Secured event decoding by refactoring deprecated functions. (#1126)

* Secured event and authentication decoding by removing deprecated functions.

* Added extended, discrete-value, double-out-of-range, signed-out-of-range, unsigned-out-of-range, change-of-characterstring, change-of-status-flags, change-of-reliability, and change-of-timer event notification encode, decode, and unit testing with #ifdef disabled by default.
This commit is contained in:
Steve Karg
2025-11-05 21:41:30 -06:00
committed by GitHub
parent 4dd13cf199
commit 35f3964b5a
15 changed files with 4449 additions and 1345 deletions
+114 -77
View File
@@ -22,29 +22,17 @@ int bacapp_encode_authentication_factor(
int apdu_len = 0;
len = encode_context_enumerated(apdu, 0, af->format_type);
if (len < 0) {
return -1;
} else {
apdu_len += len;
if (apdu) {
apdu += len;
}
apdu_len += len;
if (apdu) {
apdu += len;
}
len = encode_context_unsigned(apdu, 1, af->format_class);
if (len < 0) {
return -1;
} else {
apdu_len += len;
if (apdu) {
apdu += len;
}
apdu_len += len;
if (apdu) {
apdu += len;
}
len = encode_context_octet_string(apdu, 2, &af->value);
if (len < 0) {
return -1;
} else {
apdu_len += len;
}
apdu_len += len;
return apdu_len;
}
@@ -77,56 +65,122 @@ int bacapp_encode_context_authentication_factor(
return apdu_len;
}
/**
* @brief Decode the BACnetAuthenticationFactor complex data
* @details
* BACnetAuthenticationFactor ::= SEQUENCE {
* format-type[0] BACnetAuthenticationFactorType,
* format-class[1] Unsigned,
* value[2] OctetString
* -- for encoding of values into this octet string see Annex P.
* }
*
* @param apdu Pointer to the buffer for decoding.
* @param apdu_size Number of valid bytes in the buffer.
* @param af Pointer to the property decoded data to be stored, or NULL for
* length of the decoded bytes.
* @return Number of bytes decoded or BACNET_STATUS_ERROR on error.
*/
int bacnet_authentication_factor_decode(
const uint8_t *apdu, unsigned apdu_size, BACNET_AUTHENTICATION_FACTOR *af)
{
int len = 0, apdu_len = 0;
uint32_t enum_value = 0;
BACNET_UNSIGNED_INTEGER unsigned_value = 0;
BACNET_OCTET_STRING *octet_string_value = NULL;
/* format-type[0] BACnetAuthenticationFactorType */
len = bacnet_enumerated_context_decode(
&apdu[apdu_len], apdu_size - apdu_len, 0, &enum_value);
if (len > 0) {
if (af) {
if (enum_value > AUTHENTICATION_FACTOR_MAX) {
enum_value = AUTHENTICATION_FACTOR_MAX;
}
af->format_type = (BACNET_AUTHENTICATION_FACTOR_TYPE)enum_value;
}
apdu_len += len;
} else {
return BACNET_STATUS_ERROR;
}
/* format-class[1] Unsigned */
len = bacnet_unsigned_context_decode(
&apdu[apdu_len], apdu_size - apdu_len, 1, &unsigned_value);
if (len > 0) {
if (af) {
af->format_class = unsigned_value;
}
apdu_len += len;
} else {
return BACNET_STATUS_ERROR;
}
/* value[2] OctetString */
if (af) {
octet_string_value = &af->value;
} else {
octet_string_value = NULL;
}
len = bacnet_octet_string_context_decode(
&apdu[apdu_len], apdu_size - apdu_len, 2, octet_string_value);
if (len > 0) {
apdu_len += len;
} else {
return BACNET_STATUS_ERROR;
}
return apdu_len;
}
/**
* @brief Decode the BACnetAuthenticationFactor complex data
* @param apdu Pointer to the buffer for decoding.
* @param af Pointer to the property decoded data to be stored
* @return Bytes decoded or BACNET_STATUS_REJECT on error.
* @deprecated Use bacnet_authentication_factor_decode() instead
*/
int bacapp_decode_authentication_factor(
const uint8_t *apdu, BACNET_AUTHENTICATION_FACTOR *af)
{
int len;
int apdu_len = 0;
uint32_t format_type = af->format_type;
BACNET_UNSIGNED_INTEGER unsigned_value = 0;
return bacnet_authentication_factor_decode(apdu, MAX_APDU, af);
}
if (decode_is_context_tag(&apdu[apdu_len], 0)) {
len = decode_context_enumerated(&apdu[apdu_len], 0, &format_type);
if (len < 0) {
return -1;
} else if (format_type < AUTHENTICATION_FACTOR_MAX) {
/**
* @brief Decode the context tagged BACnetAuthenticationFactor complex data
* @param apdu Pointer to the buffer for decoding.
* @param apdu_size Number of valid bytes in the buffer.
* @param tag context tag number wrapping the complex data
* @param af Pointer to the property decoded data to be stored, or NULL
* for the length in bytes decoded
* @return Number of bytes decoded,
* 0 if opening tag doesn't match (use to detect OPTIONAL),
* or BACNET_STATUS_ERROR on error.
*/
int bacnet_authentication_factor_context_decode(
const uint8_t *apdu,
unsigned apdu_size,
uint8_t tag,
BACNET_AUTHENTICATION_FACTOR *af)
{
int len = 0, apdu_len = 0;
if (bacnet_is_opening_tag_number(
&apdu[apdu_len], apdu_size - apdu_len, tag, &len)) {
apdu_len += len;
len = bacnet_authentication_factor_decode(
&apdu[apdu_len], apdu_size - apdu_len, af);
if (len > 0) {
apdu_len += len;
af->format_type = (BACNET_AUTHENTICATION_FACTOR_TYPE)format_type;
} else {
/* FIXME: Maybe this should return BACNET_STATUS_REJECT */
return -1;
return BACNET_STATUS_ERROR;
}
if (bacnet_is_closing_tag_number(
&apdu[apdu_len], apdu_size - apdu_len, tag, &len)) {
apdu_len += len;
} else {
return BACNET_STATUS_ERROR;
}
} else {
return -1;
}
if (decode_is_context_tag(&apdu[apdu_len], 1)) {
len = decode_context_unsigned(&apdu[apdu_len], 1, &unsigned_value);
if (len < 0) {
return -1;
} else {
af->format_class = unsigned_value;
apdu_len += len;
}
} else {
return -1;
}
if (decode_is_context_tag(&apdu[apdu_len], 2)) {
len = decode_context_octet_string(&apdu[apdu_len], 2, &af->value);
if (len < 0) {
return -1;
} else {
apdu_len += len;
}
} else {
return -1;
return 0;
}
return apdu_len;
@@ -137,30 +191,13 @@ int bacapp_decode_authentication_factor(
* @param apdu Pointer to the buffer for decoding.
* @param tag context tag number wrapping the complex data
* @param af Pointer to the property decoded data to be stored
* @return Bytes decoded or BACNET_STATUS_REJECT on error.
* @return Number of bytes decoded,
* 0 if opening tag doesn't match (use to detect OPTIONAL),
* or BACNET_STATUS_ERROR on error.
* @deprecated Use bacnet_authentication_factor_context_decode() instead
*/
int bacapp_decode_context_authentication_factor(
const uint8_t *apdu, uint8_t tag, BACNET_AUTHENTICATION_FACTOR *af)
{
int len = 0;
int section_length;
if (decode_is_opening_tag_number(&apdu[len], tag)) {
len++;
section_length = bacapp_decode_authentication_factor(&apdu[len], af);
if (section_length == -1) {
len = -1;
} else {
len += section_length;
if (decode_is_closing_tag_number(&apdu[len], tag)) {
len++;
} else {
len = -1;
}
}
} else {
len = -1;
}
return len;
return bacnet_authentication_factor_context_decode(apdu, MAX_APDU, tag, af);
}