 | [diff] [blame] | 690 | TransportStats* stats) { |
Harald Alvestrand | 78a5e96 | 2019-04-03 08:42:39 | [diff] [blame] | 691 | RTC_DCHECK_RUN_ON(network_thread_); |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 692 | RTC_DCHECK(dtls_transport); |
| 693 | TransportChannelStats substats; |
Niels Möller | 6a48a1d | 2021-02-05 11:34:14 | [diff] [blame] | 694 | substats.component = component; |
Harald Alvestrand | 5cb7807 | 2019-10-28 08:51:17 | [diff] [blame] | 695 | dtls_transport->GetSslVersionBytes(&substats.ssl_version_bytes); |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 696 | dtls_transport->GetSrtpCryptoSuite(&substats.srtp_crypto_suite); |
| 697 | dtls_transport->GetSslCipherSuite(&substats.ssl_cipher_suite); |
| 698 | substats.dtls_state = dtls_transport->dtls_state(); |
Philipp Hancke | 69c1df2 | 2022-04-22 13:46:24 | [diff] [blame] | 699 | rtc::SSLRole dtls_role; |
| 700 | if (dtls_transport->GetDtlsRole(&dtls_role)) { |
| 701 | substats.dtls_role = dtls_role; |
| 702 | } |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 703 | if (!dtls_transport->ice_transport()->GetStats( |
Jonas Oreland | 149dc72 | 2019-08-28 06:10:27 | [diff] [blame] | 704 | &substats.ice_transport_stats)) { |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 705 | return false; |
| 706 | } |
Philipp Hancke | 36e4dd2 | 2023-09-28 09:02:21 | [diff] [blame] | 707 | substats.ssl_peer_signature_algorithm = |
| 708 | dtls_transport->GetSslPeerSignatureAlgorithm(); |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 709 | stats->channel_stats.push_back(substats); |
| 710 | return true; |
| 711 | } |
| 712 | |
Zhi Huang | e818b6e | 2018-02-22 23:26:27 | [diff] [blame] | 713 | } // namespace cricket |