1*19c3b8c2SApple OSS Distributions /*
2*19c3b8c2SApple OSS Distributions * Copyright (c) 2021 Apple Inc. All rights reserved.
3*19c3b8c2SApple OSS Distributions *
4*19c3b8c2SApple OSS Distributions * @APPLE_OSREFERENCE_LICENSE_HEADER_START@
5*19c3b8c2SApple OSS Distributions *
6*19c3b8c2SApple OSS Distributions * This file contains Original Code and/or Modifications of Original Code
7*19c3b8c2SApple OSS Distributions * as defined in and that are subject to the Apple Public Source License
8*19c3b8c2SApple OSS Distributions * Version 2.0 (the 'License'). You may not use this file except in
9*19c3b8c2SApple OSS Distributions * compliance with the License. The rights granted to you under the License
10*19c3b8c2SApple OSS Distributions * may not be used to create, or enable the creation or redistribution of,
11*19c3b8c2SApple OSS Distributions * unlawful or unlicensed copies of an Apple operating system, or to
12*19c3b8c2SApple OSS Distributions * circumvent, violate, or enable the circumvention or violation of, any
13*19c3b8c2SApple OSS Distributions * terms of an Apple operating system software license agreement.
14*19c3b8c2SApple OSS Distributions *
15*19c3b8c2SApple OSS Distributions * Please obtain a copy of the License at
16*19c3b8c2SApple OSS Distributions * http://www.opensource.apple.com/apsl/ and read it before using this file.
17*19c3b8c2SApple OSS Distributions *
18*19c3b8c2SApple OSS Distributions * The Original Code and all software distributed under the License are
19*19c3b8c2SApple OSS Distributions * distributed on an 'AS IS' basis, WITHOUT WARRANTY OF ANY KIND, EITHER
20*19c3b8c2SApple OSS Distributions * EXPRESS OR IMPLIED, AND APPLE HEREBY DISCLAIMS ALL SUCH WARRANTIES,
21*19c3b8c2SApple OSS Distributions * INCLUDING WITHOUT LIMITATION, ANY WARRANTIES OF MERCHANTABILITY,
22*19c3b8c2SApple OSS Distributions * FITNESS FOR A PARTICULAR PURPOSE, QUIET ENJOYMENT OR NON-INFRINGEMENT.
23*19c3b8c2SApple OSS Distributions * Please see the License for the specific language governing rights and
24*19c3b8c2SApple OSS Distributions * limitations under the License.
25*19c3b8c2SApple OSS Distributions *
26*19c3b8c2SApple OSS Distributions * @APPLE_OSREFERENCE_LICENSE_HEADER_END@
27*19c3b8c2SApple OSS Distributions */
28*19c3b8c2SApple OSS Distributions
29*19c3b8c2SApple OSS Distributions #define _IP_VHL 1
30*19c3b8c2SApple OSS Distributions
31*19c3b8c2SApple OSS Distributions #include <sys/fcntl.h>
32*19c3b8c2SApple OSS Distributions #include <sys/socket.h>
33*19c3b8c2SApple OSS Distributions #include <net/if.h>
34*19c3b8c2SApple OSS Distributions #include <netinet/in.h>
35*19c3b8c2SApple OSS Distributions #include <netinet/tcp.h>
36*19c3b8c2SApple OSS Distributions #include <netinet/ip_icmp.h>
37*19c3b8c2SApple OSS Distributions #include <arpa/inet.h>
38*19c3b8c2SApple OSS Distributions
39*19c3b8c2SApple OSS Distributions #include <darwintest.h>
40*19c3b8c2SApple OSS Distributions #include <string.h>
41*19c3b8c2SApple OSS Distributions #include <unistd.h>
42*19c3b8c2SApple OSS Distributions
43*19c3b8c2SApple OSS Distributions /*
44*19c3b8c2SApple OSS Distributions * This test helps to reproduce a buffer overflow in the control plane:
45*19c3b8c2SApple OSS Distributions * rdar://84355745
46*19c3b8c2SApple OSS Distributions *
47*19c3b8c2SApple OSS Distributions * The test allows to create a custom ICMP reply, and to send only a portion of it.
48*19c3b8c2SApple OSS Distributions *
49*19c3b8c2SApple OSS Distributions * To reproduce rdar://84355745, the test creates an ICMP "host unreachable" packet
50*19c3b8c2SApple OSS Distributions * that contains a TCP header, and sends the first 28 bytes of the ICMP payload
51*19c3b8c2SApple OSS Distributions * (48 including the outer IP header).
52*19c3b8c2SApple OSS Distributions *
53*19c3b8c2SApple OSS Distributions * +-----+-----+-----+-----+
54*19c3b8c2SApple OSS Distributions * | IP | ICMP| IP | TCP |
55*19c3b8c2SApple OSS Distributions * +-----+-----+-----+-----+
56*19c3b8c2SApple OSS Distributions *
57*19c3b8c2SApple OSS Distributions * <---------------->
58*19c3b8c2SApple OSS Distributions * sent payload
59*19c3b8c2SApple OSS Distributions *
60*19c3b8c2SApple OSS Distributions * This allows us to ensure that the parsing of the (potentially truncated) TCP
61*19c3b8c2SApple OSS Distributions * headers is done in a secure way.
62*19c3b8c2SApple OSS Distributions */
63*19c3b8c2SApple OSS Distributions static void
init_sin_address(struct sockaddr_in * sin)64*19c3b8c2SApple OSS Distributions init_sin_address(struct sockaddr_in *sin)
65*19c3b8c2SApple OSS Distributions {
66*19c3b8c2SApple OSS Distributions memset(sin, 0, sizeof(struct sockaddr_in));
67*19c3b8c2SApple OSS Distributions sin->sin_len = sizeof(struct sockaddr_in);
68*19c3b8c2SApple OSS Distributions sin->sin_family = AF_INET;
69*19c3b8c2SApple OSS Distributions }
70*19c3b8c2SApple OSS Distributions
71*19c3b8c2SApple OSS Distributions static uint16_t
checksum_buffer(uint16_t * buf,size_t len)72*19c3b8c2SApple OSS Distributions checksum_buffer(uint16_t *buf, size_t len)
73*19c3b8c2SApple OSS Distributions {
74*19c3b8c2SApple OSS Distributions unsigned long sum = 0;
75*19c3b8c2SApple OSS Distributions while (len > 1) {
76*19c3b8c2SApple OSS Distributions sum += *buf++;
77*19c3b8c2SApple OSS Distributions len -= 2;
78*19c3b8c2SApple OSS Distributions if (sum & 0x80000000) {
79*19c3b8c2SApple OSS Distributions sum = (sum >> 16) + (sum & 0xFFF);
80*19c3b8c2SApple OSS Distributions }
81*19c3b8c2SApple OSS Distributions }
82*19c3b8c2SApple OSS Distributions if (len == 1) {
83*19c3b8c2SApple OSS Distributions sum += ((unsigned long)(*(uint8_t*)buf) << 8);
84*19c3b8c2SApple OSS Distributions }
85*19c3b8c2SApple OSS Distributions while (sum >> 16) {
86*19c3b8c2SApple OSS Distributions sum = (sum >> 16) + (sum & 0xFFFF);
87*19c3b8c2SApple OSS Distributions }
88*19c3b8c2SApple OSS Distributions
89*19c3b8c2SApple OSS Distributions return (uint16_t)~sum;
90*19c3b8c2SApple OSS Distributions }
91*19c3b8c2SApple OSS Distributions
92*19c3b8c2SApple OSS Distributions #define MAXICMPBUFLEN 128
93*19c3b8c2SApple OSS Distributions typedef struct icmp4_pcb {
94*19c3b8c2SApple OSS Distributions int fd;
95*19c3b8c2SApple OSS Distributions int id;
96*19c3b8c2SApple OSS Distributions int seq;
97*19c3b8c2SApple OSS Distributions int err;
98*19c3b8c2SApple OSS Distributions int syserr;
99*19c3b8c2SApple OSS Distributions size_t txlen;
100*19c3b8c2SApple OSS Distributions uint16_t icmp_hdr_len;
101*19c3b8c2SApple OSS Distributions struct icmp *icmp_hdr;
102*19c3b8c2SApple OSS Distributions uint16_t inner_ip_hdr_len;
103*19c3b8c2SApple OSS Distributions struct ip *inner_ip_hdr;
104*19c3b8c2SApple OSS Distributions uint16_t inner_tcp_hdr_len;
105*19c3b8c2SApple OSS Distributions struct tcphdr *inner_tcp_hdr;
106*19c3b8c2SApple OSS Distributions struct in_addr in4addr_local;
107*19c3b8c2SApple OSS Distributions struct in_addr in4addr_remote;
108*19c3b8c2SApple OSS Distributions uint64_t buf[MAXICMPBUFLEN / 8];
109*19c3b8c2SApple OSS Distributions } icmp4_pcb, *icmp4_pcb_t;
110*19c3b8c2SApple OSS Distributions
111*19c3b8c2SApple OSS Distributions static void
icmp4_pcb_print(icmp4_pcb_t pcb)112*19c3b8c2SApple OSS Distributions icmp4_pcb_print(icmp4_pcb_t pcb)
113*19c3b8c2SApple OSS Distributions {
114*19c3b8c2SApple OSS Distributions if (pcb == NULL) {
115*19c3b8c2SApple OSS Distributions fprintf(stdout, "icmp pcb: null");
116*19c3b8c2SApple OSS Distributions return;
117*19c3b8c2SApple OSS Distributions }
118*19c3b8c2SApple OSS Distributions
119*19c3b8c2SApple OSS Distributions fprintf(stdout, "icmp pcb: \n"
120*19c3b8c2SApple OSS Distributions " fd=%d\n"
121*19c3b8c2SApple OSS Distributions " id=%d\n"
122*19c3b8c2SApple OSS Distributions " seq=%d\n"
123*19c3b8c2SApple OSS Distributions " err=%d\n"
124*19c3b8c2SApple OSS Distributions " syserr=%d\n"
125*19c3b8c2SApple OSS Distributions " txlen=%lu\n"
126*19c3b8c2SApple OSS Distributions " ICMP:\n"
127*19c3b8c2SApple OSS Distributions " len=%hu\n"
128*19c3b8c2SApple OSS Distributions " type=%d\n"
129*19c3b8c2SApple OSS Distributions " code=%d\n"
130*19c3b8c2SApple OSS Distributions " cksum=%hu\n"
131*19c3b8c2SApple OSS Distributions " icmp_id=%hu\n"
132*19c3b8c2SApple OSS Distributions " icmp_seq=%hu\n"
133*19c3b8c2SApple OSS Distributions " IP:\n"
134*19c3b8c2SApple OSS Distributions " len=%hu\n"
135*19c3b8c2SApple OSS Distributions " hl=%hu\n"
136*19c3b8c2SApple OSS Distributions " cksum=%hu\n"
137*19c3b8c2SApple OSS Distributions " TCP:\n"
138*19c3b8c2SApple OSS Distributions " len=%hu\n"
139*19c3b8c2SApple OSS Distributions " sport=%hu [%hu]\n"
140*19c3b8c2SApple OSS Distributions " dport=%hu [%hu]\n"
141*19c3b8c2SApple OSS Distributions " cksum=%hu\n",
142*19c3b8c2SApple OSS Distributions pcb->id,
143*19c3b8c2SApple OSS Distributions pcb->id,
144*19c3b8c2SApple OSS Distributions pcb->seq,
145*19c3b8c2SApple OSS Distributions pcb->err,
146*19c3b8c2SApple OSS Distributions pcb->syserr,
147*19c3b8c2SApple OSS Distributions pcb->txlen,
148*19c3b8c2SApple OSS Distributions pcb->icmp_hdr_len,
149*19c3b8c2SApple OSS Distributions (uint16_t)(pcb->icmp_hdr == NULL ? -1 : pcb->icmp_hdr->icmp_type),
150*19c3b8c2SApple OSS Distributions (uint16_t)(pcb->icmp_hdr == NULL ? -1 : pcb->icmp_hdr->icmp_code),
151*19c3b8c2SApple OSS Distributions (uint16_t)(pcb->icmp_hdr == NULL ? -1 : pcb->icmp_hdr->icmp_cksum),
152*19c3b8c2SApple OSS Distributions (uint16_t)(pcb->icmp_hdr == NULL ? -1 : pcb->icmp_hdr->icmp_id),
153*19c3b8c2SApple OSS Distributions (uint16_t)(pcb->icmp_hdr == NULL ? -1 : pcb->icmp_hdr->icmp_seq),
154*19c3b8c2SApple OSS Distributions pcb->inner_ip_hdr_len,
155*19c3b8c2SApple OSS Distributions (uint16_t)(pcb->inner_ip_hdr == NULL ? -1 : IP_VHL_HL(pcb->inner_ip_hdr->ip_vhl) << 2),
156*19c3b8c2SApple OSS Distributions (uint16_t)(pcb->inner_ip_hdr == NULL ? -1 : pcb->inner_ip_hdr->ip_sum),
157*19c3b8c2SApple OSS Distributions pcb->inner_tcp_hdr_len,
158*19c3b8c2SApple OSS Distributions (uint16_t)(pcb->inner_tcp_hdr == NULL ? -1 : pcb->inner_tcp_hdr->th_sport),
159*19c3b8c2SApple OSS Distributions (uint16_t)(pcb->inner_tcp_hdr == NULL ? -1 : ntohs(pcb->inner_tcp_hdr->th_sport)),
160*19c3b8c2SApple OSS Distributions (uint16_t)(pcb->inner_tcp_hdr == NULL ? -1 : pcb->inner_tcp_hdr->th_dport),
161*19c3b8c2SApple OSS Distributions (uint16_t)(pcb->inner_tcp_hdr == NULL ? -1 : ntohs(pcb->inner_tcp_hdr->th_dport)),
162*19c3b8c2SApple OSS Distributions (uint16_t)(pcb->inner_tcp_hdr == NULL ? -1 : pcb->inner_tcp_hdr->th_sum));
163*19c3b8c2SApple OSS Distributions }
164*19c3b8c2SApple OSS Distributions
165*19c3b8c2SApple OSS Distributions static void
icmp4_pcb_init(icmp4_pcb_t pcb)166*19c3b8c2SApple OSS Distributions icmp4_pcb_init(icmp4_pcb_t pcb)
167*19c3b8c2SApple OSS Distributions {
168*19c3b8c2SApple OSS Distributions memset(pcb, 0, sizeof(struct icmp4_pcb));
169*19c3b8c2SApple OSS Distributions }
170*19c3b8c2SApple OSS Distributions
171*19c3b8c2SApple OSS Distributions static void
icmp4_pcb_close(icmp4_pcb_t pcb)172*19c3b8c2SApple OSS Distributions icmp4_pcb_close(icmp4_pcb_t pcb)
173*19c3b8c2SApple OSS Distributions {
174*19c3b8c2SApple OSS Distributions if (pcb->fd != -1) {
175*19c3b8c2SApple OSS Distributions close(pcb->fd);
176*19c3b8c2SApple OSS Distributions pcb->fd = -1;
177*19c3b8c2SApple OSS Distributions }
178*19c3b8c2SApple OSS Distributions }
179*19c3b8c2SApple OSS Distributions
180*19c3b8c2SApple OSS Distributions static int
icmp4_pcb_open(icmp4_pcb_t pcb,struct in_addr * local,struct in_addr * remote)181*19c3b8c2SApple OSS Distributions icmp4_pcb_open(icmp4_pcb_t pcb, struct in_addr *local, struct in_addr *remote)
182*19c3b8c2SApple OSS Distributions {
183*19c3b8c2SApple OSS Distributions pcb->fd = socket(AF_INET, SOCK_RAW, IPPROTO_ICMP);
184*19c3b8c2SApple OSS Distributions if (pcb->fd == -1) {
185*19c3b8c2SApple OSS Distributions pcb->syserr = errno;
186*19c3b8c2SApple OSS Distributions pcb->err = -1;
187*19c3b8c2SApple OSS Distributions goto out;
188*19c3b8c2SApple OSS Distributions }
189*19c3b8c2SApple OSS Distributions int on = 1;
190*19c3b8c2SApple OSS Distributions if (setsockopt(pcb->fd, SOL_SOCKET, SO_NOSIGPIPE, &on, sizeof(on)) == -1) {
191*19c3b8c2SApple OSS Distributions pcb->syserr = errno;
192*19c3b8c2SApple OSS Distributions close(pcb->fd);
193*19c3b8c2SApple OSS Distributions pcb->err = -2;
194*19c3b8c2SApple OSS Distributions goto out;
195*19c3b8c2SApple OSS Distributions }
196*19c3b8c2SApple OSS Distributions
197*19c3b8c2SApple OSS Distributions struct sockaddr_in sin;
198*19c3b8c2SApple OSS Distributions memset(&sin, 0, sizeof(struct sockaddr_in));
199*19c3b8c2SApple OSS Distributions sin.sin_len = sizeof(struct sockaddr_in);
200*19c3b8c2SApple OSS Distributions sin.sin_family = AF_INET;
201*19c3b8c2SApple OSS Distributions memcpy(&sin.sin_addr, local, sizeof(struct in_addr));
202*19c3b8c2SApple OSS Distributions
203*19c3b8c2SApple OSS Distributions if (bind(pcb->fd, (struct sockaddr*)&sin, sin.sin_len) == -1) {
204*19c3b8c2SApple OSS Distributions pcb->syserr = errno;
205*19c3b8c2SApple OSS Distributions pcb->err = -3;
206*19c3b8c2SApple OSS Distributions goto out;
207*19c3b8c2SApple OSS Distributions }
208*19c3b8c2SApple OSS Distributions memcpy(&(pcb->in4addr_local), local, sizeof(struct in_addr));
209*19c3b8c2SApple OSS Distributions
210*19c3b8c2SApple OSS Distributions memcpy(&sin.sin_addr, remote, sizeof(struct in_addr));
211*19c3b8c2SApple OSS Distributions if (connect(pcb->fd, (struct sockaddr*)&sin, sin.sin_len) == -1) {
212*19c3b8c2SApple OSS Distributions pcb->syserr = errno;
213*19c3b8c2SApple OSS Distributions pcb->err = -4;
214*19c3b8c2SApple OSS Distributions goto out;
215*19c3b8c2SApple OSS Distributions }
216*19c3b8c2SApple OSS Distributions memcpy(&(pcb->in4addr_remote), remote, sizeof(struct in_addr));
217*19c3b8c2SApple OSS Distributions
218*19c3b8c2SApple OSS Distributions out:
219*19c3b8c2SApple OSS Distributions if (pcb->err != 0) {
220*19c3b8c2SApple OSS Distributions icmp4_pcb_close(pcb);
221*19c3b8c2SApple OSS Distributions }
222*19c3b8c2SApple OSS Distributions return pcb->err;
223*19c3b8c2SApple OSS Distributions }
224*19c3b8c2SApple OSS Distributions
225*19c3b8c2SApple OSS Distributions static size_t
icmp4_pcb_get_payload_len(icmp4_pcb_t pcb)226*19c3b8c2SApple OSS Distributions icmp4_pcb_get_payload_len(icmp4_pcb_t pcb)
227*19c3b8c2SApple OSS Distributions {
228*19c3b8c2SApple OSS Distributions return pcb->icmp_hdr_len + pcb->inner_ip_hdr_len + pcb->inner_ip_hdr_len;
229*19c3b8c2SApple OSS Distributions }
230*19c3b8c2SApple OSS Distributions
231*19c3b8c2SApple OSS Distributions static size_t
icmp4_pcb_set_payload(icmp4_pcb_t pcb,struct icmp * icmp_in,struct ip * ip_in,struct tcphdr * tcp_in)232*19c3b8c2SApple OSS Distributions icmp4_pcb_set_payload(icmp4_pcb_t pcb, struct icmp *icmp_in, struct ip *ip_in, struct tcphdr *tcp_in)
233*19c3b8c2SApple OSS Distributions {
234*19c3b8c2SApple OSS Distributions uint8_t *ptr = (uint8_t*)pcb->buf;
235*19c3b8c2SApple OSS Distributions pcb->icmp_hdr_len = ICMP_MINLEN;
236*19c3b8c2SApple OSS Distributions pcb->inner_ip_hdr_len = (uint16_t)(IP_VHL_HL(ip_in->ip_vhl) << 2);
237*19c3b8c2SApple OSS Distributions pcb->inner_tcp_hdr_len = sizeof(struct tcphdr);
238*19c3b8c2SApple OSS Distributions
239*19c3b8c2SApple OSS Distributions pcb->inner_tcp_hdr = (struct tcphdr*)(ptr + pcb->icmp_hdr_len + pcb->inner_ip_hdr_len);
240*19c3b8c2SApple OSS Distributions pcb->inner_tcp_hdr->th_sport = htons(tcp_in->th_sport);
241*19c3b8c2SApple OSS Distributions pcb->inner_tcp_hdr->th_dport = htons(tcp_in->th_dport);
242*19c3b8c2SApple OSS Distributions pcb->inner_tcp_hdr->th_seq = htonl(tcp_in->th_seq);
243*19c3b8c2SApple OSS Distributions pcb->inner_tcp_hdr->th_ack = htonl(tcp_in->th_ack);
244*19c3b8c2SApple OSS Distributions pcb->inner_tcp_hdr->th_flags = tcp_in->th_flags;
245*19c3b8c2SApple OSS Distributions pcb->inner_tcp_hdr->th_sum = 0;
246*19c3b8c2SApple OSS Distributions pcb->inner_tcp_hdr->th_sum = checksum_buffer((uint16_t*)pcb->inner_tcp_hdr, pcb->inner_tcp_hdr_len);
247*19c3b8c2SApple OSS Distributions
248*19c3b8c2SApple OSS Distributions pcb->inner_ip_hdr = (struct ip*)(ptr + pcb->icmp_hdr_len);
249*19c3b8c2SApple OSS Distributions pcb->inner_ip_hdr->ip_vhl = ip_in->ip_vhl;
250*19c3b8c2SApple OSS Distributions pcb->inner_ip_hdr->ip_tos = ip_in->ip_tos;
251*19c3b8c2SApple OSS Distributions pcb->inner_ip_hdr->ip_len = pcb->inner_tcp_hdr_len + pcb->inner_ip_hdr_len;
252*19c3b8c2SApple OSS Distributions pcb->inner_ip_hdr->ip_id = 1;
253*19c3b8c2SApple OSS Distributions pcb->inner_ip_hdr->ip_off = 0;
254*19c3b8c2SApple OSS Distributions pcb->inner_ip_hdr->ip_ttl = 64;
255*19c3b8c2SApple OSS Distributions pcb->inner_ip_hdr->ip_p = IPPROTO_TCP;
256*19c3b8c2SApple OSS Distributions pcb->inner_ip_hdr->ip_sum = 0;
257*19c3b8c2SApple OSS Distributions memcpy(&(pcb->inner_ip_hdr->ip_src), &(pcb->in4addr_local), sizeof(struct in_addr));
258*19c3b8c2SApple OSS Distributions memcpy(&(pcb->inner_ip_hdr->ip_dst), &(pcb->in4addr_remote), sizeof(struct in_addr));
259*19c3b8c2SApple OSS Distributions pcb->inner_ip_hdr->ip_sum = checksum_buffer((uint16_t*)pcb->inner_ip_hdr, pcb->inner_ip_hdr_len);
260*19c3b8c2SApple OSS Distributions
261*19c3b8c2SApple OSS Distributions pcb->icmp_hdr = (struct icmp*)pcb->buf;
262*19c3b8c2SApple OSS Distributions
263*19c3b8c2SApple OSS Distributions pcb->icmp_hdr->icmp_type = icmp_in->icmp_type;
264*19c3b8c2SApple OSS Distributions pcb->icmp_hdr->icmp_code = icmp_in->icmp_code;
265*19c3b8c2SApple OSS Distributions pcb->icmp_hdr->icmp_cksum = 0;
266*19c3b8c2SApple OSS Distributions pcb->icmp_hdr->icmp_id = htons(pcb->id++);
267*19c3b8c2SApple OSS Distributions pcb->icmp_hdr->icmp_seq = htons(pcb->seq++);
268*19c3b8c2SApple OSS Distributions pcb->icmp_hdr->icmp_cksum = checksum_buffer((uint16_t*)pcb->icmp_hdr, sizeof(struct icmp));
269*19c3b8c2SApple OSS Distributions
270*19c3b8c2SApple OSS Distributions return icmp4_pcb_get_payload_len(pcb);
271*19c3b8c2SApple OSS Distributions }
272*19c3b8c2SApple OSS Distributions
273*19c3b8c2SApple OSS Distributions static int
icmp4_pcb_send_unreach(icmp4_pcb_t pcb,size_t maxlen)274*19c3b8c2SApple OSS Distributions icmp4_pcb_send_unreach(icmp4_pcb_t pcb, size_t maxlen)
275*19c3b8c2SApple OSS Distributions {
276*19c3b8c2SApple OSS Distributions size_t out_len = icmp4_pcb_get_payload_len(pcb);
277*19c3b8c2SApple OSS Distributions if (maxlen < out_len) {
278*19c3b8c2SApple OSS Distributions out_len = maxlen;
279*19c3b8c2SApple OSS Distributions }
280*19c3b8c2SApple OSS Distributions
281*19c3b8c2SApple OSS Distributions fprintf(stderr, "Going to send %lu bytes of ICMP packet\n", out_len);
282*19c3b8c2SApple OSS Distributions ssize_t len = send(pcb->fd, pcb->buf, out_len, 0);
283*19c3b8c2SApple OSS Distributions
284*19c3b8c2SApple OSS Distributions if (len < 0 || (size_t)len != out_len) {
285*19c3b8c2SApple OSS Distributions pcb->err = -6;
286*19c3b8c2SApple OSS Distributions pcb->syserr = errno;
287*19c3b8c2SApple OSS Distributions } else {
288*19c3b8c2SApple OSS Distributions pcb->err = 0;
289*19c3b8c2SApple OSS Distributions }
290*19c3b8c2SApple OSS Distributions return pcb->err;
291*19c3b8c2SApple OSS Distributions }
292*19c3b8c2SApple OSS Distributions
293*19c3b8c2SApple OSS Distributions static void
icmp4_pcb_assert_payload_correct(icmp4_pcb_t pcb,size_t maxlen)294*19c3b8c2SApple OSS Distributions icmp4_pcb_assert_payload_correct(icmp4_pcb_t pcb, size_t maxlen)
295*19c3b8c2SApple OSS Distributions {
296*19c3b8c2SApple OSS Distributions if (pcb == NULL) {
297*19c3b8c2SApple OSS Distributions return;
298*19c3b8c2SApple OSS Distributions }
299*19c3b8c2SApple OSS Distributions
300*19c3b8c2SApple OSS Distributions T_ASSERT_NE(pcb->inner_ip_hdr, NULL, "IP hdr not set");
301*19c3b8c2SApple OSS Distributions
302*19c3b8c2SApple OSS Distributions int icmplen = icmp4_pcb_get_payload_len(pcb);
303*19c3b8c2SApple OSS Distributions T_ASSERT_LE(ICMP_MINLEN, icmplen, "ICMP payload smaller than minimal ICMP len");
304*19c3b8c2SApple OSS Distributions
305*19c3b8c2SApple OSS Distributions T_ASSERT_GE(icmplen, ICMP_ADVLENMIN, "ICMP payload smaller than minimal advertised ICMP len");
306*19c3b8c2SApple OSS Distributions
307*19c3b8c2SApple OSS Distributions // validate icmplen < ICMP_ADVLEN(icp) (ip_icmp.c:567)
308*19c3b8c2SApple OSS Distributions int inner_ip_hdr_len = (IP_VHL_HL(pcb->inner_ip_hdr->ip_vhl) << 2);
309*19c3b8c2SApple OSS Distributions int icmp_advlen = 8 + inner_ip_hdr_len + 8;
310*19c3b8c2SApple OSS Distributions T_ASSERT_GE(icmplen, icmp_advlen, "ICMP payload smaller than advertised ICMP len");
311*19c3b8c2SApple OSS Distributions
312*19c3b8c2SApple OSS Distributions // validate inner IP header length (ip_icmp.c:568)
313*19c3b8c2SApple OSS Distributions T_ASSERT_GE(inner_ip_hdr_len, sizeof(struct ip), "IP payload smaller than IP header length");
314*19c3b8c2SApple OSS Distributions
315*19c3b8c2SApple OSS Distributions // validate that the TCP header is outside of maxlen
316*19c3b8c2SApple OSS Distributions size_t tcp_hdr_offset = (size_t)((uint8_t*)(pcb->inner_tcp_hdr) - (uint8_t*)(pcb->icmp_hdr));
317*19c3b8c2SApple OSS Distributions fprintf(stdout, "tcp_hdr_offset: %lu, maxlen: %lu\n", tcp_hdr_offset, maxlen);
318*19c3b8c2SApple OSS Distributions T_ASSERT_LE(maxlen, tcp_hdr_offset, "TCP header within maxlen");
319*19c3b8c2SApple OSS Distributions }
320*19c3b8c2SApple OSS Distributions
321*19c3b8c2SApple OSS Distributions T_DECL(icmp_send_malformed_packet_1, "ICMP packet with malformed TCP header")
322*19c3b8c2SApple OSS Distributions {
323*19c3b8c2SApple OSS Distributions struct sockaddr_in sin = {};
324*19c3b8c2SApple OSS Distributions
325*19c3b8c2SApple OSS Distributions init_sin_address(&sin);
326*19c3b8c2SApple OSS Distributions T_ASSERT_EQ(inet_pton(AF_INET, "127.0.0.1", &sin.sin_addr), 1, NULL);
327*19c3b8c2SApple OSS Distributions
328*19c3b8c2SApple OSS Distributions icmp4_pcb pcb;
329*19c3b8c2SApple OSS Distributions icmp4_pcb_init(&pcb);
330*19c3b8c2SApple OSS Distributions
331*19c3b8c2SApple OSS Distributions T_ASSERT_EQ(icmp4_pcb_open(&pcb, &sin.sin_addr, &sin.sin_addr), 0, NULL);
332*19c3b8c2SApple OSS Distributions
333*19c3b8c2SApple OSS Distributions struct icmp icmp_payload = {
334*19c3b8c2SApple OSS Distributions .icmp_type = ICMP_UNREACH,
335*19c3b8c2SApple OSS Distributions .icmp_code = ICMP_UNREACH_HOST,
336*19c3b8c2SApple OSS Distributions };
337*19c3b8c2SApple OSS Distributions struct ip ip_payload = {
338*19c3b8c2SApple OSS Distributions .ip_vhl = 0x45,
339*19c3b8c2SApple OSS Distributions .ip_tos = 0,
340*19c3b8c2SApple OSS Distributions .ip_len = sizeof(struct ip) + sizeof(struct tcphdr),
341*19c3b8c2SApple OSS Distributions .ip_id = 1,
342*19c3b8c2SApple OSS Distributions .ip_off = 0,
343*19c3b8c2SApple OSS Distributions .ip_ttl = 64,
344*19c3b8c2SApple OSS Distributions };
345*19c3b8c2SApple OSS Distributions struct tcphdr tcp_payload = {
346*19c3b8c2SApple OSS Distributions .th_sport = 1234,
347*19c3b8c2SApple OSS Distributions .th_dport = 80,
348*19c3b8c2SApple OSS Distributions .th_seq = 1024,
349*19c3b8c2SApple OSS Distributions .th_ack = 4096,
350*19c3b8c2SApple OSS Distributions .th_flags = TH_FLAGS,
351*19c3b8c2SApple OSS Distributions };
352*19c3b8c2SApple OSS Distributions
353*19c3b8c2SApple OSS Distributions T_ASSERT_GT(icmp4_pcb_set_payload(&pcb, &icmp_payload, &ip_payload, &tcp_payload), 0L, NULL);
354*19c3b8c2SApple OSS Distributions
355*19c3b8c2SApple OSS Distributions icmp4_pcb_print(&pcb);
356*19c3b8c2SApple OSS Distributions
357*19c3b8c2SApple OSS Distributions size_t sendlen = 28;
358*19c3b8c2SApple OSS Distributions icmp4_pcb_assert_payload_correct(&pcb, sendlen);
359*19c3b8c2SApple OSS Distributions
360*19c3b8c2SApple OSS Distributions T_ASSERT_EQ(icmp4_pcb_send_unreach(&pcb, sendlen), 0, NULL);
361*19c3b8c2SApple OSS Distributions
362*19c3b8c2SApple OSS Distributions icmp4_pcb_close(&pcb);
363*19c3b8c2SApple OSS Distributions }
364