xref: /freebsd/contrib/wpa/src/wps/ndef.c (revision a90b9d0159070121c221b966469c3e36d912bf82)
1e28a4053SRui Paulo /*
2e28a4053SRui Paulo  * NDEF(NFC Data Exchange Format) routines for Wi-Fi Protected Setup
3e28a4053SRui Paulo  *   Reference is "NFCForum-TS-NDEF_1.0 2006-07-24".
4f05cddf9SRui Paulo  * Copyright (c) 2009-2012, Masashi Honma <masashi.honma@gmail.com>
5e28a4053SRui Paulo  *
6f05cddf9SRui Paulo  * This software may be distributed under the terms of the BSD license.
7f05cddf9SRui Paulo  * See README for more details.
8e28a4053SRui Paulo  */
9e28a4053SRui Paulo 
10e28a4053SRui Paulo #include "includes.h"
11e28a4053SRui Paulo #include "common.h"
12e28a4053SRui Paulo #include "wps/wps.h"
13e28a4053SRui Paulo 
14e28a4053SRui Paulo #define FLAG_MESSAGE_BEGIN (1 << 7)
15e28a4053SRui Paulo #define FLAG_MESSAGE_END (1 << 6)
16e28a4053SRui Paulo #define FLAG_CHUNK (1 << 5)
17e28a4053SRui Paulo #define FLAG_SHORT_RECORD (1 << 4)
18e28a4053SRui Paulo #define FLAG_ID_LENGTH_PRESENT (1 << 3)
19f05cddf9SRui Paulo #define FLAG_TNF_NFC_FORUM (0x01)
20e28a4053SRui Paulo #define FLAG_TNF_RFC2046 (0x02)
21e28a4053SRui Paulo 
22e28a4053SRui Paulo struct ndef_record {
23f05cddf9SRui Paulo 	const u8 *type;
24f05cddf9SRui Paulo 	const u8 *id;
25f05cddf9SRui Paulo 	const u8 *payload;
26e28a4053SRui Paulo 	u8 type_length;
27e28a4053SRui Paulo 	u8 id_length;
28e28a4053SRui Paulo 	u32 payload_length;
29e28a4053SRui Paulo 	u32 total_length;
30e28a4053SRui Paulo };
31e28a4053SRui Paulo 
32325151a3SRui Paulo static const char wifi_handover_type[] = "application/vnd.wfa.wsc";
33325151a3SRui Paulo static const char p2p_handover_type[] = "application/vnd.wfa.p2p";
34e28a4053SRui Paulo 
ndef_parse_record(const u8 * data,u32 size,struct ndef_record * record)35f05cddf9SRui Paulo static int ndef_parse_record(const u8 *data, u32 size,
36f05cddf9SRui Paulo 			     struct ndef_record *record)
37e28a4053SRui Paulo {
38f05cddf9SRui Paulo 	const u8 *pos = data + 1;
39e28a4053SRui Paulo 
40e28a4053SRui Paulo 	if (size < 2)
41e28a4053SRui Paulo 		return -1;
42e28a4053SRui Paulo 	record->type_length = *pos++;
43e28a4053SRui Paulo 	if (data[0] & FLAG_SHORT_RECORD) {
44e28a4053SRui Paulo 		if (size < 3)
45e28a4053SRui Paulo 			return -1;
46e28a4053SRui Paulo 		record->payload_length = *pos++;
47e28a4053SRui Paulo 	} else {
48325151a3SRui Paulo 		u32 len;
49325151a3SRui Paulo 
50e28a4053SRui Paulo 		if (size < 6)
51e28a4053SRui Paulo 			return -1;
52325151a3SRui Paulo 		len = WPA_GET_BE32(pos);
53325151a3SRui Paulo 		if (len > size - 6 || len > 20000)
54325151a3SRui Paulo 			return -1;
55325151a3SRui Paulo 		record->payload_length = len;
56e28a4053SRui Paulo 		pos += sizeof(u32);
57e28a4053SRui Paulo 	}
58e28a4053SRui Paulo 
59e28a4053SRui Paulo 	if (data[0] & FLAG_ID_LENGTH_PRESENT) {
60e28a4053SRui Paulo 		if ((int) size < pos - data + 1)
61e28a4053SRui Paulo 			return -1;
62e28a4053SRui Paulo 		record->id_length = *pos++;
63e28a4053SRui Paulo 	} else
64e28a4053SRui Paulo 		record->id_length = 0;
65e28a4053SRui Paulo 
66*a90b9d01SCy Schubert 	if (record->type_length > data + size - pos)
67*a90b9d01SCy Schubert 		return -1;
68e28a4053SRui Paulo 	record->type = record->type_length == 0 ? NULL : pos;
69e28a4053SRui Paulo 	pos += record->type_length;
70e28a4053SRui Paulo 
71*a90b9d01SCy Schubert 	if (record->id_length > data + size - pos)
72*a90b9d01SCy Schubert 		return -1;
73e28a4053SRui Paulo 	record->id = record->id_length == 0 ? NULL : pos;
74e28a4053SRui Paulo 	pos += record->id_length;
75e28a4053SRui Paulo 
76*a90b9d01SCy Schubert 	if (record->payload_length > (size_t) (data + size - pos))
77*a90b9d01SCy Schubert 		return -1;
78e28a4053SRui Paulo 	record->payload = record->payload_length == 0 ? NULL : pos;
79e28a4053SRui Paulo 	pos += record->payload_length;
80e28a4053SRui Paulo 
81e28a4053SRui Paulo 	record->total_length = pos - data;
82325151a3SRui Paulo 	if (record->total_length > size ||
83325151a3SRui Paulo 	    record->total_length < record->payload_length)
84e28a4053SRui Paulo 		return -1;
85e28a4053SRui Paulo 	return 0;
86e28a4053SRui Paulo }
87e28a4053SRui Paulo 
88e28a4053SRui Paulo 
ndef_parse_records(const struct wpabuf * buf,int (* filter)(struct ndef_record *))89f05cddf9SRui Paulo static struct wpabuf * ndef_parse_records(const struct wpabuf *buf,
90e28a4053SRui Paulo 					  int (*filter)(struct ndef_record *))
91e28a4053SRui Paulo {
92e28a4053SRui Paulo 	struct ndef_record record;
93e28a4053SRui Paulo 	int len = wpabuf_len(buf);
94f05cddf9SRui Paulo 	const u8 *data = wpabuf_head(buf);
95e28a4053SRui Paulo 
96e28a4053SRui Paulo 	while (len > 0) {
97e28a4053SRui Paulo 		if (ndef_parse_record(data, len, &record) < 0) {
98e28a4053SRui Paulo 			wpa_printf(MSG_ERROR, "NDEF : Failed to parse");
99e28a4053SRui Paulo 			return NULL;
100e28a4053SRui Paulo 		}
101e28a4053SRui Paulo 		if (filter == NULL || filter(&record))
102e28a4053SRui Paulo 			return wpabuf_alloc_copy(record.payload,
103e28a4053SRui Paulo 						 record.payload_length);
104e28a4053SRui Paulo 		data += record.total_length;
105e28a4053SRui Paulo 		len -= record.total_length;
106e28a4053SRui Paulo 	}
107e28a4053SRui Paulo 	wpa_printf(MSG_ERROR, "NDEF : Record not found");
108e28a4053SRui Paulo 	return NULL;
109e28a4053SRui Paulo }
110e28a4053SRui Paulo 
111e28a4053SRui Paulo 
ndef_build_record(u8 flags,const void * type,u8 type_length,void * id,u8 id_length,const struct wpabuf * payload)112325151a3SRui Paulo static struct wpabuf * ndef_build_record(u8 flags, const void *type,
113e28a4053SRui Paulo 					 u8 type_length, void *id,
114f05cddf9SRui Paulo 					 u8 id_length,
115f05cddf9SRui Paulo 					 const struct wpabuf *payload)
116e28a4053SRui Paulo {
117e28a4053SRui Paulo 	struct wpabuf *record;
118e28a4053SRui Paulo 	size_t total_len;
119e28a4053SRui Paulo 	int short_record;
120e28a4053SRui Paulo 	u8 local_flag;
121f05cddf9SRui Paulo 	size_t payload_length = wpabuf_len(payload);
122e28a4053SRui Paulo 
123e28a4053SRui Paulo 	short_record = payload_length < 256 ? 1 : 0;
124e28a4053SRui Paulo 
125e28a4053SRui Paulo 	total_len = 2; /* flag + type length */
126e28a4053SRui Paulo 	/* payload length */
127e28a4053SRui Paulo 	total_len += short_record ? sizeof(u8) : sizeof(u32);
128e28a4053SRui Paulo 	if (id_length > 0)
129e28a4053SRui Paulo 		total_len += 1;
130e28a4053SRui Paulo 	total_len += type_length + id_length + payload_length;
131e28a4053SRui Paulo 	record = wpabuf_alloc(total_len);
132e28a4053SRui Paulo 	if (record == NULL) {
133e28a4053SRui Paulo 		wpa_printf(MSG_ERROR, "NDEF : Failed to allocate "
134e28a4053SRui Paulo 			   "record for build");
135e28a4053SRui Paulo 		return NULL;
136e28a4053SRui Paulo 	}
137e28a4053SRui Paulo 
138e28a4053SRui Paulo 	local_flag = flags;
139e28a4053SRui Paulo 	if (id_length > 0)
140e28a4053SRui Paulo 		local_flag |= FLAG_ID_LENGTH_PRESENT;
141e28a4053SRui Paulo 	if (short_record)
142e28a4053SRui Paulo 		local_flag |= FLAG_SHORT_RECORD;
143e28a4053SRui Paulo 	wpabuf_put_u8(record, local_flag);
144e28a4053SRui Paulo 
145e28a4053SRui Paulo 	wpabuf_put_u8(record, type_length);
146e28a4053SRui Paulo 
147e28a4053SRui Paulo 	if (short_record)
148e28a4053SRui Paulo 		wpabuf_put_u8(record, payload_length);
149e28a4053SRui Paulo 	else
150e28a4053SRui Paulo 		wpabuf_put_be32(record, payload_length);
151e28a4053SRui Paulo 
152e28a4053SRui Paulo 	if (id_length > 0)
153e28a4053SRui Paulo 		wpabuf_put_u8(record, id_length);
154e28a4053SRui Paulo 	wpabuf_put_data(record, type, type_length);
155e28a4053SRui Paulo 	wpabuf_put_data(record, id, id_length);
156f05cddf9SRui Paulo 	wpabuf_put_buf(record, payload);
157e28a4053SRui Paulo 	return record;
158e28a4053SRui Paulo }
159e28a4053SRui Paulo 
160e28a4053SRui Paulo 
wifi_filter(struct ndef_record * record)161e28a4053SRui Paulo static int wifi_filter(struct ndef_record *record)
162e28a4053SRui Paulo {
1635b9c547cSRui Paulo 	if (record->type == NULL ||
1645b9c547cSRui Paulo 	    record->type_length != os_strlen(wifi_handover_type))
165e28a4053SRui Paulo 		return 0;
166e28a4053SRui Paulo 	if (os_memcmp(record->type, wifi_handover_type,
167e28a4053SRui Paulo 		      os_strlen(wifi_handover_type)) != 0)
168e28a4053SRui Paulo 		return 0;
169e28a4053SRui Paulo 	return 1;
170e28a4053SRui Paulo }
171e28a4053SRui Paulo 
172e28a4053SRui Paulo 
ndef_parse_wifi(const struct wpabuf * buf)173f05cddf9SRui Paulo struct wpabuf * ndef_parse_wifi(const struct wpabuf *buf)
174e28a4053SRui Paulo {
175e28a4053SRui Paulo 	return ndef_parse_records(buf, wifi_filter);
176e28a4053SRui Paulo }
177e28a4053SRui Paulo 
178e28a4053SRui Paulo 
ndef_build_wifi(const struct wpabuf * buf)179f05cddf9SRui Paulo struct wpabuf * ndef_build_wifi(const struct wpabuf *buf)
180e28a4053SRui Paulo {
181e28a4053SRui Paulo 	return ndef_build_record(FLAG_MESSAGE_BEGIN | FLAG_MESSAGE_END |
182e28a4053SRui Paulo 				 FLAG_TNF_RFC2046, wifi_handover_type,
183f05cddf9SRui Paulo 				 os_strlen(wifi_handover_type), NULL, 0, buf);
184f05cddf9SRui Paulo }
185f05cddf9SRui Paulo 
186f05cddf9SRui Paulo 
p2p_filter(struct ndef_record * record)1875b9c547cSRui Paulo static int p2p_filter(struct ndef_record *record)
188f05cddf9SRui Paulo {
1895b9c547cSRui Paulo 	if (record->type == NULL ||
1905b9c547cSRui Paulo 	    record->type_length != os_strlen(p2p_handover_type))
1915b9c547cSRui Paulo 		return 0;
1925b9c547cSRui Paulo 	if (os_memcmp(record->type, p2p_handover_type,
1935b9c547cSRui Paulo 		      os_strlen(p2p_handover_type)) != 0)
1945b9c547cSRui Paulo 		return 0;
1955b9c547cSRui Paulo 	return 1;
196f05cddf9SRui Paulo }
197f05cddf9SRui Paulo 
1985b9c547cSRui Paulo 
ndef_parse_p2p(const struct wpabuf * buf)1995b9c547cSRui Paulo struct wpabuf * ndef_parse_p2p(const struct wpabuf *buf)
2005b9c547cSRui Paulo {
2015b9c547cSRui Paulo 	return ndef_parse_records(buf, p2p_filter);
202f05cddf9SRui Paulo }
203f05cddf9SRui Paulo 
204f05cddf9SRui Paulo 
ndef_build_p2p(const struct wpabuf * buf)2055b9c547cSRui Paulo struct wpabuf * ndef_build_p2p(const struct wpabuf *buf)
2065b9c547cSRui Paulo {
2075b9c547cSRui Paulo 	return ndef_build_record(FLAG_MESSAGE_BEGIN | FLAG_MESSAGE_END |
2085b9c547cSRui Paulo 				 FLAG_TNF_RFC2046, p2p_handover_type,
2095b9c547cSRui Paulo 				 os_strlen(p2p_handover_type), NULL, 0, buf);
210e28a4053SRui Paulo }
211