Secure ReadProperty decoding and BACnetActionCommand (#702)

* Refactored and secured BACnetActionCommand codec into bacaction.c module for command object and added to bacapp module encode/decode with define for enabling and pseudo application tag for internal use.

* Simplified bacapp_data_len() and moved into bacdcode module as bacnet_enclosed_data_len() function.

* Secured ReadProperty-REQUEST and -ACK decoding.

* Removed deprecated Keylist_Key() functions from usage.

* Removed pseudo application datatypes from bacapp_data_decode() which only uses primitive application tag encoded values.

* Defined INT_MAX when it is not already defined by compiler or libc.

* Deprecated bacapp_decode_application_data_len() and bacapp_decode_context_data_len() as they are no longer used in any code in the library.

* Added BACnetScale to bacapp module. Improved complex property value decoding. Refactored bacapp_decode_known_property() function.

* Refactored and improved the bacapp_snprintf() function for printing EPICS.

* Fixed Lighting Output WriteProperty to handle known property decoding.
This commit is contained in:
Steve Karg
2024-07-25 17:12:08 -05:00
committed by GitHub
parent 923eaf2313
commit 4326128e72
191 changed files with 3856 additions and 2099 deletions
+95 -364
View File
@@ -21,316 +21,34 @@
/* BACnet Stack defines - first */
#include "bacnet/bacdef.h"
/* BACnet Stack API */
#include "bacnet/bacaction.h"
#include "bacnet/bacdcode.h"
#include "bacnet/bactext.h"
#include "bacnet/lighting.h"
#include "bacnet/proplist.h"
#include "bacnet/timestamp.h"
#include "bacnet/basic/object/device.h"
#include "bacnet/basic/services.h"
/* me!*/
#include "bacnet/basic/object/command.h"
/*
BACnetActionCommand ::= SEQUENCE {
deviceIdentifier [0] BACnetObjectIdentifier OPTIONAL,
objectIdentifier [1] BACnetObjectIdentifier,
propertyIdentifier [2] BACnetPropertyIdentifier,
propertyArrayIndex [3] Unsigned OPTIONAL,
--used only with array datatype
propertyValue [4] ABSTRACT-SYNTAX.&Type,
priority [5] Unsigned (1..16) OPTIONAL,
--used only when property is commandable
postDelay [6] Unsigned OPTIONAL,
quitOnFailure [7] BOOLEAN,
writeSuccessful [8] BOOLEAN
}
*/
int cl_encode_apdu(uint8_t *apdu, BACNET_ACTION_LIST *bcl)
{
int len = 0;
int apdu_len = 0;
if (bcl->Device_Id.instance <= BACNET_MAX_INSTANCE) {
len = encode_context_object_id(
&apdu[apdu_len], 0, bcl->Device_Id.type, bcl->Device_Id.instance);
if (len < 0) {
return BACNET_STATUS_REJECT;
}
apdu_len += len;
}
/* TODO: Check for object type and instance limits */
len = encode_context_object_id(
&apdu[apdu_len], 1, bcl->Object_Id.type, bcl->Object_Id.instance);
if (len < 0) {
return BACNET_STATUS_REJECT;
}
apdu_len += len;
len =
encode_context_enumerated(&apdu[apdu_len], 2, bcl->Property_Identifier);
if (len < 0) {
return BACNET_STATUS_REJECT;
}
apdu_len += len;
if (bcl->Property_Array_Index != BACNET_ARRAY_ALL) {
len = encode_context_unsigned(
&apdu[apdu_len], 3, bcl->Property_Array_Index);
if (len < 0) {
return BACNET_STATUS_REJECT;
}
apdu_len += len;
}
/* BACnet Testing Observed Incident oi00108
Command Action not correctly formatted
Revealed by BACnet Test Client v1.8.16 (
www.bac-test.com/bacnet-test-client-download ) BITS: BIT00031 BC
135.1: 9.20.1.7 BC 135.1: 9.20.1.9 Any discussions can be directed to
edward@bac-test.com Please feel free to remove this comment when my
changes have been reviewed by all interested parties. Say 6 months ->
September 2016 */
len = encode_opening_tag(&apdu[apdu_len], 4);
if (len < 0) {
return BACNET_STATUS_REJECT;
}
apdu_len += len;
len = bacapp_encode_application_data(&apdu[apdu_len], &bcl->Value);
if (len < 0) {
return BACNET_STATUS_REJECT;
}
apdu_len += len;
len = encode_closing_tag(&apdu[apdu_len], 4);
if (len < 0) {
return BACNET_STATUS_REJECT;
}
apdu_len += len;
if (bcl->Priority != BACNET_NO_PRIORITY) {
len = encode_context_unsigned(&apdu[apdu_len], 5, bcl->Priority);
if (len < 0) {
return BACNET_STATUS_REJECT;
}
apdu_len += len;
}
if (bcl->Post_Delay != 0xFFFFFFFFU) {
len = encode_context_unsigned(&apdu[apdu_len], 6, bcl->Post_Delay);
if (len < 0) {
return BACNET_STATUS_REJECT;
}
apdu_len += len;
}
len = encode_context_boolean(&apdu[apdu_len], 7, bcl->Quit_On_Failure);
if (len < 0) {
return BACNET_STATUS_REJECT;
}
apdu_len += len;
len = encode_context_boolean(&apdu[apdu_len], 8, bcl->Write_Successful);
if (len < 0) {
return BACNET_STATUS_REJECT;
}
apdu_len += len;
return apdu_len;
}
int cl_decode_apdu(uint8_t *apdu,
unsigned apdu_len,
BACNET_APPLICATION_TAG tag,
BACNET_ACTION_LIST *bcl)
{
int len = 0;
int dec_len = 0;
uint8_t tag_number = 0;
uint32_t len_value_type = 0;
uint32_t enum_value = 0;
BACNET_UNSIGNED_INTEGER unsigned_value = 0;
if (decode_is_context_tag(&apdu[dec_len], 0)) {
/* Tag 0: Device ID */
dec_len++;
len = decode_object_id(
&apdu[dec_len], &bcl->Device_Id.type, &bcl->Device_Id.instance);
if (len < 0) {
return BACNET_STATUS_REJECT;
}
dec_len += len;
}
if (!decode_is_context_tag(&apdu[dec_len++], 1)) {
return BACNET_STATUS_REJECT;
}
len = decode_object_id(
&apdu[dec_len], &bcl->Object_Id.type, &bcl->Object_Id.instance);
if (len < 0) {
return BACNET_STATUS_REJECT;
}
dec_len += len;
len = decode_tag_number_and_value(
&apdu[dec_len], &tag_number, &len_value_type);
if (len < 0) {
return BACNET_STATUS_REJECT;
}
dec_len += len;
if (tag_number != 2) {
return BACNET_STATUS_REJECT;
}
len = decode_enumerated(&apdu[dec_len], len_value_type, &enum_value);
if (len < 0) {
return BACNET_STATUS_REJECT;
}
bcl->Property_Identifier = enum_value;
dec_len += len;
if (decode_is_context_tag(&apdu[dec_len], 3)) {
len = decode_tag_number_and_value(
&apdu[dec_len], &tag_number, &len_value_type);
dec_len += len;
len = decode_unsigned(&apdu[dec_len], len_value_type, &unsigned_value);
if (len < 0) {
return BACNET_STATUS_REJECT;
}
bcl->Property_Array_Index = unsigned_value;
dec_len += len;
} else {
bcl->Property_Array_Index = BACNET_ARRAY_ALL;
}
if (!decode_is_context_tag(&apdu[dec_len], 4)) {
return BACNET_STATUS_REJECT;
}
bcl->Value.context_specific = true;
bcl->Value.context_tag = 4;
bcl->Value.tag = tag;
switch (tag) {
case BACNET_APPLICATION_TAG_NULL:
len = 1;
break;
case BACNET_APPLICATION_TAG_BOOLEAN:
len = decode_context_boolean2(
&apdu[dec_len], 4, &bcl->Value.type.Boolean);
if (len < 0) {
return BACNET_STATUS_REJECT;
}
break;
case BACNET_APPLICATION_TAG_UNSIGNED_INT:
len = decode_context_unsigned(&apdu[dec_len], 4, &unsigned_value);
if (len < 0) {
return BACNET_STATUS_REJECT;
}
bcl->Value.type.Unsigned_Int = unsigned_value;
break;
case BACNET_APPLICATION_TAG_SIGNED_INT:
len = decode_context_signed(
&apdu[dec_len], 4, &bcl->Value.type.Signed_Int);
break;
case BACNET_APPLICATION_TAG_REAL:
len = decode_context_real(&apdu[dec_len], 4, &bcl->Value.type.Real);
break;
case BACNET_APPLICATION_TAG_DOUBLE:
len = decode_context_double(
&apdu[dec_len], 4, &bcl->Value.type.Double);
break;
case BACNET_APPLICATION_TAG_OCTET_STRING:
len = decode_context_octet_string(
&apdu[dec_len], 4, &bcl->Value.type.Octet_String);
break;
case BACNET_APPLICATION_TAG_CHARACTER_STRING:
len = decode_context_character_string(
&apdu[dec_len], 4, &bcl->Value.type.Character_String);
break;
case BACNET_APPLICATION_TAG_BIT_STRING:
len = decode_context_bitstring(
&apdu[dec_len], 4, &bcl->Value.type.Bit_String);
if (len < 0) {
return BACNET_STATUS_REJECT;
}
break;
case BACNET_APPLICATION_TAG_ENUMERATED:
len = decode_context_enumerated(
&apdu[dec_len], 4, &bcl->Value.type.Enumerated);
break;
case BACNET_APPLICATION_TAG_DATE:
len = decode_context_date(&apdu[dec_len], 4, &bcl->Value.type.Date);
break;
case BACNET_APPLICATION_TAG_TIME:
len = decode_context_bacnet_time(
&apdu[dec_len], 4, &bcl->Value.type.Time);
break;
case BACNET_APPLICATION_TAG_OBJECT_ID:
len = decode_context_object_id(&apdu[dec_len], 4,
&bcl->Value.type.Object_Id.type,
&bcl->Value.type.Object_Id.instance);
break;
#if defined(BACAPP_TYPES_EXTRA)
case BACNET_APPLICATION_TAG_LIGHTING_COMMAND:
len = lighting_command_decode(&apdu[dec_len], apdu_len - dec_len,
&bcl->Value.type.Lighting_Command);
break;
#endif
default:
return BACNET_STATUS_REJECT;
}
if (len > 0) {
dec_len += len;
}
if (decode_is_context_tag(&apdu[dec_len], 5)) {
len = decode_tag_number_and_value(
&apdu[dec_len], &tag_number, &len_value_type);
dec_len += len;
len = decode_unsigned(&apdu[dec_len], len_value_type, &unsigned_value);
if (len < 0) {
return BACNET_STATUS_REJECT;
}
bcl->Priority = (uint8_t)unsigned_value;
dec_len += len;
} else {
bcl->Priority = BACNET_NO_PRIORITY;
}
if (decode_is_context_tag(&apdu[dec_len], 6)) {
len = decode_tag_number_and_value(
&apdu[dec_len], &tag_number, &len_value_type);
dec_len += len;
len = decode_unsigned(&apdu[dec_len], len_value_type, &unsigned_value);
if (len < 0) {
return BACNET_STATUS_REJECT;
}
bcl->Post_Delay = unsigned_value;
dec_len += len;
} else {
bcl->Post_Delay = 0xFFFFFFFFU;
}
if (!decode_is_context_tag(&apdu[dec_len], 7)) {
return BACNET_STATUS_REJECT;
}
len = decode_context_boolean2(&apdu[dec_len], 7, &bcl->Quit_On_Failure);
if (len < 0) {
return BACNET_STATUS_REJECT;
}
dec_len += len;
if (!decode_is_context_tag(&apdu[dec_len], 8)) {
return BACNET_STATUS_REJECT;
}
len = decode_context_boolean2(&apdu[dec_len], 8, &bcl->Write_Successful);
if (len < 0) {
return BACNET_STATUS_REJECT;
}
dec_len += len;
if (dec_len < apdu_len) {
return BACNET_STATUS_REJECT;
}
return dec_len;
}
COMMAND_DESCR Command_Descr[MAX_COMMANDS];
static COMMAND_DESCR Command_Descr[MAX_COMMANDS];
/* clang-format off */
/* These arrays are used by the ReadPropertyMultiple handler */
static const int Command_Properties_Required[] = { PROP_OBJECT_IDENTIFIER,
PROP_OBJECT_NAME, PROP_OBJECT_TYPE, PROP_PRESENT_VALUE, PROP_IN_PROCESS,
PROP_ALL_WRITES_SUCCESSFUL, PROP_ACTION, -1 };
static const int Command_Properties_Required[] = {
PROP_OBJECT_IDENTIFIER,
PROP_OBJECT_NAME,
PROP_OBJECT_TYPE,
PROP_PRESENT_VALUE,
PROP_IN_PROCESS,
PROP_ALL_WRITES_SUCCESSFUL,
PROP_ACTION,
-1 };
static const int Command_Properties_Optional[] = { PROP_DESCRIPTION, -1 };
static const int Command_Properties_Optional[] = { -1 };
static const int Command_Properties_Proprietary[] = { -1 };
/* clang-format on */
/**
* Returns the list of required, optional, and proprietary properties.
@@ -584,14 +302,78 @@ bool Command_Object_Name(
index = Command_Instance_To_Index(object_instance);
if (index < MAX_COMMANDS) {
snprintf(text, sizeof(text), "COMMAND %lu",
(unsigned long)object_instance);
snprintf(
text, sizeof(text), "COMMAND %lu", (unsigned long)object_instance);
status = characterstring_init_ansi(object_name, text);
}
return status;
}
/**
* @brief For a given object instance-number, returns the object data
* @param object_instance [in] BACnet network port object instance number
* @return pointer to the object data
*/
static COMMAND_DESCR *Object_Data(uint32_t object_instance)
{
unsigned int index = Command_Instance_To_Index(object_instance);
if (index < MAX_COMMANDS) {
return &Command_Descr[index];
}
return NULL;
}
BACNET_ACTION_LIST * Command_Action_List_Entry(
uint32_t instance, unsigned index)
{
COMMAND_DESCR *pObject;
BACNET_ACTION_LIST *pAction = NULL;
pObject = Object_Data(instance);
if (pObject && (index < MAX_COMMAND_ACTIONS)) {
pAction = &pObject->Action[index];
}
return pAction;
}
/**
* @brief For a given object instance-number, returns the number of actions
*/
unsigned Command_Action_List_Count(
uint32_t instance)
{
(void)instance;
return MAX_COMMAND_ACTIONS;
}
/**
* @brief Encode a BACnetARRAY property element
* @param object_instance [in] BACnet network port object instance number
* @param index [in] array index requested:
* 0 to N for individual array members
* @param apdu [out] Buffer in which the APDU contents are built, or NULL to
* return the length of buffer if it had been built
* @return The length of the apdu encoded or
* BACNET_STATUS_ERROR for ERROR_CODE_INVALID_ARRAY_INDEX
*/
static int Command_Action_List_Encode(
uint32_t object_instance, BACNET_ARRAY_INDEX index, uint8_t *apdu)
{
int apdu_len = BACNET_STATUS_ERROR;
COMMAND_DESCR *pObject;
pObject = Object_Data(object_instance);
if (pObject && (index < MAX_COMMAND_ACTIONS)) {
apdu_len = bacnet_action_command_encode(
apdu, &pObject->Action[index]);
}
return apdu_len;
}
/**
* ReadProperty handler for this object. For the given ReadProperty
* data, the application_data is loaded or the error flags are set.
@@ -605,26 +387,16 @@ bool Command_Object_Name(
int Command_Read_Property(BACNET_READ_PROPERTY_DATA *rpdata)
{
int apdu_len = 0; /* return value */
int len = 0;
BACNET_CHARACTER_STRING char_string;
unsigned object_index = 0;
uint8_t *apdu = NULL;
uint16_t apdu_max = 0;
COMMAND_DESCR *CurrentCommand;
int apdu_size = 0;
if ((rpdata == NULL) || (rpdata->application_data == NULL) ||
(rpdata->application_data_len == 0)) {
return 0;
}
apdu_max = rpdata->application_data_len;
object_index = Command_Instance_To_Index(rpdata->object_instance);
if (object_index < MAX_COMMANDS) {
CurrentCommand = &Command_Descr[object_index];
} else {
return false;
}
apdu = rpdata->application_data;
apdu_size = rpdata->application_data_len;
switch ((int)rpdata->object_property) {
case PROP_OBJECT_IDENTIFIER:
apdu_len = encode_application_object_id(
@@ -632,7 +404,6 @@ int Command_Read_Property(BACNET_READ_PROPERTY_DATA *rpdata)
break;
case PROP_OBJECT_NAME:
case PROP_DESCRIPTION:
Command_Object_Name(rpdata->object_instance, &char_string);
apdu_len =
encode_application_character_string(&apdu[0], &char_string);
@@ -651,60 +422,20 @@ int Command_Read_Property(BACNET_READ_PROPERTY_DATA *rpdata)
&apdu[0], Command_In_Process(rpdata->object_instance));
break;
case PROP_ALL_WRITES_SUCCESSFUL:
apdu_len = encode_application_boolean(&apdu[0],
apdu_len = encode_application_boolean(
&apdu[0],
Command_All_Writes_Successful(rpdata->object_instance));
break;
case PROP_ACTION:
/* TODO */
if (rpdata->array_index == 0) {
apdu_len =
encode_application_unsigned(&apdu[0], MAX_COMMAND_ACTIONS);
} else if (rpdata->array_index == BACNET_ARRAY_ALL) {
int i;
for (i = 0; i < MAX_COMMAND_ACTIONS; i++) {
BACNET_ACTION_LIST *Curr_CL_Member =
&CurrentCommand->Action[0];
/* another loop, for additional actions in the list */
for (; Curr_CL_Member != NULL;
Curr_CL_Member = Curr_CL_Member->next) {
len = cl_encode_apdu(
&apdu[apdu_len], &CurrentCommand->Action[0]);
apdu_len += len;
/* assume the next one is of the same length, which need
* not be the case */
if ((i != MAX_COMMAND_ACTIONS - 1) &&
(apdu_len + len) >= apdu_max) {
rpdata->error_code =
ERROR_CODE_ABORT_SEGMENTATION_NOT_SUPPORTED;
apdu_len = BACNET_STATUS_ABORT;
break;
}
}
}
} else {
if (rpdata->array_index < MAX_COMMAND_ACTIONS) {
BACNET_ACTION_LIST *Curr_CL_Member =
&CurrentCommand->Action[rpdata->array_index];
/* another loop, for additional actions in the list */
for (; Curr_CL_Member != NULL;
Curr_CL_Member = Curr_CL_Member->next) {
len = cl_encode_apdu(
&apdu[apdu_len], &CurrentCommand->Action[0]);
apdu_len += len;
/* assume the next one is of the same length, which need
* not be the case */
if ((apdu_len + len) >= apdu_max) {
rpdata->error_code =
ERROR_CODE_ABORT_SEGMENTATION_NOT_SUPPORTED;
apdu_len = BACNET_STATUS_ABORT;
break;
}
}
} else {
rpdata->error_class = ERROR_CLASS_PROPERTY;
rpdata->error_code = ERROR_CODE_INVALID_ARRAY_INDEX;
apdu_len = BACNET_STATUS_ERROR;
}
apdu_len = bacnet_array_encode(rpdata->object_instance,
rpdata->array_index, Command_Action_List_Encode,
MAX_COMMAND_ACTIONS, apdu, apdu_size);
if (apdu_len == BACNET_STATUS_ABORT) {
rpdata->error_code =
ERROR_CODE_ABORT_SEGMENTATION_NOT_SUPPORTED;
} else if (apdu_len == BACNET_STATUS_ERROR) {
rpdata->error_class = ERROR_CLASS_PROPERTY;
rpdata->error_code = ERROR_CODE_INVALID_ARRAY_INDEX;
}
break;
default:
@@ -781,8 +512,8 @@ bool Command_Write_Property(BACNET_WRITE_PROPERTY_DATA *wp_data)
break;
default:
if (property_lists_member(
Command_Properties_Required, Command_Properties_Optional,
Command_Properties_Proprietary, wp_data->object_property)) {
Command_Properties_Required, Command_Properties_Optional,
Command_Properties_Proprietary, wp_data->object_property)) {
wp_data->error_class = ERROR_CLASS_PROPERTY;
wp_data->error_code = ERROR_CODE_WRITE_ACCESS_DENIED;
} else {