test(wpa_supplicant): wait for the idle task after esp_wifi_deinit in eloop unit test
Closes IDFCI-11307 and IDFCI-12170
See merge request espressif/esp-idf!52111
The Wi-Fi task deletes itself when esp_wifi_deinit() is called, and FreeRTOS
only reclaims its TCB and stack from the idle task afterwards. Test apps that
read the heap right after deinit therefore see that memory as still allocated
and report a leak, most visibly as the eloop unit tests failing on ESP32.
Wait for the idle task at every point where a test deinitialises Wi-Fi
before a leak check, replacing the single-tick delays that only matched what
esp_wifi_deinit() already waits for internally.
Low-RSSI roaming used determine_best_ap(0), so a 1 dB better AP was
enough and nearby APs could ping-pong. Add ESP_WIFI_ROAMING_LOW_RSSI_ROAM_DIFF
(default 5 dB) as hysteresis for that path.
Accept spec-legal NAN availability time bitmaps (period > 512 TU,
bitmap length > 4, full 9-bit start offset) so iPhone secured NDP
setup is no longer rejected with NDL_UNACCEPTABLE.
Fixes NAN NDP interop with the iPhone 17 series.
1. Added validation for password and reserved data length in ESPTouch v2
2. Added bound check for data index in ESPTouch v1 HT40
3. prevent buffer overflow when parsing MBSSID beacon
- Set internal NAN params based on the user configurable Platform
- On a secured NDP the responder could not derive keys
(passphrase/credential mismatch); reject cleanly and
fire ndp_terminated/ndp_confirm(REJECTED) on every
teardown path so the host frees the NDP-ID.
- Tear down the old NDP when the same peer re-initiates with
a new M1, instead of rejecting and leaking the NDL.
- Commit 08e98f6f30 utilises CONFIG_LWIP_ND6_SUPPORT_STATIC_ENTRIES
for adding static entries.
- It moves netif calls that generate GOT IPv6 to NAN_STARTED default
handler without guard, but guards the removal in NDP Confirm handler
- Fix the possible duplicate calls by putting calls from NAN_STARTED
handler under CONFIG_LWIP_ND6_SUPPORT_STATIC_ENTRIES guard
- subscriber security gate, so a gated (dropped) match still logged an
affirmative match line while no WIFI_EVENT_NAN_SVC_MATCH was posted.
Log only when the event is sent.
- security_cfg was copied into the service slot even with security_reqd=0,
while credential validation only runs when security_reqd is set. Such an
undeclared config silently armed the subscriber service-match security
gate, suppressing match events. Scrub security_cfg from the working copy
and warn instead.
The six key-material hexdumps (ND-IGTK/BIGTK/TK/GTK and the peer IGTK/BIGTK)
kept a leftover '##' dev-grep marker on their tag string. Drop it; the
descriptive labels stay and the dumps remain at ESP_LOG_DEBUG.
- Tighten the own GTK Key ID guard from ">3" (which admitted 0 and 3) to
the spec range 1..2 (Wi-Fi Aware v4.0 §7.1.3.2).
- When the Encrypted-Key-Data bit is clear, ignore the Key Data instead of
parsing KDEs from the clear: group KDEs are only ever carried KEK-wrapped
(§7.1.3.5; 802.11-2020 §12.7.2). Also store the peer IPN/BIPN from the
IGTK/BIGTK KDEs for the BIP RX replay-counter seed.
The peer IGTK/BIGTK were installed with an all-zero seq, so the blob's BIP
RX replay counter started at 0 instead of the peer's advertised value. Store
the 6-octet IPN/BIPN from the IGTK/BIGTK KDE (the octets after the 2-byte
Key ID, per 802.11 Fig 12-42/12-47) into the NDL and pass them as the
install seq. The parser side of this lands with the group-KDE guards.
Rebuilt libs with NAN group-key (GTK/IGTK/BIGTK) support, matching the
nan_key_type_t and group-protection header updates so the MD5-checked
esp_wifi_driver.h and esp_wifi_types_generic.h verify.
Refresh stale/missing documentation now that the features are implemented:
- group_data_prot / group_mgmt_prot in wifi_nan_discovery_security_params_t
(esp_wifi_types_generic.h) and wifi_nan_security_params_t (esp_private/
wifi.h): describe GTKSA / IGTKSA+BIGTKSA instead of "not supported".
- CSID enum: document NCS-GTK-CCM-128 (set internally via group_data_prot,
not user-selectable) and NCS-PK-PASN-128 (NAN Pairing, via the Wi-Fi
Aware component).
- Drop "dummy" from the esp_nan_construct_nira() doc (it builds a real
NIRA) and a stale "IGTK/BIGTK are placeholders" comment.
The NAN key-type selectors are defined by the blob in esp_wifi_driver.h
(nan_key_type_t), which nan_i.h already includes. Add the group-integrity
key types NAN_KEY_ND_IGTK (3) and NAN_KEY_ND_BIGTK (4) there to match the
blob, and drop the duplicate host definitions from nan_i.h so a single
shared enum is used. Resolves the review request to declare these in
nan_key_type_t and avoids redefining the typedef.
Move the NAN_KEY_ND_TK/ND_GTK/NM_TK/ND_IGTK/ND_BIGTK selectors from #defines
into a nan_key_type_t enum, and finalize their doc wording (drop the
"provisional" note now that the IGTK/BIGTK values are verified against the
blob ABI). They are still passed to esp_wifi_set_nan_key_internal() as the
int key_flag argument, so no call-site or ABI change. Also tidy the
surrounding doc comments.
Replace the three NAN_KDE_OUI_RSN_* byte writes in nan_kde_put_hdr() with a
single nan_kde_rsn_oui[] array, and remove the now-unused NAN_KDE_OUI_RSN_*
byte macros and the never-used NAN_KDE_OUI_WFA_* byte macros. The combined
NAN_KDE_OUI_RSN / NAN_KDE_OUI_WFA (used by the KDE parser) are kept.