1*6777b538SAndroid Build Coastguard Worker // Copyright 2012 The Chromium Authors
2*6777b538SAndroid Build Coastguard Worker // Use of this source code is governed by a BSD-style license that can be
3*6777b538SAndroid Build Coastguard Worker // found in the LICENSE file.
4*6777b538SAndroid Build Coastguard Worker
5*6777b538SAndroid Build Coastguard Worker #include "net/websockets/websocket_frame.h"
6*6777b538SAndroid Build Coastguard Worker
7*6777b538SAndroid Build Coastguard Worker #include <stddef.h>
8*6777b538SAndroid Build Coastguard Worker #include <string.h>
9*6777b538SAndroid Build Coastguard Worker
10*6777b538SAndroid Build Coastguard Worker #include <ostream>
11*6777b538SAndroid Build Coastguard Worker
12*6777b538SAndroid Build Coastguard Worker #include "base/check.h"
13*6777b538SAndroid Build Coastguard Worker #include "base/check_op.h"
14*6777b538SAndroid Build Coastguard Worker #include "base/containers/span.h"
15*6777b538SAndroid Build Coastguard Worker #include "base/containers/span_writer.h"
16*6777b538SAndroid Build Coastguard Worker #include "base/numerics/safe_conversions.h"
17*6777b538SAndroid Build Coastguard Worker #include "base/rand_util.h"
18*6777b538SAndroid Build Coastguard Worker #include "base/ranges/algorithm.h"
19*6777b538SAndroid Build Coastguard Worker #include "build/build_config.h"
20*6777b538SAndroid Build Coastguard Worker #include "net/base/net_errors.h"
21*6777b538SAndroid Build Coastguard Worker
22*6777b538SAndroid Build Coastguard Worker namespace net {
23*6777b538SAndroid Build Coastguard Worker
24*6777b538SAndroid Build Coastguard Worker namespace {
25*6777b538SAndroid Build Coastguard Worker
26*6777b538SAndroid Build Coastguard Worker // GCC (and Clang) can transparently use vector ops. Only try to do this on
27*6777b538SAndroid Build Coastguard Worker // architectures where we know it works, otherwise gcc will attempt to emulate
28*6777b538SAndroid Build Coastguard Worker // the vector ops, which is unlikely to be efficient.
29*6777b538SAndroid Build Coastguard Worker #if defined(COMPILER_GCC) && \
30*6777b538SAndroid Build Coastguard Worker (defined(ARCH_CPU_X86_FAMILY) || defined(ARCH_CPU_ARM_FAMILY))
31*6777b538SAndroid Build Coastguard Worker
32*6777b538SAndroid Build Coastguard Worker using PackedMaskType = uint32_t __attribute__((vector_size(16)));
33*6777b538SAndroid Build Coastguard Worker
34*6777b538SAndroid Build Coastguard Worker #else
35*6777b538SAndroid Build Coastguard Worker
36*6777b538SAndroid Build Coastguard Worker using PackedMaskType = size_t;
37*6777b538SAndroid Build Coastguard Worker
38*6777b538SAndroid Build Coastguard Worker #endif // defined(COMPILER_GCC) &&
39*6777b538SAndroid Build Coastguard Worker // (defined(ARCH_CPU_X86_FAMILY) || defined(ARCH_CPU_ARM_FAMILY))
40*6777b538SAndroid Build Coastguard Worker
41*6777b538SAndroid Build Coastguard Worker constexpr uint8_t kFinalBit = 0x80;
42*6777b538SAndroid Build Coastguard Worker constexpr uint8_t kReserved1Bit = 0x40;
43*6777b538SAndroid Build Coastguard Worker constexpr uint8_t kReserved2Bit = 0x20;
44*6777b538SAndroid Build Coastguard Worker constexpr uint8_t kReserved3Bit = 0x10;
45*6777b538SAndroid Build Coastguard Worker constexpr uint8_t kOpCodeMask = 0xF;
46*6777b538SAndroid Build Coastguard Worker constexpr uint8_t kMaskBit = 0x80;
47*6777b538SAndroid Build Coastguard Worker constexpr uint64_t kMaxPayloadLengthWithoutExtendedLengthField = 125;
48*6777b538SAndroid Build Coastguard Worker constexpr uint64_t kPayloadLengthWithTwoByteExtendedLengthField = 126;
49*6777b538SAndroid Build Coastguard Worker constexpr uint64_t kPayloadLengthWithEightByteExtendedLengthField = 127;
50*6777b538SAndroid Build Coastguard Worker
MaskWebSocketFramePayloadByBytes(const WebSocketMaskingKey & masking_key,size_t masking_key_offset,char * const begin,char * const end)51*6777b538SAndroid Build Coastguard Worker inline void MaskWebSocketFramePayloadByBytes(
52*6777b538SAndroid Build Coastguard Worker const WebSocketMaskingKey& masking_key,
53*6777b538SAndroid Build Coastguard Worker size_t masking_key_offset,
54*6777b538SAndroid Build Coastguard Worker char* const begin,
55*6777b538SAndroid Build Coastguard Worker char* const end) {
56*6777b538SAndroid Build Coastguard Worker for (char* masked = begin; masked != end; ++masked) {
57*6777b538SAndroid Build Coastguard Worker *masked ^= masking_key.key[masking_key_offset++ %
58*6777b538SAndroid Build Coastguard Worker WebSocketFrameHeader::kMaskingKeyLength];
59*6777b538SAndroid Build Coastguard Worker }
60*6777b538SAndroid Build Coastguard Worker }
61*6777b538SAndroid Build Coastguard Worker
62*6777b538SAndroid Build Coastguard Worker } // namespace
63*6777b538SAndroid Build Coastguard Worker
Clone() const64*6777b538SAndroid Build Coastguard Worker std::unique_ptr<WebSocketFrameHeader> WebSocketFrameHeader::Clone() const {
65*6777b538SAndroid Build Coastguard Worker auto ret = std::make_unique<WebSocketFrameHeader>(opcode);
66*6777b538SAndroid Build Coastguard Worker ret->CopyFrom(*this);
67*6777b538SAndroid Build Coastguard Worker return ret;
68*6777b538SAndroid Build Coastguard Worker }
69*6777b538SAndroid Build Coastguard Worker
CopyFrom(const WebSocketFrameHeader & source)70*6777b538SAndroid Build Coastguard Worker void WebSocketFrameHeader::CopyFrom(const WebSocketFrameHeader& source) {
71*6777b538SAndroid Build Coastguard Worker final = source.final;
72*6777b538SAndroid Build Coastguard Worker reserved1 = source.reserved1;
73*6777b538SAndroid Build Coastguard Worker reserved2 = source.reserved2;
74*6777b538SAndroid Build Coastguard Worker reserved3 = source.reserved3;
75*6777b538SAndroid Build Coastguard Worker opcode = source.opcode;
76*6777b538SAndroid Build Coastguard Worker masked = source.masked;
77*6777b538SAndroid Build Coastguard Worker masking_key = source.masking_key;
78*6777b538SAndroid Build Coastguard Worker payload_length = source.payload_length;
79*6777b538SAndroid Build Coastguard Worker }
80*6777b538SAndroid Build Coastguard Worker
WebSocketFrame(WebSocketFrameHeader::OpCode opcode)81*6777b538SAndroid Build Coastguard Worker WebSocketFrame::WebSocketFrame(WebSocketFrameHeader::OpCode opcode)
82*6777b538SAndroid Build Coastguard Worker : header(opcode) {}
83*6777b538SAndroid Build Coastguard Worker
84*6777b538SAndroid Build Coastguard Worker WebSocketFrame::~WebSocketFrame() = default;
85*6777b538SAndroid Build Coastguard Worker
86*6777b538SAndroid Build Coastguard Worker WebSocketFrameChunk::WebSocketFrameChunk() = default;
87*6777b538SAndroid Build Coastguard Worker
88*6777b538SAndroid Build Coastguard Worker WebSocketFrameChunk::~WebSocketFrameChunk() = default;
89*6777b538SAndroid Build Coastguard Worker
GetWebSocketFrameHeaderSize(const WebSocketFrameHeader & header)90*6777b538SAndroid Build Coastguard Worker size_t GetWebSocketFrameHeaderSize(const WebSocketFrameHeader& header) {
91*6777b538SAndroid Build Coastguard Worker size_t extended_length_size = 0u;
92*6777b538SAndroid Build Coastguard Worker if (header.payload_length > kMaxPayloadLengthWithoutExtendedLengthField &&
93*6777b538SAndroid Build Coastguard Worker header.payload_length <= UINT16_MAX) {
94*6777b538SAndroid Build Coastguard Worker extended_length_size = 2u;
95*6777b538SAndroid Build Coastguard Worker } else if (header.payload_length > UINT16_MAX) {
96*6777b538SAndroid Build Coastguard Worker extended_length_size = 8u;
97*6777b538SAndroid Build Coastguard Worker }
98*6777b538SAndroid Build Coastguard Worker
99*6777b538SAndroid Build Coastguard Worker return (WebSocketFrameHeader::kBaseHeaderSize + extended_length_size +
100*6777b538SAndroid Build Coastguard Worker (header.masked ? WebSocketFrameHeader::kMaskingKeyLength : 0u));
101*6777b538SAndroid Build Coastguard Worker }
102*6777b538SAndroid Build Coastguard Worker
WriteWebSocketFrameHeader(const WebSocketFrameHeader & header,const WebSocketMaskingKey * masking_key,char * buffer_ptr,int buffer_size)103*6777b538SAndroid Build Coastguard Worker int WriteWebSocketFrameHeader(const WebSocketFrameHeader& header,
104*6777b538SAndroid Build Coastguard Worker const WebSocketMaskingKey* masking_key,
105*6777b538SAndroid Build Coastguard Worker char* buffer_ptr,
106*6777b538SAndroid Build Coastguard Worker int buffer_size) {
107*6777b538SAndroid Build Coastguard Worker base::span<uint8_t> buffer = base::as_writable_bytes(
108*6777b538SAndroid Build Coastguard Worker // TODO(crbug.com/40284755): It's not possible to construct this span
109*6777b538SAndroid Build Coastguard Worker // soundedly here. WriteWebSocketFrameHeader() should receive a span
110*6777b538SAndroid Build Coastguard Worker // instead of a pointer and length.
111*6777b538SAndroid Build Coastguard Worker UNSAFE_BUFFERS(
112*6777b538SAndroid Build Coastguard Worker base::span(buffer_ptr, base::checked_cast<size_t>(buffer_size))));
113*6777b538SAndroid Build Coastguard Worker
114*6777b538SAndroid Build Coastguard Worker DCHECK((header.opcode & kOpCodeMask) == header.opcode)
115*6777b538SAndroid Build Coastguard Worker << "header.opcode must fit to kOpCodeMask.";
116*6777b538SAndroid Build Coastguard Worker DCHECK(header.payload_length <= static_cast<uint64_t>(INT64_MAX))
117*6777b538SAndroid Build Coastguard Worker << "WebSocket specification doesn't allow a frame longer than "
118*6777b538SAndroid Build Coastguard Worker << "INT64_MAX (0x7FFFFFFFFFFFFFFF) bytes.";
119*6777b538SAndroid Build Coastguard Worker
120*6777b538SAndroid Build Coastguard Worker // WebSocket frame format is as follows:
121*6777b538SAndroid Build Coastguard Worker // - Common header (2 bytes)
122*6777b538SAndroid Build Coastguard Worker // - Optional extended payload length
123*6777b538SAndroid Build Coastguard Worker // (2 or 8 bytes, present if actual payload length is more than 125 bytes)
124*6777b538SAndroid Build Coastguard Worker // - Optional masking key (4 bytes, present if MASK bit is on)
125*6777b538SAndroid Build Coastguard Worker // - Actual payload (XOR masked with masking key if MASK bit is on)
126*6777b538SAndroid Build Coastguard Worker //
127*6777b538SAndroid Build Coastguard Worker // This function constructs frame header (the first three in the list
128*6777b538SAndroid Build Coastguard Worker // above).
129*6777b538SAndroid Build Coastguard Worker
130*6777b538SAndroid Build Coastguard Worker size_t header_size = GetWebSocketFrameHeaderSize(header);
131*6777b538SAndroid Build Coastguard Worker if (header_size > buffer.size()) {
132*6777b538SAndroid Build Coastguard Worker return ERR_INVALID_ARGUMENT;
133*6777b538SAndroid Build Coastguard Worker }
134*6777b538SAndroid Build Coastguard Worker
135*6777b538SAndroid Build Coastguard Worker base::SpanWriter writer(buffer);
136*6777b538SAndroid Build Coastguard Worker
137*6777b538SAndroid Build Coastguard Worker uint8_t first_byte = 0u;
138*6777b538SAndroid Build Coastguard Worker first_byte |= header.final ? kFinalBit : 0u;
139*6777b538SAndroid Build Coastguard Worker first_byte |= header.reserved1 ? kReserved1Bit : 0u;
140*6777b538SAndroid Build Coastguard Worker first_byte |= header.reserved2 ? kReserved2Bit : 0u;
141*6777b538SAndroid Build Coastguard Worker first_byte |= header.reserved3 ? kReserved3Bit : 0u;
142*6777b538SAndroid Build Coastguard Worker first_byte |= header.opcode & kOpCodeMask;
143*6777b538SAndroid Build Coastguard Worker writer.WriteU8BigEndian(first_byte);
144*6777b538SAndroid Build Coastguard Worker
145*6777b538SAndroid Build Coastguard Worker int extended_length_size = 0;
146*6777b538SAndroid Build Coastguard Worker uint8_t second_byte = 0u;
147*6777b538SAndroid Build Coastguard Worker second_byte |= header.masked ? kMaskBit : 0u;
148*6777b538SAndroid Build Coastguard Worker if (header.payload_length <= kMaxPayloadLengthWithoutExtendedLengthField) {
149*6777b538SAndroid Build Coastguard Worker second_byte |= header.payload_length;
150*6777b538SAndroid Build Coastguard Worker } else if (header.payload_length <= UINT16_MAX) {
151*6777b538SAndroid Build Coastguard Worker second_byte |= kPayloadLengthWithTwoByteExtendedLengthField;
152*6777b538SAndroid Build Coastguard Worker extended_length_size = 2;
153*6777b538SAndroid Build Coastguard Worker } else {
154*6777b538SAndroid Build Coastguard Worker second_byte |= kPayloadLengthWithEightByteExtendedLengthField;
155*6777b538SAndroid Build Coastguard Worker extended_length_size = 8;
156*6777b538SAndroid Build Coastguard Worker }
157*6777b538SAndroid Build Coastguard Worker writer.WriteU8BigEndian(second_byte);
158*6777b538SAndroid Build Coastguard Worker
159*6777b538SAndroid Build Coastguard Worker // Writes "extended payload length" field.
160*6777b538SAndroid Build Coastguard Worker if (extended_length_size == 2) {
161*6777b538SAndroid Build Coastguard Worker writer.WriteU16BigEndian(static_cast<uint16_t>(header.payload_length));
162*6777b538SAndroid Build Coastguard Worker } else if (extended_length_size == 8) {
163*6777b538SAndroid Build Coastguard Worker writer.WriteU64BigEndian(header.payload_length);
164*6777b538SAndroid Build Coastguard Worker }
165*6777b538SAndroid Build Coastguard Worker
166*6777b538SAndroid Build Coastguard Worker // Writes "masking key" field, if needed.
167*6777b538SAndroid Build Coastguard Worker if (header.masked) {
168*6777b538SAndroid Build Coastguard Worker DCHECK(masking_key);
169*6777b538SAndroid Build Coastguard Worker writer.Write(masking_key->key);
170*6777b538SAndroid Build Coastguard Worker } else {
171*6777b538SAndroid Build Coastguard Worker DCHECK(!masking_key);
172*6777b538SAndroid Build Coastguard Worker }
173*6777b538SAndroid Build Coastguard Worker
174*6777b538SAndroid Build Coastguard Worker // Verify we wrote the expected number of bytes.
175*6777b538SAndroid Build Coastguard Worker DCHECK_EQ(header_size, writer.num_written());
176*6777b538SAndroid Build Coastguard Worker return header_size;
177*6777b538SAndroid Build Coastguard Worker }
178*6777b538SAndroid Build Coastguard Worker
GenerateWebSocketMaskingKey()179*6777b538SAndroid Build Coastguard Worker WebSocketMaskingKey GenerateWebSocketMaskingKey() {
180*6777b538SAndroid Build Coastguard Worker // Masking keys should be generated from a cryptographically secure random
181*6777b538SAndroid Build Coastguard Worker // number generator, which means web application authors should not be able
182*6777b538SAndroid Build Coastguard Worker // to guess the next value of masking key.
183*6777b538SAndroid Build Coastguard Worker WebSocketMaskingKey masking_key;
184*6777b538SAndroid Build Coastguard Worker base::RandBytes(masking_key.key, WebSocketFrameHeader::kMaskingKeyLength);
185*6777b538SAndroid Build Coastguard Worker return masking_key;
186*6777b538SAndroid Build Coastguard Worker }
187*6777b538SAndroid Build Coastguard Worker
MaskWebSocketFramePayload(const WebSocketMaskingKey & masking_key,uint64_t frame_offset,char * const data,int data_size)188*6777b538SAndroid Build Coastguard Worker void MaskWebSocketFramePayload(const WebSocketMaskingKey& masking_key,
189*6777b538SAndroid Build Coastguard Worker uint64_t frame_offset,
190*6777b538SAndroid Build Coastguard Worker char* const data,
191*6777b538SAndroid Build Coastguard Worker int data_size) {
192*6777b538SAndroid Build Coastguard Worker static constexpr size_t kMaskingKeyLength =
193*6777b538SAndroid Build Coastguard Worker WebSocketFrameHeader::kMaskingKeyLength;
194*6777b538SAndroid Build Coastguard Worker
195*6777b538SAndroid Build Coastguard Worker DCHECK_GE(data_size, 0);
196*6777b538SAndroid Build Coastguard Worker
197*6777b538SAndroid Build Coastguard Worker // Most of the masking is done in chunks of sizeof(PackedMaskType), except for
198*6777b538SAndroid Build Coastguard Worker // the beginning and the end of the buffer which may be unaligned.
199*6777b538SAndroid Build Coastguard Worker // PackedMaskType must be a multiple of kMaskingKeyLength in size.
200*6777b538SAndroid Build Coastguard Worker PackedMaskType packed_mask_key;
201*6777b538SAndroid Build Coastguard Worker static constexpr size_t kPackedMaskKeySize = sizeof(packed_mask_key);
202*6777b538SAndroid Build Coastguard Worker static_assert((kPackedMaskKeySize >= kMaskingKeyLength &&
203*6777b538SAndroid Build Coastguard Worker kPackedMaskKeySize % kMaskingKeyLength == 0),
204*6777b538SAndroid Build Coastguard Worker "PackedMaskType size is not a multiple of mask length");
205*6777b538SAndroid Build Coastguard Worker char* const end = data + data_size;
206*6777b538SAndroid Build Coastguard Worker // If the buffer is too small for the vectorised version to be useful, revert
207*6777b538SAndroid Build Coastguard Worker // to the byte-at-a-time implementation early.
208*6777b538SAndroid Build Coastguard Worker if (data_size <= static_cast<int>(kPackedMaskKeySize * 2)) {
209*6777b538SAndroid Build Coastguard Worker MaskWebSocketFramePayloadByBytes(
210*6777b538SAndroid Build Coastguard Worker masking_key, frame_offset % kMaskingKeyLength, data, end);
211*6777b538SAndroid Build Coastguard Worker return;
212*6777b538SAndroid Build Coastguard Worker }
213*6777b538SAndroid Build Coastguard Worker const size_t data_modulus =
214*6777b538SAndroid Build Coastguard Worker reinterpret_cast<size_t>(data) % kPackedMaskKeySize;
215*6777b538SAndroid Build Coastguard Worker char* const aligned_begin =
216*6777b538SAndroid Build Coastguard Worker data_modulus == 0 ? data : (data + kPackedMaskKeySize - data_modulus);
217*6777b538SAndroid Build Coastguard Worker // Guaranteed by the above check for small data_size.
218*6777b538SAndroid Build Coastguard Worker DCHECK(aligned_begin < end);
219*6777b538SAndroid Build Coastguard Worker MaskWebSocketFramePayloadByBytes(
220*6777b538SAndroid Build Coastguard Worker masking_key, frame_offset % kMaskingKeyLength, data, aligned_begin);
221*6777b538SAndroid Build Coastguard Worker const size_t end_modulus = reinterpret_cast<size_t>(end) % kPackedMaskKeySize;
222*6777b538SAndroid Build Coastguard Worker char* const aligned_end = end - end_modulus;
223*6777b538SAndroid Build Coastguard Worker // Guaranteed by the above check for small data_size.
224*6777b538SAndroid Build Coastguard Worker DCHECK(aligned_end > aligned_begin);
225*6777b538SAndroid Build Coastguard Worker // Create a version of the mask which is rotated by the appropriate offset
226*6777b538SAndroid Build Coastguard Worker // for our alignment. The "trick" here is that 0 XORed with the mask will
227*6777b538SAndroid Build Coastguard Worker // give the value of the mask for the appropriate byte.
228*6777b538SAndroid Build Coastguard Worker char realigned_mask[kMaskingKeyLength] = {};
229*6777b538SAndroid Build Coastguard Worker MaskWebSocketFramePayloadByBytes(
230*6777b538SAndroid Build Coastguard Worker masking_key,
231*6777b538SAndroid Build Coastguard Worker (frame_offset + aligned_begin - data) % kMaskingKeyLength,
232*6777b538SAndroid Build Coastguard Worker realigned_mask,
233*6777b538SAndroid Build Coastguard Worker realigned_mask + kMaskingKeyLength);
234*6777b538SAndroid Build Coastguard Worker
235*6777b538SAndroid Build Coastguard Worker for (size_t i = 0; i < kPackedMaskKeySize; i += kMaskingKeyLength) {
236*6777b538SAndroid Build Coastguard Worker // memcpy() is allegedly blessed by the C++ standard for type-punning.
237*6777b538SAndroid Build Coastguard Worker memcpy(reinterpret_cast<char*>(&packed_mask_key) + i,
238*6777b538SAndroid Build Coastguard Worker realigned_mask,
239*6777b538SAndroid Build Coastguard Worker kMaskingKeyLength);
240*6777b538SAndroid Build Coastguard Worker }
241*6777b538SAndroid Build Coastguard Worker
242*6777b538SAndroid Build Coastguard Worker // The main loop.
243*6777b538SAndroid Build Coastguard Worker for (char* merged = aligned_begin; merged != aligned_end;
244*6777b538SAndroid Build Coastguard Worker merged += kPackedMaskKeySize) {
245*6777b538SAndroid Build Coastguard Worker // This is not quite standard-compliant C++. However, the standard-compliant
246*6777b538SAndroid Build Coastguard Worker // equivalent (using memcpy()) compiles to slower code using g++. In
247*6777b538SAndroid Build Coastguard Worker // practice, this will work for the compilers and architectures currently
248*6777b538SAndroid Build Coastguard Worker // supported by Chromium, and the tests are extremely unlikely to pass if a
249*6777b538SAndroid Build Coastguard Worker // future compiler/architecture breaks it.
250*6777b538SAndroid Build Coastguard Worker *reinterpret_cast<PackedMaskType*>(merged) ^= packed_mask_key;
251*6777b538SAndroid Build Coastguard Worker }
252*6777b538SAndroid Build Coastguard Worker
253*6777b538SAndroid Build Coastguard Worker MaskWebSocketFramePayloadByBytes(
254*6777b538SAndroid Build Coastguard Worker masking_key,
255*6777b538SAndroid Build Coastguard Worker (frame_offset + (aligned_end - data)) % kMaskingKeyLength,
256*6777b538SAndroid Build Coastguard Worker aligned_end,
257*6777b538SAndroid Build Coastguard Worker end);
258*6777b538SAndroid Build Coastguard Worker }
259*6777b538SAndroid Build Coastguard Worker
260*6777b538SAndroid Build Coastguard Worker } // namespace net
261