1
10
13
14
20
21
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
103
104
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
127
128
129
133
134
135
136
137
138
139
140
141
142
143
144
145
...
...
...
#define NX_SECURE_SOURCE_CODE
#include "nx_secure_tls.h"
...
...
UINT _nx_secure_tls_session_sni_extension_parse(NX_SECURE_TLS_SESSION *tls_session,
NX_SECURE_TLS_HELLO_EXTENSION *extensions,
UINT num_extensions, NX_SECURE_X509_DNS_NAME *dns_name)
{
UINT i;
const UCHAR *data_ptr;
UCHAR name_type;
USHORT list_length;
UINT offset;
NX_PARAMETER_NOT_USED(tls_session);
for (i = 0; i < num_extensions; ++i)
{
if (extensions[i].nx_secure_tls_extension_id == NX_SECURE_TLS_EXTENSION_SERVER_NAME_INDICATION)
{
/* ... */
/* ... */
data_ptr = extensions[i].nx_secure_tls_extension_data;
list_length = (USHORT)((data_ptr[0] << 8) + data_ptr[1]);
offset = 2;
name_type = data_ptr[offset];
offset += 1;
dns_name -> nx_secure_x509_dns_name_length = (USHORT)((data_ptr[offset] << 8) + data_ptr[offset + 1]);
offset += 2;
if (name_type != NX_SECURE_TLS_SNI_NAME_TYPE_DNS ||
list_length > extensions[i].nx_secure_tls_extension_data_length ||
dns_name -> nx_secure_x509_dns_name_length > list_length)
{
return(NX_SECURE_TLS_SNI_EXTENSION_INVALID);
}if (name_type != NX_SECURE_TLS_SNI_NAME_TYPE_DNS || list_length > extensions[i].nx_secure_tls_extension_data_length || dns_name -> nx_secure_x509_dns_name_length > list_length) { ... }
if (dns_name -> nx_secure_x509_dns_name_length > NX_SECURE_X509_DNS_NAME_MAX)
{
dns_name -> nx_secure_x509_dns_name_length = NX_SECURE_X509_DNS_NAME_MAX;
}if (dns_name -> nx_secure_x509_dns_name_length > NX_SECURE_X509_DNS_NAME_MAX) { ... }
NX_SECURE_MEMCPY(dns_name -> nx_secure_x509_dns_name, &data_ptr[offset], dns_name -> nx_secure_x509_dns_name_length);
return(NX_SUCCESS);
}if (extensions[i].nx_secure_tls_extension_id == NX_SECURE_TLS_EXTENSION_SERVER_NAME_INDICATION) { ... }
}for (i = 0; i < num_extensions; ++i) { ... }
return(NX_SECURE_TLS_EXTENSION_NOT_FOUND);
}{ ... }