Coverage Report

Created: 2025-12-03 07:13

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/curl/lib/mqtt.c
Line
Count
Source
1
/***************************************************************************
2
 *                                  _   _ ____  _
3
 *  Project                     ___| | | |  _ \| |
4
 *                             / __| | | | |_) | |
5
 *                            | (__| |_| |  _ <| |___
6
 *                             \___|\___/|_| \_\_____|
7
 *
8
 * Copyright (C) Daniel Stenberg, <daniel@haxx.se>, et al.
9
 * Copyright (C) Björn Stenberg, <bjorn@haxx.se>
10
 *
11
 * This software is licensed as described in the file COPYING, which
12
 * you should have received as part of this distribution. The terms
13
 * are also available at https://curl.se/docs/copyright.html.
14
 *
15
 * You may opt to use, copy, modify, merge, publish, distribute and/or sell
16
 * copies of the Software, and permit persons to whom the Software is
17
 * furnished to do so, under the terms of the COPYING file.
18
 *
19
 * This software is distributed on an "AS IS" basis, WITHOUT WARRANTY OF ANY
20
 * KIND, either express or implied.
21
 *
22
 * SPDX-License-Identifier: curl
23
 *
24
 ***************************************************************************/
25
26
#include "curl_setup.h"
27
28
#ifndef CURL_DISABLE_MQTT
29
30
#include "urldata.h"
31
#include <curl/curl.h>
32
#include "transfer.h"
33
#include "sendf.h"
34
#include "progress.h"
35
#include "mqtt.h"
36
#include "select.h"
37
#include "url.h"
38
#include "escape.h"
39
#include "curlx/warnless.h"
40
#include "multiif.h"
41
#include "rand.h"
42
43
/* first byte is command.
44
   second byte is for flags. */
45
1.22k
#define MQTT_MSG_CONNECT    0x10
46
/* #define MQTT_MSG_CONNACK    0x20 */
47
2.14k
#define MQTT_MSG_PUBLISH    0x30
48
136
#define MQTT_MSG_SUBSCRIBE  0x82
49
98
#define MQTT_MSG_SUBACK     0x90
50
15.4k
#define MQTT_MSG_DISCONNECT 0xe0
51
/* #define MQTT_MSG_PINGREQ    0xC0 */
52
15.4k
#define MQTT_MSG_PINGRESP   0xD0
53
54
5.26M
#define MQTT_CONNACK_LEN 2
55
154
#define MQTT_SUBACK_LEN 3
56
7.35k
#define MQTT_CLIENTID_LEN 12 /* "curl0123abcd" */
57
58
/* meta key for storing protocol meta at easy handle */
59
21.1M
#define CURL_META_MQTT_EASY   "meta:proto:mqtt:easy"
60
/* meta key for storing protocol meta at connection */
61
10.6M
#define CURL_META_MQTT_CONN   "meta:proto:mqtt:conn"
62
63
enum mqttstate {
64
  MQTT_FIRST,             /* 0 */
65
  MQTT_REMAINING_LENGTH,  /* 1 */
66
  MQTT_CONNACK,           /* 2 */
67
  MQTT_SUBACK,            /* 3 */
68
  MQTT_SUBACK_COMING,     /* 4 - the SUBACK remainder */
69
  MQTT_PUBWAIT,    /* 5 - wait for publish */
70
  MQTT_PUB_REMAIN,  /* 6 - wait for the remainder of the publish */
71
72
  MQTT_NOSTATE /* 7 - never used an actual state */
73
};
74
75
struct mqtt_conn {
76
  enum mqttstate state;
77
  enum mqttstate nextstate; /* switch to this after remaining length is
78
                               done */
79
  unsigned int packetid;
80
};
81
82
/* protocol-specific transfer-related data */
83
struct MQTT {
84
  struct dynbuf sendbuf;
85
  /* when receiving */
86
  struct dynbuf recvbuf;
87
  size_t npacket; /* byte counter */
88
  size_t remaining_length;
89
  unsigned char pkt_hd[4]; /* for decoding the arriving packet length */
90
  struct curltime lastTime; /* last time we sent or received data */
91
  unsigned char firstbyte;
92
  BIT(pingsent); /* 1 while we wait for ping response */
93
};
94
95
96
/*
97
 * Forward declarations.
98
 */
99
100
static CURLcode mqtt_do(struct Curl_easy *data, bool *done);
101
static CURLcode mqtt_done(struct Curl_easy *data,
102
                          CURLcode status, bool premature);
103
static CURLcode mqtt_doing(struct Curl_easy *data, bool *done);
104
static CURLcode mqtt_pollset(struct Curl_easy *data,
105
                             struct easy_pollset *ps);
106
static CURLcode mqtt_setup_conn(struct Curl_easy *data,
107
                                struct connectdata *conn);
108
109
/*
110
 * MQTT protocol handler.
111
 */
112
113
const struct Curl_handler Curl_handler_mqtt = {
114
  "mqtt",                             /* scheme */
115
  mqtt_setup_conn,                    /* setup_connection */
116
  mqtt_do,                            /* do_it */
117
  mqtt_done,                          /* done */
118
  ZERO_NULL,                          /* do_more */
119
  ZERO_NULL,                          /* connect_it */
120
  ZERO_NULL,                          /* connecting */
121
  mqtt_doing,                         /* doing */
122
  ZERO_NULL,                          /* proto_pollset */
123
  mqtt_pollset,                       /* doing_pollset */
124
  ZERO_NULL,                          /* domore_pollset */
125
  ZERO_NULL,                          /* perform_pollset */
126
  ZERO_NULL,                          /* disconnect */
127
  ZERO_NULL,                          /* write_resp */
128
  ZERO_NULL,                          /* write_resp_hd */
129
  ZERO_NULL,                          /* connection_check */
130
  ZERO_NULL,                          /* attach connection */
131
  ZERO_NULL,                          /* follow */
132
  PORT_MQTT,                          /* defport */
133
  CURLPROTO_MQTT,                     /* protocol */
134
  CURLPROTO_MQTT,                     /* family */
135
  PROTOPT_NONE                        /* flags */
136
};
137
138
static void mqtt_easy_dtor(void *key, size_t klen, void *entry)
139
5.40k
{
140
5.40k
  struct MQTT *mq = entry;
141
5.40k
  (void)key;
142
5.40k
  (void)klen;
143
5.40k
  curlx_dyn_free(&mq->sendbuf);
144
5.40k
  curlx_dyn_free(&mq->recvbuf);
145
5.40k
  curlx_free(mq);
146
5.40k
}
147
148
static void mqtt_conn_dtor(void *key, size_t klen, void *entry)
149
5.40k
{
150
5.40k
  (void)key;
151
5.40k
  (void)klen;
152
5.40k
  curlx_free(entry);
153
5.40k
}
154
155
static CURLcode mqtt_setup_conn(struct Curl_easy *data,
156
                                struct connectdata *conn)
157
5.40k
{
158
  /* setup MQTT specific meta data at easy handle and connection */
159
5.40k
  struct mqtt_conn *mqtt;
160
5.40k
  struct MQTT *mq;
161
162
5.40k
  mqtt = curlx_calloc(1, sizeof(*mqtt));
163
5.40k
  if(!mqtt ||
164
5.40k
     Curl_conn_meta_set(conn, CURL_META_MQTT_CONN, mqtt, mqtt_conn_dtor))
165
0
    return CURLE_OUT_OF_MEMORY;
166
167
5.40k
  mq = curlx_calloc(1, sizeof(struct MQTT));
168
5.40k
  if(!mq)
169
0
    return CURLE_OUT_OF_MEMORY;
170
5.40k
  curlx_dyn_init(&mq->recvbuf, DYN_MQTT_RECV);
171
5.40k
  curlx_dyn_init(&mq->sendbuf, DYN_MQTT_SEND);
172
5.40k
  if(Curl_meta_set(data, CURL_META_MQTT_EASY, mq, mqtt_easy_dtor))
173
0
    return CURLE_OUT_OF_MEMORY;
174
5.40k
  return CURLE_OK;
175
5.40k
}
176
177
static CURLcode mqtt_send(struct Curl_easy *data,
178
                          const char *buf, size_t len)
179
1.38k
{
180
1.38k
  size_t n;
181
1.38k
  CURLcode result;
182
1.38k
  struct MQTT *mq = Curl_meta_get(data, CURL_META_MQTT_EASY);
183
184
1.38k
  if(!mq)
185
0
    return CURLE_FAILED_INIT;
186
187
1.38k
  result = Curl_xfer_send(data, buf, len, FALSE, &n);
188
1.38k
  if(result)
189
0
    return result;
190
1.38k
  mq->lastTime = curlx_now();
191
1.38k
  Curl_debug(data, CURLINFO_HEADER_OUT, buf, n);
192
1.38k
  if(len != n) {
193
0
    size_t nsend = len - n;
194
0
    if(curlx_dyn_len(&mq->sendbuf)) {
195
0
      DEBUGASSERT(curlx_dyn_len(&mq->sendbuf) >= nsend);
196
0
      result = curlx_dyn_tail(&mq->sendbuf, nsend); /* keep this much */
197
0
    }
198
0
    else {
199
0
      result = curlx_dyn_addn(&mq->sendbuf, &buf[n], nsend);
200
0
    }
201
0
  }
202
1.38k
  else
203
1.38k
    curlx_dyn_reset(&mq->sendbuf);
204
1.38k
  return result;
205
1.38k
}
206
207
/* Generic function called by the multi interface to figure out what socket(s)
208
   to wait for and for what actions during the DOING and PROTOCONNECT
209
   states */
210
static CURLcode mqtt_pollset(struct Curl_easy *data,
211
                             struct easy_pollset *ps)
212
5.28M
{
213
5.28M
  return Curl_pollset_add_in(data, ps, data->conn->sock[FIRSTSOCKET]);
214
5.28M
}
215
216
static int mqtt_encode_len(char *buf, size_t len)
217
1.37k
{
218
1.37k
  int i;
219
220
2.86k
  for(i = 0; (len > 0) && (i < 4); i++) {
221
1.48k
    unsigned char encoded;
222
1.48k
    encoded = len % 0x80;
223
1.48k
    len /= 0x80;
224
1.48k
    if(len)
225
108
      encoded |= 0x80;
226
1.48k
    buf[i] = (char)encoded;
227
1.48k
  }
228
229
1.37k
  return i;
230
1.37k
}
231
232
/* add the passwd to the CONNECT packet */
233
static int add_passwd(const char *passwd, const size_t plen,
234
                      char *pkt, const size_t start, int remain_pos)
235
34
{
236
  /* magic number that need to be set properly */
237
34
  const size_t conn_flags_pos = remain_pos + 8;
238
34
  if(plen > 0xffff)
239
1
    return 1;
240
241
  /* set password flag */
242
33
  pkt[conn_flags_pos] |= 0x40;
243
244
  /* length of password provided */
245
33
  pkt[start] = (char)((plen >> 8) & 0xFF);
246
33
  pkt[start + 1] = (char)(plen & 0xFF);
247
33
  memcpy(&pkt[start + 2], passwd, plen);
248
33
  return 0;
249
34
}
250
251
/* add user to the CONNECT packet */
252
static int add_user(const char *username, const size_t ulen,
253
                    unsigned char *pkt, const size_t start, int remain_pos)
254
131
{
255
  /* magic number that need to be set properly */
256
131
  const size_t conn_flags_pos = remain_pos + 8;
257
131
  if(ulen > 0xffff)
258
6
    return 1;
259
260
  /* set username flag */
261
125
  pkt[conn_flags_pos] |= 0x80;
262
  /* length of username provided */
263
125
  pkt[start] = (unsigned char)((ulen >> 8) & 0xFF);
264
125
  pkt[start + 1] = (unsigned char)(ulen & 0xFF);
265
125
  memcpy(&pkt[start + 2], username, ulen);
266
125
  return 0;
267
131
}
268
269
/* add client ID to the CONNECT packet */
270
static int add_client_id(const char *client_id, const size_t client_id_len,
271
                         char *pkt, const size_t start)
272
1.22k
{
273
1.22k
  if(client_id_len != MQTT_CLIENTID_LEN)
274
0
    return 1;
275
1.22k
  pkt[start] = 0x00;
276
1.22k
  pkt[start + 1] = MQTT_CLIENTID_LEN;
277
1.22k
  memcpy(&pkt[start + 2], client_id, MQTT_CLIENTID_LEN);
278
1.22k
  return 0;
279
1.22k
}
280
281
/* Set initial values of CONNECT packet */
282
static int init_connpack(char *packet, char *remain, int remain_pos)
283
1.22k
{
284
  /* Fixed header starts */
285
  /* packet type */
286
1.22k
  packet[0] = MQTT_MSG_CONNECT;
287
  /* remaining length field */
288
1.22k
  memcpy(&packet[1], remain, remain_pos);
289
  /* Fixed header ends */
290
291
  /* Variable header starts */
292
  /* protocol length */
293
1.22k
  packet[remain_pos + 1] = 0x00;
294
1.22k
  packet[remain_pos + 2] = 0x04;
295
  /* protocol name */
296
1.22k
  packet[remain_pos + 3] = 'M';
297
1.22k
  packet[remain_pos + 4] = 'Q';
298
1.22k
  packet[remain_pos + 5] = 'T';
299
1.22k
  packet[remain_pos + 6] = 'T';
300
  /* protocol level */
301
1.22k
  packet[remain_pos + 7] = 0x04;
302
  /* CONNECT flag: CleanSession */
303
1.22k
  packet[remain_pos + 8] = 0x02;
304
  /* keep-alive 0 = disabled */
305
1.22k
  packet[remain_pos + 9] = 0x00;
306
1.22k
  packet[remain_pos + 10] = 0x3c;
307
  /* end of variable header */
308
1.22k
  return remain_pos + 10;
309
1.22k
}
310
311
static CURLcode mqtt_connect(struct Curl_easy *data)
312
1.22k
{
313
1.22k
  CURLcode result = CURLE_OK;
314
1.22k
  int pos = 0;
315
1.22k
  int rc = 0;
316
  /* remain length */
317
1.22k
  int remain_pos = 0;
318
1.22k
  char remain[4] = {0};
319
1.22k
  size_t packetlen = 0;
320
1.22k
  size_t start_user = 0;
321
1.22k
  size_t start_pwd = 0;
322
1.22k
  char client_id[MQTT_CLIENTID_LEN + 1] = "curl";
323
1.22k
  const size_t clen = strlen("curl");
324
1.22k
  char *packet = NULL;
325
326
  /* extracting username from request */
327
1.22k
  const char *username = data->state.aptr.user ?
328
1.05k
    data->state.aptr.user : "";
329
1.22k
  const size_t ulen = strlen(username);
330
  /* extracting password from request */
331
1.22k
  const char *passwd = data->state.aptr.passwd ?
332
1.18k
    data->state.aptr.passwd : "";
333
1.22k
  const size_t plen = strlen(passwd);
334
1.22k
  const size_t payloadlen = ulen + plen + MQTT_CLIENTID_LEN + 2 +
335
  /* The plus 2s below are for the MSB and LSB describing the length of the
336
     string to be added on the payload. Refer to spec 1.5.2 and 1.5.4 */
337
1.22k
    (ulen ? 2 : 0) +
338
1.22k
    (plen ? 2 : 0);
339
340
  /* getting how much occupy the remain length */
341
1.22k
  remain_pos = mqtt_encode_len(remain, payloadlen + 10);
342
343
  /* 10 length of variable header and 1 the first byte of the fixed header */
344
1.22k
  packetlen = payloadlen + 10 + remain_pos + 1;
345
346
  /* allocating packet */
347
1.22k
  if(packetlen > 0xFFFFFFF)
348
0
    return CURLE_WEIRD_SERVER_REPLY;
349
1.22k
  packet = curlx_calloc(1, packetlen);
350
1.22k
  if(!packet)
351
0
    return CURLE_OUT_OF_MEMORY;
352
353
  /* set initial values for the CONNECT packet */
354
1.22k
  pos = init_connpack(packet, remain, remain_pos);
355
356
1.22k
  result = Curl_rand_alnum(data, (unsigned char *)&client_id[clen],
357
1.22k
                           MQTT_CLIENTID_LEN - clen + 1);
358
  /* add client id */
359
1.22k
  rc = add_client_id(client_id, strlen(client_id), packet, pos + 1);
360
1.22k
  if(rc) {
361
0
    failf(data, "Client ID length mismatched: [%zu]", strlen(client_id));
362
0
    result = CURLE_WEIRD_SERVER_REPLY;
363
0
    goto end;
364
0
  }
365
1.22k
  infof(data, "Using client id '%s'", client_id);
366
367
  /* position where the user payload starts */
368
1.22k
  start_user = pos + 3 + MQTT_CLIENTID_LEN;
369
  /* position where the password payload starts */
370
1.22k
  start_pwd = start_user + ulen;
371
  /* if username was provided, add it to the packet */
372
1.22k
  if(ulen) {
373
131
    start_pwd += 2;
374
375
131
    rc = add_user(username, ulen,
376
131
                  (unsigned char *)packet, start_user, remain_pos);
377
131
    if(rc) {
378
6
      failf(data, "Username too long: [%zu]", ulen);
379
6
      result = CURLE_WEIRD_SERVER_REPLY;
380
6
      goto end;
381
6
    }
382
131
  }
383
384
  /* if passwd was provided, add it to the packet */
385
1.21k
  if(plen) {
386
34
    rc = add_passwd(passwd, plen, packet, start_pwd, remain_pos);
387
34
    if(rc) {
388
1
      failf(data, "Password too long: [%zu]", plen);
389
1
      result = CURLE_WEIRD_SERVER_REPLY;
390
1
      goto end;
391
1
    }
392
34
  }
393
394
1.21k
  if(!result)
395
1.21k
    result = mqtt_send(data, packet, packetlen);
396
397
1.22k
end:
398
1.22k
  if(packet)
399
1.22k
    curlx_free(packet);
400
1.22k
  Curl_safefree(data->state.aptr.user);
401
1.22k
  Curl_safefree(data->state.aptr.passwd);
402
1.22k
  return result;
403
1.21k
}
404
405
static CURLcode mqtt_disconnect(struct Curl_easy *data)
406
17
{
407
17
  return mqtt_send(data, "\xe0\x00", 2);
408
17
}
409
410
static CURLcode mqtt_recv_atleast(struct Curl_easy *data, size_t nbytes)
411
5.26M
{
412
5.26M
  struct MQTT *mq = Curl_meta_get(data, CURL_META_MQTT_EASY);
413
5.26M
  size_t rlen;
414
5.26M
  CURLcode result;
415
416
5.26M
  if(!mq)
417
0
    return CURLE_FAILED_INIT;
418
5.26M
  rlen = curlx_dyn_len(&mq->recvbuf);
419
420
5.26M
  if(rlen < nbytes) {
421
5.26M
    unsigned char readbuf[1024];
422
5.26M
    size_t nread;
423
424
5.26M
    DEBUGASSERT(nbytes - rlen < sizeof(readbuf));
425
5.26M
    result = Curl_xfer_recv(data, (char *)readbuf, nbytes - rlen, &nread);
426
5.26M
    if(result)
427
4
      return result;
428
5.26M
    if(curlx_dyn_addn(&mq->recvbuf, readbuf, nread))
429
0
      return CURLE_OUT_OF_MEMORY;
430
5.26M
    rlen = curlx_dyn_len(&mq->recvbuf);
431
5.26M
  }
432
5.26M
  return (rlen >= nbytes) ? CURLE_OK : CURLE_AGAIN;
433
5.26M
}
434
435
static void mqtt_recv_consume(struct Curl_easy *data, size_t nbytes)
436
208
{
437
208
  struct MQTT *mq = Curl_meta_get(data, CURL_META_MQTT_EASY);
438
208
  DEBUGASSERT(mq);
439
208
  if(mq) {
440
208
    size_t rlen = curlx_dyn_len(&mq->recvbuf);
441
208
    if(rlen <= nbytes)
442
208
      curlx_dyn_reset(&mq->recvbuf);
443
0
    else
444
0
      curlx_dyn_tail(&mq->recvbuf, rlen - nbytes);
445
208
  }
446
208
}
447
448
static CURLcode mqtt_verify_connack(struct Curl_easy *data)
449
5.26M
{
450
5.26M
  struct MQTT *mq = Curl_meta_get(data, CURL_META_MQTT_EASY);
451
5.26M
  CURLcode result;
452
5.26M
  char *ptr;
453
454
5.26M
  DEBUGASSERT(mq);
455
5.26M
  if(!mq)
456
0
    return CURLE_FAILED_INIT;
457
458
5.26M
  result = mqtt_recv_atleast(data, MQTT_CONNACK_LEN);
459
5.26M
  if(result)
460
5.26M
    goto fail;
461
462
  /* verify CONNACK */
463
177
  DEBUGASSERT(curlx_dyn_len(&mq->recvbuf) >= MQTT_CONNACK_LEN);
464
177
  ptr = curlx_dyn_ptr(&mq->recvbuf);
465
177
  Curl_debug(data, CURLINFO_HEADER_IN, ptr, MQTT_CONNACK_LEN);
466
467
177
  if(ptr[0] != 0x00 || ptr[1] != 0x00) {
468
8
    failf(data, "Expected %02x%02x but got %02x%02x",
469
8
          0x00, 0x00, ptr[0], ptr[1]);
470
8
    curlx_dyn_reset(&mq->recvbuf);
471
8
    result = CURLE_WEIRD_SERVER_REPLY;
472
8
    goto fail;
473
8
  }
474
169
  mqtt_recv_consume(data, MQTT_CONNACK_LEN);
475
5.26M
fail:
476
5.26M
  return result;
477
169
}
478
479
static CURLcode mqtt_get_topic(struct Curl_easy *data,
480
                               char **topic, size_t *topiclen)
481
168
{
482
168
  char *path = data->state.up.path;
483
168
  CURLcode result = CURLE_URL_MALFORMAT;
484
168
  if(strlen(path) > 1) {
485
164
    result = Curl_urldecode(path + 1, 0, topic, topiclen, REJECT_NADA);
486
164
    if(!result && (*topiclen > 0xffff)) {
487
11
      failf(data, "Too long MQTT topic");
488
11
      result = CURLE_URL_MALFORMAT;
489
11
    }
490
164
  }
491
4
  else
492
4
    failf(data, "No MQTT topic found. Forgot to URL encode it?");
493
494
168
  return result;
495
168
}
496
497
static CURLcode mqtt_subscribe(struct Curl_easy *data)
498
140
{
499
140
  CURLcode result = CURLE_OK;
500
140
  char *topic = NULL;
501
140
  size_t topiclen;
502
140
  unsigned char *packet = NULL;
503
140
  size_t packetlen;
504
140
  char encodedsize[4];
505
140
  size_t n;
506
140
  struct connectdata *conn = data->conn;
507
140
  struct mqtt_conn *mqtt = Curl_conn_meta_get(conn, CURL_META_MQTT_CONN);
508
509
140
  if(!mqtt)
510
0
    return CURLE_FAILED_INIT;
511
512
140
  result = mqtt_get_topic(data, &topic, &topiclen);
513
140
  if(result)
514
4
    goto fail;
515
516
136
  mqtt->packetid++;
517
518
136
  packetlen = topiclen + 5; /* packetid + topic (has a two byte length field)
519
                               + 2 bytes topic length + QoS byte */
520
136
  n = mqtt_encode_len((char *)encodedsize, packetlen);
521
136
  packetlen += n + 1; /* add one for the control packet type byte */
522
523
136
  packet = curlx_malloc(packetlen);
524
136
  if(!packet) {
525
0
    result = CURLE_OUT_OF_MEMORY;
526
0
    goto fail;
527
0
  }
528
529
136
  packet[0] = MQTT_MSG_SUBSCRIBE;
530
136
  memcpy(&packet[1], encodedsize, n);
531
136
  packet[1 + n] = (mqtt->packetid >> 8) & 0xff;
532
136
  packet[2 + n] = mqtt->packetid & 0xff;
533
136
  packet[3 + n] = (topiclen >> 8) & 0xff;
534
136
  packet[4 + n ] = topiclen & 0xff;
535
136
  memcpy(&packet[5 + n], topic, topiclen);
536
136
  packet[5 + n + topiclen] = 0; /* QoS zero */
537
538
136
  result = mqtt_send(data, (const char *)packet, packetlen);
539
540
140
fail:
541
140
  curlx_free(topic);
542
140
  curlx_free(packet);
543
140
  return result;
544
136
}
545
546
/*
547
 * Called when the first byte was already read.
548
 */
549
static CURLcode mqtt_verify_suback(struct Curl_easy *data)
550
66
{
551
66
  struct MQTT *mq = Curl_meta_get(data, CURL_META_MQTT_EASY);
552
66
  struct connectdata *conn = data->conn;
553
66
  struct mqtt_conn *mqtt = Curl_conn_meta_get(conn, CURL_META_MQTT_CONN);
554
66
  CURLcode result;
555
66
  char *ptr;
556
557
66
  if(!mqtt || !mq)
558
0
    return CURLE_FAILED_INIT;
559
560
66
  result = mqtt_recv_atleast(data, MQTT_SUBACK_LEN);
561
66
  if(result)
562
17
    goto fail;
563
564
  /* verify SUBACK */
565
49
  DEBUGASSERT(curlx_dyn_len(&mq->recvbuf) >= MQTT_SUBACK_LEN);
566
49
  ptr = curlx_dyn_ptr(&mq->recvbuf);
567
49
  Curl_debug(data, CURLINFO_HEADER_IN, ptr, MQTT_SUBACK_LEN);
568
569
49
  if(((unsigned char)ptr[0]) != ((mqtt->packetid >> 8) & 0xff) ||
570
46
     ((unsigned char)ptr[1]) != (mqtt->packetid & 0xff) ||
571
41
     ptr[2] != 0x00) {
572
10
    curlx_dyn_reset(&mq->recvbuf);
573
10
    result = CURLE_WEIRD_SERVER_REPLY;
574
10
    goto fail;
575
10
  }
576
39
  mqtt_recv_consume(data, MQTT_SUBACK_LEN);
577
66
fail:
578
66
  return result;
579
39
}
580
581
17
#define MAX_MQTT_MESSAGE_SIZE 0xFFFFFFF
582
583
static CURLcode mqtt_publish(struct Curl_easy *data)
584
29
{
585
29
  CURLcode result;
586
29
  char *payload = data->set.postfields;
587
29
  size_t payloadlen;
588
29
  char *topic = NULL;
589
29
  size_t topiclen;
590
29
  unsigned char *pkt = NULL;
591
29
  size_t i = 0;
592
29
  size_t remaininglength;
593
29
  size_t encodelen;
594
29
  char encodedbytes[4];
595
29
  curl_off_t postfieldsize = data->set.postfieldsize;
596
597
29
  if(!payload) {
598
1
    DEBUGF(infof(data, "mqtt_publish without payload, return bad arg"));
599
1
    return CURLE_BAD_FUNCTION_ARGUMENT;
600
1
  }
601
28
  if(!curlx_sotouz_fits(postfieldsize, &payloadlen)) {
602
28
    if(postfieldsize > 0) /* off_t does not fit into size_t */
603
0
      return CURLE_BAD_FUNCTION_ARGUMENT;
604
28
    payloadlen = strlen(payload);
605
28
  }
606
607
28
  result = mqtt_get_topic(data, &topic, &topiclen);
608
28
  if(result)
609
11
    goto fail;
610
611
17
  remaininglength = payloadlen + 2 + topiclen;
612
17
  encodelen = mqtt_encode_len(encodedbytes, remaininglength);
613
17
  if(MAX_MQTT_MESSAGE_SIZE - remaininglength - 1 < encodelen) {
614
0
    result = CURLE_TOO_LARGE;
615
0
    goto fail;
616
0
  }
617
618
  /* add the control byte and the encoded remaining length */
619
17
  pkt = curlx_malloc(remaininglength + 1 + encodelen);
620
17
  if(!pkt) {
621
0
    result = CURLE_OUT_OF_MEMORY;
622
0
    goto fail;
623
0
  }
624
625
  /* assemble packet */
626
17
  pkt[i++] = MQTT_MSG_PUBLISH;
627
17
  memcpy(&pkt[i], encodedbytes, encodelen);
628
17
  i += encodelen;
629
17
  pkt[i++] = (topiclen >> 8) & 0xff;
630
17
  pkt[i++] = (topiclen & 0xff);
631
17
  memcpy(&pkt[i], topic, topiclen);
632
17
  i += topiclen;
633
17
  memcpy(&pkt[i], payload, payloadlen);
634
17
  i += payloadlen;
635
17
  result = mqtt_send(data, (const char *)pkt, i);
636
637
28
fail:
638
28
  curlx_free(pkt);
639
28
  curlx_free(topic);
640
28
  return result;
641
17
}
642
643
static size_t mqtt_decode_len(unsigned char *buf,
644
                              size_t buflen, size_t *lenbytes)
645
22.5k
{
646
22.5k
  size_t len = 0;
647
22.5k
  size_t mult = 1;
648
22.5k
  size_t i;
649
22.5k
  unsigned char encoded = 128;
650
651
46.1k
  for(i = 0; (i < buflen) && (encoded & 128); i++) {
652
23.5k
    encoded = buf[i];
653
23.5k
    len += (encoded & 127) * mult;
654
23.5k
    mult *= 128;
655
23.5k
  }
656
657
22.5k
  if(lenbytes)
658
0
    *lenbytes = i;
659
660
22.5k
  return len;
661
22.5k
}
662
663
#ifdef DEBUGBUILD
664
static const char *statenames[]={
665
  "MQTT_FIRST",
666
  "MQTT_REMAINING_LENGTH",
667
  "MQTT_CONNACK",
668
  "MQTT_SUBACK",
669
  "MQTT_SUBACK_COMING",
670
  "MQTT_PUBWAIT",
671
  "MQTT_PUB_REMAIN",
672
673
  "NOT A STATE"
674
};
675
#endif
676
677
/* The only way to change state */
678
static void mqstate(struct Curl_easy *data,
679
                    enum mqttstate state,
680
                    enum mqttstate nextstate) /* used if state == FIRST */
681
50.7k
{
682
50.7k
  struct connectdata *conn = data->conn;
683
50.7k
  struct mqtt_conn *mqtt = Curl_conn_meta_get(conn, CURL_META_MQTT_CONN);
684
50.7k
  DEBUGASSERT(mqtt);
685
50.7k
  if(!mqtt)
686
0
    return;
687
50.7k
#ifdef DEBUGBUILD
688
50.7k
  infof(data, "%s (from %s) (next is %s)",
689
50.7k
        statenames[state],
690
50.7k
        statenames[mqtt->state],
691
50.7k
        (state == MQTT_FIRST) ? statenames[nextstate] : "");
692
50.7k
#endif
693
50.7k
  mqtt->state = state;
694
50.7k
  if(state == MQTT_FIRST)
695
23.5k
    mqtt->nextstate = nextstate;
696
50.7k
}
697
698
699
static CURLcode mqtt_read_publish(struct Curl_easy *data, bool *done)
700
2.33k
{
701
2.33k
  CURLcode result = CURLE_OK;
702
2.33k
  struct connectdata *conn = data->conn;
703
2.33k
  size_t nread;
704
2.33k
  size_t remlen;
705
2.33k
  struct mqtt_conn *mqtt = Curl_conn_meta_get(conn, CURL_META_MQTT_CONN);
706
2.33k
  struct MQTT *mq = Curl_meta_get(data, CURL_META_MQTT_EASY);
707
2.33k
  unsigned char packet;
708
709
2.33k
  DEBUGASSERT(mqtt);
710
2.33k
  if(!mqtt || !mq)
711
0
    return CURLE_FAILED_INIT;
712
713
2.33k
  switch(mqtt->state) {
714
66
MQTT_SUBACK_COMING:
715
66
  case MQTT_SUBACK_COMING:
716
66
    result = mqtt_verify_suback(data);
717
66
    if(result)
718
27
      break;
719
720
39
    mqstate(data, MQTT_FIRST, MQTT_PUBWAIT);
721
39
    break;
722
723
125
  case MQTT_SUBACK:
724
2.13k
  case MQTT_PUBWAIT:
725
    /* we are expecting PUBLISH or SUBACK */
726
2.13k
    packet = mq->firstbyte & 0xf0;
727
2.13k
    if(packet == MQTT_MSG_PUBLISH)
728
2.03k
      mqstate(data, MQTT_PUB_REMAIN, MQTT_NOSTATE);
729
98
    else if(packet == MQTT_MSG_SUBACK) {
730
66
      mqstate(data, MQTT_SUBACK_COMING, MQTT_NOSTATE);
731
66
      goto MQTT_SUBACK_COMING;
732
66
    }
733
32
    else if(packet == MQTT_MSG_DISCONNECT) {
734
9
      infof(data, "Got DISCONNECT");
735
9
      *done = TRUE;
736
9
      goto end;
737
9
    }
738
23
    else {
739
23
      result = CURLE_WEIRD_SERVER_REPLY;
740
23
      goto end;
741
23
    }
742
743
    /* -- switched state -- */
744
2.03k
    remlen = mq->remaining_length;
745
2.03k
    infof(data, "Remaining length: %zu bytes", remlen);
746
2.03k
    if(data->set.max_filesize &&
747
399
       (curl_off_t)remlen > data->set.max_filesize) {
748
16
      failf(data, "Maximum file size exceeded");
749
16
      result = CURLE_FILESIZE_EXCEEDED;
750
16
      goto end;
751
16
    }
752
2.01k
    Curl_pgrsSetDownloadSize(data, remlen);
753
2.01k
    data->req.bytecount = 0;
754
2.01k
    data->req.size = remlen;
755
2.01k
    mq->npacket = remlen; /* get this many bytes */
756
2.01k
    FALLTHROUGH();
757
2.22k
  case MQTT_PUB_REMAIN: {
758
    /* read rest of packet, but no more. Cap to buffer size */
759
2.22k
    char buffer[4*1024];
760
2.22k
    size_t rest = mq->npacket;
761
2.22k
    if(rest > sizeof(buffer))
762
175
      rest = sizeof(buffer);
763
2.22k
    result = Curl_xfer_recv(data, buffer, rest, &nread);
764
2.22k
    if(result) {
765
1
      if(CURLE_AGAIN == result) {
766
1
        infof(data, "EEEE AAAAGAIN");
767
1
      }
768
1
      goto end;
769
1
    }
770
2.22k
    if(!nread) {
771
129
      infof(data, "server disconnected");
772
129
      result = CURLE_PARTIAL_FILE;
773
129
      goto end;
774
129
    }
775
776
    /* we received something */
777
2.09k
    mq->lastTime = curlx_now();
778
779
    /* if QoS is set, message contains packet id */
780
2.09k
    result = Curl_client_write(data, CLIENTWRITE_BODY, buffer, nread);
781
2.09k
    if(result)
782
1
      goto end;
783
784
2.09k
    mq->npacket -= nread;
785
2.09k
    if(!mq->npacket)
786
      /* no more PUBLISH payload, back to subscribe wait state */
787
1.88k
      mqstate(data, MQTT_FIRST, MQTT_PUBWAIT);
788
2.09k
    break;
789
2.09k
  }
790
0
  default:
791
0
    DEBUGASSERT(NULL); /* illegal state */
792
0
    result = CURLE_WEIRD_SERVER_REPLY;
793
0
    goto end;
794
2.33k
  }
795
2.33k
end:
796
2.33k
  return result;
797
2.33k
}
798
799
static CURLcode mqtt_do(struct Curl_easy *data, bool *done)
800
1.22k
{
801
1.22k
  struct MQTT *mq = Curl_meta_get(data, CURL_META_MQTT_EASY);
802
1.22k
  CURLcode result = CURLE_OK;
803
1.22k
  *done = FALSE; /* unconditionally */
804
805
1.22k
  if(!mq)
806
0
    return CURLE_FAILED_INIT;
807
1.22k
  mq->lastTime = curlx_now();
808
1.22k
  mq->pingsent = FALSE;
809
810
1.22k
  result = mqtt_connect(data);
811
1.22k
  if(result) {
812
7
    failf(data, "Error %d sending MQTT CONNECT request", result);
813
7
    return result;
814
7
  }
815
1.21k
  mqstate(data, MQTT_FIRST, MQTT_CONNACK);
816
1.21k
  return CURLE_OK;
817
1.22k
}
818
819
static CURLcode mqtt_done(struct Curl_easy *data,
820
                          CURLcode status, bool premature)
821
1.22k
{
822
1.22k
  struct MQTT *mq = Curl_meta_get(data, CURL_META_MQTT_EASY);
823
1.22k
  (void)status;
824
1.22k
  (void)premature;
825
1.22k
  if(mq) {
826
1.22k
    curlx_dyn_free(&mq->sendbuf);
827
1.22k
    curlx_dyn_free(&mq->recvbuf);
828
1.22k
  }
829
1.22k
  return CURLE_OK;
830
1.22k
}
831
832
/* we ping regularly to avoid being disconnected by the server */
833
static CURLcode mqtt_ping(struct Curl_easy *data)
834
5.28M
{
835
5.28M
  struct MQTT *mq = Curl_meta_get(data, CURL_META_MQTT_EASY);
836
5.28M
  CURLcode result = CURLE_OK;
837
5.28M
  struct connectdata *conn = data->conn;
838
5.28M
  struct mqtt_conn *mqtt = Curl_conn_meta_get(conn, CURL_META_MQTT_CONN);
839
840
5.28M
  if(!mqtt || !mq)
841
0
    return CURLE_FAILED_INIT;
842
843
5.28M
  if(mqtt->state == MQTT_FIRST &&
844
23.6k
     !mq->pingsent &&
845
23.6k
     data->set.upkeep_interval_ms > 0) {
846
8.52k
    struct curltime t = curlx_now();
847
8.52k
    timediff_t diff = curlx_timediff_ms(t, mq->lastTime);
848
849
8.52k
    if(diff > data->set.upkeep_interval_ms) {
850
      /* 0xC0 is PINGREQ, and 0x00 is remaining length */
851
0
      unsigned char packet[2] = { 0xC0, 0x00 };
852
0
      size_t packetlen = sizeof(packet);
853
854
0
      result = mqtt_send(data, (char *)packet, packetlen);
855
0
      if(!result) {
856
0
        mq->pingsent = TRUE;
857
0
      }
858
0
      infof(data, "mqtt_ping: sent ping request.");
859
0
    }
860
8.52k
  }
861
5.28M
  return result;
862
5.28M
}
863
864
static CURLcode mqtt_doing(struct Curl_easy *data, bool *done)
865
5.28M
{
866
5.28M
  struct MQTT *mq = Curl_meta_get(data, CURL_META_MQTT_EASY);
867
5.28M
  CURLcode result = CURLE_OK;
868
5.28M
  size_t nread;
869
5.28M
  unsigned char recvbyte;
870
5.28M
  struct mqtt_conn *mqtt = Curl_conn_meta_get(data->conn, CURL_META_MQTT_CONN);
871
872
5.28M
  if(!mqtt || !mq)
873
0
    return CURLE_FAILED_INIT;
874
875
5.28M
  *done = FALSE;
876
877
5.28M
  if(curlx_dyn_len(&mq->sendbuf)) {
878
    /* send the remainder of an outgoing packet */
879
0
    result = mqtt_send(data, curlx_dyn_ptr(&mq->sendbuf),
880
0
                       curlx_dyn_len(&mq->sendbuf));
881
0
    if(result)
882
0
      return result;
883
0
  }
884
885
5.28M
  result = mqtt_ping(data);
886
5.28M
  if(result)
887
0
    return result;
888
889
5.28M
  infof(data, "mqtt_doing: state [%d]", (int) mqtt->state);
890
5.28M
  switch(mqtt->state) {
891
23.6k
  case MQTT_FIRST:
892
    /* Read the initial byte only */
893
23.6k
    result = Curl_xfer_recv(data, (char *)&mq->firstbyte, 1, &nread);
894
23.6k
    if(result)
895
370
      break;
896
23.3k
    else if(!nread) {
897
718
      failf(data, "Connection disconnected");
898
718
      *done = TRUE;
899
718
      result = CURLE_RECV_ERROR;
900
718
      break;
901
718
    }
902
22.5k
    Curl_debug(data, CURLINFO_HEADER_IN, (const char *)&mq->firstbyte, 1);
903
904
    /* we received something */
905
22.5k
    mq->lastTime = curlx_now();
906
907
    /* remember the first byte */
908
22.5k
    mq->npacket = 0;
909
22.5k
    mqstate(data, MQTT_REMAINING_LENGTH, MQTT_NOSTATE);
910
22.5k
    FALLTHROUGH();
911
22.6k
  case MQTT_REMAINING_LENGTH:
912
23.6k
    do {
913
23.6k
      result = Curl_xfer_recv(data, (char *)&recvbyte, 1, &nread);
914
23.6k
      if(result || !nread)
915
97
        break;
916
23.5k
      Curl_debug(data, CURLINFO_HEADER_IN, (const char *)&recvbyte, 1);
917
23.5k
      mq->pkt_hd[mq->npacket++] = recvbyte;
918
23.5k
    } while((recvbyte & 0x80) && (mq->npacket < 4));
919
22.6k
    if(!result && nread && (recvbyte & 0x80))
920
      /* MQTT supports up to 127 * 128^0 + 127 * 128^1 + 127 * 128^2 +
921
         127 * 128^3 bytes. server tried to send more */
922
5
      result = CURLE_WEIRD_SERVER_REPLY;
923
22.6k
    if(result)
924
21
      break;
925
22.5k
    mq->remaining_length = mqtt_decode_len(mq->pkt_hd, mq->npacket, NULL);
926
22.5k
    mq->npacket = 0;
927
22.5k
    if(mq->remaining_length) {
928
7.15k
      mqstate(data, mqtt->nextstate, MQTT_NOSTATE);
929
7.15k
      break;
930
7.15k
    }
931
15.4k
    mqstate(data, MQTT_FIRST, MQTT_FIRST);
932
933
15.4k
    if(mq->firstbyte == MQTT_MSG_DISCONNECT) {
934
9
      infof(data, "Got DISCONNECT");
935
9
      *done = TRUE;
936
9
    }
937
938
    /* ping response */
939
15.4k
    if(mq->firstbyte == MQTT_MSG_PINGRESP) {
940
197
      infof(data, "Received ping response.");
941
197
      mq->pingsent = FALSE;
942
197
      mqstate(data, MQTT_FIRST, MQTT_PUBWAIT);
943
197
    }
944
15.4k
    break;
945
5.26M
  case MQTT_CONNACK:
946
5.26M
    result = mqtt_verify_connack(data);
947
5.26M
    if(result)
948
5.26M
      break;
949
950
169
    if(data->state.httpreq == HTTPREQ_POST) {
951
29
      result = mqtt_publish(data);
952
29
      if(!result) {
953
17
        result = mqtt_disconnect(data);
954
17
        *done = TRUE;
955
17
      }
956
29
      mqtt->nextstate = MQTT_FIRST;
957
29
    }
958
140
    else {
959
140
      result = mqtt_subscribe(data);
960
140
      if(!result) {
961
136
        mqstate(data, MQTT_FIRST, MQTT_SUBACK);
962
136
      }
963
140
    }
964
169
    break;
965
966
125
  case MQTT_SUBACK:
967
2.13k
  case MQTT_PUBWAIT:
968
2.33k
  case MQTT_PUB_REMAIN:
969
2.33k
    result = mqtt_read_publish(data, done);
970
2.33k
    break;
971
972
140
  default:
973
140
    failf(data, "State not handled yet");
974
140
    *done = TRUE;
975
140
    break;
976
5.28M
  }
977
978
5.28M
  if(result == CURLE_AGAIN)
979
5.26M
    result = CURLE_OK;
980
5.28M
  return result;
981
5.28M
}
982
983
#endif /* CURL_DISABLE_MQTT */