Received: by 2002:a25:868d:0:0:0:0:0 with SMTP id z13csp11970ybk; Fri, 8 May 2020 17:00:58 -0700 (PDT) X-Google-Smtp-Source: APiQypK050Sj6U99gBfJLGJpZTzIpuyeKI1ON7XvdPQn+X1yggvWXfMyEiDN38TfM89S5Z8oBPzR X-Received: by 2002:a05:6402:204b:: with SMTP id bc11mr4360957edb.114.1588982458199; Fri, 08 May 2020 17:00:58 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1588982458; cv=none; d=google.com; s=arc-20160816; b=ssK7uM7itEWErxDREVW3MXaMMUjldyLR+YZAxNRFvcpS0VMUl2JyE4CXt16o8sWVXI 8MV8YvJ5Kcot8hJIj6Af+TIig5PRbzGJqgI3AN1ftkl+lCQvXGX6K8JvKykqZG+hEVam Ka+gi7BJ9kuy8WMV6xTdpcWC+pVu8sy/iqohyLtHxcmBaAqCa1w1oPNTgLuwUp/CkRK6 BOgCtsOrBNQCBgtwcUuXEPnV73zuB+f1lF+iknDLCUBQ99n8x21t7HxkCfQRrIgBVWA9 8vTOQAFVSy7iDaG5CYmpa9tGQ2b9bO2/P8O3cXJl5Ok06sr0EfwBN2l0430HniQYWoD5 z+Qw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:content-transfer-encoding:mime-version :references:in-reply-to:message-id:date:subject:cc:to:from :ironport-sdr:ironport-sdr; bh=z1SRqOqMM9cXxG3Ym2P+pthb/0x8SIZRV/Fen7vFsD0=; b=Sr7QXPOcdLyJwF0hB5f3d4fznBJe9dIRq//rENujdw36/U1lks4i26dARoA2WD3q0U eHIBWg0hSc91DfMRHIFJYTozQsXF8ZMEgPogyDvwUOwdiBq2YlmSfTikF7ceobSrSv+0 bZUi6iSUAsS4P7wSSitWZcKKoGgZHQt1zl1JVZ/RaJxA0gzILSDTNwG5bDlk4l+rviRi 0fnzr9UgyVNF0gI7bgXlMbFv3Ci/oodaP0jlOeJiXPnDxpj0Uv36TZLXgoPxSup5bcft ObQPPnSVxmo6llib73xvId8jFfNBpGNIiwbbIW99prUazP2H5Fh8+G/K3fV97rpVsjdH kVXw== ARC-Authentication-Results: i=1; mx.google.com; spf=pass (google.com: domain of linux-bluetooth-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-bluetooth-owner@vger.kernel.org; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=intel.com Return-Path: Received: from vger.kernel.org (vger.kernel.org. [23.128.96.18]) by mx.google.com with ESMTP id e25si545308ejc.36.2020.05.08.17.00.34; Fri, 08 May 2020 17:00:58 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-bluetooth-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) client-ip=23.128.96.18; Authentication-Results: mx.google.com; spf=pass (google.com: domain of linux-bluetooth-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-bluetooth-owner@vger.kernel.org; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=intel.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1726380AbgEIAA1 (ORCPT + 99 others); Fri, 8 May 2020 20:00:27 -0400 Received: from mga04.intel.com ([192.55.52.120]:65492 "EHLO mga04.intel.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1728351AbgEIAA0 (ORCPT ); Fri, 8 May 2020 20:00:26 -0400 IronPort-SDR: 0nQV3sRBNzkHYJ/YibmfbHq5M8LMFgUnglwxmnjlIDu/5AWXtwXdzsHqSPBy5PkTy2n8dSheOq ZBvKCbeKwOwA== X-Amp-Result: SKIPPED(no attachment in message) X-Amp-File-Uploaded: False Received: from orsmga004.jf.intel.com ([10.7.209.38]) by fmsmga104.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 08 May 2020 17:00:26 -0700 IronPort-SDR: LhcSlBqa2YAPTY4Ho88ji0wupgObXiIP5BOJyVmPYhvsI1Iwp+nWlknJU2Y8gzbeW7H54AEhHb 3WkA8ZAt2uKQ== X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="5.73,369,1583222400"; d="scan'208";a="408275091" Received: from ingas-nuc1.sea.intel.com ([10.254.110.242]) by orsmga004.jf.intel.com with ESMTP; 08 May 2020 17:00:26 -0700 From: Inga Stotland To: linux-bluetooth@vger.kernel.org Cc: brian.gix@intel.com, Inga Stotland Subject: [PATCH BlueZ 1/4] mesh: On node attach, verify element/model composition only Date: Fri, 8 May 2020 17:00:21 -0700 Message-Id: <20200509000024.5704-2-inga.stotland@intel.com> X-Mailer: git-send-email 2.21.3 In-Reply-To: <20200509000024.5704-1-inga.stotland@intel.com> References: <20200509000024.5704-1-inga.stotland@intel.com> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Sender: linux-bluetooth-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-bluetooth@vger.kernel.org When attaching an existing node, verify only the "elements" part of device composition, i.e., skip verification of CID/PID/VID, CRPL and features. --- mesh/node.c | 10 ++++------ 1 file changed, 4 insertions(+), 6 deletions(-) diff --git a/mesh/node.c b/mesh/node.c index acda6d472..e3f9e52e3 100644 --- a/mesh/node.c +++ b/mesh/node.c @@ -1378,7 +1378,7 @@ static bool check_req_node(struct managed_obj_request *req) { uint8_t node_comp[MAX_MSG_LEN - 2]; uint8_t attach_comp[MAX_MSG_LEN - 2]; - + uint16_t offset = 10; uint16_t node_len = node_generate_comp(req->node, node_comp, sizeof(node_comp)); @@ -1389,12 +1389,10 @@ static bool check_req_node(struct managed_obj_request *req) uint16_t attach_len = node_generate_comp(req->attach, attach_comp, sizeof(attach_comp)); - /* Ignore feature bits in Composition Compare */ - node_comp[8] = 0; - attach_comp[8] = 0; - + /* Verify only element/models composition */ if (node_len != attach_len || - memcmp(node_comp, attach_comp, node_len)) { + memcmp(&node_comp[offset], &attach_comp[offset], + node_len - offset)) { l_debug("Failed to verify app's composition data"); return false; } -- 2.21.3