client-parser.c 15 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588
  1. /*
  2. * libwebsockets - small server side websockets and web server implementation
  3. *
  4. * Copyright (C) 2010-2014 Andy Green <andy@warmcat.com>
  5. *
  6. * This library is free software; you can redistribute it and/or
  7. * modify it under the terms of the GNU Lesser General Public
  8. * License as published by the Free Software Foundation:
  9. * version 2.1 of the License.
  10. *
  11. * This library is distributed in the hope that it will be useful,
  12. * but WITHOUT ANY WARRANTY; without even the implied warranty of
  13. * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
  14. * Lesser General Public License for more details.
  15. *
  16. * You should have received a copy of the GNU Lesser General Public
  17. * License along with this library; if not, write to the Free Software
  18. * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston,
  19. * MA 02110-1301 USA
  20. */
  21. #include "private-libwebsockets.h"
  22. /*
  23. * parsers.c: lws_rx_sm() needs to be roughly kept in
  24. * sync with changes here, esp related to ext draining
  25. */
  26. int lws_client_rx_sm(struct lws *wsi, unsigned char c)
  27. {
  28. int callback_action = LWS_CALLBACK_CLIENT_RECEIVE;
  29. int handled, n, m, rx_draining_ext = 0;
  30. unsigned short close_code;
  31. struct lws_tokens eff_buf;
  32. unsigned char *pp;
  33. if (wsi->u.ws.rx_draining_ext) {
  34. assert(!c);
  35. eff_buf.token = NULL;
  36. eff_buf.token_len = 0;
  37. lws_remove_wsi_from_draining_ext_list(wsi);
  38. rx_draining_ext = 1;
  39. lwsl_debug("%s: doing draining flow\n", __func__);
  40. goto drain_extension;
  41. }
  42. if (wsi->socket_is_permanently_unusable)
  43. return -1;
  44. switch (wsi->lws_rx_parse_state) {
  45. case LWS_RXPS_NEW:
  46. /* control frames (PING) may interrupt checkable sequences */
  47. wsi->u.ws.defeat_check_utf8 = 0;
  48. switch (wsi->ietf_spec_revision) {
  49. case 13:
  50. wsi->u.ws.opcode = c & 0xf;
  51. /* revisit if an extension wants them... */
  52. switch (wsi->u.ws.opcode) {
  53. case LWSWSOPC_TEXT_FRAME:
  54. wsi->u.ws.rsv_first_msg = (c & 0x70);
  55. wsi->u.ws.continuation_possible = 1;
  56. wsi->u.ws.check_utf8 = lws_check_opt(
  57. wsi->context->options,
  58. LWS_SERVER_OPTION_VALIDATE_UTF8);
  59. wsi->u.ws.utf8 = 0;
  60. break;
  61. case LWSWSOPC_BINARY_FRAME:
  62. wsi->u.ws.rsv_first_msg = (c & 0x70);
  63. wsi->u.ws.check_utf8 = 0;
  64. wsi->u.ws.continuation_possible = 1;
  65. break;
  66. case LWSWSOPC_CONTINUATION:
  67. if (!wsi->u.ws.continuation_possible) {
  68. lwsl_info("disordered continuation\n");
  69. return -1;
  70. }
  71. break;
  72. case LWSWSOPC_CLOSE:
  73. wsi->u.ws.check_utf8 = 0;
  74. wsi->u.ws.utf8 = 0;
  75. break;
  76. case 3:
  77. case 4:
  78. case 5:
  79. case 6:
  80. case 7:
  81. case 0xb:
  82. case 0xc:
  83. case 0xd:
  84. case 0xe:
  85. case 0xf:
  86. lwsl_info("illegal opcode\n");
  87. return -1;
  88. default:
  89. wsi->u.ws.defeat_check_utf8 = 1;
  90. break;
  91. }
  92. wsi->u.ws.rsv = (c & 0x70);
  93. /* revisit if an extension wants them... */
  94. if (
  95. #ifndef LWS_NO_EXTENSIONS
  96. !wsi->count_act_ext &&
  97. #endif
  98. wsi->u.ws.rsv) {
  99. lwsl_info("illegal rsv bits set\n");
  100. return -1;
  101. }
  102. wsi->u.ws.final = !!((c >> 7) & 1);
  103. lwsl_ext("%s: This RX frame Final %d\n", __func__, wsi->u.ws.final);
  104. if (wsi->u.ws.owed_a_fin &&
  105. (wsi->u.ws.opcode == LWSWSOPC_TEXT_FRAME ||
  106. wsi->u.ws.opcode == LWSWSOPC_BINARY_FRAME)) {
  107. lwsl_info("hey you owed us a FIN\n");
  108. return -1;
  109. }
  110. if ((!(wsi->u.ws.opcode & 8)) && wsi->u.ws.final) {
  111. wsi->u.ws.continuation_possible = 0;
  112. wsi->u.ws.owed_a_fin = 0;
  113. }
  114. if ((wsi->u.ws.opcode & 8) && !wsi->u.ws.final) {
  115. lwsl_info("control message cannot be fragmented\n");
  116. return -1;
  117. }
  118. if (!wsi->u.ws.final)
  119. wsi->u.ws.owed_a_fin = 1;
  120. switch (wsi->u.ws.opcode) {
  121. case LWSWSOPC_TEXT_FRAME:
  122. case LWSWSOPC_BINARY_FRAME:
  123. wsi->u.ws.frame_is_binary = wsi->u.ws.opcode ==
  124. LWSWSOPC_BINARY_FRAME;
  125. break;
  126. }
  127. wsi->lws_rx_parse_state = LWS_RXPS_04_FRAME_HDR_LEN;
  128. break;
  129. default:
  130. lwsl_err("unknown spec version %02d\n",
  131. wsi->ietf_spec_revision);
  132. break;
  133. }
  134. break;
  135. case LWS_RXPS_04_FRAME_HDR_LEN:
  136. wsi->u.ws.this_frame_masked = !!(c & 0x80);
  137. switch (c & 0x7f) {
  138. case 126:
  139. /* control frames are not allowed to have big lengths */
  140. if (wsi->u.ws.opcode & 8)
  141. goto illegal_ctl_length;
  142. wsi->lws_rx_parse_state = LWS_RXPS_04_FRAME_HDR_LEN16_2;
  143. break;
  144. case 127:
  145. /* control frames are not allowed to have big lengths */
  146. if (wsi->u.ws.opcode & 8)
  147. goto illegal_ctl_length;
  148. wsi->lws_rx_parse_state = LWS_RXPS_04_FRAME_HDR_LEN64_8;
  149. break;
  150. default:
  151. wsi->u.ws.rx_packet_length = c;
  152. if (wsi->u.ws.this_frame_masked)
  153. wsi->lws_rx_parse_state =
  154. LWS_RXPS_07_COLLECT_FRAME_KEY_1;
  155. else {
  156. if (c)
  157. wsi->lws_rx_parse_state =
  158. LWS_RXPS_PAYLOAD_UNTIL_LENGTH_EXHAUSTED;
  159. else {
  160. wsi->lws_rx_parse_state = LWS_RXPS_NEW;
  161. goto spill;
  162. }
  163. }
  164. break;
  165. }
  166. break;
  167. case LWS_RXPS_04_FRAME_HDR_LEN16_2:
  168. wsi->u.ws.rx_packet_length = c << 8;
  169. wsi->lws_rx_parse_state = LWS_RXPS_04_FRAME_HDR_LEN16_1;
  170. break;
  171. case LWS_RXPS_04_FRAME_HDR_LEN16_1:
  172. wsi->u.ws.rx_packet_length |= c;
  173. if (wsi->u.ws.this_frame_masked)
  174. wsi->lws_rx_parse_state = LWS_RXPS_07_COLLECT_FRAME_KEY_1;
  175. else {
  176. if (wsi->u.ws.rx_packet_length)
  177. wsi->lws_rx_parse_state =
  178. LWS_RXPS_PAYLOAD_UNTIL_LENGTH_EXHAUSTED;
  179. else {
  180. wsi->lws_rx_parse_state = LWS_RXPS_NEW;
  181. goto spill;
  182. }
  183. }
  184. break;
  185. case LWS_RXPS_04_FRAME_HDR_LEN64_8:
  186. if (c & 0x80) {
  187. lwsl_warn("b63 of length must be zero\n");
  188. /* kill the connection */
  189. return -1;
  190. }
  191. #if defined __LP64__
  192. wsi->u.ws.rx_packet_length = ((size_t)c) << 56;
  193. #else
  194. wsi->u.ws.rx_packet_length = 0;
  195. #endif
  196. wsi->lws_rx_parse_state = LWS_RXPS_04_FRAME_HDR_LEN64_7;
  197. break;
  198. case LWS_RXPS_04_FRAME_HDR_LEN64_7:
  199. #if defined __LP64__
  200. wsi->u.ws.rx_packet_length |= ((size_t)c) << 48;
  201. #endif
  202. wsi->lws_rx_parse_state = LWS_RXPS_04_FRAME_HDR_LEN64_6;
  203. break;
  204. case LWS_RXPS_04_FRAME_HDR_LEN64_6:
  205. #if defined __LP64__
  206. wsi->u.ws.rx_packet_length |= ((size_t)c) << 40;
  207. #endif
  208. wsi->lws_rx_parse_state = LWS_RXPS_04_FRAME_HDR_LEN64_5;
  209. break;
  210. case LWS_RXPS_04_FRAME_HDR_LEN64_5:
  211. #if defined __LP64__
  212. wsi->u.ws.rx_packet_length |= ((size_t)c) << 32;
  213. #endif
  214. wsi->lws_rx_parse_state = LWS_RXPS_04_FRAME_HDR_LEN64_4;
  215. break;
  216. case LWS_RXPS_04_FRAME_HDR_LEN64_4:
  217. wsi->u.ws.rx_packet_length |= ((size_t)c) << 24;
  218. wsi->lws_rx_parse_state = LWS_RXPS_04_FRAME_HDR_LEN64_3;
  219. break;
  220. case LWS_RXPS_04_FRAME_HDR_LEN64_3:
  221. wsi->u.ws.rx_packet_length |= ((size_t)c) << 16;
  222. wsi->lws_rx_parse_state = LWS_RXPS_04_FRAME_HDR_LEN64_2;
  223. break;
  224. case LWS_RXPS_04_FRAME_HDR_LEN64_2:
  225. wsi->u.ws.rx_packet_length |= ((size_t)c) << 8;
  226. wsi->lws_rx_parse_state = LWS_RXPS_04_FRAME_HDR_LEN64_1;
  227. break;
  228. case LWS_RXPS_04_FRAME_HDR_LEN64_1:
  229. wsi->u.ws.rx_packet_length |= (size_t)c;
  230. if (wsi->u.ws.this_frame_masked)
  231. wsi->lws_rx_parse_state =
  232. LWS_RXPS_07_COLLECT_FRAME_KEY_1;
  233. else {
  234. if (wsi->u.ws.rx_packet_length)
  235. wsi->lws_rx_parse_state =
  236. LWS_RXPS_PAYLOAD_UNTIL_LENGTH_EXHAUSTED;
  237. else {
  238. wsi->lws_rx_parse_state = LWS_RXPS_NEW;
  239. goto spill;
  240. }
  241. }
  242. break;
  243. case LWS_RXPS_07_COLLECT_FRAME_KEY_1:
  244. wsi->u.ws.mask[0] = c;
  245. if (c)
  246. wsi->u.ws.all_zero_nonce = 0;
  247. wsi->lws_rx_parse_state = LWS_RXPS_07_COLLECT_FRAME_KEY_2;
  248. break;
  249. case LWS_RXPS_07_COLLECT_FRAME_KEY_2:
  250. wsi->u.ws.mask[1] = c;
  251. if (c)
  252. wsi->u.ws.all_zero_nonce = 0;
  253. wsi->lws_rx_parse_state = LWS_RXPS_07_COLLECT_FRAME_KEY_3;
  254. break;
  255. case LWS_RXPS_07_COLLECT_FRAME_KEY_3:
  256. wsi->u.ws.mask[2] = c;
  257. if (c)
  258. wsi->u.ws.all_zero_nonce = 0;
  259. wsi->lws_rx_parse_state = LWS_RXPS_07_COLLECT_FRAME_KEY_4;
  260. break;
  261. case LWS_RXPS_07_COLLECT_FRAME_KEY_4:
  262. wsi->u.ws.mask[3] = c;
  263. if (c)
  264. wsi->u.ws.all_zero_nonce = 0;
  265. if (wsi->u.ws.rx_packet_length)
  266. wsi->lws_rx_parse_state =
  267. LWS_RXPS_PAYLOAD_UNTIL_LENGTH_EXHAUSTED;
  268. else {
  269. wsi->lws_rx_parse_state = LWS_RXPS_NEW;
  270. goto spill;
  271. }
  272. break;
  273. case LWS_RXPS_PAYLOAD_UNTIL_LENGTH_EXHAUSTED:
  274. assert(wsi->u.ws.rx_ubuf);
  275. if (wsi->u.ws.rx_draining_ext)
  276. goto drain_extension;
  277. if (wsi->u.ws.this_frame_masked && !wsi->u.ws.all_zero_nonce)
  278. c ^= wsi->u.ws.mask[(wsi->u.ws.mask_idx++) & 3];
  279. wsi->u.ws.rx_ubuf[LWS_PRE + (wsi->u.ws.rx_ubuf_head++)] = c;
  280. if (--wsi->u.ws.rx_packet_length == 0) {
  281. /* spill because we have the whole frame */
  282. wsi->lws_rx_parse_state = LWS_RXPS_NEW;
  283. goto spill;
  284. }
  285. /*
  286. * if there's no protocol max frame size given, we are
  287. * supposed to default to context->pt_serv_buf_size
  288. */
  289. if (!wsi->protocol->rx_buffer_size &&
  290. wsi->u.ws.rx_ubuf_head != wsi->context->pt_serv_buf_size)
  291. break;
  292. if (wsi->protocol->rx_buffer_size &&
  293. wsi->u.ws.rx_ubuf_head != wsi->protocol->rx_buffer_size)
  294. break;
  295. /* spill because we filled our rx buffer */
  296. spill:
  297. handled = 0;
  298. /*
  299. * is this frame a control packet we should take care of at this
  300. * layer? If so service it and hide it from the user callback
  301. */
  302. switch (wsi->u.ws.opcode) {
  303. case LWSWSOPC_CLOSE:
  304. pp = (unsigned char *)&wsi->u.ws.rx_ubuf[LWS_PRE];
  305. if (lws_check_opt(wsi->context->options,
  306. LWS_SERVER_OPTION_VALIDATE_UTF8) &&
  307. wsi->u.ws.rx_ubuf_head > 2 &&
  308. lws_check_utf8(&wsi->u.ws.utf8, pp + 2,
  309. wsi->u.ws.rx_ubuf_head - 2))
  310. goto utf8_fail;
  311. /* is this an acknowledgement of our close? */
  312. if (wsi->state == LWSS_AWAITING_CLOSE_ACK) {
  313. /*
  314. * fine he has told us he is closing too, let's
  315. * finish our close
  316. */
  317. lwsl_parser("seen server's close ack\n");
  318. return -1;
  319. }
  320. lwsl_parser("client sees server close len = %d\n",
  321. wsi->u.ws.rx_ubuf_head);
  322. if (wsi->u.ws.rx_ubuf_head >= 2) {
  323. close_code = (pp[0] << 8) | pp[1];
  324. if (close_code < 1000 ||
  325. close_code == 1004 ||
  326. close_code == 1005 ||
  327. close_code == 1006 ||
  328. close_code == 1012 ||
  329. close_code == 1013 ||
  330. close_code == 1014 ||
  331. close_code == 1015 ||
  332. (close_code >= 1016 && close_code < 3000)
  333. ) {
  334. pp[0] = (LWS_CLOSE_STATUS_PROTOCOL_ERR >> 8) & 0xff;
  335. pp[1] = LWS_CLOSE_STATUS_PROTOCOL_ERR & 0xff;
  336. }
  337. }
  338. if (user_callback_handle_rxflow(
  339. wsi->protocol->callback, wsi,
  340. LWS_CALLBACK_WS_PEER_INITIATED_CLOSE,
  341. wsi->user_space, pp,
  342. wsi->u.ws.rx_ubuf_head))
  343. return -1;
  344. if (lws_partial_buffered(wsi))
  345. /*
  346. * if we're in the middle of something,
  347. * we can't do a normal close response and
  348. * have to just close our end.
  349. */
  350. wsi->socket_is_permanently_unusable = 1;
  351. else
  352. /*
  353. * parrot the close packet payload back
  354. * we do not care about how it went, we are closing
  355. * immediately afterwards
  356. */
  357. lws_write(wsi, (unsigned char *)&wsi->u.ws.rx_ubuf[LWS_PRE],
  358. wsi->u.ws.rx_ubuf_head,
  359. LWS_WRITE_CLOSE);
  360. wsi->state = LWSS_RETURNED_CLOSE_ALREADY;
  361. /* close the connection */
  362. return -1;
  363. case LWSWSOPC_PING:
  364. lwsl_info("received %d byte ping, sending pong\n",
  365. wsi->u.ws.rx_ubuf_head);
  366. /* he set a close reason on this guy, ignore PING */
  367. if (wsi->u.ws.close_in_ping_buffer_len)
  368. goto ping_drop;
  369. if (wsi->u.ws.ping_pending_flag) {
  370. /*
  371. * there is already a pending ping payload
  372. * we should just log and drop
  373. */
  374. lwsl_parser("DROP PING since one pending\n");
  375. goto ping_drop;
  376. }
  377. /* control packets can only be < 128 bytes long */
  378. if (wsi->u.ws.rx_ubuf_head > 128 - 3) {
  379. lwsl_parser("DROP PING payload too large\n");
  380. goto ping_drop;
  381. }
  382. /* stash the pong payload */
  383. memcpy(wsi->u.ws.ping_payload_buf + LWS_PRE,
  384. &wsi->u.ws.rx_ubuf[LWS_PRE],
  385. wsi->u.ws.rx_ubuf_head);
  386. wsi->u.ws.ping_payload_len = wsi->u.ws.rx_ubuf_head;
  387. wsi->u.ws.ping_pending_flag = 1;
  388. /* get it sent as soon as possible */
  389. lws_callback_on_writable(wsi);
  390. ping_drop:
  391. wsi->u.ws.rx_ubuf_head = 0;
  392. handled = 1;
  393. break;
  394. case LWSWSOPC_PONG:
  395. lwsl_info("client receied pong\n");
  396. lwsl_hexdump(&wsi->u.ws.rx_ubuf[LWS_PRE],
  397. wsi->u.ws.rx_ubuf_head);
  398. if (wsi->pending_timeout == PENDING_TIMEOUT_WS_PONG_CHECK_GET_PONG) {
  399. lwsl_info("received expected PONG on wsi %p\n", wsi);
  400. lws_set_timeout(wsi, NO_PENDING_TIMEOUT, 0);
  401. }
  402. /* issue it */
  403. callback_action = LWS_CALLBACK_CLIENT_RECEIVE_PONG;
  404. break;
  405. case LWSWSOPC_CONTINUATION:
  406. case LWSWSOPC_TEXT_FRAME:
  407. case LWSWSOPC_BINARY_FRAME:
  408. break;
  409. default:
  410. lwsl_parser("Reserved opc 0x%2X\n", wsi->u.ws.opcode);
  411. /*
  412. * It's something special we can't understand here.
  413. * Pass the payload up to the extension's parsing
  414. * state machine.
  415. */
  416. eff_buf.token = &wsi->u.ws.rx_ubuf[LWS_PRE];
  417. eff_buf.token_len = wsi->u.ws.rx_ubuf_head;
  418. if (lws_ext_cb_active(wsi,
  419. LWS_EXT_CB_EXTENDED_PAYLOAD_RX,
  420. &eff_buf, 0) <= 0) { /* not handle or fail */
  421. lwsl_ext("Unhandled ext opc 0x%x\n", wsi->u.ws.opcode);
  422. wsi->u.ws.rx_ubuf_head = 0;
  423. return 0;
  424. }
  425. handled = 1;
  426. break;
  427. }
  428. /*
  429. * No it's real payload, pass it up to the user callback.
  430. * It's nicely buffered with the pre-padding taken care of
  431. * so it can be sent straight out again using lws_write
  432. */
  433. if (handled)
  434. goto already_done;
  435. eff_buf.token = &wsi->u.ws.rx_ubuf[LWS_PRE];
  436. eff_buf.token_len = wsi->u.ws.rx_ubuf_head;
  437. drain_extension:
  438. lwsl_ext("%s: passing %d to ext\n", __func__, eff_buf.token_len);
  439. n = lws_ext_cb_active(wsi, LWS_EXT_CB_PAYLOAD_RX, &eff_buf, 0);
  440. lwsl_ext("Ext RX returned %d\n", n);
  441. if (n < 0) {
  442. wsi->socket_is_permanently_unusable = 1;
  443. return -1;
  444. }
  445. lwsl_ext("post inflate eff_buf len %d\n", eff_buf.token_len);
  446. if (rx_draining_ext && !eff_buf.token_len) {
  447. lwsl_err(" --- ignoring zero drain result, ending drain\n");
  448. goto already_done;
  449. }
  450. if (wsi->u.ws.check_utf8 && !wsi->u.ws.defeat_check_utf8) {
  451. if (lws_check_utf8(&wsi->u.ws.utf8,
  452. (unsigned char *)eff_buf.token,
  453. eff_buf.token_len))
  454. goto utf8_fail;
  455. /* we are ending partway through utf-8 character? */
  456. if (!wsi->u.ws.rx_packet_length && wsi->u.ws.final &&
  457. wsi->u.ws.utf8 && !n) {
  458. lwsl_info("FINAL utf8 error\n");
  459. utf8_fail: lwsl_info("utf8 error\n");
  460. return -1;
  461. }
  462. }
  463. if (eff_buf.token_len < 0 &&
  464. callback_action != LWS_CALLBACK_CLIENT_RECEIVE_PONG)
  465. goto already_done;
  466. if (!eff_buf.token)
  467. goto already_done;
  468. eff_buf.token[eff_buf.token_len] = '\0';
  469. if (!wsi->protocol->callback)
  470. goto already_done;
  471. if (callback_action == LWS_CALLBACK_CLIENT_RECEIVE_PONG)
  472. lwsl_info("Client doing pong callback\n");
  473. if (n && eff_buf.token_len)
  474. /* extension had more... main loop will come back
  475. * we want callback to be done with this set, if so,
  476. * because lws_is_final() hides it was final until the
  477. * last chunk
  478. */
  479. lws_add_wsi_to_draining_ext_list(wsi);
  480. else
  481. lws_remove_wsi_from_draining_ext_list(wsi);
  482. if (wsi->state == LWSS_RETURNED_CLOSE_ALREADY ||
  483. wsi->state == LWSS_AWAITING_CLOSE_ACK)
  484. goto already_done;
  485. m = wsi->protocol->callback(wsi,
  486. (enum lws_callback_reasons)callback_action,
  487. wsi->user_space, eff_buf.token, eff_buf.token_len);
  488. /* if user code wants to close, let caller know */
  489. if (m)
  490. return 1;
  491. already_done:
  492. wsi->u.ws.rx_ubuf_head = 0;
  493. break;
  494. default:
  495. lwsl_err("client rx illegal state\n");
  496. return 1;
  497. }
  498. return 0;
  499. illegal_ctl_length:
  500. lwsl_warn("Control frame asking for extended length is illegal\n");
  501. /* kill the connection */
  502. return -1;
  503. }