ua_server_binary.c 19 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446
  1. #include "ua_util.h"
  2. #include "ua_server_internal.h"
  3. #include "ua_types_encoding_binary.h"
  4. #include "ua_transport_generated.h"
  5. #include "ua_services.h"
  6. #include "ua_statuscodes.h"
  7. #include "ua_securechannel_manager.h"
  8. #include "ua_session_manager.h"
  9. /** Max size of messages that are allocated on the stack */
  10. #define MAX_STACK_MESSAGE 65536
  11. static void processHEL(UA_Connection *connection, const UA_ByteString *msg, size_t *pos) {
  12. UA_TcpHelloMessage helloMessage;
  13. if(UA_TcpHelloMessage_decodeBinary(msg, pos, &helloMessage) != UA_STATUSCODE_GOOD) {
  14. connection->close(connection);
  15. return;
  16. }
  17. connection->remoteConf.maxChunkCount = helloMessage.maxChunkCount;
  18. connection->remoteConf.maxMessageSize = helloMessage.maxMessageSize;
  19. connection->remoteConf.protocolVersion = helloMessage.protocolVersion;
  20. connection->remoteConf.recvBufferSize = helloMessage.receiveBufferSize;
  21. if(connection->localConf.sendBufferSize > helloMessage.receiveBufferSize)
  22. connection->localConf.sendBufferSize = helloMessage.receiveBufferSize;
  23. if(connection->localConf.recvBufferSize > helloMessage.sendBufferSize)
  24. connection->localConf.recvBufferSize = helloMessage.sendBufferSize;
  25. connection->remoteConf.sendBufferSize = helloMessage.sendBufferSize;
  26. connection->state = UA_CONNECTION_ESTABLISHED;
  27. UA_TcpHelloMessage_deleteMembers(&helloMessage);
  28. // build acknowledge response
  29. UA_TcpAcknowledgeMessage ackMessage;
  30. ackMessage.protocolVersion = connection->localConf.protocolVersion;
  31. ackMessage.receiveBufferSize = connection->localConf.recvBufferSize;
  32. ackMessage.sendBufferSize = connection->localConf.sendBufferSize;
  33. ackMessage.maxMessageSize = connection->localConf.maxMessageSize;
  34. ackMessage.maxChunkCount = connection->localConf.maxChunkCount;
  35. UA_TcpMessageHeader ackHeader;
  36. ackHeader.messageTypeAndFinal = UA_MESSAGETYPEANDFINAL_ACKF;
  37. ackHeader.messageSize = 8 + 20; /* ackHeader + ackMessage */
  38. UA_ByteString ack_msg;
  39. if(connection->getBuffer(connection, &ack_msg) != UA_STATUSCODE_GOOD)
  40. return;
  41. size_t tmpPos = 0;
  42. UA_TcpMessageHeader_encodeBinary(&ackHeader, &ack_msg, &tmpPos);
  43. UA_TcpAcknowledgeMessage_encodeBinary(&ackMessage, &ack_msg, &tmpPos);
  44. if(connection->write(connection, &ack_msg, ackHeader.messageSize) != UA_STATUSCODE_GOOD)
  45. connection->releaseBuffer(connection, &ack_msg);
  46. }
  47. static void processOPN(UA_Connection *connection, UA_Server *server, const UA_ByteString *msg,
  48. size_t *pos) {
  49. if(connection->state != UA_CONNECTION_ESTABLISHED) {
  50. connection->close(connection);
  51. return;
  52. }
  53. UA_UInt32 secureChannelId;
  54. UA_StatusCode retval = UA_UInt32_decodeBinary(msg, pos, &secureChannelId);
  55. UA_AsymmetricAlgorithmSecurityHeader asymHeader;
  56. retval |= UA_AsymmetricAlgorithmSecurityHeader_decodeBinary(msg, pos, &asymHeader);
  57. UA_SequenceHeader seqHeader;
  58. retval |= UA_SequenceHeader_decodeBinary(msg, pos, &seqHeader);
  59. UA_NodeId requestType;
  60. retval |= UA_NodeId_decodeBinary(msg, pos, &requestType);
  61. UA_OpenSecureChannelRequest r;
  62. retval |= UA_OpenSecureChannelRequest_decodeBinary(msg, pos, &r);
  63. if(retval != UA_STATUSCODE_GOOD || requestType.identifier.numeric != 446) {
  64. UA_AsymmetricAlgorithmSecurityHeader_deleteMembers(&asymHeader);
  65. UA_SequenceHeader_deleteMembers(&seqHeader);
  66. UA_NodeId_deleteMembers(&requestType);
  67. UA_OpenSecureChannelRequest_deleteMembers(&r);
  68. connection->close(connection);
  69. return;
  70. }
  71. UA_OpenSecureChannelResponse p;
  72. UA_OpenSecureChannelResponse_init(&p);
  73. Service_OpenSecureChannel(server, connection, &r, &p);
  74. UA_OpenSecureChannelRequest_deleteMembers(&r);
  75. UA_SecureChannel *channel = connection->channel;
  76. if(!channel) {
  77. connection->close(connection);
  78. UA_OpenSecureChannelResponse_deleteMembers(&p);
  79. UA_AsymmetricAlgorithmSecurityHeader_deleteMembers(&asymHeader);
  80. return;
  81. }
  82. /* send the response with an asymmetric security header */
  83. #ifndef UA_MULTITHREADING
  84. seqHeader.sequenceNumber = ++channel->sequenceNumber;
  85. #else
  86. seqHeader.sequenceNumber = uatomic_add_return(&channel->sequenceNumber, 1);
  87. #endif
  88. UA_SecureConversationMessageHeader respHeader;
  89. respHeader.messageHeader.messageTypeAndFinal = UA_MESSAGETYPEANDFINAL_OPNF;
  90. respHeader.messageHeader.messageSize = 0;
  91. respHeader.secureChannelId = p.securityToken.channelId;
  92. UA_NodeId responseType = UA_NODEID_NUMERIC(0, UA_NS0ID_OPENSECURECHANNELRESPONSE +
  93. UA_ENCODINGOFFSET_BINARY);
  94. UA_ByteString resp_msg;
  95. retval = connection->getBuffer(connection, &resp_msg);
  96. if(retval != UA_STATUSCODE_GOOD) {
  97. UA_OpenSecureChannelResponse_deleteMembers(&p);
  98. UA_AsymmetricAlgorithmSecurityHeader_deleteMembers(&asymHeader);
  99. return;
  100. }
  101. size_t tmpPos = 12; /* skip the secureconversationmessageheader for now */
  102. retval |= UA_AsymmetricAlgorithmSecurityHeader_encodeBinary(&asymHeader, &resp_msg, &tmpPos); // just mirror back
  103. retval |= UA_SequenceHeader_encodeBinary(&seqHeader, &resp_msg, &tmpPos); // just mirror back
  104. retval |= UA_NodeId_encodeBinary(&responseType, &resp_msg, &tmpPos);
  105. retval |= UA_OpenSecureChannelResponse_encodeBinary(&p, &resp_msg, &tmpPos);
  106. if(retval != UA_STATUSCODE_GOOD) {
  107. connection->releaseBuffer(connection, &resp_msg);
  108. connection->close(connection);
  109. } else {
  110. respHeader.messageHeader.messageSize = tmpPos;
  111. tmpPos = 0;
  112. UA_SecureConversationMessageHeader_encodeBinary(&respHeader, &resp_msg, &tmpPos);
  113. if(connection->write(connection, &resp_msg,
  114. respHeader.messageHeader.messageSize) != UA_STATUSCODE_GOOD)
  115. connection->releaseBuffer(connection, &resp_msg);
  116. }
  117. UA_OpenSecureChannelResponse_deleteMembers(&p);
  118. UA_AsymmetricAlgorithmSecurityHeader_deleteMembers(&asymHeader);
  119. }
  120. static void init_response_header(const UA_RequestHeader *p, UA_ResponseHeader *r) {
  121. r->requestHandle = p->requestHandle;
  122. r->stringTableSize = 0;
  123. r->timestamp = UA_DateTime_now();
  124. }
  125. /* The request/response are casted to the header (first element of their struct) */
  126. static void invoke_service(UA_Server *server, UA_SecureChannel *channel, UA_UInt32 requestId,
  127. UA_RequestHeader *request, const UA_DataType *responseType,
  128. void (*service)(UA_Server*, UA_Session*, void*, void*)) {
  129. UA_ResponseHeader *response = UA_alloca(responseType->memSize);
  130. UA_init(response, responseType);
  131. init_response_header(request, response);
  132. /* try to get the session from the securechannel first */
  133. UA_Session *session = UA_SecureChannel_getSession(channel, &request->authenticationToken);
  134. if(!session || session->channel != channel) {
  135. response->serviceResult = UA_STATUSCODE_BADSESSIONIDINVALID;
  136. } else if(session->activated == UA_FALSE) {
  137. response->serviceResult = UA_STATUSCODE_BADSESSIONNOTACTIVATED;
  138. /* the session is invalidated FIXME: do this delayed*/
  139. UA_SessionManager_removeSession(&server->sessionManager, server, &request->authenticationToken);
  140. } else {
  141. UA_Session_updateLifetime(session);
  142. service(server, session, request, response);
  143. }
  144. UA_StatusCode retval = UA_SecureChannel_sendBinaryMessage(channel, requestId, response, responseType);
  145. if(retval != UA_STATUSCODE_GOOD) {
  146. if(retval == UA_STATUSCODE_BADENCODINGLIMITSEXCEEDED)
  147. response->serviceResult = UA_STATUSCODE_BADRESPONSETOOLARGE;
  148. else
  149. response->serviceResult = retval;
  150. UA_SecureChannel_sendBinaryMessage(channel, requestId, response, &UA_TYPES[UA_TYPES_SERVICEFAULT]);
  151. }
  152. UA_deleteMembers(response, responseType);
  153. }
  154. #define INVOKE_SERVICE(REQUEST, RESPONSETYPE) do { \
  155. UA_##REQUEST##Request p; \
  156. if(UA_##REQUEST##Request_decodeBinary(msg, pos, &p)) \
  157. return; \
  158. invoke_service(server, clientChannel, sequenceHeader.requestId, \
  159. &p.requestHeader, &UA_TYPES[RESPONSETYPE], \
  160. (void (*)(UA_Server*, UA_Session*, void*,void*))Service_##REQUEST); \
  161. UA_##REQUEST##Request_deleteMembers(&p); \
  162. } while(0)
  163. static void processMSG(UA_Connection *connection, UA_Server *server, const UA_ByteString *msg, size_t *pos) {
  164. /* Read in the securechannel */
  165. UA_UInt32 secureChannelId;
  166. UA_StatusCode retval = UA_UInt32_decodeBinary(msg, pos, &secureChannelId);
  167. if(retval != UA_STATUSCODE_GOOD)
  168. return;
  169. /* the anonymous channel is used e.g. to allow getEndpoints without a channel */
  170. UA_SecureChannel *clientChannel = connection->channel;
  171. UA_SecureChannel anonymousChannel;
  172. if(!clientChannel) {
  173. UA_SecureChannel_init(&anonymousChannel);
  174. anonymousChannel.connection = connection;
  175. clientChannel = &anonymousChannel;
  176. #ifdef EXTENSION_STATELESS
  177. UA_SecureChannel_attachSession(&anonymousChannel, &anonymousSession);
  178. #endif
  179. }
  180. /* Read the security header */
  181. UA_UInt32 tokenId = 0;
  182. UA_SequenceHeader sequenceHeader;
  183. retval = UA_UInt32_decodeBinary(msg, pos, &tokenId);
  184. retval |= UA_SequenceHeader_decodeBinary(msg, pos, &sequenceHeader);
  185. #ifndef EXTENSION_STATELESS
  186. if(retval != UA_STATUSCODE_GOOD || tokenId==0) //0 is invalid
  187. #else
  188. if(retval != UA_STATUSCODE_GOOD)
  189. #endif
  190. return;
  191. if(clientChannel != &anonymousChannel){
  192. if(tokenId!=clientChannel->securityToken.tokenId){
  193. //is client using a newly issued token?
  194. if(tokenId==clientChannel->nextSecurityToken.tokenId){ //tokenId is not 0
  195. UA_SecureChannel_revolveTokens(clientChannel);
  196. }else{
  197. //FIXME: how to react to this, what do we have to return? Or just kill the channel
  198. }
  199. }
  200. }
  201. /* Read the request type */
  202. UA_NodeId requestType;
  203. if(UA_NodeId_decodeBinary(msg, pos, &requestType) != UA_STATUSCODE_GOOD)
  204. return;
  205. if(requestType.identifierType != UA_NODEIDTYPE_NUMERIC) {
  206. UA_NodeId_deleteMembers(&requestType);
  207. return;
  208. }
  209. switch(requestType.identifier.numeric - UA_ENCODINGOFFSET_BINARY) {
  210. case UA_NS0ID_GETENDPOINTSREQUEST: {
  211. UA_GetEndpointsRequest p;
  212. UA_GetEndpointsResponse r;
  213. if(UA_GetEndpointsRequest_decodeBinary(msg, pos, &p))
  214. return;
  215. UA_GetEndpointsResponse_init(&r);
  216. init_response_header(&p.requestHeader, &r.responseHeader);
  217. Service_GetEndpoints(server, &p, &r);
  218. UA_GetEndpointsRequest_deleteMembers(&p);
  219. UA_SecureChannel_sendBinaryMessage(clientChannel, sequenceHeader.requestId, &r,
  220. &UA_TYPES[UA_TYPES_GETENDPOINTSRESPONSE]);
  221. UA_GetEndpointsResponse_deleteMembers(&r);
  222. break;
  223. }
  224. case UA_NS0ID_FINDSERVERSREQUEST: {
  225. UA_FindServersRequest p;
  226. UA_FindServersResponse r;
  227. if(UA_FindServersRequest_decodeBinary(msg, pos, &p))
  228. return;
  229. UA_FindServersResponse_init(&r);
  230. init_response_header(&p.requestHeader, &r.responseHeader);
  231. Service_FindServers(server, &p, &r);
  232. UA_FindServersRequest_deleteMembers(&p);
  233. UA_SecureChannel_sendBinaryMessage(clientChannel, sequenceHeader.requestId, &r,
  234. &UA_TYPES[UA_TYPES_FINDSERVERSRESPONSE]);
  235. UA_FindServersResponse_deleteMembers(&r);
  236. break;
  237. }
  238. case UA_NS0ID_CREATESESSIONREQUEST: {
  239. UA_CreateSessionRequest p;
  240. UA_CreateSessionResponse r;
  241. if(UA_CreateSessionRequest_decodeBinary(msg, pos, &p))
  242. return;
  243. UA_CreateSessionResponse_init(&r);
  244. init_response_header(&p.requestHeader, &r.responseHeader);
  245. Service_CreateSession(server, clientChannel, &p, &r);
  246. UA_CreateSessionRequest_deleteMembers(&p);
  247. UA_SecureChannel_sendBinaryMessage(clientChannel, sequenceHeader.requestId, &r,
  248. &UA_TYPES[UA_TYPES_CREATESESSIONRESPONSE]);
  249. UA_CreateSessionResponse_deleteMembers(&r);
  250. break;
  251. }
  252. case UA_NS0ID_ACTIVATESESSIONREQUEST: {
  253. UA_ActivateSessionRequest p;
  254. UA_ActivateSessionResponse r;
  255. if(UA_ActivateSessionRequest_decodeBinary(msg, pos, &p))
  256. return;
  257. UA_ActivateSessionResponse_init(&r);
  258. init_response_header(&p.requestHeader, &r.responseHeader);
  259. Service_ActivateSession(server, clientChannel, &p, &r);
  260. UA_ActivateSessionRequest_deleteMembers(&p);
  261. UA_SecureChannel_sendBinaryMessage(clientChannel, sequenceHeader.requestId, &r,
  262. &UA_TYPES[UA_TYPES_ACTIVATESESSIONRESPONSE]);
  263. UA_ActivateSessionResponse_deleteMembers(&r);
  264. break;
  265. }
  266. case UA_NS0ID_CLOSESESSIONREQUEST:
  267. INVOKE_SERVICE(CloseSession, UA_TYPES_CLOSESESSIONRESPONSE);
  268. break;
  269. case UA_NS0ID_READREQUEST:
  270. INVOKE_SERVICE(Read, UA_TYPES_READRESPONSE);
  271. break;
  272. case UA_NS0ID_WRITEREQUEST:
  273. INVOKE_SERVICE(Write, UA_TYPES_WRITERESPONSE);
  274. break;
  275. case UA_NS0ID_BROWSEREQUEST:
  276. INVOKE_SERVICE(Browse, UA_TYPES_BROWSERESPONSE);
  277. break;
  278. case UA_NS0ID_BROWSENEXTREQUEST:
  279. INVOKE_SERVICE(BrowseNext, UA_TYPES_BROWSENEXTRESPONSE);
  280. break;
  281. case UA_NS0ID_ADDREFERENCESREQUEST:
  282. INVOKE_SERVICE(AddReferences, UA_TYPES_ADDREFERENCESRESPONSE);
  283. break;
  284. case UA_NS0ID_REGISTERNODESREQUEST:
  285. INVOKE_SERVICE(RegisterNodes, UA_TYPES_REGISTERNODESRESPONSE);
  286. break;
  287. case UA_NS0ID_UNREGISTERNODESREQUEST:
  288. INVOKE_SERVICE(UnregisterNodes, UA_TYPES_UNREGISTERNODESRESPONSE);
  289. break;
  290. case UA_NS0ID_TRANSLATEBROWSEPATHSTONODEIDSREQUEST:
  291. INVOKE_SERVICE(TranslateBrowsePathsToNodeIds, UA_TYPES_TRANSLATEBROWSEPATHSTONODEIDSRESPONSE);
  292. break;
  293. #ifdef ENABLE_SUBSCRIPTIONS
  294. case UA_NS0ID_CREATESUBSCRIPTIONREQUEST:
  295. INVOKE_SERVICE(CreateSubscription, UA_TYPES_CREATESUBSCRIPTIONRESPONSE);
  296. break;
  297. case UA_NS0ID_PUBLISHREQUEST:
  298. INVOKE_SERVICE(Publish, UA_TYPES_PUBLISHRESPONSE);
  299. break;
  300. case UA_NS0ID_MODIFYSUBSCRIPTIONREQUEST:
  301. INVOKE_SERVICE(ModifySubscription, UA_TYPES_MODIFYSUBSCRIPTIONRESPONSE);
  302. break;
  303. case UA_NS0ID_DELETESUBSCRIPTIONSREQUEST:
  304. INVOKE_SERVICE(DeleteSubscriptions, UA_TYPES_DELETESUBSCRIPTIONSRESPONSE);
  305. break;
  306. case UA_NS0ID_CREATEMONITOREDITEMSREQUEST:
  307. INVOKE_SERVICE(CreateMonitoredItems, UA_TYPES_CREATEMONITOREDITEMSRESPONSE);
  308. break;
  309. case UA_NS0ID_DELETEMONITOREDITEMSREQUEST:
  310. INVOKE_SERVICE(DeleteMonitoredItems, UA_TYPES_DELETEMONITOREDITEMSRESPONSE);
  311. break;
  312. #endif
  313. #ifdef ENABLE_METHODCALLS
  314. case UA_NS0ID_CALLREQUEST:
  315. INVOKE_SERVICE(Call, UA_TYPES_CALLRESPONSE);
  316. break;
  317. #endif
  318. #ifdef ENABLE_ADDNODES
  319. case UA_NS0ID_ADDNODESREQUEST:
  320. INVOKE_SERVICE(AddNodes, UA_TYPES_ADDNODESRESPONSE);
  321. break;
  322. case UA_NS0ID_DELETENODESREQUEST:
  323. INVOKE_SERVICE(DeleteNodes, UA_TYPES_DELETENODESRESPONSE);
  324. break;
  325. #endif
  326. default: {
  327. if(requestType.namespaceIndex == 0 && requestType.identifier.numeric==787)
  328. UA_LOG_INFO(server->logger, UA_LOGCATEGORY_COMMUNICATION,
  329. "Client requested a subscription that are not supported, the message will be skipped");
  330. else
  331. UA_LOG_INFO(server->logger, UA_LOGCATEGORY_COMMUNICATION, "Unknown request: NodeId(ns=%d, i=%d)",
  332. requestType.namespaceIndex, requestType.identifier.numeric);
  333. UA_RequestHeader p;
  334. UA_ServiceFault r;
  335. if(UA_RequestHeader_decodeBinary(msg, pos, &p) != UA_STATUSCODE_GOOD)
  336. return;
  337. UA_ServiceFault_init(&r);
  338. init_response_header(&p, &r.responseHeader);
  339. r.responseHeader.serviceResult = UA_STATUSCODE_BADSERVICEUNSUPPORTED;
  340. #ifdef EXTENSION_STATELESS
  341. if(retval != UA_STATUSCODE_GOOD)
  342. r.responseHeader.serviceResult = retval;
  343. #endif
  344. UA_SecureChannel_sendBinaryMessage(clientChannel, sequenceHeader.requestId, &r,
  345. &UA_TYPES[UA_TYPES_SERVICEFAULT]);
  346. UA_RequestHeader_deleteMembers(&p);
  347. UA_ServiceFault_deleteMembers(&r);
  348. break;
  349. }
  350. }
  351. }
  352. static void processCLO(UA_Connection *connection, UA_Server *server, const UA_ByteString *msg, size_t *pos) {
  353. UA_UInt32 secureChannelId;
  354. UA_StatusCode retval = UA_UInt32_decodeBinary(msg, pos, &secureChannelId);
  355. if(retval != UA_STATUSCODE_GOOD || !connection->channel ||
  356. connection->channel->securityToken.channelId != secureChannelId)
  357. return;
  358. Service_CloseSecureChannel(server, secureChannelId);
  359. }
  360. void UA_Server_processBinaryMessage(UA_Server *server, UA_Connection *connection, UA_ByteString *msg) {
  361. if(msg->length <= 0)
  362. return;
  363. size_t pos = 0;
  364. UA_TcpMessageHeader tcpMessageHeader;
  365. do {
  366. if(UA_TcpMessageHeader_decodeBinary(msg, &pos, &tcpMessageHeader)) {
  367. UA_LOG_INFO(server->logger, UA_LOGCATEGORY_COMMUNICATION, "Decoding of message header failed");
  368. connection->close(connection);
  369. break;
  370. }
  371. size_t targetpos = pos - 8 + tcpMessageHeader.messageSize;
  372. switch(tcpMessageHeader.messageTypeAndFinal & 0xffffff) {
  373. case UA_MESSAGETYPEANDFINAL_HELF & 0xffffff:
  374. processHEL(connection, msg, &pos);
  375. break;
  376. case UA_MESSAGETYPEANDFINAL_OPNF & 0xffffff:
  377. processOPN(connection, server, msg, &pos);
  378. break;
  379. case UA_MESSAGETYPEANDFINAL_MSGF & 0xffffff:
  380. #ifndef EXTENSION_STATELESS
  381. if(connection->state != UA_CONNECTION_ESTABLISHED){
  382. connection->close(connection);
  383. UA_ByteString_deleteMembers(msg);
  384. return;
  385. }else
  386. #endif
  387. processMSG(connection, server, msg, &pos);
  388. break;
  389. case UA_MESSAGETYPEANDFINAL_CLOF & 0xffffff:
  390. processCLO(connection, server, msg, &pos);
  391. connection->close(connection);
  392. UA_ByteString_deleteMembers(msg);
  393. return;
  394. }
  395. UA_TcpMessageHeader_deleteMembers(&tcpMessageHeader);
  396. if(pos != targetpos) {
  397. UA_LOG_INFO(server->logger, UA_LOGCATEGORY_COMMUNICATION,
  398. "The message was not entirely processed, skipping to the end");
  399. pos = targetpos;
  400. }
  401. } while(msg->length > (UA_Int32)pos);
  402. UA_ByteString_deleteMembers(msg);
  403. }