From d7e7eff6b5a9ea567c7a65af25b87588a10ea69b Mon Sep 17 00:00:00 2001 From: "shoney.arickathil" Date: Tue, 8 Sep 2026 18:15:53 +0200 Subject: [PATCH] feat(tls): sans-io TLS 1.3 client handshake driver (rv2 9 phase F3c-core) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit - wo_tls_client: a pure state machine (no sockets). Caller frames records; driver runs ClientHello->ServerHello->flight->Finished and hands back bytes to send. Keeps all I/O out of the security-critical FSM - start_with (inject CH + ephemeral priv), push_record, take_output, encrypt/decrypt (application traffic keys). Handshake-message reassembly across records; per-message transcript timing (CertVerify signs CH..Cert, Finished MACs CH..CertVerify); constant-time Finished compare; every failure lands in FAILED (no warn-and-continue) - verifies server CertificateVerify (phase E+D) + server Finished, emits the client Finished, switches to application keys - KAT: whole handshake driven offline against the RFC 8448 record trace — client Finished record byte-for-byte, first client app record byte-for-byte, NewSessionTicket + server app data decrypt to plaintext, tampered flight -> FAILED. test_tls 90 pass, ASan/UBSan clean - SECURITY TODO before live use (documented in tls.h + story): chain walk to a trust anchor + SAN/hostname match; random ephemeral for production start; the net.connect_tls socket glue Co-Authored-By: Claude Opus 4.8 (cherry picked from commit 74c332d7efdb8bbfdbe90bd2fcc3defa2fe8da00) --- runtime/src/tls.c | 201 ++++++++++++++++++++++++++++++ runtime/src/tls.h | 64 ++++++++++ runtime/test/test_tls.c | 60 +++++++++ runtime/test/tls_driver_vectors.h | 175 ++++++++++++++++++++++++++ 4 files changed, 500 insertions(+) create mode 100644 runtime/test/tls_driver_vectors.h diff --git a/runtime/src/tls.c b/runtime/src/tls.c index aaee9da..6cfc5f4 100644 --- a/runtime/src/tls.c +++ b/runtime/src/tls.c @@ -401,3 +401,204 @@ int wo_tls_build_client_hello(const char *hostname, size_t hostlen, *outlen = w.n; return 0; } + +/* ---- sans-io client handshake driver (phase F3c) ------------------------- + * The FSM described in tls.h. The caller frames records; this drives the + * handshake and produces the client Finished. Every failure path lands in + * ST_FAILED and returns WO_TLS_FAILED — there is no "warn and continue". */ + +enum { ST_WANT_SH = 0, ST_WANT_FLIGHT, ST_ESTABLISHED, ST_FAILED }; + +/* Constant-time 32-byte compare (verify_data). 1 equal, 0 not. */ +static int ct_eq32(const uint8_t *a, const uint8_t *b) { + uint8_t d = 0; + for (int i = 0; i < 32; i++) d |= a[i] ^ b[i]; + return d == 0; +} + +/* Append to the transcript; 0 ok, -1 overflow. */ +static int tr_add(wo_tls_client *c, const uint8_t *p, size_t n) { + if (c->tlen + n > sizeof c->transcript) return -1; + memcpy(c->transcript + c->tlen, p, n); c->tlen += n; + return 0; +} + +int wo_tls_client_start_with(wo_tls_client *c, const uint8_t *ch_msg, + size_t ch_len, const uint8_t priv[32]) { + memset(c, 0, sizeof *c); + memcpy(c->client_priv, priv, 32); + /* client_pub = X25519(priv, basepoint 9) — informational here. */ + uint8_t base[32] = { 9 }; + wo_x25519(c->client_pub, priv, base); + + if (tr_add(c, ch_msg, ch_len) != 0) { c->st = ST_FAILED; return -1; } + /* frame the ClientHello as a plaintext handshake record (legacy 0x0301). */ + if (5 + ch_len > sizeof c->out) { c->st = ST_FAILED; return -1; } + c->out[0] = WO_TLS_CT_HANDSHAKE; + c->out[1] = 0x03; c->out[2] = 0x01; + c->out[3] = (uint8_t)(ch_len >> 8); c->out[4] = (uint8_t)ch_len; + memcpy(c->out + 5, ch_msg, ch_len); + c->outn = 5 + ch_len; + c->st = ST_WANT_SH; + return 0; +} + +size_t wo_tls_client_take_output(wo_tls_client *c, uint8_t *out, size_t outcap) { + size_t n = c->outn < outcap ? c->outn : 0; /* all-or-nothing */ + if (n) { memcpy(out, c->out, n); c->outn = 0; } + return n; +} + +/* Process the ServerHello record. */ +static wo_tls_status on_server_hello(wo_tls_client *c, const uint8_t *rec, + size_t reclen) { + size_t bodylen = ((size_t)rec[3] << 8) | rec[4]; + if (bodylen + 5 != reclen) return WO_TLS_FAILED; + const uint8_t *sh = rec + 5; + uint8_t server_pub[32]; + if (wo_tls_parse_server_hello(sh, bodylen, &c->suite, server_pub) != 0) + return WO_TLS_FAILED; + c->keylen = c->suite == WO_TLS_AES_128_GCM_SHA256 ? 16 : 32; + if (tr_add(c, sh, bodylen) != 0) return WO_TLS_FAILED; + + uint8_t ecdhe[32], th[32]; + wo_x25519(ecdhe, c->client_priv, server_pub); + wo_sha256(c->transcript, c->tlen, th); /* CH..SH */ + wo_tls_derive_handshake(&c->ks, ecdhe, 32, th); + /* read = server handshake keys, write = client handshake keys */ + wo_tls_traffic_keys(c->ks.server_hs_traffic, c->keylen, c->rd_key, c->rd_iv); + wo_tls_traffic_keys(c->ks.client_hs_traffic, c->keylen, c->wr_key, c->wr_iv); + c->rd_seq = c->wr_seq = 0; + c->st = ST_WANT_FLIGHT; + return WO_TLS_WANT_MORE; +} + +/* Handle one decrypted handshake message from the server flight. Returns 1 if + * this message completed the handshake (server Finished), 0 to continue, -1 on + * failure. */ +static int on_flight_msg(wo_tls_client *c, const uint8_t *msg, size_t mlen) { + uint8_t type = msg[0]; + if (type == 0x08) { /* EncryptedExtensions */ + return tr_add(c, msg, mlen) == 0 ? 0 : -1; + } + if (type == 0x0b) { /* Certificate */ + /* leaf = first CertificateEntry's cert_data */ + if (mlen < 8) return -1; + size_t p = 4 + 1 + msg[4]; /* skip ctx */ + if (p + 3 > mlen) return -1; + p += 3; /* cert_list length */ + if (p + 3 > mlen) return -1; + size_t clen = ((size_t)msg[p] << 16) | ((size_t)msg[p+1] << 8) | msg[p+2]; + p += 3; + if (p + clen > mlen || clen > sizeof c->leaf) return -1; + memcpy(c->leaf, msg + p, clen); c->leaflen = clen; + return tr_add(c, msg, mlen) == 0 ? 0 : -1; + } + if (type == 0x0f) { /* CertificateVerify */ + if (c->leaflen == 0 || mlen < 8) return -1; + uint8_t th[32]; + wo_sha256(c->transcript, c->tlen, th); /* CH..Certificate */ + uint16_t scheme = ((uint16_t)msg[4] << 8) | msg[5]; + size_t siglen = ((size_t)msg[6] << 8) | msg[7]; + if (8 + siglen > mlen) return -1; + if (!wo_tls_verify_cert_verify(c->leaf, c->leaflen, scheme, msg + 8, siglen, th)) + return -1; + return tr_add(c, msg, mlen) == 0 ? 0 : -1; + } + if (type == 0x14) { /* Finished (server) */ + if (mlen != 4 + 32) return -1; + uint8_t th[32], expect[32]; + wo_sha256(c->transcript, c->tlen, th); /* CH..CertificateVerify */ + wo_tls_finished_verify(c->ks.server_hs_traffic, th, expect); + if (!ct_eq32(expect, msg + 4)) return -1; + if (tr_add(c, msg, mlen) != 0) return -1; + + /* application keys need the transcript through server Finished. */ + uint8_t th_sf[32]; + wo_sha256(c->transcript, c->tlen, th_sf); /* CH..server Finished */ + wo_tls_derive_application(&c->ks, th_sf); + + /* client Finished = HMAC over the same transcript with client hs key */ + uint8_t vd[32]; + wo_tls_finished_verify(c->ks.client_hs_traffic, th_sf, vd); + uint8_t cfin[36]; + cfin[0] = 0x14; cfin[1] = 0; cfin[2] = 0; cfin[3] = 32; + memcpy(cfin + 4, vd, 32); + /* encrypt with the client HANDSHAKE keys, then switch to app keys. */ + int n = wo_tls_record_seal(c->suite, c->wr_key, c->keylen, c->wr_iv, + c->wr_seq, WO_TLS_CT_HANDSHAKE, cfin, 36, c->out); + if (n < 0) return -1; + c->outn = (size_t)n; c->wr_seq++; + + wo_tls_traffic_keys(c->ks.server_ap_traffic, c->keylen, c->rd_key, c->rd_iv); + wo_tls_traffic_keys(c->ks.client_ap_traffic, c->keylen, c->wr_key, c->wr_iv); + c->rd_seq = c->wr_seq = 0; + c->st = ST_ESTABLISHED; + return 1; + } + return -1; /* unexpected message */ +} + +wo_tls_status wo_tls_client_push_record(wo_tls_client *c, const uint8_t *rec, + size_t reclen) { + if (c->st == ST_FAILED) return WO_TLS_FAILED; + if (reclen < 5) { c->st = ST_FAILED; return WO_TLS_FAILED; } + uint8_t ct = rec[0]; + if (ct == WO_TLS_CT_CHANGE_CIPHER_SPEC) return WO_TLS_WANT_MORE; /* ignore */ + + if (c->st == ST_WANT_SH) { + if (ct != WO_TLS_CT_HANDSHAKE) { c->st = ST_FAILED; return WO_TLS_FAILED; } + wo_tls_status s = on_server_hello(c, rec, reclen); + if (s == WO_TLS_FAILED) c->st = ST_FAILED; + return s; + } + if (c->st == ST_WANT_FLIGHT) { + if (ct != WO_TLS_CT_APPLICATION_DATA) { c->st = ST_FAILED; return WO_TLS_FAILED; } + uint8_t pt[WO_TLS_BUF_MAX]; uint8_t inner = 0; + int n = wo_tls_record_open(c->suite, c->rd_key, c->keylen, c->rd_iv, + c->rd_seq, rec, reclen, pt, &inner); + if (n < 0) { c->st = ST_FAILED; return WO_TLS_FAILED; } + c->rd_seq++; + if (inner != WO_TLS_CT_HANDSHAKE) { c->st = ST_FAILED; return WO_TLS_FAILED; } + if (c->hsn + (size_t)n > sizeof c->hsbuf) { c->st = ST_FAILED; return WO_TLS_FAILED; } + memcpy(c->hsbuf + c->hsn, pt, (size_t)n); c->hsn += (size_t)n; + + /* process every complete handshake message now buffered */ + size_t off = 0; + while (c->hsn - off >= 4) { + const uint8_t *m = c->hsbuf + off; + size_t mlen = 4 + (((size_t)m[1] << 16) | ((size_t)m[2] << 8) | m[3]); + if (c->hsn - off < mlen) break; /* wait for more records */ + int r = on_flight_msg(c, m, mlen); + if (r < 0) { c->st = ST_FAILED; return WO_TLS_FAILED; } + off += mlen; + if (r == 1) return WO_TLS_ESTABLISHED; /* Finished processed */ + } + /* keep the tail (a partial message) for the next record */ + if (off > 0) { memmove(c->hsbuf, c->hsbuf + off, c->hsn - off); c->hsn -= off; } + return WO_TLS_WANT_MORE; + } + return WO_TLS_WANT_MORE; /* already established */ +} + +int wo_tls_client_encrypt(wo_tls_client *c, const uint8_t *data, size_t len, + uint8_t *out, size_t outcap) { + if (c->st != ST_ESTABLISHED) return -1; + if (len + WO_TLS_RECORD_OVERHEAD > outcap) return -1; + int n = wo_tls_record_seal(c->suite, c->wr_key, c->keylen, c->wr_iv, + c->wr_seq, WO_TLS_CT_APPLICATION_DATA, data, len, out); + if (n < 0) return -1; + c->wr_seq++; + return n; +} + +int wo_tls_client_decrypt(wo_tls_client *c, const uint8_t *rec, size_t reclen, + uint8_t *out, size_t outcap, uint8_t *content_type) { + if (c->st != ST_ESTABLISHED) return -1; + if (reclen > outcap + WO_TLS_RECORD_OVERHEAD) return -1; + int n = wo_tls_record_open(c->suite, c->rd_key, c->keylen, c->rd_iv, + c->rd_seq, rec, reclen, out, content_type); + if (n < 0) return -1; + c->rd_seq++; + return n; +} diff --git a/runtime/src/tls.h b/runtime/src/tls.h index 15d0525..2f4214a 100644 --- a/runtime/src/tls.h +++ b/runtime/src/tls.h @@ -109,4 +109,68 @@ int wo_tls_build_client_hello(const char *hostname, size_t hostlen, const uint8_t session_id[32], uint8_t *out, size_t outcap, size_t *outlen); +/* ---- sans-io client handshake driver (phase F3c) ------------------------- + * A pure state machine: no sockets. The caller frames TLS records (read the + * 5-byte header, then that many bytes) and feeds whole records in; the driver + * advances the handshake and hands back bytes to send. This keeps every I/O + * concern out of the security-critical FSM, so it is fully testable offline + * (KAT'd against the RFC 8448 record trace). + * + * SECURITY NOTE — not yet a safe live client: this core verifies the server's + * CertificateVerify and Finished (proving possession of the leaf key) but does + * NOT yet walk the certificate chain to a trust anchor or match the hostname + * against the cert SAN. Those (the deferred phase-E bits) MUST land before this + * drives a real connection, or the client is open to MITM. It is currently an + * internal building block; net.connect_tls is not wired to it. */ + +#define WO_TLS_BUF_MAX 16384u /* transcript / reassembly cap (RFC 8448 fits) */ +#define WO_TLS_LEAF_MAX 8192u /* largest leaf certificate accepted */ + +typedef enum { + WO_TLS_WANT_MORE = 0, /* need another record */ + WO_TLS_ESTABLISHED = 1, /* handshake done; output holds client Finished */ + WO_TLS_FAILED = -1, /* verification/parse failure — connection dead */ +} wo_tls_status; + +typedef struct { + int suite; + size_t keylen; /* AEAD key length, 16 or 32 */ + uint8_t client_priv[32], client_pub[32]; + wo_tls_key_schedule ks; + /* current read/write record protection (handshake, then application) */ + uint8_t rd_key[32], rd_iv[12], wr_key[32], wr_iv[12]; + uint64_t rd_seq, wr_seq; + uint8_t transcript[WO_TLS_BUF_MAX]; size_t tlen; + uint8_t hsbuf[WO_TLS_BUF_MAX]; size_t hsn; /* reassembled handshake bytes */ + uint8_t leaf[WO_TLS_LEAF_MAX]; size_t leaflen; + uint16_t cv_scheme; + uint8_t out[1024]; size_t outn; /* bytes for the caller to send */ + int st; /* internal FSM state */ +} wo_tls_client; + +/* Start a handshake from a caller-built ClientHello handshake message and a + * fixed X25519 private key (production passes fresh randomness; the KAT injects + * the RFC's). Frames the ClientHello into a plaintext record in c->out for the + * caller to send, and seeds the transcript. 0 ok, -1 on a buffer problem. */ +int wo_tls_client_start_with(wo_tls_client *c, const uint8_t *ch_msg, + size_t ch_len, const uint8_t priv[32]); + +/* Feed one whole TLS record. Advances the FSM. Returns WANT_MORE (need the + * next record), ESTABLISHED (handshake complete — drain c->out for the client + * Finished, then use the encrypt/decrypt calls), or FAILED. */ +wo_tls_status wo_tls_client_push_record(wo_tls_client *c, const uint8_t *rec, + size_t reclen); + +/* Copy out (and clear) the bytes the driver wants sent. Returns the count. */ +size_t wo_tls_client_take_output(wo_tls_client *c, uint8_t *out, size_t outcap); + +/* Application data, post-handshake (application traffic keys). encrypt writes a + * full record into out; decrypt reads one record and yields the plaintext plus + * its inner content type. Return the byte count, or -1 on overflow / auth + * failure. */ +int wo_tls_client_encrypt(wo_tls_client *c, const uint8_t *data, size_t len, + uint8_t *out, size_t outcap); +int wo_tls_client_decrypt(wo_tls_client *c, const uint8_t *rec, size_t reclen, + uint8_t *out, size_t outcap, uint8_t *content_type); + #endif diff --git a/runtime/test/test_tls.c b/runtime/test/test_tls.c index 301881c..50ef113 100644 --- a/runtime/test/test_tls.c +++ b/runtime/test/test_tls.c @@ -9,6 +9,7 @@ #include "t.h" #include "tls_record_vectors.h" #include "tls_hs_vectors.h" +#include "tls_driver_vectors.h" /* RFC 8448 §3 recorded ServerHello handshake message (90 octets). */ #define SH_MSG "\x02\x00\x00\x56\x03\x03\xa6\xaf\x06\xa4\x12\x18\x60\xdc\x5e\x6e\x60\x24\x9c\xd3\x4c\x95\x93\x0c\x8a\xc5\xcb\x14\x34\xda\xc1\x55\x77\x2e\xd3\xe2\x69\x28\x00\x13\x01\x00\x00\x2e\x00\x33\x00\x24\x00\x1d\x00\x20\xc9\x82\x88\x76\x11\x20\x95\xfe\x66\x76\x2b\xdb\xf7\xc6\x72\xe1\x56\xd6\xcc\x25\x3b\x83\x3d\xf1\xdd\x69\xb1\xb0\x4e\x75\x1f\x0f\x00\x2b\x00\x02\x03\x04" @@ -235,5 +236,64 @@ int main(void) { T_CHECK(memcmp(vd, hs_cfin + 4, 32) == 0); } + /* Sans-io client driver (phase F3c): the whole handshake driven offline + * against the RFC 8448 record trace, then application data both ways. */ + { + static wo_tls_client c; /* ~40 KB — keep off the stack */ + uint8_t priv[32], ch[256]; + memcpy(priv, drv_client_priv, 32); + memcpy(ch, drv_ch_msg, sizeof drv_ch_msg); + T_CHECK(wo_tls_client_start_with(&c, ch, sizeof drv_ch_msg, priv) == 0); + /* it framed a ClientHello record to send */ + uint8_t sent[512]; + size_t sn = wo_tls_client_take_output(&c, sent, sizeof sent); + T_CHECK(sn == 5 + sizeof drv_ch_msg && sent[0] == 22); + + uint8_t rsh[128]; memcpy(rsh, drv_rec_sh, sizeof drv_rec_sh); + T_CHECK(wo_tls_client_push_record(&c, rsh, sizeof drv_rec_sh) == WO_TLS_WANT_MORE); + + uint8_t rfl[1024]; memcpy(rfl, drv_rec_flight, sizeof drv_rec_flight); + T_CHECK(wo_tls_client_push_record(&c, rfl, sizeof drv_rec_flight) == WO_TLS_ESTABLISHED); + + /* the client Finished record we emit matches RFC 8448 byte-for-byte */ + uint8_t fin[128]; + size_t fn = wo_tls_client_take_output(&c, fin, sizeof fin); + T_CHECK(fn == sizeof drv_rec_cfin); + T_CHECK(memcmp(fin, drv_rec_cfin, sizeof drv_rec_cfin) == 0); + + /* application encrypt: our first app record equals the recorded one */ + uint8_t app[128]; + int an = wo_tls_client_encrypt(&c, drv_capp_pt, sizeof drv_capp_pt, app, sizeof app); + T_CHECK(an == (int)sizeof drv_rec_capp); + T_CHECK(memcmp(app, drv_rec_capp, sizeof drv_rec_capp) == 0); + + /* server sends NewSessionTicket first (server app seq 0) — decrypt it + * (a post-handshake handshake message), advancing the read seq. */ + uint8_t nst[256]; uint8_t ct2 = 0; + memcpy(nst, drv_rec_nst, sizeof drv_rec_nst); + int nn = wo_tls_client_decrypt(&c, nst, sizeof drv_rec_nst, nst, sizeof nst, &ct2); + T_CHECK(nn > 0 && ct2 == 22); /* handshake (ticket) */ + + /* then the server's application data (seq 1) decrypts to the plaintext */ + uint8_t sapp[128]; uint8_t ct3 = 0; + int dn = wo_tls_client_decrypt(&c, drv_rec_sapp, sizeof drv_rec_sapp, + sapp, sizeof sapp, &ct3); + T_CHECK(dn == (int)sizeof drv_sapp_pt && ct3 == 23); + T_CHECK(memcmp(sapp, drv_sapp_pt, sizeof drv_sapp_pt) == 0); + } + + /* Driver rejects a tampered server flight (auth failure -> FAILED). */ + { + static wo_tls_client c; + uint8_t priv[32], ch[256]; + memcpy(priv, drv_client_priv, 32); memcpy(ch, drv_ch_msg, sizeof drv_ch_msg); + wo_tls_client_start_with(&c, ch, sizeof drv_ch_msg, priv); + uint8_t rsh[128]; memcpy(rsh, drv_rec_sh, sizeof drv_rec_sh); + wo_tls_client_push_record(&c, rsh, sizeof drv_rec_sh); + uint8_t rfl[1024]; memcpy(rfl, drv_rec_flight, sizeof drv_rec_flight); + rfl[100] ^= 0x01; /* corrupt the ciphertext */ + T_CHECK(wo_tls_client_push_record(&c, rfl, sizeof drv_rec_flight) == WO_TLS_FAILED); + } + return t_report("test_tls"); } diff --git a/runtime/test/tls_driver_vectors.h b/runtime/test/tls_driver_vectors.h new file mode 100644 index 0000000..faf8ffc --- /dev/null +++ b/runtime/test/tls_driver_vectors.h @@ -0,0 +1,175 @@ +/* Generated from RFC 8448 §3 'Simple 1-RTT Handshake'. Wire records + + * ephemeral key + app-data plaintext for the phase-F3c sans-io driver KAT. */ +static const unsigned char drv_client_priv[] = { + 0x49,0xaf,0x42,0xba,0x7f,0x79,0x94,0x85,0x2d,0x71,0x3e,0xf2, + 0x78,0x4b,0xcb,0xca,0xa7,0x91,0x1d,0xe2,0x6a,0xdc,0x56,0x42, + 0xcb,0x63,0x45,0x40,0xe7,0xea,0x50,0x05, +}; + +static const unsigned char drv_ch_msg[] = { + 0x01,0x00,0x00,0xc0,0x03,0x03,0xcb,0x34,0xec,0xb1,0xe7,0x81, + 0x63,0xba,0x1c,0x38,0xc6,0xda,0xcb,0x19,0x6a,0x6d,0xff,0xa2, + 0x1a,0x8d,0x99,0x12,0xec,0x18,0xa2,0xef,0x62,0x83,0x02,0x4d, + 0xec,0xe7,0x00,0x00,0x06,0x13,0x01,0x13,0x03,0x13,0x02,0x01, + 0x00,0x00,0x91,0x00,0x00,0x00,0x0b,0x00,0x09,0x00,0x00,0x06, + 0x73,0x65,0x72,0x76,0x65,0x72,0xff,0x01,0x00,0x01,0x00,0x00, + 0x0a,0x00,0x14,0x00,0x12,0x00,0x1d,0x00,0x17,0x00,0x18,0x00, + 0x19,0x01,0x00,0x01,0x01,0x01,0x02,0x01,0x03,0x01,0x04,0x00, + 0x23,0x00,0x00,0x00,0x33,0x00,0x26,0x00,0x24,0x00,0x1d,0x00, + 0x20,0x99,0x38,0x1d,0xe5,0x60,0xe4,0xbd,0x43,0xd2,0x3d,0x8e, + 0x43,0x5a,0x7d,0xba,0xfe,0xb3,0xc0,0x6e,0x51,0xc1,0x3c,0xae, + 0x4d,0x54,0x13,0x69,0x1e,0x52,0x9a,0xaf,0x2c,0x00,0x2b,0x00, + 0x03,0x02,0x03,0x04,0x00,0x0d,0x00,0x20,0x00,0x1e,0x04,0x03, + 0x05,0x03,0x06,0x03,0x02,0x03,0x08,0x04,0x08,0x05,0x08,0x06, + 0x04,0x01,0x05,0x01,0x06,0x01,0x02,0x01,0x04,0x02,0x05,0x02, + 0x06,0x02,0x02,0x02,0x00,0x2d,0x00,0x02,0x01,0x01,0x00,0x1c, + 0x00,0x02,0x40,0x01, +}; + +static const unsigned char drv_rec_sh[] = { + 0x16,0x03,0x03,0x00,0x5a,0x02,0x00,0x00,0x56,0x03,0x03,0xa6, + 0xaf,0x06,0xa4,0x12,0x18,0x60,0xdc,0x5e,0x6e,0x60,0x24,0x9c, + 0xd3,0x4c,0x95,0x93,0x0c,0x8a,0xc5,0xcb,0x14,0x34,0xda,0xc1, + 0x55,0x77,0x2e,0xd3,0xe2,0x69,0x28,0x00,0x13,0x01,0x00,0x00, + 0x2e,0x00,0x33,0x00,0x24,0x00,0x1d,0x00,0x20,0xc9,0x82,0x88, + 0x76,0x11,0x20,0x95,0xfe,0x66,0x76,0x2b,0xdb,0xf7,0xc6,0x72, + 0xe1,0x56,0xd6,0xcc,0x25,0x3b,0x83,0x3d,0xf1,0xdd,0x69,0xb1, + 0xb0,0x4e,0x75,0x1f,0x0f,0x00,0x2b,0x00,0x02,0x03,0x04, +}; + +static const unsigned char drv_rec_flight[] = { + 0x17,0x03,0x03,0x02,0xa2,0xd1,0xff,0x33,0x4a,0x56,0xf5,0xbf, + 0xf6,0x59,0x4a,0x07,0xcc,0x87,0xb5,0x80,0x23,0x3f,0x50,0x0f, + 0x45,0xe4,0x89,0xe7,0xf3,0x3a,0xf3,0x5e,0xdf,0x78,0x69,0xfc, + 0xf4,0x0a,0xa4,0x0a,0xa2,0xb8,0xea,0x73,0xf8,0x48,0xa7,0xca, + 0x07,0x61,0x2e,0xf9,0xf9,0x45,0xcb,0x96,0x0b,0x40,0x68,0x90, + 0x51,0x23,0xea,0x78,0xb1,0x11,0xb4,0x29,0xba,0x91,0x91,0xcd, + 0x05,0xd2,0xa3,0x89,0x28,0x0f,0x52,0x61,0x34,0xaa,0xdc,0x7f, + 0xc7,0x8c,0x4b,0x72,0x9d,0xf8,0x28,0xb5,0xec,0xf7,0xb1,0x3b, + 0xd9,0xae,0xfb,0x0e,0x57,0xf2,0x71,0x58,0x5b,0x8e,0xa9,0xbb, + 0x35,0x5c,0x7c,0x79,0x02,0x07,0x16,0xcf,0xb9,0xb1,0x18,0x3e, + 0xf3,0xab,0x20,0xe3,0x7d,0x57,0xa6,0xb9,0xd7,0x47,0x76,0x09, + 0xae,0xe6,0xe1,0x22,0xa4,0xcf,0x51,0x42,0x73,0x25,0x25,0x0c, + 0x7d,0x0e,0x50,0x92,0x89,0x44,0x4c,0x9b,0x3a,0x64,0x8f,0x1d, + 0x71,0x03,0x5d,0x2e,0xd6,0x5b,0x0e,0x3c,0xdd,0x0c,0xba,0xe8, + 0xbf,0x2d,0x0b,0x22,0x78,0x12,0xcb,0xb3,0x60,0x98,0x72,0x55, + 0xcc,0x74,0x41,0x10,0xc4,0x53,0xba,0xa4,0xfc,0xd6,0x10,0x92, + 0x8d,0x80,0x98,0x10,0xe4,0xb7,0xed,0x1a,0x8f,0xd9,0x91,0xf0, + 0x6a,0xa6,0x24,0x82,0x04,0x79,0x7e,0x36,0xa6,0xa7,0x3b,0x70, + 0xa2,0x55,0x9c,0x09,0xea,0xd6,0x86,0x94,0x5b,0xa2,0x46,0xab, + 0x66,0xe5,0xed,0xd8,0x04,0x4b,0x4c,0x6d,0xe3,0xfc,0xf2,0xa8, + 0x94,0x41,0xac,0x66,0x27,0x2f,0xd8,0xfb,0x33,0x0e,0xf8,0x19, + 0x05,0x79,0xb3,0x68,0x45,0x96,0xc9,0x60,0xbd,0x59,0x6e,0xea, + 0x52,0x0a,0x56,0xa8,0xd6,0x50,0xf5,0x63,0xaa,0xd2,0x74,0x09, + 0x96,0x0d,0xca,0x63,0xd3,0xe6,0x88,0x61,0x1e,0xa5,0xe2,0x2f, + 0x44,0x15,0xcf,0x95,0x38,0xd5,0x1a,0x20,0x0c,0x27,0x03,0x42, + 0x72,0x96,0x8a,0x26,0x4e,0xd6,0x54,0x0c,0x84,0x83,0x8d,0x89, + 0xf7,0x2c,0x24,0x46,0x1a,0xad,0x6d,0x26,0xf5,0x9e,0xca,0xba, + 0x9a,0xcb,0xbb,0x31,0x7b,0x66,0xd9,0x02,0xf4,0xf2,0x92,0xa3, + 0x6a,0xc1,0xb6,0x39,0xc6,0x37,0xce,0x34,0x31,0x17,0xb6,0x59, + 0x62,0x22,0x45,0x31,0x7b,0x49,0xee,0xda,0x0c,0x62,0x58,0xf1, + 0x00,0xd7,0xd9,0x61,0xff,0xb1,0x38,0x64,0x7e,0x92,0xea,0x33, + 0x0f,0xae,0xea,0x6d,0xfa,0x31,0xc7,0xa8,0x4d,0xc3,0xbd,0x7e, + 0x1b,0x7a,0x6c,0x71,0x78,0xaf,0x36,0x87,0x90,0x18,0xe3,0xf2, + 0x52,0x10,0x7f,0x24,0x3d,0x24,0x3d,0xc7,0x33,0x9d,0x56,0x84, + 0xc8,0xb0,0x37,0x8b,0xf3,0x02,0x44,0xda,0x8c,0x87,0xc8,0x43, + 0xf5,0xe5,0x6e,0xb4,0xc5,0xe8,0x28,0x0a,0x2b,0x48,0x05,0x2c, + 0xf9,0x3b,0x16,0x49,0x9a,0x66,0xdb,0x7c,0xca,0x71,0xe4,0x59, + 0x94,0x26,0xf7,0xd4,0x61,0xe6,0x6f,0x99,0x88,0x2b,0xd8,0x9f, + 0xc5,0x08,0x00,0xbe,0xcc,0xa6,0x2d,0x6c,0x74,0x11,0x6d,0xbd, + 0x29,0x72,0xfd,0xa1,0xfa,0x80,0xf8,0x5d,0xf8,0x81,0xed,0xbe, + 0x5a,0x37,0x66,0x89,0x36,0xb3,0x35,0x58,0x3b,0x59,0x91,0x86, + 0xdc,0x5c,0x69,0x18,0xa3,0x96,0xfa,0x48,0xa1,0x81,0xd6,0xb6, + 0xfa,0x4f,0x9d,0x62,0xd5,0x13,0xaf,0xbb,0x99,0x2f,0x2b,0x99, + 0x2f,0x67,0xf8,0xaf,0xe6,0x7f,0x76,0x91,0x3f,0xa3,0x88,0xcb, + 0x56,0x30,0xc8,0xca,0x01,0xe0,0xc6,0x5d,0x11,0xc6,0x6a,0x1e, + 0x2a,0xc4,0xc8,0x59,0x77,0xb7,0xc7,0xa6,0x99,0x9b,0xbf,0x10, + 0xdc,0x35,0xae,0x69,0xf5,0x51,0x56,0x14,0x63,0x6c,0x0b,0x9b, + 0x68,0xc1,0x9e,0xd2,0xe3,0x1c,0x0b,0x3b,0x66,0x76,0x30,0x38, + 0xeb,0xba,0x42,0xf3,0xb3,0x8e,0xdc,0x03,0x99,0xf3,0xa9,0xf2, + 0x3f,0xaa,0x63,0x97,0x8c,0x31,0x7f,0xc9,0xfa,0x66,0xa7,0x3f, + 0x60,0xf0,0x50,0x4d,0xe9,0x3b,0x5b,0x84,0x5e,0x27,0x55,0x92, + 0xc1,0x23,0x35,0xee,0x34,0x0b,0xbc,0x4f,0xdd,0xd5,0x02,0x78, + 0x40,0x16,0xe4,0xb3,0xbe,0x7e,0xf0,0x4d,0xda,0x49,0xf4,0xb4, + 0x40,0xa3,0x0c,0xb5,0xd2,0xaf,0x93,0x98,0x28,0xfd,0x4a,0xe3, + 0x79,0x4e,0x44,0xf9,0x4d,0xf5,0xa6,0x31,0xed,0xe4,0x2c,0x17, + 0x19,0xbf,0xda,0xbf,0x02,0x53,0xfe,0x51,0x75,0xbe,0x89,0x8e, + 0x75,0x0e,0xdc,0x53,0x37,0x0d,0x2b, +}; + +static const unsigned char drv_rec_cfin[] = { + 0x17,0x03,0x03,0x00,0x35,0x75,0xec,0x4d,0xc2,0x38,0xcc,0xe6, + 0x0b,0x29,0x80,0x44,0xa7,0x1e,0x21,0x9c,0x56,0xcc,0x77,0xb0, + 0x51,0x7f,0xe9,0xb9,0x3c,0x7a,0x4b,0xfc,0x44,0xd8,0x7f,0x38, + 0xf8,0x03,0x38,0xac,0x98,0xfc,0x46,0xde,0xb3,0x84,0xbd,0x1c, + 0xae,0xac,0xab,0x68,0x67,0xd7,0x26,0xc4,0x05,0x46, +}; + +static const unsigned char drv_rec_nst[] = { + 0x17,0x03,0x03,0x00,0xde,0x3a,0x6b,0x8f,0x90,0x41,0x4a,0x97, + 0xd6,0x95,0x9c,0x34,0x87,0x68,0x0d,0xe5,0x13,0x4a,0x2b,0x24, + 0x0e,0x6c,0xff,0xac,0x11,0x6e,0x95,0xd4,0x1d,0x6a,0xf8,0xf6, + 0xb5,0x80,0xdc,0xf3,0xd1,0x1d,0x63,0xc7,0x58,0xdb,0x28,0x9a, + 0x01,0x59,0x40,0x25,0x2f,0x55,0x71,0x3e,0x06,0x1d,0xc1,0x3e, + 0x07,0x88,0x91,0xa3,0x8e,0xfb,0xcf,0x57,0x53,0xad,0x8e,0xf1, + 0x70,0xad,0x3c,0x73,0x53,0xd1,0x6d,0x9d,0xa7,0x73,0xb9,0xca, + 0x7f,0x2b,0x9f,0xa1,0xb6,0xc0,0xd4,0xa3,0xd0,0x3f,0x75,0xe0, + 0x9c,0x30,0xba,0x1e,0x62,0x97,0x2a,0xc4,0x6f,0x75,0xf7,0xb9, + 0x81,0xbe,0x63,0x43,0x9b,0x29,0x99,0xce,0x13,0x06,0x46,0x15, + 0x13,0x98,0x91,0xd5,0xe4,0xc5,0xb4,0x06,0xf1,0x6e,0x3f,0xc1, + 0x81,0xa7,0x7c,0xa4,0x75,0x84,0x00,0x25,0xdb,0x2f,0x0a,0x77, + 0xf8,0x1b,0x5a,0xb0,0x5b,0x94,0xc0,0x13,0x46,0x75,0x5f,0x69, + 0x23,0x2c,0x86,0x51,0x9d,0x86,0xcb,0xee,0xac,0x87,0xaa,0xc3, + 0x47,0xd1,0x43,0xf9,0x60,0x5d,0x64,0xf6,0x50,0xdb,0x4d,0x02, + 0x3e,0x70,0xe9,0x52,0xca,0x49,0xfe,0x51,0x37,0x12,0x1c,0x74, + 0xbc,0x26,0x97,0x68,0x7e,0x24,0x87,0x46,0xd6,0xdf,0x35,0x30, + 0x05,0xf3,0xbc,0xe1,0x86,0x96,0x12,0x9c,0x81,0x53,0x55,0x6b, + 0x3b,0x6c,0x67,0x79,0xb3,0x7b,0xf1,0x59,0x85,0x68,0x4f, +}; + +static const unsigned char drv_rec_capp[] = { + 0x17,0x03,0x03,0x00,0x43,0xa2,0x3f,0x70,0x54,0xb6,0x2c,0x94, + 0xd0,0xaf,0xfa,0xfe,0x82,0x28,0xba,0x55,0xcb,0xef,0xac,0xea, + 0x42,0xf9,0x14,0xaa,0x66,0xbc,0xab,0x3f,0x2b,0x98,0x19,0xa8, + 0xa5,0xb4,0x6b,0x39,0x5b,0xd5,0x4a,0x9a,0x20,0x44,0x1e,0x2b, + 0x62,0x97,0x4e,0x1f,0x5a,0x62,0x92,0xa2,0x97,0x70,0x14,0xbd, + 0x1e,0x3d,0xea,0xe6,0x3a,0xee,0xbb,0x21,0x69,0x49,0x15,0xe4, +}; + +static const unsigned char drv_capp_pt[] = { + 0x00,0x01,0x02,0x03,0x04,0x05,0x06,0x07,0x08,0x09,0x0a,0x0b, + 0x0c,0x0d,0x0e,0x0f,0x10,0x11,0x12,0x13,0x14,0x15,0x16,0x17, + 0x18,0x19,0x1a,0x1b,0x1c,0x1d,0x1e,0x1f,0x20,0x21,0x22,0x23, + 0x24,0x25,0x26,0x27,0x28,0x29,0x2a,0x2b,0x2c,0x2d,0x2e,0x2f, + 0x30,0x31, +}; + +static const unsigned char drv_rec_sapp[] = { + 0x17,0x03,0x03,0x00,0x43,0x2e,0x93,0x7e,0x11,0xef,0x4a,0xc7, + 0x40,0xe5,0x38,0xad,0x36,0x00,0x5f,0xc4,0xa4,0x69,0x32,0xfc, + 0x32,0x25,0xd0,0x5f,0x82,0xaa,0x1b,0x36,0xe3,0x0e,0xfa,0xf9, + 0x7d,0x90,0xe6,0xdf,0xfc,0x60,0x2d,0xcb,0x50,0x1a,0x59,0xa8, + 0xfc,0xc4,0x9c,0x4b,0xf2,0xe5,0xf0,0xa2,0x1c,0x00,0x47,0xc2, + 0xab,0xf3,0x32,0x54,0x0d,0xd0,0x32,0xe1,0x67,0xc2,0x95,0x5d, +}; + +static const unsigned char drv_sapp_pt[] = { + 0x00,0x01,0x02,0x03,0x04,0x05,0x06,0x07,0x08,0x09,0x0a,0x0b, + 0x0c,0x0d,0x0e,0x0f,0x10,0x11,0x12,0x13,0x14,0x15,0x16,0x17, + 0x18,0x19,0x1a,0x1b,0x1c,0x1d,0x1e,0x1f,0x20,0x21,0x22,0x23, + 0x24,0x25,0x26,0x27,0x28,0x29,0x2a,0x2b,0x2c,0x2d,0x2e,0x2f, + 0x30,0x31, +}; + +static const unsigned char drv_c_ap[] = { + 0x9e,0x40,0x64,0x6c,0xe7,0x9a,0x7f,0x9d,0xc0,0x5a,0xf8,0x88, + 0x9b,0xce,0x65,0x52,0x87,0x5a,0xfa,0x0b,0x06,0xdf,0x00,0x87, + 0xf7,0x92,0xeb,0xb7,0xc1,0x75,0x04,0xa5, +}; + +static const unsigned char drv_s_ap[] = { + 0xa1,0x1a,0xf9,0xf0,0x55,0x31,0xf8,0x56,0xad,0x47,0x11,0x6b, + 0x45,0xa9,0x50,0x32,0x82,0x04,0xb4,0xf4,0x4b,0xfb,0x6b,0x3a, + 0x4b,0x4f,0x1f,0x3f,0xcb,0x63,0x16,0x43, +}; +