fix(nan): log service match only after the security gate passes

- subscriber security gate, so a gated (dropped) match still logged an
   affirmative match line while no WIFI_EVENT_NAN_SVC_MATCH was posted.
   Log only when the event is sent.

 - security_cfg was copied into the service slot even with security_reqd=0,
   while credential validation only runs when security_reqd is set. Such an
   undeclared config silently armed the subscriber service-match security
   gate, suppressing match events. Scrub security_cfg from the working copy
   and warn instead.
This commit is contained in:
Sarvesh Bodakhe
2026-07-17 14:01:21 +05:30
committed by Akshat Agrawal
parent 9e9c16c724
commit 7ed4798191
@@ -934,8 +934,6 @@ static void nan_app_service_match_cb(uint8_t sub_id, struct nan_cb_peer_info *pe
}
NAN_DATA_UNLOCK();
ESP_LOGI(TAG, "Service matched with capabilities: 0x%04x", capab);
#ifdef CONFIG_ESP_WIFI_NAN_SECURITY
/* Service-match security gate, keyed by the local subscribe (sub_id):
* 1. This subscribe was created without credentials (open subscribe) ->
@@ -969,6 +967,8 @@ static void nan_app_service_match_cb(uint8_t sub_id, struct nan_cb_peer_info *pe
}
#endif
ESP_LOGI(TAG, "Service matched with capabilities: 0x%04x", capab);
size_t evt_data_len = sizeof(wifi_event_nan_svc_match_t) + ssi_len;
wifi_event_nan_svc_match_t *evt = (wifi_event_nan_svc_match_t *)os_zalloc(evt_data_len);
if (!evt) {
@@ -2174,6 +2174,10 @@ uint8_t esp_wifi_nan_publish_service(const wifi_nan_publish_cfg_t *publish_cfg)
goto fail;
}
memcpy(cfg, publish_cfg, sizeof(*cfg));
if (!cfg->security_reqd && cfg->security_cfg) {
ESP_LOGW(TAG, "'%s': security_cfg ignored, security_reqd not set", cfg->service_name);
cfg->security_cfg = NULL;
}
cfg->pairing = NULL;
if (publish_cfg->pairing) {
cfg->pairing = os_malloc(sizeof(*cfg->pairing));
@@ -2355,6 +2359,10 @@ uint8_t esp_wifi_nan_subscribe_service(const wifi_nan_subscribe_cfg_t *subscribe
goto fail;
}
memcpy(cfg, subscribe_cfg, sizeof(*cfg));
if (!cfg->security_reqd && cfg->security_cfg) {
ESP_LOGW(TAG, "'%s': security_cfg ignored, security_reqd not set", cfg->service_name);
cfg->security_cfg = NULL;
}
cfg->pairing = NULL;
if (subscribe_cfg->pairing) {
cfg->pairing = os_malloc(sizeof(*cfg->pairing));