mirror of
https://github.com/PurpleI2P/i2pd.git
synced 2025-01-22 04:04:16 +00:00
check I2NP messsage buffer size
This commit is contained in:
parent
a1e820182c
commit
df18692af9
@ -283,7 +283,7 @@ namespace client
|
|||||||
break;
|
break;
|
||||||
case eI2NPDeliveryStatus:
|
case eI2NPDeliveryStatus:
|
||||||
// we assume tunnel tests non-encrypted
|
// we assume tunnel tests non-encrypted
|
||||||
HandleDeliveryStatusMessage (CreateI2NPMessage (buf, GetI2NPMessageLength (buf), from));
|
HandleDeliveryStatusMessage (CreateI2NPMessage (buf, GetI2NPMessageLength (buf, len), from));
|
||||||
break;
|
break;
|
||||||
case eI2NPDatabaseStore:
|
case eI2NPDatabaseStore:
|
||||||
HandleDatabaseStoreMessage (buf + I2NP_HEADER_SIZE, bufbe16toh (buf + I2NP_HEADER_SIZE_OFFSET));
|
HandleDatabaseStoreMessage (buf + I2NP_HEADER_SIZE, bufbe16toh (buf + I2NP_HEADER_SIZE_OFFSET));
|
||||||
@ -292,7 +292,7 @@ namespace client
|
|||||||
HandleDatabaseSearchReplyMessage (buf + I2NP_HEADER_SIZE, bufbe16toh (buf + I2NP_HEADER_SIZE_OFFSET));
|
HandleDatabaseSearchReplyMessage (buf + I2NP_HEADER_SIZE, bufbe16toh (buf + I2NP_HEADER_SIZE_OFFSET));
|
||||||
break;
|
break;
|
||||||
default:
|
default:
|
||||||
i2p::HandleI2NPMessage (CreateI2NPMessage (buf, GetI2NPMessageLength (buf), from));
|
i2p::HandleI2NPMessage (CreateI2NPMessage (buf, GetI2NPMessageLength (buf, len), from));
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
@ -512,12 +512,17 @@ namespace garlic
|
|||||||
|
|
||||||
void GarlicDestination::HandleGarlicPayload (uint8_t * buf, size_t len, std::shared_ptr<i2p::tunnel::InboundTunnel> from)
|
void GarlicDestination::HandleGarlicPayload (uint8_t * buf, size_t len, std::shared_ptr<i2p::tunnel::InboundTunnel> from)
|
||||||
{
|
{
|
||||||
const uint8_t * buf1 = buf;
|
if (len < 1)
|
||||||
|
{
|
||||||
|
LogPrint (eLogError, "Garlic: payload is too short");
|
||||||
|
return;
|
||||||
|
}
|
||||||
int numCloves = buf[0];
|
int numCloves = buf[0];
|
||||||
LogPrint (eLogDebug, "Garlic: ", numCloves," cloves");
|
LogPrint (eLogDebug, "Garlic: ", numCloves," cloves");
|
||||||
buf++;
|
buf++; len--;
|
||||||
for (int i = 0; i < numCloves; i++)
|
for (int i = 0; i < numCloves; i++)
|
||||||
{
|
{
|
||||||
|
const uint8_t * buf1 = buf;
|
||||||
// delivery instructions
|
// delivery instructions
|
||||||
uint8_t flag = buf[0];
|
uint8_t flag = buf[0];
|
||||||
buf++; // flag
|
buf++; // flag
|
||||||
@ -527,17 +532,29 @@ namespace garlic
|
|||||||
LogPrint (eLogWarning, "Garlic: clove encrypted");
|
LogPrint (eLogWarning, "Garlic: clove encrypted");
|
||||||
buf += 32;
|
buf += 32;
|
||||||
}
|
}
|
||||||
|
ptrdiff_t offset = buf - buf1;
|
||||||
GarlicDeliveryType deliveryType = (GarlicDeliveryType)((flag >> 5) & 0x03);
|
GarlicDeliveryType deliveryType = (GarlicDeliveryType)((flag >> 5) & 0x03);
|
||||||
switch (deliveryType)
|
switch (deliveryType)
|
||||||
{
|
{
|
||||||
case eGarlicDeliveryTypeLocal:
|
case eGarlicDeliveryTypeLocal:
|
||||||
LogPrint (eLogDebug, "Garlic: type local");
|
LogPrint (eLogDebug, "Garlic: type local");
|
||||||
HandleI2NPMessage (buf, len, from);
|
if (offset > (int)len)
|
||||||
|
{
|
||||||
|
LogPrint (eLogError, "Garlic: message is too short");
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
HandleI2NPMessage (buf, len - offset, from);
|
||||||
break;
|
break;
|
||||||
case eGarlicDeliveryTypeDestination:
|
case eGarlicDeliveryTypeDestination:
|
||||||
LogPrint (eLogDebug, "Garlic: type destination");
|
LogPrint (eLogDebug, "Garlic: type destination");
|
||||||
buf += 32; // destination. check it later or for multiple destinations
|
buf += 32; // destination. check it later or for multiple destinations
|
||||||
HandleI2NPMessage (buf, len, from);
|
offset = buf1 - buf;
|
||||||
|
if (offset > (int)len)
|
||||||
|
{
|
||||||
|
LogPrint (eLogError, "Garlic: message is too short");
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
HandleI2NPMessage (buf, len - offset, from);
|
||||||
break;
|
break;
|
||||||
case eGarlicDeliveryTypeTunnel:
|
case eGarlicDeliveryTypeTunnel:
|
||||||
{
|
{
|
||||||
@ -545,9 +562,15 @@ namespace garlic
|
|||||||
// gwHash and gwTunnel sequence is reverted
|
// gwHash and gwTunnel sequence is reverted
|
||||||
uint8_t * gwHash = buf;
|
uint8_t * gwHash = buf;
|
||||||
buf += 32;
|
buf += 32;
|
||||||
|
offset = buf1 - buf;
|
||||||
|
if (offset + 4 > (int)len)
|
||||||
|
{
|
||||||
|
LogPrint (eLogError, "Garlic: message is too short");
|
||||||
|
break;
|
||||||
|
}
|
||||||
uint32_t gwTunnel = bufbe32toh (buf);
|
uint32_t gwTunnel = bufbe32toh (buf);
|
||||||
buf += 4;
|
buf += 4; offset += 4;
|
||||||
auto msg = CreateI2NPMessage (buf, GetI2NPMessageLength (buf), from);
|
auto msg = CreateI2NPMessage (buf, GetI2NPMessageLength (buf, len - offset), from);
|
||||||
if (from) // received through an inbound tunnel
|
if (from) // received through an inbound tunnel
|
||||||
{
|
{
|
||||||
std::shared_ptr<i2p::tunnel::OutboundTunnel> tunnel;
|
std::shared_ptr<i2p::tunnel::OutboundTunnel> tunnel;
|
||||||
@ -568,9 +591,17 @@ namespace garlic
|
|||||||
{
|
{
|
||||||
uint8_t * ident = buf;
|
uint8_t * ident = buf;
|
||||||
buf += 32;
|
buf += 32;
|
||||||
|
offset = buf1 - buf;
|
||||||
if (!from) // received directly
|
if (!from) // received directly
|
||||||
|
{
|
||||||
|
if (offset > (int)len)
|
||||||
|
{
|
||||||
|
LogPrint (eLogError, "Garlic: message is too short");
|
||||||
|
break;
|
||||||
|
}
|
||||||
i2p::transport::transports.SendMessage (ident,
|
i2p::transport::transports.SendMessage (ident,
|
||||||
CreateI2NPMessage (buf, GetI2NPMessageLength (buf)));
|
CreateI2NPMessage (buf, GetI2NPMessageLength (buf, len - offset)));
|
||||||
|
}
|
||||||
else
|
else
|
||||||
LogPrint (eLogWarning, "Garlic: type router for inbound tunnels not supported");
|
LogPrint (eLogWarning, "Garlic: type router for inbound tunnels not supported");
|
||||||
break;
|
break;
|
||||||
@ -578,15 +609,22 @@ namespace garlic
|
|||||||
default:
|
default:
|
||||||
LogPrint (eLogWarning, "Garlic: unknown delivery type ", (int)deliveryType);
|
LogPrint (eLogWarning, "Garlic: unknown delivery type ", (int)deliveryType);
|
||||||
}
|
}
|
||||||
buf += GetI2NPMessageLength (buf); // I2NP
|
if (offset > (int)len)
|
||||||
|
{
|
||||||
|
LogPrint (eLogError, "Garlic: message is too short");
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
buf += GetI2NPMessageLength (buf, len - offset); // I2NP
|
||||||
buf += 4; // CloveID
|
buf += 4; // CloveID
|
||||||
buf += 8; // Date
|
buf += 8; // Date
|
||||||
buf += 3; // Certificate
|
buf += 3; // Certificate
|
||||||
if (buf - buf1 > (int)len)
|
offset = buf1 - buf;
|
||||||
|
if (offset > (int)len)
|
||||||
{
|
{
|
||||||
LogPrint (eLogError, "Garlic: clove is too long");
|
LogPrint (eLogError, "Garlic: clove is too long");
|
||||||
break;
|
break;
|
||||||
}
|
}
|
||||||
|
len -= offset;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
@ -546,18 +546,40 @@ namespace i2p
|
|||||||
return msg;
|
return msg;
|
||||||
}
|
}
|
||||||
|
|
||||||
size_t GetI2NPMessageLength (const uint8_t * msg)
|
size_t GetI2NPMessageLength (const uint8_t * msg, size_t len)
|
||||||
{
|
{
|
||||||
return bufbe16toh (msg + I2NP_HEADER_SIZE_OFFSET) + I2NP_HEADER_SIZE;
|
if (len < I2NP_HEADER_SIZE_OFFSET + 2)
|
||||||
|
{
|
||||||
|
LogPrint (eLogError, "I2NP: message length ", len, " is smaller than header");
|
||||||
|
return len;
|
||||||
|
}
|
||||||
|
auto l = bufbe16toh (msg + I2NP_HEADER_SIZE_OFFSET) + I2NP_HEADER_SIZE;
|
||||||
|
if (l > len)
|
||||||
|
{
|
||||||
|
LogPrint (eLogError, "I2NP: message length ", l, " exceeds buffer length ", len);
|
||||||
|
l = len;
|
||||||
|
}
|
||||||
|
return l;
|
||||||
}
|
}
|
||||||
|
|
||||||
void HandleI2NPMessage (uint8_t * msg, size_t len)
|
void HandleI2NPMessage (uint8_t * msg, size_t len)
|
||||||
{
|
{
|
||||||
|
if (len < I2NP_HEADER_SIZE)
|
||||||
|
{
|
||||||
|
LogPrint (eLogError, "I2NP: message length ", len, " is smaller than header");
|
||||||
|
return;
|
||||||
|
}
|
||||||
uint8_t typeID = msg[I2NP_HEADER_TYPEID_OFFSET];
|
uint8_t typeID = msg[I2NP_HEADER_TYPEID_OFFSET];
|
||||||
uint32_t msgID = bufbe32toh (msg + I2NP_HEADER_MSGID_OFFSET);
|
uint32_t msgID = bufbe32toh (msg + I2NP_HEADER_MSGID_OFFSET);
|
||||||
LogPrint (eLogDebug, "I2NP: msg received len=", len,", type=", (int)typeID, ", msgID=", (unsigned int)msgID);
|
LogPrint (eLogDebug, "I2NP: msg received len=", len,", type=", (int)typeID, ", msgID=", (unsigned int)msgID);
|
||||||
uint8_t * buf = msg + I2NP_HEADER_SIZE;
|
uint8_t * buf = msg + I2NP_HEADER_SIZE;
|
||||||
int size = bufbe16toh (msg + I2NP_HEADER_SIZE_OFFSET);
|
auto size = bufbe16toh (msg + I2NP_HEADER_SIZE_OFFSET);
|
||||||
|
len -= I2NP_HEADER_SIZE;
|
||||||
|
if (size > len)
|
||||||
|
{
|
||||||
|
LogPrint (eLogError, "I2NP: payload size ", size, " exceeds buffer length ", len);
|
||||||
|
size = len;
|
||||||
|
}
|
||||||
switch (typeID)
|
switch (typeID)
|
||||||
{
|
{
|
||||||
case eI2NPVariableTunnelBuild:
|
case eI2NPVariableTunnelBuild:
|
||||||
|
@ -243,7 +243,7 @@ namespace tunnel
|
|||||||
const uint8_t * buf, size_t len, uint32_t replyMsgID = 0);
|
const uint8_t * buf, size_t len, uint32_t replyMsgID = 0);
|
||||||
std::shared_ptr<I2NPMessage> CreateTunnelGatewayMsg (uint32_t tunnelID, std::shared_ptr<I2NPMessage> msg);
|
std::shared_ptr<I2NPMessage> CreateTunnelGatewayMsg (uint32_t tunnelID, std::shared_ptr<I2NPMessage> msg);
|
||||||
|
|
||||||
size_t GetI2NPMessageLength (const uint8_t * msg);
|
size_t GetI2NPMessageLength (const uint8_t * msg, size_t len);
|
||||||
void HandleI2NPMessage (uint8_t * msg, size_t len);
|
void HandleI2NPMessage (uint8_t * msg, size_t len);
|
||||||
void HandleI2NPMessage (std::shared_ptr<I2NPMessage> msg);
|
void HandleI2NPMessage (std::shared_ptr<I2NPMessage> msg);
|
||||||
|
|
||||||
|
@ -454,7 +454,7 @@ namespace i2p
|
|||||||
|
|
||||||
void RouterContext::HandleI2NPMessage (const uint8_t * buf, size_t len, std::shared_ptr<i2p::tunnel::InboundTunnel> from)
|
void RouterContext::HandleI2NPMessage (const uint8_t * buf, size_t len, std::shared_ptr<i2p::tunnel::InboundTunnel> from)
|
||||||
{
|
{
|
||||||
i2p::HandleI2NPMessage (CreateI2NPMessage (buf, GetI2NPMessageLength (buf), from));
|
i2p::HandleI2NPMessage (CreateI2NPMessage (buf, GetI2NPMessageLength (buf, len), from));
|
||||||
}
|
}
|
||||||
|
|
||||||
void RouterContext::ProcessGarlicMessage (std::shared_ptr<I2NPMessage> msg)
|
void RouterContext::ProcessGarlicMessage (std::shared_ptr<I2NPMessage> msg)
|
||||||
|
Loading…
x
Reference in New Issue
Block a user