Since IV Index is used in application nonces, we need to honor IV Update
flag not only in network layer crypto, but also in application layer.
Otherwise, we cannot decode application payloads from nodes that are in
IV Update state.
---
mesh/net.c | 18 ++++++++++--------
1 file changed, 10 insertions(+), 8 deletions(-)
diff --git a/mesh/net.c b/mesh/net.c
index a597b8794..1aa1c4cfa 100644
--- a/mesh/net.c
+++ b/mesh/net.c
@@ -2489,6 +2489,14 @@ static void net_rx(void *net_ptr, void *user_data)
size_t out_size;
uint32_t key_id;
int8_t rssi = 0;
+ uint32_t iv_index;
+ bool iv_flag = !!(net->iv_index & 1);
+ bool iv_pkt = !!(data->data[0] & 0x80);
+
+ if (iv_pkt == iv_flag)
+ iv_index = net->iv_index;
+ else
+ iv_index = net->iv_index - 1;
key_id = net_key_decrypt(net->iv_index, data->data, data->len,
&out, &out_size);
@@ -2504,16 +2512,10 @@ static void net_rx(void *net_ptr, void *user_data)
rssi = data->info->rssi;
}
- relay_advice = packet_received(net, key_id, net->iv_index,
+ relay_advice = packet_received(net, key_id, iv_index,
out, out_size, rssi);
if (relay_advice > data->relay_advice) {
- bool iv_flag = !!(net->iv_index & 1);
- bool iv_pkt = !!(data->data[0] & 0x80);
-
- data->iv_index = net->iv_index;
- if (iv_pkt != iv_flag)
- data->iv_index--;
-
+ data->iv_index = iv_index;
data->relay_advice = relay_advice;
data->key_id = key_id;
data->net = net;
--
2.19.1