aboutsummaryrefslogtreecommitdiffstats
path: root/src/eap_server/eap_sim.c
diff options
context:
space:
mode:
authorJouni Malinen <j@w1.fi>2007-12-16 04:01:26 (GMT)
committerJouni Malinen <j@w1.fi>2007-12-16 04:01:26 (GMT)
commit4d61a4709d188656fe54324b7811a75eb4eb535a (patch)
tree59b8c2c849029be1f2aa929c021117184e956cf4 /src/eap_server/eap_sim.c
parentacf92247025eafd9c35ed53148bbe9cb11ac4096 (diff)
downloadhostap-history-4d61a4709d188656fe54324b7811a75eb4eb535a.zip
hostap-history-4d61a4709d188656fe54324b7811a75eb4eb535a.tar.gz
hostap-history-4d61a4709d188656fe54324b7811a75eb4eb535a.tar.bz2
Added 'struct wpabuf' data structure for presenting data buffers.
This can be used to clean up various code areas that are storing a pointer to an allocated buffer and a length field separately. wpabuf.h defines number of helper functions to make it simpler to use wpabuf. In addition, this adds some bounds checking to buffer writes since wpabuf_put*() functions will abort the program should something try to write beyond the end of a buffer. This commit is also changing EAP and EAPOL interfaces to use struct wpabuf which makes the number of changes quite large. This will, obviously, also mean that 0.6.x branch is not anymore source code compatible with 0.5.x as far as EAP method interface is concerned.
Diffstat (limited to 'src/eap_server/eap_sim.c')
-rw-r--r--src/eap_server/eap_sim.c77
1 files changed, 38 insertions, 39 deletions
diff --git a/src/eap_server/eap_sim.c b/src/eap_server/eap_sim.c
index 0700e5c..41ff7a2 100644
--- a/src/eap_server/eap_sim.c
+++ b/src/eap_server/eap_sim.c
@@ -95,8 +95,8 @@ static void eap_sim_reset(struct eap_sm *sm, void *priv)
}
-static u8 * eap_sim_build_start(struct eap_sm *sm, struct eap_sim_data *data,
- int id, size_t *reqDataLen)
+static struct wpabuf * eap_sim_build_start(struct eap_sm *sm,
+ struct eap_sim_data *data, u8 id)
{
struct eap_sim_msg *msg;
u8 ver[2];
@@ -114,7 +114,7 @@ static u8 * eap_sim_build_start(struct eap_sm *sm, struct eap_sim_data *data,
ver[1] = EAP_SIM_VERSION;
eap_sim_msg_add(msg, EAP_SIM_AT_VERSION_LIST, sizeof(ver),
ver, sizeof(ver));
- return eap_sim_msg_finish(msg, reqDataLen, NULL, NULL, 0);
+ return eap_sim_msg_finish(msg, NULL, NULL, 0);
}
@@ -182,9 +182,9 @@ static int eap_sim_build_encr(struct eap_sm *sm, struct eap_sim_data *data,
}
-static u8 * eap_sim_build_challenge(struct eap_sm *sm,
- struct eap_sim_data *data,
- int id, size_t *reqDataLen)
+static struct wpabuf * eap_sim_build_challenge(struct eap_sm *sm,
+ struct eap_sim_data *data,
+ u8 id)
{
struct eap_sim_msg *msg;
@@ -202,14 +202,13 @@ static u8 * eap_sim_build_challenge(struct eap_sm *sm,
wpa_printf(MSG_DEBUG, " AT_MAC");
eap_sim_msg_add_mac(msg, EAP_SIM_AT_MAC);
- return eap_sim_msg_finish(msg, reqDataLen, data->k_aut, data->nonce_mt,
+ return eap_sim_msg_finish(msg, data->k_aut, data->nonce_mt,
EAP_SIM_NONCE_MT_LEN);
}
-static u8 * eap_sim_build_reauth(struct eap_sm *sm,
- struct eap_sim_data *data,
- int id, size_t *reqDataLen)
+static struct wpabuf * eap_sim_build_reauth(struct eap_sm *sm,
+ struct eap_sim_data *data, u8 id)
{
struct eap_sim_msg *msg;
@@ -236,22 +235,21 @@ static u8 * eap_sim_build_reauth(struct eap_sm *sm,
wpa_printf(MSG_DEBUG, " AT_MAC");
eap_sim_msg_add_mac(msg, EAP_SIM_AT_MAC);
- return eap_sim_msg_finish(msg, reqDataLen, data->k_aut, NULL, 0);
+ return eap_sim_msg_finish(msg, data->k_aut, NULL, 0);
}
-static u8 * eap_sim_buildReq(struct eap_sm *sm, void *priv, int id,
- size_t *reqDataLen)
+static struct wpabuf * eap_sim_buildReq(struct eap_sm *sm, void *priv, u8 id)
{
struct eap_sim_data *data = priv;
switch (data->state) {
case START:
- return eap_sim_build_start(sm, data, id, reqDataLen);
+ return eap_sim_build_start(sm, data, id);
case CHALLENGE:
- return eap_sim_build_challenge(sm, data, id, reqDataLen);
+ return eap_sim_build_challenge(sm, data, id);
case REAUTH:
- return eap_sim_build_reauth(sm, data, id, reqDataLen);
+ return eap_sim_build_reauth(sm, data, id);
default:
wpa_printf(MSG_DEBUG, "EAP-SIM: Unknown state %d in "
"buildReq", data->state);
@@ -262,15 +260,14 @@ static u8 * eap_sim_buildReq(struct eap_sm *sm, void *priv, int id,
static Boolean eap_sim_check(struct eap_sm *sm, void *priv,
- u8 *respData, size_t respDataLen)
+ struct wpabuf *respData)
{
struct eap_sim_data *data = priv;
const u8 *pos;
size_t len;
u8 subtype;
- pos = eap_hdr_validate(EAP_VENDOR_IETF, EAP_TYPE_SIM,
- respData, respDataLen, &len);
+ pos = eap_hdr_validate(EAP_VENDOR_IETF, EAP_TYPE_SIM, respData, &len);
if (pos == NULL || len < 3) {
wpa_printf(MSG_INFO, "EAP-SIM: Invalid frame");
return TRUE;
@@ -320,7 +317,7 @@ static int eap_sim_supported_ver(struct eap_sim_data *data, int version)
static void eap_sim_process_start(struct eap_sm *sm,
struct eap_sim_data *data,
- u8 *respData, size_t respDataLen,
+ struct wpabuf *respData,
struct eap_sim_attrs *attr)
{
const u8 *identity;
@@ -433,14 +430,14 @@ static void eap_sim_process_start(struct eap_sm *sm,
static void eap_sim_process_challenge(struct eap_sm *sm,
struct eap_sim_data *data,
- u8 *respData, size_t respDataLen,
+ struct wpabuf *respData,
struct eap_sim_attrs *attr)
{
const u8 *identity;
size_t identity_len;
if (attr->mac == NULL ||
- eap_sim_verify_mac(data->k_aut, respData, respDataLen, attr->mac,
+ eap_sim_verify_mac(data->k_aut, respData, attr->mac,
(u8 *) data->sres,
data->num_chal * EAP_SIM_SRES_LEN)) {
wpa_printf(MSG_WARNING, "EAP-SIM: Challenge message "
@@ -478,7 +475,7 @@ static void eap_sim_process_challenge(struct eap_sm *sm,
static void eap_sim_process_reauth(struct eap_sm *sm,
struct eap_sim_data *data,
- u8 *respData, size_t respDataLen,
+ struct wpabuf *respData,
struct eap_sim_attrs *attr)
{
struct eap_sim_attrs eattr;
@@ -487,8 +484,8 @@ static void eap_sim_process_reauth(struct eap_sm *sm,
size_t identity_len, id2_len;
if (attr->mac == NULL ||
- eap_sim_verify_mac(data->k_aut, respData, respDataLen, attr->mac,
- data->nonce_s, EAP_SIM_NONCE_S_LEN)) {
+ eap_sim_verify_mac(data->k_aut, respData, attr->mac, data->nonce_s,
+ EAP_SIM_NONCE_S_LEN)) {
wpa_printf(MSG_WARNING, "EAP-SIM: Re-authentication message "
"did not include valid AT_MAC");
goto fail;
@@ -564,7 +561,7 @@ fail:
static void eap_sim_process_client_error(struct eap_sm *sm,
struct eap_sim_data *data,
- u8 *respData, size_t respDataLen,
+ struct wpabuf *respData,
struct eap_sim_attrs *attr)
{
wpa_printf(MSG_DEBUG, "EAP-SIM: Client reported error %d",
@@ -574,40 +571,42 @@ static void eap_sim_process_client_error(struct eap_sm *sm,
static void eap_sim_process(struct eap_sm *sm, void *priv,
- u8 *respData, size_t respDataLen)
+ struct wpabuf *respData)
{
struct eap_sim_data *data = priv;
- struct eap_hdr *resp;
- u8 *pos, subtype;
+ const u8 *pos, *end;
+ u8 subtype;
size_t len;
struct eap_sim_attrs attr;
- resp = (struct eap_hdr *) respData;
- pos = (u8 *) (resp + 1);
- subtype = pos[1];
- len = be_to_host16(resp->length);
- pos += 4;
+ pos = eap_hdr_validate(EAP_VENDOR_IETF, EAP_TYPE_SIM, respData, &len);
+ if (pos == NULL || len < 3)
+ return;
+
+ end = pos + len;
+ subtype = *pos;
+ pos += 3;
- if (eap_sim_parse_attr(pos, respData + len, &attr, 0, 0)) {
+ if (eap_sim_parse_attr(pos, end, &attr, 0, 0)) {
wpa_printf(MSG_DEBUG, "EAP-SIM: Failed to parse attributes");
eap_sim_state(data, FAILURE);
return;
}
if (subtype == EAP_SIM_SUBTYPE_CLIENT_ERROR) {
- eap_sim_process_client_error(sm, data, respData, len, &attr);
+ eap_sim_process_client_error(sm, data, respData, &attr);
return;
}
switch (data->state) {
case START:
- eap_sim_process_start(sm, data, respData, len, &attr);
+ eap_sim_process_start(sm, data, respData, &attr);
break;
case CHALLENGE:
- eap_sim_process_challenge(sm, data, respData, len, &attr);
+ eap_sim_process_challenge(sm, data, respData, &attr);
break;
case REAUTH:
- eap_sim_process_reauth(sm, data, respData, len, &attr);
+ eap_sim_process_reauth(sm, data, respData, &attr);
break;
default:
wpa_printf(MSG_DEBUG, "EAP-SIM: Unknown state %d in "