First step: AutoIP compiled in and working

Dependencies:   mbed

Committer:
darran
Date:
Fri Jun 18 15:54:21 2010 +0000
Revision:
1:4218cacaf696
Parent:
0:55a05330f8cc

        

Who changed what in which revision?

UserRevisionLine numberNew contents of line
darran 0:55a05330f8cc 1 /*****************************************************************************
darran 0:55a05330f8cc 2 * pap.c - Network Password Authentication Protocol program file.
darran 0:55a05330f8cc 3 *
darran 0:55a05330f8cc 4 * Copyright (c) 2003 by Marc Boucher, Services Informatiques (MBSI) inc.
darran 0:55a05330f8cc 5 * portions Copyright (c) 1997 by Global Election Systems Inc.
darran 0:55a05330f8cc 6 *
darran 0:55a05330f8cc 7 * The authors hereby grant permission to use, copy, modify, distribute,
darran 0:55a05330f8cc 8 * and license this software and its documentation for any purpose, provided
darran 0:55a05330f8cc 9 * that existing copyright notices are retained in all copies and that this
darran 0:55a05330f8cc 10 * notice and the following disclaimer are included verbatim in any
darran 0:55a05330f8cc 11 * distributions. No written agreement, license, or royalty fee is required
darran 0:55a05330f8cc 12 * for any of the authorized uses.
darran 0:55a05330f8cc 13 *
darran 0:55a05330f8cc 14 * THIS SOFTWARE IS PROVIDED BY THE CONTRIBUTORS *AS IS* AND ANY EXPRESS OR
darran 0:55a05330f8cc 15 * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
darran 0:55a05330f8cc 16 * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.
darran 0:55a05330f8cc 17 * IN NO EVENT SHALL THE CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT,
darran 0:55a05330f8cc 18 * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
darran 0:55a05330f8cc 19 * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
darran 0:55a05330f8cc 20 * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
darran 0:55a05330f8cc 21 * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
darran 0:55a05330f8cc 22 * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
darran 0:55a05330f8cc 23 * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
darran 0:55a05330f8cc 24 *
darran 0:55a05330f8cc 25 ******************************************************************************
darran 0:55a05330f8cc 26 * REVISION HISTORY
darran 0:55a05330f8cc 27 *
darran 0:55a05330f8cc 28 * 03-01-01 Marc Boucher <marc@mbsi.ca>
darran 0:55a05330f8cc 29 * Ported to lwIP.
darran 0:55a05330f8cc 30 * 97-12-12 Guy Lancaster <lancasterg@acm.org>, Global Election Systems Inc.
darran 0:55a05330f8cc 31 * Original.
darran 0:55a05330f8cc 32 *****************************************************************************/
darran 0:55a05330f8cc 33 /*
darran 0:55a05330f8cc 34 * upap.c - User/Password Authentication Protocol.
darran 0:55a05330f8cc 35 *
darran 0:55a05330f8cc 36 * Copyright (c) 1989 Carnegie Mellon University.
darran 0:55a05330f8cc 37 * All rights reserved.
darran 0:55a05330f8cc 38 *
darran 0:55a05330f8cc 39 * Redistribution and use in source and binary forms are permitted
darran 0:55a05330f8cc 40 * provided that the above copyright notice and this paragraph are
darran 0:55a05330f8cc 41 * duplicated in all such forms and that any documentation,
darran 0:55a05330f8cc 42 * advertising materials, and other materials related to such
darran 0:55a05330f8cc 43 * distribution and use acknowledge that the software was developed
darran 0:55a05330f8cc 44 * by Carnegie Mellon University. The name of the
darran 0:55a05330f8cc 45 * University may not be used to endorse or promote products derived
darran 0:55a05330f8cc 46 * from this software without specific prior written permission.
darran 0:55a05330f8cc 47 * THIS SOFTWARE IS PROVIDED ``AS IS'' AND WITHOUT ANY EXPRESS OR
darran 0:55a05330f8cc 48 * IMPLIED WARRANTIES, INCLUDING, WITHOUT LIMITATION, THE IMPLIED
darran 0:55a05330f8cc 49 * WARRANTIES OF MERCHANTIBILITY AND FITNESS FOR A PARTICULAR PURPOSE.
darran 0:55a05330f8cc 50 */
darran 0:55a05330f8cc 51
darran 0:55a05330f8cc 52 #include "lwip/opt.h"
darran 0:55a05330f8cc 53
darran 0:55a05330f8cc 54 #if PPP_SUPPORT /* don't build if not configured for use in lwipopts.h */
darran 0:55a05330f8cc 55
darran 0:55a05330f8cc 56 #if PAP_SUPPORT /* don't build if not configured for use in lwipopts.h */
darran 0:55a05330f8cc 57
darran 0:55a05330f8cc 58 #include "ppp.h"
darran 0:55a05330f8cc 59 #include "pppdebug.h"
darran 0:55a05330f8cc 60
darran 0:55a05330f8cc 61 #include "auth.h"
darran 0:55a05330f8cc 62 #include "pap.h"
darran 0:55a05330f8cc 63
darran 0:55a05330f8cc 64 #include <string.h>
darran 0:55a05330f8cc 65
darran 0:55a05330f8cc 66 #if 0 /* UNUSED */
darran 0:55a05330f8cc 67 static bool hide_password = 1;
darran 0:55a05330f8cc 68
darran 0:55a05330f8cc 69 /*
darran 0:55a05330f8cc 70 * Command-line options.
darran 0:55a05330f8cc 71 */
darran 0:55a05330f8cc 72 static option_t pap_option_list[] = {
darran 0:55a05330f8cc 73 { "hide-password", o_bool, &hide_password,
darran 0:55a05330f8cc 74 "Don't output passwords to log", 1 },
darran 0:55a05330f8cc 75 { "show-password", o_bool, &hide_password,
darran 0:55a05330f8cc 76 "Show password string in debug log messages", 0 },
darran 0:55a05330f8cc 77 { "pap-restart", o_int, &upap[0].us_timeouttime,
darran 0:55a05330f8cc 78 "Set retransmit timeout for PAP" },
darran 0:55a05330f8cc 79 { "pap-max-authreq", o_int, &upap[0].us_maxtransmits,
darran 0:55a05330f8cc 80 "Set max number of transmissions for auth-reqs" },
darran 0:55a05330f8cc 81 { "pap-timeout", o_int, &upap[0].us_reqtimeout,
darran 0:55a05330f8cc 82 "Set time limit for peer PAP authentication" },
darran 0:55a05330f8cc 83 { NULL }
darran 0:55a05330f8cc 84 };
darran 0:55a05330f8cc 85 #endif
darran 0:55a05330f8cc 86
darran 0:55a05330f8cc 87 /*
darran 0:55a05330f8cc 88 * Protocol entry points.
darran 0:55a05330f8cc 89 */
darran 0:55a05330f8cc 90 static void upap_init (int);
darran 0:55a05330f8cc 91 static void upap_lowerup (int);
darran 0:55a05330f8cc 92 static void upap_lowerdown (int);
darran 0:55a05330f8cc 93 static void upap_input (int, u_char *, int);
darran 0:55a05330f8cc 94 static void upap_protrej (int);
darran 0:55a05330f8cc 95 #if PPP_ADDITIONAL_CALLBACKS
darran 0:55a05330f8cc 96 static int upap_printpkt (u_char *, int, void (*)(void *, char *, ...), void *);
darran 0:55a05330f8cc 97 #endif /* PPP_ADDITIONAL_CALLBACKS */
darran 0:55a05330f8cc 98
darran 0:55a05330f8cc 99 struct protent pap_protent = {
darran 0:55a05330f8cc 100 PPP_PAP,
darran 0:55a05330f8cc 101 upap_init,
darran 0:55a05330f8cc 102 upap_input,
darran 0:55a05330f8cc 103 upap_protrej,
darran 0:55a05330f8cc 104 upap_lowerup,
darran 0:55a05330f8cc 105 upap_lowerdown,
darran 0:55a05330f8cc 106 NULL,
darran 0:55a05330f8cc 107 NULL,
darran 0:55a05330f8cc 108 #if PPP_ADDITIONAL_CALLBACKS
darran 0:55a05330f8cc 109 upap_printpkt,
darran 0:55a05330f8cc 110 NULL,
darran 0:55a05330f8cc 111 #endif /* PPP_ADDITIONAL_CALLBACKS */
darran 0:55a05330f8cc 112 1,
darran 0:55a05330f8cc 113 "PAP",
darran 0:55a05330f8cc 114 #if PPP_ADDITIONAL_CALLBACKS
darran 0:55a05330f8cc 115 NULL,
darran 0:55a05330f8cc 116 NULL,
darran 0:55a05330f8cc 117 NULL
darran 0:55a05330f8cc 118 #endif /* PPP_ADDITIONAL_CALLBACKS */
darran 0:55a05330f8cc 119 };
darran 0:55a05330f8cc 120
darran 0:55a05330f8cc 121 upap_state upap[NUM_PPP]; /* UPAP state; one for each unit */
darran 0:55a05330f8cc 122
darran 0:55a05330f8cc 123 static void upap_timeout (void *);
darran 0:55a05330f8cc 124 static void upap_reqtimeout(void *);
darran 0:55a05330f8cc 125 static void upap_rauthreq (upap_state *, u_char *, u_char, int);
darran 0:55a05330f8cc 126 static void upap_rauthack (upap_state *, u_char *, int, int);
darran 0:55a05330f8cc 127 static void upap_rauthnak (upap_state *, u_char *, int, int);
darran 0:55a05330f8cc 128 static void upap_sauthreq (upap_state *);
darran 0:55a05330f8cc 129 static void upap_sresp (upap_state *, u_char, u_char, char *, int);
darran 0:55a05330f8cc 130
darran 0:55a05330f8cc 131
darran 0:55a05330f8cc 132 /*
darran 0:55a05330f8cc 133 * upap_init - Initialize a UPAP unit.
darran 0:55a05330f8cc 134 */
darran 0:55a05330f8cc 135 static void
darran 0:55a05330f8cc 136 upap_init(int unit)
darran 0:55a05330f8cc 137 {
darran 0:55a05330f8cc 138 upap_state *u = &upap[unit];
darran 0:55a05330f8cc 139
darran 0:55a05330f8cc 140 UPAPDEBUG(LOG_INFO, ("upap_init: %d\n", unit));
darran 0:55a05330f8cc 141 u->us_unit = unit;
darran 0:55a05330f8cc 142 u->us_user = NULL;
darran 0:55a05330f8cc 143 u->us_userlen = 0;
darran 0:55a05330f8cc 144 u->us_passwd = NULL;
darran 0:55a05330f8cc 145 u->us_passwdlen = 0;
darran 0:55a05330f8cc 146 u->us_clientstate = UPAPCS_INITIAL;
darran 0:55a05330f8cc 147 u->us_serverstate = UPAPSS_INITIAL;
darran 0:55a05330f8cc 148 u->us_id = 0;
darran 0:55a05330f8cc 149 u->us_timeouttime = UPAP_DEFTIMEOUT;
darran 0:55a05330f8cc 150 u->us_maxtransmits = 10;
darran 0:55a05330f8cc 151 u->us_reqtimeout = UPAP_DEFREQTIME;
darran 0:55a05330f8cc 152 }
darran 0:55a05330f8cc 153
darran 0:55a05330f8cc 154 /*
darran 0:55a05330f8cc 155 * upap_authwithpeer - Authenticate us with our peer (start client).
darran 0:55a05330f8cc 156 *
darran 0:55a05330f8cc 157 * Set new state and send authenticate's.
darran 0:55a05330f8cc 158 */
darran 0:55a05330f8cc 159 void
darran 0:55a05330f8cc 160 upap_authwithpeer(int unit, char *user, char *password)
darran 0:55a05330f8cc 161 {
darran 0:55a05330f8cc 162 upap_state *u = &upap[unit];
darran 0:55a05330f8cc 163
darran 0:55a05330f8cc 164 UPAPDEBUG(LOG_INFO, ("upap_authwithpeer: %d user=%s password=%s s=%d\n",
darran 0:55a05330f8cc 165 unit, user, password, u->us_clientstate));
darran 0:55a05330f8cc 166
darran 0:55a05330f8cc 167 /* Save the username and password we're given */
darran 0:55a05330f8cc 168 u->us_user = user;
darran 0:55a05330f8cc 169 u->us_userlen = (int)strlen(user);
darran 0:55a05330f8cc 170 u->us_passwd = password;
darran 0:55a05330f8cc 171 u->us_passwdlen = (int)strlen(password);
darran 0:55a05330f8cc 172
darran 0:55a05330f8cc 173 u->us_transmits = 0;
darran 0:55a05330f8cc 174
darran 0:55a05330f8cc 175 /* Lower layer up yet? */
darran 0:55a05330f8cc 176 if (u->us_clientstate == UPAPCS_INITIAL ||
darran 0:55a05330f8cc 177 u->us_clientstate == UPAPCS_PENDING) {
darran 0:55a05330f8cc 178 u->us_clientstate = UPAPCS_PENDING;
darran 0:55a05330f8cc 179 return;
darran 0:55a05330f8cc 180 }
darran 0:55a05330f8cc 181
darran 0:55a05330f8cc 182 upap_sauthreq(u); /* Start protocol */
darran 0:55a05330f8cc 183 }
darran 0:55a05330f8cc 184
darran 0:55a05330f8cc 185
darran 0:55a05330f8cc 186 /*
darran 0:55a05330f8cc 187 * upap_authpeer - Authenticate our peer (start server).
darran 0:55a05330f8cc 188 *
darran 0:55a05330f8cc 189 * Set new state.
darran 0:55a05330f8cc 190 */
darran 0:55a05330f8cc 191 void
darran 0:55a05330f8cc 192 upap_authpeer(int unit)
darran 0:55a05330f8cc 193 {
darran 0:55a05330f8cc 194 upap_state *u = &upap[unit];
darran 0:55a05330f8cc 195
darran 0:55a05330f8cc 196 /* Lower layer up yet? */
darran 0:55a05330f8cc 197 if (u->us_serverstate == UPAPSS_INITIAL ||
darran 0:55a05330f8cc 198 u->us_serverstate == UPAPSS_PENDING) {
darran 0:55a05330f8cc 199 u->us_serverstate = UPAPSS_PENDING;
darran 0:55a05330f8cc 200 return;
darran 0:55a05330f8cc 201 }
darran 0:55a05330f8cc 202
darran 0:55a05330f8cc 203 u->us_serverstate = UPAPSS_LISTEN;
darran 0:55a05330f8cc 204 if (u->us_reqtimeout > 0) {
darran 0:55a05330f8cc 205 TIMEOUT(upap_reqtimeout, u, u->us_reqtimeout);
darran 0:55a05330f8cc 206 }
darran 0:55a05330f8cc 207 }
darran 0:55a05330f8cc 208
darran 0:55a05330f8cc 209 /*
darran 0:55a05330f8cc 210 * upap_timeout - Retransmission timer for sending auth-reqs expired.
darran 0:55a05330f8cc 211 */
darran 0:55a05330f8cc 212 static void
darran 0:55a05330f8cc 213 upap_timeout(void *arg)
darran 0:55a05330f8cc 214 {
darran 0:55a05330f8cc 215 upap_state *u = (upap_state *) arg;
darran 0:55a05330f8cc 216
darran 0:55a05330f8cc 217 UPAPDEBUG(LOG_INFO, ("upap_timeout: %d timeout %d expired s=%d\n",
darran 0:55a05330f8cc 218 u->us_unit, u->us_timeouttime, u->us_clientstate));
darran 0:55a05330f8cc 219
darran 0:55a05330f8cc 220 if (u->us_clientstate != UPAPCS_AUTHREQ) {
darran 0:55a05330f8cc 221 UPAPDEBUG(LOG_INFO, ("upap_timeout: not in AUTHREQ state!\n"));
darran 0:55a05330f8cc 222 return;
darran 0:55a05330f8cc 223 }
darran 0:55a05330f8cc 224
darran 0:55a05330f8cc 225 if (u->us_transmits >= u->us_maxtransmits) {
darran 0:55a05330f8cc 226 /* give up in disgust */
darran 0:55a05330f8cc 227 UPAPDEBUG(LOG_ERR, ("No response to PAP authenticate-requests\n"));
darran 0:55a05330f8cc 228 u->us_clientstate = UPAPCS_BADAUTH;
darran 0:55a05330f8cc 229 auth_withpeer_fail(u->us_unit, PPP_PAP);
darran 0:55a05330f8cc 230 return;
darran 0:55a05330f8cc 231 }
darran 0:55a05330f8cc 232
darran 0:55a05330f8cc 233 upap_sauthreq(u); /* Send Authenticate-Request and set upap timeout*/
darran 0:55a05330f8cc 234 }
darran 0:55a05330f8cc 235
darran 0:55a05330f8cc 236
darran 0:55a05330f8cc 237 /*
darran 0:55a05330f8cc 238 * upap_reqtimeout - Give up waiting for the peer to send an auth-req.
darran 0:55a05330f8cc 239 */
darran 0:55a05330f8cc 240 static void
darran 0:55a05330f8cc 241 upap_reqtimeout(void *arg)
darran 0:55a05330f8cc 242 {
darran 0:55a05330f8cc 243 upap_state *u = (upap_state *) arg;
darran 0:55a05330f8cc 244
darran 0:55a05330f8cc 245 if (u->us_serverstate != UPAPSS_LISTEN) {
darran 0:55a05330f8cc 246 return; /* huh?? */
darran 0:55a05330f8cc 247 }
darran 0:55a05330f8cc 248
darran 0:55a05330f8cc 249 auth_peer_fail(u->us_unit, PPP_PAP);
darran 0:55a05330f8cc 250 u->us_serverstate = UPAPSS_BADAUTH;
darran 0:55a05330f8cc 251 }
darran 0:55a05330f8cc 252
darran 0:55a05330f8cc 253
darran 0:55a05330f8cc 254 /*
darran 0:55a05330f8cc 255 * upap_lowerup - The lower layer is up.
darran 0:55a05330f8cc 256 *
darran 0:55a05330f8cc 257 * Start authenticating if pending.
darran 0:55a05330f8cc 258 */
darran 0:55a05330f8cc 259 static void
darran 0:55a05330f8cc 260 upap_lowerup(int unit)
darran 0:55a05330f8cc 261 {
darran 0:55a05330f8cc 262 upap_state *u = &upap[unit];
darran 0:55a05330f8cc 263
darran 0:55a05330f8cc 264 UPAPDEBUG(LOG_INFO, ("upap_lowerup: init %d clientstate s=%d\n", unit, u->us_clientstate));
darran 0:55a05330f8cc 265
darran 0:55a05330f8cc 266 if (u->us_clientstate == UPAPCS_INITIAL) {
darran 0:55a05330f8cc 267 u->us_clientstate = UPAPCS_CLOSED;
darran 0:55a05330f8cc 268 } else if (u->us_clientstate == UPAPCS_PENDING) {
darran 0:55a05330f8cc 269 upap_sauthreq(u); /* send an auth-request */
darran 0:55a05330f8cc 270 /* now client state is UPAPCS__AUTHREQ */
darran 0:55a05330f8cc 271 }
darran 0:55a05330f8cc 272
darran 0:55a05330f8cc 273 if (u->us_serverstate == UPAPSS_INITIAL) {
darran 0:55a05330f8cc 274 u->us_serverstate = UPAPSS_CLOSED;
darran 0:55a05330f8cc 275 } else if (u->us_serverstate == UPAPSS_PENDING) {
darran 0:55a05330f8cc 276 u->us_serverstate = UPAPSS_LISTEN;
darran 0:55a05330f8cc 277 if (u->us_reqtimeout > 0) {
darran 0:55a05330f8cc 278 TIMEOUT(upap_reqtimeout, u, u->us_reqtimeout);
darran 0:55a05330f8cc 279 }
darran 0:55a05330f8cc 280 }
darran 0:55a05330f8cc 281 }
darran 0:55a05330f8cc 282
darran 0:55a05330f8cc 283
darran 0:55a05330f8cc 284 /*
darran 0:55a05330f8cc 285 * upap_lowerdown - The lower layer is down.
darran 0:55a05330f8cc 286 *
darran 0:55a05330f8cc 287 * Cancel all timeouts.
darran 0:55a05330f8cc 288 */
darran 0:55a05330f8cc 289 static void
darran 0:55a05330f8cc 290 upap_lowerdown(int unit)
darran 0:55a05330f8cc 291 {
darran 0:55a05330f8cc 292 upap_state *u = &upap[unit];
darran 0:55a05330f8cc 293
darran 0:55a05330f8cc 294 UPAPDEBUG(LOG_INFO, ("upap_lowerdown: %d s=%d\n", unit, u->us_clientstate));
darran 0:55a05330f8cc 295
darran 0:55a05330f8cc 296 if (u->us_clientstate == UPAPCS_AUTHREQ) { /* Timeout pending? */
darran 0:55a05330f8cc 297 UNTIMEOUT(upap_timeout, u); /* Cancel timeout */
darran 0:55a05330f8cc 298 }
darran 0:55a05330f8cc 299 if (u->us_serverstate == UPAPSS_LISTEN && u->us_reqtimeout > 0) {
darran 0:55a05330f8cc 300 UNTIMEOUT(upap_reqtimeout, u);
darran 0:55a05330f8cc 301 }
darran 0:55a05330f8cc 302
darran 0:55a05330f8cc 303 u->us_clientstate = UPAPCS_INITIAL;
darran 0:55a05330f8cc 304 u->us_serverstate = UPAPSS_INITIAL;
darran 0:55a05330f8cc 305 }
darran 0:55a05330f8cc 306
darran 0:55a05330f8cc 307
darran 0:55a05330f8cc 308 /*
darran 0:55a05330f8cc 309 * upap_protrej - Peer doesn't speak this protocol.
darran 0:55a05330f8cc 310 *
darran 0:55a05330f8cc 311 * This shouldn't happen. In any case, pretend lower layer went down.
darran 0:55a05330f8cc 312 */
darran 0:55a05330f8cc 313 static void
darran 0:55a05330f8cc 314 upap_protrej(int unit)
darran 0:55a05330f8cc 315 {
darran 0:55a05330f8cc 316 upap_state *u = &upap[unit];
darran 0:55a05330f8cc 317
darran 0:55a05330f8cc 318 if (u->us_clientstate == UPAPCS_AUTHREQ) {
darran 0:55a05330f8cc 319 UPAPDEBUG(LOG_ERR, ("PAP authentication failed due to protocol-reject\n"));
darran 0:55a05330f8cc 320 auth_withpeer_fail(unit, PPP_PAP);
darran 0:55a05330f8cc 321 }
darran 0:55a05330f8cc 322 if (u->us_serverstate == UPAPSS_LISTEN) {
darran 0:55a05330f8cc 323 UPAPDEBUG(LOG_ERR, ("PAP authentication of peer failed (protocol-reject)\n"));
darran 0:55a05330f8cc 324 auth_peer_fail(unit, PPP_PAP);
darran 0:55a05330f8cc 325 }
darran 0:55a05330f8cc 326 upap_lowerdown(unit);
darran 0:55a05330f8cc 327 }
darran 0:55a05330f8cc 328
darran 0:55a05330f8cc 329
darran 0:55a05330f8cc 330 /*
darran 0:55a05330f8cc 331 * upap_input - Input UPAP packet.
darran 0:55a05330f8cc 332 */
darran 0:55a05330f8cc 333 static void
darran 0:55a05330f8cc 334 upap_input(int unit, u_char *inpacket, int l)
darran 0:55a05330f8cc 335 {
darran 0:55a05330f8cc 336 upap_state *u = &upap[unit];
darran 0:55a05330f8cc 337 u_char *inp;
darran 0:55a05330f8cc 338 u_char code, id;
darran 0:55a05330f8cc 339 int len;
darran 0:55a05330f8cc 340
darran 0:55a05330f8cc 341 /*
darran 0:55a05330f8cc 342 * Parse header (code, id and length).
darran 0:55a05330f8cc 343 * If packet too short, drop it.
darran 0:55a05330f8cc 344 */
darran 0:55a05330f8cc 345 inp = inpacket;
darran 0:55a05330f8cc 346 if (l < (int)UPAP_HEADERLEN) {
darran 0:55a05330f8cc 347 UPAPDEBUG(LOG_INFO, ("pap_input: rcvd short header.\n"));
darran 0:55a05330f8cc 348 return;
darran 0:55a05330f8cc 349 }
darran 0:55a05330f8cc 350 GETCHAR(code, inp);
darran 0:55a05330f8cc 351 GETCHAR(id, inp);
darran 0:55a05330f8cc 352 GETSHORT(len, inp);
darran 0:55a05330f8cc 353 if (len < (int)UPAP_HEADERLEN) {
darran 0:55a05330f8cc 354 UPAPDEBUG(LOG_INFO, ("pap_input: rcvd illegal length.\n"));
darran 0:55a05330f8cc 355 return;
darran 0:55a05330f8cc 356 }
darran 0:55a05330f8cc 357 if (len > l) {
darran 0:55a05330f8cc 358 UPAPDEBUG(LOG_INFO, ("pap_input: rcvd short packet.\n"));
darran 0:55a05330f8cc 359 return;
darran 0:55a05330f8cc 360 }
darran 0:55a05330f8cc 361 len -= UPAP_HEADERLEN;
darran 0:55a05330f8cc 362
darran 0:55a05330f8cc 363 /*
darran 0:55a05330f8cc 364 * Action depends on code.
darran 0:55a05330f8cc 365 */
darran 0:55a05330f8cc 366 switch (code) {
darran 0:55a05330f8cc 367 case UPAP_AUTHREQ:
darran 0:55a05330f8cc 368 upap_rauthreq(u, inp, id, len);
darran 0:55a05330f8cc 369 break;
darran 0:55a05330f8cc 370
darran 0:55a05330f8cc 371 case UPAP_AUTHACK:
darran 0:55a05330f8cc 372 upap_rauthack(u, inp, id, len);
darran 0:55a05330f8cc 373 break;
darran 0:55a05330f8cc 374
darran 0:55a05330f8cc 375 case UPAP_AUTHNAK:
darran 0:55a05330f8cc 376 upap_rauthnak(u, inp, id, len);
darran 0:55a05330f8cc 377 break;
darran 0:55a05330f8cc 378
darran 0:55a05330f8cc 379 default: /* XXX Need code reject */
darran 0:55a05330f8cc 380 UPAPDEBUG(LOG_INFO, ("pap_input: UNHANDLED default: code: %d, id: %d, len: %d.\n", code, id, len));
darran 0:55a05330f8cc 381 break;
darran 0:55a05330f8cc 382 }
darran 0:55a05330f8cc 383 }
darran 0:55a05330f8cc 384
darran 0:55a05330f8cc 385
darran 0:55a05330f8cc 386 /*
darran 0:55a05330f8cc 387 * upap_rauth - Receive Authenticate.
darran 0:55a05330f8cc 388 */
darran 0:55a05330f8cc 389 static void
darran 0:55a05330f8cc 390 upap_rauthreq(upap_state *u, u_char *inp, u_char id, int len)
darran 0:55a05330f8cc 391 {
darran 0:55a05330f8cc 392 u_char ruserlen, rpasswdlen;
darran 0:55a05330f8cc 393 char *ruser, *rpasswd;
darran 0:55a05330f8cc 394 u_char retcode;
darran 0:55a05330f8cc 395 char *msg;
darran 0:55a05330f8cc 396 int msglen;
darran 0:55a05330f8cc 397
darran 0:55a05330f8cc 398 UPAPDEBUG(LOG_INFO, ("pap_rauth: Rcvd id %d.\n", id));
darran 0:55a05330f8cc 399
darran 0:55a05330f8cc 400 if (u->us_serverstate < UPAPSS_LISTEN) {
darran 0:55a05330f8cc 401 return;
darran 0:55a05330f8cc 402 }
darran 0:55a05330f8cc 403
darran 0:55a05330f8cc 404 /*
darran 0:55a05330f8cc 405 * If we receive a duplicate authenticate-request, we are
darran 0:55a05330f8cc 406 * supposed to return the same status as for the first request.
darran 0:55a05330f8cc 407 */
darran 0:55a05330f8cc 408 if (u->us_serverstate == UPAPSS_OPEN) {
darran 0:55a05330f8cc 409 upap_sresp(u, UPAP_AUTHACK, id, "", 0); /* return auth-ack */
darran 0:55a05330f8cc 410 return;
darran 0:55a05330f8cc 411 }
darran 0:55a05330f8cc 412 if (u->us_serverstate == UPAPSS_BADAUTH) {
darran 0:55a05330f8cc 413 upap_sresp(u, UPAP_AUTHNAK, id, "", 0); /* return auth-nak */
darran 0:55a05330f8cc 414 return;
darran 0:55a05330f8cc 415 }
darran 0:55a05330f8cc 416
darran 0:55a05330f8cc 417 /*
darran 0:55a05330f8cc 418 * Parse user/passwd.
darran 0:55a05330f8cc 419 */
darran 0:55a05330f8cc 420 if (len < (int)sizeof (u_char)) {
darran 0:55a05330f8cc 421 UPAPDEBUG(LOG_INFO, ("pap_rauth: rcvd short packet.\n"));
darran 0:55a05330f8cc 422 return;
darran 0:55a05330f8cc 423 }
darran 0:55a05330f8cc 424 GETCHAR(ruserlen, inp);
darran 0:55a05330f8cc 425 len -= sizeof (u_char) + ruserlen + sizeof (u_char);
darran 0:55a05330f8cc 426 if (len < 0) {
darran 0:55a05330f8cc 427 UPAPDEBUG(LOG_INFO, ("pap_rauth: rcvd short packet.\n"));
darran 0:55a05330f8cc 428 return;
darran 0:55a05330f8cc 429 }
darran 0:55a05330f8cc 430 ruser = (char *) inp;
darran 0:55a05330f8cc 431 INCPTR(ruserlen, inp);
darran 0:55a05330f8cc 432 GETCHAR(rpasswdlen, inp);
darran 0:55a05330f8cc 433 if (len < rpasswdlen) {
darran 0:55a05330f8cc 434 UPAPDEBUG(LOG_INFO, ("pap_rauth: rcvd short packet.\n"));
darran 0:55a05330f8cc 435 return;
darran 0:55a05330f8cc 436 }
darran 0:55a05330f8cc 437 rpasswd = (char *) inp;
darran 0:55a05330f8cc 438
darran 0:55a05330f8cc 439 /*
darran 0:55a05330f8cc 440 * Check the username and password given.
darran 0:55a05330f8cc 441 */
darran 0:55a05330f8cc 442 retcode = check_passwd(u->us_unit, ruser, ruserlen, rpasswd, rpasswdlen, &msg, &msglen);
darran 0:55a05330f8cc 443 /* lwip: currently retcode is always UPAP_AUTHACK */
darran 0:55a05330f8cc 444 BZERO(rpasswd, rpasswdlen);
darran 0:55a05330f8cc 445
darran 0:55a05330f8cc 446 upap_sresp(u, retcode, id, msg, msglen);
darran 0:55a05330f8cc 447
darran 0:55a05330f8cc 448 if (retcode == UPAP_AUTHACK) {
darran 0:55a05330f8cc 449 u->us_serverstate = UPAPSS_OPEN;
darran 0:55a05330f8cc 450 auth_peer_success(u->us_unit, PPP_PAP, ruser, ruserlen);
darran 0:55a05330f8cc 451 } else {
darran 0:55a05330f8cc 452 u->us_serverstate = UPAPSS_BADAUTH;
darran 0:55a05330f8cc 453 auth_peer_fail(u->us_unit, PPP_PAP);
darran 0:55a05330f8cc 454 }
darran 0:55a05330f8cc 455
darran 0:55a05330f8cc 456 if (u->us_reqtimeout > 0) {
darran 0:55a05330f8cc 457 UNTIMEOUT(upap_reqtimeout, u);
darran 0:55a05330f8cc 458 }
darran 0:55a05330f8cc 459 }
darran 0:55a05330f8cc 460
darran 0:55a05330f8cc 461
darran 0:55a05330f8cc 462 /*
darran 0:55a05330f8cc 463 * upap_rauthack - Receive Authenticate-Ack.
darran 0:55a05330f8cc 464 */
darran 0:55a05330f8cc 465 static void
darran 0:55a05330f8cc 466 upap_rauthack(upap_state *u, u_char *inp, int id, int len)
darran 0:55a05330f8cc 467 {
darran 0:55a05330f8cc 468 u_char msglen;
darran 0:55a05330f8cc 469 char *msg;
darran 0:55a05330f8cc 470
darran 0:55a05330f8cc 471 LWIP_UNUSED_ARG(id);
darran 0:55a05330f8cc 472
darran 0:55a05330f8cc 473 UPAPDEBUG(LOG_INFO, ("pap_rauthack: Rcvd id %d s=%d\n", id, u->us_clientstate));
darran 0:55a05330f8cc 474
darran 0:55a05330f8cc 475 if (u->us_clientstate != UPAPCS_AUTHREQ) { /* XXX */
darran 0:55a05330f8cc 476 UPAPDEBUG(LOG_INFO, ("pap_rauthack: us_clientstate != UPAPCS_AUTHREQ\n"));
darran 0:55a05330f8cc 477 return;
darran 0:55a05330f8cc 478 }
darran 0:55a05330f8cc 479
darran 0:55a05330f8cc 480 /*
darran 0:55a05330f8cc 481 * Parse message.
darran 0:55a05330f8cc 482 */
darran 0:55a05330f8cc 483 if (len < (int)sizeof (u_char)) {
darran 0:55a05330f8cc 484 UPAPDEBUG(LOG_INFO, ("pap_rauthack: ignoring missing msg-length.\n"));
darran 0:55a05330f8cc 485 } else {
darran 0:55a05330f8cc 486 GETCHAR(msglen, inp);
darran 0:55a05330f8cc 487 if (msglen > 0) {
darran 0:55a05330f8cc 488 len -= sizeof (u_char);
darran 0:55a05330f8cc 489 if (len < msglen) {
darran 0:55a05330f8cc 490 UPAPDEBUG(LOG_INFO, ("pap_rauthack: rcvd short packet.\n"));
darran 0:55a05330f8cc 491 return;
darran 0:55a05330f8cc 492 }
darran 0:55a05330f8cc 493 msg = (char *) inp;
darran 0:55a05330f8cc 494 PRINTMSG(msg, msglen);
darran 0:55a05330f8cc 495 }
darran 0:55a05330f8cc 496 }
darran 0:55a05330f8cc 497 UNTIMEOUT(upap_timeout, u); /* Cancel timeout */
darran 0:55a05330f8cc 498 u->us_clientstate = UPAPCS_OPEN;
darran 0:55a05330f8cc 499
darran 0:55a05330f8cc 500 auth_withpeer_success(u->us_unit, PPP_PAP);
darran 0:55a05330f8cc 501 }
darran 0:55a05330f8cc 502
darran 0:55a05330f8cc 503
darran 0:55a05330f8cc 504 /*
darran 0:55a05330f8cc 505 * upap_rauthnak - Receive Authenticate-Nak.
darran 0:55a05330f8cc 506 */
darran 0:55a05330f8cc 507 static void
darran 0:55a05330f8cc 508 upap_rauthnak(upap_state *u, u_char *inp, int id, int len)
darran 0:55a05330f8cc 509 {
darran 0:55a05330f8cc 510 u_char msglen;
darran 0:55a05330f8cc 511 char *msg;
darran 0:55a05330f8cc 512
darran 0:55a05330f8cc 513 LWIP_UNUSED_ARG(id);
darran 0:55a05330f8cc 514
darran 0:55a05330f8cc 515 UPAPDEBUG(LOG_INFO, ("pap_rauthnak: Rcvd id %d s=%d\n", id, u->us_clientstate));
darran 0:55a05330f8cc 516
darran 0:55a05330f8cc 517 if (u->us_clientstate != UPAPCS_AUTHREQ) { /* XXX */
darran 0:55a05330f8cc 518 return;
darran 0:55a05330f8cc 519 }
darran 0:55a05330f8cc 520
darran 0:55a05330f8cc 521 /*
darran 0:55a05330f8cc 522 * Parse message.
darran 0:55a05330f8cc 523 */
darran 0:55a05330f8cc 524 if (len < sizeof (u_char)) {
darran 0:55a05330f8cc 525 UPAPDEBUG(LOG_INFO, ("pap_rauthnak: ignoring missing msg-length.\n"));
darran 0:55a05330f8cc 526 } else {
darran 0:55a05330f8cc 527 GETCHAR(msglen, inp);
darran 0:55a05330f8cc 528 if(msglen > 0) {
darran 0:55a05330f8cc 529 len -= sizeof (u_char);
darran 0:55a05330f8cc 530 if (len < msglen) {
darran 0:55a05330f8cc 531 UPAPDEBUG(LOG_INFO, ("pap_rauthnak: rcvd short packet.\n"));
darran 0:55a05330f8cc 532 return;
darran 0:55a05330f8cc 533 }
darran 0:55a05330f8cc 534 msg = (char *) inp;
darran 0:55a05330f8cc 535 PRINTMSG(msg, msglen);
darran 0:55a05330f8cc 536 }
darran 0:55a05330f8cc 537 }
darran 0:55a05330f8cc 538
darran 0:55a05330f8cc 539 u->us_clientstate = UPAPCS_BADAUTH;
darran 0:55a05330f8cc 540
darran 0:55a05330f8cc 541 UPAPDEBUG(LOG_ERR, ("PAP authentication failed\n"));
darran 0:55a05330f8cc 542 auth_withpeer_fail(u->us_unit, PPP_PAP);
darran 0:55a05330f8cc 543 }
darran 0:55a05330f8cc 544
darran 0:55a05330f8cc 545
darran 0:55a05330f8cc 546 /*
darran 0:55a05330f8cc 547 * upap_sauthreq - Send an Authenticate-Request.
darran 0:55a05330f8cc 548 */
darran 0:55a05330f8cc 549 static void
darran 0:55a05330f8cc 550 upap_sauthreq(upap_state *u)
darran 0:55a05330f8cc 551 {
darran 0:55a05330f8cc 552 u_char *outp;
darran 0:55a05330f8cc 553 int outlen;
darran 0:55a05330f8cc 554
darran 0:55a05330f8cc 555 outlen = UPAP_HEADERLEN + 2 * sizeof (u_char)
darran 0:55a05330f8cc 556 + u->us_userlen + u->us_passwdlen;
darran 0:55a05330f8cc 557 outp = outpacket_buf[u->us_unit];
darran 0:55a05330f8cc 558
darran 0:55a05330f8cc 559 MAKEHEADER(outp, PPP_PAP);
darran 0:55a05330f8cc 560
darran 0:55a05330f8cc 561 PUTCHAR(UPAP_AUTHREQ, outp);
darran 0:55a05330f8cc 562 PUTCHAR(++u->us_id, outp);
darran 0:55a05330f8cc 563 PUTSHORT(outlen, outp);
darran 0:55a05330f8cc 564 PUTCHAR(u->us_userlen, outp);
darran 0:55a05330f8cc 565 BCOPY(u->us_user, outp, u->us_userlen);
darran 0:55a05330f8cc 566 INCPTR(u->us_userlen, outp);
darran 0:55a05330f8cc 567 PUTCHAR(u->us_passwdlen, outp);
darran 0:55a05330f8cc 568 BCOPY(u->us_passwd, outp, u->us_passwdlen);
darran 0:55a05330f8cc 569
darran 0:55a05330f8cc 570 pppWrite(u->us_unit, outpacket_buf[u->us_unit], outlen + PPP_HDRLEN);
darran 0:55a05330f8cc 571
darran 0:55a05330f8cc 572 UPAPDEBUG(LOG_INFO, ("pap_sauth: Sent id %d\n", u->us_id));
darran 0:55a05330f8cc 573
darran 0:55a05330f8cc 574 TIMEOUT(upap_timeout, u, u->us_timeouttime);
darran 0:55a05330f8cc 575 ++u->us_transmits;
darran 0:55a05330f8cc 576 u->us_clientstate = UPAPCS_AUTHREQ;
darran 0:55a05330f8cc 577 }
darran 0:55a05330f8cc 578
darran 0:55a05330f8cc 579
darran 0:55a05330f8cc 580 /*
darran 0:55a05330f8cc 581 * upap_sresp - Send a response (ack or nak).
darran 0:55a05330f8cc 582 */
darran 0:55a05330f8cc 583 static void
darran 0:55a05330f8cc 584 upap_sresp(upap_state *u, u_char code, u_char id, char *msg, int msglen)
darran 0:55a05330f8cc 585 {
darran 0:55a05330f8cc 586 u_char *outp;
darran 0:55a05330f8cc 587 int outlen;
darran 0:55a05330f8cc 588
darran 0:55a05330f8cc 589 outlen = UPAP_HEADERLEN + sizeof (u_char) + msglen;
darran 0:55a05330f8cc 590 outp = outpacket_buf[u->us_unit];
darran 0:55a05330f8cc 591 MAKEHEADER(outp, PPP_PAP);
darran 0:55a05330f8cc 592
darran 0:55a05330f8cc 593 PUTCHAR(code, outp);
darran 0:55a05330f8cc 594 PUTCHAR(id, outp);
darran 0:55a05330f8cc 595 PUTSHORT(outlen, outp);
darran 0:55a05330f8cc 596 PUTCHAR(msglen, outp);
darran 0:55a05330f8cc 597 BCOPY(msg, outp, msglen);
darran 0:55a05330f8cc 598 pppWrite(u->us_unit, outpacket_buf[u->us_unit], outlen + PPP_HDRLEN);
darran 0:55a05330f8cc 599
darran 0:55a05330f8cc 600 UPAPDEBUG(LOG_INFO, ("pap_sresp: Sent code %d, id %d s=%d\n", code, id, u->us_clientstate));
darran 0:55a05330f8cc 601 }
darran 0:55a05330f8cc 602
darran 0:55a05330f8cc 603 #if PPP_ADDITIONAL_CALLBACKS
darran 0:55a05330f8cc 604 static char *upap_codenames[] = {
darran 0:55a05330f8cc 605 "AuthReq", "AuthAck", "AuthNak"
darran 0:55a05330f8cc 606 };
darran 0:55a05330f8cc 607
darran 0:55a05330f8cc 608 /*
darran 0:55a05330f8cc 609 * upap_printpkt - print the contents of a PAP packet.
darran 0:55a05330f8cc 610 */
darran 0:55a05330f8cc 611 static int upap_printpkt(
darran 0:55a05330f8cc 612 u_char *p,
darran 0:55a05330f8cc 613 int plen,
darran 0:55a05330f8cc 614 void (*printer) (void *, char *, ...),
darran 0:55a05330f8cc 615 void *arg
darran 0:55a05330f8cc 616 )
darran 0:55a05330f8cc 617 {
darran 0:55a05330f8cc 618 LWIP_UNUSED_ARG(p);
darran 0:55a05330f8cc 619 LWIP_UNUSED_ARG(plen);
darran 0:55a05330f8cc 620 LWIP_UNUSED_ARG(printer);
darran 0:55a05330f8cc 621 LWIP_UNUSED_ARG(arg);
darran 0:55a05330f8cc 622 return 0;
darran 0:55a05330f8cc 623 }
darran 0:55a05330f8cc 624 #endif /* PPP_ADDITIONAL_CALLBACKS */
darran 0:55a05330f8cc 625
darran 0:55a05330f8cc 626 #endif /* PAP_SUPPORT */
darran 0:55a05330f8cc 627
darran 0:55a05330f8cc 628 #endif /* PPP_SUPPORT */