12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394959697989910010110210310410510610710810911011111211311411511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614714814915015115215315415515615715815916016116216316416516616716816917017117217317417517617717817918018118218318418518618718818919019119219319419519619719819920020120220320420520620720820921021121221321421521621721821922022122222322422522622722822923023123223323423523623723823924024124224324424524624724824925025125225325425525625725825926026126226326426526626726826927027127227327427527627727827928028128228328428528628728828929029129229329429529629729829930030130230330430530630730830931031131231331431531631731831932032132232332432532632732832933033133233333433533633733833934034134234334434534634734834935035135235335435535635735835936036136236336436536636736836937037137237337437537637737837938038138238338438538638738838939039139239339439539639739839940040140240340440540640740840941041141241341441541641741841942042142242342442542642742842943043143243343443543643743843944044144244344444544644744844945045145245345445545645745845946046146246346446546646746846947047147247347447547647747847948048148248348448548648748848949049149249349449549649749849950050150250350450550650750850951051151251351451551651751851952052152252352452552652752852953053153253353453553653753853954054154254354454554654754854955055155255355455555655755855956056156256356456556656756856957057157257357457557657757857958058158258358458558658758858959059159259359459559659759859960060160260360460560660760860961061161261361461561661761861962062162262362462562662762862963063163263363463563663763863964064164264364464564664764864965065165265365465565665765865966066166266366466566666766866967067167267367467567667767867968068168268368468568668768868969069169269369469569669769869970070170270370470570670770870971071171271371471571671771871972072172272372472572672772872973073173273373473573673773873974074174274374474574674774874975075175275375475575675775875976076176276376476576676776876977077177277377477577677777877978078178278378478578678778878979079179279379479579679779879980080180280380480580680780880981081181281381481581681781881982082182282382482582682782882983083183283383483583683783883984084184284384484584684784884985085185285385485585685785885986086186286386486586686786886987087187287387487587687787887988088188288388488588688788888989089189289389489589689789889990090190290390490590690790890991091191291391491591691791891992092192292392492592692792892993093193293393493593693793893994094194294394494594694794894995095195295395495595695795895996096196296396496596696796896997097197297397497597697797897998098198298398498598698798898999099199299399499599699799899910001001100210031004100510061007100810091010101110121013101410151016101710181019102010211022102310241025102610271028102910301031103210331034103510361037103810391040104110421043104410451046104710481049105010511052105310541055105610571058105910601061106210631064106510661067106810691070107110721073107410751076107710781079108010811082108310841085108610871088108910901091109210931094109510961097109810991100110111021103110411051106110711081109111011111112111311141115111611171118111911201121112211231124112511261127112811291130113111321133113411351136113711381139114011411142114311441145114611471148114911501151115211531154115511561157115811591160116111621163116411651166116711681169117011711172117311741175117611771178117911801181118211831184118511861187118811891190119111921193119411951196119711981199120012011202120312041205120612071208120912101211121212131214121512161217121812191220122112221223122412251226122712281229123012311232123312341235123612371238123912401241124212431244124512461247124812491250125112521253125412551256125712581259126012611262126312641265126612671268126912701271127212731274127512761277127812791280128112821283128412851286128712881289129012911292129312941295129612971298129913001301130213031304130513061307130813091310131113121313131413151316131713181319132013211322132313241325132613271328132913301331133213331334133513361337133813391340134113421343134413451346134713481349135013511352135313541355135613571358135913601361136213631364136513661367136813691370137113721373137413751376137713781379138013811382138313841385138613871388138913901391139213931394139513961397139813991400140114021403140414051406140714081409141014111412141314141415141614171418141914201421142214231424142514261427142814291430143114321433143414351436143714381439144014411442144314441445144614471448144914501451145214531454145514561457145814591460146114621463146414651466146714681469147014711472147314741475147614771478147914801481148214831484148514861487148814891490149114921493149414951496149714981499150015011502150315041505150615071508150915101511151215131514151515161517151815191520152115221523152415251526152715281529153015311532153315341535153615371538153915401541154215431544154515461547154815491550155115521553155415551556155715581559156015611562156315641565156615671568156915701571157215731574157515761577157815791580158115821583158415851586158715881589159015911592159315941595159615971598159916001601160216031604160516061607160816091610161116121613161416151616161716181619162016211622162316241625162616271628162916301631163216331634163516361637163816391640164116421643164416451646164716481649165016511652165316541655165616571658165916601661166216631664166516661667166816691670167116721673167416751676167716781679168016811682168316841685168616871688168916901691169216931694169516961697169816991700170117021703170417051706170717081709171017111712171317141715171617171718171917201721172217231724172517261727172817291730173117321733173417351736173717381739174017411742174317441745174617471748174917501751175217531754175517561757175817591760176117621763176417651766176717681769177017711772177317741775177617771778177917801781178217831784178517861787178817891790179117921793179417951796179717981799180018011802180318041805180618071808180918101811181218131814181518161817181818191820182118221823182418251826182718281829183018311832183318341835183618371838183918401841184218431844184518461847184818491850185118521853185418551856185718581859186018611862186318641865186618671868186918701871187218731874187518761877187818791880188118821883188418851886188718881889189018911892189318941895189618971898189919001901190219031904190519061907190819091910191119121913191419151916191719181919192019211922192319241925192619271928192919301931193219331934193519361937193819391940194119421943194419451946194719481949195019511952195319541955195619571958195919601961196219631964196519661967196819691970197119721973197419751976197719781979198019811982198319841985198619871988198919901991 |
- /*
- * Wi-Fi Protected Setup - Strict protocol validation routines
- * Copyright (c) 2010, Atheros Communications, Inc.
- *
- * This program is free software; you can redistribute it and/or modify
- * it under the terms of the GNU General Public License version 2 as
- * published by the Free Software Foundation.
- *
- * Alternatively, this software may be distributed under the terms of BSD
- * license.
- *
- * See README and COPYING for more details.
- */
- #include "utils/includes.h"
- #include "utils/common.h"
- #include "wps_i.h"
- #include "wps.h"
- #ifndef WPS_STRICT_ALL
- #define WPS_STRICT_WPS2
- #endif /* WPS_STRICT_ALL */
- static int wps_validate_version(const u8 *version, int mandatory)
- {
- if (version == NULL) {
- if (mandatory) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Version attribute "
- "missing");
- return -1;
- }
- return 0;
- }
- if (*version != 0x10) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Invalid Version attribute "
- "value 0x%x", *version);
- return -1;
- }
- return 0;
- }
- static int wps_validate_version2(const u8 *version2, int mandatory)
- {
- if (version2 == NULL) {
- if (mandatory) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Version2 attribute "
- "missing");
- return -1;
- }
- return 0;
- }
- if (*version2 < 0x20) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Invalid Version2 attribute "
- "value 0x%x", *version2);
- return -1;
- }
- return 0;
- }
- static int wps_validate_request_type(const u8 *request_type, int mandatory)
- {
- if (request_type == NULL) {
- if (mandatory) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Request Type "
- "attribute missing");
- return -1;
- }
- return 0;
- }
- if (*request_type > 0x03) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Invalid Request Type "
- "attribute value 0x%x", *request_type);
- return -1;
- }
- return 0;
- }
- static int wps_validate_response_type(const u8 *response_type, int mandatory)
- {
- if (response_type == NULL) {
- if (mandatory) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Response Type "
- "attribute missing");
- return -1;
- }
- return 0;
- }
- if (*response_type > 0x03) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Invalid Response Type "
- "attribute value 0x%x", *response_type);
- return -1;
- }
- return 0;
- }
- static int valid_config_methods(u16 val, int wps2)
- {
- if (wps2) {
- if ((val & 0x6000) && !(val & WPS_CONFIG_DISPLAY)) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Physical/Virtual "
- "Display flag without old Display flag "
- "set");
- return 0;
- }
- if (!(val & 0x6000) && (val & WPS_CONFIG_DISPLAY)) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Display flag "
- "without Physical/Virtual Display flag");
- return 0;
- }
- if ((val & 0x0600) && !(val & WPS_CONFIG_PUSHBUTTON)) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Physical/Virtual "
- "PushButton flag without old PushButton "
- "flag set");
- return 0;
- }
- if (!(val & 0x0600) && (val & WPS_CONFIG_PUSHBUTTON)) {
- wpa_printf(MSG_INFO, "WPS-STRICT: PushButton flag "
- "without Physical/Virtual PushButton flag");
- return 0;
- }
- }
- return 1;
- }
- static int wps_validate_config_methods(const u8 *config_methods, int wps2,
- int mandatory)
- {
- u16 val;
- if (config_methods == NULL) {
- if (mandatory) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Configuration "
- "Methods attribute missing");
- return -1;
- }
- return 0;
- }
- val = WPA_GET_BE16(config_methods);
- if (!valid_config_methods(val, wps2)) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Invalid Configuration "
- "Methods attribute value 0x%04x", val);
- return -1;
- }
- return 0;
- }
- static int wps_validate_ap_config_methods(const u8 *config_methods, int wps2,
- int mandatory)
- {
- u16 val;
- if (wps_validate_config_methods(config_methods, wps2, mandatory) < 0)
- return -1;
- if (config_methods == NULL)
- return 0;
- val = WPA_GET_BE16(config_methods);
- if (val & WPS_CONFIG_PUSHBUTTON) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Invalid Configuration "
- "Methods attribute value 0x%04x in AP info "
- "(PushButton not allowed for registering new ER)",
- val);
- return -1;
- }
- return 0;
- }
- static int wps_validate_uuid_e(const u8 *uuid_e, int mandatory)
- {
- if (uuid_e == NULL) {
- if (mandatory) {
- wpa_printf(MSG_INFO, "WPS-STRICT: UUID-E "
- "attribute missing");
- return -1;
- }
- return 0;
- }
- return 0;
- }
- static int wps_validate_uuid_r(const u8 *uuid_r, int mandatory)
- {
- if (uuid_r == NULL) {
- if (mandatory) {
- wpa_printf(MSG_INFO, "WPS-STRICT: UUID-R "
- "attribute missing");
- return -1;
- }
- return 0;
- }
- return 0;
- }
- static int wps_validate_primary_dev_type(const u8 *primary_dev_type,
- int mandatory)
- {
- if (primary_dev_type == NULL) {
- if (mandatory) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Primary Device Type "
- "attribute missing");
- return -1;
- }
- return 0;
- }
- return 0;
- }
- static int wps_validate_rf_bands(const u8 *rf_bands, int mandatory)
- {
- if (rf_bands == NULL) {
- if (mandatory) {
- wpa_printf(MSG_INFO, "WPS-STRICT: RF Bands "
- "attribute missing");
- return -1;
- }
- return 0;
- }
- if (*rf_bands != WPS_RF_24GHZ && *rf_bands != WPS_RF_50GHZ &&
- *rf_bands != (WPS_RF_24GHZ | WPS_RF_50GHZ)) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Invalid Rf Bands "
- "attribute value 0x%x", *rf_bands);
- return -1;
- }
- return 0;
- }
- static int wps_validate_assoc_state(const u8 *assoc_state, int mandatory)
- {
- u16 val;
- if (assoc_state == NULL) {
- if (mandatory) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Association State "
- "attribute missing");
- return -1;
- }
- return 0;
- }
- val = WPA_GET_BE16(assoc_state);
- if (val > 4) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Invalid Association State "
- "attribute value 0x%04x", val);
- return -1;
- }
- return 0;
- }
- static int wps_validate_config_error(const u8 *config_error, int mandatory)
- {
- u16 val;
- if (config_error == NULL) {
- if (mandatory) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Configuration Error "
- "attribute missing");
- return -1;
- }
- return 0;
- }
- val = WPA_GET_BE16(config_error);
- if (val > 18) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Invalid Configuration Error "
- "attribute value 0x%04x", val);
- return -1;
- }
- return 0;
- }
- static int wps_validate_dev_password_id(const u8 *dev_password_id,
- int mandatory)
- {
- u16 val;
- if (dev_password_id == NULL) {
- if (mandatory) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Device Password ID "
- "attribute missing");
- return -1;
- }
- return 0;
- }
- val = WPA_GET_BE16(dev_password_id);
- if (val >= 0x0006 && val <= 0x000f) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Invalid Device Password ID "
- "attribute value 0x%04x", val);
- return -1;
- }
- return 0;
- }
- static int wps_validate_manufacturer(const u8 *manufacturer, size_t len,
- int mandatory)
- {
- if (manufacturer == NULL) {
- if (mandatory) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Manufacturer "
- "attribute missing");
- return -1;
- }
- return 0;
- }
- if (len > 0 && manufacturer[len - 1] == 0) {
- wpa_hexdump_ascii(MSG_INFO, "WPS-STRICT: Invalid Manufacturer "
- "attribute value", manufacturer, len);
- return -1;
- }
- return 0;
- }
- static int wps_validate_model_name(const u8 *model_name, size_t len,
- int mandatory)
- {
- if (model_name == NULL) {
- if (mandatory) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Model Name "
- "attribute missing");
- return -1;
- }
- return 0;
- }
- if (len > 0 && model_name[len - 1] == 0) {
- wpa_hexdump_ascii(MSG_INFO, "WPS-STRICT: Invalid Model Name "
- "attribute value", model_name, len);
- return -1;
- }
- return 0;
- }
- static int wps_validate_model_number(const u8 *model_number, size_t len,
- int mandatory)
- {
- if (model_number == NULL) {
- if (mandatory) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Model Number "
- "attribute missing");
- return -1;
- }
- return 0;
- }
- if (len > 0 && model_number[len - 1] == 0) {
- wpa_hexdump_ascii(MSG_INFO, "WPS-STRICT: Invalid Model Number "
- "attribute value", model_number, len);
- return -1;
- }
- return 0;
- }
- static int wps_validate_serial_number(const u8 *serial_number, size_t len,
- int mandatory)
- {
- if (serial_number == NULL) {
- if (mandatory) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Serial Number "
- "attribute missing");
- return -1;
- }
- return 0;
- }
- if (len > 0 && serial_number[len - 1] == 0) {
- wpa_hexdump_ascii(MSG_INFO, "WPS-STRICT: Invalid Serial "
- "Number attribute value",
- serial_number, len);
- return -1;
- }
- return 0;
- }
- static int wps_validate_dev_name(const u8 *dev_name, size_t len,
- int mandatory)
- {
- if (dev_name == NULL) {
- if (mandatory) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Device Name "
- "attribute missing");
- return -1;
- }
- return 0;
- }
- if (len > 0 && dev_name[len - 1] == 0) {
- wpa_hexdump_ascii(MSG_INFO, "WPS-STRICT: Invalid Device Name "
- "attribute value", dev_name, len);
- return -1;
- }
- return 0;
- }
- static int wps_validate_request_to_enroll(const u8 *request_to_enroll,
- int mandatory)
- {
- if (request_to_enroll == NULL) {
- if (mandatory) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Request to Enroll "
- "attribute missing");
- return -1;
- }
- return 0;
- }
- if (*request_to_enroll > 0x01) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Invalid Request to Enroll "
- "attribute value 0x%x", *request_to_enroll);
- return -1;
- }
- return 0;
- }
- static int wps_validate_req_dev_type(const u8 *req_dev_type[], size_t num,
- int mandatory)
- {
- if (num == 0) {
- if (mandatory) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Requested Device "
- "Type attribute missing");
- return -1;
- }
- return 0;
- }
- return 0;
- }
- static int wps_validate_wps_state(const u8 *wps_state, int mandatory)
- {
- if (wps_state == NULL) {
- if (mandatory) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Wi-Fi Protected "
- "Setup State attribute missing");
- return -1;
- }
- return 0;
- }
- if (*wps_state != WPS_STATE_NOT_CONFIGURED &&
- *wps_state != WPS_STATE_CONFIGURED) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Invalid Wi-Fi Protected "
- "Setup State attribute value 0x%x", *wps_state);
- return -1;
- }
- return 0;
- }
- static int wps_validate_ap_setup_locked(const u8 *ap_setup_locked,
- int mandatory)
- {
- if (ap_setup_locked == NULL) {
- if (mandatory) {
- wpa_printf(MSG_INFO, "WPS-STRICT: AP Setup Locked "
- "attribute missing");
- return -1;
- }
- return 0;
- }
- if (*ap_setup_locked > 1) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Invalid AP Setup Locked "
- "attribute value 0x%x", *ap_setup_locked);
- return -1;
- }
- return 0;
- }
- static int wps_validate_selected_registrar(const u8 *selected_registrar,
- int mandatory)
- {
- if (selected_registrar == NULL) {
- if (mandatory) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Selected Registrar "
- "attribute missing");
- return -1;
- }
- return 0;
- }
- if (*selected_registrar > 1) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Invalid Selected Registrar "
- "attribute value 0x%x", *selected_registrar);
- return -1;
- }
- return 0;
- }
- static int wps_validate_sel_reg_config_methods(const u8 *config_methods,
- int wps2, int mandatory)
- {
- u16 val;
- if (config_methods == NULL) {
- if (mandatory) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Selected Registrar "
- "Configuration Methods attribute missing");
- return -1;
- }
- return 0;
- }
- val = WPA_GET_BE16(config_methods);
- if (!valid_config_methods(val, wps2)) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Invalid Selected Registrar "
- "Configuration Methods attribute value 0x%04x",
- val);
- return -1;
- }
- return 0;
- }
- static int wps_validate_authorized_macs(const u8 *authorized_macs, size_t len,
- int mandatory)
- {
- if (authorized_macs == NULL) {
- if (mandatory) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Authorized MACs "
- "attribute missing");
- return -1;
- }
- return 0;
- }
- if (len > 30 && (len % ETH_ALEN) != 0) {
- wpa_hexdump(MSG_INFO, "WPS-STRICT: Invalid Authorized "
- "MACs attribute value", authorized_macs, len);
- return -1;
- }
- return 0;
- }
- static int wps_validate_msg_type(const u8 *msg_type, int mandatory)
- {
- if (msg_type == NULL) {
- if (mandatory) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Message Type "
- "attribute missing");
- return -1;
- }
- return 0;
- }
- if (*msg_type < WPS_Beacon || *msg_type > WPS_WSC_DONE) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Invalid Message Type "
- "attribute value 0x%x", *msg_type);
- return -1;
- }
- return 0;
- }
- static int wps_validate_mac_addr(const u8 *mac_addr, int mandatory)
- {
- if (mac_addr == NULL) {
- if (mandatory) {
- wpa_printf(MSG_INFO, "WPS-STRICT: MAC Address "
- "attribute missing");
- return -1;
- }
- return 0;
- }
- if (mac_addr[0] & 0x01) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Invalid MAC Address "
- "attribute value " MACSTR, MAC2STR(mac_addr));
- return -1;
- }
- return 0;
- }
- static int wps_validate_enrollee_nonce(const u8 *enrollee_nonce, int mandatory)
- {
- if (enrollee_nonce == NULL) {
- if (mandatory) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Enrollee Nonce "
- "attribute missing");
- return -1;
- }
- return 0;
- }
- return 0;
- }
- static int wps_validate_registrar_nonce(const u8 *registrar_nonce,
- int mandatory)
- {
- if (registrar_nonce == NULL) {
- if (mandatory) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Registrar Nonce "
- "attribute missing");
- return -1;
- }
- return 0;
- }
- return 0;
- }
- static int wps_validate_public_key(const u8 *public_key, size_t len,
- int mandatory)
- {
- if (public_key == NULL) {
- if (mandatory) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Public Key "
- "attribute missing");
- return -1;
- }
- return 0;
- }
- if (len != 192) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Invalid Public Key "
- "attribute length %d", (int) len);
- return -1;
- }
- return 0;
- }
- static int num_bits_set(u16 val)
- {
- int c;
- for (c = 0; val; c++)
- val &= val - 1;
- return c;
- }
- static int wps_validate_auth_type_flags(const u8 *flags, int mandatory)
- {
- u16 val;
- if (flags == NULL) {
- if (mandatory) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Authentication Type "
- "Flags attribute missing");
- return -1;
- }
- return 0;
- }
- val = WPA_GET_BE16(flags);
- if ((val & ~WPS_AUTH_TYPES) || !(val & WPS_AUTH_WPA2PSK)) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Invalid Authentication Type "
- "Flags attribute value 0x%04x", val);
- return -1;
- }
- return 0;
- }
- static int wps_validate_auth_type(const u8 *type, int mandatory)
- {
- u16 val;
- if (type == NULL) {
- if (mandatory) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Authentication Type "
- "attribute missing");
- return -1;
- }
- return 0;
- }
- val = WPA_GET_BE16(type);
- if ((val & ~WPS_AUTH_TYPES) || val == 0 ||
- (num_bits_set(val) > 1 &&
- val != (WPS_AUTH_WPAPSK | WPS_AUTH_WPA2PSK))) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Invalid Authentication Type "
- "attribute value 0x%04x", val);
- return -1;
- }
- return 0;
- }
- static int wps_validate_encr_type_flags(const u8 *flags, int mandatory)
- {
- u16 val;
- if (flags == NULL) {
- if (mandatory) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Encryption Type "
- "Flags attribute missing");
- return -1;
- }
- return 0;
- }
- val = WPA_GET_BE16(flags);
- if ((val & ~WPS_ENCR_TYPES) || !(val & WPS_ENCR_AES)) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Invalid Encryption Type "
- "Flags attribute value 0x%04x", val);
- return -1;
- }
- return 0;
- }
- static int wps_validate_encr_type(const u8 *type, int mandatory)
- {
- u16 val;
- if (type == NULL) {
- if (mandatory) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Encryption Type "
- "attribute missing");
- return -1;
- }
- return 0;
- }
- val = WPA_GET_BE16(type);
- if ((val & ~WPS_ENCR_TYPES) || val == 0 ||
- (num_bits_set(val) > 1 && val != (WPS_ENCR_TKIP | WPS_ENCR_AES))) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Invalid Encryption Type "
- "attribute value 0x%04x", val);
- return -1;
- }
- return 0;
- }
- static int wps_validate_conn_type_flags(const u8 *flags, int mandatory)
- {
- if (flags == NULL) {
- if (mandatory) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Connection Type "
- "Flags attribute missing");
- return -1;
- }
- return 0;
- }
- if ((*flags & ~(WPS_CONN_ESS | WPS_CONN_IBSS)) ||
- !(*flags & WPS_CONN_ESS)) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Invalid Connection Type "
- "Flags attribute value 0x%02x", *flags);
- return -1;
- }
- return 0;
- }
- static int wps_validate_os_version(const u8 *os_version, int mandatory)
- {
- if (os_version == NULL) {
- if (mandatory) {
- wpa_printf(MSG_INFO, "WPS-STRICT: OS Version "
- "attribute missing");
- return -1;
- }
- return 0;
- }
- return 0;
- }
- static int wps_validate_authenticator(const u8 *authenticator, int mandatory)
- {
- if (authenticator == NULL) {
- if (mandatory) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Authenticator "
- "attribute missing");
- return -1;
- }
- return 0;
- }
- return 0;
- }
- static int wps_validate_e_hash1(const u8 *hash, int mandatory)
- {
- if (hash == NULL) {
- if (mandatory) {
- wpa_printf(MSG_INFO, "WPS-STRICT: E-Hash1 "
- "attribute missing");
- return -1;
- }
- return 0;
- }
- return 0;
- }
- static int wps_validate_e_hash2(const u8 *hash, int mandatory)
- {
- if (hash == NULL) {
- if (mandatory) {
- wpa_printf(MSG_INFO, "WPS-STRICT: E-Hash2 "
- "attribute missing");
- return -1;
- }
- return 0;
- }
- return 0;
- }
- static int wps_validate_r_hash1(const u8 *hash, int mandatory)
- {
- if (hash == NULL) {
- if (mandatory) {
- wpa_printf(MSG_INFO, "WPS-STRICT: R-Hash1 "
- "attribute missing");
- return -1;
- }
- return 0;
- }
- return 0;
- }
- static int wps_validate_r_hash2(const u8 *hash, int mandatory)
- {
- if (hash == NULL) {
- if (mandatory) {
- wpa_printf(MSG_INFO, "WPS-STRICT: R-Hash2 "
- "attribute missing");
- return -1;
- }
- return 0;
- }
- return 0;
- }
- static int wps_validate_encr_settings(const u8 *encr_settings, size_t len,
- int mandatory)
- {
- if (encr_settings == NULL) {
- if (mandatory) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Encrypted Settings "
- "attribute missing");
- return -1;
- }
- return 0;
- }
- if (len < 16) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Invalid Encrypted Settings "
- "attribute length %d", (int) len);
- return -1;
- }
- return 0;
- }
- static int wps_validate_settings_delay_time(const u8 *delay, int mandatory)
- {
- if (delay == NULL) {
- if (mandatory) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Settings Delay Time "
- "attribute missing");
- return -1;
- }
- return 0;
- }
- return 0;
- }
- static int wps_validate_r_snonce1(const u8 *nonce, int mandatory)
- {
- if (nonce == NULL) {
- if (mandatory) {
- wpa_printf(MSG_INFO, "WPS-STRICT: R-SNonce1 "
- "attribute missing");
- return -1;
- }
- return 0;
- }
- return 0;
- }
- static int wps_validate_r_snonce2(const u8 *nonce, int mandatory)
- {
- if (nonce == NULL) {
- if (mandatory) {
- wpa_printf(MSG_INFO, "WPS-STRICT: R-SNonce2 "
- "attribute missing");
- return -1;
- }
- return 0;
- }
- return 0;
- }
- static int wps_validate_e_snonce1(const u8 *nonce, int mandatory)
- {
- if (nonce == NULL) {
- if (mandatory) {
- wpa_printf(MSG_INFO, "WPS-STRICT: E-SNonce1 "
- "attribute missing");
- return -1;
- }
- return 0;
- }
- return 0;
- }
- static int wps_validate_e_snonce2(const u8 *nonce, int mandatory)
- {
- if (nonce == NULL) {
- if (mandatory) {
- wpa_printf(MSG_INFO, "WPS-STRICT: E-SNonce2 "
- "attribute missing");
- return -1;
- }
- return 0;
- }
- return 0;
- }
- static int wps_validate_key_wrap_auth(const u8 *auth, int mandatory)
- {
- if (auth == NULL) {
- if (mandatory) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Key Wrap "
- "Authenticator attribute missing");
- return -1;
- }
- return 0;
- }
- return 0;
- }
- static int wps_validate_ssid(const u8 *ssid, size_t ssid_len, int mandatory)
- {
- if (ssid == NULL) {
- if (mandatory) {
- wpa_printf(MSG_INFO, "WPS-STRICT: SSID "
- "attribute missing");
- return -1;
- }
- return 0;
- }
- if (ssid_len == 0 || ssid[ssid_len - 1] == 0) {
- wpa_hexdump_ascii(MSG_INFO, "WPS-STRICT: Invalid SSID "
- "attribute value", ssid, ssid_len);
- return -1;
- }
- return 0;
- }
- static int wps_validate_network_key_index(const u8 *idx, int mandatory)
- {
- if (idx == NULL) {
- if (mandatory) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Network Key Index "
- "attribute missing");
- return -1;
- }
- return 0;
- }
- return 0;
- }
- static int wps_validate_network_idx(const u8 *idx, int mandatory)
- {
- if (idx == NULL) {
- if (mandatory) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Network Index "
- "attribute missing");
- return -1;
- }
- return 0;
- }
- return 0;
- }
- static int wps_validate_network_key(const u8 *key, size_t key_len,
- const u8 *encr_type, int mandatory)
- {
- if (key == NULL) {
- if (mandatory) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Network Key "
- "attribute missing");
- return -1;
- }
- return 0;
- }
- if (((encr_type == NULL || WPA_GET_BE16(encr_type) != WPS_ENCR_WEP) &&
- key_len > 8 && key_len < 64 && key[key_len - 1] == 0) ||
- key_len > 64) {
- wpa_hexdump_ascii_key(MSG_INFO, "WPS-STRICT: Invalid Network "
- "Key attribute value", key, key_len);
- return -1;
- }
- return 0;
- }
- static int wps_validate_network_key_shareable(const u8 *val, int mandatory)
- {
- if (val == NULL) {
- if (mandatory) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Network Key "
- "Shareable attribute missing");
- return -1;
- }
- return 0;
- }
- if (*val > 1) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Invalid Network Key "
- "Shareable attribute value 0x%x", *val);
- return -1;
- }
- return 0;
- }
- static int wps_validate_cred(const u8 *cred, size_t len)
- {
- struct wps_parse_attr attr;
- struct wpabuf buf;
- if (cred == NULL)
- return -1;
- wpabuf_set(&buf, cred, len);
- if (wps_parse_msg(&buf, &attr) < 0) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Failed to parse Credential");
- return -1;
- }
- if (wps_validate_network_idx(attr.network_idx, 1) ||
- wps_validate_ssid(attr.ssid, attr.ssid_len, 1) ||
- wps_validate_auth_type(attr.auth_type, 1) ||
- wps_validate_encr_type(attr.encr_type, 1) ||
- wps_validate_network_key_index(attr.network_key_idx, 0) ||
- wps_validate_network_key(attr.network_key, attr.network_key_len,
- attr.encr_type, 1) ||
- wps_validate_mac_addr(attr.mac_addr, 1) ||
- wps_validate_network_key_shareable(attr.network_key_shareable, 0))
- {
- wpa_printf(MSG_INFO, "WPS-STRICT: Invalid Credential");
- return -1;
- }
- return 0;
- }
- static int wps_validate_credential(const u8 *cred[], size_t len[], size_t num,
- int mandatory)
- {
- size_t i;
- if (num == 0) {
- if (mandatory) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Credential "
- "attribute missing");
- return -1;
- }
- return 0;
- }
- for (i = 0; i < num; i++) {
- if (wps_validate_cred(cred[i], len[i]) < 0)
- return -1;
- }
- return 0;
- }
- int wps_validate_beacon(const struct wpabuf *wps_ie)
- {
- struct wps_parse_attr attr;
- int wps2, sel_reg;
- if (wps_ie == NULL) {
- wpa_printf(MSG_INFO, "WPS-STRICT: No WPS IE in Beacon frame");
- return -1;
- }
- if (wps_parse_msg(wps_ie, &attr) < 0) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Failed to parse WPS IE in "
- "Beacon frame");
- return -1;
- }
- wps2 = attr.version2 != NULL;
- sel_reg = attr.selected_registrar != NULL &&
- *attr.selected_registrar != 0;
- if (wps_validate_version(attr.version, 1) ||
- wps_validate_wps_state(attr.wps_state, 1) ||
- wps_validate_ap_setup_locked(attr.ap_setup_locked, 0) ||
- wps_validate_selected_registrar(attr.selected_registrar, 0) ||
- wps_validate_dev_password_id(attr.dev_password_id, sel_reg) ||
- wps_validate_sel_reg_config_methods(attr.sel_reg_config_methods,
- wps2, sel_reg) ||
- wps_validate_uuid_e(attr.uuid_e, 0) ||
- wps_validate_rf_bands(attr.rf_bands, 0) ||
- wps_validate_version2(attr.version2, wps2) ||
- wps_validate_authorized_macs(attr.authorized_macs,
- attr.authorized_macs_len, 0)) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Invalid Beacon frame");
- return -1;
- }
- return 0;
- }
- int wps_validate_beacon_probe_resp(const struct wpabuf *wps_ie, int probe,
- const u8 *addr)
- {
- struct wps_parse_attr attr;
- int wps2, sel_reg;
- if (wps_ie == NULL) {
- wpa_printf(MSG_INFO, "WPS-STRICT: No WPS IE in "
- "%sProbe Response frame", probe ? "" : "Beacon/");
- return -1;
- }
- if (wps_parse_msg(wps_ie, &attr) < 0) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Failed to parse WPS IE in "
- "%sProbe Response frame", probe ? "" : "Beacon/");
- return -1;
- }
- wps2 = attr.version2 != NULL;
- sel_reg = attr.selected_registrar != NULL &&
- *attr.selected_registrar != 0;
- if (wps_validate_version(attr.version, 1) ||
- wps_validate_wps_state(attr.wps_state, 1) ||
- wps_validate_ap_setup_locked(attr.ap_setup_locked, 0) ||
- wps_validate_selected_registrar(attr.selected_registrar, 0) ||
- wps_validate_dev_password_id(attr.dev_password_id, sel_reg) ||
- wps_validate_sel_reg_config_methods(attr.sel_reg_config_methods,
- wps2, sel_reg) ||
- wps_validate_response_type(attr.response_type, probe) ||
- wps_validate_uuid_e(attr.uuid_e, probe) ||
- wps_validate_manufacturer(attr.manufacturer, attr.manufacturer_len,
- probe) ||
- wps_validate_model_name(attr.model_name, attr.model_name_len,
- probe) ||
- wps_validate_model_number(attr.model_number, attr.model_number_len,
- probe) ||
- wps_validate_serial_number(attr.serial_number,
- attr.serial_number_len, probe) ||
- wps_validate_primary_dev_type(attr.primary_dev_type, probe) ||
- wps_validate_dev_name(attr.dev_name, attr.dev_name_len, probe) ||
- wps_validate_ap_config_methods(attr.config_methods, wps2, probe) ||
- wps_validate_rf_bands(attr.rf_bands, 0) ||
- wps_validate_version2(attr.version2, wps2) ||
- wps_validate_authorized_macs(attr.authorized_macs,
- attr.authorized_macs_len, 0)) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Invalid %sProbe Response "
- "frame from " MACSTR, probe ? "" : "Beacon/",
- MAC2STR(addr));
- #ifdef WPS_STRICT_WPS2
- if (wps2)
- return -1;
- #else /* WPS_STRICT_WPS2 */
- return -1;
- #endif /* WPS_STRICT_WPS2 */
- }
- return 0;
- }
- int wps_validate_probe_req(const struct wpabuf *wps_ie, const u8 *addr)
- {
- struct wps_parse_attr attr;
- int wps2;
- if (wps_ie == NULL) {
- wpa_printf(MSG_INFO, "WPS-STRICT: No WPS IE in "
- "Probe Request frame");
- return -1;
- }
- if (wps_parse_msg(wps_ie, &attr) < 0) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Failed to parse WPS IE in "
- "Probe Request frame");
- return -1;
- }
- wps2 = attr.version2 != NULL;
- if (wps_validate_version(attr.version, 1) ||
- wps_validate_request_type(attr.request_type, 1) ||
- wps_validate_config_methods(attr.config_methods, wps2, 1) ||
- wps_validate_uuid_e(attr.uuid_e, attr.uuid_r == NULL) ||
- wps_validate_uuid_r(attr.uuid_r, attr.uuid_e == NULL) ||
- wps_validate_primary_dev_type(attr.primary_dev_type, 1) ||
- wps_validate_rf_bands(attr.rf_bands, 1) ||
- wps_validate_assoc_state(attr.assoc_state, 1) ||
- wps_validate_config_error(attr.config_error, 1) ||
- wps_validate_dev_password_id(attr.dev_password_id, 1) ||
- wps_validate_version2(attr.version2, wps2) ||
- wps_validate_manufacturer(attr.manufacturer, attr.manufacturer_len,
- wps2) ||
- wps_validate_model_name(attr.model_name, attr.model_name_len,
- wps2) ||
- wps_validate_model_number(attr.model_number, attr.model_number_len,
- wps2) ||
- wps_validate_dev_name(attr.dev_name, attr.dev_name_len, wps2) ||
- wps_validate_request_to_enroll(attr.request_to_enroll, 0) ||
- wps_validate_req_dev_type(attr.req_dev_type, attr.num_req_dev_type,
- 0)) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Invalid Probe Request "
- "frame from " MACSTR, MAC2STR(addr));
- return -1;
- }
- return 0;
- }
- int wps_validate_assoc_req(const struct wpabuf *wps_ie)
- {
- struct wps_parse_attr attr;
- int wps2;
- if (wps_ie == NULL) {
- wpa_printf(MSG_INFO, "WPS-STRICT: No WPS IE in "
- "(Re)Association Request frame");
- return -1;
- }
- if (wps_parse_msg(wps_ie, &attr) < 0) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Failed to parse WPS IE in "
- "(Re)Association Request frame");
- return -1;
- }
- wps2 = attr.version2 != NULL;
- if (wps_validate_version(attr.version, 1) ||
- wps_validate_request_type(attr.request_type, 1) ||
- wps_validate_version2(attr.version2, wps2)) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Invalid (Re)Association "
- "Request frame");
- return -1;
- }
- return 0;
- }
- int wps_validate_assoc_resp(const struct wpabuf *wps_ie)
- {
- struct wps_parse_attr attr;
- int wps2;
- if (wps_ie == NULL) {
- wpa_printf(MSG_INFO, "WPS-STRICT: No WPS IE in "
- "(Re)Association Response frame");
- return -1;
- }
- if (wps_parse_msg(wps_ie, &attr) < 0) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Failed to parse WPS IE in "
- "(Re)Association Response frame");
- return -1;
- }
- wps2 = attr.version2 != NULL;
- if (wps_validate_version(attr.version, 1) ||
- wps_validate_request_type(attr.request_type, 1) ||
- wps_validate_version2(attr.version2, wps2)) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Invalid (Re)Association "
- "Response frame");
- return -1;
- }
- return 0;
- }
- int wps_validate_m1(const struct wpabuf *tlvs)
- {
- struct wps_parse_attr attr;
- int wps2;
- if (tlvs == NULL) {
- wpa_printf(MSG_INFO, "WPS-STRICT: No TLVs in M1");
- return -1;
- }
- if (wps_parse_msg(tlvs, &attr) < 0) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Failed to parse attributes "
- "in M1");
- return -1;
- }
- wps2 = attr.version2 != NULL;
- if (wps_validate_version(attr.version, 1) ||
- wps_validate_msg_type(attr.msg_type, 1) ||
- wps_validate_uuid_e(attr.uuid_e, 1) ||
- wps_validate_mac_addr(attr.mac_addr, 1) ||
- wps_validate_enrollee_nonce(attr.enrollee_nonce, 1) ||
- wps_validate_public_key(attr.public_key, attr.public_key_len, 1) ||
- wps_validate_auth_type_flags(attr.auth_type_flags, 1) ||
- wps_validate_encr_type_flags(attr.encr_type_flags, 1) ||
- wps_validate_conn_type_flags(attr.conn_type_flags, 1) ||
- wps_validate_config_methods(attr.config_methods, wps2, 1) ||
- wps_validate_wps_state(attr.wps_state, 1) ||
- wps_validate_manufacturer(attr.manufacturer, attr.manufacturer_len,
- 1) ||
- wps_validate_model_name(attr.model_name, attr.model_name_len, 1) ||
- wps_validate_model_number(attr.model_number, attr.model_number_len,
- 1) ||
- wps_validate_serial_number(attr.serial_number,
- attr.serial_number_len, 1) ||
- wps_validate_primary_dev_type(attr.primary_dev_type, 1) ||
- wps_validate_dev_name(attr.dev_name, attr.dev_name_len, 1) ||
- wps_validate_rf_bands(attr.rf_bands, 1) ||
- wps_validate_assoc_state(attr.assoc_state, 1) ||
- wps_validate_dev_password_id(attr.dev_password_id, 1) ||
- wps_validate_config_error(attr.config_error, 1) ||
- wps_validate_os_version(attr.os_version, 1) ||
- wps_validate_version2(attr.version2, wps2) ||
- wps_validate_request_to_enroll(attr.request_to_enroll, 0)) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Invalid M1");
- #ifdef WPS_STRICT_WPS2
- if (wps2)
- return -1;
- #else /* WPS_STRICT_WPS2 */
- return -1;
- #endif /* WPS_STRICT_WPS2 */
- }
- return 0;
- }
- int wps_validate_m2(const struct wpabuf *tlvs)
- {
- struct wps_parse_attr attr;
- int wps2;
- if (tlvs == NULL) {
- wpa_printf(MSG_INFO, "WPS-STRICT: No TLVs in M2");
- return -1;
- }
- if (wps_parse_msg(tlvs, &attr) < 0) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Failed to parse attributes "
- "in M2");
- return -1;
- }
- wps2 = attr.version2 != NULL;
- if (wps_validate_version(attr.version, 1) ||
- wps_validate_msg_type(attr.msg_type, 1) ||
- wps_validate_enrollee_nonce(attr.enrollee_nonce, 1) ||
- wps_validate_registrar_nonce(attr.registrar_nonce, 1) ||
- wps_validate_uuid_r(attr.uuid_r, 1) ||
- wps_validate_public_key(attr.public_key, attr.public_key_len, 1) ||
- wps_validate_auth_type_flags(attr.auth_type_flags, 1) ||
- wps_validate_encr_type_flags(attr.encr_type_flags, 1) ||
- wps_validate_conn_type_flags(attr.conn_type_flags, 1) ||
- wps_validate_config_methods(attr.config_methods, wps2, 1) ||
- wps_validate_manufacturer(attr.manufacturer, attr.manufacturer_len,
- 1) ||
- wps_validate_model_name(attr.model_name, attr.model_name_len, 1) ||
- wps_validate_model_number(attr.model_number, attr.model_number_len,
- 1) ||
- wps_validate_serial_number(attr.serial_number,
- attr.serial_number_len, 1) ||
- wps_validate_primary_dev_type(attr.primary_dev_type, 1) ||
- wps_validate_dev_name(attr.dev_name, attr.dev_name_len, 1) ||
- wps_validate_rf_bands(attr.rf_bands, 1) ||
- wps_validate_assoc_state(attr.assoc_state, 1) ||
- wps_validate_config_error(attr.config_error, 1) ||
- wps_validate_dev_password_id(attr.dev_password_id, 1) ||
- wps_validate_os_version(attr.os_version, 1) ||
- wps_validate_version2(attr.version2, wps2) ||
- wps_validate_authenticator(attr.authenticator, 1)) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Invalid M2");
- #ifdef WPS_STRICT_WPS2
- if (wps2)
- return -1;
- #else /* WPS_STRICT_WPS2 */
- return -1;
- #endif /* WPS_STRICT_WPS2 */
- }
- return 0;
- }
- int wps_validate_m2d(const struct wpabuf *tlvs)
- {
- struct wps_parse_attr attr;
- int wps2;
- if (tlvs == NULL) {
- wpa_printf(MSG_INFO, "WPS-STRICT: No TLVs in M2D");
- return -1;
- }
- if (wps_parse_msg(tlvs, &attr) < 0) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Failed to parse attributes "
- "in M2D");
- return -1;
- }
- wps2 = attr.version2 != NULL;
- if (wps_validate_version(attr.version, 1) ||
- wps_validate_msg_type(attr.msg_type, 1) ||
- wps_validate_enrollee_nonce(attr.enrollee_nonce, 1) ||
- wps_validate_registrar_nonce(attr.registrar_nonce, 1) ||
- wps_validate_uuid_r(attr.uuid_r, 1) ||
- wps_validate_auth_type_flags(attr.auth_type_flags, 1) ||
- wps_validate_encr_type_flags(attr.encr_type_flags, 1) ||
- wps_validate_conn_type_flags(attr.conn_type_flags, 1) ||
- wps_validate_config_methods(attr.config_methods, wps2, 1) ||
- wps_validate_manufacturer(attr.manufacturer, attr.manufacturer_len,
- 1) ||
- wps_validate_model_name(attr.model_name, attr.model_name_len, 1) ||
- wps_validate_model_number(attr.model_number, attr.model_number_len,
- 1) ||
- wps_validate_serial_number(attr.serial_number,
- attr.serial_number_len, 1) ||
- wps_validate_primary_dev_type(attr.primary_dev_type, 1) ||
- wps_validate_dev_name(attr.dev_name, attr.dev_name_len, 1) ||
- wps_validate_rf_bands(attr.rf_bands, 1) ||
- wps_validate_assoc_state(attr.assoc_state, 1) ||
- wps_validate_config_error(attr.config_error, 1) ||
- wps_validate_os_version(attr.os_version, 1) ||
- wps_validate_version2(attr.version2, wps2)) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Invalid M2D");
- #ifdef WPS_STRICT_WPS2
- if (wps2)
- return -1;
- #else /* WPS_STRICT_WPS2 */
- return -1;
- #endif /* WPS_STRICT_WPS2 */
- }
- return 0;
- }
- int wps_validate_m3(const struct wpabuf *tlvs)
- {
- struct wps_parse_attr attr;
- int wps2;
- if (tlvs == NULL) {
- wpa_printf(MSG_INFO, "WPS-STRICT: No TLVs in M3");
- return -1;
- }
- if (wps_parse_msg(tlvs, &attr) < 0) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Failed to parse attributes "
- "in M3");
- return -1;
- }
- wps2 = attr.version2 != NULL;
- if (wps_validate_version(attr.version, 1) ||
- wps_validate_msg_type(attr.msg_type, 1) ||
- wps_validate_registrar_nonce(attr.registrar_nonce, 1) ||
- wps_validate_e_hash1(attr.e_hash1, 1) ||
- wps_validate_e_hash2(attr.e_hash2, 1) ||
- wps_validate_version2(attr.version2, wps2) ||
- wps_validate_authenticator(attr.authenticator, 1)) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Invalid M3");
- #ifdef WPS_STRICT_WPS2
- if (wps2)
- return -1;
- #else /* WPS_STRICT_WPS2 */
- return -1;
- #endif /* WPS_STRICT_WPS2 */
- }
- return 0;
- }
- int wps_validate_m4(const struct wpabuf *tlvs)
- {
- struct wps_parse_attr attr;
- int wps2;
- if (tlvs == NULL) {
- wpa_printf(MSG_INFO, "WPS-STRICT: No TLVs in M4");
- return -1;
- }
- if (wps_parse_msg(tlvs, &attr) < 0) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Failed to parse attributes "
- "in M4");
- return -1;
- }
- wps2 = attr.version2 != NULL;
- if (wps_validate_version(attr.version, 1) ||
- wps_validate_msg_type(attr.msg_type, 1) ||
- wps_validate_enrollee_nonce(attr.enrollee_nonce, 1) ||
- wps_validate_r_hash1(attr.r_hash1, 1) ||
- wps_validate_r_hash2(attr.r_hash2, 1) ||
- wps_validate_encr_settings(attr.encr_settings,
- attr.encr_settings_len, 1) ||
- wps_validate_version2(attr.version2, wps2) ||
- wps_validate_authenticator(attr.authenticator, 1)) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Invalid M4");
- #ifdef WPS_STRICT_WPS2
- if (wps2)
- return -1;
- #else /* WPS_STRICT_WPS2 */
- return -1;
- #endif /* WPS_STRICT_WPS2 */
- }
- return 0;
- }
- int wps_validate_m4_encr(const struct wpabuf *tlvs)
- {
- struct wps_parse_attr attr;
- int wps2;
- if (tlvs == NULL) {
- wpa_printf(MSG_INFO, "WPS-STRICT: No TLVs in M4 encrypted "
- "settings");
- return -1;
- }
- if (wps_parse_msg(tlvs, &attr) < 0) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Failed to parse attributes "
- "in M4 encrypted settings");
- return -1;
- }
- wps2 = attr.version2 != NULL;
- if (wps_validate_r_snonce1(attr.r_snonce1, 1) ||
- wps_validate_key_wrap_auth(attr.key_wrap_auth, 1)) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Invalid M4 encrypted "
- "settings");
- #ifdef WPS_STRICT_WPS2
- if (wps2)
- return -1;
- #else /* WPS_STRICT_WPS2 */
- return -1;
- #endif /* WPS_STRICT_WPS2 */
- }
- return 0;
- }
- int wps_validate_m5(const struct wpabuf *tlvs)
- {
- struct wps_parse_attr attr;
- int wps2;
- if (tlvs == NULL) {
- wpa_printf(MSG_INFO, "WPS-STRICT: No TLVs in M5");
- return -1;
- }
- if (wps_parse_msg(tlvs, &attr) < 0) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Failed to parse attributes "
- "in M5");
- return -1;
- }
- wps2 = attr.version2 != NULL;
- if (wps_validate_version(attr.version, 1) ||
- wps_validate_msg_type(attr.msg_type, 1) ||
- wps_validate_registrar_nonce(attr.registrar_nonce, 1) ||
- wps_validate_encr_settings(attr.encr_settings,
- attr.encr_settings_len, 1) ||
- wps_validate_version2(attr.version2, wps2) ||
- wps_validate_authenticator(attr.authenticator, 1)) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Invalid M5");
- #ifdef WPS_STRICT_WPS2
- if (wps2)
- return -1;
- #else /* WPS_STRICT_WPS2 */
- return -1;
- #endif /* WPS_STRICT_WPS2 */
- }
- return 0;
- }
- int wps_validate_m5_encr(const struct wpabuf *tlvs)
- {
- struct wps_parse_attr attr;
- int wps2;
- if (tlvs == NULL) {
- wpa_printf(MSG_INFO, "WPS-STRICT: No TLVs in M5 encrypted "
- "settings");
- return -1;
- }
- if (wps_parse_msg(tlvs, &attr) < 0) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Failed to parse attributes "
- "in M5 encrypted settings");
- return -1;
- }
- wps2 = attr.version2 != NULL;
- if (wps_validate_e_snonce1(attr.e_snonce1, 1) ||
- wps_validate_key_wrap_auth(attr.key_wrap_auth, 1)) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Invalid M5 encrypted "
- "settings");
- #ifdef WPS_STRICT_WPS2
- if (wps2)
- return -1;
- #else /* WPS_STRICT_WPS2 */
- return -1;
- #endif /* WPS_STRICT_WPS2 */
- }
- return 0;
- }
- int wps_validate_m6(const struct wpabuf *tlvs)
- {
- struct wps_parse_attr attr;
- int wps2;
- if (tlvs == NULL) {
- wpa_printf(MSG_INFO, "WPS-STRICT: No TLVs in M6");
- return -1;
- }
- if (wps_parse_msg(tlvs, &attr) < 0) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Failed to parse attributes "
- "in M6");
- return -1;
- }
- wps2 = attr.version2 != NULL;
- if (wps_validate_version(attr.version, 1) ||
- wps_validate_msg_type(attr.msg_type, 1) ||
- wps_validate_enrollee_nonce(attr.enrollee_nonce, 1) ||
- wps_validate_encr_settings(attr.encr_settings,
- attr.encr_settings_len, 1) ||
- wps_validate_version2(attr.version2, wps2) ||
- wps_validate_authenticator(attr.authenticator, 1)) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Invalid M6");
- #ifdef WPS_STRICT_WPS2
- if (wps2)
- return -1;
- #else /* WPS_STRICT_WPS2 */
- return -1;
- #endif /* WPS_STRICT_WPS2 */
- }
- return 0;
- }
- int wps_validate_m6_encr(const struct wpabuf *tlvs)
- {
- struct wps_parse_attr attr;
- int wps2;
- if (tlvs == NULL) {
- wpa_printf(MSG_INFO, "WPS-STRICT: No TLVs in M6 encrypted "
- "settings");
- return -1;
- }
- if (wps_parse_msg(tlvs, &attr) < 0) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Failed to parse attributes "
- "in M6 encrypted settings");
- return -1;
- }
- wps2 = attr.version2 != NULL;
- if (wps_validate_r_snonce2(attr.r_snonce2, 1) ||
- wps_validate_key_wrap_auth(attr.key_wrap_auth, 1)) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Invalid M6 encrypted "
- "settings");
- #ifdef WPS_STRICT_WPS2
- if (wps2)
- return -1;
- #else /* WPS_STRICT_WPS2 */
- return -1;
- #endif /* WPS_STRICT_WPS2 */
- }
- return 0;
- }
- int wps_validate_m7(const struct wpabuf *tlvs)
- {
- struct wps_parse_attr attr;
- int wps2;
- if (tlvs == NULL) {
- wpa_printf(MSG_INFO, "WPS-STRICT: No TLVs in M7");
- return -1;
- }
- if (wps_parse_msg(tlvs, &attr) < 0) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Failed to parse attributes "
- "in M7");
- return -1;
- }
- wps2 = attr.version2 != NULL;
- if (wps_validate_version(attr.version, 1) ||
- wps_validate_msg_type(attr.msg_type, 1) ||
- wps_validate_registrar_nonce(attr.registrar_nonce, 1) ||
- wps_validate_encr_settings(attr.encr_settings,
- attr.encr_settings_len, 1) ||
- wps_validate_settings_delay_time(attr.settings_delay_time, 0) ||
- wps_validate_version2(attr.version2, wps2) ||
- wps_validate_authenticator(attr.authenticator, 1)) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Invalid M7");
- #ifdef WPS_STRICT_WPS2
- if (wps2)
- return -1;
- #else /* WPS_STRICT_WPS2 */
- return -1;
- #endif /* WPS_STRICT_WPS2 */
- }
- return 0;
- }
- int wps_validate_m7_encr(const struct wpabuf *tlvs, int ap)
- {
- struct wps_parse_attr attr;
- int wps2;
- if (tlvs == NULL) {
- wpa_printf(MSG_INFO, "WPS-STRICT: No TLVs in M7 encrypted "
- "settings");
- return -1;
- }
- if (wps_parse_msg(tlvs, &attr) < 0) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Failed to parse attributes "
- "in M7 encrypted settings");
- return -1;
- }
- wps2 = attr.version2 != NULL;
- if (wps_validate_e_snonce2(attr.e_snonce2, 1) ||
- wps_validate_ssid(attr.ssid, attr.ssid_len, !ap) ||
- wps_validate_mac_addr(attr.mac_addr, !ap) ||
- wps_validate_auth_type(attr.auth_type, !ap) ||
- wps_validate_encr_type(attr.encr_type, !ap) ||
- wps_validate_network_key_index(attr.network_key_idx, 0) ||
- wps_validate_network_key(attr.network_key, attr.network_key_len,
- attr.encr_type, !ap) ||
- wps_validate_key_wrap_auth(attr.key_wrap_auth, 1)) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Invalid M7 encrypted "
- "settings");
- #ifdef WPS_STRICT_WPS2
- if (wps2)
- return -1;
- #else /* WPS_STRICT_WPS2 */
- return -1;
- #endif /* WPS_STRICT_WPS2 */
- }
- return 0;
- }
- int wps_validate_m8(const struct wpabuf *tlvs)
- {
- struct wps_parse_attr attr;
- int wps2;
- if (tlvs == NULL) {
- wpa_printf(MSG_INFO, "WPS-STRICT: No TLVs in M8");
- return -1;
- }
- if (wps_parse_msg(tlvs, &attr) < 0) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Failed to parse attributes "
- "in M8");
- return -1;
- }
- wps2 = attr.version2 != NULL;
- if (wps_validate_version(attr.version, 1) ||
- wps_validate_msg_type(attr.msg_type, 1) ||
- wps_validate_enrollee_nonce(attr.enrollee_nonce, 1) ||
- wps_validate_encr_settings(attr.encr_settings,
- attr.encr_settings_len, 1) ||
- wps_validate_version2(attr.version2, wps2) ||
- wps_validate_authenticator(attr.authenticator, 1)) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Invalid M8");
- #ifdef WPS_STRICT_WPS2
- if (wps2)
- return -1;
- #else /* WPS_STRICT_WPS2 */
- return -1;
- #endif /* WPS_STRICT_WPS2 */
- }
- return 0;
- }
- int wps_validate_m8_encr(const struct wpabuf *tlvs, int ap)
- {
- struct wps_parse_attr attr;
- int wps2;
- if (tlvs == NULL) {
- wpa_printf(MSG_INFO, "WPS-STRICT: No TLVs in M8 encrypted "
- "settings");
- return -1;
- }
- if (wps_parse_msg(tlvs, &attr) < 0) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Failed to parse attributes "
- "in M8 encrypted settings");
- return -1;
- }
- wps2 = attr.version2 != NULL;
- if (wps_validate_ssid(attr.ssid, attr.ssid_len, ap) ||
- wps_validate_auth_type(attr.auth_type, ap) ||
- wps_validate_encr_type(attr.encr_type, ap) ||
- wps_validate_network_key_index(attr.network_key_idx, 0) ||
- wps_validate_mac_addr(attr.mac_addr, ap) ||
- wps_validate_credential(attr.cred, attr.cred_len, attr.num_cred,
- !ap) ||
- wps_validate_key_wrap_auth(attr.key_wrap_auth, 1)) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Invalid M8 encrypted "
- "settings");
- #ifdef WPS_STRICT_WPS2
- if (wps2)
- return -1;
- #else /* WPS_STRICT_WPS2 */
- return -1;
- #endif /* WPS_STRICT_WPS2 */
- }
- return 0;
- }
- int wps_validate_wsc_ack(const struct wpabuf *tlvs)
- {
- struct wps_parse_attr attr;
- int wps2;
- if (tlvs == NULL) {
- wpa_printf(MSG_INFO, "WPS-STRICT: No TLVs in WSC_ACK");
- return -1;
- }
- if (wps_parse_msg(tlvs, &attr) < 0) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Failed to parse attributes "
- "in WSC_ACK");
- return -1;
- }
- wps2 = attr.version2 != NULL;
- if (wps_validate_version(attr.version, 1) ||
- wps_validate_msg_type(attr.msg_type, 1) ||
- wps_validate_enrollee_nonce(attr.enrollee_nonce, 1) ||
- wps_validate_registrar_nonce(attr.registrar_nonce, 1) ||
- wps_validate_version2(attr.version2, wps2)) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Invalid WSC_ACK");
- #ifdef WPS_STRICT_WPS2
- if (wps2)
- return -1;
- #else /* WPS_STRICT_WPS2 */
- return -1;
- #endif /* WPS_STRICT_WPS2 */
- }
- return 0;
- }
- int wps_validate_wsc_nack(const struct wpabuf *tlvs)
- {
- struct wps_parse_attr attr;
- int wps2;
- if (tlvs == NULL) {
- wpa_printf(MSG_INFO, "WPS-STRICT: No TLVs in WSC_NACK");
- return -1;
- }
- if (wps_parse_msg(tlvs, &attr) < 0) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Failed to parse attributes "
- "in WSC_NACK");
- return -1;
- }
- wps2 = attr.version2 != NULL;
- if (wps_validate_version(attr.version, 1) ||
- wps_validate_msg_type(attr.msg_type, 1) ||
- wps_validate_enrollee_nonce(attr.enrollee_nonce, 1) ||
- wps_validate_registrar_nonce(attr.registrar_nonce, 1) ||
- wps_validate_config_error(attr.config_error, 1) ||
- wps_validate_version2(attr.version2, wps2)) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Invalid WSC_NACK");
- #ifdef WPS_STRICT_WPS2
- if (wps2)
- return -1;
- #else /* WPS_STRICT_WPS2 */
- return -1;
- #endif /* WPS_STRICT_WPS2 */
- }
- return 0;
- }
- int wps_validate_wsc_done(const struct wpabuf *tlvs)
- {
- struct wps_parse_attr attr;
- int wps2;
- if (tlvs == NULL) {
- wpa_printf(MSG_INFO, "WPS-STRICT: No TLVs in WSC_Done");
- return -1;
- }
- if (wps_parse_msg(tlvs, &attr) < 0) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Failed to parse attributes "
- "in WSC_Done");
- return -1;
- }
- wps2 = attr.version2 != NULL;
- if (wps_validate_version(attr.version, 1) ||
- wps_validate_msg_type(attr.msg_type, 1) ||
- wps_validate_enrollee_nonce(attr.enrollee_nonce, 1) ||
- wps_validate_registrar_nonce(attr.registrar_nonce, 1) ||
- wps_validate_version2(attr.version2, wps2)) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Invalid WSC_Done");
- #ifdef WPS_STRICT_WPS2
- if (wps2)
- return -1;
- #else /* WPS_STRICT_WPS2 */
- return -1;
- #endif /* WPS_STRICT_WPS2 */
- }
- return 0;
- }
- int wps_validate_upnp_set_selected_registrar(const struct wpabuf *tlvs)
- {
- struct wps_parse_attr attr;
- int wps2;
- int sel_reg;
- if (tlvs == NULL) {
- wpa_printf(MSG_INFO, "WPS-STRICT: No TLVs in "
- "SetSelectedRegistrar");
- return -1;
- }
- if (wps_parse_msg(tlvs, &attr) < 0) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Failed to parse attributes "
- "in SetSelectedRegistrar");
- return -1;
- }
- wps2 = attr.version2 != NULL;
- sel_reg = attr.selected_registrar != NULL &&
- *attr.selected_registrar != 0;
- if (wps_validate_version(attr.version, 1) ||
- wps_validate_dev_password_id(attr.dev_password_id, sel_reg) ||
- wps_validate_sel_reg_config_methods(attr.sel_reg_config_methods,
- wps2, sel_reg) ||
- wps_validate_version2(attr.version2, wps2) ||
- wps_validate_authorized_macs(attr.authorized_macs,
- attr.authorized_macs_len, wps2) ||
- wps_validate_uuid_r(attr.uuid_r, wps2)) {
- wpa_printf(MSG_INFO, "WPS-STRICT: Invalid "
- "SetSelectedRegistrar");
- #ifdef WPS_STRICT_WPS2
- if (wps2)
- return -1;
- #else /* WPS_STRICT_WPS2 */
- return -1;
- #endif /* WPS_STRICT_WPS2 */
- }
- return 0;
- }
|