| Line | Count | Source (jump to first uncovered line) | 
| 1 |  | /* | 
| 2 |  |  * Copyright (c) 2018-2022 Yubico AB. All rights reserved. | 
| 3 |  |  * Use of this source code is governed by a BSD-style | 
| 4 |  |  * license that can be found in the LICENSE file. | 
| 5 |  |  * SPDX-License-Identifier: BSD-2-Clause | 
| 6 |  |  */ | 
| 7 |  |  | 
| 8 |  | #include "fido.h" | 
| 9 |  | #include "packed.h" | 
| 10 |  |  | 
| 11 |  | PACKED_TYPE(frame_t, | 
| 12 |  | struct frame { | 
| 13 |  |         uint32_t cid; /* channel id */ | 
| 14 |  |         union { | 
| 15 |  |                 uint8_t type; | 
| 16 |  |                 struct { | 
| 17 |  |                         uint8_t cmd; | 
| 18 |  |                         uint8_t bcnth; | 
| 19 |  |                         uint8_t bcntl; | 
| 20 |  |                         uint8_t data[CTAP_MAX_REPORT_LEN - CTAP_INIT_HEADER_LEN]; | 
| 21 |  |                 } init; | 
| 22 |  |                 struct { | 
| 23 |  |                         uint8_t seq; | 
| 24 |  |                         uint8_t data[CTAP_MAX_REPORT_LEN - CTAP_CONT_HEADER_LEN]; | 
| 25 |  |                 } cont; | 
| 26 |  |         } body; | 
| 27 |  | }) | 
| 28 |  |  | 
| 29 |  | #ifndef MIN | 
| 30 | 314k | #define MIN(x, y) ((x) > (y) ? (y) : (x)) | 
| 31 |  | #endif | 
| 32 |  |  | 
| 33 |  | static int | 
| 34 |  | tx_pkt(fido_dev_t *d, const void *pkt, size_t len, int *ms) | 
| 35 | 319k | { | 
| 36 | 319k |         struct timespec ts; | 
| 37 | 319k |         int n; | 
| 38 |  |  | 
| 39 | 319k |         if (fido_time_now(&ts) != 0) | 
| 40 | 780 |                 return (-1); | 
| 41 |  |  | 
| 42 | 318k |         n = d->io.write(d->io_handle, pkt, len); | 
| 43 |  |  | 
| 44 | 318k |         if (fido_time_delta(&ts, ms) != 0) | 
| 45 | 1.50k |                 return (-1); | 
| 46 |  |  | 
| 47 | 317k |         return (n); | 
| 48 | 318k | } | 
| 49 |  |  | 
| 50 |  | static int | 
| 51 |  | tx_empty(fido_dev_t *d, uint8_t cmd, int *ms) | 
| 52 | 4.83k | { | 
| 53 | 4.83k |         struct frame    *fp; | 
| 54 | 4.83k |         unsigned char    pkt[sizeof(*fp) + 1]; | 
| 55 | 4.83k |         const size_t     len = d->tx_len + 1; | 
| 56 | 4.83k |         int              n; | 
| 57 |  |  | 
| 58 | 4.83k |         memset(&pkt, 0, sizeof(pkt)); | 
| 59 | 4.83k |         fp = (struct frame *)(pkt + 1); | 
| 60 | 4.83k |         fp->cid = d->cid; | 
| 61 | 4.83k |         fp->body.init.cmd = CTAP_FRAME_INIT | cmd; | 
| 62 |  |  | 
| 63 | 4.83k |         if (len > sizeof(pkt) || (n = tx_pkt(d, pkt, len, ms)) < 0 || | 
| 64 | 4.83k |             (size_t)n != len) | 
| 65 | 81 |                 return (-1); | 
| 66 |  |  | 
| 67 | 4.75k |         return (0); | 
| 68 | 4.83k | } | 
| 69 |  |  | 
| 70 |  | static size_t | 
| 71 |  | tx_preamble(fido_dev_t *d, uint8_t cmd, const void *buf, size_t count, int *ms) | 
| 72 | 181k | { | 
| 73 | 181k |         struct frame    *fp; | 
| 74 | 181k |         unsigned char    pkt[sizeof(*fp) + 1]; | 
| 75 | 181k |         const size_t     len = d->tx_len + 1; | 
| 76 | 181k |         int              n; | 
| 77 |  |  | 
| 78 | 181k |         if (d->tx_len - CTAP_INIT_HEADER_LEN > sizeof(fp->body.init.data)) | 
| 79 | 0 |                 return (0); | 
| 80 |  |  | 
| 81 | 181k |         memset(&pkt, 0, sizeof(pkt)); | 
| 82 | 181k |         fp = (struct frame *)(pkt + 1); | 
| 83 | 181k |         fp->cid = d->cid; | 
| 84 | 181k |         fp->body.init.cmd = CTAP_FRAME_INIT | cmd; | 
| 85 | 181k |         fp->body.init.bcnth = (count >> 8) & 0xff; | 
| 86 | 181k |         fp->body.init.bcntl = count & 0xff; | 
| 87 | 181k |         count = MIN(count, d->tx_len - CTAP_INIT_HEADER_LEN); | 
| 88 | 181k |         memcpy(&fp->body.init.data, buf, count); | 
| 89 |  |  | 
| 90 | 181k |         if (len > sizeof(pkt) || (n = tx_pkt(d, pkt, len, ms)) < 0 || | 
| 91 | 181k |             (size_t)n != len) | 
| 92 | 1.82k |                 return (0); | 
| 93 |  |  | 
| 94 | 179k |         return (count); | 
| 95 | 181k | } | 
| 96 |  |  | 
| 97 |  | static size_t | 
| 98 |  | tx_frame(fido_dev_t *d, uint8_t seq, const void *buf, size_t count, int *ms) | 
| 99 | 133k | { | 
| 100 | 133k |         struct frame    *fp; | 
| 101 | 133k |         unsigned char    pkt[sizeof(*fp) + 1]; | 
| 102 | 133k |         const size_t     len = d->tx_len + 1; | 
| 103 | 133k |         int              n; | 
| 104 |  |  | 
| 105 | 133k |         if (d->tx_len - CTAP_CONT_HEADER_LEN > sizeof(fp->body.cont.data)) | 
| 106 | 0 |                 return (0); | 
| 107 |  |  | 
| 108 | 133k |         memset(&pkt, 0, sizeof(pkt)); | 
| 109 | 133k |         fp = (struct frame *)(pkt + 1); | 
| 110 | 133k |         fp->cid = d->cid; | 
| 111 | 133k |         fp->body.cont.seq = seq; | 
| 112 | 133k |         count = MIN(count, d->tx_len - CTAP_CONT_HEADER_LEN); | 
| 113 | 133k |         memcpy(&fp->body.cont.data, buf, count); | 
| 114 |  |  | 
| 115 | 133k |         if (len > sizeof(pkt) || (n = tx_pkt(d, pkt, len, ms)) < 0 || | 
| 116 | 133k |             (size_t)n != len) | 
| 117 | 912 |                 return (0); | 
| 118 |  |  | 
| 119 | 132k |         return (count); | 
| 120 | 133k | } | 
| 121 |  |  | 
| 122 |  | static int | 
| 123 |  | tx(fido_dev_t *d, uint8_t cmd, const unsigned char *buf, size_t count, int *ms) | 
| 124 | 181k | { | 
| 125 | 181k |         size_t n, sent; | 
| 126 |  |  | 
| 127 | 181k |         if ((sent = tx_preamble(d, cmd, buf, count, ms)) == 0) { | 
| 128 | 1.82k |                 fido_log_debug("%s: tx_preamble", __func__); | 
| 129 | 1.82k |                 return (-1); | 
| 130 | 1.82k |         } | 
| 131 |  |  | 
| 132 | 312k |         for (uint8_t seq = 0; sent < count; sent += n) { | 
| 133 | 133k |                 if (seq & 0x80) { | 
| 134 | 90 |                         fido_log_debug("%s: seq & 0x80", __func__); | 
| 135 | 90 |                         return (-1); | 
| 136 | 90 |                 } | 
| 137 | 133k |                 if ((n = tx_frame(d, seq++, buf + sent, count - sent, | 
| 138 | 133k |                     ms)) == 0) { | 
| 139 | 912 |                         fido_log_debug("%s: tx_frame", __func__); | 
| 140 | 912 |                         return (-1); | 
| 141 | 912 |                 } | 
| 142 | 133k |         } | 
| 143 |  |  | 
| 144 | 178k |         return (0); | 
| 145 | 179k | } | 
| 146 |  |  | 
| 147 |  | static int | 
| 148 |  | transport_tx(fido_dev_t *d, uint8_t cmd, const void *buf, size_t count, int *ms) | 
| 149 | 4.89k | { | 
| 150 | 4.89k |         struct timespec ts; | 
| 151 | 4.89k |         int n; | 
| 152 |  |  | 
| 153 | 4.89k |         if (fido_time_now(&ts) != 0) | 
| 154 | 43 |                 return (-1); | 
| 155 |  |  | 
| 156 | 4.85k |         n = d->transport.tx(d, cmd, buf, count); | 
| 157 |  |  | 
| 158 | 4.85k |         if (fido_time_delta(&ts, ms) != 0) | 
| 159 | 57 |                 return (-1); | 
| 160 |  |  | 
| 161 | 4.79k |         return (n); | 
| 162 | 4.85k | } | 
| 163 |  |  | 
| 164 |  | int | 
| 165 |  | fido_tx(fido_dev_t *d, uint8_t cmd, const void *buf, size_t count, int *ms) | 
| 166 | 191k | { | 
| 167 | 191k |         fido_log_debug("%s: dev=%p, cmd=0x%02x", __func__, (void *)d, cmd); | 
| 168 | 191k |         fido_log_xxd(buf, count, "%s", __func__); | 
| 169 |  |  | 
| 170 | 191k |         if (d->transport.tx != NULL) | 
| 171 | 4.89k |                 return (transport_tx(d, cmd, buf, count, ms)); | 
| 172 | 186k |         if (d->io_handle == NULL || d->io.write == NULL || count > UINT16_MAX) { | 
| 173 | 42 |                 fido_log_debug("%s: invalid argument", __func__); | 
| 174 | 42 |                 return (-1); | 
| 175 | 42 |         } | 
| 176 |  |  | 
| 177 | 186k |         return (count == 0 ? tx_empty(d, cmd, ms) : tx(d, cmd, buf, count, ms)); | 
| 178 | 186k | } | 
| 179 |  |  | 
| 180 |  | static int | 
| 181 |  | rx_frame(fido_dev_t *d, struct frame *fp, int *ms) | 
| 182 | 372k | { | 
| 183 | 372k |         struct timespec ts; | 
| 184 | 372k |         int n; | 
| 185 |  |  | 
| 186 | 372k |         memset(fp, 0, sizeof(*fp)); | 
| 187 |  |  | 
| 188 | 372k |         if (fido_time_now(&ts) != 0) | 
| 189 | 512 |                 return (-1); | 
| 190 |  |  | 
| 191 | 372k |         if (d->rx_len > sizeof(*fp) || (n = d->io.read(d->io_handle, | 
| 192 | 372k |             (unsigned char *)fp, d->rx_len, *ms)) < 0 || (size_t)n != d->rx_len) | 
| 193 | 68.9k |                 return (-1); | 
| 194 |  |  | 
| 195 | 303k |         return (fido_time_delta(&ts, ms)); | 
| 196 | 372k | } | 
| 197 |  |  | 
| 198 |  | static int | 
| 199 |  | rx_preamble(fido_dev_t *d, uint8_t cmd, struct frame *fp, int *ms) | 
| 200 | 180k | { | 
| 201 | 186k |         do { | 
| 202 | 186k |                 if (rx_frame(d, fp, ms) < 0) | 
| 203 | 66.6k |                         return (-1); | 
| 204 | 119k | #ifdef FIDO_FUZZ | 
| 205 | 119k |                 fp->cid = d->cid; | 
| 206 | 119k | #endif | 
| 207 | 119k |         } while (fp->cid != d->cid || (fp->cid == d->cid && | 
| 208 | 119k |             fp->body.init.cmd == (CTAP_FRAME_INIT | CTAP_KEEPALIVE))); | 
| 209 |  |  | 
| 210 | 114k |         if (d->rx_len > sizeof(*fp)) | 
| 211 | 0 |                 return (-1); | 
| 212 |  |  | 
| 213 | 114k |         fido_log_xxd(fp, d->rx_len, "%s", __func__); | 
| 214 | 114k | #ifdef FIDO_FUZZ | 
| 215 | 114k |         fp->body.init.cmd = (CTAP_FRAME_INIT | cmd); | 
| 216 | 114k | #endif | 
| 217 |  |  | 
| 218 | 114k |         if (fp->cid != d->cid || fp->body.init.cmd != (CTAP_FRAME_INIT | cmd)) { | 
| 219 | 0 |                 fido_log_debug("%s: cid (0x%x, 0x%x), cmd (0x%02x, 0x%02x)", | 
| 220 | 0 |                     __func__, fp->cid, d->cid, fp->body.init.cmd, cmd); | 
| 221 | 0 |                 return (-1); | 
| 222 | 0 |         } | 
| 223 |  |  | 
| 224 | 114k |         return (0); | 
| 225 | 114k | } | 
| 226 |  |  | 
| 227 |  | static int | 
| 228 |  | rx(fido_dev_t *d, uint8_t cmd, unsigned char *buf, size_t count, int *ms) | 
| 229 | 180k | { | 
| 230 | 180k |         struct frame f; | 
| 231 | 180k |         size_t r, payload_len, init_data_len, cont_data_len; | 
| 232 |  |  | 
| 233 | 180k |         if (d->rx_len <= CTAP_INIT_HEADER_LEN || | 
| 234 | 180k |             d->rx_len <= CTAP_CONT_HEADER_LEN) | 
| 235 | 0 |                 return (-1); | 
| 236 |  |  | 
| 237 | 180k |         init_data_len = d->rx_len - CTAP_INIT_HEADER_LEN; | 
| 238 | 180k |         cont_data_len = d->rx_len - CTAP_CONT_HEADER_LEN; | 
| 239 |  |  | 
| 240 | 180k |         if (init_data_len > sizeof(f.body.init.data) || | 
| 241 | 180k |             cont_data_len > sizeof(f.body.cont.data)) | 
| 242 | 0 |                 return (-1); | 
| 243 |  |  | 
| 244 | 180k |         if (rx_preamble(d, cmd, &f, ms) < 0) { | 
| 245 | 66.6k |                 fido_log_debug("%s: rx_preamble", __func__); | 
| 246 | 66.6k |                 return (-1); | 
| 247 | 66.6k |         } | 
| 248 |  |  | 
| 249 | 114k |         payload_len = (size_t)((f.body.init.bcnth << 8) | f.body.init.bcntl); | 
| 250 | 114k |         fido_log_debug("%s: payload_len=%zu", __func__, payload_len); | 
| 251 |  |  | 
| 252 | 114k |         if (count < payload_len) { | 
| 253 | 11.2k |                 fido_log_debug("%s: count < payload_len", __func__); | 
| 254 | 11.2k |                 return (-1); | 
| 255 | 11.2k |         } | 
| 256 |  |  | 
| 257 | 102k |         if (payload_len < init_data_len) { | 
| 258 | 55.7k |                 memcpy(buf, f.body.init.data, payload_len); | 
| 259 | 55.7k |                 return ((int)payload_len); | 
| 260 | 55.7k |         } | 
| 261 |  |  | 
| 262 | 47.0k |         memcpy(buf, f.body.init.data, init_data_len); | 
| 263 | 47.0k |         r = init_data_len; | 
| 264 |  |  | 
| 265 | 230k |         for (int seq = 0; r < payload_len; seq++) { | 
| 266 | 186k |                 if (rx_frame(d, &f, ms) < 0) { | 
| 267 | 3.34k |                         fido_log_debug("%s: rx_frame", __func__); | 
| 268 | 3.34k |                         return (-1); | 
| 269 | 3.34k |                 } | 
| 270 |  |  | 
| 271 | 183k |                 fido_log_xxd(&f, d->rx_len, "%s", __func__); | 
| 272 | 183k | #ifdef FIDO_FUZZ | 
| 273 | 183k |                 f.cid = d->cid; | 
| 274 | 183k |                 f.body.cont.seq = (uint8_t)seq; | 
| 275 | 183k | #endif | 
| 276 |  |  | 
| 277 | 183k |                 if (f.cid != d->cid || f.body.cont.seq != seq) { | 
| 278 | 21 |                         fido_log_debug("%s: cid (0x%x, 0x%x), seq (%d, %d)", | 
| 279 | 21 |                             __func__, f.cid, d->cid, f.body.cont.seq, seq); | 
| 280 | 21 |                         return (-1); | 
| 281 | 21 |                 } | 
| 282 |  |  | 
| 283 | 183k |                 if (payload_len - r > cont_data_len) { | 
| 284 | 143k |                         memcpy(buf + r, f.body.cont.data, cont_data_len); | 
| 285 | 143k |                         r += cont_data_len; | 
| 286 | 143k |                 } else { | 
| 287 | 39.9k |                         memcpy(buf + r, f.body.cont.data, payload_len - r); | 
| 288 | 39.9k |                         r += payload_len - r; /* break */ | 
| 289 | 39.9k |                 } | 
| 290 | 183k |         } | 
| 291 |  |  | 
| 292 | 43.7k |         return ((int)r); | 
| 293 | 47.0k | } | 
| 294 |  |  | 
| 295 |  | static int | 
| 296 |  | transport_rx(fido_dev_t *d, uint8_t cmd, void *buf, size_t count, int *ms) | 
| 297 | 4.35k | { | 
| 298 | 4.35k |         struct timespec ts; | 
| 299 | 4.35k |         int n; | 
| 300 |  |  | 
| 301 | 4.35k |         if (fido_time_now(&ts) != 0) | 
| 302 | 47 |                 return (-1); | 
| 303 |  |  | 
| 304 | 4.30k |         n = d->transport.rx(d, cmd, buf, count, *ms); | 
| 305 |  |  | 
| 306 | 4.30k |         if (fido_time_delta(&ts, ms) != 0) | 
| 307 | 65 |                 return (-1); | 
| 308 |  |  | 
| 309 | 4.23k |         return (n); | 
| 310 | 4.30k | } | 
| 311 |  |  | 
| 312 |  | int | 
| 313 |  | fido_rx(fido_dev_t *d, uint8_t cmd, void *buf, size_t count, int *ms) | 
| 314 | 185k | { | 
| 315 | 185k |         int n; | 
| 316 |  |  | 
| 317 | 185k |         fido_log_debug("%s: dev=%p, cmd=0x%02x, ms=%d", __func__, (void *)d, | 
| 318 | 185k |             cmd, *ms); | 
| 319 |  |  | 
| 320 | 185k |         if (d->transport.rx != NULL) | 
| 321 | 4.35k |                 return (transport_rx(d, cmd, buf, count, ms)); | 
| 322 | 180k |         if (d->io_handle == NULL || d->io.read == NULL || count > UINT16_MAX) { | 
| 323 | 0 |                 fido_log_debug("%s: invalid argument", __func__); | 
| 324 | 0 |                 return (-1); | 
| 325 | 0 |         } | 
| 326 | 180k |         if ((n = rx(d, cmd, buf, count, ms)) >= 0) | 
| 327 | 99.4k |                 fido_log_xxd(buf, (size_t)n, "%s", __func__); | 
| 328 |  |  | 
| 329 | 180k |         return (n); | 
| 330 | 180k | } | 
| 331 |  |  | 
| 332 |  | int | 
| 333 |  | fido_rx_cbor_status(fido_dev_t *d, int *ms) | 
| 334 | 3.95k | { | 
| 335 | 3.95k |         unsigned char   *msg; | 
| 336 | 3.95k |         int              msglen; | 
| 337 | 3.95k |         int              r; | 
| 338 |  |  | 
| 339 | 3.95k |         if ((msg = malloc(FIDO_MAXMSG)) == NULL) { | 
| 340 | 25 |                 r = FIDO_ERR_INTERNAL; | 
| 341 | 25 |                 goto out; | 
| 342 | 25 |         } | 
| 343 |  |  | 
| 344 | 3.93k |         if ((msglen = fido_rx(d, CTAP_CMD_CBOR, msg, FIDO_MAXMSG, ms)) < 0 || | 
| 345 | 3.93k |             (size_t)msglen < 1) { | 
| 346 | 2.61k |                 fido_log_debug("%s: fido_rx", __func__); | 
| 347 | 2.61k |                 r = FIDO_ERR_RX; | 
| 348 | 2.61k |                 goto out; | 
| 349 | 2.61k |         } | 
| 350 |  |  | 
| 351 | 1.32k |         r = msg[0]; | 
| 352 | 3.95k | out: | 
| 353 | 3.95k |         freezero(msg, FIDO_MAXMSG); | 
| 354 |  |  | 
| 355 | 3.95k |         return (r); | 
| 356 | 1.32k | } |