refactor(wifi): NAN datapath header cleanups and docs

- Rename NAN_IPV6_ADDR_ID_LEN / IS_ZERO_NAN_ADDR_ID to ..._IPV6_IDENTIFIER
  so the names no longer read like MAC-address constants; drop the
  duplicate macro definition in esp_nan.h.
- Replace literal lengths with named macros: WIFI_OUI_LEN for
  nan_vendor_ie_t.vendor_oui, and a new WIFI_MAC_ADDR_LEN (private)
  applied to the NAN-related structs and callbacks in esp_private/wifi.h.
- Document each callback in struct nan_sync_callbacks and each helper
  in struct nan_secure_dp_funcs: when fired / when invoked, what each
  argument means, and the matching spec section where useful.
- Note in wifi_nan_datapath_req_t / wifi_nan_datapath_resp_t that they
  cover the NCS-SK credential model only; pairing-based cipher suites
  (NCS-PK-PASN) install per-peer ND-PMKs via a separate pairing API
  without changing these structs. Record why per-NDP credential
  injection at response time is not viable: the responder's PMKID
  lookup happens at M1 receive time, before the indication event
  surfaces to the host.
This commit is contained in:
Sarvesh Bodakhe
2026-05-19 16:54:12 +05:30
parent cfecf60986
commit caba5dcfea
6 changed files with 187 additions and 34 deletions
@@ -988,9 +988,9 @@ typedef struct {
* @brief NAN Vendor Specific Attribute format
*/
typedef struct {
uint8_t vendor_oui[3]; /**< Vendor identifier (OUI) */
uint16_t body_len; /**< Length of body payload (max NAN_VENDOR_IE_MAX_BODY_LEN bytes) */
uint8_t *body; /**< Vendor specific body payload */
uint8_t vendor_oui[WIFI_OUI_LEN]; /**< Vendor identifier (OUI) */
uint16_t body_len; /**< Length of body payload (max 255 bytes) */
uint8_t *body; /**< Vendor specific body payload */
} nan_vendor_ie_t;
/**
@@ -1064,6 +1064,11 @@ typedef struct {
* configuration and applies them to every NDP initiated against the
* matched publisher. Per-NDP security parameters are not exposed on
* this struct: the caller never handles raw key material.
*
* @note NCS-SK only. For pairing-based cipher suites (NCS-PK-PASN), the
* per-peer ND-PMK is derived from a cached NPKSA and will be
* installed via a separate pairing API; this struct will remain
* unchanged.
*/
typedef struct {
uint8_t pub_id; /**< Publisher's service instance id */
@@ -1080,6 +1085,14 @@ typedef struct {
* configuration and applies them to every NDP this responder
* accepts. Per-NDP security parameters are not exposed on this
* struct: the caller never handles raw key material.
*
* @note NCS-SK only. For pairing-based cipher suites (NCS-PK-PASN), the
* per-peer ND-PMK is derived from a cached NPKSA and will be
* installed via a separate pairing API; this struct will remain
* unchanged. The responder must already have the PMK cached at
* M1 receive time (PMKID lookup happens before the indication
* event), so per-NDP credential injection at response time is
* not viable.
*/
typedef struct {
bool accept; /**< True - Accept incoming NDP, False - Reject it */