feat(tls): sans-io TLS 1.3 client handshake driver (rv2 9 phase F3c-core)

- wo_tls_client: a pure state machine (no sockets). Caller frames
  records; driver runs ClientHello->ServerHello->flight->Finished and
  hands back bytes to send. Keeps all I/O out of the security-critical FSM
- start_with (inject CH + ephemeral priv), push_record, take_output,
  encrypt/decrypt (application traffic keys). Handshake-message reassembly
  across records; per-message transcript timing (CertVerify signs CH..Cert,
  Finished MACs CH..CertVerify); constant-time Finished compare; every
  failure lands in FAILED (no warn-and-continue)
- verifies server CertificateVerify (phase E+D) + server Finished, emits
  the client Finished, switches to application keys
- KAT: whole handshake driven offline against the RFC 8448 record trace —
  client Finished record byte-for-byte, first client app record
  byte-for-byte, NewSessionTicket + server app data decrypt to plaintext,
  tampered flight -> FAILED. test_tls 90 pass, ASan/UBSan clean
- SECURITY TODO before live use (documented in tls.h + story): chain walk
  to a trust anchor + SAN/hostname match; random ephemeral for production
  start; the net.connect_tls socket glue

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
(cherry picked from commit 74c332d7efdb8bbfdbe90bd2fcc3defa2fe8da00)
This commit is contained in:
shoney.arickathil 2026-09-08 18:15:53 +02:00
parent c84d33c9ba
commit d7e7eff6b5
4 changed files with 500 additions and 0 deletions

View file

@ -401,3 +401,204 @@ int wo_tls_build_client_hello(const char *hostname, size_t hostlen,
*outlen = w.n; *outlen = w.n;
return 0; return 0;
} }
/* ---- sans-io client handshake driver (phase F3c) -------------------------
* The FSM described in tls.h. The caller frames records; this drives the
* handshake and produces the client Finished. Every failure path lands in
* ST_FAILED and returns WO_TLS_FAILED — there is no "warn and continue". */
enum { ST_WANT_SH = 0, ST_WANT_FLIGHT, ST_ESTABLISHED, ST_FAILED };
/* Constant-time 32-byte compare (verify_data). 1 equal, 0 not. */
static int ct_eq32(const uint8_t *a, const uint8_t *b) {
uint8_t d = 0;
for (int i = 0; i < 32; i++) d |= a[i] ^ b[i];
return d == 0;
}
/* Append to the transcript; 0 ok, -1 overflow. */
static int tr_add(wo_tls_client *c, const uint8_t *p, size_t n) {
if (c->tlen + n > sizeof c->transcript) return -1;
memcpy(c->transcript + c->tlen, p, n); c->tlen += n;
return 0;
}
int wo_tls_client_start_with(wo_tls_client *c, const uint8_t *ch_msg,
size_t ch_len, const uint8_t priv[32]) {
memset(c, 0, sizeof *c);
memcpy(c->client_priv, priv, 32);
/* client_pub = X25519(priv, basepoint 9) — informational here. */
uint8_t base[32] = { 9 };
wo_x25519(c->client_pub, priv, base);
if (tr_add(c, ch_msg, ch_len) != 0) { c->st = ST_FAILED; return -1; }
/* frame the ClientHello as a plaintext handshake record (legacy 0x0301). */
if (5 + ch_len > sizeof c->out) { c->st = ST_FAILED; return -1; }
c->out[0] = WO_TLS_CT_HANDSHAKE;
c->out[1] = 0x03; c->out[2] = 0x01;
c->out[3] = (uint8_t)(ch_len >> 8); c->out[4] = (uint8_t)ch_len;
memcpy(c->out + 5, ch_msg, ch_len);
c->outn = 5 + ch_len;
c->st = ST_WANT_SH;
return 0;
}
size_t wo_tls_client_take_output(wo_tls_client *c, uint8_t *out, size_t outcap) {
size_t n = c->outn < outcap ? c->outn : 0; /* all-or-nothing */
if (n) { memcpy(out, c->out, n); c->outn = 0; }
return n;
}
/* Process the ServerHello record. */
static wo_tls_status on_server_hello(wo_tls_client *c, const uint8_t *rec,
size_t reclen) {
size_t bodylen = ((size_t)rec[3] << 8) | rec[4];
if (bodylen + 5 != reclen) return WO_TLS_FAILED;
const uint8_t *sh = rec + 5;
uint8_t server_pub[32];
if (wo_tls_parse_server_hello(sh, bodylen, &c->suite, server_pub) != 0)
return WO_TLS_FAILED;
c->keylen = c->suite == WO_TLS_AES_128_GCM_SHA256 ? 16 : 32;
if (tr_add(c, sh, bodylen) != 0) return WO_TLS_FAILED;
uint8_t ecdhe[32], th[32];
wo_x25519(ecdhe, c->client_priv, server_pub);
wo_sha256(c->transcript, c->tlen, th); /* CH..SH */
wo_tls_derive_handshake(&c->ks, ecdhe, 32, th);
/* read = server handshake keys, write = client handshake keys */
wo_tls_traffic_keys(c->ks.server_hs_traffic, c->keylen, c->rd_key, c->rd_iv);
wo_tls_traffic_keys(c->ks.client_hs_traffic, c->keylen, c->wr_key, c->wr_iv);
c->rd_seq = c->wr_seq = 0;
c->st = ST_WANT_FLIGHT;
return WO_TLS_WANT_MORE;
}
/* Handle one decrypted handshake message from the server flight. Returns 1 if
* this message completed the handshake (server Finished), 0 to continue, -1 on
* failure. */
static int on_flight_msg(wo_tls_client *c, const uint8_t *msg, size_t mlen) {
uint8_t type = msg[0];
if (type == 0x08) { /* EncryptedExtensions */
return tr_add(c, msg, mlen) == 0 ? 0 : -1;
}
if (type == 0x0b) { /* Certificate */
/* leaf = first CertificateEntry's cert_data */
if (mlen < 8) return -1;
size_t p = 4 + 1 + msg[4]; /* skip ctx */
if (p + 3 > mlen) return -1;
p += 3; /* cert_list length */
if (p + 3 > mlen) return -1;
size_t clen = ((size_t)msg[p] << 16) | ((size_t)msg[p+1] << 8) | msg[p+2];
p += 3;
if (p + clen > mlen || clen > sizeof c->leaf) return -1;
memcpy(c->leaf, msg + p, clen); c->leaflen = clen;
return tr_add(c, msg, mlen) == 0 ? 0 : -1;
}
if (type == 0x0f) { /* CertificateVerify */
if (c->leaflen == 0 || mlen < 8) return -1;
uint8_t th[32];
wo_sha256(c->transcript, c->tlen, th); /* CH..Certificate */
uint16_t scheme = ((uint16_t)msg[4] << 8) | msg[5];
size_t siglen = ((size_t)msg[6] << 8) | msg[7];
if (8 + siglen > mlen) return -1;
if (!wo_tls_verify_cert_verify(c->leaf, c->leaflen, scheme, msg + 8, siglen, th))
return -1;
return tr_add(c, msg, mlen) == 0 ? 0 : -1;
}
if (type == 0x14) { /* Finished (server) */
if (mlen != 4 + 32) return -1;
uint8_t th[32], expect[32];
wo_sha256(c->transcript, c->tlen, th); /* CH..CertificateVerify */
wo_tls_finished_verify(c->ks.server_hs_traffic, th, expect);
if (!ct_eq32(expect, msg + 4)) return -1;
if (tr_add(c, msg, mlen) != 0) return -1;
/* application keys need the transcript through server Finished. */
uint8_t th_sf[32];
wo_sha256(c->transcript, c->tlen, th_sf); /* CH..server Finished */
wo_tls_derive_application(&c->ks, th_sf);
/* client Finished = HMAC over the same transcript with client hs key */
uint8_t vd[32];
wo_tls_finished_verify(c->ks.client_hs_traffic, th_sf, vd);
uint8_t cfin[36];
cfin[0] = 0x14; cfin[1] = 0; cfin[2] = 0; cfin[3] = 32;
memcpy(cfin + 4, vd, 32);
/* encrypt with the client HANDSHAKE keys, then switch to app keys. */
int n = wo_tls_record_seal(c->suite, c->wr_key, c->keylen, c->wr_iv,
c->wr_seq, WO_TLS_CT_HANDSHAKE, cfin, 36, c->out);
if (n < 0) return -1;
c->outn = (size_t)n; c->wr_seq++;
wo_tls_traffic_keys(c->ks.server_ap_traffic, c->keylen, c->rd_key, c->rd_iv);
wo_tls_traffic_keys(c->ks.client_ap_traffic, c->keylen, c->wr_key, c->wr_iv);
c->rd_seq = c->wr_seq = 0;
c->st = ST_ESTABLISHED;
return 1;
}
return -1; /* unexpected message */
}
wo_tls_status wo_tls_client_push_record(wo_tls_client *c, const uint8_t *rec,
size_t reclen) {
if (c->st == ST_FAILED) return WO_TLS_FAILED;
if (reclen < 5) { c->st = ST_FAILED; return WO_TLS_FAILED; }
uint8_t ct = rec[0];
if (ct == WO_TLS_CT_CHANGE_CIPHER_SPEC) return WO_TLS_WANT_MORE; /* ignore */
if (c->st == ST_WANT_SH) {
if (ct != WO_TLS_CT_HANDSHAKE) { c->st = ST_FAILED; return WO_TLS_FAILED; }
wo_tls_status s = on_server_hello(c, rec, reclen);
if (s == WO_TLS_FAILED) c->st = ST_FAILED;
return s;
}
if (c->st == ST_WANT_FLIGHT) {
if (ct != WO_TLS_CT_APPLICATION_DATA) { c->st = ST_FAILED; return WO_TLS_FAILED; }
uint8_t pt[WO_TLS_BUF_MAX]; uint8_t inner = 0;
int n = wo_tls_record_open(c->suite, c->rd_key, c->keylen, c->rd_iv,
c->rd_seq, rec, reclen, pt, &inner);
if (n < 0) { c->st = ST_FAILED; return WO_TLS_FAILED; }
c->rd_seq++;
if (inner != WO_TLS_CT_HANDSHAKE) { c->st = ST_FAILED; return WO_TLS_FAILED; }
if (c->hsn + (size_t)n > sizeof c->hsbuf) { c->st = ST_FAILED; return WO_TLS_FAILED; }
memcpy(c->hsbuf + c->hsn, pt, (size_t)n); c->hsn += (size_t)n;
/* process every complete handshake message now buffered */
size_t off = 0;
while (c->hsn - off >= 4) {
const uint8_t *m = c->hsbuf + off;
size_t mlen = 4 + (((size_t)m[1] << 16) | ((size_t)m[2] << 8) | m[3]);
if (c->hsn - off < mlen) break; /* wait for more records */
int r = on_flight_msg(c, m, mlen);
if (r < 0) { c->st = ST_FAILED; return WO_TLS_FAILED; }
off += mlen;
if (r == 1) return WO_TLS_ESTABLISHED; /* Finished processed */
}
/* keep the tail (a partial message) for the next record */
if (off > 0) { memmove(c->hsbuf, c->hsbuf + off, c->hsn - off); c->hsn -= off; }
return WO_TLS_WANT_MORE;
}
return WO_TLS_WANT_MORE; /* already established */
}
int wo_tls_client_encrypt(wo_tls_client *c, const uint8_t *data, size_t len,
uint8_t *out, size_t outcap) {
if (c->st != ST_ESTABLISHED) return -1;
if (len + WO_TLS_RECORD_OVERHEAD > outcap) return -1;
int n = wo_tls_record_seal(c->suite, c->wr_key, c->keylen, c->wr_iv,
c->wr_seq, WO_TLS_CT_APPLICATION_DATA, data, len, out);
if (n < 0) return -1;
c->wr_seq++;
return n;
}
int wo_tls_client_decrypt(wo_tls_client *c, const uint8_t *rec, size_t reclen,
uint8_t *out, size_t outcap, uint8_t *content_type) {
if (c->st != ST_ESTABLISHED) return -1;
if (reclen > outcap + WO_TLS_RECORD_OVERHEAD) return -1;
int n = wo_tls_record_open(c->suite, c->rd_key, c->keylen, c->rd_iv,
c->rd_seq, rec, reclen, out, content_type);
if (n < 0) return -1;
c->rd_seq++;
return n;
}

View file

@ -109,4 +109,68 @@ int wo_tls_build_client_hello(const char *hostname, size_t hostlen,
const uint8_t session_id[32], uint8_t *out, const uint8_t session_id[32], uint8_t *out,
size_t outcap, size_t *outlen); size_t outcap, size_t *outlen);
/* ---- sans-io client handshake driver (phase F3c) -------------------------
* A pure state machine: no sockets. The caller frames TLS records (read the
* 5-byte header, then that many bytes) and feeds whole records in; the driver
* advances the handshake and hands back bytes to send. This keeps every I/O
* concern out of the security-critical FSM, so it is fully testable offline
* (KAT'd against the RFC 8448 record trace).
*
* SECURITY NOTE — not yet a safe live client: this core verifies the server's
* CertificateVerify and Finished (proving possession of the leaf key) but does
* NOT yet walk the certificate chain to a trust anchor or match the hostname
* against the cert SAN. Those (the deferred phase-E bits) MUST land before this
* drives a real connection, or the client is open to MITM. It is currently an
* internal building block; net.connect_tls is not wired to it. */
#define WO_TLS_BUF_MAX 16384u /* transcript / reassembly cap (RFC 8448 fits) */
#define WO_TLS_LEAF_MAX 8192u /* largest leaf certificate accepted */
typedef enum {
WO_TLS_WANT_MORE = 0, /* need another record */
WO_TLS_ESTABLISHED = 1, /* handshake done; output holds client Finished */
WO_TLS_FAILED = -1, /* verification/parse failure — connection dead */
} wo_tls_status;
typedef struct {
int suite;
size_t keylen; /* AEAD key length, 16 or 32 */
uint8_t client_priv[32], client_pub[32];
wo_tls_key_schedule ks;
/* current read/write record protection (handshake, then application) */
uint8_t rd_key[32], rd_iv[12], wr_key[32], wr_iv[12];
uint64_t rd_seq, wr_seq;
uint8_t transcript[WO_TLS_BUF_MAX]; size_t tlen;
uint8_t hsbuf[WO_TLS_BUF_MAX]; size_t hsn; /* reassembled handshake bytes */
uint8_t leaf[WO_TLS_LEAF_MAX]; size_t leaflen;
uint16_t cv_scheme;
uint8_t out[1024]; size_t outn; /* bytes for the caller to send */
int st; /* internal FSM state */
} wo_tls_client;
/* Start a handshake from a caller-built ClientHello handshake message and a
* fixed X25519 private key (production passes fresh randomness; the KAT injects
* the RFC's). Frames the ClientHello into a plaintext record in c->out for the
* caller to send, and seeds the transcript. 0 ok, -1 on a buffer problem. */
int wo_tls_client_start_with(wo_tls_client *c, const uint8_t *ch_msg,
size_t ch_len, const uint8_t priv[32]);
/* Feed one whole TLS record. Advances the FSM. Returns WANT_MORE (need the
* next record), ESTABLISHED (handshake complete — drain c->out for the client
* Finished, then use the encrypt/decrypt calls), or FAILED. */
wo_tls_status wo_tls_client_push_record(wo_tls_client *c, const uint8_t *rec,
size_t reclen);
/* Copy out (and clear) the bytes the driver wants sent. Returns the count. */
size_t wo_tls_client_take_output(wo_tls_client *c, uint8_t *out, size_t outcap);
/* Application data, post-handshake (application traffic keys). encrypt writes a
* full record into out; decrypt reads one record and yields the plaintext plus
* its inner content type. Return the byte count, or -1 on overflow / auth
* failure. */
int wo_tls_client_encrypt(wo_tls_client *c, const uint8_t *data, size_t len,
uint8_t *out, size_t outcap);
int wo_tls_client_decrypt(wo_tls_client *c, const uint8_t *rec, size_t reclen,
uint8_t *out, size_t outcap, uint8_t *content_type);
#endif #endif

View file

@ -9,6 +9,7 @@
#include "t.h" #include "t.h"
#include "tls_record_vectors.h" #include "tls_record_vectors.h"
#include "tls_hs_vectors.h" #include "tls_hs_vectors.h"
#include "tls_driver_vectors.h"
/* RFC 8448 §3 recorded ServerHello handshake message (90 octets). */ /* RFC 8448 §3 recorded ServerHello handshake message (90 octets). */
#define SH_MSG "\x02\x00\x00\x56\x03\x03\xa6\xaf\x06\xa4\x12\x18\x60\xdc\x5e\x6e\x60\x24\x9c\xd3\x4c\x95\x93\x0c\x8a\xc5\xcb\x14\x34\xda\xc1\x55\x77\x2e\xd3\xe2\x69\x28\x00\x13\x01\x00\x00\x2e\x00\x33\x00\x24\x00\x1d\x00\x20\xc9\x82\x88\x76\x11\x20\x95\xfe\x66\x76\x2b\xdb\xf7\xc6\x72\xe1\x56\xd6\xcc\x25\x3b\x83\x3d\xf1\xdd\x69\xb1\xb0\x4e\x75\x1f\x0f\x00\x2b\x00\x02\x03\x04" #define SH_MSG "\x02\x00\x00\x56\x03\x03\xa6\xaf\x06\xa4\x12\x18\x60\xdc\x5e\x6e\x60\x24\x9c\xd3\x4c\x95\x93\x0c\x8a\xc5\xcb\x14\x34\xda\xc1\x55\x77\x2e\xd3\xe2\x69\x28\x00\x13\x01\x00\x00\x2e\x00\x33\x00\x24\x00\x1d\x00\x20\xc9\x82\x88\x76\x11\x20\x95\xfe\x66\x76\x2b\xdb\xf7\xc6\x72\xe1\x56\xd6\xcc\x25\x3b\x83\x3d\xf1\xdd\x69\xb1\xb0\x4e\x75\x1f\x0f\x00\x2b\x00\x02\x03\x04"
@ -235,5 +236,64 @@ int main(void) {
T_CHECK(memcmp(vd, hs_cfin + 4, 32) == 0); T_CHECK(memcmp(vd, hs_cfin + 4, 32) == 0);
} }
/* Sans-io client driver (phase F3c): the whole handshake driven offline
* against the RFC 8448 record trace, then application data both ways. */
{
static wo_tls_client c; /* ~40 KB — keep off the stack */
uint8_t priv[32], ch[256];
memcpy(priv, drv_client_priv, 32);
memcpy(ch, drv_ch_msg, sizeof drv_ch_msg);
T_CHECK(wo_tls_client_start_with(&c, ch, sizeof drv_ch_msg, priv) == 0);
/* it framed a ClientHello record to send */
uint8_t sent[512];
size_t sn = wo_tls_client_take_output(&c, sent, sizeof sent);
T_CHECK(sn == 5 + sizeof drv_ch_msg && sent[0] == 22);
uint8_t rsh[128]; memcpy(rsh, drv_rec_sh, sizeof drv_rec_sh);
T_CHECK(wo_tls_client_push_record(&c, rsh, sizeof drv_rec_sh) == WO_TLS_WANT_MORE);
uint8_t rfl[1024]; memcpy(rfl, drv_rec_flight, sizeof drv_rec_flight);
T_CHECK(wo_tls_client_push_record(&c, rfl, sizeof drv_rec_flight) == WO_TLS_ESTABLISHED);
/* the client Finished record we emit matches RFC 8448 byte-for-byte */
uint8_t fin[128];
size_t fn = wo_tls_client_take_output(&c, fin, sizeof fin);
T_CHECK(fn == sizeof drv_rec_cfin);
T_CHECK(memcmp(fin, drv_rec_cfin, sizeof drv_rec_cfin) == 0);
/* application encrypt: our first app record equals the recorded one */
uint8_t app[128];
int an = wo_tls_client_encrypt(&c, drv_capp_pt, sizeof drv_capp_pt, app, sizeof app);
T_CHECK(an == (int)sizeof drv_rec_capp);
T_CHECK(memcmp(app, drv_rec_capp, sizeof drv_rec_capp) == 0);
/* server sends NewSessionTicket first (server app seq 0) — decrypt it
* (a post-handshake handshake message), advancing the read seq. */
uint8_t nst[256]; uint8_t ct2 = 0;
memcpy(nst, drv_rec_nst, sizeof drv_rec_nst);
int nn = wo_tls_client_decrypt(&c, nst, sizeof drv_rec_nst, nst, sizeof nst, &ct2);
T_CHECK(nn > 0 && ct2 == 22); /* handshake (ticket) */
/* then the server's application data (seq 1) decrypts to the plaintext */
uint8_t sapp[128]; uint8_t ct3 = 0;
int dn = wo_tls_client_decrypt(&c, drv_rec_sapp, sizeof drv_rec_sapp,
sapp, sizeof sapp, &ct3);
T_CHECK(dn == (int)sizeof drv_sapp_pt && ct3 == 23);
T_CHECK(memcmp(sapp, drv_sapp_pt, sizeof drv_sapp_pt) == 0);
}
/* Driver rejects a tampered server flight (auth failure -> FAILED). */
{
static wo_tls_client c;
uint8_t priv[32], ch[256];
memcpy(priv, drv_client_priv, 32); memcpy(ch, drv_ch_msg, sizeof drv_ch_msg);
wo_tls_client_start_with(&c, ch, sizeof drv_ch_msg, priv);
uint8_t rsh[128]; memcpy(rsh, drv_rec_sh, sizeof drv_rec_sh);
wo_tls_client_push_record(&c, rsh, sizeof drv_rec_sh);
uint8_t rfl[1024]; memcpy(rfl, drv_rec_flight, sizeof drv_rec_flight);
rfl[100] ^= 0x01; /* corrupt the ciphertext */
T_CHECK(wo_tls_client_push_record(&c, rfl, sizeof drv_rec_flight) == WO_TLS_FAILED);
}
return t_report("test_tls"); return t_report("test_tls");
} }

View file

@ -0,0 +1,175 @@
/* Generated from RFC 8448 §3 'Simple 1-RTT Handshake'. Wire records +
* ephemeral key + app-data plaintext for the phase-F3c sans-io driver KAT. */
static const unsigned char drv_client_priv[] = {
0x49,0xaf,0x42,0xba,0x7f,0x79,0x94,0x85,0x2d,0x71,0x3e,0xf2,
0x78,0x4b,0xcb,0xca,0xa7,0x91,0x1d,0xe2,0x6a,0xdc,0x56,0x42,
0xcb,0x63,0x45,0x40,0xe7,0xea,0x50,0x05,
};
static const unsigned char drv_ch_msg[] = {
0x01,0x00,0x00,0xc0,0x03,0x03,0xcb,0x34,0xec,0xb1,0xe7,0x81,
0x63,0xba,0x1c,0x38,0xc6,0xda,0xcb,0x19,0x6a,0x6d,0xff,0xa2,
0x1a,0x8d,0x99,0x12,0xec,0x18,0xa2,0xef,0x62,0x83,0x02,0x4d,
0xec,0xe7,0x00,0x00,0x06,0x13,0x01,0x13,0x03,0x13,0x02,0x01,
0x00,0x00,0x91,0x00,0x00,0x00,0x0b,0x00,0x09,0x00,0x00,0x06,
0x73,0x65,0x72,0x76,0x65,0x72,0xff,0x01,0x00,0x01,0x00,0x00,
0x0a,0x00,0x14,0x00,0x12,0x00,0x1d,0x00,0x17,0x00,0x18,0x00,
0x19,0x01,0x00,0x01,0x01,0x01,0x02,0x01,0x03,0x01,0x04,0x00,
0x23,0x00,0x00,0x00,0x33,0x00,0x26,0x00,0x24,0x00,0x1d,0x00,
0x20,0x99,0x38,0x1d,0xe5,0x60,0xe4,0xbd,0x43,0xd2,0x3d,0x8e,
0x43,0x5a,0x7d,0xba,0xfe,0xb3,0xc0,0x6e,0x51,0xc1,0x3c,0xae,
0x4d,0x54,0x13,0x69,0x1e,0x52,0x9a,0xaf,0x2c,0x00,0x2b,0x00,
0x03,0x02,0x03,0x04,0x00,0x0d,0x00,0x20,0x00,0x1e,0x04,0x03,
0x05,0x03,0x06,0x03,0x02,0x03,0x08,0x04,0x08,0x05,0x08,0x06,
0x04,0x01,0x05,0x01,0x06,0x01,0x02,0x01,0x04,0x02,0x05,0x02,
0x06,0x02,0x02,0x02,0x00,0x2d,0x00,0x02,0x01,0x01,0x00,0x1c,
0x00,0x02,0x40,0x01,
};
static const unsigned char drv_rec_sh[] = {
0x16,0x03,0x03,0x00,0x5a,0x02,0x00,0x00,0x56,0x03,0x03,0xa6,
0xaf,0x06,0xa4,0x12,0x18,0x60,0xdc,0x5e,0x6e,0x60,0x24,0x9c,
0xd3,0x4c,0x95,0x93,0x0c,0x8a,0xc5,0xcb,0x14,0x34,0xda,0xc1,
0x55,0x77,0x2e,0xd3,0xe2,0x69,0x28,0x00,0x13,0x01,0x00,0x00,
0x2e,0x00,0x33,0x00,0x24,0x00,0x1d,0x00,0x20,0xc9,0x82,0x88,
0x76,0x11,0x20,0x95,0xfe,0x66,0x76,0x2b,0xdb,0xf7,0xc6,0x72,
0xe1,0x56,0xd6,0xcc,0x25,0x3b,0x83,0x3d,0xf1,0xdd,0x69,0xb1,
0xb0,0x4e,0x75,0x1f,0x0f,0x00,0x2b,0x00,0x02,0x03,0x04,
};
static const unsigned char drv_rec_flight[] = {
0x17,0x03,0x03,0x02,0xa2,0xd1,0xff,0x33,0x4a,0x56,0xf5,0xbf,
0xf6,0x59,0x4a,0x07,0xcc,0x87,0xb5,0x80,0x23,0x3f,0x50,0x0f,
0x45,0xe4,0x89,0xe7,0xf3,0x3a,0xf3,0x5e,0xdf,0x78,0x69,0xfc,
0xf4,0x0a,0xa4,0x0a,0xa2,0xb8,0xea,0x73,0xf8,0x48,0xa7,0xca,
0x07,0x61,0x2e,0xf9,0xf9,0x45,0xcb,0x96,0x0b,0x40,0x68,0x90,
0x51,0x23,0xea,0x78,0xb1,0x11,0xb4,0x29,0xba,0x91,0x91,0xcd,
0x05,0xd2,0xa3,0x89,0x28,0x0f,0x52,0x61,0x34,0xaa,0xdc,0x7f,
0xc7,0x8c,0x4b,0x72,0x9d,0xf8,0x28,0xb5,0xec,0xf7,0xb1,0x3b,
0xd9,0xae,0xfb,0x0e,0x57,0xf2,0x71,0x58,0x5b,0x8e,0xa9,0xbb,
0x35,0x5c,0x7c,0x79,0x02,0x07,0x16,0xcf,0xb9,0xb1,0x18,0x3e,
0xf3,0xab,0x20,0xe3,0x7d,0x57,0xa6,0xb9,0xd7,0x47,0x76,0x09,
0xae,0xe6,0xe1,0x22,0xa4,0xcf,0x51,0x42,0x73,0x25,0x25,0x0c,
0x7d,0x0e,0x50,0x92,0x89,0x44,0x4c,0x9b,0x3a,0x64,0x8f,0x1d,
0x71,0x03,0x5d,0x2e,0xd6,0x5b,0x0e,0x3c,0xdd,0x0c,0xba,0xe8,
0xbf,0x2d,0x0b,0x22,0x78,0x12,0xcb,0xb3,0x60,0x98,0x72,0x55,
0xcc,0x74,0x41,0x10,0xc4,0x53,0xba,0xa4,0xfc,0xd6,0x10,0x92,
0x8d,0x80,0x98,0x10,0xe4,0xb7,0xed,0x1a,0x8f,0xd9,0x91,0xf0,
0x6a,0xa6,0x24,0x82,0x04,0x79,0x7e,0x36,0xa6,0xa7,0x3b,0x70,
0xa2,0x55,0x9c,0x09,0xea,0xd6,0x86,0x94,0x5b,0xa2,0x46,0xab,
0x66,0xe5,0xed,0xd8,0x04,0x4b,0x4c,0x6d,0xe3,0xfc,0xf2,0xa8,
0x94,0x41,0xac,0x66,0x27,0x2f,0xd8,0xfb,0x33,0x0e,0xf8,0x19,
0x05,0x79,0xb3,0x68,0x45,0x96,0xc9,0x60,0xbd,0x59,0x6e,0xea,
0x52,0x0a,0x56,0xa8,0xd6,0x50,0xf5,0x63,0xaa,0xd2,0x74,0x09,
0x96,0x0d,0xca,0x63,0xd3,0xe6,0x88,0x61,0x1e,0xa5,0xe2,0x2f,
0x44,0x15,0xcf,0x95,0x38,0xd5,0x1a,0x20,0x0c,0x27,0x03,0x42,
0x72,0x96,0x8a,0x26,0x4e,0xd6,0x54,0x0c,0x84,0x83,0x8d,0x89,
0xf7,0x2c,0x24,0x46,0x1a,0xad,0x6d,0x26,0xf5,0x9e,0xca,0xba,
0x9a,0xcb,0xbb,0x31,0x7b,0x66,0xd9,0x02,0xf4,0xf2,0x92,0xa3,
0x6a,0xc1,0xb6,0x39,0xc6,0x37,0xce,0x34,0x31,0x17,0xb6,0x59,
0x62,0x22,0x45,0x31,0x7b,0x49,0xee,0xda,0x0c,0x62,0x58,0xf1,
0x00,0xd7,0xd9,0x61,0xff,0xb1,0x38,0x64,0x7e,0x92,0xea,0x33,
0x0f,0xae,0xea,0x6d,0xfa,0x31,0xc7,0xa8,0x4d,0xc3,0xbd,0x7e,
0x1b,0x7a,0x6c,0x71,0x78,0xaf,0x36,0x87,0x90,0x18,0xe3,0xf2,
0x52,0x10,0x7f,0x24,0x3d,0x24,0x3d,0xc7,0x33,0x9d,0x56,0x84,
0xc8,0xb0,0x37,0x8b,0xf3,0x02,0x44,0xda,0x8c,0x87,0xc8,0x43,
0xf5,0xe5,0x6e,0xb4,0xc5,0xe8,0x28,0x0a,0x2b,0x48,0x05,0x2c,
0xf9,0x3b,0x16,0x49,0x9a,0x66,0xdb,0x7c,0xca,0x71,0xe4,0x59,
0x94,0x26,0xf7,0xd4,0x61,0xe6,0x6f,0x99,0x88,0x2b,0xd8,0x9f,
0xc5,0x08,0x00,0xbe,0xcc,0xa6,0x2d,0x6c,0x74,0x11,0x6d,0xbd,
0x29,0x72,0xfd,0xa1,0xfa,0x80,0xf8,0x5d,0xf8,0x81,0xed,0xbe,
0x5a,0x37,0x66,0x89,0x36,0xb3,0x35,0x58,0x3b,0x59,0x91,0x86,
0xdc,0x5c,0x69,0x18,0xa3,0x96,0xfa,0x48,0xa1,0x81,0xd6,0xb6,
0xfa,0x4f,0x9d,0x62,0xd5,0x13,0xaf,0xbb,0x99,0x2f,0x2b,0x99,
0x2f,0x67,0xf8,0xaf,0xe6,0x7f,0x76,0x91,0x3f,0xa3,0x88,0xcb,
0x56,0x30,0xc8,0xca,0x01,0xe0,0xc6,0x5d,0x11,0xc6,0x6a,0x1e,
0x2a,0xc4,0xc8,0x59,0x77,0xb7,0xc7,0xa6,0x99,0x9b,0xbf,0x10,
0xdc,0x35,0xae,0x69,0xf5,0x51,0x56,0x14,0x63,0x6c,0x0b,0x9b,
0x68,0xc1,0x9e,0xd2,0xe3,0x1c,0x0b,0x3b,0x66,0x76,0x30,0x38,
0xeb,0xba,0x42,0xf3,0xb3,0x8e,0xdc,0x03,0x99,0xf3,0xa9,0xf2,
0x3f,0xaa,0x63,0x97,0x8c,0x31,0x7f,0xc9,0xfa,0x66,0xa7,0x3f,
0x60,0xf0,0x50,0x4d,0xe9,0x3b,0x5b,0x84,0x5e,0x27,0x55,0x92,
0xc1,0x23,0x35,0xee,0x34,0x0b,0xbc,0x4f,0xdd,0xd5,0x02,0x78,
0x40,0x16,0xe4,0xb3,0xbe,0x7e,0xf0,0x4d,0xda,0x49,0xf4,0xb4,
0x40,0xa3,0x0c,0xb5,0xd2,0xaf,0x93,0x98,0x28,0xfd,0x4a,0xe3,
0x79,0x4e,0x44,0xf9,0x4d,0xf5,0xa6,0x31,0xed,0xe4,0x2c,0x17,
0x19,0xbf,0xda,0xbf,0x02,0x53,0xfe,0x51,0x75,0xbe,0x89,0x8e,
0x75,0x0e,0xdc,0x53,0x37,0x0d,0x2b,
};
static const unsigned char drv_rec_cfin[] = {
0x17,0x03,0x03,0x00,0x35,0x75,0xec,0x4d,0xc2,0x38,0xcc,0xe6,
0x0b,0x29,0x80,0x44,0xa7,0x1e,0x21,0x9c,0x56,0xcc,0x77,0xb0,
0x51,0x7f,0xe9,0xb9,0x3c,0x7a,0x4b,0xfc,0x44,0xd8,0x7f,0x38,
0xf8,0x03,0x38,0xac,0x98,0xfc,0x46,0xde,0xb3,0x84,0xbd,0x1c,
0xae,0xac,0xab,0x68,0x67,0xd7,0x26,0xc4,0x05,0x46,
};
static const unsigned char drv_rec_nst[] = {
0x17,0x03,0x03,0x00,0xde,0x3a,0x6b,0x8f,0x90,0x41,0x4a,0x97,
0xd6,0x95,0x9c,0x34,0x87,0x68,0x0d,0xe5,0x13,0x4a,0x2b,0x24,
0x0e,0x6c,0xff,0xac,0x11,0x6e,0x95,0xd4,0x1d,0x6a,0xf8,0xf6,
0xb5,0x80,0xdc,0xf3,0xd1,0x1d,0x63,0xc7,0x58,0xdb,0x28,0x9a,
0x01,0x59,0x40,0x25,0x2f,0x55,0x71,0x3e,0x06,0x1d,0xc1,0x3e,
0x07,0x88,0x91,0xa3,0x8e,0xfb,0xcf,0x57,0x53,0xad,0x8e,0xf1,
0x70,0xad,0x3c,0x73,0x53,0xd1,0x6d,0x9d,0xa7,0x73,0xb9,0xca,
0x7f,0x2b,0x9f,0xa1,0xb6,0xc0,0xd4,0xa3,0xd0,0x3f,0x75,0xe0,
0x9c,0x30,0xba,0x1e,0x62,0x97,0x2a,0xc4,0x6f,0x75,0xf7,0xb9,
0x81,0xbe,0x63,0x43,0x9b,0x29,0x99,0xce,0x13,0x06,0x46,0x15,
0x13,0x98,0x91,0xd5,0xe4,0xc5,0xb4,0x06,0xf1,0x6e,0x3f,0xc1,
0x81,0xa7,0x7c,0xa4,0x75,0x84,0x00,0x25,0xdb,0x2f,0x0a,0x77,
0xf8,0x1b,0x5a,0xb0,0x5b,0x94,0xc0,0x13,0x46,0x75,0x5f,0x69,
0x23,0x2c,0x86,0x51,0x9d,0x86,0xcb,0xee,0xac,0x87,0xaa,0xc3,
0x47,0xd1,0x43,0xf9,0x60,0x5d,0x64,0xf6,0x50,0xdb,0x4d,0x02,
0x3e,0x70,0xe9,0x52,0xca,0x49,0xfe,0x51,0x37,0x12,0x1c,0x74,
0xbc,0x26,0x97,0x68,0x7e,0x24,0x87,0x46,0xd6,0xdf,0x35,0x30,
0x05,0xf3,0xbc,0xe1,0x86,0x96,0x12,0x9c,0x81,0x53,0x55,0x6b,
0x3b,0x6c,0x67,0x79,0xb3,0x7b,0xf1,0x59,0x85,0x68,0x4f,
};
static const unsigned char drv_rec_capp[] = {
0x17,0x03,0x03,0x00,0x43,0xa2,0x3f,0x70,0x54,0xb6,0x2c,0x94,
0xd0,0xaf,0xfa,0xfe,0x82,0x28,0xba,0x55,0xcb,0xef,0xac,0xea,
0x42,0xf9,0x14,0xaa,0x66,0xbc,0xab,0x3f,0x2b,0x98,0x19,0xa8,
0xa5,0xb4,0x6b,0x39,0x5b,0xd5,0x4a,0x9a,0x20,0x44,0x1e,0x2b,
0x62,0x97,0x4e,0x1f,0x5a,0x62,0x92,0xa2,0x97,0x70,0x14,0xbd,
0x1e,0x3d,0xea,0xe6,0x3a,0xee,0xbb,0x21,0x69,0x49,0x15,0xe4,
};
static const unsigned char drv_capp_pt[] = {
0x00,0x01,0x02,0x03,0x04,0x05,0x06,0x07,0x08,0x09,0x0a,0x0b,
0x0c,0x0d,0x0e,0x0f,0x10,0x11,0x12,0x13,0x14,0x15,0x16,0x17,
0x18,0x19,0x1a,0x1b,0x1c,0x1d,0x1e,0x1f,0x20,0x21,0x22,0x23,
0x24,0x25,0x26,0x27,0x28,0x29,0x2a,0x2b,0x2c,0x2d,0x2e,0x2f,
0x30,0x31,
};
static const unsigned char drv_rec_sapp[] = {
0x17,0x03,0x03,0x00,0x43,0x2e,0x93,0x7e,0x11,0xef,0x4a,0xc7,
0x40,0xe5,0x38,0xad,0x36,0x00,0x5f,0xc4,0xa4,0x69,0x32,0xfc,
0x32,0x25,0xd0,0x5f,0x82,0xaa,0x1b,0x36,0xe3,0x0e,0xfa,0xf9,
0x7d,0x90,0xe6,0xdf,0xfc,0x60,0x2d,0xcb,0x50,0x1a,0x59,0xa8,
0xfc,0xc4,0x9c,0x4b,0xf2,0xe5,0xf0,0xa2,0x1c,0x00,0x47,0xc2,
0xab,0xf3,0x32,0x54,0x0d,0xd0,0x32,0xe1,0x67,0xc2,0x95,0x5d,
};
static const unsigned char drv_sapp_pt[] = {
0x00,0x01,0x02,0x03,0x04,0x05,0x06,0x07,0x08,0x09,0x0a,0x0b,
0x0c,0x0d,0x0e,0x0f,0x10,0x11,0x12,0x13,0x14,0x15,0x16,0x17,
0x18,0x19,0x1a,0x1b,0x1c,0x1d,0x1e,0x1f,0x20,0x21,0x22,0x23,
0x24,0x25,0x26,0x27,0x28,0x29,0x2a,0x2b,0x2c,0x2d,0x2e,0x2f,
0x30,0x31,
};
static const unsigned char drv_c_ap[] = {
0x9e,0x40,0x64,0x6c,0xe7,0x9a,0x7f,0x9d,0xc0,0x5a,0xf8,0x88,
0x9b,0xce,0x65,0x52,0x87,0x5a,0xfa,0x0b,0x06,0xdf,0x00,0x87,
0xf7,0x92,0xeb,0xb7,0xc1,0x75,0x04,0xa5,
};
static const unsigned char drv_s_ap[] = {
0xa1,0x1a,0xf9,0xf0,0x55,0x31,0xf8,0x56,0xad,0x47,0x11,0x6b,
0x45,0xa9,0x50,0x32,0x82,0x04,0xb4,0xf4,0x4b,0xfb,0x6b,0x3a,
0x4b,0x4f,0x1f,0x3f,0xcb,0x63,0x16,0x43,
};