From f2cf9d74860f29701863e8a6166589883995db81 Mon Sep 17 00:00:00 2001 From: Sarvesh Bodakhe Date: Wed, 1 Jul 2026 13:56:19 +0530 Subject: [PATCH] fix(nan): free NDL slot and deny peer when get_mac fails on NDP resp The NDP indication handler recorded an NDL slot, then on esp_wifi_get_mac failure unlocked and returned without releasing the slot or answering the peer: the slot leaked (counting against the NDL limit) and the peer waited indefinitely. On failure now reset the NDL and send a deny response, mirroring the existing allocation-failure cleanup path. Also drop the redundant pre-branch get_mac/IPv6-derive: its result was only used on the auto-response path, which recomputes it, so on the indication path it was dead work and a second leak site. --- .../esp_wifi/wifi_apps/nan_app/src/nan_app.c | 18 ++++++------------ 1 file changed, 6 insertions(+), 12 deletions(-) diff --git a/components/esp_wifi/wifi_apps/nan_app/src/nan_app.c b/components/esp_wifi/wifi_apps/nan_app/src/nan_app.c index 9a85de3e439..06995d26a5b 100644 --- a/components/esp_wifi/wifi_apps/nan_app/src/nan_app.c +++ b/components/esp_wifi/wifi_apps/nan_app/src/nan_app.c @@ -1183,17 +1183,6 @@ static void nan_app_ndp_indication_cb(uint8_t pub_id, struct ndp_cb_peer_info *p nan_security_apply_pending(ndl, p_own_svc, pub_id, peer_nmi, peer_ndi); #endif - if (device_caps & NAN_CAPS_NDPE_ATTR) { - uint8_t own_bssid[6]; - esp_err_t err = esp_wifi_get_mac(WIFI_IF_NAN, own_bssid); - if (err != ESP_OK) { - NAN_DATA_UNLOCK(); - ESP_LOGE(TAG, "Cannot get own BSSID!"); - return; - } - esp_wifi_nan_get_ipv6_linklocal_from_mac(&own_ipv6.u_addr.ip6, own_bssid); - } - if (p_own_svc->ndp_resp_needed) { ESP_LOGD(TAG, "NDP Req from "MACSTR" [NDP Id: %d], Accept OR Deny using NDP command", MAC2STR(peer_nmi), ndp_id); @@ -1209,8 +1198,13 @@ static void nan_app_ndp_indication_cb(uint8_t pub_id, struct ndp_cb_peer_info *p uint8_t own_bssid[6]; esp_err_t err = esp_wifi_get_mac(WIFI_IF_NAN, own_bssid); if (err != ESP_OK) { + /* Cannot build the auto-response: free the NDL slot and deny the + * peer so it does not wait indefinitely. Send outside the lock. */ + ESP_LOGE(TAG, "get own NAN MAC failed, rc=0x%x; denying NDP ndp_id=%d", err, ndp_id); + nan_reset_ndl(ndp_id, false); NAN_DATA_UNLOCK(); - ESP_LOGE(TAG, "Cannot get own BSSID!"); + ndp_resp.accept = false; + esp_nan_internal_datapath_resp(&ndp_resp, (uint8_t *)&own_ipv6.u_addr.ip6.addr[2]); return; } esp_wifi_nan_get_ipv6_linklocal_from_mac(&own_ipv6.u_addr.ip6, own_bssid);