Line | Count | Source (jump to first uncovered line) |
1 | | /* |
2 | | * Copyright (c) 2020 Yubico AB. All rights reserved. |
3 | | * Use of this source code is governed by a BSD-style |
4 | | * license that can be found in the LICENSE file. |
5 | | */ |
6 | | |
7 | | #include "fido.h" |
8 | | #include "fido/config.h" |
9 | | #include "fido/es256.h" |
10 | | |
11 | 286 | #define CMD_ENABLE_ENTATTEST 0x01 |
12 | 286 | #define CMD_TOGGLE_ALWAYS_UV 0x02 |
13 | 478 | #define CMD_SET_PIN_MINLEN 0x03 |
14 | | |
15 | | static int |
16 | | config_prepare_hmac(uint8_t subcmd, const cbor_item_t *item, fido_blob_t *hmac) |
17 | 738 | { |
18 | 738 | uint8_t prefix[32 + 2 * sizeof(uint8_t)], cbor[128]; |
19 | 738 | size_t cbor_len; |
20 | 738 | |
21 | 738 | memset(prefix, 0xff, sizeof(prefix)); |
22 | 738 | prefix[sizeof(prefix) - 2] = CTAP_CBOR_CONFIG; |
23 | 738 | prefix[sizeof(prefix) - 1] = subcmd; |
24 | 738 | |
25 | 738 | if (item == NULL) |
26 | 738 | return fido_blob_set(hmac, prefix, sizeof(prefix)); |
27 | 738 | |
28 | 738 | if ((cbor_len = cbor_serialize(item, cbor, sizeof(cbor))) == 0) { |
29 | 0 | fido_log_debug("%s: cbor_serialize", __func__); |
30 | 0 | return -1; |
31 | 0 | } |
32 | 738 | if ((hmac->ptr = malloc(cbor_len + sizeof(prefix))) == NULL) { |
33 | 7 | fido_log_debug("%s: malloc", __func__); |
34 | 7 | return -1; |
35 | 7 | } |
36 | 731 | memcpy(hmac->ptr, prefix, sizeof(prefix)); |
37 | 731 | memcpy(hmac->ptr + sizeof(prefix), cbor, cbor_len); |
38 | 731 | hmac->len = cbor_len + sizeof(prefix); |
39 | 731 | |
40 | 731 | return 0; |
41 | 731 | } |
42 | | |
43 | | static int |
44 | | config_tx(fido_dev_t *dev, uint8_t subcmd, cbor_item_t **paramv, size_t paramc, |
45 | | const char *pin) |
46 | 1.05k | { |
47 | 1.05k | cbor_item_t *argv[4]; |
48 | 1.05k | es256_pk_t *pk = NULL; |
49 | 1.05k | fido_blob_t *ecdh = NULL, f, hmac; |
50 | 1.05k | const uint8_t cmd = CTAP_CBOR_CONFIG; |
51 | 1.05k | int r = FIDO_ERR_INTERNAL; |
52 | 1.05k | |
53 | 1.05k | memset(&f, 0, sizeof(f)); |
54 | 1.05k | memset(&hmac, 0, sizeof(hmac)); |
55 | 1.05k | memset(&argv, 0, sizeof(argv)); |
56 | 1.05k | |
57 | 1.05k | /* subCommand */ |
58 | 1.05k | if ((argv[0] = cbor_build_uint8(subcmd)) == NULL) { |
59 | 15 | fido_log_debug("%s: cbor encode", __func__); |
60 | 15 | goto fail; |
61 | 15 | } |
62 | 1.03k | |
63 | 1.03k | /* pinProtocol, pinAuth */ |
64 | 1.03k | if (fido_dev_can_get_uv_token(dev, pin, FIDO_OPT_OMIT)) { |
65 | 746 | if ((argv[1] = cbor_flatten_vector(paramv, paramc)) == NULL) { |
66 | 8 | fido_log_debug("%s: cbor_flatten_vector", __func__); |
67 | 8 | goto fail; |
68 | 8 | } |
69 | 738 | if (config_prepare_hmac(subcmd, argv[1], &hmac) < 0) { |
70 | 7 | fido_log_debug("%s: config_prepare_hmac", __func__); |
71 | 7 | goto fail; |
72 | 7 | } |
73 | 731 | if ((r = fido_do_ecdh(dev, &pk, &ecdh)) != FIDO_OK) { |
74 | 610 | fido_log_debug("%s: fido_do_ecdh", __func__); |
75 | 610 | goto fail; |
76 | 610 | } |
77 | 121 | if ((r = cbor_add_uv_params(dev, cmd, &hmac, pk, ecdh, pin, |
78 | 121 | NULL, &argv[3], &argv[2])) != FIDO_OK) { |
79 | 107 | fido_log_debug("%s: cbor_add_uv_params", __func__); |
80 | 107 | goto fail; |
81 | 107 | } |
82 | 303 | } |
83 | 303 | |
84 | 303 | /* framing and transmission */ |
85 | 303 | if (cbor_build_frame(cmd, argv, nitems(argv), &f) < 0 || |
86 | 303 | fido_tx(dev, CTAP_CMD_CBOR, f.ptr, f.len) < 0) { |
87 | 41 | fido_log_debug("%s: fido_tx", __func__); |
88 | 41 | r = FIDO_ERR_TX; |
89 | 41 | goto fail; |
90 | 41 | } |
91 | 262 | |
92 | 262 | r = FIDO_OK; |
93 | 1.05k | fail: |
94 | 1.05k | cbor_vector_free(argv, nitems(argv)); |
95 | 1.05k | es256_pk_free(&pk); |
96 | 1.05k | fido_blob_free(&ecdh); |
97 | 1.05k | free(f.ptr); |
98 | 1.05k | free(hmac.ptr); |
99 | 1.05k | |
100 | 1.05k | return r; |
101 | 262 | } |
102 | | |
103 | | static int |
104 | | config_enable_entattest_wait(fido_dev_t *dev, const char *pin, int ms) |
105 | 286 | { |
106 | 286 | int r; |
107 | 286 | |
108 | 286 | if ((r = config_tx(dev, CMD_ENABLE_ENTATTEST, NULL, 0, pin)) != FIDO_OK) |
109 | 286 | return r; |
110 | 74 | |
111 | 74 | return fido_rx_cbor_status(dev, ms); |
112 | 74 | } |
113 | | |
114 | | int |
115 | | fido_dev_enable_entattest(fido_dev_t *dev, const char *pin) |
116 | 286 | { |
117 | 286 | return (config_enable_entattest_wait(dev, pin, -1)); |
118 | 286 | } |
119 | | |
120 | | static int |
121 | | config_toggle_always_uv_wait(fido_dev_t *dev, const char *pin, int ms) |
122 | 286 | { |
123 | 286 | int r; |
124 | 286 | |
125 | 286 | if ((r = config_tx(dev, CMD_TOGGLE_ALWAYS_UV, NULL, 0, pin)) != FIDO_OK) |
126 | 286 | return r; |
127 | 77 | |
128 | 77 | return (fido_rx_cbor_status(dev, ms)); |
129 | 77 | } |
130 | | |
131 | | int |
132 | | fido_dev_toggle_always_uv(fido_dev_t *dev, const char *pin) |
133 | 286 | { |
134 | 286 | return config_toggle_always_uv_wait(dev, pin, -1); |
135 | 286 | } |
136 | | |
137 | | static int |
138 | | config_pin_minlen_tx(fido_dev_t *dev, size_t len, bool force, const char *pin) |
139 | 579 | { |
140 | 579 | cbor_item_t *argv[3]; |
141 | 579 | int r; |
142 | 579 | |
143 | 579 | memset(argv, 0, sizeof(argv)); |
144 | 579 | |
145 | 579 | if ((!len && !force) || len > UINT8_MAX) { |
146 | 98 | r = FIDO_ERR_INVALID_ARGUMENT; |
147 | 98 | goto fail; |
148 | 98 | } |
149 | 481 | if (len && (argv[0] = cbor_build_uint8((uint8_t)len)) == NULL) { |
150 | 1 | fido_log_debug("%s: cbor_encode_uint8", __func__); |
151 | 1 | r = FIDO_ERR_INTERNAL; |
152 | 1 | goto fail; |
153 | 1 | } |
154 | 480 | if (force && (argv[2] = cbor_build_bool(true)) == NULL) { |
155 | 2 | fido_log_debug("%s: cbor_build_bool", __func__); |
156 | 2 | r = FIDO_ERR_INTERNAL; |
157 | 2 | goto fail; |
158 | 2 | } |
159 | 478 | if ((r = config_tx(dev, CMD_SET_PIN_MINLEN, argv, nitems(argv), |
160 | 478 | pin)) != FIDO_OK) { |
161 | 367 | fido_log_debug("%s: config_tx", __func__); |
162 | 367 | goto fail; |
163 | 367 | } |
164 | 579 | |
165 | 579 | fail: |
166 | 579 | cbor_vector_free(argv, nitems(argv)); |
167 | 579 | |
168 | 579 | return r; |
169 | 478 | } |
170 | | |
171 | | static int |
172 | | config_pin_minlen(fido_dev_t *dev, size_t len, bool force, const char *pin, |
173 | | int ms) |
174 | 579 | { |
175 | 579 | int r; |
176 | 579 | |
177 | 579 | if ((r = config_pin_minlen_tx(dev, len, force, pin)) != FIDO_OK) |
178 | 579 | return r; |
179 | 111 | |
180 | 111 | return fido_rx_cbor_status(dev, ms); |
181 | 111 | } |
182 | | |
183 | | int |
184 | | fido_dev_set_pin_minlen(fido_dev_t *dev, size_t len, const char *pin) |
185 | 290 | { |
186 | 290 | return config_pin_minlen(dev, len, false, pin, -1); |
187 | 290 | } |
188 | | |
189 | | int |
190 | | fido_dev_force_pin_change(fido_dev_t *dev, const char *pin) |
191 | 289 | { |
192 | 289 | return config_pin_minlen(dev, 0, true, pin, -1); |
193 | 289 | } |