* or implied warranty.
*/
+/*
+ * Message protection services: unwrap with scatter-gather API.
+ */
+
#include "gssapiP_eap.h"
/*
assert(header != NULL);
padding = gssEapLocateIov(iov, iov_count, GSS_IOV_BUFFER_TYPE_PADDING);
- if (padding != NULL && padding->buffer.length != 0)
+ if (padding != NULL && padding->buffer.length != 0) {
+ *minor = GSSEAP_BAD_PADDING_IOV;
return GSS_S_DEFECTIVE_TOKEN;
+ }
trailer = gssEapLocateIov(iov, iov_count, GSS_IOV_BUFFER_TYPE_TRAILER);
ptr = (unsigned char *)header->buffer.value;
- if (header->buffer.length < 16)
+ if (header->buffer.length < 16) {
+ *minor = GSSEAP_TOK_TRUNC;
return GSS_S_DEFECTIVE_TOKEN;
+ }
- if ((ptr[2] & flags) != flags)
+ if ((ptr[2] & flags) != flags) {
+ *minor = GSSEAP_BAD_DIRECTION;
return GSS_S_BAD_SIG;
+ }
if (toktype == TOK_TYPE_WRAP) {
unsigned int krbTrailerLen;
|| althdr[2] != ptr[2]
|| althdr[3] != ptr[3]
|| memcmp(althdr + 8, ptr + 8, 8) != 0) {
- *minor = 0;
+ *minor = GSSEAP_BAD_WRAP_TOKEN;
return GSS_S_BAD_SIG;
}
} else {
return code;
defective:
- *minor = 0;
+ *minor = GSSEAP_BAD_WRAP_TOKEN;
return GSS_S_DEFECTIVE_TOKEN;
}
assert(toktype == TOK_TYPE_WRAP);
if (toktype != TOK_TYPE_WRAP) {
- code = EINVAL;
+ code = GSSEAP_WRONG_TOK_ID;
goto cleanup;
}
if (type == GSS_IOV_BUFFER_TYPE_DATA) {
if (data != NULL) {
/* only a single DATA buffer can appear */
- code = EINVAL;
+ code = GSSEAP_BAD_STREAM_IOV;
goto cleanup;
}
if (data == NULL) {
/* a single DATA buffer must be present */
- code = EINVAL;
+ code = GSSEAP_BAD_STREAM_IOV;
goto cleanup;
}
}
/* IOV: -----------0-------------+---1---+--2--+----------------3--------------*/
- /* Old: GSS-Header | Conf | Data | Pad | */
/* CFX: GSS-Header | Kerb-Header | Data | | EC | E(Header) | Kerb-Trailer */
/* GSS: -------GSS-HEADER--------+-DATA--+-PAD-+----------GSS-TRAILER----------*/
if (stream->buffer.length < theader->buffer.length +
tpadding->buffer.length +
ttrailer->buffer.length) {
- code = KRB5_BAD_MSIZE;
major = GSS_S_DEFECTIVE_TOKEN;
+ code = GSSEAP_TOK_TRUNC;
goto cleanup;
}
{
OM_uint32 major;
- if (ctx->encryptionType == ENCTYPE_NULL)
+ if (ctx->encryptionType == ENCTYPE_NULL) {
+ *minor = GSSEAP_KEY_UNAVAILABLE;
return GSS_S_UNAVAILABLE;
+ }
if (gssEapLocateIov(iov, iov_count, GSS_IOV_BUFFER_TYPE_STREAM) != NULL) {
major = unwrapStream(minor, ctx, conf_state, qop_state,
gss_iov_buffer_desc *iov,
int iov_count)
{
- if (!CTX_IS_ESTABLISHED(ctx))
+ OM_uint32 major;
+
+ if (ctx == GSS_C_NO_CONTEXT) {
+ *minor = EINVAL;
return GSS_S_NO_CONTEXT;
+ }
- return gssEapUnwrapOrVerifyMIC(minor, ctx, conf_state, qop_state,
- iov, iov_count, TOK_TYPE_WRAP);
+ *minor = 0;
+
+ GSSEAP_MUTEX_LOCK(&ctx->mutex);
+
+ if (!CTX_IS_ESTABLISHED(ctx)) {
+ major = GSS_S_NO_CONTEXT;
+ *minor = GSSEAP_CONTEXT_INCOMPLETE;
+ goto cleanup;
+ }
+
+ major = gssEapUnwrapOrVerifyMIC(minor, ctx, conf_state, qop_state,
+ iov, iov_count, TOK_TYPE_WRAP);
+ if (GSS_ERROR(major))
+ goto cleanup;
+
+cleanup:
+ GSSEAP_MUTEX_UNLOCK(&ctx->mutex);
+
+ return major;
}