From 161197138ae79be3114710aa1cd29c3f5930fac0 Mon Sep 17 00:00:00 2001 From: Sarvesh Bodakhe Date: Mon, 13 Jul 2026 15:01:44 +0530 Subject: [PATCH 1/3] fix(nan): log service match only after the security gate passes - subscriber security gate, so a gated (dropped) match still logged an affirmative match line while no WIFI_EVENT_NAN_SVC_MATCH was posted. Log only when the event is sent. - security_cfg was copied into the service slot even with security_reqd=0, while credential validation only runs when security_reqd is set. Such an undeclared config silently armed the subscriber service-match security gate, suppressing match events. Scrub security_cfg from the working copy and warn instead. --- components/esp_wifi/wifi_apps/nan_app/src/nan_app.c | 12 ++++++++++-- 1 file changed, 10 insertions(+), 2 deletions(-) diff --git a/components/esp_wifi/wifi_apps/nan_app/src/nan_app.c b/components/esp_wifi/wifi_apps/nan_app/src/nan_app.c index 6dca0787e16..39fa16791ef 100644 --- a/components/esp_wifi/wifi_apps/nan_app/src/nan_app.c +++ b/components/esp_wifi/wifi_apps/nan_app/src/nan_app.c @@ -934,8 +934,6 @@ static void nan_app_service_match_cb(uint8_t sub_id, struct nan_cb_peer_info *pe } NAN_DATA_UNLOCK(); - ESP_LOGI(TAG, "Service matched with capabilities: 0x%04x", capab); - #ifdef CONFIG_ESP_WIFI_NAN_SECURITY /* Service-match security gate, keyed by the local subscribe (sub_id): * 1. This subscribe was created without credentials (open subscribe) -> @@ -969,6 +967,8 @@ static void nan_app_service_match_cb(uint8_t sub_id, struct nan_cb_peer_info *pe } #endif + ESP_LOGI(TAG, "Service matched with capabilities: 0x%04x", capab); + size_t evt_data_len = sizeof(wifi_event_nan_svc_match_t) + ssi_len; wifi_event_nan_svc_match_t *evt = (wifi_event_nan_svc_match_t *)os_zalloc(evt_data_len); if (!evt) { @@ -2174,6 +2174,10 @@ uint8_t esp_wifi_nan_publish_service(const wifi_nan_publish_cfg_t *publish_cfg) goto fail; } memcpy(cfg, publish_cfg, sizeof(*cfg)); + if (!cfg->security_reqd && cfg->security_cfg) { + ESP_LOGW(TAG, "'%s': security_cfg ignored, security_reqd not set", cfg->service_name); + cfg->security_cfg = NULL; + } cfg->pairing = NULL; if (publish_cfg->pairing) { cfg->pairing = os_malloc(sizeof(*cfg->pairing)); @@ -2355,6 +2359,10 @@ uint8_t esp_wifi_nan_subscribe_service(const wifi_nan_subscribe_cfg_t *subscribe goto fail; } memcpy(cfg, subscribe_cfg, sizeof(*cfg)); + if (!cfg->security_reqd && cfg->security_cfg) { + ESP_LOGW(TAG, "'%s': security_cfg ignored, security_reqd not set", cfg->service_name); + cfg->security_cfg = NULL; + } cfg->pairing = NULL; if (subscribe_cfg->pairing) { cfg->pairing = os_malloc(sizeof(*cfg->pairing)); From a8ff7d2ab305c4669f0db016331afcf2887706d8 Mon Sep 17 00:00:00 2001 From: Nachiket Kukade Date: Fri, 17 Jul 2026 12:24:31 +0530 Subject: [PATCH 2/3] fix(nan): Guard netif calls in NAN_STARTED default event handler - Commit 08e98f6f3015 utilises CONFIG_LWIP_ND6_SUPPORT_STATIC_ENTRIES for adding static entries. - It moves netif calls that generate GOT IPv6 to NAN_STARTED default handler without guard, but guards the removal in NDP Confirm handler - Fix the possible duplicate calls by putting calls from NAN_STARTED handler under CONFIG_LWIP_ND6_SUPPORT_STATIC_ENTRIES guard --- components/esp_wifi/src/wifi_default.c | 2 ++ 1 file changed, 2 insertions(+) diff --git a/components/esp_wifi/src/wifi_default.c b/components/esp_wifi/src/wifi_default.c index c73f4294abc..3798a647ac8 100644 --- a/components/esp_wifi/src/wifi_default.c +++ b/components/esp_wifi/src/wifi_default.c @@ -187,8 +187,10 @@ static void wifi_default_action_nan_started(void *arg, esp_event_base_t base, in /* Bring the netif up before esp_netif_create_ip6_linklocal() (a no-op unless * netif_is_up()). esp_netif_up() is private, so use the public action handler; * NAN is non-DHCP, so it only calls esp_netif_up() and ignores the event args. */ +#if CONFIG_LWIP_ND6_SUPPORT_STATIC_ENTRIES esp_netif_action_connected(s_wifi_netifs[WIFI_IF_NAN], NULL, 0, NULL); esp_netif_create_ip6_linklocal(s_wifi_netifs[WIFI_IF_NAN]); +#endif } } From 4f93a6777bfea13a43e6d1afb4ef6654f2d35f76 Mon Sep 17 00:00:00 2001 From: Akshat Agrawal Date: Tue, 7 Jul 2026 19:22:26 +0530 Subject: [PATCH 3/3] Fix(NAN): fix Memory Corruption due to BIP encryption - Set internal NAN params based on the user configurable Platform - On a secured NDP the responder could not derive keys (passphrase/credential mismatch); reject cleanly and fire ndp_terminated/ndp_confirm(REJECTED) on every teardown path so the host frees the NDP-ID. - Tear down the old NDP when the same peer re-initiates with a new M1, instead of rejecting and leaking the NDL. --- components/esp_wifi/lib | 2 +- .../include/apps_private/wifi_apps_private.h | 20 +++++++++++++ .../esp_wifi/wifi_apps/nan_app/src/nan_app.c | 30 +++++++++++++++++++ .../esp_supplicant/src/esp_wifi_driver.h | 7 ++++- 4 files changed, 57 insertions(+), 2 deletions(-) diff --git a/components/esp_wifi/lib b/components/esp_wifi/lib index 248fd630de1..11721cfefe4 160000 --- a/components/esp_wifi/lib +++ b/components/esp_wifi/lib @@ -1 +1 @@ -Subproject commit 248fd630de1f6e4873085e3af9af280895b42d61 +Subproject commit 11721cfefe4f9a3d8f205c87e478e2d01315c240 diff --git a/components/esp_wifi/wifi_apps/include/apps_private/wifi_apps_private.h b/components/esp_wifi/wifi_apps/include/apps_private/wifi_apps_private.h index 95bf9465500..3d56822e010 100644 --- a/components/esp_wifi/wifi_apps/include/apps_private/wifi_apps_private.h +++ b/components/esp_wifi/wifi_apps/include/apps_private/wifi_apps_private.h @@ -49,6 +49,26 @@ void esp_nan_action_start(esp_netif_t *nan_netif); */ void esp_nan_action_stop(void); +/** + * @brief NAN peer-platform compatibility mode + */ +typedef enum { + NAN_COMPATIBILITY_MODE_DEFAULT = 0, /**< Default compatibility mode for Wi-Fi Aware peers */ + NAN_COMPATIBILITY_MODE_IOS, /**< Interoperate with iOS Wi-Fi Aware peers */ + NAN_COMPATIBILITY_MODE_ANDROID, /**< Interoperate with Android Wi-Fi Aware peers */ +} nan_compatibility_mode_t; + +/** + * @brief Set NAN peer-platform compatibility mode + * + * @param mode Compatibility mode to target for discovery/SSI framing. + * + * @return + * - ESP_OK: succeed + * - ESP_FAIL: Invalid compatibility mode + */ +esp_err_t esp_nan_set_compatibility_mode_internal(nan_compatibility_mode_t mode); + #endif /* CONFIG_ESP_WIFI_NAN_SYNC_ENABLE */ #ifdef CONFIG_ESP_WIFI_NAN_PAIRING diff --git a/components/esp_wifi/wifi_apps/nan_app/src/nan_app.c b/components/esp_wifi/wifi_apps/nan_app/src/nan_app.c index 39fa16791ef..c70e1f9ac5f 100644 --- a/components/esp_wifi/wifi_apps/nan_app/src/nan_app.c +++ b/components/esp_wifi/wifi_apps/nan_app/src/nan_app.c @@ -61,6 +61,8 @@ bool esp_nan_verify_nira_get_own_svc(uint8_t *peer_mac, uint8_t *nira_attr, #if defined(CONFIG_ESP_WIFI_NAN_SYNC_ENABLE) && defined(CONFIG_ESP_WIFI_PASN_SUPPORT) #include "esp_private/esp_supp_nan.h" #include "apps_private/wifi_apps_private.h" +#elif defined(CONFIG_ESP_WIFI_NAN_SYNC_ENABLE) +#include "apps_private/wifi_apps_private.h" #endif /* NAN States */ @@ -1891,6 +1893,34 @@ void esp_nan_action_stop(void) os_event_group_set_bits(nan_event_group, NAN_STOPPED_BIT); } +static int nan_set_params_ipc(void *arg) +{ + wifi_nan_compat_params_t *params = arg; + + return esp_wifi_nan_set_params_internal(*params); +} + +esp_err_t esp_nan_set_compatibility_mode_internal(nan_compatibility_mode_t mode) +{ + wifi_ipc_config_t cfg; + wifi_nan_compat_params_t params = {0}; + + if (mode > NAN_COMPATIBILITY_MODE_ANDROID) { + ESP_LOGE(TAG, "Invalid compatibility mode"); + return ESP_ERR_INVALID_ARG; + } + + if (mode == NAN_COMPATIBILITY_MODE_ANDROID) { + params.nan_gsp_in_sda = 1; + } + + cfg.fn = nan_set_params_ipc; + cfg.arg = ¶ms; + cfg.arg_size = sizeof(params); + + return esp_wifi_ipc_internal(&cfg, false); +} + esp_err_t esp_wifi_nan_sync_start(const wifi_nan_sync_config_t *nan_cfg) { wifi_mode_t mode; diff --git a/components/wpa_supplicant/esp_supplicant/src/esp_wifi_driver.h b/components/wpa_supplicant/esp_supplicant/src/esp_wifi_driver.h index 0b00cad906b..4e9dcdeae94 100644 --- a/components/wpa_supplicant/esp_supplicant/src/esp_wifi_driver.h +++ b/components/wpa_supplicant/esp_supplicant/src/esp_wifi_driver.h @@ -249,6 +249,11 @@ typedef struct { bool is_valid; /**< True if this credential entry is valid */ } wifi_nan_peer_creds_t; +typedef struct { + uint8_t nan_gsp_in_sda : 1; /**< Include GSP in SDA for Android peer compatibility */ + uint8_t reserved : 7; +} wifi_nan_compat_params_t; + typedef wifi_scan_channel_bitmap_t channel_bitmap_t; uint8_t *esp_wifi_ap_get_prof_pmk_internal(void); @@ -354,5 +359,5 @@ esp_err_t esp_wifi_nan_save_own_nik(const uint8_t own_nik[ESP_WIFI_NAN_NIK_LEN]) esp_err_t esp_wifi_nan_save_creds_for_peer(const uint8_t peer_nik[ESP_WIFI_NAN_NIK_LEN], const uint8_t npk[ESP_WIFI_NAN_NPK_LEN], const uint8_t service_hash[6]); esp_err_t esp_wifi_nan_erase_all_creds(void); - +esp_err_t esp_wifi_nan_set_params_internal(wifi_nan_compat_params_t params); #endif /* _ESP_WIFI_DRIVER_H_ */