Example self-announcing webserver which controls a servo through a smallHTML userinterface.

Dependencies:   mbed

Committer:
dirkx
Date:
Sat Aug 14 15:56:01 2010 +0000
Revision:
0:a259777c45a3

        

Who changed what in which revision?

UserRevisionLine numberNew contents of line
dirkx 0:a259777c45a3 1 /*****************************************************************************
dirkx 0:a259777c45a3 2 * pap.c - Network Password Authentication Protocol program file.
dirkx 0:a259777c45a3 3 *
dirkx 0:a259777c45a3 4 * Copyright (c) 2003 by Marc Boucher, Services Informatiques (MBSI) inc.
dirkx 0:a259777c45a3 5 * portions Copyright (c) 1997 by Global Election Systems Inc.
dirkx 0:a259777c45a3 6 *
dirkx 0:a259777c45a3 7 * The authors hereby grant permission to use, copy, modify, distribute,
dirkx 0:a259777c45a3 8 * and license this software and its documentation for any purpose, provided
dirkx 0:a259777c45a3 9 * that existing copyright notices are retained in all copies and that this
dirkx 0:a259777c45a3 10 * notice and the following disclaimer are included verbatim in any
dirkx 0:a259777c45a3 11 * distributions. No written agreement, license, or royalty fee is required
dirkx 0:a259777c45a3 12 * for any of the authorized uses.
dirkx 0:a259777c45a3 13 *
dirkx 0:a259777c45a3 14 * THIS SOFTWARE IS PROVIDED BY THE CONTRIBUTORS *AS IS* AND ANY EXPRESS OR
dirkx 0:a259777c45a3 15 * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
dirkx 0:a259777c45a3 16 * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.
dirkx 0:a259777c45a3 17 * IN NO EVENT SHALL THE CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT,
dirkx 0:a259777c45a3 18 * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
dirkx 0:a259777c45a3 19 * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
dirkx 0:a259777c45a3 20 * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
dirkx 0:a259777c45a3 21 * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
dirkx 0:a259777c45a3 22 * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
dirkx 0:a259777c45a3 23 * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
dirkx 0:a259777c45a3 24 *
dirkx 0:a259777c45a3 25 ******************************************************************************
dirkx 0:a259777c45a3 26 * REVISION HISTORY
dirkx 0:a259777c45a3 27 *
dirkx 0:a259777c45a3 28 * 03-01-01 Marc Boucher <marc@mbsi.ca>
dirkx 0:a259777c45a3 29 * Ported to lwIP.
dirkx 0:a259777c45a3 30 * 97-12-12 Guy Lancaster <lancasterg@acm.org>, Global Election Systems Inc.
dirkx 0:a259777c45a3 31 * Original.
dirkx 0:a259777c45a3 32 *****************************************************************************/
dirkx 0:a259777c45a3 33 /*
dirkx 0:a259777c45a3 34 * upap.c - User/Password Authentication Protocol.
dirkx 0:a259777c45a3 35 *
dirkx 0:a259777c45a3 36 * Copyright (c) 1989 Carnegie Mellon University.
dirkx 0:a259777c45a3 37 * All rights reserved.
dirkx 0:a259777c45a3 38 *
dirkx 0:a259777c45a3 39 * Redistribution and use in source and binary forms are permitted
dirkx 0:a259777c45a3 40 * provided that the above copyright notice and this paragraph are
dirkx 0:a259777c45a3 41 * duplicated in all such forms and that any documentation,
dirkx 0:a259777c45a3 42 * advertising materials, and other materials related to such
dirkx 0:a259777c45a3 43 * distribution and use acknowledge that the software was developed
dirkx 0:a259777c45a3 44 * by Carnegie Mellon University. The name of the
dirkx 0:a259777c45a3 45 * University may not be used to endorse or promote products derived
dirkx 0:a259777c45a3 46 * from this software without specific prior written permission.
dirkx 0:a259777c45a3 47 * THIS SOFTWARE IS PROVIDED ``AS IS'' AND WITHOUT ANY EXPRESS OR
dirkx 0:a259777c45a3 48 * IMPLIED WARRANTIES, INCLUDING, WITHOUT LIMITATION, THE IMPLIED
dirkx 0:a259777c45a3 49 * WARRANTIES OF MERCHANTIBILITY AND FITNESS FOR A PARTICULAR PURPOSE.
dirkx 0:a259777c45a3 50 */
dirkx 0:a259777c45a3 51
dirkx 0:a259777c45a3 52 #include "lwip/opt.h"
dirkx 0:a259777c45a3 53
dirkx 0:a259777c45a3 54 #if PPP_SUPPORT /* don't build if not configured for use in lwipopts.h */
dirkx 0:a259777c45a3 55
dirkx 0:a259777c45a3 56 #if PAP_SUPPORT /* don't build if not configured for use in lwipopts.h */
dirkx 0:a259777c45a3 57
dirkx 0:a259777c45a3 58 #include "ppp.h"
dirkx 0:a259777c45a3 59 #include "pppdebug.h"
dirkx 0:a259777c45a3 60
dirkx 0:a259777c45a3 61 #include "auth.h"
dirkx 0:a259777c45a3 62 #include "pap.h"
dirkx 0:a259777c45a3 63
dirkx 0:a259777c45a3 64 #include <string.h>
dirkx 0:a259777c45a3 65
dirkx 0:a259777c45a3 66 #if 0 /* UNUSED */
dirkx 0:a259777c45a3 67 static bool hide_password = 1;
dirkx 0:a259777c45a3 68
dirkx 0:a259777c45a3 69 /*
dirkx 0:a259777c45a3 70 * Command-line options.
dirkx 0:a259777c45a3 71 */
dirkx 0:a259777c45a3 72 static option_t pap_option_list[] = {
dirkx 0:a259777c45a3 73 { "hide-password", o_bool, &hide_password,
dirkx 0:a259777c45a3 74 "Don't output passwords to log", 1 },
dirkx 0:a259777c45a3 75 { "show-password", o_bool, &hide_password,
dirkx 0:a259777c45a3 76 "Show password string in debug log messages", 0 },
dirkx 0:a259777c45a3 77 { "pap-restart", o_int, &upap[0].us_timeouttime,
dirkx 0:a259777c45a3 78 "Set retransmit timeout for PAP" },
dirkx 0:a259777c45a3 79 { "pap-max-authreq", o_int, &upap[0].us_maxtransmits,
dirkx 0:a259777c45a3 80 "Set max number of transmissions for auth-reqs" },
dirkx 0:a259777c45a3 81 { "pap-timeout", o_int, &upap[0].us_reqtimeout,
dirkx 0:a259777c45a3 82 "Set time limit for peer PAP authentication" },
dirkx 0:a259777c45a3 83 { NULL }
dirkx 0:a259777c45a3 84 };
dirkx 0:a259777c45a3 85 #endif
dirkx 0:a259777c45a3 86
dirkx 0:a259777c45a3 87 /*
dirkx 0:a259777c45a3 88 * Protocol entry points.
dirkx 0:a259777c45a3 89 */
dirkx 0:a259777c45a3 90 static void upap_init (int);
dirkx 0:a259777c45a3 91 static void upap_lowerup (int);
dirkx 0:a259777c45a3 92 static void upap_lowerdown (int);
dirkx 0:a259777c45a3 93 static void upap_input (int, u_char *, int);
dirkx 0:a259777c45a3 94 static void upap_protrej (int);
dirkx 0:a259777c45a3 95 #if PPP_ADDITIONAL_CALLBACKS
dirkx 0:a259777c45a3 96 static int upap_printpkt (u_char *, int, void (*)(void *, char *, ...), void *);
dirkx 0:a259777c45a3 97 #endif /* PPP_ADDITIONAL_CALLBACKS */
dirkx 0:a259777c45a3 98
dirkx 0:a259777c45a3 99 struct protent pap_protent = {
dirkx 0:a259777c45a3 100 PPP_PAP,
dirkx 0:a259777c45a3 101 upap_init,
dirkx 0:a259777c45a3 102 upap_input,
dirkx 0:a259777c45a3 103 upap_protrej,
dirkx 0:a259777c45a3 104 upap_lowerup,
dirkx 0:a259777c45a3 105 upap_lowerdown,
dirkx 0:a259777c45a3 106 NULL,
dirkx 0:a259777c45a3 107 NULL,
dirkx 0:a259777c45a3 108 #if PPP_ADDITIONAL_CALLBACKS
dirkx 0:a259777c45a3 109 upap_printpkt,
dirkx 0:a259777c45a3 110 NULL,
dirkx 0:a259777c45a3 111 #endif /* PPP_ADDITIONAL_CALLBACKS */
dirkx 0:a259777c45a3 112 1,
dirkx 0:a259777c45a3 113 "PAP",
dirkx 0:a259777c45a3 114 #if PPP_ADDITIONAL_CALLBACKS
dirkx 0:a259777c45a3 115 NULL,
dirkx 0:a259777c45a3 116 NULL,
dirkx 0:a259777c45a3 117 NULL
dirkx 0:a259777c45a3 118 #endif /* PPP_ADDITIONAL_CALLBACKS */
dirkx 0:a259777c45a3 119 };
dirkx 0:a259777c45a3 120
dirkx 0:a259777c45a3 121 upap_state upap[NUM_PPP]; /* UPAP state; one for each unit */
dirkx 0:a259777c45a3 122
dirkx 0:a259777c45a3 123 static void upap_timeout (void *);
dirkx 0:a259777c45a3 124 static void upap_reqtimeout(void *);
dirkx 0:a259777c45a3 125 static void upap_rauthreq (upap_state *, u_char *, u_char, int);
dirkx 0:a259777c45a3 126 static void upap_rauthack (upap_state *, u_char *, int, int);
dirkx 0:a259777c45a3 127 static void upap_rauthnak (upap_state *, u_char *, int, int);
dirkx 0:a259777c45a3 128 static void upap_sauthreq (upap_state *);
dirkx 0:a259777c45a3 129 static void upap_sresp (upap_state *, u_char, u_char, char *, int);
dirkx 0:a259777c45a3 130
dirkx 0:a259777c45a3 131
dirkx 0:a259777c45a3 132 /*
dirkx 0:a259777c45a3 133 * upap_init - Initialize a UPAP unit.
dirkx 0:a259777c45a3 134 */
dirkx 0:a259777c45a3 135 static void
dirkx 0:a259777c45a3 136 upap_init(int unit)
dirkx 0:a259777c45a3 137 {
dirkx 0:a259777c45a3 138 upap_state *u = &upap[unit];
dirkx 0:a259777c45a3 139
dirkx 0:a259777c45a3 140 UPAPDEBUG(LOG_INFO, ("upap_init: %d\n", unit));
dirkx 0:a259777c45a3 141 u->us_unit = unit;
dirkx 0:a259777c45a3 142 u->us_user = NULL;
dirkx 0:a259777c45a3 143 u->us_userlen = 0;
dirkx 0:a259777c45a3 144 u->us_passwd = NULL;
dirkx 0:a259777c45a3 145 u->us_passwdlen = 0;
dirkx 0:a259777c45a3 146 u->us_clientstate = UPAPCS_INITIAL;
dirkx 0:a259777c45a3 147 u->us_serverstate = UPAPSS_INITIAL;
dirkx 0:a259777c45a3 148 u->us_id = 0;
dirkx 0:a259777c45a3 149 u->us_timeouttime = UPAP_DEFTIMEOUT;
dirkx 0:a259777c45a3 150 u->us_maxtransmits = 10;
dirkx 0:a259777c45a3 151 u->us_reqtimeout = UPAP_DEFREQTIME;
dirkx 0:a259777c45a3 152 }
dirkx 0:a259777c45a3 153
dirkx 0:a259777c45a3 154 /*
dirkx 0:a259777c45a3 155 * upap_authwithpeer - Authenticate us with our peer (start client).
dirkx 0:a259777c45a3 156 *
dirkx 0:a259777c45a3 157 * Set new state and send authenticate's.
dirkx 0:a259777c45a3 158 */
dirkx 0:a259777c45a3 159 void
dirkx 0:a259777c45a3 160 upap_authwithpeer(int unit, char *user, char *password)
dirkx 0:a259777c45a3 161 {
dirkx 0:a259777c45a3 162 upap_state *u = &upap[unit];
dirkx 0:a259777c45a3 163
dirkx 0:a259777c45a3 164 UPAPDEBUG(LOG_INFO, ("upap_authwithpeer: %d user=%s password=%s s=%d\n",
dirkx 0:a259777c45a3 165 unit, user, password, u->us_clientstate));
dirkx 0:a259777c45a3 166
dirkx 0:a259777c45a3 167 /* Save the username and password we're given */
dirkx 0:a259777c45a3 168 u->us_user = user;
dirkx 0:a259777c45a3 169 u->us_userlen = (int)strlen(user);
dirkx 0:a259777c45a3 170 u->us_passwd = password;
dirkx 0:a259777c45a3 171 u->us_passwdlen = (int)strlen(password);
dirkx 0:a259777c45a3 172
dirkx 0:a259777c45a3 173 u->us_transmits = 0;
dirkx 0:a259777c45a3 174
dirkx 0:a259777c45a3 175 /* Lower layer up yet? */
dirkx 0:a259777c45a3 176 if (u->us_clientstate == UPAPCS_INITIAL ||
dirkx 0:a259777c45a3 177 u->us_clientstate == UPAPCS_PENDING) {
dirkx 0:a259777c45a3 178 u->us_clientstate = UPAPCS_PENDING;
dirkx 0:a259777c45a3 179 return;
dirkx 0:a259777c45a3 180 }
dirkx 0:a259777c45a3 181
dirkx 0:a259777c45a3 182 upap_sauthreq(u); /* Start protocol */
dirkx 0:a259777c45a3 183 }
dirkx 0:a259777c45a3 184
dirkx 0:a259777c45a3 185
dirkx 0:a259777c45a3 186 /*
dirkx 0:a259777c45a3 187 * upap_authpeer - Authenticate our peer (start server).
dirkx 0:a259777c45a3 188 *
dirkx 0:a259777c45a3 189 * Set new state.
dirkx 0:a259777c45a3 190 */
dirkx 0:a259777c45a3 191 void
dirkx 0:a259777c45a3 192 upap_authpeer(int unit)
dirkx 0:a259777c45a3 193 {
dirkx 0:a259777c45a3 194 upap_state *u = &upap[unit];
dirkx 0:a259777c45a3 195
dirkx 0:a259777c45a3 196 /* Lower layer up yet? */
dirkx 0:a259777c45a3 197 if (u->us_serverstate == UPAPSS_INITIAL ||
dirkx 0:a259777c45a3 198 u->us_serverstate == UPAPSS_PENDING) {
dirkx 0:a259777c45a3 199 u->us_serverstate = UPAPSS_PENDING;
dirkx 0:a259777c45a3 200 return;
dirkx 0:a259777c45a3 201 }
dirkx 0:a259777c45a3 202
dirkx 0:a259777c45a3 203 u->us_serverstate = UPAPSS_LISTEN;
dirkx 0:a259777c45a3 204 if (u->us_reqtimeout > 0) {
dirkx 0:a259777c45a3 205 TIMEOUT(upap_reqtimeout, u, u->us_reqtimeout);
dirkx 0:a259777c45a3 206 }
dirkx 0:a259777c45a3 207 }
dirkx 0:a259777c45a3 208
dirkx 0:a259777c45a3 209 /*
dirkx 0:a259777c45a3 210 * upap_timeout - Retransmission timer for sending auth-reqs expired.
dirkx 0:a259777c45a3 211 */
dirkx 0:a259777c45a3 212 static void
dirkx 0:a259777c45a3 213 upap_timeout(void *arg)
dirkx 0:a259777c45a3 214 {
dirkx 0:a259777c45a3 215 upap_state *u = (upap_state *) arg;
dirkx 0:a259777c45a3 216
dirkx 0:a259777c45a3 217 UPAPDEBUG(LOG_INFO, ("upap_timeout: %d timeout %d expired s=%d\n",
dirkx 0:a259777c45a3 218 u->us_unit, u->us_timeouttime, u->us_clientstate));
dirkx 0:a259777c45a3 219
dirkx 0:a259777c45a3 220 if (u->us_clientstate != UPAPCS_AUTHREQ) {
dirkx 0:a259777c45a3 221 UPAPDEBUG(LOG_INFO, ("upap_timeout: not in AUTHREQ state!\n"));
dirkx 0:a259777c45a3 222 return;
dirkx 0:a259777c45a3 223 }
dirkx 0:a259777c45a3 224
dirkx 0:a259777c45a3 225 if (u->us_transmits >= u->us_maxtransmits) {
dirkx 0:a259777c45a3 226 /* give up in disgust */
dirkx 0:a259777c45a3 227 UPAPDEBUG(LOG_ERR, ("No response to PAP authenticate-requests\n"));
dirkx 0:a259777c45a3 228 u->us_clientstate = UPAPCS_BADAUTH;
dirkx 0:a259777c45a3 229 auth_withpeer_fail(u->us_unit, PPP_PAP);
dirkx 0:a259777c45a3 230 return;
dirkx 0:a259777c45a3 231 }
dirkx 0:a259777c45a3 232
dirkx 0:a259777c45a3 233 upap_sauthreq(u); /* Send Authenticate-Request and set upap timeout*/
dirkx 0:a259777c45a3 234 }
dirkx 0:a259777c45a3 235
dirkx 0:a259777c45a3 236
dirkx 0:a259777c45a3 237 /*
dirkx 0:a259777c45a3 238 * upap_reqtimeout - Give up waiting for the peer to send an auth-req.
dirkx 0:a259777c45a3 239 */
dirkx 0:a259777c45a3 240 static void
dirkx 0:a259777c45a3 241 upap_reqtimeout(void *arg)
dirkx 0:a259777c45a3 242 {
dirkx 0:a259777c45a3 243 upap_state *u = (upap_state *) arg;
dirkx 0:a259777c45a3 244
dirkx 0:a259777c45a3 245 if (u->us_serverstate != UPAPSS_LISTEN) {
dirkx 0:a259777c45a3 246 return; /* huh?? */
dirkx 0:a259777c45a3 247 }
dirkx 0:a259777c45a3 248
dirkx 0:a259777c45a3 249 auth_peer_fail(u->us_unit, PPP_PAP);
dirkx 0:a259777c45a3 250 u->us_serverstate = UPAPSS_BADAUTH;
dirkx 0:a259777c45a3 251 }
dirkx 0:a259777c45a3 252
dirkx 0:a259777c45a3 253
dirkx 0:a259777c45a3 254 /*
dirkx 0:a259777c45a3 255 * upap_lowerup - The lower layer is up.
dirkx 0:a259777c45a3 256 *
dirkx 0:a259777c45a3 257 * Start authenticating if pending.
dirkx 0:a259777c45a3 258 */
dirkx 0:a259777c45a3 259 static void
dirkx 0:a259777c45a3 260 upap_lowerup(int unit)
dirkx 0:a259777c45a3 261 {
dirkx 0:a259777c45a3 262 upap_state *u = &upap[unit];
dirkx 0:a259777c45a3 263
dirkx 0:a259777c45a3 264 UPAPDEBUG(LOG_INFO, ("upap_lowerup: init %d clientstate s=%d\n", unit, u->us_clientstate));
dirkx 0:a259777c45a3 265
dirkx 0:a259777c45a3 266 if (u->us_clientstate == UPAPCS_INITIAL) {
dirkx 0:a259777c45a3 267 u->us_clientstate = UPAPCS_CLOSED;
dirkx 0:a259777c45a3 268 } else if (u->us_clientstate == UPAPCS_PENDING) {
dirkx 0:a259777c45a3 269 upap_sauthreq(u); /* send an auth-request */
dirkx 0:a259777c45a3 270 /* now client state is UPAPCS__AUTHREQ */
dirkx 0:a259777c45a3 271 }
dirkx 0:a259777c45a3 272
dirkx 0:a259777c45a3 273 if (u->us_serverstate == UPAPSS_INITIAL) {
dirkx 0:a259777c45a3 274 u->us_serverstate = UPAPSS_CLOSED;
dirkx 0:a259777c45a3 275 } else if (u->us_serverstate == UPAPSS_PENDING) {
dirkx 0:a259777c45a3 276 u->us_serverstate = UPAPSS_LISTEN;
dirkx 0:a259777c45a3 277 if (u->us_reqtimeout > 0) {
dirkx 0:a259777c45a3 278 TIMEOUT(upap_reqtimeout, u, u->us_reqtimeout);
dirkx 0:a259777c45a3 279 }
dirkx 0:a259777c45a3 280 }
dirkx 0:a259777c45a3 281 }
dirkx 0:a259777c45a3 282
dirkx 0:a259777c45a3 283
dirkx 0:a259777c45a3 284 /*
dirkx 0:a259777c45a3 285 * upap_lowerdown - The lower layer is down.
dirkx 0:a259777c45a3 286 *
dirkx 0:a259777c45a3 287 * Cancel all timeouts.
dirkx 0:a259777c45a3 288 */
dirkx 0:a259777c45a3 289 static void
dirkx 0:a259777c45a3 290 upap_lowerdown(int unit)
dirkx 0:a259777c45a3 291 {
dirkx 0:a259777c45a3 292 upap_state *u = &upap[unit];
dirkx 0:a259777c45a3 293
dirkx 0:a259777c45a3 294 UPAPDEBUG(LOG_INFO, ("upap_lowerdown: %d s=%d\n", unit, u->us_clientstate));
dirkx 0:a259777c45a3 295
dirkx 0:a259777c45a3 296 if (u->us_clientstate == UPAPCS_AUTHREQ) { /* Timeout pending? */
dirkx 0:a259777c45a3 297 UNTIMEOUT(upap_timeout, u); /* Cancel timeout */
dirkx 0:a259777c45a3 298 }
dirkx 0:a259777c45a3 299 if (u->us_serverstate == UPAPSS_LISTEN && u->us_reqtimeout > 0) {
dirkx 0:a259777c45a3 300 UNTIMEOUT(upap_reqtimeout, u);
dirkx 0:a259777c45a3 301 }
dirkx 0:a259777c45a3 302
dirkx 0:a259777c45a3 303 u->us_clientstate = UPAPCS_INITIAL;
dirkx 0:a259777c45a3 304 u->us_serverstate = UPAPSS_INITIAL;
dirkx 0:a259777c45a3 305 }
dirkx 0:a259777c45a3 306
dirkx 0:a259777c45a3 307
dirkx 0:a259777c45a3 308 /*
dirkx 0:a259777c45a3 309 * upap_protrej - Peer doesn't speak this protocol.
dirkx 0:a259777c45a3 310 *
dirkx 0:a259777c45a3 311 * This shouldn't happen. In any case, pretend lower layer went down.
dirkx 0:a259777c45a3 312 */
dirkx 0:a259777c45a3 313 static void
dirkx 0:a259777c45a3 314 upap_protrej(int unit)
dirkx 0:a259777c45a3 315 {
dirkx 0:a259777c45a3 316 upap_state *u = &upap[unit];
dirkx 0:a259777c45a3 317
dirkx 0:a259777c45a3 318 if (u->us_clientstate == UPAPCS_AUTHREQ) {
dirkx 0:a259777c45a3 319 UPAPDEBUG(LOG_ERR, ("PAP authentication failed due to protocol-reject\n"));
dirkx 0:a259777c45a3 320 auth_withpeer_fail(unit, PPP_PAP);
dirkx 0:a259777c45a3 321 }
dirkx 0:a259777c45a3 322 if (u->us_serverstate == UPAPSS_LISTEN) {
dirkx 0:a259777c45a3 323 UPAPDEBUG(LOG_ERR, ("PAP authentication of peer failed (protocol-reject)\n"));
dirkx 0:a259777c45a3 324 auth_peer_fail(unit, PPP_PAP);
dirkx 0:a259777c45a3 325 }
dirkx 0:a259777c45a3 326 upap_lowerdown(unit);
dirkx 0:a259777c45a3 327 }
dirkx 0:a259777c45a3 328
dirkx 0:a259777c45a3 329
dirkx 0:a259777c45a3 330 /*
dirkx 0:a259777c45a3 331 * upap_input - Input UPAP packet.
dirkx 0:a259777c45a3 332 */
dirkx 0:a259777c45a3 333 static void
dirkx 0:a259777c45a3 334 upap_input(int unit, u_char *inpacket, int l)
dirkx 0:a259777c45a3 335 {
dirkx 0:a259777c45a3 336 upap_state *u = &upap[unit];
dirkx 0:a259777c45a3 337 u_char *inp;
dirkx 0:a259777c45a3 338 u_char code, id;
dirkx 0:a259777c45a3 339 int len;
dirkx 0:a259777c45a3 340
dirkx 0:a259777c45a3 341 /*
dirkx 0:a259777c45a3 342 * Parse header (code, id and length).
dirkx 0:a259777c45a3 343 * If packet too short, drop it.
dirkx 0:a259777c45a3 344 */
dirkx 0:a259777c45a3 345 inp = inpacket;
dirkx 0:a259777c45a3 346 if (l < (int)UPAP_HEADERLEN) {
dirkx 0:a259777c45a3 347 UPAPDEBUG(LOG_INFO, ("pap_input: rcvd short header.\n"));
dirkx 0:a259777c45a3 348 return;
dirkx 0:a259777c45a3 349 }
dirkx 0:a259777c45a3 350 GETCHAR(code, inp);
dirkx 0:a259777c45a3 351 GETCHAR(id, inp);
dirkx 0:a259777c45a3 352 GETSHORT(len, inp);
dirkx 0:a259777c45a3 353 if (len < (int)UPAP_HEADERLEN) {
dirkx 0:a259777c45a3 354 UPAPDEBUG(LOG_INFO, ("pap_input: rcvd illegal length.\n"));
dirkx 0:a259777c45a3 355 return;
dirkx 0:a259777c45a3 356 }
dirkx 0:a259777c45a3 357 if (len > l) {
dirkx 0:a259777c45a3 358 UPAPDEBUG(LOG_INFO, ("pap_input: rcvd short packet.\n"));
dirkx 0:a259777c45a3 359 return;
dirkx 0:a259777c45a3 360 }
dirkx 0:a259777c45a3 361 len -= UPAP_HEADERLEN;
dirkx 0:a259777c45a3 362
dirkx 0:a259777c45a3 363 /*
dirkx 0:a259777c45a3 364 * Action depends on code.
dirkx 0:a259777c45a3 365 */
dirkx 0:a259777c45a3 366 switch (code) {
dirkx 0:a259777c45a3 367 case UPAP_AUTHREQ:
dirkx 0:a259777c45a3 368 upap_rauthreq(u, inp, id, len);
dirkx 0:a259777c45a3 369 break;
dirkx 0:a259777c45a3 370
dirkx 0:a259777c45a3 371 case UPAP_AUTHACK:
dirkx 0:a259777c45a3 372 upap_rauthack(u, inp, id, len);
dirkx 0:a259777c45a3 373 break;
dirkx 0:a259777c45a3 374
dirkx 0:a259777c45a3 375 case UPAP_AUTHNAK:
dirkx 0:a259777c45a3 376 upap_rauthnak(u, inp, id, len);
dirkx 0:a259777c45a3 377 break;
dirkx 0:a259777c45a3 378
dirkx 0:a259777c45a3 379 default: /* XXX Need code reject */
dirkx 0:a259777c45a3 380 UPAPDEBUG(LOG_INFO, ("pap_input: UNHANDLED default: code: %d, id: %d, len: %d.\n", code, id, len));
dirkx 0:a259777c45a3 381 break;
dirkx 0:a259777c45a3 382 }
dirkx 0:a259777c45a3 383 }
dirkx 0:a259777c45a3 384
dirkx 0:a259777c45a3 385
dirkx 0:a259777c45a3 386 /*
dirkx 0:a259777c45a3 387 * upap_rauth - Receive Authenticate.
dirkx 0:a259777c45a3 388 */
dirkx 0:a259777c45a3 389 static void
dirkx 0:a259777c45a3 390 upap_rauthreq(upap_state *u, u_char *inp, u_char id, int len)
dirkx 0:a259777c45a3 391 {
dirkx 0:a259777c45a3 392 u_char ruserlen, rpasswdlen;
dirkx 0:a259777c45a3 393 char *ruser, *rpasswd;
dirkx 0:a259777c45a3 394 u_char retcode;
dirkx 0:a259777c45a3 395 char *msg;
dirkx 0:a259777c45a3 396 int msglen;
dirkx 0:a259777c45a3 397
dirkx 0:a259777c45a3 398 UPAPDEBUG(LOG_INFO, ("pap_rauth: Rcvd id %d.\n", id));
dirkx 0:a259777c45a3 399
dirkx 0:a259777c45a3 400 if (u->us_serverstate < UPAPSS_LISTEN) {
dirkx 0:a259777c45a3 401 return;
dirkx 0:a259777c45a3 402 }
dirkx 0:a259777c45a3 403
dirkx 0:a259777c45a3 404 /*
dirkx 0:a259777c45a3 405 * If we receive a duplicate authenticate-request, we are
dirkx 0:a259777c45a3 406 * supposed to return the same status as for the first request.
dirkx 0:a259777c45a3 407 */
dirkx 0:a259777c45a3 408 if (u->us_serverstate == UPAPSS_OPEN) {
dirkx 0:a259777c45a3 409 upap_sresp(u, UPAP_AUTHACK, id, "", 0); /* return auth-ack */
dirkx 0:a259777c45a3 410 return;
dirkx 0:a259777c45a3 411 }
dirkx 0:a259777c45a3 412 if (u->us_serverstate == UPAPSS_BADAUTH) {
dirkx 0:a259777c45a3 413 upap_sresp(u, UPAP_AUTHNAK, id, "", 0); /* return auth-nak */
dirkx 0:a259777c45a3 414 return;
dirkx 0:a259777c45a3 415 }
dirkx 0:a259777c45a3 416
dirkx 0:a259777c45a3 417 /*
dirkx 0:a259777c45a3 418 * Parse user/passwd.
dirkx 0:a259777c45a3 419 */
dirkx 0:a259777c45a3 420 if (len < (int)sizeof (u_char)) {
dirkx 0:a259777c45a3 421 UPAPDEBUG(LOG_INFO, ("pap_rauth: rcvd short packet.\n"));
dirkx 0:a259777c45a3 422 return;
dirkx 0:a259777c45a3 423 }
dirkx 0:a259777c45a3 424 GETCHAR(ruserlen, inp);
dirkx 0:a259777c45a3 425 len -= sizeof (u_char) + ruserlen + sizeof (u_char);
dirkx 0:a259777c45a3 426 if (len < 0) {
dirkx 0:a259777c45a3 427 UPAPDEBUG(LOG_INFO, ("pap_rauth: rcvd short packet.\n"));
dirkx 0:a259777c45a3 428 return;
dirkx 0:a259777c45a3 429 }
dirkx 0:a259777c45a3 430 ruser = (char *) inp;
dirkx 0:a259777c45a3 431 INCPTR(ruserlen, inp);
dirkx 0:a259777c45a3 432 GETCHAR(rpasswdlen, inp);
dirkx 0:a259777c45a3 433 if (len < rpasswdlen) {
dirkx 0:a259777c45a3 434 UPAPDEBUG(LOG_INFO, ("pap_rauth: rcvd short packet.\n"));
dirkx 0:a259777c45a3 435 return;
dirkx 0:a259777c45a3 436 }
dirkx 0:a259777c45a3 437 rpasswd = (char *) inp;
dirkx 0:a259777c45a3 438
dirkx 0:a259777c45a3 439 /*
dirkx 0:a259777c45a3 440 * Check the username and password given.
dirkx 0:a259777c45a3 441 */
dirkx 0:a259777c45a3 442 retcode = check_passwd(u->us_unit, ruser, ruserlen, rpasswd, rpasswdlen, &msg, &msglen);
dirkx 0:a259777c45a3 443 /* lwip: currently retcode is always UPAP_AUTHACK */
dirkx 0:a259777c45a3 444 BZERO(rpasswd, rpasswdlen);
dirkx 0:a259777c45a3 445
dirkx 0:a259777c45a3 446 upap_sresp(u, retcode, id, msg, msglen);
dirkx 0:a259777c45a3 447
dirkx 0:a259777c45a3 448 if (retcode == UPAP_AUTHACK) {
dirkx 0:a259777c45a3 449 u->us_serverstate = UPAPSS_OPEN;
dirkx 0:a259777c45a3 450 auth_peer_success(u->us_unit, PPP_PAP, ruser, ruserlen);
dirkx 0:a259777c45a3 451 } else {
dirkx 0:a259777c45a3 452 u->us_serverstate = UPAPSS_BADAUTH;
dirkx 0:a259777c45a3 453 auth_peer_fail(u->us_unit, PPP_PAP);
dirkx 0:a259777c45a3 454 }
dirkx 0:a259777c45a3 455
dirkx 0:a259777c45a3 456 if (u->us_reqtimeout > 0) {
dirkx 0:a259777c45a3 457 UNTIMEOUT(upap_reqtimeout, u);
dirkx 0:a259777c45a3 458 }
dirkx 0:a259777c45a3 459 }
dirkx 0:a259777c45a3 460
dirkx 0:a259777c45a3 461
dirkx 0:a259777c45a3 462 /*
dirkx 0:a259777c45a3 463 * upap_rauthack - Receive Authenticate-Ack.
dirkx 0:a259777c45a3 464 */
dirkx 0:a259777c45a3 465 static void
dirkx 0:a259777c45a3 466 upap_rauthack(upap_state *u, u_char *inp, int id, int len)
dirkx 0:a259777c45a3 467 {
dirkx 0:a259777c45a3 468 u_char msglen;
dirkx 0:a259777c45a3 469 char *msg;
dirkx 0:a259777c45a3 470
dirkx 0:a259777c45a3 471 LWIP_UNUSED_ARG(id);
dirkx 0:a259777c45a3 472
dirkx 0:a259777c45a3 473 UPAPDEBUG(LOG_INFO, ("pap_rauthack: Rcvd id %d s=%d\n", id, u->us_clientstate));
dirkx 0:a259777c45a3 474
dirkx 0:a259777c45a3 475 if (u->us_clientstate != UPAPCS_AUTHREQ) { /* XXX */
dirkx 0:a259777c45a3 476 UPAPDEBUG(LOG_INFO, ("pap_rauthack: us_clientstate != UPAPCS_AUTHREQ\n"));
dirkx 0:a259777c45a3 477 return;
dirkx 0:a259777c45a3 478 }
dirkx 0:a259777c45a3 479
dirkx 0:a259777c45a3 480 /*
dirkx 0:a259777c45a3 481 * Parse message.
dirkx 0:a259777c45a3 482 */
dirkx 0:a259777c45a3 483 if (len < (int)sizeof (u_char)) {
dirkx 0:a259777c45a3 484 UPAPDEBUG(LOG_INFO, ("pap_rauthack: ignoring missing msg-length.\n"));
dirkx 0:a259777c45a3 485 } else {
dirkx 0:a259777c45a3 486 GETCHAR(msglen, inp);
dirkx 0:a259777c45a3 487 if (msglen > 0) {
dirkx 0:a259777c45a3 488 len -= sizeof (u_char);
dirkx 0:a259777c45a3 489 if (len < msglen) {
dirkx 0:a259777c45a3 490 UPAPDEBUG(LOG_INFO, ("pap_rauthack: rcvd short packet.\n"));
dirkx 0:a259777c45a3 491 return;
dirkx 0:a259777c45a3 492 }
dirkx 0:a259777c45a3 493 msg = (char *) inp;
dirkx 0:a259777c45a3 494 PRINTMSG(msg, msglen);
dirkx 0:a259777c45a3 495 }
dirkx 0:a259777c45a3 496 }
dirkx 0:a259777c45a3 497 UNTIMEOUT(upap_timeout, u); /* Cancel timeout */
dirkx 0:a259777c45a3 498 u->us_clientstate = UPAPCS_OPEN;
dirkx 0:a259777c45a3 499
dirkx 0:a259777c45a3 500 auth_withpeer_success(u->us_unit, PPP_PAP);
dirkx 0:a259777c45a3 501 }
dirkx 0:a259777c45a3 502
dirkx 0:a259777c45a3 503
dirkx 0:a259777c45a3 504 /*
dirkx 0:a259777c45a3 505 * upap_rauthnak - Receive Authenticate-Nak.
dirkx 0:a259777c45a3 506 */
dirkx 0:a259777c45a3 507 static void
dirkx 0:a259777c45a3 508 upap_rauthnak(upap_state *u, u_char *inp, int id, int len)
dirkx 0:a259777c45a3 509 {
dirkx 0:a259777c45a3 510 u_char msglen;
dirkx 0:a259777c45a3 511 char *msg;
dirkx 0:a259777c45a3 512
dirkx 0:a259777c45a3 513 LWIP_UNUSED_ARG(id);
dirkx 0:a259777c45a3 514
dirkx 0:a259777c45a3 515 UPAPDEBUG(LOG_INFO, ("pap_rauthnak: Rcvd id %d s=%d\n", id, u->us_clientstate));
dirkx 0:a259777c45a3 516
dirkx 0:a259777c45a3 517 if (u->us_clientstate != UPAPCS_AUTHREQ) { /* XXX */
dirkx 0:a259777c45a3 518 return;
dirkx 0:a259777c45a3 519 }
dirkx 0:a259777c45a3 520
dirkx 0:a259777c45a3 521 /*
dirkx 0:a259777c45a3 522 * Parse message.
dirkx 0:a259777c45a3 523 */
dirkx 0:a259777c45a3 524 if (len < sizeof (u_char)) {
dirkx 0:a259777c45a3 525 UPAPDEBUG(LOG_INFO, ("pap_rauthnak: ignoring missing msg-length.\n"));
dirkx 0:a259777c45a3 526 } else {
dirkx 0:a259777c45a3 527 GETCHAR(msglen, inp);
dirkx 0:a259777c45a3 528 if(msglen > 0) {
dirkx 0:a259777c45a3 529 len -= sizeof (u_char);
dirkx 0:a259777c45a3 530 if (len < msglen) {
dirkx 0:a259777c45a3 531 UPAPDEBUG(LOG_INFO, ("pap_rauthnak: rcvd short packet.\n"));
dirkx 0:a259777c45a3 532 return;
dirkx 0:a259777c45a3 533 }
dirkx 0:a259777c45a3 534 msg = (char *) inp;
dirkx 0:a259777c45a3 535 PRINTMSG(msg, msglen);
dirkx 0:a259777c45a3 536 }
dirkx 0:a259777c45a3 537 }
dirkx 0:a259777c45a3 538
dirkx 0:a259777c45a3 539 u->us_clientstate = UPAPCS_BADAUTH;
dirkx 0:a259777c45a3 540
dirkx 0:a259777c45a3 541 UPAPDEBUG(LOG_ERR, ("PAP authentication failed\n"));
dirkx 0:a259777c45a3 542 auth_withpeer_fail(u->us_unit, PPP_PAP);
dirkx 0:a259777c45a3 543 }
dirkx 0:a259777c45a3 544
dirkx 0:a259777c45a3 545
dirkx 0:a259777c45a3 546 /*
dirkx 0:a259777c45a3 547 * upap_sauthreq - Send an Authenticate-Request.
dirkx 0:a259777c45a3 548 */
dirkx 0:a259777c45a3 549 static void
dirkx 0:a259777c45a3 550 upap_sauthreq(upap_state *u)
dirkx 0:a259777c45a3 551 {
dirkx 0:a259777c45a3 552 u_char *outp;
dirkx 0:a259777c45a3 553 int outlen;
dirkx 0:a259777c45a3 554
dirkx 0:a259777c45a3 555 outlen = UPAP_HEADERLEN + 2 * sizeof (u_char)
dirkx 0:a259777c45a3 556 + u->us_userlen + u->us_passwdlen;
dirkx 0:a259777c45a3 557 outp = outpacket_buf[u->us_unit];
dirkx 0:a259777c45a3 558
dirkx 0:a259777c45a3 559 MAKEHEADER(outp, PPP_PAP);
dirkx 0:a259777c45a3 560
dirkx 0:a259777c45a3 561 PUTCHAR(UPAP_AUTHREQ, outp);
dirkx 0:a259777c45a3 562 PUTCHAR(++u->us_id, outp);
dirkx 0:a259777c45a3 563 PUTSHORT(outlen, outp);
dirkx 0:a259777c45a3 564 PUTCHAR(u->us_userlen, outp);
dirkx 0:a259777c45a3 565 BCOPY(u->us_user, outp, u->us_userlen);
dirkx 0:a259777c45a3 566 INCPTR(u->us_userlen, outp);
dirkx 0:a259777c45a3 567 PUTCHAR(u->us_passwdlen, outp);
dirkx 0:a259777c45a3 568 BCOPY(u->us_passwd, outp, u->us_passwdlen);
dirkx 0:a259777c45a3 569
dirkx 0:a259777c45a3 570 pppWrite(u->us_unit, outpacket_buf[u->us_unit], outlen + PPP_HDRLEN);
dirkx 0:a259777c45a3 571
dirkx 0:a259777c45a3 572 UPAPDEBUG(LOG_INFO, ("pap_sauth: Sent id %d\n", u->us_id));
dirkx 0:a259777c45a3 573
dirkx 0:a259777c45a3 574 TIMEOUT(upap_timeout, u, u->us_timeouttime);
dirkx 0:a259777c45a3 575 ++u->us_transmits;
dirkx 0:a259777c45a3 576 u->us_clientstate = UPAPCS_AUTHREQ;
dirkx 0:a259777c45a3 577 }
dirkx 0:a259777c45a3 578
dirkx 0:a259777c45a3 579
dirkx 0:a259777c45a3 580 /*
dirkx 0:a259777c45a3 581 * upap_sresp - Send a response (ack or nak).
dirkx 0:a259777c45a3 582 */
dirkx 0:a259777c45a3 583 static void
dirkx 0:a259777c45a3 584 upap_sresp(upap_state *u, u_char code, u_char id, char *msg, int msglen)
dirkx 0:a259777c45a3 585 {
dirkx 0:a259777c45a3 586 u_char *outp;
dirkx 0:a259777c45a3 587 int outlen;
dirkx 0:a259777c45a3 588
dirkx 0:a259777c45a3 589 outlen = UPAP_HEADERLEN + sizeof (u_char) + msglen;
dirkx 0:a259777c45a3 590 outp = outpacket_buf[u->us_unit];
dirkx 0:a259777c45a3 591 MAKEHEADER(outp, PPP_PAP);
dirkx 0:a259777c45a3 592
dirkx 0:a259777c45a3 593 PUTCHAR(code, outp);
dirkx 0:a259777c45a3 594 PUTCHAR(id, outp);
dirkx 0:a259777c45a3 595 PUTSHORT(outlen, outp);
dirkx 0:a259777c45a3 596 PUTCHAR(msglen, outp);
dirkx 0:a259777c45a3 597 BCOPY(msg, outp, msglen);
dirkx 0:a259777c45a3 598 pppWrite(u->us_unit, outpacket_buf[u->us_unit], outlen + PPP_HDRLEN);
dirkx 0:a259777c45a3 599
dirkx 0:a259777c45a3 600 UPAPDEBUG(LOG_INFO, ("pap_sresp: Sent code %d, id %d s=%d\n", code, id, u->us_clientstate));
dirkx 0:a259777c45a3 601 }
dirkx 0:a259777c45a3 602
dirkx 0:a259777c45a3 603 #if PPP_ADDITIONAL_CALLBACKS
dirkx 0:a259777c45a3 604 static char *upap_codenames[] = {
dirkx 0:a259777c45a3 605 "AuthReq", "AuthAck", "AuthNak"
dirkx 0:a259777c45a3 606 };
dirkx 0:a259777c45a3 607
dirkx 0:a259777c45a3 608 /*
dirkx 0:a259777c45a3 609 * upap_printpkt - print the contents of a PAP packet.
dirkx 0:a259777c45a3 610 */
dirkx 0:a259777c45a3 611 static int upap_printpkt(
dirkx 0:a259777c45a3 612 u_char *p,
dirkx 0:a259777c45a3 613 int plen,
dirkx 0:a259777c45a3 614 void (*printer) (void *, char *, ...),
dirkx 0:a259777c45a3 615 void *arg
dirkx 0:a259777c45a3 616 )
dirkx 0:a259777c45a3 617 {
dirkx 0:a259777c45a3 618 LWIP_UNUSED_ARG(p);
dirkx 0:a259777c45a3 619 LWIP_UNUSED_ARG(plen);
dirkx 0:a259777c45a3 620 LWIP_UNUSED_ARG(printer);
dirkx 0:a259777c45a3 621 LWIP_UNUSED_ARG(arg);
dirkx 0:a259777c45a3 622 return 0;
dirkx 0:a259777c45a3 623 }
dirkx 0:a259777c45a3 624 #endif /* PPP_ADDITIONAL_CALLBACKS */
dirkx 0:a259777c45a3 625
dirkx 0:a259777c45a3 626 #endif /* PAP_SUPPORT */
dirkx 0:a259777c45a3 627
dirkx 0:a259777c45a3 628 #endif /* PPP_SUPPORT */