summaryrefslogtreecommitdiffstats
path: root/src
diff options
context:
space:
mode:
Diffstat (limited to 'src')
-rw-r--r--src/AFC.c51
-rw-r--r--src/AFC.h10
-rw-r--r--src/Makefile.am8
-rw-r--r--src/MobileSync.c305
-rw-r--r--src/MobileSync.h39
-rw-r--r--src/initconf.c30
-rw-r--r--src/lockdown.c921
-rw-r--r--src/lockdown.h17
-rw-r--r--src/plist.c245
-rw-r--r--src/plist.h38
-rw-r--r--src/usbmux.c3
-rw-r--r--src/usbmux.h20
-rw-r--r--src/userpref.c10
-rw-r--r--src/userpref.h2
-rw-r--r--src/utils.c25
-rw-r--r--src/utils.h4
16 files changed, 906 insertions, 822 deletions
diff --git a/src/AFC.c b/src/AFC.c
index cd24cc6..67d37f3 100644
--- a/src/AFC.c
+++ b/src/AFC.c
@@ -21,8 +21,7 @@
21 21
22#include <stdio.h> 22#include <stdio.h>
23#include "AFC.h" 23#include "AFC.h"
24#include "plist.h" 24
25#include "utils.h"
26 25
27 26
28// This is the maximum size an AFC data packet can be 27// This is the maximum size an AFC data packet can be
@@ -246,7 +245,7 @@ static int receive_AFC_data(iphone_afc_client_t client, char **dump_here)
246 return retval; 245 return retval;
247 } 246 }
248 247
249 uint32 param1 = buffer[sizeof(AFCPacket)]; 248 uint32_t param1 = buffer[sizeof(AFCPacket)];
250 free(buffer); 249 free(buffer);
251 250
252 if (r_packet->operation == AFC_ERROR && !(client->afc_packet->operation == AFC_DELETE && param1 == 7)) { 251 if (r_packet->operation == AFC_ERROR && !(client->afc_packet->operation == AFC_DELETE && param1 == 7)) {
@@ -475,7 +474,7 @@ iphone_error_t iphone_afc_delete_file(iphone_afc_client_t client, const char *pa
475iphone_error_t iphone_afc_rename_file(iphone_afc_client_t client, const char *from, const char *to) 474iphone_error_t iphone_afc_rename_file(iphone_afc_client_t client, const char *from, const char *to)
476{ 475{
477 char *response = NULL; 476 char *response = NULL;
478 char *send = (char *) malloc(sizeof(char) * (strlen(from) + strlen(to) + 1 + sizeof(uint32))); 477 char *send = (char *) malloc(sizeof(char) * (strlen(from) + strlen(to) + 1 + sizeof(uint32_t)));
479 int bytes = 0; 478 int bytes = 0;
480 479
481 if (!client || !from || !to || !client->afc_packet || !client->connection) 480 if (!client || !from || !to || !client->afc_packet || !client->connection)
@@ -661,7 +660,7 @@ iphone_afc_open_file(iphone_afc_client_t client, const char *filename,
661 iphone_afc_file_mode_t file_mode, iphone_afc_file_t * file) 660 iphone_afc_file_mode_t file_mode, iphone_afc_file_t * file)
662{ 661{
663 iphone_afc_file_t file_loc = NULL; 662 iphone_afc_file_t file_loc = NULL;
664 uint32 ag = 0; 663 uint32_t ag = 0;
665 int bytes = 0, length = 0; 664 int bytes = 0, length = 0;
666 char *data = (char *) malloc(sizeof(char) * (8 + strlen(filename) + 1)); 665 char *data = (char *) malloc(sizeof(char) * (8 + strlen(filename) + 1));
667 666
@@ -796,8 +795,8 @@ iphone_afc_write_file(iphone_afc_client_t client, iphone_afc_file_t file,
796{ 795{
797 char *acknowledgement = NULL; 796 char *acknowledgement = NULL;
798 const int MAXIMUM_WRITE_SIZE = 1 << 15; 797 const int MAXIMUM_WRITE_SIZE = 1 << 15;
799 uint32 zero = 0, current_count = 0, i = 0; 798 uint32_t zero = 0, current_count = 0, i = 0;
800 uint32 segments = (length / MAXIMUM_WRITE_SIZE); 799 uint32_t segments = (length / MAXIMUM_WRITE_SIZE);
801 int bytes_loc = 0; 800 int bytes_loc = 0;
802 char *out_buffer = NULL; 801 char *out_buffer = NULL;
803 802
@@ -815,8 +814,8 @@ iphone_afc_write_file(iphone_afc_client_t client, iphone_afc_file_t file,
815 client->afc_packet->entire_length = client->afc_packet->this_length + MAXIMUM_WRITE_SIZE; 814 client->afc_packet->entire_length = client->afc_packet->this_length + MAXIMUM_WRITE_SIZE;
816 client->afc_packet->operation = AFC_WRITE; 815 client->afc_packet->operation = AFC_WRITE;
817 out_buffer = (char *) malloc(sizeof(char) * client->afc_packet->entire_length - sizeof(AFCPacket)); 816 out_buffer = (char *) malloc(sizeof(char) * client->afc_packet->entire_length - sizeof(AFCPacket));
818 memcpy(out_buffer, (char *) &file->filehandle, sizeof(uint32)); 817 memcpy(out_buffer, (char *) &file->filehandle, sizeof(uint32_t));
819 memcpy(out_buffer + 4, (char *) &zero, sizeof(uint32)); 818 memcpy(out_buffer + 4, (char *) &zero, sizeof(uint32_t));
820 memcpy(out_buffer + 8, data + current_count, MAXIMUM_WRITE_SIZE); 819 memcpy(out_buffer + 8, data + current_count, MAXIMUM_WRITE_SIZE);
821 bytes_loc = dispatch_AFC_packet(client, out_buffer, MAXIMUM_WRITE_SIZE + 8); 820 bytes_loc = dispatch_AFC_packet(client, out_buffer, MAXIMUM_WRITE_SIZE + 8);
822 if (bytes_loc < 0) { 821 if (bytes_loc < 0) {
@@ -848,8 +847,8 @@ iphone_afc_write_file(iphone_afc_client_t client, iphone_afc_file_t file,
848 client->afc_packet->entire_length = client->afc_packet->this_length + (length - current_count); 847 client->afc_packet->entire_length = client->afc_packet->this_length + (length - current_count);
849 client->afc_packet->operation = AFC_WRITE; 848 client->afc_packet->operation = AFC_WRITE;
850 out_buffer = (char *) malloc(sizeof(char) * client->afc_packet->entire_length - sizeof(AFCPacket)); 849 out_buffer = (char *) malloc(sizeof(char) * client->afc_packet->entire_length - sizeof(AFCPacket));
851 memcpy(out_buffer, (char *) &file->filehandle, sizeof(uint32)); 850 memcpy(out_buffer, (char *) &file->filehandle, sizeof(uint32_t));
852 memcpy(out_buffer + 4, (char *) &zero, sizeof(uint32)); 851 memcpy(out_buffer + 4, (char *) &zero, sizeof(uint32_t));
853 memcpy(out_buffer + 8, data + current_count, (length - current_count)); 852 memcpy(out_buffer + 8, data + current_count, (length - current_count));
854 bytes_loc = dispatch_AFC_packet(client, out_buffer, (length - current_count) + 8); 853 bytes_loc = dispatch_AFC_packet(client, out_buffer, (length - current_count) + 8);
855 free(out_buffer); 854 free(out_buffer);
@@ -884,7 +883,7 @@ iphone_error_t iphone_afc_close_file(iphone_afc_client_t client, iphone_afc_file
884 if (!client || !file) 883 if (!client || !file)
885 return IPHONE_E_INVALID_ARG; 884 return IPHONE_E_INVALID_ARG;
886 char *buffer = malloc(sizeof(char) * 8); 885 char *buffer = malloc(sizeof(char) * 8);
887 uint32 zero = 0; 886 uint32_t zero = 0;
888 int bytes = 0; 887 int bytes = 0;
889 888
890 afc_lock(client); 889 afc_lock(client);
@@ -892,8 +891,8 @@ iphone_error_t iphone_afc_close_file(iphone_afc_client_t client, iphone_afc_file
892 log_debug_msg("afc_close_file: File handle %i\n", file->filehandle); 891 log_debug_msg("afc_close_file: File handle %i\n", file->filehandle);
893 892
894 // Send command 893 // Send command
895 memcpy(buffer, &file->filehandle, sizeof(uint32)); 894 memcpy(buffer, &file->filehandle, sizeof(uint32_t));
896 memcpy(buffer + sizeof(uint32), &zero, sizeof(zero)); 895 memcpy(buffer + sizeof(uint32_t), &zero, sizeof(zero));
897 client->afc_packet->operation = AFC_FILE_CLOSE; 896 client->afc_packet->operation = AFC_FILE_CLOSE;
898 client->afc_packet->entire_length = client->afc_packet->this_length = 0; 897 client->afc_packet->entire_length = client->afc_packet->this_length = 0;
899 bytes = dispatch_AFC_packet(client, buffer, sizeof(char) * 8); 898 bytes = dispatch_AFC_packet(client, buffer, sizeof(char) * 8);
@@ -929,7 +928,7 @@ iphone_error_t iphone_afc_close_file(iphone_afc_client_t client, iphone_afc_file
929iphone_error_t iphone_afc_seek_file(iphone_afc_client_t client, iphone_afc_file_t file, int seekpos) 928iphone_error_t iphone_afc_seek_file(iphone_afc_client_t client, iphone_afc_file_t file, int seekpos)
930{ 929{
931 char *buffer = (char *) malloc(sizeof(char) * 24); 930 char *buffer = (char *) malloc(sizeof(char) * 24);
932 uint32 seekto = 0, zero = 0; 931 uint32_t seekto = 0, zero = 0;
933 int bytes = 0; 932 int bytes = 0;
934 933
935 if (seekpos < 0) 934 if (seekpos < 0)
@@ -939,12 +938,12 @@ iphone_error_t iphone_afc_seek_file(iphone_afc_client_t client, iphone_afc_file_
939 938
940 // Send the command 939 // Send the command
941 seekto = seekpos; 940 seekto = seekpos;
942 memcpy(buffer, &file->filehandle, sizeof(uint32)); // handle 941 memcpy(buffer, &file->filehandle, sizeof(uint32_t)); // handle
943 memcpy(buffer + 4, &zero, sizeof(uint32)); // pad 942 memcpy(buffer + 4, &zero, sizeof(uint32_t)); // pad
944 memcpy(buffer + 8, &zero, sizeof(uint32)); // fromwhere 943 memcpy(buffer + 8, &zero, sizeof(uint32_t)); // fromwhere
945 memcpy(buffer + 12, &zero, sizeof(uint32)); // pad 944 memcpy(buffer + 12, &zero, sizeof(uint32_t)); // pad
946 memcpy(buffer + 16, &seekto, sizeof(uint32)); // offset 945 memcpy(buffer + 16, &seekto, sizeof(uint32_t)); // offset
947 memcpy(buffer + 20, &zero, sizeof(uint32)); // pad 946 memcpy(buffer + 20, &zero, sizeof(uint32_t)); // pad
948 client->afc_packet->operation = AFC_FILE_SEEK; 947 client->afc_packet->operation = AFC_FILE_SEEK;
949 client->afc_packet->this_length = client->afc_packet->entire_length = 0; 948 client->afc_packet->this_length = client->afc_packet->entire_length = 0;
950 bytes = dispatch_AFC_packet(client, buffer, 23); 949 bytes = dispatch_AFC_packet(client, buffer, 23);
@@ -984,14 +983,14 @@ iphone_error_t iphone_afc_truncate_file(iphone_afc_client_t client, iphone_afc_f
984{ 983{
985 char *buffer = (char *) malloc(sizeof(char) * 16); 984 char *buffer = (char *) malloc(sizeof(char) * 16);
986 int bytes = 0; 985 int bytes = 0;
987 uint32 zero = 0; 986 uint32_t zero = 0;
988 987
989 afc_lock(client); 988 afc_lock(client);
990 989
991 // Send command 990 // Send command
992 memcpy(buffer, &file->filehandle, sizeof(uint32)); // handle 991 memcpy(buffer, &file->filehandle, sizeof(uint32_t)); // handle
993 memcpy(buffer + 4, &zero, sizeof(uint32)); // pad 992 memcpy(buffer + 4, &zero, sizeof(uint32_t)); // pad
994 memcpy(buffer + 8, &newsize, sizeof(uint32)); // newsize 993 memcpy(buffer + 8, &newsize, sizeof(uint32_t)); // newsize
995 memcpy(buffer + 12, &zero, 3); // pad 994 memcpy(buffer + 12, &zero, 3); // pad
996 client->afc_packet->operation = AFC_FILE_TRUNCATE; 995 client->afc_packet->operation = AFC_FILE_TRUNCATE;
997 client->afc_packet->this_length = client->afc_packet->entire_length = 0; 996 client->afc_packet->this_length = client->afc_packet->entire_length = 0;
@@ -1017,7 +1016,7 @@ iphone_error_t iphone_afc_truncate_file(iphone_afc_client_t client, iphone_afc_f
1017 } 1016 }
1018} 1017}
1019 1018
1020uint32 iphone_afc_get_file_handle(iphone_afc_file_t file) 1019uint32_t iphone_afc_get_file_handle(iphone_afc_file_t file)
1021{ 1020{
1022 return file->filehandle; 1021 return file->filehandle;
1023} 1022}
diff --git a/src/AFC.h b/src/AFC.h
index 463c13e..5e4d17c 100644
--- a/src/AFC.h
+++ b/src/AFC.h
@@ -29,12 +29,12 @@
29#include <glib.h> 29#include <glib.h>
30 30
31typedef struct { 31typedef struct {
32 uint32 header1, header2; 32 uint32_t header1, header2;
33 uint32 entire_length, unknown1, this_length, unknown2, packet_num, unknown3, operation, unknown4; 33 uint32_t entire_length, unknown1, this_length, unknown2, packet_num, unknown3, operation, unknown4;
34} AFCPacket; 34} AFCPacket;
35 35
36typedef struct { 36typedef struct {
37 uint32 filehandle, unknown1, size, unknown2; 37 uint32_t filehandle, unknown1, size, unknown2;
38} AFCFilePacket; 38} AFCFilePacket;
39 39
40typedef struct __AFCToken { 40typedef struct __AFCToken {
@@ -51,7 +51,7 @@ struct iphone_afc_client_int {
51}; 51};
52 52
53struct iphone_afc_file_int { 53struct iphone_afc_file_int {
54 uint32 filehandle, blocks, size, type; 54 uint32_t filehandle, blocks, size, type;
55}; 55};
56 56
57 57
@@ -74,4 +74,4 @@ enum {
74 AFC_WRITE = 0x00000010 74 AFC_WRITE = 0x00000010
75}; 75};
76 76
77uint32 iphone_afc_get_file_handle(iphone_afc_file_t file); 77uint32_t iphone_afc_get_file_handle(iphone_afc_file_t file);
diff --git a/src/Makefile.am b/src/Makefile.am
index 382be1f..1b97f45 100644
--- a/src/Makefile.am
+++ b/src/Makefile.am
@@ -1,15 +1,15 @@
1INCLUDES = -I$(top_srcdir)/include 1INCLUDES = -I$(top_srcdir)/include
2 2
3AM_CFLAGS = $(libxml2_CFLAGS) $(libusb_CFLAGS) $(libglib2_CFLAGS) $(libgnutls_CFLAGS) $(libtasn1_CFLAGS) $(libgthread2_CFLAGS) -g -Wall 3AM_CFLAGS = $(libxml2_CFLAGS) $(libusb_CFLAGS) $(libglib2_CFLAGS) $(libgnutls_CFLAGS) $(libtasn1_CFLAGS) $(libgthread2_CFLAGS) $(libplist_CFLAGS) -g -Wall
4AM_LDFLAGS = $(libxml2_LIBS) $(libusb_LIBS) $(libglib2_LIBS) $(libgnutls_LIBS) $(libtasn1_LIBS) $(libgthread2_LIBS) 4AM_LDFLAGS = $(libxml2_LIBS) $(libusb_LIBS) $(libglib2_LIBS) $(libgnutls_LIBS) $(libtasn1_LIBS) $(libgthread2_LIBS) $(libplist_LIBS)
5 5
6bin_PROGRAMS = libiphone-initconf 6bin_PROGRAMS = libiphone-initconf
7 7
8 8
9libiphone_initconf_SOURCES = initconf.c userpref.c lockdown.c plist.c usbmux.c iphone.c utils.c 9libiphone_initconf_SOURCES = initconf.c userpref.c utils.c
10libiphone_initconf_CFLAGS = $(libgthread2_CFLAGS) $(AM_CFLAGS) 10libiphone_initconf_CFLAGS = $(libgthread2_CFLAGS) $(AM_CFLAGS)
11libiphone_initconf_LDFLAGS = $(libgthread2_LIBS) $(AM_LDFLAGS) 11libiphone_initconf_LDFLAGS = $(libgthread2_LIBS) $(AM_LDFLAGS)
12 12
13 13
14lib_LTLIBRARIES = libiphone.la 14lib_LTLIBRARIES = libiphone.la
15libiphone_la_SOURCES = usbmux.c iphone.c plist.c lockdown.c AFC.c userpref.c utils.c 15libiphone_la_SOURCES = usbmux.c iphone.c lockdown.c AFC.c userpref.c utils.c MobileSync.c
diff --git a/src/MobileSync.c b/src/MobileSync.c
new file mode 100644
index 0000000..752aee9
--- /dev/null
+++ b/src/MobileSync.c
@@ -0,0 +1,305 @@
1/*
2 * MobileSync.c
3 * Contains functions for the built-in MobileSync client.
4 *
5 * Copyright (c) 2009 Jonathan Beck All Rights Reserved.
6 *
7 * This library is free software; you can redistribute it and/or
8 * modify it under the terms of the GNU Lesser General Public
9 * License as published by the Free Software Foundation; either
10 * version 2.1 of the License, or (at your option) any later version.
11 *
12 * This library is distributed in the hope that it will be useful,
13 * but WITHOUT ANY WARRANTY; without even the implied warranty of
14 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
15 * Lesser General Public License for more details.
16 *
17 * You should have received a copy of the GNU Lesser General Public
18 * License along with this library; if not, write to the Free Software
19 * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA
20 */
21
22#include "MobileSync.h"
23#include <plist/plist.h>
24#include <string.h>
25
26
27#define MSYNC_VERSION_INT1 100
28#define MSYNC_VERSION_INT2 100
29
30iphone_error_t iphone_msync_new_client(iphone_device_t device, int src_port, int dst_port,
31 iphone_msync_client_t * client)
32{
33 if (!device || src_port == 0 || dst_port == 0 || !client || *client)
34 return IPHONE_E_INVALID_ARG;
35
36 iphone_error_t ret = IPHONE_E_UNKNOWN_ERROR;
37
38 iphone_msync_client_t client_loc = (iphone_msync_client_t) malloc(sizeof(struct iphone_msync_client_int));
39
40 // Attempt connection
41 client_loc->connection = NULL;
42 ret = iphone_mux_new_client(device, src_port, dst_port, &client_loc->connection);
43 if (IPHONE_E_SUCCESS != ret || !client_loc->connection) {
44 free(client_loc);
45 return ret;
46 }
47 //perform handshake
48 plist_t array = NULL;
49
50 //first receive version
51 ret = iphone_msync_recv(client_loc, &array);
52
53 plist_t msg_node =
54 plist_find_node_by_string(array, "DLMessageVersionExchange");
55 plist_t ver_1 = plist_get_next_sibling(msg_node);
56 plist_t ver_2 = plist_get_next_sibling(ver_1);
57
58 plist_type ver_1_type = plist_get_node_type(ver_1);
59 plist_type ver_2_type = plist_get_node_type(ver_2);
60
61 if (PLIST_UINT == ver_1_type && PLIST_UINT == ver_2_type) {
62
63 uint64_t ver_1_val = 0;
64 uint64_t ver_2_val = 0;
65
66 plist_get_uint_val(ver_1, &ver_1_val);
67 plist_get_uint_val(ver_2, &ver_2_val);
68
69 plist_free(array);
70 array = NULL;
71
72 if (ver_1_type == PLIST_UINT && ver_2_type == PLIST_UINT && ver_1_val == MSYNC_VERSION_INT1
73 && ver_2_val == MSYNC_VERSION_INT2) {
74
75 array = plist_new_array();
76 plist_add_sub_string_el(array, "DLMessageVersionExchange");
77 plist_add_sub_string_el(array, "DLVersionsOk");
78
79 ret = iphone_msync_send(client_loc, array);
80
81 plist_free(array);
82 array = NULL;
83
84 ret = iphone_msync_recv(client_loc, &array);
85 plist_t rep_node =
86 plist_find_node_by_string(array, "DLMessageDeviceReady");
87
88 if (rep_node) {
89 ret = IPHONE_E_SUCCESS;
90 *client = client_loc;
91 }
92 plist_free(array);
93 array = NULL;
94
95 }
96 }
97
98 if (IPHONE_E_SUCCESS != ret)
99 iphone_msync_free_client(client_loc);
100
101 return ret;
102}
103
104static void iphone_msync_stop_session(iphone_msync_client_t client)
105{
106 if (!client)
107 return;
108
109 plist_t array = plist_new_array();
110 plist_add_sub_string_el(array, "DLMessageDisconnect");
111 plist_add_sub_string_el(array, "All done, thanks for the memories");
112
113 iphone_msync_send(client, array);
114 plist_free(array);
115 array = NULL;
116}
117
118iphone_error_t iphone_msync_free_client(iphone_msync_client_t client)
119{
120 if (!client)
121 return IPHONE_E_INVALID_ARG;
122
123 iphone_msync_stop_session(client);
124 return iphone_mux_free_client(client->connection);
125}
126
127/** Polls the iPhone for MobileSync data.
128 *
129 * @param client The MobileSync client
130 * @param dump_data The pointer to the location of the buffer in which to store
131 * the received data
132 * @param recv_byhtes The number of bytes received
133 *
134 * @return an error code
135 */
136iphone_error_t iphone_msync_recv(iphone_msync_client_t client, plist_t * plist)
137{
138 if (!client || !plist || (plist && *plist))
139 return IPHONE_E_INVALID_ARG;
140 iphone_error_t ret = IPHONE_E_UNKNOWN_ERROR;
141 char *receive;
142 uint32_t datalen = 0, bytes = 0;
143
144 ret = iphone_mux_recv(client->connection, (char *) &datalen, sizeof(datalen), &bytes);
145 datalen = ntohl(datalen);
146
147 receive = (char *) malloc(sizeof(char) * datalen);
148 ret = iphone_mux_recv(client->connection, receive, datalen, &bytes);
149
150 plist_from_bin(receive, bytes, plist);
151
152 char *XMLContent = NULL;
153 uint32_t length = 0;
154 plist_to_xml(*plist, &XMLContent, &length);
155 log_dbg_msg(DBGMASK_MOBILESYNC, "Recv msg :\nsize : %i\nbuffer :\n%s\n", length, XMLContent);
156 free(XMLContent);
157
158 return ret;
159}
160
161/** Sends MobileSync data to the iPhone
162 *
163 * @note This function is low-level and should only be used if you need to send
164 * a new type of message.
165 *
166 * @param client The MobileSync client
167 * @param raw_data The null terminated string buffer to send
168 * @param length The length of data to send
169 * @param sent_bytes The number of bytes sent
170 *
171 * @return an error code
172 */
173iphone_error_t iphone_msync_send(iphone_msync_client_t client, plist_t plist)
174{
175 if (!client || !plist)
176 return IPHONE_E_INVALID_ARG;
177
178 char *XMLContent = NULL;
179 uint32_t length = 0;
180 plist_to_xml(plist, &XMLContent, &length);
181 log_dbg_msg(DBGMASK_MOBILESYNC, "Send msg :\nsize : %i\nbuffer :\n%s\n", length, XMLContent);
182 free(XMLContent);
183
184 char *content = NULL;
185 length = 0;
186
187 plist_to_bin(plist, &content, &length);
188
189 char *real_query;
190 int bytes;
191 iphone_error_t ret = IPHONE_E_UNKNOWN_ERROR;
192
193 real_query = (char *) malloc(sizeof(char) * (length + 4));
194 length = htonl(length);
195 memcpy(real_query, &length, sizeof(length));
196 memcpy(real_query + 4, content, ntohl(length));
197
198 ret = iphone_mux_send(client->connection, real_query, ntohl(length) + sizeof(length), &bytes);
199 free(real_query);
200 return ret;
201}
202
203iphone_error_t iphone_msync_get_all_contacts(iphone_msync_client_t client)
204{
205 if (!client)
206 return IPHONE_E_INVALID_ARG;
207
208 iphone_error_t ret = IPHONE_E_UNKNOWN_ERROR;
209 plist_t array = NULL;
210
211 array = plist_new_array();
212 plist_add_sub_string_el(array, "SDMessageSyncDataClassWithDevice");
213 plist_add_sub_string_el(array, "com.apple.Contacts");
214 plist_add_sub_string_el(array, "---");
215 plist_add_sub_string_el(array, "2009-01-09 18:03:58 +0100");
216 plist_add_sub_uint_el(array, 106);
217 plist_add_sub_string_el(array, "___EmptyParameterString___");
218
219 ret = iphone_msync_send(client, array);
220 plist_free(array);
221 array = NULL;
222
223 ret = iphone_msync_recv(client, &array);
224
225 plist_t rep_node = plist_find_node(array, PLIST_STRING, "SDSyncTypeSlow", strlen("SDSyncTypeSlow"));
226
227 if (!rep_node)
228 return ret;
229
230 plist_free(array);
231 array = NULL;
232
233 array = plist_new_array();
234 plist_add_sub_string_el(array, "SDMessageGetAllRecordsFromDevice");
235 plist_add_sub_string_el(array, "com.apple.Contacts");
236
237
238 ret = iphone_msync_send(client, array);
239 plist_free(array);
240 array = NULL;
241
242 ret = iphone_msync_recv(client, &array);
243
244 plist_t contact_node;
245 plist_t switch_node;
246
247 contact_node = plist_find_node(array, PLIST_STRING, "com.apple.Contacts", strlen("com.apple.Contacts"));
248 switch_node =
249 plist_find_node(array, PLIST_STRING, "SDMessageDeviceReadyToReceiveChanges",
250 strlen("SDMessageDeviceReadyToReceiveChanges"));
251
252 while (NULL == switch_node) {
253
254 plist_free(array);
255 array = NULL;
256
257 array = plist_new_array();
258 plist_add_sub_string_el(array, "SDMessageAcknowledgeChangesFromDevice");
259 plist_add_sub_string_el(array, "com.apple.Contacts");
260
261 ret = iphone_msync_send(client, array);
262 plist_free(array);
263 array = NULL;
264
265 ret = iphone_msync_recv(client, &array);
266
267 contact_node = plist_find_node(array, PLIST_STRING, "com.apple.Contacts", strlen("com.apple.Contacts"));
268 switch_node =
269 plist_find_node(array, PLIST_STRING, "SDMessageDeviceReadyToReceiveChanges",
270 strlen("SDMessageDeviceReadyToReceiveChanges"));
271 }
272
273 array = plist_new_array();
274 plist_add_sub_string_el(array, "DLMessagePing");
275 plist_add_sub_string_el(array, "Preparing to get changes for device");
276
277 ret = iphone_msync_send(client, array);
278 plist_free(array);
279 array = NULL;
280
281 array = plist_new_array();
282 plist_add_sub_string_el(array, "SDMessageProcessChanges");
283 plist_add_sub_string_el(array, "com.apple.Contacts");
284 plist_add_sub_node(array, plist_new_dict());
285 plist_add_sub_bool_el(array, 0);
286 plist_t dict = plist_new_dict();
287 plist_add_sub_node(array, dict);
288 plist_add_sub_key_el(dict, "SyncDeviceLinkEntityNamesKey");
289 plist_t array2 = plist_new_array();
290 plist_add_sub_string_el(array2, "com.apple.contacts.Contact");
291 plist_add_sub_string_el(array2, "com.apple.contacts.Group");
292 plist_add_sub_key_el(dict, "SyncDeviceLinkAllRecordsOfPulledEntityTypeSentKey");
293 plist_add_sub_bool_el(dict, 0);
294
295 ret = iphone_msync_send(client, array);
296 plist_free(array);
297 array = NULL;
298
299 ret = iphone_msync_recv(client, &array);
300 plist_free(array);
301 array = NULL;
302
303
304 return ret;
305}
diff --git a/src/MobileSync.h b/src/MobileSync.h
new file mode 100644
index 0000000..7655b59
--- /dev/null
+++ b/src/MobileSync.h
@@ -0,0 +1,39 @@
1/*
2 * MobileSync.h
3 * Definitions for the built-in MobileSync client
4 *
5 * Copyright (c) 2009 Jonathan Beck All Rights Reserved.
6 *
7 * This library is free software; you can redistribute it and/or
8 * modify it under the terms of the GNU Lesser General Public
9 * License as published by the Free Software Foundation; either
10 * version 2.1 of the License, or (at your option) any later version.
11 *
12 * This library is distributed in the hope that it will be useful,
13 * but WITHOUT ANY WARRANTY; without even the implied warranty of
14 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
15 * Lesser General Public License for more details.
16 *
17 * You should have received a copy of the GNU Lesser General Public
18 * License along with this library; if not, write to the Free Software
19 * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA
20 */
21#ifndef MOBILESYNC_H
22#define MOBILESYNC_H
23
24#include "usbmux.h"
25#include "iphone.h"
26#include "utils.h"
27
28#include <plist/plist.h>
29
30
31
32struct iphone_msync_client_int {
33 iphone_umux_client_t connection;
34};
35
36
37iphone_error_t iphone_msync_get_all_contacts(iphone_msync_client_t client);
38
39#endif
diff --git a/src/initconf.c b/src/initconf.c
index 205c97a..538f344 100644
--- a/src/initconf.c
+++ b/src/initconf.c
@@ -28,7 +28,6 @@
28 28
29#include "libiphone/libiphone.h" 29#include "libiphone/libiphone.h"
30#include "userpref.h" 30#include "userpref.h"
31#include "lockdown.h"
32#include "utils.h" 31#include "utils.h"
33 32
34/** Generates a 2048 byte key, split into a function so that it can be run in a 33/** Generates a 2048 byte key, split into a function so that it can be run in a
@@ -60,6 +59,35 @@ static void progress_bar(gpointer mutex)
60 g_thread_exit(0); 59 g_thread_exit(0);
61} 60}
62 61
62int get_rand(int min, int max)
63{
64 int retval = (rand() % (max - min)) + min;
65 return retval;
66}
67
68/** Generates a valid HostID (which is actually a UUID).
69 *
70 * @param A null terminated string containing a valid HostID.
71 */
72char *lockdownd_generate_hostid()
73{
74 char *hostid = (char *) malloc(sizeof(char) * 37); // HostID's are just UUID's, and UUID's are 36 characters long
75 const char *chars = "ABCDEF0123456789";
76 srand(time(NULL));
77 int i = 0;
78
79 for (i = 0; i < 36; i++) {
80 if (i == 8 || i == 13 || i == 18 || i == 23) {
81 hostid[i] = '-';
82 continue;
83 } else {
84 hostid[i] = chars[get_rand(0, 16)];
85 }
86 }
87 hostid[36] = '\0'; // make it a real string
88 return hostid;
89}
90
63int main(int argc, char *argv[]) 91int main(int argc, char *argv[])
64{ 92{
65 GThread *progress_thread, *key_thread; 93 GThread *progress_thread, *key_thread;
diff --git a/src/lockdown.c b/src/lockdown.c
index 2d85a03..a02e6a8 100644
--- a/src/lockdown.c
+++ b/src/lockdown.c
@@ -31,6 +31,9 @@
31#include <libtasn1.h> 31#include <libtasn1.h>
32#include <gnutls/x509.h> 32#include <gnutls/x509.h>
33 33
34#include <plist/plist.h>
35
36
34const ASN1_ARRAY_TYPE pkcs1_asn1_tab[] = { 37const ASN1_ARRAY_TYPE pkcs1_asn1_tab[] = {
35 {"PKCS1", 536872976, 0}, 38 {"PKCS1", 536872976, 0},
36 {0, 1073741836, 0}, 39 {0, 1073741836, 0},
@@ -40,35 +43,6 @@ const ASN1_ARRAY_TYPE pkcs1_asn1_tab[] = {
40 {0, 0, 0} 43 {0, 0, 0}
41}; 44};
42 45
43static int get_rand(int min, int max)
44{
45 int retval = (rand() % (max - min)) + min;
46 return retval;
47}
48
49/** Generates a valid HostID (which is actually a UUID).
50 *
51 * @param A null terminated string containing a valid HostID.
52 */
53char *lockdownd_generate_hostid(void)
54{
55 char *hostid = (char *) malloc(sizeof(char) * 37); // HostID's are just UUID's, and UUID's are 36 characters long
56 const char *chars = "ABCDEF0123456789";
57 srand(time(NULL));
58 int i = 0;
59
60 for (i = 0; i < 36; i++) {
61 if (i == 8 || i == 13 || i == 18 || i == 23) {
62 hostid[i] = '-';
63 continue;
64 } else {
65 hostid[i] = chars[get_rand(0, 16)];
66 }
67 }
68 hostid[36] = '\0'; // make it a real string
69 return hostid;
70}
71
72/** Creates a lockdownd client for the give iPhone. 46/** Creates a lockdownd client for the give iPhone.
73 * 47 *
74 * @param phone The iPhone to create a lockdownd client for 48 * @param phone The iPhone to create a lockdownd client for
@@ -101,57 +75,56 @@ iphone_lckd_client_t new_lockdownd_client(iphone_device_t phone)
101static void iphone_lckd_stop_session(iphone_lckd_client_t control) 75static void iphone_lckd_stop_session(iphone_lckd_client_t control)
102{ 76{
103 if (!control) 77 if (!control)
104 return; // IPHONE_E_INVALID_ARG; 78 return; //IPHONE_E_INVALID_ARG;
105 xmlDocPtr plist = new_plist(); 79
106 xmlNode *dict, *key;
107 char **dictionary;
108 int bytes = 0, i = 0;
109 iphone_error_t ret = IPHONE_E_UNKNOWN_ERROR; 80 iphone_error_t ret = IPHONE_E_UNKNOWN_ERROR;
110 81
111 log_debug_msg("lockdownd_stop_session() called\n"); 82 plist_t dict = plist_new_dict();
112 dict = add_child_to_plist(plist, "dict", "\n", NULL, 0); 83 plist_add_sub_key_el(dict, "Request");
113 key = add_key_str_dict_element(plist, dict, "Request", "StopSession", 1); 84 plist_add_sub_string_el(dict, "StopSession");
114 key = add_key_str_dict_element(plist, dict, "SessionID", control->session_id, 1); 85 plist_add_sub_key_el(dict, "SessionID");
86 plist_add_sub_string_el(dict, control->session_id);
115 87
116 char *XML_content; 88 log_dbg_msg(DBGMASK_LOCKDOWND, "iphone_lckd_stop_session() called\n");
117 uint32 length;
118 89
119 xmlDocDumpMemory(plist, (xmlChar **) & XML_content, &length); 90 ret = iphone_lckd_send(control, dict);
120 ret = iphone_lckd_send(control, XML_content, length, &bytes);
121 91
122 xmlFree(XML_content); 92 plist_free(dict);
123 xmlFreeDoc(plist); 93 dict = NULL;
124 plist = NULL; 94
125 ret = iphone_lckd_recv(control, &XML_content, &bytes); 95 ret = iphone_lckd_recv(control, &dict);
126 96
127 plist = xmlReadMemory(XML_content, bytes, NULL, NULL, 0);
128 if (!plist) {
129 log_debug_msg("lockdownd_stop_session(): IPHONE_E_PLIST_ERROR\n");
130 return; //IPHONE_E_PLIST_ERROR;
131 }
132 dict = xmlDocGetRootElement(plist);
133 for (dict = dict->children; dict; dict = dict->next) {
134 if (!xmlStrcmp(dict->name, "dict"))
135 break;
136 }
137 if (!dict) { 97 if (!dict) {
138 log_debug_msg("lockdownd_stop_session(): IPHONE_E_DICT_ERROR\n"); 98 log_dbg_msg(DBGMASK_LOCKDOWND, "lockdownd_stop_session(): IPHONE_E_PLIST_ERROR\n");
139 return; //IPHONE_E_DICT_ERROR; 99 return; // IPHONE_E_PLIST_ERROR;
140 } 100 }
141 dictionary = read_dict_element_strings(dict);
142 xmlFreeDoc(plist);
143 free(XML_content);
144 101
145 for (i = 0; dictionary[i]; i += 2) { 102 plist_t query_node = plist_find_node_by_string(dict, "StopSession");
146 if (!strcmp(dictionary[i], "Result") && !strcmp(dictionary[i + 1], "Success")) { 103 plist_t result_node = plist_get_next_sibling(query_node);
147 log_debug_msg("lockdownd_stop_session(): success\n"); 104 plist_t value_node = plist_get_next_sibling(result_node);
105
106 plist_type result_type = plist_get_node_type(result_node);
107 plist_type value_type = plist_get_node_type(value_node);
108
109 if (result_type == PLIST_KEY && value_type == PLIST_STRING) {
110
111 char *result_value = NULL;
112 char *value_value = NULL;
113
114 plist_get_key_val(result_node, &result_value);
115 plist_get_string_val(value_node, &value_value);
116
117 if (!strcmp(result_value, "Result") && !strcmp(value_value, "Success")) {
118 log_dbg_msg(DBGMASK_LOCKDOWND, "lockdownd_stop_session(): success\n");
148 ret = IPHONE_E_SUCCESS; 119 ret = IPHONE_E_SUCCESS;
149 break;
150 } 120 }
121 free(result_value);
122 free(value_value);
151 } 123 }
124 plist_free(dict);
125 dict = NULL;
152 126
153 free_dictionary(dictionary); 127 return; // ret;
154 return; //ret;
155} 128}
156 129
157/** 130/**
@@ -164,14 +137,14 @@ static void iphone_lckd_stop_session(iphone_lckd_client_t control)
164static void iphone_lckd_stop_SSL_session(iphone_lckd_client_t client) 137static void iphone_lckd_stop_SSL_session(iphone_lckd_client_t client)
165{ 138{
166 if (!client) { 139 if (!client) {
167 log_debug_msg("lockdownd_stop_SSL_session(): invalid argument!\n"); 140 log_dbg_msg(DBGMASK_LOCKDOWND, "lockdownd_stop_SSL_session(): invalid argument!\n");
168 return; 141 return;
169 } 142 }
170 143
171 if (client->in_SSL) { 144 if (client->in_SSL) {
172 log_debug_msg("Stopping SSL Session\n"); 145 log_dbg_msg(DBGMASK_LOCKDOWND, "Stopping SSL Session\n");
173 iphone_lckd_stop_session(client); 146 iphone_lckd_stop_session(client);
174 log_debug_msg("Sending SSL close notify\n"); 147 log_dbg_msg(DBGMASK_LOCKDOWND, "Sending SSL close notify\n");
175 gnutls_bye(*client->ssl_session, GNUTLS_SHUT_RDWR); 148 gnutls_bye(*client->ssl_session, GNUTLS_SHUT_RDWR);
176 } 149 }
177 if (client->ssl_session) { 150 if (client->ssl_session) {
@@ -217,13 +190,13 @@ iphone_error_t iphone_lckd_free_client(iphone_lckd_client_t client)
217 * 190 *
218 * @return The number of bytes received 191 * @return The number of bytes received
219 */ 192 */
220iphone_error_t iphone_lckd_recv(iphone_lckd_client_t client, char **dump_data, uint32_t * recv_bytes) 193iphone_error_t iphone_lckd_recv(iphone_lckd_client_t client, plist_t * plist)
221{ 194{
222 if (!client || !dump_data || !recv_bytes) 195 if (!client || !plist || (plist && *plist))
223 return IPHONE_E_INVALID_ARG; 196 return IPHONE_E_INVALID_ARG;
224 iphone_error_t ret = IPHONE_E_UNKNOWN_ERROR; 197 iphone_error_t ret = IPHONE_E_UNKNOWN_ERROR;
225 char *receive; 198 char *receive;
226 uint32 datalen = 0, bytes = 0; 199 uint32_t datalen = 0, bytes = 0;
227 200
228 if (!client->in_SSL) 201 if (!client->in_SSL)
229 ret = iphone_mux_recv(client->connection, (char *) &datalen, sizeof(datalen), &bytes); 202 ret = iphone_mux_recv(client->connection, (char *) &datalen, sizeof(datalen), &bytes);
@@ -242,8 +215,18 @@ iphone_error_t iphone_lckd_recv(iphone_lckd_client_t client, char **dump_data, u
242 if (bytes > 0) 215 if (bytes > 0)
243 ret = IPHONE_E_SUCCESS; 216 ret = IPHONE_E_SUCCESS;
244 } 217 }
245 *dump_data = receive; 218
246 *recv_bytes = bytes; 219 if (bytes <= 0) {
220 free(receive);
221 return IPHONE_E_NOT_ENOUGH_DATA;
222 }
223
224 plist_from_xml(receive, bytes, plist);
225 free(receive);
226
227 if (!*plist)
228 ret = IPHONE_E_PLIST_ERROR;
229
247 return ret; 230 return ret;
248} 231}
249 232
@@ -252,26 +235,31 @@ iphone_error_t iphone_lckd_recv(iphone_lckd_client_t client, char **dump_data, u
252 * @note This function is low-level and should only be used if you need to send 235 * @note This function is low-level and should only be used if you need to send
253 * a new type of message. 236 * a new type of message.
254 * 237 *
255 * @param control The lockdownd client 238 * @param client The lockdownd client
256 * @param raw_data The null terminated string buffer to send 239 * @param plist The plist to send
257 * @param length The length of data to send
258 * 240 *
259 * @return The number of bytes sent 241 * @return an error code (IPHONE_E_SUCCESS on success)
260 */ 242 */
261iphone_error_t iphone_lckd_send(iphone_lckd_client_t client, char *raw_data, uint32_t length, uint32_t * sent_bytes) 243iphone_error_t iphone_lckd_send(iphone_lckd_client_t client, plist_t plist)
262{ 244{
263 if (!client || !raw_data || length == 0 || !sent_bytes) 245 if (!client || !plist)
264 return IPHONE_E_INVALID_ARG; 246 return IPHONE_E_INVALID_ARG;
265 char *real_query; 247 char *real_query;
266 int bytes; 248 int bytes;
249 char *XMLContent = NULL;
250 uint32_t length = 0;
267 iphone_error_t ret = IPHONE_E_UNKNOWN_ERROR; 251 iphone_error_t ret = IPHONE_E_UNKNOWN_ERROR;
268 252
253 plist_to_xml(plist, &XMLContent, &length);
254 log_dbg_msg(DBGMASK_LOCKDOWND, "Send msg :\nsize : %i\nbuffer :\n%s\n", length, XMLContent);
255
256
269 real_query = (char *) malloc(sizeof(char) * (length + 4)); 257 real_query = (char *) malloc(sizeof(char) * (length + 4));
270 length = htonl(length); 258 length = htonl(length);
271 memcpy(real_query, &length, sizeof(length)); 259 memcpy(real_query, &length, sizeof(length));
272 memcpy(real_query + 4, raw_data, ntohl(length)); 260 memcpy(real_query + 4, XMLContent, ntohl(length));
273 log_debug_msg("lockdownd_send(): made the query, sending it along\n"); 261 free(XMLContent);
274 dump_debug_buffer("grpkt", real_query, ntohl(length) + 4); 262 log_dbg_msg(DBGMASK_LOCKDOWND, "lockdownd_send(): made the query, sending it along\n");
275 263
276 if (!client->in_SSL) 264 if (!client->in_SSL)
277 ret = iphone_mux_send(client->connection, real_query, ntohl(length) + sizeof(length), &bytes); 265 ret = iphone_mux_send(client->connection, real_query, ntohl(length) + sizeof(length), &bytes);
@@ -279,9 +267,9 @@ iphone_error_t iphone_lckd_send(iphone_lckd_client_t client, char *raw_data, uin
279 gnutls_record_send(*client->ssl_session, real_query, ntohl(length) + sizeof(length)); 267 gnutls_record_send(*client->ssl_session, real_query, ntohl(length) + sizeof(length));
280 ret = IPHONE_E_SUCCESS; 268 ret = IPHONE_E_SUCCESS;
281 } 269 }
282 log_debug_msg("lockdownd_send(): sent it!\n"); 270 log_dbg_msg(DBGMASK_LOCKDOWND, "lockdownd_send(): sent it!\n");
283 free(real_query); 271 free(real_query);
284 *sent_bytes = bytes; 272
285 return ret; 273 return ret;
286} 274}
287 275
@@ -297,49 +285,50 @@ iphone_error_t lockdownd_hello(iphone_lckd_client_t control)
297{ 285{
298 if (!control) 286 if (!control)
299 return IPHONE_E_INVALID_ARG; 287 return IPHONE_E_INVALID_ARG;
300 xmlDocPtr plist = new_plist(); 288
301 xmlNode *dict, *key;
302 char **dictionary;
303 int bytes = 0, i = 0;
304 iphone_error_t ret = IPHONE_E_UNKNOWN_ERROR; 289 iphone_error_t ret = IPHONE_E_UNKNOWN_ERROR;
305 290
306 log_debug_msg("lockdownd_hello() called\n"); 291 plist_t dict = plist_new_dict();
307 dict = add_child_to_plist(plist, "dict", "\n", NULL, 0); 292 plist_add_sub_key_el(dict, "Request");
308 key = add_key_str_dict_element(plist, dict, "Request", "QueryType", 1); 293 plist_add_sub_string_el(dict, "QueryType");
309 char *XML_content;
310 uint32 length;
311 294
312 xmlDocDumpMemory(plist, (xmlChar **) & XML_content, &length); 295 log_dbg_msg(DBGMASK_LOCKDOWND, "lockdownd_hello() called\n");
313 ret = iphone_lckd_send(control, XML_content, length, &bytes); 296 ret = iphone_lckd_send(control, dict);
314 297
315 xmlFree(XML_content); 298 plist_free(dict);
316 xmlFreeDoc(plist); 299 dict = NULL;
317 plist = NULL;
318 ret = iphone_lckd_recv(control, &XML_content, &bytes);
319 300
320 plist = xmlReadMemory(XML_content, bytes, NULL, NULL, 0); 301 ret = iphone_lckd_recv(control, &dict);
321 if (!plist) 302
322 return IPHONE_E_PLIST_ERROR; 303 if (IPHONE_E_SUCCESS != ret)
323 dict = xmlDocGetRootElement(plist); 304 return ret;
324 for (dict = dict->children; dict; dict = dict->next) { 305
325 if (!xmlStrcmp(dict->name, "dict")) 306 plist_t query_node = plist_find_node_by_string(dict, "QueryType");
326 break; 307 plist_t result_node = plist_get_next_sibling(query_node);
327 } 308 plist_t value_node = plist_get_next_sibling(result_node);
328 if (!dict) 309
329 return IPHONE_E_DICT_ERROR; 310 plist_type result_type = plist_get_node_type(result_node);
330 dictionary = read_dict_element_strings(dict); 311 plist_type value_type = plist_get_node_type(value_node);
331 xmlFreeDoc(plist); 312
332 free(XML_content); 313 if (result_type == PLIST_KEY && value_type == PLIST_STRING) {
333 314
334 for (i = 0; dictionary[i]; i += 2) { 315 char *result_value = NULL;
335 if (!strcmp(dictionary[i], "Result") && !strcmp(dictionary[i + 1], "Success")) { 316 char *value_value = NULL;
336 log_debug_msg("lockdownd_hello(): success\n"); 317
318 plist_get_key_val(result_node, &result_value);
319 plist_get_string_val(value_node, &value_value);
320
321 if (!strcmp(result_value, "Result") && !strcmp(value_value, "Success")) {
322 log_dbg_msg(DBGMASK_LOCKDOWND, "lockdownd_hello(): success\n");
337 ret = IPHONE_E_SUCCESS; 323 ret = IPHONE_E_SUCCESS;
338 break;
339 } 324 }
325 free(result_value);
326 free(value_value);
340 } 327 }
341 328
342 free_dictionary(dictionary); 329 plist_free(dict);
330 dict = NULL;
331
343 return ret; 332 return ret;
344} 333}
345 334
@@ -351,74 +340,91 @@ iphone_error_t lockdownd_hello(iphone_lckd_client_t control)
351 * 340 *
352 * @return IPHONE_E_SUCCESS on success. 341 * @return IPHONE_E_SUCCESS on success.
353 */ 342 */
354iphone_error_t lockdownd_generic_get_value(iphone_lckd_client_t control, const char *req_key, const char *req_string, 343iphone_error_t lockdownd_generic_get_value(iphone_lckd_client_t control, const char *req_key, char *req_string,
355 char **value) 344 gnutls_datum_t * value)
356{ 345{
357 if (!control || !req_key || !value || (value && *value)) 346 if (!control || !req_key || !value || value->data)
358 return IPHONE_E_INVALID_ARG; 347 return IPHONE_E_INVALID_ARG;
359 xmlDocPtr plist = new_plist(); 348
360 xmlNode *dict = NULL; 349 plist_t dict = NULL;
361 xmlNode *key = NULL;;
362 char **dictionary = NULL;
363 int bytes = 0, i = 0;
364 char *XML_content = NULL;
365 uint32 length = 0;
366 iphone_error_t ret = IPHONE_E_UNKNOWN_ERROR; 350 iphone_error_t ret = IPHONE_E_UNKNOWN_ERROR;
367 351
368 /* Setup DevicePublicKey request plist */ 352 /* Setup DevicePublicKey request plist */
369 dict = add_child_to_plist(plist, "dict", "\n", NULL, 0); 353 dict = plist_new_dict();
370 key = add_key_str_dict_element(plist, dict, req_key, req_string, 1); 354 plist_add_sub_key_el(dict, req_key);
371 key = add_key_str_dict_element(plist, dict, "Request", "GetValue", 1); 355 plist_add_sub_string_el(dict, req_string);
372 xmlDocDumpMemory(plist, (xmlChar **) & XML_content, &length); 356 plist_add_sub_key_el(dict, "Request");
357 plist_add_sub_string_el(dict, "GetValue");
373 358
374 /* send to iPhone */ 359 /* send to iPhone */
375 ret = iphone_lckd_send(control, XML_content, length, &bytes); 360 ret = iphone_lckd_send(control, dict);
376 361
377 xmlFree(XML_content); 362 plist_free(dict);
378 xmlFreeDoc(plist); 363 dict = NULL;
379 plist = NULL;
380 364
381 if (ret != IPHONE_E_SUCCESS) 365 if (ret != IPHONE_E_SUCCESS)
382 return ret; 366 return ret;
383 367
384 /* Now get iPhone's answer */ 368 /* Now get iPhone's answer */
385 ret = iphone_lckd_recv(control, &XML_content, &bytes); 369 ret = iphone_lckd_recv(control, &dict);
386 370
387 if (ret != IPHONE_E_SUCCESS) 371 if (ret != IPHONE_E_SUCCESS)
388 return ret; 372 return ret;
389 373
390 plist = xmlReadMemory(XML_content, bytes, NULL, NULL, 0); 374 plist_t query_node = plist_find_node_by_string(dict, "GetValue");
391 if (!plist) 375 plist_t result_key_node = plist_get_next_sibling(query_node);
392 return IPHONE_E_PLIST_ERROR; 376 plist_t result_value_node = plist_get_next_sibling(result_key_node);
393 dict = xmlDocGetRootElement(plist);
394 for (dict = dict->children; dict; dict = dict->next) {
395 if (!xmlStrcmp(dict->name, "dict"))
396 break;
397 }
398 if (!dict)
399 return IPHONE_E_DICT_ERROR;
400 377
401 /* Parse xml to check success and to find public key */ 378 plist_type result_key_type = plist_get_node_type(result_key_node);
402 dictionary = read_dict_element_strings(dict); 379 plist_type result_value_type = plist_get_node_type(result_value_node);
403 xmlFreeDoc(plist);
404 free(XML_content);
405 380
406 int success = 0; 381 if (result_key_type == PLIST_KEY && result_value_type == PLIST_STRING) {
407 for (i = 0; dictionary[i]; i += 2) { 382
408 if (!strcmp(dictionary[i], "Result") && !strcmp(dictionary[i + 1], "Success")) { 383 char *result_key = NULL;
409 success = 1; 384 char *result_value = NULL;
410 } 385 ret = IPHONE_E_DICT_ERROR;
411 if (!strcmp(dictionary[i], "Value")) { 386
412 *value = strdup(dictionary[i + 1]); 387 plist_get_key_val(result_key_node, &result_key);
388 plist_get_string_val(result_value_node, &result_value);
389
390 if (!strcmp(result_key, "Result") && !strcmp(result_value, "Success")) {
391 log_dbg_msg(DBGMASK_LOCKDOWND, "lockdownd_generic_get_value(): success\n");
392 ret = IPHONE_E_SUCCESS;
413 } 393 }
394 free(result_key);
395 free(result_value);
396 }
397 if (ret != IPHONE_E_SUCCESS) {
398 return ret;
414 } 399 }
415 400
416 if (dictionary) { 401 plist_t value_key_node = plist_get_next_sibling(result_key_node);
417 free_dictionary(dictionary); 402 plist_t value_value_node = plist_get_next_sibling(value_key_node);
418 dictionary = NULL; 403
404 plist_type value_key_type = plist_get_node_type(value_key_node);
405
406 if (value_key_type == PLIST_KEY) {
407
408 char *result_key = NULL;
409 plist_get_key_val(value_key_node, &result_key);
410
411 if (!strcmp(result_key, "Value")) {
412 log_dbg_msg(DBGMASK_LOCKDOWND, "lockdownd_generic_get_value(): success\n");
413
414 plist_type value_value_type;
415 char *value_value = NULL;
416 uint64_t valval_length = 0;
417
418 plist_get_type_and_value(value_value_node, &value_value_type, (void *) (&value_value), &valval_length);
419
420 value->data = value_value;
421 value->size = valval_length;
422 ret = IPHONE_E_SUCCESS;
423 }
424 free(result_key);
419 } 425 }
420 if (success) 426
421 ret = IPHONE_E_SUCCESS; 427 plist_free(dict);
422 return ret; 428 return ret;
423} 429}
424 430
@@ -430,7 +436,9 @@ iphone_error_t lockdownd_generic_get_value(iphone_lckd_client_t control, const c
430 */ 436 */
431iphone_error_t lockdownd_get_device_uid(iphone_lckd_client_t control, char **uid) 437iphone_error_t lockdownd_get_device_uid(iphone_lckd_client_t control, char **uid)
432{ 438{
433 return lockdownd_generic_get_value(control, "Key", "UniqueDeviceID", uid); 439 gnutls_datum_t temp = { NULL, 0 };
440 return lockdownd_generic_get_value(control, "Key", "UniqueDeviceID", &temp);
441 *uid = temp.data;
434} 442}
435 443
436/** Askes for the device's public key. Part of the lockdownd handshake. 444/** Askes for the device's public key. Part of the lockdownd handshake.
@@ -439,7 +447,7 @@ iphone_error_t lockdownd_get_device_uid(iphone_lckd_client_t control, char **uid
439 * 447 *
440 * @return 1 on success and 0 on failure. 448 * @return 1 on success and 0 on failure.
441 */ 449 */
442iphone_error_t lockdownd_get_device_public_key(iphone_lckd_client_t control, char **public_key) 450iphone_error_t lockdownd_get_device_public_key(iphone_lckd_client_t control, gnutls_datum_t * public_key)
443{ 451{
444 return lockdownd_generic_get_value(control, "Key", "DevicePublicKey", public_key); 452 return lockdownd_generic_get_value(control, "Key", "DevicePublicKey", public_key);
445} 453}
@@ -511,107 +519,91 @@ iphone_error_t iphone_lckd_new_client(iphone_device_t device, iphone_lckd_client
511iphone_error_t lockdownd_pair_device(iphone_lckd_client_t control, char *uid, char *host_id) 519iphone_error_t lockdownd_pair_device(iphone_lckd_client_t control, char *uid, char *host_id)
512{ 520{
513 iphone_error_t ret = IPHONE_E_UNKNOWN_ERROR; 521 iphone_error_t ret = IPHONE_E_UNKNOWN_ERROR;
514 xmlDocPtr plist = new_plist(); 522 plist_t dict = NULL;
515 xmlNode *dict = NULL; 523 plist_t dict_record = NULL;
516 xmlNode *dictRecord = NULL; 524
517 char **dictionary = NULL; 525 gnutls_datum_t device_cert = { NULL, 0 };
518 int bytes = 0, i = 0; 526 gnutls_datum_t host_cert = { NULL, 0 };
519 char *XML_content = NULL; 527 gnutls_datum_t root_cert = { NULL, 0 };
520 uint32 length = 0; 528 gnutls_datum_t public_key = { NULL, 0 };
521 529
522 char *device_cert_b64 = NULL; 530 ret = lockdownd_get_device_public_key(control, &public_key);
523 char *host_cert_b64 = NULL;
524 char *root_cert_b64 = NULL;
525 char *public_key_b64 = NULL;
526
527 ret = lockdownd_get_device_public_key(control, &public_key_b64);
528 if (ret != IPHONE_E_SUCCESS) { 531 if (ret != IPHONE_E_SUCCESS) {
529 log_debug_msg("Device refused to send public key.\n"); 532 log_debug_msg("Device refused to send public key.\n");
530 return ret; 533 return ret;
531 } 534 }
532 535
533 ret = lockdownd_gen_pair_cert(public_key_b64, &device_cert_b64, &host_cert_b64, &root_cert_b64); 536 ret = lockdownd_gen_pair_cert(public_key, &device_cert, &host_cert, &root_cert);
534 if (ret != IPHONE_E_SUCCESS) { 537 if (ret != IPHONE_E_SUCCESS) {
535 free(public_key_b64); 538 free(public_key.data);
536 return ret; 539 return ret;
537 } 540 }
538 541
539 /* Setup Pair request plist */ 542 /* Setup Pair request plist */
540 dict = add_child_to_plist(plist, "dict", "\n", NULL, 0); 543 dict = plist_new_dict();
541 dictRecord = add_key_dict_node(plist, dict, "PairRecord", "\n", 1); 544 plist_add_sub_key_el(dict, "PairRecord");
542 //dictRecord = add_child_to_plist(plist, "dict", "\n", NULL, 1); 545 dict_record = plist_new_dict();
543 add_key_data_dict_element(plist, dictRecord, "DeviceCertificate", device_cert_b64, 2); 546 plist_add_sub_node(dict, dict_record);
544 add_key_data_dict_element(plist, dictRecord, "HostCertificate", host_cert_b64, 2); 547 plist_add_sub_key_el(dict_record, "DeviceCertificate");
545 add_key_str_dict_element(plist, dictRecord, "HostID", host_id, 2); 548 plist_add_sub_data_el(dict_record, device_cert.data, device_cert.size);
546 add_key_data_dict_element(plist, dictRecord, "RootCertificate", root_cert_b64, 2); 549 plist_add_sub_key_el(dict_record, "HostCertificate");
547 add_key_str_dict_element(plist, dict, "Request", "Pair", 1); 550 plist_add_sub_data_el(dict_record, host_cert.data, host_cert.size);
548 551 plist_add_sub_key_el(dict_record, "HostID");
549 xmlDocDumpMemory(plist, (xmlChar **) & XML_content, &length); 552 plist_add_sub_string_el(dict_record, host_id);
550 553 plist_add_sub_key_el(dict_record, "RootCertificate");
551 printf("XML Pairing request : %s\n", XML_content); 554 plist_add_sub_data_el(dict_record, root_cert.data, root_cert.size);
555 plist_add_sub_key_el(dict_record, "Request");
556 plist_add_sub_string_el(dict_record, "Pair");
552 557
553 /* send to iPhone */ 558 /* send to iPhone */
554 ret = iphone_lckd_send(control, XML_content, length, &bytes); 559 ret = iphone_lckd_send(control, dict);
555 560 plist_free(dict);
556 xmlFree(XML_content); 561 dict = NULL;
557 xmlFreeDoc(plist);
558 plist = NULL;
559 562
560 if (ret != IPHONE_E_SUCCESS) 563 if (ret != IPHONE_E_SUCCESS)
561 return ret; 564 return ret;
562 565
563 /* Now get iPhone's answer */ 566 /* Now get iPhone's answer */
564 ret = iphone_lckd_recv(control, &XML_content, &bytes); 567 ret = iphone_lckd_recv(control, &dict);
565 568
566 if (ret != IPHONE_E_SUCCESS) 569 if (ret != IPHONE_E_SUCCESS)
567 return ret; 570 return ret;
568 571
569 log_debug_msg("lockdown_pair_device: iPhone's response to our pair request:\n"); 572 plist_t query_node = plist_find_node_by_string(dict, "Pair");
570 log_debug_msg(XML_content); 573 plist_t result_key_node = plist_get_next_sibling(query_node);
571 log_debug_msg("\n\n"); 574 plist_t result_value_node = plist_get_next_sibling(result_key_node);
572 575
573 plist = xmlReadMemory(XML_content, bytes, NULL, NULL, 0); 576 plist_type result_key_type = plist_get_node_type(result_key_node);
574 if (!plist) { 577 plist_type result_value_type = plist_get_node_type(result_value_node);
575 free(public_key_b64); 578
576 return IPHONE_E_PLIST_ERROR; 579 if (result_key_type == PLIST_KEY && result_value_type == PLIST_STRING) {
577 }
578 dict = xmlDocGetRootElement(plist);
579 for (dict = dict->children; dict; dict = dict->next) {
580 if (!xmlStrcmp(dict->name, "dict"))
581 break;
582 }
583 if (!dict) {
584 free(public_key_b64);
585 return IPHONE_E_DICT_ERROR;
586 }
587 580
588 /* Parse xml to check success and to find public key */ 581 char *result_key = NULL;
589 dictionary = read_dict_element_strings(dict); 582 char *result_value = NULL;
590 xmlFreeDoc(plist);
591 free(XML_content);
592 583
593 int success = 0; 584 plist_get_key_val(result_key_node, &result_key);
594 for (i = 0; dictionary[i]; i += 2) { 585 plist_get_string_val(result_value_node, &result_value);
595 if (!strcmp(dictionary[i], "Result") && !strcmp(dictionary[i + 1], "Success")) { 586
596 success = 1; 587 if (!strcmp(result_key, "Result") && !strcmp(result_value, "Success")) {
588 ret = IPHONE_E_SUCCESS;
597 } 589 }
598 }
599 590
600 if (dictionary) { 591 free(result_key);
601 free_dictionary(dictionary); 592 free(result_value);
602 dictionary = NULL;
603 } 593 }
594 plist_free(dict);
595 dict = NULL;
604 596
605 /* store public key in config if pairing succeeded */ 597 /* store public key in config if pairing succeeded */
606 if (success) { 598 if (ret == IPHONE_E_SUCCESS) {
607 log_debug_msg("lockdownd_pair_device: pair success\n"); 599 log_dbg_msg(DBGMASK_LOCKDOWND, "lockdownd_pair_device: pair success\n");
608 store_device_public_key(uid, public_key_b64); 600 store_device_public_key(uid, public_key);
609 ret = IPHONE_E_SUCCESS; 601 ret = IPHONE_E_SUCCESS;
610 } else { 602 } else {
611 log_debug_msg("lockdownd_pair_device: pair failure\n"); 603 log_dbg_msg(DBGMASK_LOCKDOWND, "lockdownd_pair_device: pair failure\n");
612 ret = IPHONE_E_PAIRING_FAILED; 604 ret = IPHONE_E_PAIRING_FAILED;
613 } 605 }
614 free(public_key_b64); 606 free(public_key.data);
615 return ret; 607 return ret;
616} 608}
617 609
@@ -624,55 +616,51 @@ iphone_error_t lockdownd_pair_device(iphone_lckd_client_t control, char *uid, ch
624void lockdownd_close(iphone_lckd_client_t control) 616void lockdownd_close(iphone_lckd_client_t control)
625{ 617{
626 if (!control) 618 if (!control)
627 return; // IPHONE_E_INVALID_ARG; 619 return; //IPHONE_E_INVALID_ARG;
628 xmlDocPtr plist = new_plist(); 620
629 xmlNode *dict, *key;
630 char **dictionary;
631 int bytes = 0, i = 0;
632 iphone_error_t ret = IPHONE_E_UNKNOWN_ERROR; 621 iphone_error_t ret = IPHONE_E_UNKNOWN_ERROR;
633 622
634 log_debug_msg("lockdownd_close() called\n"); 623 plist_t dict = plist_new_dict();
635 dict = add_child_to_plist(plist, "dict", "\n", NULL, 0); 624 plist_add_sub_key_el(dict, "Request");
636 key = add_key_str_dict_element(plist, dict, "Request", "Goodbye", 1); 625 plist_add_sub_string_el(dict, "Goodbye");
637 char *XML_content;
638 uint32 length;
639 626
640 xmlDocDumpMemory(plist, (xmlChar **) & XML_content, &length); 627 log_dbg_msg(DBGMASK_LOCKDOWND, "lockdownd_close() called\n");
641 ret = iphone_lckd_send(control, XML_content, length, &bytes);
642 628
643 xmlFree(XML_content); 629 ret = iphone_lckd_send(control, dict);
644 xmlFreeDoc(plist); 630 plist_free(dict);
645 plist = NULL; 631 dict = NULL;
646 ret = iphone_lckd_recv(control, &XML_content, &bytes); 632
633 ret = iphone_lckd_recv(control, &dict);
647 634
648 plist = xmlReadMemory(XML_content, bytes, NULL, NULL, 0);
649 if (!plist) {
650 log_debug_msg("lockdownd_close(): IPHONE_E_PLIST_ERROR\n");
651 return; //IPHONE_E_PLIST_ERROR;
652 }
653 dict = xmlDocGetRootElement(plist);
654 for (dict = dict->children; dict; dict = dict->next) {
655 if (!xmlStrcmp(dict->name, "dict"))
656 break;
657 }
658 if (!dict) { 635 if (!dict) {
659 log_debug_msg("lockdownd_close(): IPHONE_E_DICT_ERROR\n"); 636 log_dbg_msg(DBGMASK_LOCKDOWND, "lockdownd_close(): IPHONE_E_PLIST_ERROR\n");
660 return; //IPHONE_E_DICT_ERROR; 637 return; // IPHONE_E_PLIST_ERROR;
661 } 638 }
662 dictionary = read_dict_element_strings(dict);
663 xmlFreeDoc(plist);
664 free(XML_content);
665 639
666 for (i = 0; dictionary[i]; i += 2) { 640 plist_t query_node = plist_find_node_by_string(dict, "Goodbye");
667 if (!strcmp(dictionary[i], "Result") && !strcmp(dictionary[i + 1], "Success")) { 641 plist_t result_node = plist_get_next_sibling(query_node);
668 log_debug_msg("lockdownd_close(): success\n"); 642 plist_t value_node = plist_get_next_sibling(result_node);
643
644 plist_type result_type = plist_get_node_type(result_node);
645 plist_type value_type = plist_get_node_type(value_node);
646
647 if (result_type == PLIST_KEY && value_type == PLIST_STRING) {
648 char *result_value = NULL;
649 char *value_value = NULL;
650
651 plist_get_key_val(result_node, &result_value);
652 plist_get_string_val(value_node, &value_value);
653
654 if (!strcmp(result_value, "Result") && !strcmp(value_value, "Success")) {
655 log_dbg_msg(DBGMASK_LOCKDOWND, "lockdownd_close(): success\n");
669 ret = IPHONE_E_SUCCESS; 656 ret = IPHONE_E_SUCCESS;
670 break;
671 } 657 }
658 free(result_value);
659 free(value_value);
672 } 660 }
673 661 plist_free(dict);
674 free_dictionary(dictionary); 662 dict = NULL;
675 return; //ret; 663 return; // ret;
676} 664}
677 665
678/** Generates the device certificate from the public key as well as the host 666/** Generates the device certificate from the public key as well as the host
@@ -680,25 +668,19 @@ void lockdownd_close(iphone_lckd_client_t control)
680 * 668 *
681 * @return IPHONE_E_SUCCESS on success. 669 * @return IPHONE_E_SUCCESS on success.
682 */ 670 */
683iphone_error_t lockdownd_gen_pair_cert(char *public_key_b64, char **device_cert_b64, char **host_cert_b64, 671iphone_error_t lockdownd_gen_pair_cert(gnutls_datum_t public_key, gnutls_datum_t * odevice_cert,
684 char **root_cert_b64) 672 gnutls_datum_t * ohost_cert, gnutls_datum_t * oroot_cert)
685{ 673{
686 if (!public_key_b64 || !device_cert_b64 || !host_cert_b64 || !root_cert_b64) 674 if (!public_key.data || !odevice_cert || !ohost_cert || !oroot_cert)
687 return IPHONE_E_INVALID_ARG; 675 return IPHONE_E_INVALID_ARG;
688 iphone_error_t ret = IPHONE_E_UNKNOWN_ERROR; 676 iphone_error_t ret = IPHONE_E_UNKNOWN_ERROR;
689 677
690 gnutls_datum_t modulus = { NULL, 0 }; 678 gnutls_datum_t modulus = { NULL, 0 };
691 gnutls_datum_t exponent = { NULL, 0 }; 679 gnutls_datum_t exponent = { NULL, 0 };
692 680
693 /* first decode base64 public_key */
694 gnutls_datum_t pem_pub_key;
695 gsize decoded_size;
696 pem_pub_key.data = g_base64_decode(public_key_b64, &decoded_size);
697 pem_pub_key.size = decoded_size;
698
699 /* now decode the PEM encoded key */ 681 /* now decode the PEM encoded key */
700 gnutls_datum_t der_pub_key; 682 gnutls_datum_t der_pub_key;
701 if (GNUTLS_E_SUCCESS == gnutls_pem_base64_decode_alloc("RSA PUBLIC KEY", &pem_pub_key, &der_pub_key)) { 683 if (GNUTLS_E_SUCCESS == gnutls_pem_base64_decode_alloc("RSA PUBLIC KEY", &public_key, &der_pub_key)) {
702 684
703 /* initalize asn.1 parser */ 685 /* initalize asn.1 parser */
704 ASN1_TYPE pkcs1 = ASN1_TYPE_EMPTY; 686 ASN1_TYPE pkcs1 = ASN1_TYPE_EMPTY;
@@ -782,10 +764,18 @@ iphone_error_t lockdownd_gen_pair_cert(char *public_key_b64, char **device_cert_
782 dev_pem.data = gnutls_malloc(dev_pem.size); 764 dev_pem.data = gnutls_malloc(dev_pem.size);
783 gnutls_x509_crt_export(dev_cert, GNUTLS_X509_FMT_PEM, dev_pem.data, &dev_pem.size); 765 gnutls_x509_crt_export(dev_cert, GNUTLS_X509_FMT_PEM, dev_pem.data, &dev_pem.size);
784 766
785 /* now encode certificates for output */ 767 /* copy buffer for output */
786 *device_cert_b64 = g_base64_encode(dev_pem.data, dev_pem.size); 768 odevice_cert->data = malloc(dev_pem.size);
787 *host_cert_b64 = g_base64_encode(pem_host_cert.data, pem_host_cert.size); 769 memcpy(odevice_cert->data, dev_pem.data, dev_pem.size);
788 *root_cert_b64 = g_base64_encode(pem_root_cert.data, pem_root_cert.size); 770 odevice_cert->size = dev_pem.size;
771
772 ohost_cert->data = malloc(pem_host_cert.size);
773 memcpy(ohost_cert->data, pem_host_cert.data, pem_host_cert.size);
774 ohost_cert->size = pem_host_cert.size;
775
776 oroot_cert->data = malloc(pem_root_cert.size);
777 memcpy(oroot_cert->data, pem_root_cert.data, pem_root_cert.size);
778 oroot_cert->size = pem_root_cert.size;
789 } 779 }
790 gnutls_free(pem_root_priv.data); 780 gnutls_free(pem_root_priv.data);
791 gnutls_free(pem_root_cert.data); 781 gnutls_free(pem_root_cert.data);
@@ -797,7 +787,6 @@ iphone_error_t lockdownd_gen_pair_cert(char *public_key_b64, char **device_cert_
797 gnutls_free(exponent.data); 787 gnutls_free(exponent.data);
798 788
799 gnutls_free(der_pub_key.data); 789 gnutls_free(der_pub_key.data);
800 g_free(pem_pub_key.data);
801 790
802 return ret; 791 return ret;
803} 792}
@@ -811,129 +800,127 @@ iphone_error_t lockdownd_gen_pair_cert(char *public_key_b64, char **device_cert_
811 */ 800 */
812iphone_error_t lockdownd_start_SSL_session(iphone_lckd_client_t control, const char *HostID) 801iphone_error_t lockdownd_start_SSL_session(iphone_lckd_client_t control, const char *HostID)
813{ 802{
814 xmlDocPtr plist = new_plist(); 803 plist_t dict = NULL;
815 xmlNode *dict = add_child_to_plist(plist, "dict", "\n", NULL, 0); 804 uint32_t return_me = 0;
816 xmlNode *key;
817 char *what2send = NULL, **dictionary = NULL;
818 uint32 len = 0, bytes = 0, return_me = 0, i = 0;
819 iphone_error_t ret = IPHONE_E_UNKNOWN_ERROR;
820 // end variables
821 805
806 iphone_error_t ret = IPHONE_E_UNKNOWN_ERROR;
822 control->session_id[0] = '\0'; 807 control->session_id[0] = '\0';
823 808
824 key = add_key_str_dict_element(plist, dict, "HostID", HostID, 1); 809 /* Setup DevicePublicKey request plist */
825 if (!key) { 810 dict = plist_new_dict();
826 log_debug_msg("Couldn't add a key.\n"); 811 plist_add_sub_key_el(dict, "HostID");
827 xmlFreeDoc(plist); 812 plist_add_sub_string_el(dict, HostID);
828 return IPHONE_E_DICT_ERROR; 813 plist_add_sub_key_el(dict, "Request");
829 } 814 plist_add_sub_string_el(dict, "StartSession");
830 key = add_key_str_dict_element(plist, dict, "Request", "StartSession", 1);
831 if (!key) {
832 log_debug_msg("Couldn't add a key.\n");
833 xmlFreeDoc(plist);
834 return IPHONE_E_DICT_ERROR;
835 }
836
837 xmlDocDumpMemory(plist, (xmlChar **) & what2send, &len);
838 ret = iphone_lckd_send(control, what2send, len, &bytes);
839 815
840 xmlFree(what2send); 816 ret = iphone_lckd_send(control, dict);
841 xmlFreeDoc(plist); 817 plist_free(dict);
818 dict = NULL;
842 819
843 if (ret != IPHONE_E_SUCCESS) 820 if (ret != IPHONE_E_SUCCESS)
844 return ret; 821 return ret;
845 822
846 if (bytes > 0) { 823 ret = iphone_lckd_recv(control, &dict);
847 ret = iphone_lckd_recv(control, &what2send, &len); 824
848 plist = xmlReadMemory(what2send, len, NULL, NULL, 0); 825 if (!dict)
849 dict = xmlDocGetRootElement(plist); 826 return IPHONE_E_PLIST_ERROR;
850 if (!dict) 827
851 return IPHONE_E_DICT_ERROR; 828 plist_t query_node = plist_find_node(dict, PLIST_STRING, "StartSession", strlen("StartSession"));
852 for (dict = dict->children; dict; dict = dict->next) { 829 plist_t result_key_node = plist_get_next_sibling(query_node);
853 if (!xmlStrcmp(dict->name, "dict")) 830 plist_t result_value_node = plist_get_next_sibling(result_key_node);
854 break; 831
855 } 832 plist_type result_key_type = plist_get_node_type(result_key_node);
856 dictionary = read_dict_element_strings(dict); 833 plist_type result_value_type = plist_get_node_type(result_value_node);
857 xmlFreeDoc(plist); 834
858 free(what2send); 835 if (result_key_type == PLIST_KEY && result_value_type == PLIST_STRING) {
836 char *result_key = NULL;
837 char *result_value = NULL;
838
839 plist_get_key_val(result_key_node, &result_key);
840 plist_get_string_val(result_value_node, &result_value);
841
859 ret = IPHONE_E_SSL_ERROR; 842 ret = IPHONE_E_SSL_ERROR;
860 for (i = 0; dictionary[i]; i += 2) { 843 if (!strcmp(result_key, "Result") && !strcmp(result_value, "Success")) {
861 if (!strcmp(dictionary[i], "Result") && !strcmp(dictionary[i + 1], "Success")) { 844 // Set up GnuTLS...
862 // Set up GnuTLS... 845 //gnutls_anon_client_credentials_t anoncred;
863 //gnutls_anon_client_credentials_t anoncred; 846 gnutls_certificate_credentials_t xcred;
864 gnutls_certificate_credentials_t xcred; 847
865 848 log_dbg_msg(DBGMASK_LOCKDOWND, "We started the session OK, now trying GnuTLS\n");
866 log_debug_msg("We started the session OK, now trying GnuTLS\n"); 849 errno = 0;
867 errno = 0; 850 gnutls_global_init();
868 gnutls_global_init(); 851 //gnutls_anon_allocate_client_credentials(&anoncred);
869 //gnutls_anon_allocate_client_credentials(&anoncred); 852 gnutls_certificate_allocate_credentials(&xcred);
870 gnutls_certificate_allocate_credentials(&xcred); 853 gnutls_certificate_set_x509_trust_file(xcred, "hostcert.pem", GNUTLS_X509_FMT_PEM);
871 gnutls_certificate_set_x509_trust_file(xcred, "hostcert.pem", GNUTLS_X509_FMT_PEM); 854 gnutls_init(control->ssl_session, GNUTLS_CLIENT);
872 gnutls_init(control->ssl_session, GNUTLS_CLIENT); 855 {
873 { 856 int protocol_priority[16] = { GNUTLS_SSL3, 0 };
874 int protocol_priority[16] = { GNUTLS_SSL3, 0 }; 857 int kx_priority[16] = { GNUTLS_KX_ANON_DH, GNUTLS_KX_RSA, 0 };
875 int kx_priority[16] = { GNUTLS_KX_ANON_DH, GNUTLS_KX_RSA, 0 }; 858 int cipher_priority[16] = { GNUTLS_CIPHER_AES_128_CBC, GNUTLS_CIPHER_AES_256_CBC, 0 };
876 int cipher_priority[16] = { GNUTLS_CIPHER_AES_128_CBC, GNUTLS_CIPHER_AES_256_CBC, 0 }; 859 int mac_priority[16] = { GNUTLS_MAC_SHA1, GNUTLS_MAC_MD5, 0 };
877 int mac_priority[16] = { GNUTLS_MAC_SHA1, GNUTLS_MAC_MD5, 0 }; 860 int comp_priority[16] = { GNUTLS_COMP_NULL, 0 };
878 int comp_priority[16] = { GNUTLS_COMP_NULL, 0 }; 861
879 862 gnutls_cipher_set_priority(*control->ssl_session, cipher_priority);
880 gnutls_cipher_set_priority(*control->ssl_session, cipher_priority); 863 gnutls_compression_set_priority(*control->ssl_session, comp_priority);
881 gnutls_compression_set_priority(*control->ssl_session, comp_priority); 864 gnutls_kx_set_priority(*control->ssl_session, kx_priority);
882 gnutls_kx_set_priority(*control->ssl_session, kx_priority); 865 gnutls_protocol_set_priority(*control->ssl_session, protocol_priority);
883 gnutls_protocol_set_priority(*control->ssl_session, protocol_priority); 866 gnutls_mac_set_priority(*control->ssl_session, mac_priority);
884 gnutls_mac_set_priority(*control->ssl_session, mac_priority); 867
885 868 }
886 } 869 gnutls_credentials_set(*control->ssl_session, GNUTLS_CRD_CERTIFICATE, xcred); // this part is killing me.
887 gnutls_credentials_set(*control->ssl_session, GNUTLS_CRD_CERTIFICATE, xcred); // this part is killing me. 870
888 871 log_dbg_msg(DBGMASK_LOCKDOWND, "GnuTLS step 1...\n");
889 log_debug_msg("GnuTLS step 1...\n"); 872 gnutls_transport_set_ptr(*control->ssl_session, (gnutls_transport_ptr_t) control);
890 gnutls_transport_set_ptr(*control->ssl_session, (gnutls_transport_ptr_t) control); 873 log_dbg_msg(DBGMASK_LOCKDOWND, "GnuTLS step 2...\n");
891 log_debug_msg("GnuTLS step 2...\n"); 874 gnutls_transport_set_push_function(*control->ssl_session, (gnutls_push_func) & lockdownd_secuwrite);
892 gnutls_transport_set_push_function(*control->ssl_session, (gnutls_push_func) & lockdownd_secuwrite); 875 log_dbg_msg(DBGMASK_LOCKDOWND, "GnuTLS step 3...\n");
893 log_debug_msg("GnuTLS step 3...\n"); 876 gnutls_transport_set_pull_function(*control->ssl_session, (gnutls_pull_func) & lockdownd_securead);
894 gnutls_transport_set_pull_function(*control->ssl_session, (gnutls_pull_func) & lockdownd_securead); 877 log_dbg_msg(DBGMASK_LOCKDOWND, "GnuTLS step 4 -- now handshaking...\n");
895 log_debug_msg("GnuTLS step 4 -- now handshaking...\n"); 878
896 879 if (errno)
897 if (errno) 880 log_dbg_msg(DBGMASK_LOCKDOWND, "WARN: errno says %s before handshake!\n", strerror(errno));
898 log_debug_msg("WARN: errno says %s before handshake!\n", strerror(errno)); 881 return_me = gnutls_handshake(*control->ssl_session);
899 return_me = gnutls_handshake(*control->ssl_session); 882 log_dbg_msg(DBGMASK_LOCKDOWND, "GnuTLS handshake done...\n");
900 log_debug_msg("GnuTLS handshake done...\n"); 883
901 884 if (return_me != GNUTLS_E_SUCCESS) {
902 if (return_me != GNUTLS_E_SUCCESS) { 885 log_dbg_msg(DBGMASK_LOCKDOWND, "GnuTLS reported something wrong.\n");
903 log_debug_msg("GnuTLS reported something wrong.\n"); 886 gnutls_perror(return_me);
904 gnutls_perror(return_me); 887 log_dbg_msg(DBGMASK_LOCKDOWND, "oh.. errno says %s\n", strerror(errno));
905 log_debug_msg("oh.. errno says %s\n", strerror(errno)); 888 return IPHONE_E_SSL_ERROR;
906 return IPHONE_E_SSL_ERROR; 889 } else {
907 } else { 890 control->in_SSL = 1;
908 control->in_SSL = 1; 891 ret = IPHONE_E_SUCCESS;
909 ret = IPHONE_E_SUCCESS;
910 }
911 } else if (!strcmp(dictionary[i], "SessionID")) {
912 // we need to store the session ID for StopSession
913 strcpy(control->session_id, dictionary[i + 1]);
914 log_debug_msg("SessionID: %s\n", control->session_id);
915 free_dictionary(dictionary);
916 return ret;
917 } 892 }
918 } 893 }
919 if (ret == IPHONE_E_SUCCESS) { 894 }
920 log_debug_msg("Failed to get SessionID!\n"); 895 //store session id
921 return ret; 896 plist_t session_node = plist_find_node_by_key(dict, "SessionID");
922 } 897 if (session_node) {
923 898
924 log_debug_msg("Apparently failed negotiating with lockdownd.\n"); 899 plist_t session_node_val = plist_get_next_sibling(session_node);
925 log_debug_msg("Responding dictionary: \n"); 900 plist_type session_node_val_type = plist_get_node_type(session_node_val);
926 for (i = 0; dictionary[i]; i += 2) { 901
927 log_debug_msg("\t%s: %s\n", dictionary[i], dictionary[i + 1]); 902 if (session_node_val_type == PLIST_STRING) {
903
904 char *session_id = NULL;
905 plist_get_string_val(session_node_val, &session_id);
906
907 if (session_node_val_type == PLIST_STRING && session_id) {
908 // we need to store the session ID for StopSession
909 strcpy(control->session_id, session_id);
910 log_dbg_msg(DBGMASK_LOCKDOWND, "SessionID: %s\n", control->session_id);
911 }
912 free(session_id);
928 } 913 }
914 } else
915 log_dbg_msg(DBGMASK_LOCKDOWND, "Failed to get SessionID!\n");
916 plist_free(dict);
917 dict = NULL;
929 918
919 if (ret == IPHONE_E_SUCCESS)
920 return ret;
930 921
931 free_dictionary(dictionary); 922 log_dbg_msg(DBGMASK_LOCKDOWND, "Apparently failed negotiating with lockdownd.\n");
932 return IPHONE_E_SSL_ERROR; 923 return IPHONE_E_SSL_ERROR;
933 } else {
934 log_debug_msg("Didn't get enough bytes.\n");
935 return IPHONE_E_NOT_ENOUGH_DATA;
936 }
937} 924}
938 925
939/** gnutls callback for writing data to the iPhone. 926/** gnutls callback for writing data to the iPhone.
@@ -949,10 +936,10 @@ ssize_t lockdownd_secuwrite(gnutls_transport_ptr_t transport, char *buffer, size
949 int bytes = 0; 936 int bytes = 0;
950 iphone_lckd_client_t control; 937 iphone_lckd_client_t control;
951 control = (iphone_lckd_client_t) transport; 938 control = (iphone_lckd_client_t) transport;
952 log_debug_msg("lockdownd_secuwrite() called\n"); 939 log_dbg_msg(DBGMASK_LOCKDOWND, "lockdownd_secuwrite() called\n");
953 log_debug_msg("pre-send\nlength = %zi\n", length); 940 log_dbg_msg(DBGMASK_LOCKDOWND, "pre-send\nlength = %zi\n", length);
954 iphone_mux_send(control->connection, buffer, length, &bytes); 941 iphone_mux_send(control->connection, buffer, length, &bytes);
955 log_debug_msg("post-send\nsent %i bytes\n", bytes); 942 log_dbg_msg(DBGMASK_LOCKDOWND, "post-send\nsent %i bytes\n", bytes);
956 943
957 dump_debug_buffer("sslpacketwrite.out", buffer, length); 944 dump_debug_buffer("sslpacketwrite.out", buffer, length);
958 return bytes; 945 return bytes;
@@ -972,7 +959,7 @@ ssize_t lockdownd_securead(gnutls_transport_ptr_t transport, char *buffer, size_
972 char *hackhackhack = NULL; 959 char *hackhackhack = NULL;
973 iphone_lckd_client_t control; 960 iphone_lckd_client_t control;
974 control = (iphone_lckd_client_t) transport; 961 control = (iphone_lckd_client_t) transport;
975 log_debug_msg("lockdownd_securead() called\nlength = %zi\n", length); 962 log_dbg_msg(DBGMASK_LOCKDOWND, "lockdownd_securead() called\nlength = %zi\n", length);
976 // Buffering hack! Throw what we've got in our "buffer" into the stream first, then get more. 963 // Buffering hack! Throw what we've got in our "buffer" into the stream first, then get more.
977 if (control->gtls_buffer_hack_len > 0) { 964 if (control->gtls_buffer_hack_len > 0) {
978 if (length > control->gtls_buffer_hack_len) { // If it's asking for more than we got 965 if (length > control->gtls_buffer_hack_len) { // If it's asking for more than we got
@@ -981,7 +968,7 @@ ssize_t lockdownd_securead(gnutls_transport_ptr_t transport, char *buffer, size_
981 memcpy(buffer, control->gtls_buffer_hack, control->gtls_buffer_hack_len); // Fill their buffer partially 968 memcpy(buffer, control->gtls_buffer_hack, control->gtls_buffer_hack_len); // Fill their buffer partially
982 free(control->gtls_buffer_hack); // free our memory, it's not chained anymore 969 free(control->gtls_buffer_hack); // free our memory, it's not chained anymore
983 control->gtls_buffer_hack_len = 0; // we don't have a hack buffer anymore 970 control->gtls_buffer_hack_len = 0; // we don't have a hack buffer anymore
984 log_debug_msg("Did a partial fill to help quench thirst for data\n"); 971 log_dbg_msg(DBGMASK_LOCKDOWND, "Did a partial fill to help quench thirst for data\n");
985 } else if (length < control->gtls_buffer_hack_len) { // If it's asking for less... 972 } else if (length < control->gtls_buffer_hack_len) { // If it's asking for less...
986 control->gtls_buffer_hack_len -= length; // subtract what they're asking for 973 control->gtls_buffer_hack_len -= length; // subtract what they're asking for
987 memcpy(buffer, control->gtls_buffer_hack, length); // fill their buffer 974 memcpy(buffer, control->gtls_buffer_hack, length); // fill their buffer
@@ -990,33 +977,34 @@ ssize_t lockdownd_securead(gnutls_transport_ptr_t transport, char *buffer, size_
990 free(control->gtls_buffer_hack); // Free the old one 977 free(control->gtls_buffer_hack); // Free the old one
991 control->gtls_buffer_hack = hackhackhack; // And make it the new one. 978 control->gtls_buffer_hack = hackhackhack; // And make it the new one.
992 hackhackhack = NULL; 979 hackhackhack = NULL;
993 log_debug_msg("Quenched the thirst for data; new hack length is %i\n", control->gtls_buffer_hack_len); 980 log_dbg_msg(DBGMASK_LOCKDOWND, "Quenched the thirst for data; new hack length is %i\n",
981 control->gtls_buffer_hack_len);
994 return length; // hand it over. 982 return length; // hand it over.
995 } else { // length == hack length 983 } else { // length == hack length
996 memcpy(buffer, control->gtls_buffer_hack, length); // copy our buffer into theirs 984 memcpy(buffer, control->gtls_buffer_hack, length); // copy our buffer into theirs
997 free(control->gtls_buffer_hack); // free our "obligation" 985 free(control->gtls_buffer_hack); // free our "obligation"
998 control->gtls_buffer_hack_len = 0; // free our "obligation" 986 control->gtls_buffer_hack_len = 0; // free our "obligation"
999 log_debug_msg("Satiated the thirst for data; now we have to eventually receive again.\n"); 987 log_dbg_msg(DBGMASK_LOCKDOWND, "Satiated the thirst for data; now we have to eventually receive again.\n");
1000 return length; // hand it over 988 return length; // hand it over
1001 } 989 }
1002 } 990 }
1003 // End buffering hack! 991 // End buffering hack!
1004 char *recv_buffer = (char *) malloc(sizeof(char) * (length * 1000)); // ensuring nothing stupid happens 992 char *recv_buffer = (char *) malloc(sizeof(char) * (length * 1000)); // ensuring nothing stupid happens
1005 993
1006 log_debug_msg("pre-read\nclient wants %zi bytes\n", length); 994 log_dbg_msg(DBGMASK_LOCKDOWND, "pre-read\nclient wants %zi bytes\n", length);
1007 iphone_mux_recv(control->connection, recv_buffer, (length * 1000), &bytes); 995 iphone_mux_recv(control->connection, recv_buffer, (length * 1000), &bytes);
1008 log_debug_msg("post-read\nwe got %i bytes\n", bytes); 996 log_dbg_msg(DBGMASK_LOCKDOWND, "post-read\nwe got %i bytes\n", bytes);
1009 if (bytes < 0) { 997 if (bytes < 0) {
1010 log_debug_msg("lockdownd_securead(): uh oh\n"); 998 log_dbg_msg(DBGMASK_LOCKDOWND, "lockdownd_securead(): uh oh\n");
1011 log_debug_msg 999 log_dbg_msg(DBGMASK_LOCKDOWND,
1012 ("I believe what we have here is a failure to communicate... libusb says %s but strerror says %s\n", 1000 "I believe what we have here is a failure to communicate... libusb says %s but strerror says %s\n",
1013 usb_strerror(), strerror(errno)); 1001 usb_strerror(), strerror(errno));
1014 return bytes + 28; // an errno 1002 return bytes + 28; // an errno
1015 } 1003 }
1016 if (bytes >= length) { 1004 if (bytes >= length) {
1017 if (bytes > length) { 1005 if (bytes > length) {
1018 log_debug_msg 1006 log_dbg_msg(DBGMASK_LOCKDOWND,
1019 ("lockdownd_securead: Client deliberately read less data than was there; resorting to GnuTLS buffering hack.\n"); 1007 "lockdownd_securead: Client deliberately read less data than was there; resorting to GnuTLS buffering hack.\n");
1020 if (!control->gtls_buffer_hack_len) { // if there's no hack buffer yet 1008 if (!control->gtls_buffer_hack_len) { // if there's no hack buffer yet
1021 //control->gtls_buffer_hack = strndup(recv_buffer+length, bytes-length); // strndup is NOT a good solution! 1009 //control->gtls_buffer_hack = strndup(recv_buffer+length, bytes-length); // strndup is NOT a good solution!
1022 control->gtls_buffer_hack_len += bytes - length; 1010 control->gtls_buffer_hack_len += bytes - length;
@@ -1032,10 +1020,11 @@ ssize_t lockdownd_securead(gnutls_transport_ptr_t transport, char *buffer, size_
1032 memcpy(buffer + pos_start_fill, recv_buffer, length); 1020 memcpy(buffer + pos_start_fill, recv_buffer, length);
1033 free(recv_buffer); 1021 free(recv_buffer);
1034 if (bytes == length) { 1022 if (bytes == length) {
1035 log_debug_msg("Returning how much we received.\n"); 1023 log_dbg_msg(DBGMASK_LOCKDOWND, "Returning how much we received.\n");
1036 return bytes; 1024 return bytes;
1037 } else { 1025 } else {
1038 log_debug_msg("Returning what they want to hear.\nHack length: %i\n", control->gtls_buffer_hack_len); 1026 log_dbg_msg(DBGMASK_LOCKDOWND, "Returning what they want to hear.\nHack length: %i\n",
1027 control->gtls_buffer_hack_len);
1039 return length; 1028 return length;
1040 } 1029 }
1041 } 1030 }
@@ -1060,86 +1049,72 @@ iphone_error_t iphone_lckd_start_service(iphone_lckd_client_t client, const char
1060 if (!client->in_SSL && !lockdownd_start_SSL_session(client, host_id)) 1049 if (!client->in_SSL && !lockdownd_start_SSL_session(client, host_id))
1061 return IPHONE_E_SSL_ERROR; 1050 return IPHONE_E_SSL_ERROR;
1062 1051
1063 char *XML_query, **dictionary; 1052 plist_t dict = NULL;
1064 uint32 length, i = 0, port_loc = 0, bytes = 0; 1053 uint32_t port_loc = 0;
1065 uint8 result = 0;
1066 iphone_error_t ret = IPHONE_E_UNKNOWN_ERROR; 1054 iphone_error_t ret = IPHONE_E_UNKNOWN_ERROR;
1067 1055
1068 free(host_id); 1056 free(host_id);
1069 host_id = NULL; 1057 host_id = NULL;
1070 1058
1071 xmlDocPtr plist = new_plist(); 1059 dict = plist_new_dict();
1072 xmlNode *dict = add_child_to_plist(plist, "dict", "\n", NULL, 0); 1060 plist_add_sub_key_el(dict, "Request");
1073 xmlNode *key; 1061 plist_add_sub_string_el(dict, "StartService");
1074 key = add_key_str_dict_element(plist, dict, "Request", "StartService", 1); 1062 plist_add_sub_key_el(dict, "Service");
1075 if (!key) { 1063 plist_add_sub_string_el(dict, service);
1076 xmlFreeDoc(plist);
1077 return IPHONE_E_UNKNOWN_ERROR;
1078 }
1079 key = add_key_str_dict_element(plist, dict, "Service", service, 1);
1080 if (!key) {
1081 xmlFreeDoc(plist);
1082 return IPHONE_E_UNKNOWN_ERROR;
1083 }
1084 1064
1085 xmlDocDumpMemory(plist, (xmlChar **) & XML_query, &length); 1065 /* send to iPhone */
1066 ret = iphone_lckd_send(client, dict);
1067 plist_free(dict);
1068 dict = NULL;
1086 1069
1087 ret = iphone_lckd_send(client, XML_query, length, &bytes);
1088 free(XML_query);
1089 if (IPHONE_E_SUCCESS != ret) 1070 if (IPHONE_E_SUCCESS != ret)
1090 return ret; 1071 return ret;
1091 1072
1092 ret = iphone_lckd_recv(client, &XML_query, &bytes); 1073 ret = iphone_lckd_recv(client, &dict);
1093 xmlFreeDoc(plist); 1074
1094 if (IPHONE_E_SUCCESS != ret) 1075 if (IPHONE_E_SUCCESS != ret)
1095 return ret; 1076 return ret;
1096 1077
1097 if (bytes <= 0) 1078 if (!dict)
1098 return IPHONE_E_NOT_ENOUGH_DATA; 1079 return IPHONE_E_PLIST_ERROR;
1099 else {
1100 plist = xmlReadMemory(XML_query, bytes, NULL, NULL, 0);
1101 if (!plist)
1102 return IPHONE_E_UNKNOWN_ERROR;
1103 dict = xmlDocGetRootElement(plist);
1104 if (!dict)
1105 return IPHONE_E_UNKNOWN_ERROR;
1106 for (dict = dict->children; dict; dict = dict->next) {
1107 if (!xmlStrcmp(dict->name, "dict"))
1108 break;
1109 }
1110 1080
1111 if (!dict) 1081 plist_t query_node = plist_find_node_by_string(dict, "StartService");
1112 return IPHONE_E_UNKNOWN_ERROR; 1082 plist_t result_key_node = plist_get_next_sibling(query_node);
1113 dictionary = read_dict_element_strings(dict); 1083 plist_t result_value_node = plist_get_next_sibling(result_key_node);
1114 1084
1115 for (i = 0; dictionary[i]; i += 2) { 1085 plist_t port_key_node = plist_find_node_by_key(dict, "Port");
1116 log_debug_msg("lockdownd_start_service() dictionary %s: %s\n", dictionary[i], dictionary[i + 1]); 1086 plist_t port_value_node = plist_get_next_sibling(port_key_node);
1117 1087
1118 if (!xmlStrcmp(dictionary[i], "Port")) { 1088 plist_type result_key_type = plist_get_node_type(result_key_node);
1119 port_loc = atoi(dictionary[i + 1]); 1089 plist_type result_value_type = plist_get_node_type(result_value_node);
1120 log_debug_msg("lockdownd_start_service() atoi'd port: %i\n", port); 1090 plist_type port_key_type = plist_get_node_type(port_key_node);
1121 } 1091 plist_type port_value_type = plist_get_node_type(port_value_node);
1122 1092
1123 if (!xmlStrcmp(dictionary[i], "Result")) { 1093 if (result_key_type == PLIST_KEY && result_value_type == PLIST_STRING && port_key_type == PLIST_KEY
1124 if (!xmlStrcmp(dictionary[i + 1], "Success")) { 1094 && port_value_type == PLIST_UINT) {
1125 result = 1; 1095
1126 } 1096 char *result_key = NULL;
1127 } 1097 char *result_value = NULL;
1128 } 1098 char *port_key = NULL;
1099 uint64_t port_value = 0;
1129 1100
1130 log_debug_msg("lockdownd_start_service(): DATA RECEIVED:\n\n"); 1101 plist_get_key_val(result_key_node, &result_key);
1131 log_debug_msg(XML_query); 1102 plist_get_string_val(result_value_node, &result_value);
1132 log_debug_msg("end data received by lockdownd_start_service()\n"); 1103 plist_get_key_val(port_key_node, &port_key);
1104 plist_get_uint_val(port_value_node, &port_value);
1133 1105
1134 free(XML_query); 1106 if (!strcmp(result_key, "Result") && !strcmp(result_value, "Success") && !strcmp(port_key, "Port")) {
1135 xmlFreeDoc(plist); 1107 port_loc = port_value;
1136 free_dictionary(dictionary); 1108 ret = IPHONE_E_SUCCESS;
1137 if (port && result) { 1109 }
1110
1111 if (port && ret == IPHONE_E_SUCCESS)
1138 *port = port_loc; 1112 *port = port_loc;
1139 return IPHONE_E_SUCCESS; 1113 else
1140 } else 1114 ret = IPHONE_E_UNKNOWN_ERROR;
1141 return IPHONE_E_UNKNOWN_ERROR;
1142 } 1115 }
1143 1116
1144 return IPHONE_E_UNKNOWN_ERROR; 1117 plist_free(dict);
1118 dict = NULL;
1119 return ret;
1145} 1120}
diff --git a/src/lockdown.h b/src/lockdown.h
index 91bcc77..2f2a4b9 100644
--- a/src/lockdown.h
+++ b/src/lockdown.h
@@ -23,7 +23,6 @@
23#define LOCKDOWND_H 23#define LOCKDOWND_H
24 24
25#include "usbmux.h" 25#include "usbmux.h"
26#include "plist.h"
27 26
28#include <gnutls/gnutls.h> 27#include <gnutls/gnutls.h>
29#include <string.h> 28#include <string.h>
@@ -41,17 +40,17 @@ struct iphone_lckd_client_int {
41 char session_id[40]; 40 char session_id[40];
42}; 41};
43 42
44char *lockdownd_generate_hostid(void);
45
46iphone_lckd_client_t new_lockdownd_client(iphone_device_t phone); 43iphone_lckd_client_t new_lockdownd_client(iphone_device_t phone);
47iphone_error_t lockdownd_hello(iphone_lckd_client_t control); 44iphone_error_t lockdownd_hello(iphone_lckd_client_t control);
48iphone_error_t lockdownd_generic_get_value(iphone_lckd_client_t control, const char *req_key, const char *req_string,
49 char **value);
50iphone_error_t lockdownd_get_device_public_key(iphone_lckd_client_t control, char **public_key);
51 45
52iphone_error_t lockdownd_gen_pair_cert(char *public_key_b64, char **device_cert_b64, char **host_cert_b64, 46iphone_error_t lockdownd_generic_get_value(iphone_lckd_client_t control, const char *req_key, char *req_string,
53 char **root_cert_b64); 47 gnutls_datum_t * value);
54iphone_error_t lockdownd_pair_device(iphone_lckd_client_t control, char *public_key, char *host_id); 48
49iphone_error_t lockdownd_get_device_public_key(iphone_lckd_client_t control, gnutls_datum_t * public_key);
50
51iphone_error_t lockdownd_gen_pair_cert(gnutls_datum_t public_key, gnutls_datum_t * device_cert,
52 gnutls_datum_t * host_cert, gnutls_datum_t * root_cert);
53iphone_error_t lockdownd_pair_device(iphone_lckd_client_t control, char *uid, char *host_id);
55void lockdownd_close(iphone_lckd_client_t control); 54void lockdownd_close(iphone_lckd_client_t control);
56 55
57// SSL functions 56// SSL functions
diff --git a/src/plist.c b/src/plist.c
deleted file mode 100644
index b9d9e6a..0000000
--- a/src/plist.c
+++ /dev/null
@@ -1,245 +0,0 @@
1/*
2 * plist.c
3 * Builds plist XML structures.
4 *
5 * Copyright (c) 2008 Zach C. All Rights Reserved.
6 *
7 * This library is free software; you can redistribute it and/or
8 * modify it under the terms of the GNU Lesser General Public
9 * License as published by the Free Software Foundation; either
10 * version 2.1 of the License, or (at your option) any later version.
11 *
12 * This library is distributed in the hope that it will be useful,
13 * but WITHOUT ANY WARRANTY; without even the implied warranty of
14 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
15 * Lesser General Public License for more details.
16 *
17 * You should have received a copy of the GNU Lesser General Public
18 * License along with this library; if not, write to the Free Software
19 * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA
20 */
21
22#include <libxml/parser.h>
23#include <libxml/tree.h>
24#include <string.h>
25#include <assert.h>
26#include "plist.h"
27
28const char *plist_base = "<?xml version=\"1.0\" encoding=\"UTF-8\"?>\n\
29<!DOCTYPE plist PUBLIC \"-//Apple Computer//DTD PLIST 1.0//EN\" \"http://www.apple.com/DTDs/PropertyList-1.0.dtd\">\n\
30<plist version=\"1.0\">\n\
31</plist>\0";
32
33/** Formats a block of text to be a given indentation and width.
34 *
35 * The total width of the return string will be depth + cols.
36 *
37 * @param buf The string to format.
38 * @param cols The number of text columns for returned block of text.
39 * @param depth The number of tabs to indent the returned block of text.
40 *
41 * @return The formatted string.
42 */
43static char *format_string(const char *buf, int cols, int depth)
44{
45 int colw = depth + cols + 1;
46 int len = strlen(buf);
47 int nlines = len / cols + 1;
48 char *new_buf = (char *) malloc(nlines * colw + depth + 1);
49 int i = 0;
50 int j = 0;
51
52 assert(cols >= 0);
53 assert(depth >= 0);
54
55 // Inserts new lines and tabs at appropriate locations
56 for (i = 0; i < nlines; i++) {
57 new_buf[i * colw] = '\n';
58 for (j = 0; j < depth; j++)
59 new_buf[i * colw + 1 + j] = '\t';
60 memcpy(new_buf + i * colw + 1 + depth, buf + i * cols, cols);
61 }
62 new_buf[len + (1 + depth) * nlines] = '\n';
63
64 // Inserts final row of indentation and termination character
65 for (j = 0; j < depth; j++)
66 new_buf[len + (1 + depth) * nlines + 1 + j] = '\t';
67 new_buf[len + (1 + depth) * nlines + depth + 1] = '\0';
68
69 return new_buf;
70}
71
72/** Creates a new plist XML document.
73 *
74 * @return The plist XML document.
75 */
76xmlDocPtr new_plist(void)
77{
78 char *plist = strdup(plist_base);
79 xmlDocPtr plist_xml = xmlReadMemory(plist, strlen(plist), NULL, NULL, 0);
80
81 if (!plist_xml)
82 return NULL;
83
84 free(plist);
85
86 return plist_xml;
87}
88
89/** Destroys a previously created XML document.
90 *
91 * @param plist The XML document to destroy.
92 */
93void free_plist(xmlDocPtr plist)
94{
95 if (!plist)
96 return;
97
98 xmlFreeDoc(plist);
99}
100
101/** Adds a new node as a child to a given node.
102 *
103 * This is a lower level function so you probably want to use
104 * add_key_str_dict_element, add_key_dict_node or add_key_data_dict_element
105 * instead.
106 *
107 * @param plist The plist XML document to which the to_node belongs.
108 * @param name The name of the new node.
109 * @param content The string containing the text node of the new node.
110 * @param to_node The node to attach the child node to. If none is given, the
111 * root node of the given document is used.
112 * @param depth The number of tabs to indent the new node.
113 *
114 * @return The newly created node.
115 */
116xmlNode *add_child_to_plist(xmlDocPtr plist, const char *name, const char *content, xmlNode * to_node, int depth)
117{
118 int i = 0;
119 xmlNode *child;
120
121 if (!plist)
122 return NULL;
123 assert(depth >= 0);
124 if (!to_node)
125 to_node = xmlDocGetRootElement(plist);
126
127 for (i = 0; i < depth; i++) {
128 xmlNodeAddContent(to_node, "\t");
129 }
130 child = xmlNewChild(to_node, NULL, name, content);
131 xmlNodeAddContent(to_node, "\n");
132
133 return child;
134}
135
136/** Adds a string key-pair to a plist XML document.
137 *
138 * @param plist The plist XML document to add the new node to.
139 * @param dict The dictionary node within the plist XML document to add the new node to.
140 * @param key The string containing the key value.
141 * @param value The string containing the value.
142 * @param depth The number of tabs to indent the new node.
143 *
144 * @return The newly created key node.
145 */
146xmlNode *add_key_str_dict_element(xmlDocPtr plist, xmlNode * dict, const char *key, const char *value, int depth)
147{
148 xmlNode *keyPtr;
149
150 keyPtr = add_child_to_plist(plist, "key", key, dict, depth);
151 add_child_to_plist(plist, "string", value, dict, depth);
152
153 return keyPtr;
154}
155
156/** Adds a new dictionary key-pair to a plist XML document.
157 *
158 * @param plist The plist XML document to add the new node to.
159 * @param dict The dictionary node within the plist XML document to add the new node to.
160 * @param key The string containing the key value.
161 * @param value The string containing the value.
162 * @param depth The number of tabs to indent the new node.
163 *
164 * @return The newly created dict node.
165 */
166xmlNode *add_key_dict_node(xmlDocPtr plist, xmlNode * dict, const char *key, const char *value, int depth)
167{
168 xmlNode *child;
169
170 add_child_to_plist(plist, "key", key, dict, depth);
171 child = add_child_to_plist(plist, "dict", value, dict, depth);
172
173 return child;
174}
175
176/** Adds a new data dictionary key-pair to a plist XML document.
177 *
178 * @param plist The plist XML document to add the new node to.
179 * @param dict The dictionary node within the plist XML document to add the new node to.
180 * @param key The string containing the key value.
181 * @param value The string containing the value.
182 * @param depth The number of tabs to indent the new node.
183 *
184 * @return The newly created key node.
185 */
186xmlNode *add_key_data_dict_element(xmlDocPtr plist, xmlNode * dict, const char *key, const char *value, int depth)
187{
188 xmlNode *keyPtr;
189
190 keyPtr = add_child_to_plist(plist, "key", key, dict, depth);
191 add_child_to_plist(plist, "data", format_string(value, 60, depth), dict, depth);
192
193 return keyPtr;
194}
195
196/** Reads a set of keys and strings into an array from a plist XML document.
197 *
198 * @param dict The root XMLNode of a plist XML document to be read.
199 *
200 * @return An array where each even number is a key and the odd numbers are
201 * values. If the odd number is \0, that's the end of the list.
202 */
203char **read_dict_element_strings(xmlNode * dict)
204{
205 char **return_me = NULL, **old = NULL;
206 int current_length = 0;
207 int current_pos = 0;
208 xmlNode *dict_walker;
209
210 for (dict_walker = dict->children; dict_walker; dict_walker = dict_walker->next) {
211 if (!xmlStrcmp(dict_walker->name, "key")) {
212 current_length += 2;
213 old = return_me;
214 return_me = realloc(return_me, sizeof(char *) * current_length);
215 if (!return_me) {
216 free(old);
217 return NULL;
218 }
219 return_me[current_pos++] = xmlNodeGetContent(dict_walker);
220 return_me[current_pos++] = xmlNodeGetContent(dict_walker->next->next);
221 }
222 }
223
224 old = return_me;
225 return_me = realloc(return_me, sizeof(char *) * (current_length + 1));
226 return_me[current_pos] = NULL;
227
228 return return_me;
229}
230
231/** Destroys a dictionary as returned by read_dict_element_strings
232 */
233void free_dictionary(char **dictionary)
234{
235 int i = 0;
236
237 if (!dictionary)
238 return;
239
240 for (i = 0; dictionary[i]; i++) {
241 free(dictionary[i]);
242 }
243
244 free(dictionary);
245}
diff --git a/src/plist.h b/src/plist.h
deleted file mode 100644
index cd2028e..0000000
--- a/src/plist.h
+++ /dev/null
@@ -1,38 +0,0 @@
1/*
2 * plist.h
3 * contains structures and the like for plists
4 *
5 * Copyright (c) 2008 Zach C. All Rights Reserved.
6 *
7 * This library is free software; you can redistribute it and/or
8 * modify it under the terms of the GNU Lesser General Public
9 * License as published by the Free Software Foundation; either
10 * version 2.1 of the License, or (at your option) any later version.
11 *
12 * This library is distributed in the hope that it will be useful,
13 * but WITHOUT ANY WARRANTY; without even the implied warranty of
14 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
15 * Lesser General Public License for more details.
16 *
17 * You should have received a copy of the GNU Lesser General Public
18 * License along with this library; if not, write to the Free Software
19 * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA
20 */
21
22#ifndef PLIST_H
23#define PLIST_H
24
25#include <libxml/parser.h>
26#include <libxml/tree.h>
27
28xmlNode *add_key_dict_node(xmlDocPtr plist, xmlNode * dict, const char *key, const char *value, int depth);
29xmlNode *add_key_str_dict_element(xmlDocPtr plist, xmlNode * dict, const char *key, const char *value, int depth);
30xmlNode *add_key_data_dict_element(xmlDocPtr plist, xmlNode * dict, const char *key, const char *value, int depth);
31xmlNode *add_child_to_plist(xmlDocPtr plist, const char *name, const char *content, xmlNode * to_node, int depth);
32
33void free_plist(xmlDocPtr plist);
34xmlDocPtr new_plist(void);
35
36char **read_dict_element_strings(xmlNode * dict);
37void free_dictionary(char **dictionary);
38#endif
diff --git a/src/usbmux.c b/src/usbmux.c
index c7ac7ef..5eaa1d1 100644
--- a/src/usbmux.c
+++ b/src/usbmux.c
@@ -38,7 +38,7 @@ static int clients = 0;
38 * 38 *
39 * @return A USBMux packet 39 * @return A USBMux packet
40 */ 40 */
41usbmux_tcp_header *new_mux_packet(uint16 s_port, uint16 d_port) 41usbmux_tcp_header *new_mux_packet(uint16_t s_port, uint16_t d_port)
42{ 42{
43 usbmux_tcp_header *conn = (usbmux_tcp_header *) malloc(sizeof(usbmux_tcp_header)); 43 usbmux_tcp_header *conn = (usbmux_tcp_header *) malloc(sizeof(usbmux_tcp_header));
44 conn->type = htonl(6); 44 conn->type = htonl(6);
@@ -313,6 +313,7 @@ iphone_error_t iphone_mux_recv(iphone_umux_client_t client, char *data, uint32_t
313 } else { 313 } else {
314 memcpy(data, client->recv_buffer, client->r_len); 314 memcpy(data, client->recv_buffer, client->r_len);
315 free(client->recv_buffer); // don't need to deal with anymore, but... 315 free(client->recv_buffer); // don't need to deal with anymore, but...
316 client->recv_buffer = NULL;
316 offset = client->r_len; // see #2b, above 317 offset = client->r_len; // see #2b, above
317 client->r_len = 0; 318 client->r_len = 0;
318 } 319 }
diff --git a/src/usbmux.h b/src/usbmux.h
index fd5fc78..bea83f7 100644
--- a/src/usbmux.h
+++ b/src/usbmux.h
@@ -22,6 +22,7 @@
22#include <sys/types.h> 22#include <sys/types.h>
23#include <stdlib.h> 23#include <stdlib.h>
24#include <stdint.h> 24#include <stdint.h>
25#include "libiphone/libiphone.h"
25 26
26#ifndef USBMUX_H 27#ifndef USBMUX_H
27#define USBMUX_H 28#define USBMUX_H
@@ -30,17 +31,12 @@
30#include "iphone.h" 31#include "iphone.h"
31#endif 32#endif
32 33
33typedef uint16_t uint16;
34typedef uint32_t uint32;
35typedef uint8_t uint8;
36
37
38typedef struct { 34typedef struct {
39 uint32 type, length; 35 uint32_t type, length;
40 uint16 sport, dport; 36 uint16_t sport, dport;
41 uint32 scnt, ocnt; 37 uint32_t scnt, ocnt;
42 uint8 offset, tcp_flags; 38 uint8_t offset, tcp_flags;
43 uint16 window, nullnull, length16; 39 uint16_t window, nullnull, length16;
44} usbmux_tcp_header; 40} usbmux_tcp_header;
45 41
46struct iphone_umux_client_int { 42struct iphone_umux_client_int {
@@ -50,10 +46,10 @@ struct iphone_umux_client_int {
50 int r_len; 46 int r_len;
51}; 47};
52 48
53usbmux_tcp_header *new_mux_packet(uint16 s_port, uint16 d_port); 49usbmux_tcp_header *new_mux_packet(uint16_t s_port, uint16_t d_port);
54 50
55typedef struct { 51typedef struct {
56 uint32 type, length, major, minor, allnull; 52 uint32_t type, length, major, minor, allnull;
57} usbmux_version_header; 53} usbmux_version_header;
58 54
59usbmux_version_header *version_header(void); 55usbmux_version_header *version_header(void);
diff --git a/src/userpref.c b/src/userpref.c
index 5f227b0..3e5eb06 100644
--- a/src/userpref.c
+++ b/src/userpref.c
@@ -111,10 +111,10 @@ int is_device_known(char *uid)
111 * @return 1 on success and 0 if no public key is given or if it has already 111 * @return 1 on success and 0 if no public key is given or if it has already
112 * been marked as connected previously. 112 * been marked as connected previously.
113 */ 113 */
114int store_device_public_key(char *uid, char *public_key) 114int store_device_public_key(char *uid, gnutls_datum_t public_key)
115{ 115{
116 116
117 if (NULL == public_key || is_device_known(uid)) 117 if (NULL == public_key.data || is_device_known(uid))
118 return 0; 118 return 0;
119 119
120 /* ensure config directory exists */ 120 /* ensure config directory exists */
@@ -124,15 +124,11 @@ int store_device_public_key(char *uid, char *public_key)
124 gchar *device_file = g_strconcat(uid, ".pem", NULL); 124 gchar *device_file = g_strconcat(uid, ".pem", NULL);
125 gchar *pem = g_build_path(G_DIR_SEPARATOR_S, g_get_user_config_dir(), LIBIPHONE_CONF_DIR, device_file, NULL); 125 gchar *pem = g_build_path(G_DIR_SEPARATOR_S, g_get_user_config_dir(), LIBIPHONE_CONF_DIR, device_file, NULL);
126 126
127 /* decode public key for storing */
128 gsize decoded_size;
129 gchar *data = g_base64_decode(public_key, &decoded_size);
130 /* store file */ 127 /* store file */
131 FILE *pFile = fopen(pem, "wb"); 128 FILE *pFile = fopen(pem, "wb");
132 fwrite(data, 1, decoded_size, pFile); 129 fwrite(public_key.data, 1, public_key.size, pFile);
133 fclose(pFile); 130 fclose(pFile);
134 g_free(pem); 131 g_free(pem);
135 g_free(data);
136 g_free(device_file); 132 g_free(device_file);
137 return 1; 133 return 1;
138} 134}
diff --git a/src/userpref.h b/src/userpref.h
index e7835d0..7e606eb 100644
--- a/src/userpref.h
+++ b/src/userpref.h
@@ -40,7 +40,7 @@ int is_device_known(char *uid);
40/** 40/**
41 * @return 1 if everything went well. Returns 0 otherwise. 41 * @return 1 if everything went well. Returns 0 otherwise.
42 */ 42 */
43int store_device_public_key(char *uid, char *public_key); 43int store_device_public_key(char *uid, gnutls_datum_t public_key);
44 44
45/** 45/**
46 * @return 1 if everything went well. Returns 0 otherwise. 46 * @return 1 if everything went well. Returns 0 otherwise.
diff --git a/src/utils.c b/src/utils.c
index fb98471..5b0872d 100644
--- a/src/utils.c
+++ b/src/utils.c
@@ -23,6 +23,7 @@
23#include "utils.h" 23#include "utils.h"
24 24
25int toto_debug = 0; 25int toto_debug = 0;
26uint16_t dbg_mask = 0;
26 27
27/** 28/**
28 * Sets the level of debugging. Currently the only acceptable values are 0 and 29 * Sets the level of debugging. Currently the only acceptable values are 0 and
@@ -36,6 +37,15 @@ void iphone_set_debug(int level)
36} 37}
37 38
38 39
40/**
41 * Set debug ids to display. Values can be OR-ed
42 *
43 * @param level Set to 0 for no debugging or 1 for debugging.
44 */
45void iphone_set_debug_mask(uint16_t mask)
46{
47 dbg_mask = mask;
48}
39 49
40void log_debug_msg(const char *format, ...) 50void log_debug_msg(const char *format, ...)
41{ 51{
@@ -53,6 +63,21 @@ void log_debug_msg(const char *format, ...)
53#endif 63#endif
54} 64}
55 65
66void log_dbg_msg(uint16_t id, const char *format, ...)
67{
68#ifndef STRIP_DEBUG_CODE
69 if (id & dbg_mask) {
70 va_list args;
71 /* run the real fprintf */
72 va_start(args, format);
73
74 vfprintf(stderr, format, args);
75
76 va_end(args);
77 }
78#endif
79}
80
56inline void log_debug_buffer(const char *data, const int length) 81inline void log_debug_buffer(const char *data, const int length)
57{ 82{
58#ifndef STRIP_DEBUG_CODE 83#ifndef STRIP_DEBUG_CODE
diff --git a/src/utils.h b/src/utils.h
index 489f610..1750b8e 100644
--- a/src/utils.h
+++ b/src/utils.h
@@ -24,7 +24,11 @@
24 24
25#include "libiphone/libiphone.h" 25#include "libiphone/libiphone.h"
26 26
27
28
27inline void log_debug_msg(const char *format, ...); 29inline void log_debug_msg(const char *format, ...);
30inline void log_dbg_msg(uint16_t id, const char *format, ...);
31
28inline void log_debug_buffer(const char *data, const int length); 32inline void log_debug_buffer(const char *data, const int length);
29inline void dump_debug_buffer(const char *file, const char *data, const int length); 33inline void dump_debug_buffer(const char *file, const char *data, const int length);
30#endif 34#endif