Merge branch 'bugfix/nan_mem_corruption_v6.1' into 'release/v6.1'

Fix(NAN): fix Memory Corruption due to BIP encryption (Backport v6.1)

See merge request espressif/esp-idf!50883
This commit is contained in:
Jiang Jiang Jian
2026-07-18 02:18:48 +08:00
5 changed files with 69 additions and 4 deletions
+2
View File
@@ -187,8 +187,10 @@ static void wifi_default_action_nan_started(void *arg, esp_event_base_t base, in
/* Bring the netif up before esp_netif_create_ip6_linklocal() (a no-op unless
* netif_is_up()). esp_netif_up() is private, so use the public action handler;
* NAN is non-DHCP, so it only calls esp_netif_up() and ignores the event args. */
#if CONFIG_LWIP_ND6_SUPPORT_STATIC_ENTRIES
esp_netif_action_connected(s_wifi_netifs[WIFI_IF_NAN], NULL, 0, NULL);
esp_netif_create_ip6_linklocal(s_wifi_netifs[WIFI_IF_NAN]);
#endif
}
}
@@ -49,6 +49,26 @@ void esp_nan_action_start(esp_netif_t *nan_netif);
*/
void esp_nan_action_stop(void);
/**
* @brief NAN peer-platform compatibility mode
*/
typedef enum {
NAN_COMPATIBILITY_MODE_DEFAULT = 0, /**< Default compatibility mode for Wi-Fi Aware peers */
NAN_COMPATIBILITY_MODE_IOS, /**< Interoperate with iOS Wi-Fi Aware peers */
NAN_COMPATIBILITY_MODE_ANDROID, /**< Interoperate with Android Wi-Fi Aware peers */
} nan_compatibility_mode_t;
/**
* @brief Set NAN peer-platform compatibility mode
*
* @param mode Compatibility mode to target for discovery/SSI framing.
*
* @return
* - ESP_OK: succeed
* - ESP_FAIL: Invalid compatibility mode
*/
esp_err_t esp_nan_set_compatibility_mode_internal(nan_compatibility_mode_t mode);
#endif /* CONFIG_ESP_WIFI_NAN_SYNC_ENABLE */
#ifdef CONFIG_ESP_WIFI_NAN_PAIRING
@@ -61,6 +61,8 @@ bool esp_nan_verify_nira_get_own_svc(uint8_t *peer_mac, uint8_t *nira_attr,
#if defined(CONFIG_ESP_WIFI_NAN_SYNC_ENABLE) && defined(CONFIG_ESP_WIFI_PASN_SUPPORT)
#include "esp_private/esp_supp_nan.h"
#include "apps_private/wifi_apps_private.h"
#elif defined(CONFIG_ESP_WIFI_NAN_SYNC_ENABLE)
#include "apps_private/wifi_apps_private.h"
#endif
/* NAN States */
@@ -934,8 +936,6 @@ static void nan_app_service_match_cb(uint8_t sub_id, struct nan_cb_peer_info *pe
}
NAN_DATA_UNLOCK();
ESP_LOGI(TAG, "Service matched with capabilities: 0x%04x", capab);
#ifdef CONFIG_ESP_WIFI_NAN_SECURITY
/* Service-match security gate, keyed by the local subscribe (sub_id):
* 1. This subscribe was created without credentials (open subscribe) ->
@@ -969,6 +969,8 @@ static void nan_app_service_match_cb(uint8_t sub_id, struct nan_cb_peer_info *pe
}
#endif
ESP_LOGI(TAG, "Service matched with capabilities: 0x%04x", capab);
size_t evt_data_len = sizeof(wifi_event_nan_svc_match_t) + ssi_len;
wifi_event_nan_svc_match_t *evt = (wifi_event_nan_svc_match_t *)os_zalloc(evt_data_len);
if (!evt) {
@@ -1891,6 +1893,34 @@ void esp_nan_action_stop(void)
os_event_group_set_bits(nan_event_group, NAN_STOPPED_BIT);
}
static int nan_set_params_ipc(void *arg)
{
wifi_nan_compat_params_t *params = arg;
return esp_wifi_nan_set_params_internal(*params);
}
esp_err_t esp_nan_set_compatibility_mode_internal(nan_compatibility_mode_t mode)
{
wifi_ipc_config_t cfg;
wifi_nan_compat_params_t params = {0};
if (mode > NAN_COMPATIBILITY_MODE_ANDROID) {
ESP_LOGE(TAG, "Invalid compatibility mode");
return ESP_ERR_INVALID_ARG;
}
if (mode == NAN_COMPATIBILITY_MODE_ANDROID) {
params.nan_gsp_in_sda = 1;
}
cfg.fn = nan_set_params_ipc;
cfg.arg = &params;
cfg.arg_size = sizeof(params);
return esp_wifi_ipc_internal(&cfg, false);
}
esp_err_t esp_wifi_nan_sync_start(const wifi_nan_sync_config_t *nan_cfg)
{
wifi_mode_t mode;
@@ -2174,6 +2204,10 @@ uint8_t esp_wifi_nan_publish_service(const wifi_nan_publish_cfg_t *publish_cfg)
goto fail;
}
memcpy(cfg, publish_cfg, sizeof(*cfg));
if (!cfg->security_reqd && cfg->security_cfg) {
ESP_LOGW(TAG, "'%s': security_cfg ignored, security_reqd not set", cfg->service_name);
cfg->security_cfg = NULL;
}
cfg->pairing = NULL;
if (publish_cfg->pairing) {
cfg->pairing = os_malloc(sizeof(*cfg->pairing));
@@ -2355,6 +2389,10 @@ uint8_t esp_wifi_nan_subscribe_service(const wifi_nan_subscribe_cfg_t *subscribe
goto fail;
}
memcpy(cfg, subscribe_cfg, sizeof(*cfg));
if (!cfg->security_reqd && cfg->security_cfg) {
ESP_LOGW(TAG, "'%s': security_cfg ignored, security_reqd not set", cfg->service_name);
cfg->security_cfg = NULL;
}
cfg->pairing = NULL;
if (subscribe_cfg->pairing) {
cfg->pairing = os_malloc(sizeof(*cfg->pairing));
@@ -249,6 +249,11 @@ typedef struct {
bool is_valid; /**< True if this credential entry is valid */
} wifi_nan_peer_creds_t;
typedef struct {
uint8_t nan_gsp_in_sda : 1; /**< Include GSP in SDA for Android peer compatibility */
uint8_t reserved : 7;
} wifi_nan_compat_params_t;
typedef wifi_scan_channel_bitmap_t channel_bitmap_t;
uint8_t *esp_wifi_ap_get_prof_pmk_internal(void);
@@ -354,5 +359,5 @@ esp_err_t esp_wifi_nan_save_own_nik(const uint8_t own_nik[ESP_WIFI_NAN_NIK_LEN])
esp_err_t esp_wifi_nan_save_creds_for_peer(const uint8_t peer_nik[ESP_WIFI_NAN_NIK_LEN],
const uint8_t npk[ESP_WIFI_NAN_NPK_LEN], const uint8_t service_hash[6]);
esp_err_t esp_wifi_nan_erase_all_creds(void);
esp_err_t esp_wifi_nan_set_params_internal(wifi_nan_compat_params_t params);
#endif /* _ESP_WIFI_DRIVER_H_ */