2 * Copyright (c) 2020 Yubico AB. All rights reserved.
3 * Use of this source code is governed by a BSD-style
4 * license that can be found in the LICENSE file.
9 #include <sys/socket.h>
11 #include <linux/nfc.h>
19 #include "fido/param.h"
23 #define TX_CHUNK_SIZE 240
25 static const uint8_t aid[] = { 0xa0, 0x00, 0x00, 0x06, 0x47, 0x2f, 0x00, 0x01 };
26 static const uint8_t v_u2f[] = { 'U', '2', 'F', '_', 'V', '2' };
27 static const uint8_t v_fido[] = { 'F', 'I', 'D', 'O', '_', '2', '_', '0' };
34 const sigset_t *sigmaskp;
39 tx_short_apdu(fido_dev_t *d, const iso7816_header_t *h, const uint8_t *payload,
40 uint8_t payload_len, uint8_t cla_flags)
42 uint8_t apdu[5 + UINT8_MAX + 1];
47 memset(&apdu, 0, sizeof(apdu));
48 apdu[0] = h->cla | cla_flags;
52 apdu[4] = payload_len;
53 memcpy(&apdu[5], payload, payload_len);
54 apdu_len = (size_t)(5 + payload_len + 1);
56 if (d->io.write(d->io_handle, apdu, apdu_len) < 0) {
57 fido_log_debug("%s: write", __func__);
61 if (cla_flags & 0x10) {
62 if (d->io.read(d->io_handle, sw, sizeof(sw), -1) != 2) {
63 fido_log_debug("%s: read", __func__);
66 if ((sw[0] << 8 | sw[1]) != SW_NO_ERROR) {
67 fido_log_debug("%s: unexpected sw", __func__);
74 explicit_bzero(apdu, sizeof(apdu));
80 nfc_do_tx(fido_dev_t *d, const uint8_t *apdu_ptr, size_t apdu_len)
84 if (fido_buf_read(&apdu_ptr, &apdu_len, &h, sizeof(h)) < 0) {
85 fido_log_debug("%s: header", __func__);
89 fido_log_debug("%s: apdu_len %zu", __func__, apdu_len);
93 apdu_len -= 2; /* trim le1 le2 */
95 while (apdu_len > TX_CHUNK_SIZE) {
96 if (tx_short_apdu(d, &h, apdu_ptr, TX_CHUNK_SIZE, 0x10) < 0) {
97 fido_log_debug("%s: chain", __func__);
100 apdu_ptr += TX_CHUNK_SIZE;
101 apdu_len -= TX_CHUNK_SIZE;
104 if (tx_short_apdu(d, &h, apdu_ptr, (uint8_t)apdu_len, 0) < 0) {
105 fido_log_debug("%s: tx_short_apdu", __func__);
113 fido_nfc_tx(fido_dev_t *d, uint8_t cmd, const unsigned char *buf, size_t count)
115 iso7816_apdu_t *apdu = NULL;
121 case CTAP_CMD_INIT: /* select */
122 if ((apdu = iso7816_new(0, 0xa4, 0x04, sizeof(aid))) == NULL ||
123 iso7816_add(apdu, aid, sizeof(aid)) < 0) {
124 fido_log_debug("%s: iso7816", __func__);
128 case CTAP_CMD_CBOR: /* wrap cbor */
129 if (count > UINT16_MAX || (apdu = iso7816_new(0x80, 0x10, 0x80,
130 (uint16_t)count)) == NULL ||
131 iso7816_add(apdu, buf, count) < 0) {
132 fido_log_debug("%s: iso7816", __func__);
136 case CTAP_CMD_MSG: /* already an apdu */
139 fido_log_debug("%s: cmd=%02x", __func__, cmd);
144 ptr = iso7816_ptr(apdu);
145 len = iso7816_len(apdu);
151 if (nfc_do_tx(d, ptr, len) < 0) {
152 fido_log_debug("%s: nfc_do_tx", __func__);
164 rx_init(fido_dev_t *d, unsigned char *buf, size_t count, int ms)
166 fido_ctap_info_t *attr = (fido_ctap_info_t *)buf;
170 if (count != sizeof(*attr)) {
171 fido_log_debug("%s: count=%zu", __func__, count);
175 memset(attr, 0, sizeof(*attr));
177 if ((n = d->io.read(d->io_handle, f, sizeof(f), ms)) < 2 ||
178 (f[n - 2] << 8 | f[n - 1]) != SW_NO_ERROR) {
179 fido_log_debug("%s: read", __func__);
185 if (n == sizeof(v_u2f) && memcmp(f, v_u2f, sizeof(v_u2f)) == 0)
186 attr->flags = FIDO_CAP_CBOR;
187 else if (n == sizeof(v_fido) && memcmp(f, v_fido, sizeof(v_fido)) == 0)
188 attr->flags = FIDO_CAP_CBOR | FIDO_CAP_NMSG;
190 fido_log_debug("%s: unknown version string", __func__);
192 attr->flags = FIDO_CAP_CBOR | FIDO_CAP_NMSG;
198 memcpy(&attr->nonce, &d->nonce, sizeof(attr->nonce)); /* XXX */
204 tx_get_response(fido_dev_t *d, uint8_t count)
208 memset(apdu, 0, sizeof(apdu));
209 apdu[1] = 0xc0; /* GET_RESPONSE */
212 if (d->io.write(d->io_handle, apdu, sizeof(apdu)) < 0) {
213 fido_log_debug("%s: write", __func__);
221 rx_apdu(fido_dev_t *d, uint8_t sw[2], unsigned char **buf, size_t *count, int ms)
226 if ((n = d->io.read(d->io_handle, f, sizeof(f), ms)) < 2) {
227 fido_log_debug("%s: read", __func__);
231 if (fido_buf_write(buf, count, f, (size_t)(n - 2)) < 0) {
232 fido_log_debug("%s: fido_buf_write", __func__);
236 memcpy(sw, f + n - 2, 2);
240 explicit_bzero(f, sizeof(f));
246 rx_msg(fido_dev_t *d, unsigned char *buf, size_t count, int ms)
249 const size_t bufsiz = count;
251 if (rx_apdu(d, sw, &buf, &count, ms) < 0) {
252 fido_log_debug("%s: preamble", __func__);
256 while (sw[0] == SW1_MORE_DATA)
257 if (tx_get_response(d, sw[1]) < 0 ||
258 rx_apdu(d, sw, &buf, &count, ms) < 0) {
259 fido_log_debug("%s: chain", __func__);
263 if (fido_buf_write(&buf, &count, sw, sizeof(sw)) < 0) {
264 fido_log_debug("%s: sw", __func__);
268 if (bufsiz - count > INT_MAX) {
269 fido_log_debug("%s: bufsiz", __func__);
273 return ((int)(bufsiz - count));
277 rx_cbor(fido_dev_t *d, unsigned char *buf, size_t count, int ms)
281 if ((r = rx_msg(d, buf, count, ms)) < 2)
288 fido_nfc_rx(fido_dev_t *d, uint8_t cmd, unsigned char *buf, size_t count, int ms)
292 return (rx_init(d, buf, count, ms));
294 return (rx_cbor(d, buf, count, ms));
296 return (rx_msg(d, buf, count, ms));
298 fido_log_debug("%s: cmd=%02x", __func__, cmd);
304 get_parent_attr(struct udev_device *dev, const char *subsystem,
305 const char *devtype, const char *attr)
307 struct udev_device *parent;
310 if ((parent = udev_device_get_parent_with_subsystem_devtype(dev,
311 subsystem, devtype)) == NULL || (value =
312 udev_device_get_sysattr_value(parent, attr)) == NULL)
315 return (strdup(value));
319 get_usb_attr(struct udev_device *dev, const char *attr)
321 return (get_parent_attr(dev, "usb", "usb_device", attr));
325 to_int(const char *str, int base)
330 ll = strtoll(str, &ep, base);
331 if (str == ep || *ep != '\0')
333 else if (ll == LLONG_MIN && errno == ERANGE)
335 else if (ll == LLONG_MAX && errno == ERANGE)
337 else if (ll < 0 || ll > INT_MAX)
344 copy_info(fido_dev_info_t *di, struct udev *udev,
345 struct udev_list_entry *udev_entry)
349 struct udev_device *dev = NULL;
352 memset(di, 0, sizeof(*di));
354 if ((name = udev_list_entry_get_name(udev_entry)) == NULL ||
355 (dev = udev_device_new_from_syspath(udev, name)) == NULL)
358 if ((di->path = strdup(name)) == NULL ||
359 (di->manufacturer = get_usb_attr(dev, "manufacturer")) == NULL ||
360 (di->product = get_usb_attr(dev, "product")) == NULL)
363 /* XXX assumes USB for vendor/product info */
364 if ((str = get_usb_attr(dev, "idVendor")) != NULL &&
365 (id = to_int(str, 16)) > 0 && id <= UINT16_MAX)
366 di->vendor_id = (int16_t)id;
369 if ((str = get_usb_attr(dev, "idProduct")) != NULL &&
370 (id = to_int(str, 16)) > 0 && id <= UINT16_MAX)
371 di->product_id = (int16_t)id;
377 udev_device_unref(dev);
381 free(di->manufacturer);
383 explicit_bzero(di, sizeof(*di));
390 sysnum_from_syspath(const char *path)
392 struct udev *udev = NULL;
393 struct udev_device *dev = NULL;
397 if ((udev = udev_new()) == NULL ||
398 (dev = udev_device_new_from_syspath(udev, path)) == NULL ||
399 (str = udev_device_get_sysnum(dev)) == NULL)
402 idx = to_int(str, 10);
405 udev_device_unref(dev);
413 fido_nfc_manifest(fido_dev_info_t *devlist, size_t ilen, size_t *olen)
415 struct udev *udev = NULL;
416 struct udev_enumerate *udev_enum = NULL;
417 struct udev_list_entry *udev_list;
418 struct udev_list_entry *udev_entry;
419 int r = FIDO_ERR_INTERNAL;
427 return (FIDO_ERR_INVALID_ARGUMENT);
429 if ((udev = udev_new()) == NULL ||
430 (udev_enum = udev_enumerate_new(udev)) == NULL)
433 if (udev_enumerate_add_match_subsystem(udev_enum, "nfc") < 0 ||
434 udev_enumerate_scan_devices(udev_enum) < 0)
437 if ((udev_list = udev_enumerate_get_list_entry(udev_enum)) == NULL) {
438 r = FIDO_OK; /* zero nfc devices */
442 udev_list_entry_foreach(udev_entry, udev_list) {
443 if (copy_info(&devlist[*olen], udev, udev_entry) == 0) {
444 devlist[*olen].io = (fido_dev_io_t) {
450 devlist[*olen].transport = (fido_dev_transport_t) {
454 if (++(*olen) == ilen)
461 if (udev_enum != NULL)
462 udev_enumerate_unref(udev_enum);
470 nfc_target_connect(struct nfc_linux *ctx)
472 struct sockaddr_nfc sa;
474 memset(&sa, 0, sizeof(sa));
475 sa.sa_family = AF_NFC;
476 sa.dev_idx = ctx->dev;
477 sa.target_idx = ctx->target;
478 sa.nfc_protocol = NFC_PROTO_ISO14443;
480 if ((ctx->fd = socket(AF_NFC, SOCK_SEQPACKET | SOCK_CLOEXEC,
481 NFC_SOCKPROTO_RAW)) == -1) {
482 fido_log_error(errno, "%s: socket", __func__);
485 if (connect(ctx->fd, (struct sockaddr *)&sa, sizeof(sa)) == -1) {
486 fido_log_error(errno, "%s: connect", __func__);
487 if (close(ctx->fd) == -1)
488 fido_log_error(errno, "%s: close", __func__);
497 nfc_free(struct nfc_linux **ctx_p)
499 struct nfc_linux *ctx;
501 if (ctx_p == NULL || (ctx = *ctx_p) == NULL)
503 if (ctx->fd != -1 && close(ctx->fd) == -1)
504 fido_log_error(errno, "%s: close", __func__);
506 fido_nl_free(&ctx->nl);
512 static struct nfc_linux *
513 nfc_new(uint32_t dev)
515 struct nfc_linux *ctx;
517 if ((ctx = calloc(1, sizeof(*ctx))) == NULL ||
518 (ctx->nl = fido_nl_new()) == NULL) {
530 fido_nfc_open(const char *path)
532 struct nfc_linux *ctx = NULL;
535 if ((idx = sysnum_from_syspath(path)) < 0 ||
536 (ctx = nfc_new((uint32_t)idx)) == NULL) {
537 fido_log_debug("%s: nfc_new", __func__);
540 if (fido_nl_power_nfc(ctx->nl, ctx->dev) < 0 ||
541 fido_nl_get_nfc_target(ctx->nl, ctx->dev, &ctx->target) < 0 ||
542 nfc_target_connect(ctx) < 0) {
543 fido_log_debug("%s: netlink", __func__);
554 fido_nfc_close(void *handle)
556 struct nfc_linux *ctx = handle;
562 fido_nfc_set_sigmask(void *handle, const fido_sigset_t *sigmask)
564 struct nfc_linux *ctx = handle;
566 ctx->sigmask = *sigmask;
567 ctx->sigmaskp = &ctx->sigmask;
573 fido_nfc_read(void *handle, unsigned char *buf, size_t len, int ms)
575 struct nfc_linux *ctx = handle;
580 memset(&iov, 0, sizeof(iov));
581 iov[0].iov_base = &preamble;
582 iov[0].iov_len = sizeof(preamble);
583 iov[1].iov_base = buf;
584 iov[1].iov_len = len;
586 if (fido_hid_unix_wait(ctx->fd, ms, ctx->sigmaskp) < 0) {
587 fido_log_debug("%s: fido_hid_unix_wait", __func__);
590 if ((r = readv(ctx->fd, iov, nitems(iov))) == -1) {
591 fido_log_error(errno, "%s: read", __func__);
595 fido_log_debug("%s: %zd < 1", __func__, r);
598 if (preamble != 0x00) {
599 fido_log_debug("%s: preamble", __func__);
604 fido_log_xxd(buf, (size_t)r, "%s", __func__);
610 fido_nfc_write(void *handle, const unsigned char *buf, size_t len)
612 struct nfc_linux *ctx = handle;
615 fido_log_xxd(buf, len, "%s", __func__);
618 fido_log_debug("%s: len", __func__);
621 if ((r = write(ctx->fd, buf, len)) == -1) {
622 fido_log_error(errno, "%s: write", __func__);
625 if (r < 0 || (size_t)r != len) {
626 fido_log_debug("%s: %zd != %zu", __func__, r, len);