diff options
Diffstat (limited to 'node')
| -rw-r--r-- | node/NodeConfig.cpp | 7 | ||||
| -rw-r--r-- | node/NodeConfig.hpp | 4 |
2 files changed, 6 insertions, 5 deletions
diff --git a/node/NodeConfig.cpp b/node/NodeConfig.cpp index fca53942..381bbd62 100644 --- a/node/NodeConfig.cpp +++ b/node/NodeConfig.cpp @@ -156,15 +156,15 @@ std::vector< Buffer<ZT_NODECONFIG_MAX_PACKET_SIZE> > NodeConfig::encodeControlMe if (((i + 1) >= payload.size())||((packet.size() + payload[i + 1].length() + 1) >= packet.capacity())) { Utils::getSecureRandom(packet.field(8,8),8); + Salsa20 s20(key,256,packet.field(8,8)); + s20.encrypt(packet.field(16,packet.size() - 16),packet.field(16,packet.size() - 16),packet.size() - 16); + memcpy(keytmp,key,32); for(unsigned int i=0;i<32;++i) keytmp[i] ^= 0x77; // use a different permutation of key for HMAC than for Salsa20 HMAC::sha256(keytmp,32,packet.field(16,packet.size() - 16),packet.size() - 16,hmac); memcpy(packet.field(0,8),hmac,8); - Salsa20 s20(key,256,packet.field(8,8)); - s20.encrypt(packet.field(16,packet.size() - 16),packet.field(16,packet.size() - 16),packet.size() - 16); - packets.push_back(packet); packet.setSize(16); // HMAC and IV @@ -200,7 +200,6 @@ bool NodeConfig::decodeControlMessagePacket(const void *key,const void *data,uns const char *pl = ((const char *)packet.data()) + 20; unsigned int pll = packet.size() - 20; - payload.clear(); for(unsigned int i=0;i<pll;) { unsigned int eos = i; while ((eos < pll)&&(pl[eos])) diff --git a/node/NodeConfig.hpp b/node/NodeConfig.hpp index d284062d..309da344 100644 --- a/node/NodeConfig.hpp +++ b/node/NodeConfig.hpp @@ -156,11 +156,13 @@ public: /** * Decode a packet from the control bus * + * Note that 'payload' is appended to. Existing data is not cleared. + * * @param key 32 byte key * @param data Packet data * @param len Packet length * @param conversationId Result parameter filled with conversation ID on success - * @param payload Result parameter filled with payload on success + * @param payload Result parameter to which results are appended * @return True on success, false on invalid packet or packet that failed authentication */ static bool decodeControlMessagePacket(const void *key,const void *data,unsigned int len,unsigned long &conversationId,std::vector<std::string> &payload); |
