From 7f287f6288d9fd4cf0842935aa684a1725cd6fd0 Mon Sep 17 00:00:00 2001 From: Sarvesh Bodakhe Date: Wed, 1 Jul 2026 17:51:08 +0530 Subject: [PATCH] fix(nan): seed peer BIP RX replay counter from the KDE IPN/BIPN The peer IGTK/BIGTK were installed with an all-zero seq, so the blob's BIP RX replay counter started at 0 instead of the peer's advertised value. Store the 6-octet IPN/BIPN from the IGTK/BIGTK KDE (the octets after the 2-byte Key ID, per 802.11 Fig 12-42/12-47) into the NDL and pass them as the install seq. The parser side of this lands with the group-KDE guards. --- components/esp_wifi/wifi_apps/nan_app/src/nan_app.c | 9 ++++----- components/esp_wifi/wifi_apps/nan_app/src/nan_i.h | 2 ++ 2 files changed, 6 insertions(+), 5 deletions(-) diff --git a/components/esp_wifi/wifi_apps/nan_app/src/nan_app.c b/components/esp_wifi/wifi_apps/nan_app/src/nan_app.c index 434924bc5d7..f9c569c9b22 100644 --- a/components/esp_wifi/wifi_apps/nan_app/src/nan_app.c +++ b/components/esp_wifi/wifi_apps/nan_app/src/nan_app.c @@ -1475,9 +1475,8 @@ static void nan_app_ndp_confirm_cb(uint8_t status, struct ndp_cb_peer_info *peer * nan_security_install_own_group_integrity_keys); not re-installed here, * to preserve the blob's monotonic BIPN/IPN across the session. Only the * peer RX keys are bound at NDP confirm. §7.1.3.3/§7.1.3.4; NMI==NDI today. - * Peer IGTK/BIGTK install RX-only against the peer NMI. seq (IPN/BIPN) - * starts at 0 for now; thread the peer's KDE IPN/BIPN once the blob - * consumes it for the BIP replay counter. */ + * Peer IGTK/BIGTK install RX-only against the peer NMI, seeding the BIP + * RX replay counter with the peer's advertised IPN/BIPN from the KDE. */ if (ndl->igtk_set && ndl->igtk_len) { if (ndl->igtk_len != NAN_ND_GTK_LEN) { ESP_LOGW(TAG, "NDP confirm: peer IGTK len=%d unsupported (BIP-CMAC-128 only); skipping", @@ -1485,7 +1484,7 @@ static void nan_app_ndp_confirm_cb(uint8_t status, struct ndp_cb_peer_info *peer } else { int r = esp_wifi_set_nan_key_internal(NAN_WIFI_WPA_ALG_BIP_CMAC_128, peer_nmi, ndl->igtk_keyid, 0, - key_rsc, 6, + ndl->igtk_ipn, 6, ndl->igtk, ndl->igtk_len, NAN_KEY_ND_IGTK); if (r != 0) { @@ -1504,7 +1503,7 @@ static void nan_app_ndp_confirm_cb(uint8_t status, struct ndp_cb_peer_info *peer } else { int r = esp_wifi_set_nan_key_internal(NAN_WIFI_WPA_ALG_BIP_CMAC_128, peer_nmi, ndl->bigtk_keyid, 0, - key_rsc, 6, + ndl->bigtk_ipn, 6, ndl->bigtk, ndl->bigtk_len, NAN_KEY_ND_BIGTK); if (r != 0) { diff --git a/components/esp_wifi/wifi_apps/nan_app/src/nan_i.h b/components/esp_wifi/wifi_apps/nan_app/src/nan_i.h index 74d038e6b15..7bbb4d8b0f0 100644 --- a/components/esp_wifi/wifi_apps/nan_app/src/nan_i.h +++ b/components/esp_wifi/wifi_apps/nan_app/src/nan_i.h @@ -332,6 +332,8 @@ struct ndl_info { uint8_t igtk_keyid; /* peer IGTK Key ID (4 or 5) */ uint8_t bigtk_keyid; /* peer BIGTK Key ID (6 or 7) */ uint8_t gtk_rsc[NAN_KEY_RSC_LEN]; /* peer GTK RSC from Key RSC field */ + uint8_t igtk_ipn[6]; /* peer IGTK IPN (seeds BIP RX replay counter) */ + uint8_t bigtk_ipn[6]; /* peer BIGTK BIPN (seeds BIP RX replay counter) */ uint8_t gtk_set: 1; uint8_t igtk_set: 1; uint8_t bigtk_set: 1;