From 0f476da0eef51820d175473a13373154aa723e5e Mon Sep 17 00:00:00 2001 From: Mike Brady <4265913+mikebrady@users.noreply.github.com> Date: Mon, 26 Sep 2022 17:24:04 +0100 Subject: [PATCH] Update the pair_ap library. Thanks again to ejurgensen for this code. --- pair_ap/client-example.c | 11 +++++++---- pair_ap/pair-internal.h | 4 ++-- pair_ap/pair-tlv.c | 3 +++ pair_ap/pair.h | 2 +- pair_ap/pair_fruit.c | 20 ++++++++------------ pair_ap/pair_homekit.c | 39 +++++++++++++++++---------------------- 6 files changed, 38 insertions(+), 41 deletions(-) diff --git a/pair_ap/client-example.c b/pair_ap/client-example.c index c5736ed5..31f46c62 100644 --- a/pair_ap/client-example.c +++ b/pair_ap/client-example.c @@ -45,18 +45,21 @@ static char * prompt_pin(void) { char *pin = NULL; - size_t len; + ssize_t len; + size_t sz; printf ("Enter pin: "); fflush (stdout); - len = getline(&pin, &len, stdin); - if (len != 5) // Includes EOL + len = getline(&pin, &sz, stdin); + if (len < 1) { - printf ("Bad pin length %zu\n", len); + printf("Bad pin entered (len=%zd)\n", len); return NULL; } + pin[len - 1] = '\0'; // Zero the EOL + return pin; } diff --git a/pair_ap/pair-internal.h b/pair_ap/pair-internal.h index 3de74daa..29302f1f 100644 --- a/pair_ap/pair-internal.h +++ b/pair_ap/pair-internal.h @@ -15,7 +15,7 @@ struct pair_client_setup_context { struct SRPUser *user; - uint8_t pin[4]; + char *pin; char device_id[PAIR_AP_DEVICE_ID_LEN_MAX]; pair_cb add_cb; @@ -50,7 +50,7 @@ struct pair_server_setup_context { struct SRPVerifier *verifier; - uint8_t pin[4]; + char *pin; char device_id[PAIR_AP_DEVICE_ID_LEN_MAX]; pair_cb add_cb; diff --git a/pair_ap/pair-tlv.c b/pair_ap/pair-tlv.c index ea1a7614..ef457407 100644 --- a/pair_ap/pair-tlv.c +++ b/pair_ap/pair-tlv.c @@ -70,6 +70,9 @@ pair_tlv_new() { void pair_tlv_free(pair_tlv_values_t *values) { + if (!values) + return; + pair_tlv_t *t = values->head; while (t) { pair_tlv_t *t2 = t; diff --git a/pair_ap/pair.h b/pair_ap/pair.h index 35a5aeb8..ec6c1a89 100644 --- a/pair_ap/pair.h +++ b/pair_ap/pair.h @@ -4,7 +4,7 @@ #include #define PAIR_AP_VERSION_MAJOR 0 -#define PAIR_AP_VERSION_MINOR 12 +#define PAIR_AP_VERSION_MINOR 14 #define PAIR_AP_DEVICE_ID_LEN_MAX 64 diff --git a/pair_ap/pair_fruit.c b/pair_ap/pair_fruit.c index 86f23636..5b81a56a 100644 --- a/pair_ap/pair_fruit.c +++ b/pair_ap/pair_fruit.c @@ -347,7 +347,7 @@ srp_user_process_challenge(struct SRPUser *usr, const unsigned char *bytes_s, in bnum u, x; *len_M = 0; - *bytes_M = 0; + *bytes_M = NULL; bnum_bin2bn(s, bytes_s, len_s); bnum_bin2bn(B, bytes_B, len_B); @@ -384,14 +384,7 @@ srp_user_process_challenge(struct SRPUser *usr, const unsigned char *bytes_s, in calculate_H_AMK(usr->alg, usr->H_AMK, usr->A, usr->M, usr->session_key, usr->session_key_len); *bytes_M = usr->M; - if (len_M) - *len_M = hash_length(usr->alg); - } - else - { - *bytes_M = NULL; - if (len_M) - *len_M = 0; + *len_M = hash_length(usr->alg); } cleanup2: @@ -607,10 +600,12 @@ client_setup_new(struct pair_setup_context *handle, const char *pin, pair_cb add if (!is_initialized()) return -1; - if (!pin || strlen(pin) < 4) + if (!pin) return -1; - memcpy(sctx->pin, pin, sizeof(sctx->pin)); + sctx->pin = strdup(pin); + if (!sctx->pin) + return -1; return 0; } @@ -627,6 +622,7 @@ client_setup_free(struct pair_setup_context *handle) free(sctx->salt); free(sctx->epk); free(sctx->authtag); + free(sctx->pin); } static uint8_t * @@ -639,7 +635,7 @@ client_setup_request1(size_t *len, struct pair_setup_context *handle) uint32_t uint32; char *data = NULL; // Necessary to initialize because plist_to_bin() uses value - sctx->user = srp_user_new(HASH_SHA1, SRP_NG_2048, USERNAME, (unsigned char *)sctx->pin, sizeof(sctx->pin), 0, 0); + sctx->user = srp_user_new(HASH_SHA1, SRP_NG_2048, USERNAME, (unsigned char *)sctx->pin, strlen(sctx->pin), 0, 0); dict = plist_new_dict(); diff --git a/pair_ap/pair_homekit.c b/pair_ap/pair_homekit.c index d08baca2..6452fb8c 100644 --- a/pair_ap/pair_homekit.c +++ b/pair_ap/pair_homekit.c @@ -472,7 +472,7 @@ srp_user_process_challenge(struct SRPUser *usr, const unsigned char *bytes_s, in bnum u, x; *len_M = 0; - *bytes_M = 0; + *bytes_M = NULL; bnum_bin2bn(s, bytes_s, len_s); bnum_bin2bn(B, bytes_B, len_B); @@ -512,14 +512,7 @@ srp_user_process_challenge(struct SRPUser *usr, const unsigned char *bytes_s, in calculate_H_AMK(usr->alg, usr->H_AMK, usr->A, usr->M, usr->session_key, usr->session_key_len); *bytes_M = usr->M; - if (len_M) - *len_M = hash_length(usr->alg); - } - else - { - *bytes_M = NULL; - if (len_M) - *len_M = 0; + *len_M = hash_length(usr->alg); } cleanup2: @@ -1180,20 +1173,17 @@ client_setup_new(struct pair_setup_context *handle, const char *pin, pair_cb add if (!is_initialized()) return -1; - if (handle->type == &pair_client_homekit_normal) - { - if (!pin || strlen(pin) < 4) - return -1; - } - else if (handle->type == &pair_client_homekit_transient && !pin) - { - pin = "3939"; - } + if (!pin && handle->type == &pair_client_homekit_transient) + pin = "3939"; + else if (!pin) + return -1; if (device_id && strlen(device_id) >= PAIR_AP_DEVICE_ID_LEN_MAX) return -1; - memcpy(sctx->pin, pin, sizeof(sctx->pin)); + sctx->pin = strdup(pin); + if (!sctx->pin) + return -1; sctx->add_cb = add_cb; sctx->add_cb_arg = cb_arg; @@ -1223,6 +1213,7 @@ client_setup_free(struct pair_setup_context *handle) free(sctx->salt); free(sctx->epk); free(sctx->authtag); + free(sctx->pin); } static uint8_t * @@ -1248,7 +1239,7 @@ client_setup_request1(size_t *len, struct pair_setup_context *handle) goto error; } - sctx->user = srp_user_new(HASH_SHA512, SRP_NG_3072, USERNAME, (unsigned char *)sctx->pin, sizeof(sctx->pin), 0, 0); + sctx->user = srp_user_new(HASH_SHA512, SRP_NG_3072, USERNAME, (unsigned char *)sctx->pin, strlen(sctx->pin), 0, 0); if (!sctx->user) { handle->errmsg = "Setup request 1: Create SRP user failed"; @@ -1949,6 +1940,7 @@ client_verify_response2(struct pair_verify_context *handle, const uint8_t *data, handle->status = PAIR_STATUS_COMPLETED; + pair_tlv_free(response); return 0; } @@ -2010,7 +2002,9 @@ server_setup_new(struct pair_setup_context *handle, const char *pin, pair_cb add if (!device_id || strlen(device_id) >= PAIR_AP_DEVICE_ID_LEN_MAX) return -1; - memcpy(sctx->pin, pin, sizeof(sctx->pin)); + sctx->pin = strdup(pin); + if (!sctx->pin) + return -1; sctx->add_cb = add_cb; sctx->add_cb_arg = cb_arg; @@ -2035,6 +2029,7 @@ server_setup_free(struct pair_setup_context *handle) free(sctx->M1); free(sctx->v); free(sctx->salt); + free(sctx->pin); } static int @@ -2063,7 +2058,7 @@ server_setup_request1(struct pair_setup_context *handle, const uint8_t *data, si sctx->is_transient = (type && type->size == 1 && type->value[0] == PairingFlagsTransient); // Note this is modified to return a 16 byte salt - ret = srp_create_salted_verification_key(HASH_SHA512, SRP_NG_3072, USERNAME, (unsigned char *)sctx->pin, sizeof(sctx->pin), + ret = srp_create_salted_verification_key(HASH_SHA512, SRP_NG_3072, USERNAME, (unsigned char *)sctx->pin, strlen(sctx->pin), &sctx->salt, &sctx->salt_len, &sctx->v, &sctx->v_len, NULL, NULL); if (ret < 0) {