wps_attr_parse.c 14 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628
  1. /*
  2. * Wi-Fi Protected Setup - attribute parsing
  3. * Copyright (c) 2008, Jouni Malinen <j@w1.fi>
  4. *
  5. * This software may be distributed under the terms of the BSD license.
  6. * See README for more details.
  7. */
  8. #include "includes.h"
  9. #include "common.h"
  10. #include "wps_defs.h"
  11. #include "wps_attr_parse.h"
  12. #ifndef CONFIG_WPS_STRICT
  13. #define WPS_WORKAROUNDS
  14. #endif /* CONFIG_WPS_STRICT */
  15. static int wps_set_vendor_ext_wfa_subelem(struct wps_parse_attr *attr,
  16. u8 id, u8 len, const u8 *pos)
  17. {
  18. wpa_printf(MSG_EXCESSIVE, "WPS: WFA subelement id=%u len=%u",
  19. id, len);
  20. switch (id) {
  21. case WFA_ELEM_VERSION2:
  22. if (len != 1) {
  23. wpa_printf(MSG_DEBUG, "WPS: Invalid Version2 length "
  24. "%u", len);
  25. return -1;
  26. }
  27. attr->version2 = pos;
  28. break;
  29. case WFA_ELEM_AUTHORIZEDMACS:
  30. attr->authorized_macs = pos;
  31. attr->authorized_macs_len = len;
  32. break;
  33. case WFA_ELEM_NETWORK_KEY_SHAREABLE:
  34. if (len != 1) {
  35. wpa_printf(MSG_DEBUG, "WPS: Invalid Network Key "
  36. "Shareable length %u", len);
  37. return -1;
  38. }
  39. attr->network_key_shareable = pos;
  40. break;
  41. case WFA_ELEM_REQUEST_TO_ENROLL:
  42. if (len != 1) {
  43. wpa_printf(MSG_DEBUG, "WPS: Invalid Request to Enroll "
  44. "length %u", len);
  45. return -1;
  46. }
  47. attr->request_to_enroll = pos;
  48. break;
  49. case WFA_ELEM_SETTINGS_DELAY_TIME:
  50. if (len != 1) {
  51. wpa_printf(MSG_DEBUG, "WPS: Invalid Settings Delay "
  52. "Time length %u", len);
  53. return -1;
  54. }
  55. attr->settings_delay_time = pos;
  56. break;
  57. case WFA_ELEM_REGISTRAR_CONFIGURATION_METHODS:
  58. if (len != 2) {
  59. wpa_printf(MSG_DEBUG, "WPS: Invalid Registrar Configuration Methods length %u",
  60. len);
  61. return -1;
  62. }
  63. attr->registrar_configuration_methods = pos;
  64. break;
  65. default:
  66. wpa_printf(MSG_MSGDUMP, "WPS: Skipped unknown WFA Vendor "
  67. "Extension subelement %u", id);
  68. break;
  69. }
  70. return 0;
  71. }
  72. static int wps_parse_vendor_ext_wfa(struct wps_parse_attr *attr, const u8 *pos,
  73. u16 len)
  74. {
  75. const u8 *end = pos + len;
  76. u8 id, elen;
  77. while (pos + 2 <= end) {
  78. id = *pos++;
  79. elen = *pos++;
  80. if (pos + elen > end)
  81. break;
  82. if (wps_set_vendor_ext_wfa_subelem(attr, id, elen, pos) < 0)
  83. return -1;
  84. pos += elen;
  85. }
  86. return 0;
  87. }
  88. static int wps_parse_vendor_ext(struct wps_parse_attr *attr, const u8 *pos,
  89. u16 len)
  90. {
  91. u32 vendor_id;
  92. if (len < 3) {
  93. wpa_printf(MSG_DEBUG, "WPS: Skip invalid Vendor Extension");
  94. return 0;
  95. }
  96. vendor_id = WPA_GET_BE24(pos);
  97. switch (vendor_id) {
  98. case WPS_VENDOR_ID_WFA:
  99. return wps_parse_vendor_ext_wfa(attr, pos + 3, len - 3);
  100. }
  101. /* Handle unknown vendor extensions */
  102. wpa_printf(MSG_MSGDUMP, "WPS: Unknown Vendor Extension (Vendor ID %u)",
  103. vendor_id);
  104. if (len > WPS_MAX_VENDOR_EXT_LEN) {
  105. wpa_printf(MSG_DEBUG, "WPS: Too long Vendor Extension (%u)",
  106. len);
  107. return -1;
  108. }
  109. if (attr->num_vendor_ext >= MAX_WPS_PARSE_VENDOR_EXT) {
  110. wpa_printf(MSG_DEBUG, "WPS: Skipped Vendor Extension "
  111. "attribute (max %d vendor extensions)",
  112. MAX_WPS_PARSE_VENDOR_EXT);
  113. return -1;
  114. }
  115. attr->vendor_ext[attr->num_vendor_ext] = pos;
  116. attr->vendor_ext_len[attr->num_vendor_ext] = len;
  117. attr->num_vendor_ext++;
  118. return 0;
  119. }
  120. static int wps_set_attr(struct wps_parse_attr *attr, u16 type,
  121. const u8 *pos, u16 len)
  122. {
  123. switch (type) {
  124. case ATTR_VERSION:
  125. if (len != 1) {
  126. wpa_printf(MSG_DEBUG, "WPS: Invalid Version length %u",
  127. len);
  128. return -1;
  129. }
  130. attr->version = pos;
  131. break;
  132. case ATTR_MSG_TYPE:
  133. if (len != 1) {
  134. wpa_printf(MSG_DEBUG, "WPS: Invalid Message Type "
  135. "length %u", len);
  136. return -1;
  137. }
  138. attr->msg_type = pos;
  139. break;
  140. case ATTR_ENROLLEE_NONCE:
  141. if (len != WPS_NONCE_LEN) {
  142. wpa_printf(MSG_DEBUG, "WPS: Invalid Enrollee Nonce "
  143. "length %u", len);
  144. return -1;
  145. }
  146. attr->enrollee_nonce = pos;
  147. break;
  148. case ATTR_REGISTRAR_NONCE:
  149. if (len != WPS_NONCE_LEN) {
  150. wpa_printf(MSG_DEBUG, "WPS: Invalid Registrar Nonce "
  151. "length %u", len);
  152. return -1;
  153. }
  154. attr->registrar_nonce = pos;
  155. break;
  156. case ATTR_UUID_E:
  157. if (len != WPS_UUID_LEN) {
  158. wpa_printf(MSG_DEBUG, "WPS: Invalid UUID-E length %u",
  159. len);
  160. return -1;
  161. }
  162. attr->uuid_e = pos;
  163. break;
  164. case ATTR_UUID_R:
  165. if (len != WPS_UUID_LEN) {
  166. wpa_printf(MSG_DEBUG, "WPS: Invalid UUID-R length %u",
  167. len);
  168. return -1;
  169. }
  170. attr->uuid_r = pos;
  171. break;
  172. case ATTR_AUTH_TYPE_FLAGS:
  173. if (len != 2) {
  174. wpa_printf(MSG_DEBUG, "WPS: Invalid Authentication "
  175. "Type Flags length %u", len);
  176. return -1;
  177. }
  178. attr->auth_type_flags = pos;
  179. break;
  180. case ATTR_ENCR_TYPE_FLAGS:
  181. if (len != 2) {
  182. wpa_printf(MSG_DEBUG, "WPS: Invalid Encryption Type "
  183. "Flags length %u", len);
  184. return -1;
  185. }
  186. attr->encr_type_flags = pos;
  187. break;
  188. case ATTR_CONN_TYPE_FLAGS:
  189. if (len != 1) {
  190. wpa_printf(MSG_DEBUG, "WPS: Invalid Connection Type "
  191. "Flags length %u", len);
  192. return -1;
  193. }
  194. attr->conn_type_flags = pos;
  195. break;
  196. case ATTR_CONFIG_METHODS:
  197. if (len != 2) {
  198. wpa_printf(MSG_DEBUG, "WPS: Invalid Config Methods "
  199. "length %u", len);
  200. return -1;
  201. }
  202. attr->config_methods = pos;
  203. break;
  204. case ATTR_SELECTED_REGISTRAR_CONFIG_METHODS:
  205. if (len != 2) {
  206. wpa_printf(MSG_DEBUG, "WPS: Invalid Selected "
  207. "Registrar Config Methods length %u", len);
  208. return -1;
  209. }
  210. attr->sel_reg_config_methods = pos;
  211. break;
  212. case ATTR_PRIMARY_DEV_TYPE:
  213. if (len != WPS_DEV_TYPE_LEN) {
  214. wpa_printf(MSG_DEBUG, "WPS: Invalid Primary Device "
  215. "Type length %u", len);
  216. return -1;
  217. }
  218. attr->primary_dev_type = pos;
  219. break;
  220. case ATTR_RF_BANDS:
  221. if (len != 1) {
  222. wpa_printf(MSG_DEBUG, "WPS: Invalid RF Bands length "
  223. "%u", len);
  224. return -1;
  225. }
  226. attr->rf_bands = pos;
  227. break;
  228. case ATTR_ASSOC_STATE:
  229. if (len != 2) {
  230. wpa_printf(MSG_DEBUG, "WPS: Invalid Association State "
  231. "length %u", len);
  232. return -1;
  233. }
  234. attr->assoc_state = pos;
  235. break;
  236. case ATTR_CONFIG_ERROR:
  237. if (len != 2) {
  238. wpa_printf(MSG_DEBUG, "WPS: Invalid Configuration "
  239. "Error length %u", len);
  240. return -1;
  241. }
  242. attr->config_error = pos;
  243. break;
  244. case ATTR_DEV_PASSWORD_ID:
  245. if (len != 2) {
  246. wpa_printf(MSG_DEBUG, "WPS: Invalid Device Password "
  247. "ID length %u", len);
  248. return -1;
  249. }
  250. attr->dev_password_id = pos;
  251. break;
  252. case ATTR_OOB_DEVICE_PASSWORD:
  253. if (len < WPS_OOB_PUBKEY_HASH_LEN + 2 ||
  254. len > WPS_OOB_PUBKEY_HASH_LEN + 2 +
  255. WPS_OOB_DEVICE_PASSWORD_LEN ||
  256. (len < WPS_OOB_PUBKEY_HASH_LEN + 2 +
  257. WPS_OOB_DEVICE_PASSWORD_MIN_LEN &&
  258. WPA_GET_BE16(pos + WPS_OOB_PUBKEY_HASH_LEN) !=
  259. DEV_PW_NFC_CONNECTION_HANDOVER)) {
  260. wpa_printf(MSG_DEBUG, "WPS: Invalid OOB Device "
  261. "Password length %u", len);
  262. return -1;
  263. }
  264. attr->oob_dev_password = pos;
  265. attr->oob_dev_password_len = len;
  266. break;
  267. case ATTR_OS_VERSION:
  268. if (len != 4) {
  269. wpa_printf(MSG_DEBUG, "WPS: Invalid OS Version length "
  270. "%u", len);
  271. return -1;
  272. }
  273. attr->os_version = pos;
  274. break;
  275. case ATTR_WPS_STATE:
  276. if (len != 1) {
  277. wpa_printf(MSG_DEBUG, "WPS: Invalid Wi-Fi Protected "
  278. "Setup State length %u", len);
  279. return -1;
  280. }
  281. attr->wps_state = pos;
  282. break;
  283. case ATTR_AUTHENTICATOR:
  284. if (len != WPS_AUTHENTICATOR_LEN) {
  285. wpa_printf(MSG_DEBUG, "WPS: Invalid Authenticator "
  286. "length %u", len);
  287. return -1;
  288. }
  289. attr->authenticator = pos;
  290. break;
  291. case ATTR_R_HASH1:
  292. if (len != WPS_HASH_LEN) {
  293. wpa_printf(MSG_DEBUG, "WPS: Invalid R-Hash1 length %u",
  294. len);
  295. return -1;
  296. }
  297. attr->r_hash1 = pos;
  298. break;
  299. case ATTR_R_HASH2:
  300. if (len != WPS_HASH_LEN) {
  301. wpa_printf(MSG_DEBUG, "WPS: Invalid R-Hash2 length %u",
  302. len);
  303. return -1;
  304. }
  305. attr->r_hash2 = pos;
  306. break;
  307. case ATTR_E_HASH1:
  308. if (len != WPS_HASH_LEN) {
  309. wpa_printf(MSG_DEBUG, "WPS: Invalid E-Hash1 length %u",
  310. len);
  311. return -1;
  312. }
  313. attr->e_hash1 = pos;
  314. break;
  315. case ATTR_E_HASH2:
  316. if (len != WPS_HASH_LEN) {
  317. wpa_printf(MSG_DEBUG, "WPS: Invalid E-Hash2 length %u",
  318. len);
  319. return -1;
  320. }
  321. attr->e_hash2 = pos;
  322. break;
  323. case ATTR_R_SNONCE1:
  324. if (len != WPS_SECRET_NONCE_LEN) {
  325. wpa_printf(MSG_DEBUG, "WPS: Invalid R-SNonce1 length "
  326. "%u", len);
  327. return -1;
  328. }
  329. attr->r_snonce1 = pos;
  330. break;
  331. case ATTR_R_SNONCE2:
  332. if (len != WPS_SECRET_NONCE_LEN) {
  333. wpa_printf(MSG_DEBUG, "WPS: Invalid R-SNonce2 length "
  334. "%u", len);
  335. return -1;
  336. }
  337. attr->r_snonce2 = pos;
  338. break;
  339. case ATTR_E_SNONCE1:
  340. if (len != WPS_SECRET_NONCE_LEN) {
  341. wpa_printf(MSG_DEBUG, "WPS: Invalid E-SNonce1 length "
  342. "%u", len);
  343. return -1;
  344. }
  345. attr->e_snonce1 = pos;
  346. break;
  347. case ATTR_E_SNONCE2:
  348. if (len != WPS_SECRET_NONCE_LEN) {
  349. wpa_printf(MSG_DEBUG, "WPS: Invalid E-SNonce2 length "
  350. "%u", len);
  351. return -1;
  352. }
  353. attr->e_snonce2 = pos;
  354. break;
  355. case ATTR_KEY_WRAP_AUTH:
  356. if (len != WPS_KWA_LEN) {
  357. wpa_printf(MSG_DEBUG, "WPS: Invalid Key Wrap "
  358. "Authenticator length %u", len);
  359. return -1;
  360. }
  361. attr->key_wrap_auth = pos;
  362. break;
  363. case ATTR_AUTH_TYPE:
  364. if (len != 2) {
  365. wpa_printf(MSG_DEBUG, "WPS: Invalid Authentication "
  366. "Type length %u", len);
  367. return -1;
  368. }
  369. attr->auth_type = pos;
  370. break;
  371. case ATTR_ENCR_TYPE:
  372. if (len != 2) {
  373. wpa_printf(MSG_DEBUG, "WPS: Invalid Encryption "
  374. "Type length %u", len);
  375. return -1;
  376. }
  377. attr->encr_type = pos;
  378. break;
  379. case ATTR_NETWORK_INDEX:
  380. if (len != 1) {
  381. wpa_printf(MSG_DEBUG, "WPS: Invalid Network Index "
  382. "length %u", len);
  383. return -1;
  384. }
  385. attr->network_idx = pos;
  386. break;
  387. case ATTR_NETWORK_KEY_INDEX:
  388. if (len != 1) {
  389. wpa_printf(MSG_DEBUG, "WPS: Invalid Network Key Index "
  390. "length %u", len);
  391. return -1;
  392. }
  393. attr->network_key_idx = pos;
  394. break;
  395. case ATTR_MAC_ADDR:
  396. if (len != ETH_ALEN) {
  397. wpa_printf(MSG_DEBUG, "WPS: Invalid MAC Address "
  398. "length %u", len);
  399. return -1;
  400. }
  401. attr->mac_addr = pos;
  402. break;
  403. case ATTR_SELECTED_REGISTRAR:
  404. if (len != 1) {
  405. wpa_printf(MSG_DEBUG, "WPS: Invalid Selected Registrar"
  406. " length %u", len);
  407. return -1;
  408. }
  409. attr->selected_registrar = pos;
  410. break;
  411. case ATTR_REQUEST_TYPE:
  412. if (len != 1) {
  413. wpa_printf(MSG_DEBUG, "WPS: Invalid Request Type "
  414. "length %u", len);
  415. return -1;
  416. }
  417. attr->request_type = pos;
  418. break;
  419. case ATTR_RESPONSE_TYPE:
  420. if (len != 1) {
  421. wpa_printf(MSG_DEBUG, "WPS: Invalid Response Type "
  422. "length %u", len);
  423. return -1;
  424. }
  425. attr->response_type = pos;
  426. break;
  427. case ATTR_MANUFACTURER:
  428. attr->manufacturer = pos;
  429. attr->manufacturer_len = len;
  430. break;
  431. case ATTR_MODEL_NAME:
  432. attr->model_name = pos;
  433. attr->model_name_len = len;
  434. break;
  435. case ATTR_MODEL_NUMBER:
  436. attr->model_number = pos;
  437. attr->model_number_len = len;
  438. break;
  439. case ATTR_SERIAL_NUMBER:
  440. attr->serial_number = pos;
  441. attr->serial_number_len = len;
  442. break;
  443. case ATTR_DEV_NAME:
  444. attr->dev_name = pos;
  445. attr->dev_name_len = len;
  446. break;
  447. case ATTR_PUBLIC_KEY:
  448. attr->public_key = pos;
  449. attr->public_key_len = len;
  450. break;
  451. case ATTR_ENCR_SETTINGS:
  452. attr->encr_settings = pos;
  453. attr->encr_settings_len = len;
  454. break;
  455. case ATTR_CRED:
  456. if (attr->num_cred >= MAX_CRED_COUNT) {
  457. wpa_printf(MSG_DEBUG, "WPS: Skipped Credential "
  458. "attribute (max %d credentials)",
  459. MAX_CRED_COUNT);
  460. break;
  461. }
  462. attr->cred[attr->num_cred] = pos;
  463. attr->cred_len[attr->num_cred] = len;
  464. attr->num_cred++;
  465. break;
  466. case ATTR_SSID:
  467. attr->ssid = pos;
  468. attr->ssid_len = len;
  469. break;
  470. case ATTR_NETWORK_KEY:
  471. attr->network_key = pos;
  472. attr->network_key_len = len;
  473. break;
  474. case ATTR_AP_SETUP_LOCKED:
  475. if (len != 1) {
  476. wpa_printf(MSG_DEBUG, "WPS: Invalid AP Setup Locked "
  477. "length %u", len);
  478. return -1;
  479. }
  480. attr->ap_setup_locked = pos;
  481. break;
  482. case ATTR_REQUESTED_DEV_TYPE:
  483. if (len != WPS_DEV_TYPE_LEN) {
  484. wpa_printf(MSG_DEBUG, "WPS: Invalid Requested Device "
  485. "Type length %u", len);
  486. return -1;
  487. }
  488. if (attr->num_req_dev_type >= MAX_REQ_DEV_TYPE_COUNT) {
  489. wpa_printf(MSG_DEBUG, "WPS: Skipped Requested Device "
  490. "Type attribute (max %u types)",
  491. MAX_REQ_DEV_TYPE_COUNT);
  492. break;
  493. }
  494. attr->req_dev_type[attr->num_req_dev_type] = pos;
  495. attr->num_req_dev_type++;
  496. break;
  497. case ATTR_SECONDARY_DEV_TYPE_LIST:
  498. if (len > WPS_SEC_DEV_TYPE_MAX_LEN ||
  499. (len % WPS_DEV_TYPE_LEN) > 0) {
  500. wpa_printf(MSG_DEBUG, "WPS: Invalid Secondary Device "
  501. "Type length %u", len);
  502. return -1;
  503. }
  504. attr->sec_dev_type_list = pos;
  505. attr->sec_dev_type_list_len = len;
  506. break;
  507. case ATTR_VENDOR_EXT:
  508. if (wps_parse_vendor_ext(attr, pos, len) < 0)
  509. return -1;
  510. break;
  511. case ATTR_AP_CHANNEL:
  512. if (len != 2) {
  513. wpa_printf(MSG_DEBUG, "WPS: Invalid AP Channel "
  514. "length %u", len);
  515. return -1;
  516. }
  517. attr->ap_channel = pos;
  518. break;
  519. default:
  520. wpa_printf(MSG_DEBUG, "WPS: Unsupported attribute type 0x%x "
  521. "len=%u", type, len);
  522. break;
  523. }
  524. return 0;
  525. }
  526. int wps_parse_msg(const struct wpabuf *msg, struct wps_parse_attr *attr)
  527. {
  528. const u8 *pos, *end;
  529. u16 type, len;
  530. #ifdef WPS_WORKAROUNDS
  531. u16 prev_type = 0;
  532. #endif /* WPS_WORKAROUNDS */
  533. os_memset(attr, 0, sizeof(*attr));
  534. pos = wpabuf_head(msg);
  535. end = pos + wpabuf_len(msg);
  536. while (pos < end) {
  537. if (end - pos < 4) {
  538. wpa_printf(MSG_DEBUG, "WPS: Invalid message - "
  539. "%lu bytes remaining",
  540. (unsigned long) (end - pos));
  541. return -1;
  542. }
  543. type = WPA_GET_BE16(pos);
  544. pos += 2;
  545. len = WPA_GET_BE16(pos);
  546. pos += 2;
  547. wpa_printf(MSG_EXCESSIVE, "WPS: attr type=0x%x len=%u",
  548. type, len);
  549. if (len > end - pos) {
  550. wpa_printf(MSG_DEBUG, "WPS: Attribute overflow");
  551. wpa_hexdump_buf(MSG_MSGDUMP, "WPS: Message data", msg);
  552. #ifdef WPS_WORKAROUNDS
  553. /*
  554. * Some deployed APs seem to have a bug in encoding of
  555. * Network Key attribute in the Credential attribute
  556. * where they add an extra octet after the Network Key
  557. * attribute at least when open network is being
  558. * provisioned.
  559. */
  560. if ((type & 0xff00) != 0x1000 &&
  561. prev_type == ATTR_NETWORK_KEY) {
  562. wpa_printf(MSG_DEBUG, "WPS: Workaround - try "
  563. "to skip unexpected octet after "
  564. "Network Key");
  565. pos -= 3;
  566. continue;
  567. }
  568. #endif /* WPS_WORKAROUNDS */
  569. return -1;
  570. }
  571. #ifdef WPS_WORKAROUNDS
  572. if (type == 0 && len == 0) {
  573. /*
  574. * Mac OS X 10.6 seems to be adding 0x00 padding to the
  575. * end of M1. Skip those to avoid interop issues.
  576. */
  577. int i;
  578. for (i = 0; i < end - pos; i++) {
  579. if (pos[i])
  580. break;
  581. }
  582. if (i == end - pos) {
  583. wpa_printf(MSG_DEBUG, "WPS: Workaround - skip "
  584. "unexpected message padding");
  585. break;
  586. }
  587. }
  588. #endif /* WPS_WORKAROUNDS */
  589. if (wps_set_attr(attr, type, pos, len) < 0)
  590. return -1;
  591. #ifdef WPS_WORKAROUNDS
  592. prev_type = type;
  593. #endif /* WPS_WORKAROUNDS */
  594. pos += len;
  595. }
  596. return 0;
  597. }