xref: /xnu-11215.81.4/tests/icmp_fragmented_payload.c (revision d4514f0bc1d3f944c22d92e68b646ac3fb40d452)
1*d4514f0bSApple OSS Distributions /*
2*d4514f0bSApple OSS Distributions  * Copyright (c) 2021 Apple Inc. All rights reserved.
3*d4514f0bSApple OSS Distributions  *
4*d4514f0bSApple OSS Distributions  * @APPLE_OSREFERENCE_LICENSE_HEADER_START@
5*d4514f0bSApple OSS Distributions  *
6*d4514f0bSApple OSS Distributions  * This file contains Original Code and/or Modifications of Original Code
7*d4514f0bSApple OSS Distributions  * as defined in and that are subject to the Apple Public Source License
8*d4514f0bSApple OSS Distributions  * Version 2.0 (the 'License'). You may not use this file except in
9*d4514f0bSApple OSS Distributions  * compliance with the License. The rights granted to you under the License
10*d4514f0bSApple OSS Distributions  * may not be used to create, or enable the creation or redistribution of,
11*d4514f0bSApple OSS Distributions  * unlawful or unlicensed copies of an Apple operating system, or to
12*d4514f0bSApple OSS Distributions  * circumvent, violate, or enable the circumvention or violation of, any
13*d4514f0bSApple OSS Distributions  * terms of an Apple operating system software license agreement.
14*d4514f0bSApple OSS Distributions  *
15*d4514f0bSApple OSS Distributions  * Please obtain a copy of the License at
16*d4514f0bSApple OSS Distributions  * http://www.opensource.apple.com/apsl/ and read it before using this file.
17*d4514f0bSApple OSS Distributions  *
18*d4514f0bSApple OSS Distributions  * The Original Code and all software distributed under the License are
19*d4514f0bSApple OSS Distributions  * distributed on an 'AS IS' basis, WITHOUT WARRANTY OF ANY KIND, EITHER
20*d4514f0bSApple OSS Distributions  * EXPRESS OR IMPLIED, AND APPLE HEREBY DISCLAIMS ALL SUCH WARRANTIES,
21*d4514f0bSApple OSS Distributions  * INCLUDING WITHOUT LIMITATION, ANY WARRANTIES OF MERCHANTABILITY,
22*d4514f0bSApple OSS Distributions  * FITNESS FOR A PARTICULAR PURPOSE, QUIET ENJOYMENT OR NON-INFRINGEMENT.
23*d4514f0bSApple OSS Distributions  * Please see the License for the specific language governing rights and
24*d4514f0bSApple OSS Distributions  * limitations under the License.
25*d4514f0bSApple OSS Distributions  *
26*d4514f0bSApple OSS Distributions  * @APPLE_OSREFERENCE_LICENSE_HEADER_END@
27*d4514f0bSApple OSS Distributions  */
28*d4514f0bSApple OSS Distributions 
29*d4514f0bSApple OSS Distributions #define _IP_VHL 1
30*d4514f0bSApple OSS Distributions 
31*d4514f0bSApple OSS Distributions #include <sys/fcntl.h>
32*d4514f0bSApple OSS Distributions #include <sys/socket.h>
33*d4514f0bSApple OSS Distributions #include <net/if.h>
34*d4514f0bSApple OSS Distributions #include <netinet/in.h>
35*d4514f0bSApple OSS Distributions #include <netinet/tcp.h>
36*d4514f0bSApple OSS Distributions #include <netinet/ip_icmp.h>
37*d4514f0bSApple OSS Distributions #include <arpa/inet.h>
38*d4514f0bSApple OSS Distributions 
39*d4514f0bSApple OSS Distributions #include <darwintest.h>
40*d4514f0bSApple OSS Distributions #include <string.h>
41*d4514f0bSApple OSS Distributions #include <unistd.h>
42*d4514f0bSApple OSS Distributions 
43*d4514f0bSApple OSS Distributions /*
44*d4514f0bSApple OSS Distributions  * This test helps to reproduce a buffer overflow in the control plane:
45*d4514f0bSApple OSS Distributions  * rdar://84355745
46*d4514f0bSApple OSS Distributions  *
47*d4514f0bSApple OSS Distributions  * The test allows to create a custom ICMP reply, and to send only a portion of it.
48*d4514f0bSApple OSS Distributions  *
49*d4514f0bSApple OSS Distributions  * To reproduce rdar://84355745, the test creates an ICMP "host unreachable" packet
50*d4514f0bSApple OSS Distributions  * that contains a TCP header, and sends the first 28 bytes of the ICMP payload
51*d4514f0bSApple OSS Distributions  * (48 including the outer IP header).
52*d4514f0bSApple OSS Distributions  *
53*d4514f0bSApple OSS Distributions  *  +-----+-----+-----+-----+
54*d4514f0bSApple OSS Distributions  *  | IP  | ICMP| IP  | TCP |
55*d4514f0bSApple OSS Distributions  *  +-----+-----+-----+-----+
56*d4514f0bSApple OSS Distributions  *
57*d4514f0bSApple OSS Distributions  *  <---------------->
58*d4514f0bSApple OSS Distributions  *     sent payload
59*d4514f0bSApple OSS Distributions  *
60*d4514f0bSApple OSS Distributions  * This allows us to ensure that the parsing of the (potentially truncated) TCP
61*d4514f0bSApple OSS Distributions  * headers is done in a secure way.
62*d4514f0bSApple OSS Distributions  */
63*d4514f0bSApple OSS Distributions static void
init_sin_address(struct sockaddr_in * sin)64*d4514f0bSApple OSS Distributions init_sin_address(struct sockaddr_in *sin)
65*d4514f0bSApple OSS Distributions {
66*d4514f0bSApple OSS Distributions 	memset(sin, 0, sizeof(struct sockaddr_in));
67*d4514f0bSApple OSS Distributions 	sin->sin_len = sizeof(struct sockaddr_in);
68*d4514f0bSApple OSS Distributions 	sin->sin_family = AF_INET;
69*d4514f0bSApple OSS Distributions }
70*d4514f0bSApple OSS Distributions 
71*d4514f0bSApple OSS Distributions static uint16_t
checksum_buffer(uint16_t * buf,size_t len)72*d4514f0bSApple OSS Distributions checksum_buffer(uint16_t *buf, size_t len)
73*d4514f0bSApple OSS Distributions {
74*d4514f0bSApple OSS Distributions 	unsigned long sum = 0;
75*d4514f0bSApple OSS Distributions 	while (len > 1) {
76*d4514f0bSApple OSS Distributions 		sum += *buf++;
77*d4514f0bSApple OSS Distributions 		len -= 2;
78*d4514f0bSApple OSS Distributions 		if (sum & 0x80000000) {
79*d4514f0bSApple OSS Distributions 			sum = (sum >> 16) + (sum & 0xFFF);
80*d4514f0bSApple OSS Distributions 		}
81*d4514f0bSApple OSS Distributions 	}
82*d4514f0bSApple OSS Distributions 	if (len == 1) {
83*d4514f0bSApple OSS Distributions 		sum += ((unsigned long)(*(uint8_t*)buf) << 8);
84*d4514f0bSApple OSS Distributions 	}
85*d4514f0bSApple OSS Distributions 	while (sum >> 16) {
86*d4514f0bSApple OSS Distributions 		sum = (sum >> 16) + (sum & 0xFFFF);
87*d4514f0bSApple OSS Distributions 	}
88*d4514f0bSApple OSS Distributions 
89*d4514f0bSApple OSS Distributions 	return (uint16_t)~sum;
90*d4514f0bSApple OSS Distributions }
91*d4514f0bSApple OSS Distributions 
92*d4514f0bSApple OSS Distributions #define MAXICMPBUFLEN 128
93*d4514f0bSApple OSS Distributions typedef struct icmp4_pcb {
94*d4514f0bSApple OSS Distributions 	int             fd;
95*d4514f0bSApple OSS Distributions 	int             id;
96*d4514f0bSApple OSS Distributions 	int             seq;
97*d4514f0bSApple OSS Distributions 	int             err;
98*d4514f0bSApple OSS Distributions 	int             syserr;
99*d4514f0bSApple OSS Distributions 	size_t          txlen;
100*d4514f0bSApple OSS Distributions 	uint16_t        icmp_hdr_len;
101*d4514f0bSApple OSS Distributions 	struct icmp    *icmp_hdr;
102*d4514f0bSApple OSS Distributions 	uint16_t        inner_ip_hdr_len;
103*d4514f0bSApple OSS Distributions 	struct ip      *inner_ip_hdr;
104*d4514f0bSApple OSS Distributions 	uint16_t        inner_tcp_hdr_len;
105*d4514f0bSApple OSS Distributions 	struct tcphdr  *inner_tcp_hdr;
106*d4514f0bSApple OSS Distributions 	struct in_addr  in4addr_local;
107*d4514f0bSApple OSS Distributions 	struct in_addr  in4addr_remote;
108*d4514f0bSApple OSS Distributions 	uint64_t        buf[MAXICMPBUFLEN / 8];
109*d4514f0bSApple OSS Distributions } icmp4_pcb, *icmp4_pcb_t;
110*d4514f0bSApple OSS Distributions 
111*d4514f0bSApple OSS Distributions static void
icmp4_pcb_print(icmp4_pcb_t pcb)112*d4514f0bSApple OSS Distributions icmp4_pcb_print(icmp4_pcb_t pcb)
113*d4514f0bSApple OSS Distributions {
114*d4514f0bSApple OSS Distributions 	if (pcb == NULL) {
115*d4514f0bSApple OSS Distributions 		fprintf(stdout, "icmp pcb: null");
116*d4514f0bSApple OSS Distributions 		return;
117*d4514f0bSApple OSS Distributions 	}
118*d4514f0bSApple OSS Distributions 
119*d4514f0bSApple OSS Distributions 	fprintf(stdout, "icmp pcb: \n"
120*d4514f0bSApple OSS Distributions 	    "  fd=%d\n"
121*d4514f0bSApple OSS Distributions 	    "  id=%d\n"
122*d4514f0bSApple OSS Distributions 	    "  seq=%d\n"
123*d4514f0bSApple OSS Distributions 	    "  err=%d\n"
124*d4514f0bSApple OSS Distributions 	    "  syserr=%d\n"
125*d4514f0bSApple OSS Distributions 	    "  txlen=%lu\n"
126*d4514f0bSApple OSS Distributions 	    "  ICMP:\n"
127*d4514f0bSApple OSS Distributions 	    "    len=%hu\n"
128*d4514f0bSApple OSS Distributions 	    "    type=%d\n"
129*d4514f0bSApple OSS Distributions 	    "    code=%d\n"
130*d4514f0bSApple OSS Distributions 	    "    cksum=%hu\n"
131*d4514f0bSApple OSS Distributions 	    "    icmp_id=%hu\n"
132*d4514f0bSApple OSS Distributions 	    "    icmp_seq=%hu\n"
133*d4514f0bSApple OSS Distributions 	    "    IP:\n"
134*d4514f0bSApple OSS Distributions 	    "      len=%hu\n"
135*d4514f0bSApple OSS Distributions 	    "      hl=%hu\n"
136*d4514f0bSApple OSS Distributions 	    "      cksum=%hu\n"
137*d4514f0bSApple OSS Distributions 	    "      TCP:\n"
138*d4514f0bSApple OSS Distributions 	    "        len=%hu\n"
139*d4514f0bSApple OSS Distributions 	    "        sport=%hu [%hu]\n"
140*d4514f0bSApple OSS Distributions 	    "        dport=%hu [%hu]\n"
141*d4514f0bSApple OSS Distributions 	    "        cksum=%hu\n",
142*d4514f0bSApple OSS Distributions 	    pcb->id,
143*d4514f0bSApple OSS Distributions 	    pcb->id,
144*d4514f0bSApple OSS Distributions 	    pcb->seq,
145*d4514f0bSApple OSS Distributions 	    pcb->err,
146*d4514f0bSApple OSS Distributions 	    pcb->syserr,
147*d4514f0bSApple OSS Distributions 	    pcb->txlen,
148*d4514f0bSApple OSS Distributions 	    pcb->icmp_hdr_len,
149*d4514f0bSApple OSS Distributions 	    (uint16_t)(pcb->icmp_hdr == NULL ? -1 : pcb->icmp_hdr->icmp_type),
150*d4514f0bSApple OSS Distributions 	    (uint16_t)(pcb->icmp_hdr == NULL ? -1 : pcb->icmp_hdr->icmp_code),
151*d4514f0bSApple OSS Distributions 	    (uint16_t)(pcb->icmp_hdr == NULL ? -1 : pcb->icmp_hdr->icmp_cksum),
152*d4514f0bSApple OSS Distributions 	    (uint16_t)(pcb->icmp_hdr == NULL ? -1 : pcb->icmp_hdr->icmp_id),
153*d4514f0bSApple OSS Distributions 	    (uint16_t)(pcb->icmp_hdr == NULL ? -1 : pcb->icmp_hdr->icmp_seq),
154*d4514f0bSApple OSS Distributions 	    pcb->inner_ip_hdr_len,
155*d4514f0bSApple OSS Distributions 	    (uint16_t)(pcb->inner_ip_hdr == NULL ? -1 : IP_VHL_HL(pcb->inner_ip_hdr->ip_vhl) << 2),
156*d4514f0bSApple OSS Distributions 	    (uint16_t)(pcb->inner_ip_hdr == NULL ? -1 : pcb->inner_ip_hdr->ip_sum),
157*d4514f0bSApple OSS Distributions 	    pcb->inner_tcp_hdr_len,
158*d4514f0bSApple OSS Distributions 	    (uint16_t)(pcb->inner_tcp_hdr == NULL ? -1 : pcb->inner_tcp_hdr->th_sport),
159*d4514f0bSApple OSS Distributions 	    (uint16_t)(pcb->inner_tcp_hdr == NULL ? -1 : ntohs(pcb->inner_tcp_hdr->th_sport)),
160*d4514f0bSApple OSS Distributions 	    (uint16_t)(pcb->inner_tcp_hdr == NULL ? -1 : pcb->inner_tcp_hdr->th_dport),
161*d4514f0bSApple OSS Distributions 	    (uint16_t)(pcb->inner_tcp_hdr == NULL ? -1 : ntohs(pcb->inner_tcp_hdr->th_dport)),
162*d4514f0bSApple OSS Distributions 	    (uint16_t)(pcb->inner_tcp_hdr == NULL ? -1 : pcb->inner_tcp_hdr->th_sum));
163*d4514f0bSApple OSS Distributions }
164*d4514f0bSApple OSS Distributions 
165*d4514f0bSApple OSS Distributions static void
icmp4_pcb_init(icmp4_pcb_t pcb)166*d4514f0bSApple OSS Distributions icmp4_pcb_init(icmp4_pcb_t pcb)
167*d4514f0bSApple OSS Distributions {
168*d4514f0bSApple OSS Distributions 	memset(pcb, 0, sizeof(struct icmp4_pcb));
169*d4514f0bSApple OSS Distributions }
170*d4514f0bSApple OSS Distributions 
171*d4514f0bSApple OSS Distributions static void
icmp4_pcb_close(icmp4_pcb_t pcb)172*d4514f0bSApple OSS Distributions icmp4_pcb_close(icmp4_pcb_t pcb)
173*d4514f0bSApple OSS Distributions {
174*d4514f0bSApple OSS Distributions 	if (pcb->fd != -1) {
175*d4514f0bSApple OSS Distributions 		close(pcb->fd);
176*d4514f0bSApple OSS Distributions 		pcb->fd = -1;
177*d4514f0bSApple OSS Distributions 	}
178*d4514f0bSApple OSS Distributions }
179*d4514f0bSApple OSS Distributions 
180*d4514f0bSApple OSS Distributions static int
icmp4_pcb_open(icmp4_pcb_t pcb,struct in_addr * local,struct in_addr * remote)181*d4514f0bSApple OSS Distributions icmp4_pcb_open(icmp4_pcb_t pcb, struct in_addr *local, struct in_addr *remote)
182*d4514f0bSApple OSS Distributions {
183*d4514f0bSApple OSS Distributions 	pcb->fd = socket(AF_INET, SOCK_RAW, IPPROTO_ICMP);
184*d4514f0bSApple OSS Distributions 	if (pcb->fd == -1) {
185*d4514f0bSApple OSS Distributions 		pcb->syserr = errno;
186*d4514f0bSApple OSS Distributions 		pcb->err = -1;
187*d4514f0bSApple OSS Distributions 		goto out;
188*d4514f0bSApple OSS Distributions 	}
189*d4514f0bSApple OSS Distributions 	int on = 1;
190*d4514f0bSApple OSS Distributions 	if (setsockopt(pcb->fd, SOL_SOCKET, SO_NOSIGPIPE, &on, sizeof(on)) == -1) {
191*d4514f0bSApple OSS Distributions 		pcb->syserr = errno;
192*d4514f0bSApple OSS Distributions 		close(pcb->fd);
193*d4514f0bSApple OSS Distributions 		pcb->err = -2;
194*d4514f0bSApple OSS Distributions 		goto out;
195*d4514f0bSApple OSS Distributions 	}
196*d4514f0bSApple OSS Distributions 
197*d4514f0bSApple OSS Distributions 	struct sockaddr_in sin;
198*d4514f0bSApple OSS Distributions 	memset(&sin, 0, sizeof(struct sockaddr_in));
199*d4514f0bSApple OSS Distributions 	sin.sin_len = sizeof(struct sockaddr_in);
200*d4514f0bSApple OSS Distributions 	sin.sin_family = AF_INET;
201*d4514f0bSApple OSS Distributions 	memcpy(&sin.sin_addr, local, sizeof(struct in_addr));
202*d4514f0bSApple OSS Distributions 
203*d4514f0bSApple OSS Distributions 	if (bind(pcb->fd, (struct sockaddr*)&sin, sin.sin_len) == -1) {
204*d4514f0bSApple OSS Distributions 		pcb->syserr = errno;
205*d4514f0bSApple OSS Distributions 		pcb->err = -3;
206*d4514f0bSApple OSS Distributions 		goto out;
207*d4514f0bSApple OSS Distributions 	}
208*d4514f0bSApple OSS Distributions 	memcpy(&(pcb->in4addr_local), local, sizeof(struct in_addr));
209*d4514f0bSApple OSS Distributions 
210*d4514f0bSApple OSS Distributions 	memcpy(&sin.sin_addr, remote, sizeof(struct in_addr));
211*d4514f0bSApple OSS Distributions 	if (connect(pcb->fd, (struct sockaddr*)&sin, sin.sin_len) == -1) {
212*d4514f0bSApple OSS Distributions 		pcb->syserr = errno;
213*d4514f0bSApple OSS Distributions 		pcb->err = -4;
214*d4514f0bSApple OSS Distributions 		goto out;
215*d4514f0bSApple OSS Distributions 	}
216*d4514f0bSApple OSS Distributions 	memcpy(&(pcb->in4addr_remote), remote, sizeof(struct in_addr));
217*d4514f0bSApple OSS Distributions 
218*d4514f0bSApple OSS Distributions out:
219*d4514f0bSApple OSS Distributions 	if (pcb->err != 0) {
220*d4514f0bSApple OSS Distributions 		icmp4_pcb_close(pcb);
221*d4514f0bSApple OSS Distributions 	}
222*d4514f0bSApple OSS Distributions 	return pcb->err;
223*d4514f0bSApple OSS Distributions }
224*d4514f0bSApple OSS Distributions 
225*d4514f0bSApple OSS Distributions static size_t
icmp4_pcb_get_payload_len(icmp4_pcb_t pcb)226*d4514f0bSApple OSS Distributions icmp4_pcb_get_payload_len(icmp4_pcb_t pcb)
227*d4514f0bSApple OSS Distributions {
228*d4514f0bSApple OSS Distributions 	return pcb->icmp_hdr_len + pcb->inner_ip_hdr_len + pcb->inner_ip_hdr_len;
229*d4514f0bSApple OSS Distributions }
230*d4514f0bSApple OSS Distributions 
231*d4514f0bSApple OSS Distributions static size_t
icmp4_pcb_set_payload(icmp4_pcb_t pcb,struct icmp * icmp_in,struct ip * ip_in,struct tcphdr * tcp_in)232*d4514f0bSApple OSS Distributions icmp4_pcb_set_payload(icmp4_pcb_t pcb, struct icmp *icmp_in, struct ip *ip_in, struct tcphdr *tcp_in)
233*d4514f0bSApple OSS Distributions {
234*d4514f0bSApple OSS Distributions 	uint8_t *ptr = (uint8_t*)pcb->buf;
235*d4514f0bSApple OSS Distributions 	pcb->icmp_hdr_len      = ICMP_MINLEN;
236*d4514f0bSApple OSS Distributions 	pcb->inner_ip_hdr_len  = (uint16_t)(IP_VHL_HL(ip_in->ip_vhl) << 2);
237*d4514f0bSApple OSS Distributions 	pcb->inner_tcp_hdr_len = sizeof(struct tcphdr);
238*d4514f0bSApple OSS Distributions 
239*d4514f0bSApple OSS Distributions 	pcb->inner_tcp_hdr           = (struct tcphdr*)(ptr + pcb->icmp_hdr_len + pcb->inner_ip_hdr_len);
240*d4514f0bSApple OSS Distributions 	pcb->inner_tcp_hdr->th_sport = htons(tcp_in->th_sport);
241*d4514f0bSApple OSS Distributions 	pcb->inner_tcp_hdr->th_dport = htons(tcp_in->th_dport);
242*d4514f0bSApple OSS Distributions 	pcb->inner_tcp_hdr->th_seq   = htonl(tcp_in->th_seq);
243*d4514f0bSApple OSS Distributions 	pcb->inner_tcp_hdr->th_ack   = htonl(tcp_in->th_ack);
244*d4514f0bSApple OSS Distributions 	pcb->inner_tcp_hdr->th_flags = tcp_in->th_flags;
245*d4514f0bSApple OSS Distributions 	pcb->inner_tcp_hdr->th_sum   = 0;
246*d4514f0bSApple OSS Distributions 	pcb->inner_tcp_hdr->th_sum   = checksum_buffer((uint16_t*)pcb->inner_tcp_hdr, pcb->inner_tcp_hdr_len);
247*d4514f0bSApple OSS Distributions 
248*d4514f0bSApple OSS Distributions 	pcb->inner_ip_hdr            = (struct ip*)(ptr + pcb->icmp_hdr_len);
249*d4514f0bSApple OSS Distributions 	pcb->inner_ip_hdr->ip_vhl    = ip_in->ip_vhl;
250*d4514f0bSApple OSS Distributions 	pcb->inner_ip_hdr->ip_tos    = ip_in->ip_tos;
251*d4514f0bSApple OSS Distributions 	pcb->inner_ip_hdr->ip_len    = pcb->inner_tcp_hdr_len + pcb->inner_ip_hdr_len;
252*d4514f0bSApple OSS Distributions 	pcb->inner_ip_hdr->ip_id     = 1;
253*d4514f0bSApple OSS Distributions 	pcb->inner_ip_hdr->ip_off    = 0;
254*d4514f0bSApple OSS Distributions 	pcb->inner_ip_hdr->ip_ttl    = 64;
255*d4514f0bSApple OSS Distributions 	pcb->inner_ip_hdr->ip_p      = IPPROTO_TCP;
256*d4514f0bSApple OSS Distributions 	pcb->inner_ip_hdr->ip_sum    = 0;
257*d4514f0bSApple OSS Distributions 	memcpy(&(pcb->inner_ip_hdr->ip_src), &(pcb->in4addr_local), sizeof(struct in_addr));
258*d4514f0bSApple OSS Distributions 	memcpy(&(pcb->inner_ip_hdr->ip_dst), &(pcb->in4addr_remote), sizeof(struct in_addr));
259*d4514f0bSApple OSS Distributions 	pcb->inner_ip_hdr->ip_sum    = checksum_buffer((uint16_t*)pcb->inner_ip_hdr, pcb->inner_ip_hdr_len);
260*d4514f0bSApple OSS Distributions 
261*d4514f0bSApple OSS Distributions 	pcb->icmp_hdr = (struct icmp*)pcb->buf;
262*d4514f0bSApple OSS Distributions 
263*d4514f0bSApple OSS Distributions 	pcb->icmp_hdr->icmp_type = icmp_in->icmp_type;
264*d4514f0bSApple OSS Distributions 	pcb->icmp_hdr->icmp_code = icmp_in->icmp_code;
265*d4514f0bSApple OSS Distributions 	pcb->icmp_hdr->icmp_cksum = 0;
266*d4514f0bSApple OSS Distributions 	pcb->icmp_hdr->icmp_id = htons(pcb->id++);
267*d4514f0bSApple OSS Distributions 	pcb->icmp_hdr->icmp_seq = htons(pcb->seq++);
268*d4514f0bSApple OSS Distributions 	pcb->icmp_hdr->icmp_cksum = checksum_buffer((uint16_t*)pcb->icmp_hdr, sizeof(struct icmp));
269*d4514f0bSApple OSS Distributions 
270*d4514f0bSApple OSS Distributions 	return icmp4_pcb_get_payload_len(pcb);
271*d4514f0bSApple OSS Distributions }
272*d4514f0bSApple OSS Distributions 
273*d4514f0bSApple OSS Distributions static int
icmp4_pcb_send_unreach(icmp4_pcb_t pcb,size_t maxlen)274*d4514f0bSApple OSS Distributions icmp4_pcb_send_unreach(icmp4_pcb_t pcb, size_t maxlen)
275*d4514f0bSApple OSS Distributions {
276*d4514f0bSApple OSS Distributions 	size_t out_len = icmp4_pcb_get_payload_len(pcb);
277*d4514f0bSApple OSS Distributions 	if (maxlen < out_len) {
278*d4514f0bSApple OSS Distributions 		out_len = maxlen;
279*d4514f0bSApple OSS Distributions 	}
280*d4514f0bSApple OSS Distributions 
281*d4514f0bSApple OSS Distributions 	fprintf(stderr, "Going to send %lu bytes of ICMP packet\n", out_len);
282*d4514f0bSApple OSS Distributions 	ssize_t len = send(pcb->fd, pcb->buf, out_len, 0);
283*d4514f0bSApple OSS Distributions 
284*d4514f0bSApple OSS Distributions 	if (len < 0 || (size_t)len != out_len) {
285*d4514f0bSApple OSS Distributions 		pcb->err = -6;
286*d4514f0bSApple OSS Distributions 		pcb->syserr = errno;
287*d4514f0bSApple OSS Distributions 	} else {
288*d4514f0bSApple OSS Distributions 		pcb->err = 0;
289*d4514f0bSApple OSS Distributions 	}
290*d4514f0bSApple OSS Distributions 	return pcb->err;
291*d4514f0bSApple OSS Distributions }
292*d4514f0bSApple OSS Distributions 
293*d4514f0bSApple OSS Distributions static void
icmp4_pcb_assert_payload_correct(icmp4_pcb_t pcb,size_t maxlen)294*d4514f0bSApple OSS Distributions icmp4_pcb_assert_payload_correct(icmp4_pcb_t pcb, size_t maxlen)
295*d4514f0bSApple OSS Distributions {
296*d4514f0bSApple OSS Distributions 	if (pcb == NULL) {
297*d4514f0bSApple OSS Distributions 		return;
298*d4514f0bSApple OSS Distributions 	}
299*d4514f0bSApple OSS Distributions 
300*d4514f0bSApple OSS Distributions 	T_ASSERT_NE(pcb->inner_ip_hdr, NULL, "IP hdr not set");
301*d4514f0bSApple OSS Distributions 
302*d4514f0bSApple OSS Distributions 	int icmplen = icmp4_pcb_get_payload_len(pcb);
303*d4514f0bSApple OSS Distributions 	T_ASSERT_LE(ICMP_MINLEN, icmplen, "ICMP payload smaller than minimal ICMP len");
304*d4514f0bSApple OSS Distributions 
305*d4514f0bSApple OSS Distributions 	T_ASSERT_GE(icmplen, ICMP_ADVLENMIN, "ICMP payload smaller than minimal advertised ICMP len");
306*d4514f0bSApple OSS Distributions 
307*d4514f0bSApple OSS Distributions 	// validate icmplen < ICMP_ADVLEN(icp) (ip_icmp.c:567)
308*d4514f0bSApple OSS Distributions 	int inner_ip_hdr_len = (IP_VHL_HL(pcb->inner_ip_hdr->ip_vhl) << 2);
309*d4514f0bSApple OSS Distributions 	int icmp_advlen = 8 + inner_ip_hdr_len + 8;
310*d4514f0bSApple OSS Distributions 	T_ASSERT_GE(icmplen, icmp_advlen, "ICMP payload smaller than advertised ICMP len");
311*d4514f0bSApple OSS Distributions 
312*d4514f0bSApple OSS Distributions 	// validate inner IP header length (ip_icmp.c:568)
313*d4514f0bSApple OSS Distributions 	T_ASSERT_GE(inner_ip_hdr_len, sizeof(struct ip), "IP payload smaller than IP header length");
314*d4514f0bSApple OSS Distributions 
315*d4514f0bSApple OSS Distributions 	// validate that the TCP header is outside of maxlen
316*d4514f0bSApple OSS Distributions 	size_t tcp_hdr_offset = (size_t)((uint8_t*)(pcb->inner_tcp_hdr) - (uint8_t*)(pcb->icmp_hdr));
317*d4514f0bSApple OSS Distributions 	fprintf(stdout, "tcp_hdr_offset: %lu, maxlen: %lu\n", tcp_hdr_offset, maxlen);
318*d4514f0bSApple OSS Distributions 	T_ASSERT_LE(maxlen, tcp_hdr_offset, "TCP header within maxlen");
319*d4514f0bSApple OSS Distributions }
320*d4514f0bSApple OSS Distributions 
321*d4514f0bSApple OSS Distributions T_DECL(icmp_send_malformed_packet_1, "ICMP packet with malformed TCP header")
322*d4514f0bSApple OSS Distributions {
323*d4514f0bSApple OSS Distributions 	struct sockaddr_in sin = {};
324*d4514f0bSApple OSS Distributions 
325*d4514f0bSApple OSS Distributions 	init_sin_address(&sin);
326*d4514f0bSApple OSS Distributions 	T_ASSERT_EQ(inet_pton(AF_INET, "127.0.0.1", &sin.sin_addr), 1, NULL);
327*d4514f0bSApple OSS Distributions 
328*d4514f0bSApple OSS Distributions 	icmp4_pcb pcb;
329*d4514f0bSApple OSS Distributions 	icmp4_pcb_init(&pcb);
330*d4514f0bSApple OSS Distributions 
331*d4514f0bSApple OSS Distributions 	T_ASSERT_EQ(icmp4_pcb_open(&pcb, &sin.sin_addr, &sin.sin_addr), 0, NULL);
332*d4514f0bSApple OSS Distributions 
333*d4514f0bSApple OSS Distributions 	struct icmp icmp_payload = {
334*d4514f0bSApple OSS Distributions 		.icmp_type = ICMP_UNREACH,
335*d4514f0bSApple OSS Distributions 		.icmp_code = ICMP_UNREACH_HOST,
336*d4514f0bSApple OSS Distributions 	};
337*d4514f0bSApple OSS Distributions 	struct ip ip_payload = {
338*d4514f0bSApple OSS Distributions 		.ip_vhl = 0x45,
339*d4514f0bSApple OSS Distributions 		.ip_tos = 0,
340*d4514f0bSApple OSS Distributions 		.ip_len = sizeof(struct ip) + sizeof(struct tcphdr),
341*d4514f0bSApple OSS Distributions 		.ip_id  = 1,
342*d4514f0bSApple OSS Distributions 		.ip_off = 0,
343*d4514f0bSApple OSS Distributions 		.ip_ttl = 64,
344*d4514f0bSApple OSS Distributions 	};
345*d4514f0bSApple OSS Distributions 	struct tcphdr tcp_payload = {
346*d4514f0bSApple OSS Distributions 		.th_sport = 1234,
347*d4514f0bSApple OSS Distributions 		.th_dport = 80,
348*d4514f0bSApple OSS Distributions 		.th_seq = 1024,
349*d4514f0bSApple OSS Distributions 		.th_ack = 4096,
350*d4514f0bSApple OSS Distributions 		.th_flags = TH_FLAGS,
351*d4514f0bSApple OSS Distributions 	};
352*d4514f0bSApple OSS Distributions 
353*d4514f0bSApple OSS Distributions 	T_ASSERT_GT(icmp4_pcb_set_payload(&pcb, &icmp_payload, &ip_payload, &tcp_payload), 0L, NULL);
354*d4514f0bSApple OSS Distributions 
355*d4514f0bSApple OSS Distributions 	icmp4_pcb_print(&pcb);
356*d4514f0bSApple OSS Distributions 
357*d4514f0bSApple OSS Distributions 	size_t sendlen = 28;
358*d4514f0bSApple OSS Distributions 	icmp4_pcb_assert_payload_correct(&pcb, sendlen);
359*d4514f0bSApple OSS Distributions 
360*d4514f0bSApple OSS Distributions 	T_ASSERT_EQ(icmp4_pcb_send_unreach(&pcb, sendlen), 0, NULL);
361*d4514f0bSApple OSS Distributions 
362*d4514f0bSApple OSS Distributions 	icmp4_pcb_close(&pcb);
363*d4514f0bSApple OSS Distributions }
364