Update the pair_ap library. Thanks again to ejurgensen for this code.

This commit is contained in:
Mike Brady
2022-09-26 17:24:04 +01:00
parent 0c8b2200f7
commit 0f476da0ee
6 changed files with 38 additions and 41 deletions
+7 -4
View File
@@ -45,18 +45,21 @@ static char *
prompt_pin(void) prompt_pin(void)
{ {
char *pin = NULL; char *pin = NULL;
size_t len; ssize_t len;
size_t sz;
printf ("Enter pin: "); printf ("Enter pin: ");
fflush (stdout); fflush (stdout);
len = getline(&pin, &len, stdin); len = getline(&pin, &sz, stdin);
if (len != 5) // Includes EOL if (len < 1)
{ {
printf ("Bad pin length %zu\n", len); printf("Bad pin entered (len=%zd)\n", len);
return NULL; return NULL;
} }
pin[len - 1] = '\0'; // Zero the EOL
return pin; return pin;
} }
+2 -2
View File
@@ -15,7 +15,7 @@ struct pair_client_setup_context
{ {
struct SRPUser *user; struct SRPUser *user;
uint8_t pin[4]; char *pin;
char device_id[PAIR_AP_DEVICE_ID_LEN_MAX]; char device_id[PAIR_AP_DEVICE_ID_LEN_MAX];
pair_cb add_cb; pair_cb add_cb;
@@ -50,7 +50,7 @@ struct pair_server_setup_context
{ {
struct SRPVerifier *verifier; struct SRPVerifier *verifier;
uint8_t pin[4]; char *pin;
char device_id[PAIR_AP_DEVICE_ID_LEN_MAX]; char device_id[PAIR_AP_DEVICE_ID_LEN_MAX];
pair_cb add_cb; pair_cb add_cb;
+3
View File
@@ -70,6 +70,9 @@ pair_tlv_new() {
void void
pair_tlv_free(pair_tlv_values_t *values) { pair_tlv_free(pair_tlv_values_t *values) {
if (!values)
return;
pair_tlv_t *t = values->head; pair_tlv_t *t = values->head;
while (t) { while (t) {
pair_tlv_t *t2 = t; pair_tlv_t *t2 = t;
+1 -1
View File
@@ -4,7 +4,7 @@
#include <stdint.h> #include <stdint.h>
#define PAIR_AP_VERSION_MAJOR 0 #define PAIR_AP_VERSION_MAJOR 0
#define PAIR_AP_VERSION_MINOR 12 #define PAIR_AP_VERSION_MINOR 14
#define PAIR_AP_DEVICE_ID_LEN_MAX 64 #define PAIR_AP_DEVICE_ID_LEN_MAX 64
+8 -12
View File
@@ -347,7 +347,7 @@ srp_user_process_challenge(struct SRPUser *usr, const unsigned char *bytes_s, in
bnum u, x; bnum u, x;
*len_M = 0; *len_M = 0;
*bytes_M = 0; *bytes_M = NULL;
bnum_bin2bn(s, bytes_s, len_s); bnum_bin2bn(s, bytes_s, len_s);
bnum_bin2bn(B, bytes_B, len_B); bnum_bin2bn(B, bytes_B, len_B);
@@ -384,14 +384,7 @@ srp_user_process_challenge(struct SRPUser *usr, const unsigned char *bytes_s, in
calculate_H_AMK(usr->alg, usr->H_AMK, usr->A, usr->M, usr->session_key, usr->session_key_len); calculate_H_AMK(usr->alg, usr->H_AMK, usr->A, usr->M, usr->session_key, usr->session_key_len);
*bytes_M = usr->M; *bytes_M = usr->M;
if (len_M) *len_M = hash_length(usr->alg);
*len_M = hash_length(usr->alg);
}
else
{
*bytes_M = NULL;
if (len_M)
*len_M = 0;
} }
cleanup2: cleanup2:
@@ -607,10 +600,12 @@ client_setup_new(struct pair_setup_context *handle, const char *pin, pair_cb add
if (!is_initialized()) if (!is_initialized())
return -1; return -1;
if (!pin || strlen(pin) < 4) if (!pin)
return -1; return -1;
memcpy(sctx->pin, pin, sizeof(sctx->pin)); sctx->pin = strdup(pin);
if (!sctx->pin)
return -1;
return 0; return 0;
} }
@@ -627,6 +622,7 @@ client_setup_free(struct pair_setup_context *handle)
free(sctx->salt); free(sctx->salt);
free(sctx->epk); free(sctx->epk);
free(sctx->authtag); free(sctx->authtag);
free(sctx->pin);
} }
static uint8_t * static uint8_t *
@@ -639,7 +635,7 @@ client_setup_request1(size_t *len, struct pair_setup_context *handle)
uint32_t uint32; uint32_t uint32;
char *data = NULL; // Necessary to initialize because plist_to_bin() uses value char *data = NULL; // Necessary to initialize because plist_to_bin() uses value
sctx->user = srp_user_new(HASH_SHA1, SRP_NG_2048, USERNAME, (unsigned char *)sctx->pin, sizeof(sctx->pin), 0, 0); sctx->user = srp_user_new(HASH_SHA1, SRP_NG_2048, USERNAME, (unsigned char *)sctx->pin, strlen(sctx->pin), 0, 0);
dict = plist_new_dict(); dict = plist_new_dict();
+17 -22
View File
@@ -472,7 +472,7 @@ srp_user_process_challenge(struct SRPUser *usr, const unsigned char *bytes_s, in
bnum u, x; bnum u, x;
*len_M = 0; *len_M = 0;
*bytes_M = 0; *bytes_M = NULL;
bnum_bin2bn(s, bytes_s, len_s); bnum_bin2bn(s, bytes_s, len_s);
bnum_bin2bn(B, bytes_B, len_B); bnum_bin2bn(B, bytes_B, len_B);
@@ -512,14 +512,7 @@ srp_user_process_challenge(struct SRPUser *usr, const unsigned char *bytes_s, in
calculate_H_AMK(usr->alg, usr->H_AMK, usr->A, usr->M, usr->session_key, usr->session_key_len); calculate_H_AMK(usr->alg, usr->H_AMK, usr->A, usr->M, usr->session_key, usr->session_key_len);
*bytes_M = usr->M; *bytes_M = usr->M;
if (len_M) *len_M = hash_length(usr->alg);
*len_M = hash_length(usr->alg);
}
else
{
*bytes_M = NULL;
if (len_M)
*len_M = 0;
} }
cleanup2: cleanup2:
@@ -1180,20 +1173,17 @@ client_setup_new(struct pair_setup_context *handle, const char *pin, pair_cb add
if (!is_initialized()) if (!is_initialized())
return -1; return -1;
if (handle->type == &pair_client_homekit_normal) if (!pin && handle->type == &pair_client_homekit_transient)
{ pin = "3939";
if (!pin || strlen(pin) < 4) else if (!pin)
return -1; return -1;
}
else if (handle->type == &pair_client_homekit_transient && !pin)
{
pin = "3939";
}
if (device_id && strlen(device_id) >= PAIR_AP_DEVICE_ID_LEN_MAX) if (device_id && strlen(device_id) >= PAIR_AP_DEVICE_ID_LEN_MAX)
return -1; return -1;
memcpy(sctx->pin, pin, sizeof(sctx->pin)); sctx->pin = strdup(pin);
if (!sctx->pin)
return -1;
sctx->add_cb = add_cb; sctx->add_cb = add_cb;
sctx->add_cb_arg = cb_arg; sctx->add_cb_arg = cb_arg;
@@ -1223,6 +1213,7 @@ client_setup_free(struct pair_setup_context *handle)
free(sctx->salt); free(sctx->salt);
free(sctx->epk); free(sctx->epk);
free(sctx->authtag); free(sctx->authtag);
free(sctx->pin);
} }
static uint8_t * static uint8_t *
@@ -1248,7 +1239,7 @@ client_setup_request1(size_t *len, struct pair_setup_context *handle)
goto error; goto error;
} }
sctx->user = srp_user_new(HASH_SHA512, SRP_NG_3072, USERNAME, (unsigned char *)sctx->pin, sizeof(sctx->pin), 0, 0); sctx->user = srp_user_new(HASH_SHA512, SRP_NG_3072, USERNAME, (unsigned char *)sctx->pin, strlen(sctx->pin), 0, 0);
if (!sctx->user) if (!sctx->user)
{ {
handle->errmsg = "Setup request 1: Create SRP user failed"; handle->errmsg = "Setup request 1: Create SRP user failed";
@@ -1949,6 +1940,7 @@ client_verify_response2(struct pair_verify_context *handle, const uint8_t *data,
handle->status = PAIR_STATUS_COMPLETED; handle->status = PAIR_STATUS_COMPLETED;
pair_tlv_free(response);
return 0; return 0;
} }
@@ -2010,7 +2002,9 @@ server_setup_new(struct pair_setup_context *handle, const char *pin, pair_cb add
if (!device_id || strlen(device_id) >= PAIR_AP_DEVICE_ID_LEN_MAX) if (!device_id || strlen(device_id) >= PAIR_AP_DEVICE_ID_LEN_MAX)
return -1; return -1;
memcpy(sctx->pin, pin, sizeof(sctx->pin)); sctx->pin = strdup(pin);
if (!sctx->pin)
return -1;
sctx->add_cb = add_cb; sctx->add_cb = add_cb;
sctx->add_cb_arg = cb_arg; sctx->add_cb_arg = cb_arg;
@@ -2035,6 +2029,7 @@ server_setup_free(struct pair_setup_context *handle)
free(sctx->M1); free(sctx->M1);
free(sctx->v); free(sctx->v);
free(sctx->salt); free(sctx->salt);
free(sctx->pin);
} }
static int static int
@@ -2063,7 +2058,7 @@ server_setup_request1(struct pair_setup_context *handle, const uint8_t *data, si
sctx->is_transient = (type && type->size == 1 && type->value[0] == PairingFlagsTransient); sctx->is_transient = (type && type->size == 1 && type->value[0] == PairingFlagsTransient);
// Note this is modified to return a 16 byte salt // Note this is modified to return a 16 byte salt
ret = srp_create_salted_verification_key(HASH_SHA512, SRP_NG_3072, USERNAME, (unsigned char *)sctx->pin, sizeof(sctx->pin), ret = srp_create_salted_verification_key(HASH_SHA512, SRP_NG_3072, USERNAME, (unsigned char *)sctx->pin, strlen(sctx->pin),
&sctx->salt, &sctx->salt_len, &sctx->v, &sctx->v_len, NULL, NULL); &sctx->salt, &sctx->salt_len, &sctx->v, &sctx->v_len, NULL, NULL);
if (ret < 0) if (ret < 0)
{ {